Be able to map a described action to the correct exploitation lifecycle phase, infer the vulnerability class from observable server behavior, and justify exploit selection by version and configuration. The single most important thing: match the exploit to the confirmed target version and service before running it.
Start practicing
Exploitation Fundamentals — choose a session length
Free · No account required
Domain overview
This domain covers turning a discovered weakness into actual access: payload delivery, command execution, and privilege escalation on Linux and Windows targets. GPEN questions present a short scenario and ask you to classify the phase, name the vulnerability class, pick exploit-selection criteria, or choose the correct enumeration command for the target OS.
Exam objectives
Classifying actions into the exploitation lifecycle, from initial payload injection through post-exploitation and privilege escalation
Identifying vulnerability classes from server behavior, such as verbose errors revealing stack traces or database queries
Selecting exploits using target version, service configuration, and reliability factors to avoid crashing the target
Using Windows commands like wmic service get and sc qc to find unquoted service paths and weak permissions
Confusing the exploitation phase with reconnaissance or scanning; command execution with elevated privileges is post-exploitation, not vulnerability discovery
Treating any verbose error as proof of SQL injection when the stack trace may indicate a different flaw such as path disclosure or misconfiguration
Choosing an exploit by CVE match alone without confirming the exact service version and configuration, causing a crash or failed attempt
Click any question to see the full explanation and answer options, or start a focused practice session above.
During a penetration test, you successfully inject a payload into a web application that results in the server executing system commands with elevated privileges. Which phase of the exploitation lifecycle does this action primarily represent?
2When selecting an exploit for a target system, which TWO factors are most critical to ensure the exploit succeeds without crashing the target service?
3Refer to the exhibit. Which step should a tester prioritize next based on the server header information?
4Why is it important to use 'staged' payloads during a penetration test when the target has limited memory or strict filtering?
5Which of the following describes the purpose of 'encoding' shellcode in an exploitation context?
6Refer to the exhibit. What does this output indicate regarding the current exploitation attempt?
7Which technique is most effective for exploiting a heap-based buffer overflow compared to a stack-based overflow?
8Which of the following is considered a 'client-side' exploitation scenario?
9When planning an exploit that requires a specific memory address, which THREE techniques can a tester use to increase the reliability of the exploit?
10What is the primary danger of using a 'bind shell' payload in a penetration test?
11During a penetration test against an internal Windows host, you use Metasploit's psexec module with a Meterpreter payload and receive a session. You then run the getuid command and see that you are running as NT AUTHORITY\SYSTEM. However, when you attempt to access a mapped network drive that the logged-on user had access to, you receive an access denied error. Which of the following best explains this behavior?
12You have identified a Windows Server 2019 target running a custom service that is vulnerable to a stack-based buffer overflow. You develop a working exploit and want to execute it during an authorized penetration test. After sending the payload, the service crashes and the target reboots. You need to minimize the impact on the production environment while still validating the vulnerability. Which approach should you take?
13During an authorized penetration test, you have gained a low-privileged shell on a Linux host. You discover that the kernel is version 4.4.0-116-generic and the system is missing several patches. You want to escalate privileges to root. Which of the following is the most reliable and safe method to achieve privilege escalation?
14You are conducting a penetration test against a web application. During exploitation, you identify a SQL injection vulnerability that allows you to execute arbitrary SQL queries. You want to leverage this to gain remote code execution on the underlying database server. Which TWO of the following techniques are most likely to achieve this goal? (Choose two.)
15A penetration tester has gained a foothold on a Windows host and wants to escalate privileges. They discover that the host has an unquoted service path vulnerability. Which command should they use to identify services with unquoted paths that contain spaces?
16A penetration tester is preparing to exploit a stack-based buffer overflow on a Linux target. The target binary has non-executable stack (NX) enabled. Which technique should the tester use to achieve code execution?
17During an exploitation attempt against a web application, you inject a payload that causes the server to return a verbose error message containing a stack trace and database query. What is the most likely type of vulnerability you have discovered?
18You are conducting a penetration test against a web application and have identified a potential SQL injection vulnerability in a login form. You want to confirm the vulnerability and extract the database schema without causing a denial of service. Which technique should you use to safely enumerate the database?
19During a penetration test, you have identified a Windows domain controller with SMB signing disabled and obtained valid domain user credentials. You want to perform a relay attack to gain administrative access to multiple hosts. Which two conditions are necessary for a successful SMB relay attack? (Choose two.)
20You are performing a penetration test against a Windows domain and have obtained domain user credentials. You want to identify which domain controllers are vulnerable to a specific privilege escalation technique. Which TWO tools or techniques are most appropriate for enumerating domain controllers and their potential vulnerabilities? (Choose two.)
Be able to map a described action to the correct exploitation lifecycle phase, infer the vulnerability class from observable server behavior, and justify exploit selection by version and configuration. The single most important thing: match the exploit to the confirmed target version and service before running it.
The Courseiva GPEN question bank contains 20 questions in the Exploitation Fundamentals domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Exploitation Fundamentals domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included