GIAC · Free Practice Questions · Last reviewed May 2026
90real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
When conducting a penetration test, why is it critical to assess the hashing algorithm used for storing passwords rather than focusing solely on the password policy itself?
Password policies are easily bypassed by users sharing credentials.
Weak algorithms allow rapid recovery of passwords once a breach occurs.
If the hashing algorithm is weak or lacks a salt, an attacker can crack the database in bulk regardless of the complexity enforced by the policy. A strong hashing algorithm acts as the final line of defense, rendering stolen hash files useless even when the database is fully compromised.
Passwords are always transmitted in plain text over the network.
The password policy is only effective for local accounts.
Which THREE of the following are primary reasons why the NTLM authentication protocol is considered insecure for modern enterprise environments?
Lack of mutual authentication allows for relay attacks.
NTLM does not require the server to prove its identity to the client. This architectural flaw enables attackers to capture a client's authentication challenge and relay it to another server, effectively masquerading as the user without ever having to crack the password or hash.
The NTLM hash format does not utilize a salt.
Because NTLM hashes do not include a unique salt for each user, identical passwords result in identical hashes across the domain. This facilitates the use of precomputed rainbow tables, which allow an attacker to look up the plaintext password for a hash almost instantly.
NTLM requires a connection to a Domain Controller for every login.
The protocol uses hard-coded encryption keys for every session.
NTLM hashes are vulnerable to pass-the-hash attacks.
In NTLM, the hash is used as the credential itself rather than a password. If an attacker captures the NTLM hash, they can present it to other network services to authenticate as the user, completely bypassing the need for the plaintext password or the cracking of the hash.
During a penetration test, you successfully dump the LSASS memory space and extract a set of NTLM hashes. Which of the following is the most efficient next step if the goal is to determine the plaintext password of a high-value administrator account?
Use the hashes to perform a Pass-the-Hash attack on every server.
Submit the hashes to an online cloud-based cracking service.
Run Hashcat with a combination of wordlists and mask attacks.
Hashcat is the industry standard for offline cracking. By using dictionary files for common passwords and mask attacks for complexity patterns, a tester can efficiently find the password. This method is highly scalable and leverages GPU hardware to test millions of variations per second.
Reverse the MD4 algorithm to recover the original string.
Refer to the exhibit. Given the output from Mimikatz, what is the most appropriate interpretation of the 'LM NTLM' value provided for the administrator account?
The hash is a salt-based hash requiring a rainbow table.
The value represents the plaintext password in hex format.
The hash can be used directly for Pass-the-Hash authentication.
In an NTLM authentication flow, the hash is the credential. If an attacker possesses the hash, they can present it to an authentication service, and the service will accept it as proof of identity. This bypasses the need to know the plaintext password entirely.
The session has expired and the hash is now unusable.
Which of the following describes the risk associated with cached credentials in the Windows operating system during a penetration test?
Cached credentials only store the user's username.
They allow offline authentication, but are stored in plain text.
They provide a target for offline cracking to recover domain passwords.
Cached domain credentials (MSCASH or Domain Cached Credentials) can be dumped from the system and cracked offline. Since these are often cached for many users, an attacker can obtain a large number of domain hashes, significantly increasing the probability of compromising accounts within the target environment.
They are automatically wiped upon every system reboot.
Why are GPUs significantly more effective than CPUs for brute-forcing unsalted NTLM hashes?
GPUs have larger cache sizes for storing wordlists.
GPUs have a faster instruction set for MD4 algorithms.
GPUs handle massive parallel operations on simple math.
Because hashing is a simple mathematical function, a GPU's thousands of parallel cores can compute many hashes simultaneously. CPUs are better at sequential, complex logic, but for raw brute-force tasks, the parallel architecture of a GPU is vastly superior, enabling billions of attempts per second.
GPUs can bypass the salt requirement during the attack.
Want more Attacking Password Hashes practice?
Practice this domainYou are performing an offline attack against a password hash stored in an NTDS.dit file. You have successfully dumped the hashes using secretsdump.py. Given the format 'Username:RID:LMHash:NTHash:::', which hash should be targeted for a modern Windows environment to maximize cracking efficiency?
The LMHash, because it is shorter and faster to calculate.
The RID, because it provides the unique identifier for the account.
The NTHash, because it is the primary hash used by NTLM authentication.
The NTHash is a MD4 hash of the Unicode representation of the plaintext password. Since Windows Vista, NTLM has become the standard authentication protocol. Targeting the NTHash allows for direct pass-the-hash exploitation without needing the plaintext, making it the most effective target for modern penetration testing engagements.
The entire string, including the colons, to ensure format integrity.
Which TWO of the following password cracking techniques are considered 'offline' attacks?
Brute-forcing an SSH service via an internet-facing portal.
Running a dictionary attack against a SAM database file.
Accessing the SAM database file directly allows for offline processing. Since the cracking happens entirely on the tester's machine, there is zero network interaction with the target, thus preventing account lockouts, avoiding detection by intrusion detection systems, and allowing for massively parallelized computation using high-end GPU hardware.
Spraying common passwords against an O365 login portal.
Attacking an NTLM hash dump using Hashcat.
Once hashes are dumped from memory or a file, they can be cracked locally without interacting with the target system. Offline attacks are the preferred methodology for ethical hackers as they allow the use of sophisticated rules, masks, and hybrid attacks without risking the integrity of the target environment.
Phishing users to submit credentials into a fake form.
What is the primary security advantage of utilizing salts in password hashing?
It increases the length of the password, making it harder to guess.
It prevents the use of precomputed rainbow tables.
Rainbow tables are precomputed databases of hashes for millions of common passwords. By adding a unique salt to every entry in a database, the hash of a password becomes unique to that specific salt, rendering static rainbow tables ineffective as they only contain non-salted or statically-salted hash results.
It forces the hashing algorithm to use more CPU cycles.
It encrypts the password instead of hashing it.
Which attack type is most effective when an attacker has a list of usernames and a single password that they believe might be reused across multiple accounts?
Dictionary attack
Password spraying
Password spraying is designed specifically to test one known or common password against many accounts simultaneously. This strategy successfully circumvents account lockout policies that would otherwise trigger after a few failed attempts on a single account, making it highly effective for gaining initial access to large corporate environments.
Birthday attack
Rainbow table attack
What is the main risk associated with storing cleartext credentials in environment variables or configuration files?
They are susceptible to rainbow table attacks.
They can be read by any user or process with sufficient file permissions.
If a file containing cleartext credentials has overly permissive access controls, any local user or compromised process can read the file. This allows attackers to harvest high-value credentials without ever needing to perform complex password attacks, making it a critical finding during any security assessment or audit.
They prevent the use of multi-factor authentication.
They automatically trigger account lockouts after one reading.
What is the primary function of 'rules' in tools like Hashcat when performing a dictionary attack?
To decrypt the hash using the specified algorithm.
To transform dictionary words into common password variations.
Rules allow for the programmatic mutation of wordlist entries. By applying rules such as appending numbers, capitalizing, or substituting characters, testers can simulate common user password patterns. This dramatically improves success rates against users who follow simple patterns to satisfy organizational password complexity policies during the cracking process.
To automatically update the hashing algorithm to a newer standard.
To bypass account lockout mechanisms on the target system.
Want more Password Attacks and Formats practice?
Practice this domainYou are performing a network audit and need to identify live hosts across a segmented network while minimizing the risk of triggering IDS alerts. Which Nmap technique is most appropriate for stealthy host discovery in a subnet where ICMP echo requests are filtered by the firewall?
Perform a standard ICMP echo sweep (-PE).
Execute a full TCP connect scan on all ports (-sT).
Utilize TCP SYN ping (-PS) on common service ports.
TCP SYN ping sends a SYN packet to common ports, effectively bypassing ICMP-only filters. Because it does not complete a full three-way handshake, it is significantly stealthier than a full TCP connect scan. This technique is a standard industry method for host discovery in hardened, filtered network environments.
Run an ARP scan across the entire subnet (-PR).
Refer to the exhibit. You executed an Nmap scan against a host and received the output shown. Which scanning technique was most likely used to produce this specific state-based output while avoiding the completion of a full TCP three-way handshake?
TCP Connect Scan (-sT)
TCP SYN Scan (-sS)
The SYN scan is the 'half-open' technique that identifies open ports by initiating the handshake but never finishing it. By sending a RST packet upon receiving a SYN/ACK, it avoids creating a full connection entry in the target's socket table, which is the standard behavior for most Nmap scans.
UDP Scan (-sU)
TCP ACK Scan (-sA)
You are analyzing a target environment and need to identify UDP services. Which THREE of the following are significant challenges associated with performing an accurate UDP scan compared to a TCP scan?
UDP is connectionless, requiring Nmap to wait for a response that may never come.
Because UDP does not utilize a handshake, the scanner must guess if a port is open based on the presence of a response or an ICMP port unreachable message. If the packet is simply dropped by the target, the status remains ambiguous, leading to significant delays and potential errors.
UDP ports must be scanned sequentially, preventing parallelization.
Many operating systems implement ICMP rate-limiting for port unreachable messages.
When a UDP port is closed, the host should send an ICMP port unreachable message. However, most modern operating systems rate-limit these packets to prevent flooding. This causes Nmap to incorrectly label ports as 'open|filtered' because it never receives the ICMP packet needed to confirm the closed status.
UDP packets are always blocked by stateful firewalls regardless of status.
UDP responses are not guaranteed, leading to high false-negative rates.
UDP does not provide a reliable 'open' acknowledgment like a TCP SYN/ACK. If a service does not send a response to the specific probe used, Nmap has no way of knowing if the port is open or closed, resulting in a high percentage of false negatives in many scenarios.
Refer to the exhibit. What is the primary purpose of the Nmap Scripting Engine (NSE) in the context of the output provided, and how does it improve upon standard port scanning?
To increase the speed of the port discovery phase.
To perform deep inspection of application-layer services.
The NSE is designed to interact with services on an application level, such as sending HTTP requests or querying databases. This provides context beyond simple port status, allowing testers to confirm if a service is actually functioning and to gather metadata like site titles or server versions.
To bypass firewalls by using script-based obfuscation.
To convert TCP scans into more reliable UDP scans.
When conducting a network scan, you notice that many hosts are not responding to ping requests, even though they are known to be online. What is the most appropriate Nmap flag to use to ensure these hosts are still scanned for open ports?
-sP (Ping scan)
-Pn (No ping)
The -Pn flag instructs Nmap to treat all hosts as online. It skips the ping discovery phase entirely, allowing the scanner to attempt port probes on every target regardless of whether they respond to ICMP. This is necessary for scanning hosts that are protected by ICMP-blocking firewalls.
-PR (ARP ping)
-sn (Disable port scan)
Refer to the exhibit. What does the Nmap status 'open|filtered' indicate about the target port, and why does this result commonly occur in penetration testing scenarios?
The port is definitely open but the response was malformed.
The port is likely closed and the firewall is silently dropping traffic.
The port is likely open but the scanner is not receiving a clear response.
This result occurs when Nmap sends a probe and receives no response. It could be that the port is open and the service is not replying, or that a firewall is filtering the traffic. The lack of feedback prevents Nmap from giving a definitive status, creating a state of uncertainty.
The port is definitely filtered and the service is unreachable.
Want more Scanning and Host Discovery practice?
Practice this domainWhich command in the Metasploit Framework allows a user to interact with a backgrounded session after a successful exploit execution?
exploit -j
sessions -i
The sessions command with the -i flag followed by the ID number is the standard syntax for interacting with a specific established Meterpreter session. It transfers the console's input/output to the remote system, allowing the tester to execute commands directly on the target machine with the payload's privileges.
run -s
use -session
Refer to the exhibit. Why did the EternalBlue exploit attempt fail despite the scanner identifying the target as vulnerable?
The RHOSTS value is configured incorrectly
The exploit module requires an active session
The target environment rejected the payload execution
Even if the target is vulnerable, the exploit might fail due to environmental factors like antivirus, system stability, or specific patch levels not caught by the scanner. This is a common real-world failure mode where the vulnerability check passes, but the actual payload delivery or execution is blocked by security controls.
The listener port is already in use by another process
What is the purpose of the 'meterpreter' payload in the Metasploit framework?
To perform network scanning
To provide an extensible, memory-only command interface
Meterpreter is designed to run in memory, minimizing its footprint on the target system. It offers a wide range of extensible commands that allow the penetration tester to interact with the system, escalate privileges, and maintain access, all while remaining highly resilient against traditional file-based signature detection methods.
To encode payloads for bypass
To generate shellcode for hardware
Refer to the exhibit. What is the most likely cause of the 'Connection reset by peer' error when using the PsExec module?
The SMB credentials provided are incorrect
The listener port is blocked by the target firewall
Endpoint security or a firewall terminated the SMB connection
This specific error code in the context of PsExec often signals that a security product or the Windows firewall identified the suspicious activity of installing a service remotely and terminated the SMB connection to prevent further compromise, which is standard behavior for modern EDR solutions in a secure environment.
The payload architecture does not match the target
Which of the following describes the function of the 'msfvenom' tool within the Metasploit ecosystem?
To act as a central vulnerability database
To automate the exploitation of remote services
To generate and encode custom payloads
Msfvenom allows for the creation of various payload types while applying encoding techniques to modify the binary signature. This is a crucial task for penetration testers who need to evade simple signature-based security controls by creating unique, obfuscated payloads that are less likely to be detected by traditional antivirus software.
To manage active sessions and post-exploitation
In Metasploit, what is the significance of the 'LHOST' parameter when setting up a reverse shell?
It defines the target's listening port
It identifies the attacker's IP address for the callback
LHOST is the essential configuration setting that dictates where the victim machine should send the reverse connection. If this is incorrect, the target will attempt to connect to the wrong address, and the listener will never receive the connection, resulting in a failed exploitation attempt during the test.
It is used to scan the local network
It defines the exploit's remote host target
Want more Metasploit practice?
Practice this domainA penetration tester is configuring an authenticated scan for a Windows environment. Which credential management strategy best minimizes the security impact while maintaining scan efficacy?
Configure the scanner to use the Domain Administrator account for full registry access.
Use a local account with no password to allow quick automated authentication.
Create a dedicated service account with granular WMI and remote registry permissions.
Dedicated accounts with restricted permissions ensure that the scanner can query the necessary system information without broad administrative access. By limiting the scope of the account to WMI and registry read access, you maintain effective scan quality while significantly reducing overall risk.
Store credentials in plain text in the scanner configuration file for easier automation.
Refer to the exhibit. An Nmap scan returns output indicating a web server is responding, but the `http-enum` script fails to identify common directories. Which action should the tester take to improve detection?
Increase the timing template to -T5 to make the scan faster.
Add the --script-args='http-enum.basepath=/admin' argument to the command.
Use a specialized web discovery tool like ffuf or Gobuster with a large wordlist.
Nmap's http-enum script uses a relatively small, hardcoded wordlist. Dedicated tools like Gobuster or ffuf allow for custom, extensive wordlists and high-concurrency requests, which are far more effective at discovering hidden web directories that Nmap scripts would overlook in a standard scan.
Change the scan to -sS to perform a stealthy SYN scan instead of service detection.
What is the primary purpose of a 'delta' or 'differential' vulnerability scan?
To increase the intensity of the scan to ensure all ports are covered.
To identify only the changes in the vulnerability posture since the last scan.
Differential scans compare the results of the current scan to a baseline, highlighting only what has been added, removed, or changed. This allows administrators to track new vulnerabilities introduced by recent updates or configuration changes without wasting resources re-scanning systems that have not changed state.
To bypass signature-based detection systems by using randomized payloads.
To perform an exhaustive search for zero-day vulnerabilities on all assets.
Which phase of a vulnerability assessment typically involves comparing the output against a known database of CVEs?
Host Discovery
Service Identification
Vulnerability Detection
Vulnerability detection is the phase where the scanner maps the software versions identified on the target against its internal CVE database. This process identifies known flaws associated with those specific versions and generates the reports that security teams use for remediation and risk prioritization.
Remediation Verification
Which of the following actions is the most appropriate step after discovering a critical vulnerability that is currently being exploited in the wild?
Wait until the full scan report is generated at the end of the month.
Notify the system owners and trigger an out-of-band remediation process.
Actively exploited vulnerabilities require immediate attention. Notifying the owners and initiating an out-of-band remediation process bypasses standard, slower reporting cycles, allowing for rapid patching or the implementation of temporary compensating controls to block exploitation attempts while the permanent fix is tested and deployed.
Re-run the scan to verify the vulnerability is not a false positive.
Isolate the server from the network immediately without notifying anyone.
Which document should a penetration tester consult to determine the allowed scope and rules of engagement for a vulnerability scan?
The organization's public-facing bug bounty program policy.
The Rules of Engagement (RoE) document.
The Rules of Engagement document outlines the authorized scope, permitted testing times, and specific constraints for the engagement. It is the primary legal and operational guide that dictates how the tester can interact with the client's assets during a vulnerability assessment.
The vendor's hardware specification sheets.
The latest version of the Common Vulnerabilities and Exposures (CVE) list.
Want more Vulnerability Scanning practice?
Practice this domainAn attacker has obtained the NTLM hash of a service account. They want to perform a Kerberoasting attack to escalate privileges. Why is this specific hash insufficient for standard Kerberoasting?
The NTLM hash is insufficient because it cannot be used to request a Ticket Granting Ticket (TGT).
The NTLM hash is only useful for Pass-the-Hash attacks and cannot facilitate any Kerberos interactions.
Kerberoasting targets the service account's password hash by requesting a TGS, not by leveraging existing NTLM hashes.
Kerberoasting relies on the KDC encrypting a service ticket with the target service account's password. The attacker requests this ticket and then attempts to brute-force the password offline. Possessing the NTLM hash of the account does not provide the encrypted TGS blob needed for this specific offline cracking methodology.
The NTLM hash must first be converted to a Kerberos AES-256 key before a TGS request can be initiated.
Which TWO of the following scenarios are most indicative of a successful Kerberoasting attack occurring within a network?
Multiple TGS-REQ packets from a single workstation targeting various SPNs within a short timeframe.
A high volume of TGS-REQ requests from a single source is a hallmark of Kerberoasting, as the attacker attempts to collect multiple tickets to maximize their chances of cracking service account passwords. This behavioral pattern is distinct from normal network activity where users typically request tickets incrementally.
A sudden spike in AS-REQ events using expired Kerberos TGTs.
The use of RC4-HMAC encryption in service ticket requests for accounts that support AES.
Attackers often force the use of RC4-HMAC (encryption type 0x17) because it is significantly faster to crack offline compared to AES-128 or AES-256. If a service account is configured for AES but receives TGS-REQ requests using RC4, it is a strong indicator of malicious intent.
Frequent failed logins followed by a successful Kerberos authentication.
An influx of TGT-REQ packets originating from non-domain controllers.
What is the primary security benefit of implementing Group Managed Service Accounts (gMSAs) in an environment vulnerable to Kerberoasting?
gMSAs prevent the KDC from issuing service tickets for the account.
gMSAs require multi-factor authentication for every TGS-REQ performed.
gMSAs use long, complex passwords that are automatically rotated by the domain controller.
The core security advantage of gMSAs is the management of long, high-entropy passwords that are rotated automatically. By removing the need for manual password management, gMSAs eliminate the risk of weak, static passwords that are easily brute-forced offline after a Kerberoasting ticket capture.
gMSAs force all Kerberos traffic to be encrypted using AES-256 only.
What is the fundamental difference between Golden Ticket and Silver Ticket attacks?
Golden Tickets require communicating with the KDC, whereas Silver Tickets do not.
Golden Tickets target the domain controller, while Silver Tickets target user workstations.
Golden Tickets grant access to any service in the domain, while Silver Tickets only grant access to one service.
Golden Tickets are forged TGTs, acting as a master key for the domain. Silver Tickets are forged TGS tickets for a specific service. By using the service account's password hash, the attacker can only successfully authenticate to the service associated with that specific account.
Silver Tickets are more powerful because they are harder to detect than Golden Tickets.
Why does the Kerberos 'PAC' (Privilege Attribute Certificate) pose a security risk in the context of ticket forgery attacks?
The PAC is always encrypted with the user's password, making it easy to crack.
The PAC allows attackers to inject arbitrary group memberships into a forged ticket.
In a forgery scenario, the attacker controls the entire ticket construction, including the PAC. By modifying the PAC data, the attacker can grant themselves administrative group memberships, effectively becoming a domain administrator as far as any service accepting the ticket is concerned, regardless of their real identity.
The PAC prevents the KDC from verifying the ticket's signature.
The PAC is required for TGT requests, making it a primary target for sniffers.
Which Kerberos feature is specifically exploited when an attacker uses 'constrained delegation' to escalate privileges?
The TGT's ability to be renewed indefinitely.
The S4U2Self and S4U2Proxy extensions.
S4U2Self allows a service to get a ticket for itself on behalf of a user, and S4U2Proxy allows the service to request a ticket to a second service on behalf of that user. These extensions are the technical foundation for constrained delegation in Active Directory.
The PAC validation performed by the Domain Controller.
The ability to use RC4 encryption for TGS requests.
Want more Kerberos Attacks practice?
Practice this domainDuring OSINT gathering, you are investigating a target's presence on social media and professional networking sites. Which TWO of the following methods are effective for gathering metadata about employees to facilitate future social engineering attacks?
Extracting EXIF data from public photos
Photos uploaded to social media or corporate blogs often contain EXIF metadata, including GPS coordinates and device hardware details. This data can reveal an employee's daily habits, office location, or preferred hardware, providing a wealth of information for planning physical access attacks or tailoring social engineering lures to the specific environment.
Performing a brute-force attack on the corporate firewall
Analyzing LinkedIn profiles for job descriptions and software stack mentions
LinkedIn profiles often list specific software used by the company, such as internal ticketing systems or CRM platforms. By reviewing these profiles, an attacker can identify the technical stack of the organization. This intelligence helps in focusing subsequent vulnerability research on the specific tools the company uses to conduct business operations.
Conducting a port scan of the internal network
Directly calling the IT helpdesk to request employee email addresses
Which of the following describes the purpose of using Google Dorks during the reconnaissance phase of a penetration test?
To bypass the target organization's firewall.
To identify publicly exposed sensitive files or directories.
Google Dorks utilize specific search operators like 'filetype:' or 'inurl:' to locate files like PDFs, spreadsheets, or configuration backups that were accidentally indexed. This helps in identifying sensitive information exposure, such as directory listings or login pages, without ever interacting directly with the target server's network infrastructure.
To execute remote code on the target's web server.
To perform a brute-force attack on user credentials.
When mapping a target's network infrastructure, why is it important to use multiple WHOIS and regional internet registry (RIR) databases?
To increase the speed of the DNS resolution process.
To bypass the need for an active port scan.
To identify all netblocks owned by the target organization.
Organizations often own IP ranges registered under different regional authorities depending on their global footprint. Using multiple WHOIS databases allows the tester to aggregate these records and build a complete picture of the organization's publicly registered network assets, which is essential for ensuring comprehensive testing of all in-scope infrastructure.
To automatically detect if a server is running an exploit.
You are analyzing the results of a passive reconnaissance scan using a tool that harvests metadata from files found on a company website. What is the primary security risk associated with this information disclosure?
The files can be used to execute arbitrary commands on the client machine.
It discloses internal network naming conventions and software versions.
Metadata often contains fields like 'creator' or 'last modified by,' which can reveal internal usernames. Furthermore, the software version used to generate the file can indicate the patching level of the workstations. This provides attackers with concrete targets for crafting specialized phishing lures or identifying vulnerable software versions used internally.
It indicates the current load on the corporate web server.
It bypasses the need for an external vulnerability assessment.
Why is it important to perform reconnaissance from a non-attributable source during a penetration test?
To improve the speed of data transfer during scans.
To avoid triggering security alerts that block the tester's IP.
Organizations often monitor for scanning activity and blacklist source IPs associated with malicious behavior. By using non-attributable sources, the tester ensures that if one source is detected and blocked, the testing engagement can continue from another, thus preventing a single block from prematurely ending the reconnaissance phase.
To bypass the need for explicit written authorization.
To increase the accuracy of vulnerability detection tools.
During the reconnaissance phase, you notice a target is using an older, unpatched version of a popular CMS. What is the most appropriate next step?
Immediately run a Metasploit exploit module against the server.
Research known CVEs for the identified version.
Researching specific CVEs for the identified CMS version allows the tester to understand the vulnerability's nature and impact. This information is crucial for planning a safe and effective exploitation strategy. It ensures that the subsequent testing phase is focused on valid attack vectors, minimizing the risk of unnecessary system downtime.
Contact the organization's IT department to report the vulnerability.
Ignore the CMS and look for other systems.
Want more Reconnaissance practice?
Practice this domainWhich TWO methods are commonly used to achieve C2 persistence while ensuring the communication remains resilient against infrastructure takedowns?
Implementing Domain Generation Algorithms (DGA).
DGA allows malware to generate a vast number of pseudo-random domain names daily. The attacker only needs to register a small subset of these to maintain connectivity. This provides massive redundancy, as defenders cannot easily block all potential future domains before they are registered by the adversary.
Hardcoding the IP address of the C2 server.
Utilizing cloud providers for domain fronting.
Domain fronting hides the true C2 destination by using a high-reputation domain hosted on the same Content Delivery Network or cloud provider as the malicious server. Traffic appears to go to a trusted site, making it highly effective at bypassing egress filters and complicating source attribution.
Using unencrypted HTTP for all C2 traffic.
Requiring manual operator interaction for beaconing.
Refer to the exhibit. What is the primary purpose of the 'jitter' parameter in this C2 configuration?
To reduce the CPU overhead on the infected host.
To synchronize beaconing across multiple infected hosts.
To prevent detection via traffic pattern analysis.
Traffic pattern analysis identifies beacons by looking for regular, periodic intervals. By adding 20% jitter to a 60-second interval, the check-in occurs between 48 and 72 seconds. This variation breaks the statistical regularity, making it much harder to distinguish from legitimate user-initiated web browsing activity.
To increase the throughput of the C2 channel.
Which term best describes the stage of a cyberattack where a compromised host signals a remote server to request instructions or transmit stolen data?
Privilege escalation
Command and control
Command and control is the industry-standard term for the maintenance of a communication channel between a compromised asset and an external adversary. This phase allows the attacker to maintain presence, send operational commands, and monitor the progress of their mission within the target environment.
Reconnaissance
Log clearing
When analyzing C2 traffic, which characteristic of a TLS/SSL certificate is most indicative of a potentially malicious beaconing endpoint?
The certificate uses a 2048-bit RSA key.
The certificate is signed by a reputable public CA.
The certificate uses a self-signed or invalid chain.
Self-signed certificates are common in rapid-deployment C2 infrastructure because they are easy to generate and cost nothing. While they trigger warnings in a browser, malware can be configured to ignore these warnings, making them a telltale sign of non-standard, likely malicious, backend communication infrastructure.
The certificate includes a valid Subject Alternative Name.
Refer to the exhibit. What does this error log suggest regarding the C2 connection attempt?
The C2 server is unreachable due to a network outage.
The client system does not trust the C2 server's certificate.
This specific TLS alert signifies that the client received a certificate it could not verify against its local root store. This is a common indicator that the C2 infrastructure is using a self-signed certificate, which the client is configured to reject due to strict security settings.
The C2 server is performing a man-in-the-middle attack.
The C2 server has exhausted its connection limit.
Which of the following is a classic characteristic of 'beaconing' behavior observed in C2 traffic?
High-volume data exfiltration during business hours.
Consistent, periodic intervals between connections.
Beaconing relies on periodic check-ins to ensure the malware maintains its connection to the C2 server. This regularity, even if jitter is present, creates a distinct statistical signature in network traffic logs, allowing security analysts to identify compromised hosts that are systematically calling out to an external C2 node.
Randomized connections to various global IP addresses.
Traffic that exclusively utilizes UDP transport.
Want more Command and Control practice?
Practice this domainDuring a penetration test, you successfully inject a payload into a web application that results in the server executing system commands with elevated privileges. Which phase of the exploitation lifecycle does this action primarily represent?
Reconnaissance
Vulnerability Assessment
Exploitation
Exploitation involves the active use of a vulnerability to gain unauthorized access or elevated privileges on a target. In this case, injecting a payload to execute system commands directly maps to this phase, as the tester is leveraging an identified flaw to manipulate the application's runtime behavior.
Post-Exploitation
When selecting an exploit for a target system, which TWO factors are most critical to ensure the exploit succeeds without crashing the target service?
The exact version of the application or OS service.
Exploits are often highly specific to binary versions. An offset that works on version 1.2 may cause a segmentation fault on 1.3 due to recompiled libraries or different memory layouts. Matching the exact build ensures that memory addresses used in the payload are valid for the target.
The color scheme of the target's command shell.
The target system's CPU architecture (e.g., x86 vs x64).
CPU architecture dictates the instruction set, register sizes, and stack frame conventions. An exploit compiled for x86 will fail to execute correctly on x64 due to incompatible register names and memory addressing modes. Aligning the exploit architecture with the target is mandatory to ensure valid machine instructions.
The network bandwidth available to the target.
The number of users currently logged in.
Refer to the exhibit. Which step should a tester prioritize next based on the server header information?
Run a brute-force password attack against the server.
Search for known vulnerabilities for Apache 2.4.41.
Identifying the service and version is a prerequisite for vulnerability research. By mapping this version to known security advisories or CVE databases, a tester can determine if public exploits exist for this specific configuration, effectively narrowing the attack surface to the most likely points of failure.
Immediately deploy a rootkit on the server.
Close the connection and report the server as secure.
Why is it important to use 'staged' payloads during a penetration test when the target has limited memory or strict filtering?
To bypass the system's firewall rules permanently.
To fit within small buffer constraints during initial exploitation.
Many vulnerabilities, such as stack-based buffer overflows, have limited space for shellcode. A staged payload uses a small 'stager' to initiate the connection and pull down the 'stage' (the full payload), allowing the exploit to succeed even when the available memory for shellcode injection is very small.
To automatically upgrade the shell to root privileges.
To increase the target's CPU usage for testing stability.
Which of the following describes the purpose of 'encoding' shellcode in an exploitation context?
To increase the execution speed of the exploit.
To bypass character-based filters and detection systems.
Security systems often scan for known shellcode patterns or restricted characters like null bytes (0x00). Encoding the payload allows it to pass through these filters by obfuscating the malicious bytes into a benign-looking format, which is later decoded by a small stub upon reaching memory.
To encrypt the traffic for legal compliance.
To permanently store the payload on the target's disk.
Refer to the exhibit. What does this output indicate regarding the current exploitation attempt?
The application is secure from buffer overflow attacks.
The tester has successfully redirected execution flow.
The instruction pointer is pointing to the attacker-controlled buffer ('AAAA'). This confirms the tester has successfully hijacked the program counter, a prerequisite for code execution. The next phase involves crafting the payload to point this address to the shellcode instead of junk data.
The system is protected by DEP/NX.
The payload is too large for the allocated buffer.
Want more Exploitation Fundamentals practice?
Practice this domainDuring an assessment, you discover a federated identity setup using AD FS. What is a common security risk associated with the reliance on the token-signing certificate in this architecture?
The certificate is public knowledge and can be used to decrypt all cloud traffic.
Compromise of the private signing key allows for the creation of unauthorized authentication tokens.
If the private key is exposed, an attacker can sign fraudulent SAML assertions. These assertions are trusted by Microsoft Entra ID as valid identity claims, effectively allowing the attacker to sign in as any user without needing their password or passing the actual identity provider's authentication checks.
AD FS requires the certificate to be stored in an unsecured plaintext file on the web server.
The relying party cannot verify the identity if the certificate expires.
When analyzing a hybrid identity environment, you notice the use of 'Seamless Single Sign-On'. What is the potential impact if the 'AZUREADSSOACC' computer object in the on-premises Active Directory is compromised?
The attacker can directly modify the Microsoft Entra ID tenant settings.
The attacker can generate valid Kerberos tickets to facilitate cloud authentication.
Seamless SSO works by providing a Kerberos ticket that Microsoft Entra ID trusts. If the computer object is controlled by an attacker, they can abuse its service key to request and forge tickets for any user account synchronized in the directory, allowing for seamless, unauthorized cloud authentication.
The attacker can permanently disable synchronization between on-premises and cloud.
All password hash synchronization processes will immediately cease.
Which of the following describes the risk of 'Guest User' accounts in an Microsoft Entra ID integration scenario?
Guest users are automatically granted Global Administrator privileges.
Guest accounts can only be created by the Global Administrator.
Guest users can potentially enumerate directory objects unless restricted.
By default, guest users can read directory information, including the list of users, groups, and applications. Restricting these permissions via the 'External Collaboration Settings' in Microsoft Entra ID is a mandatory hardening step to ensure that external entities cannot perform reconnaissance on the internal directory structure.
Guest users are exempt from Conditional Access policies.
Which THREE of the following are valid methods to mitigate the risk of password spray attacks in an integrated Microsoft Entra ID environment?
Enforce Multi-Factor Authentication for all users.
MFA is the most effective control against password spraying. Even if an attacker guesses the password, the secondary factor prevents them from gaining access. It neutralizes the utility of the guessed credential, forcing the attacker to find another way to circumvent the authentication process entirely.
Disable all legacy authentication protocols.
Legacy protocols such as POP3, IMAP, and SMTP often do not support modern MFA. Attackers use these protocols to bypass Conditional Access policies entirely. Disabling legacy auth forces all authentication attempts through modern auth flows, where MFA and other conditional controls are enforced and effective.
Implement Identity Protection to detect and block risky sign-ins.
Microsoft Entra ID Protection uses machine learning to identify sign-in risks, such as impossible travel or known malicious IP addresses. By integrating this with Conditional Access, the system can automatically block sign-ins from suspicious sources, effectively stopping spray attacks that originate from common botnet infrastructure.
Increase the minimum password length to 50 characters.
Require all users to use the same password for both on-premises and cloud.
Why is 'Password Writeback' considered a significant security risk in hybrid identity integrations?
It stores plaintext passwords on the Microsoft Entra Connect server.
It allows cloud-based compromise to escalate into the on-premises domain.
By allowing the cloud to set on-premises passwords, the trust boundary is reversed. An attacker who compromises a high-privileged account in Microsoft Entra ID can use the writeback feature to reset passwords for Domain Admins or other sensitive accounts, granting them full control over the on-premises infrastructure.
It requires the on-premises firewall to allow inbound connections from the internet.
It automatically disables the on-premises password policy.
During an assessment, you find that 'Device Writeback' is enabled. What is the security concern regarding the registration of these devices in Microsoft Entra ID?
It allows the cloud to push malware to on-premises devices.
It allows untrusted devices to satisfy Conditional Access requirements.
Devices synced to Microsoft Entra ID are marked as 'known' or 'compliant' depending on the policy. If an attacker joins a rogue device to the on-premises domain, it gets synced to the cloud. This device may then be treated as trusted, bypassing security controls that require a 'compliant' or 'managed' device.
It automatically grants the devices administrative access to the cloud tenant.
It requires all devices to be hardware-encrypted with TPM 2.0.
Want more Azure AD Integration practice?
Practice this domainDuring a post-exploitation phase, you identify an unquoted service path vulnerability on a Windows target. What is the most reliable way to escalate privileges through this misconfiguration?
Overwrite the existing service executable with a custom payload.
Modify the service configuration using the sc config command.
Place a malicious binary at the first detected space-delimited path segment.
Windows attempts to execute the path segment before the space if no quotes are present. By placing a malicious executable at that specific location with the appropriate name, the service manager will execute your file instead of the intended one, running your code with the service's high-privilege context.
Inject a DLL into the running service process memory space.
Which TWO of the following methods are commonly used by attackers to achieve persistence on a Linux system via cron jobs?
Creating a new file in /etc/cron.d/ with an execution trigger.
Files placed in /etc/cron.d/ are automatically parsed by the cron daemon. This is a common method for attackers to inject persistent tasks because it does not require modifying existing crontab entries, making it slightly more stealthy and easier to manage during the post-exploitation phase of an engagement.
Modifying the /etc/shadow file to grant root access.
Adding an entry to the crontab of a high-privilege service account.
Scheduling tasks within the crontab of accounts like root or service users allows the attacker to execute their code with the privileges of that specific user. This is a highly effective way to maintain persistence and potentially perform automated lateral movement or data exfiltration tasks.
Replacing the bash shell binary with a malicious version.
Setting a boot-time delay in the global /etc/environment file.
When attempting to escalate privileges on a Linux system, what is the significance of the SUID bit on a file owned by root?
It forces the file to run within a restricted sandbox environment.
It permits the file to execute with the owner's privileges.
When the SUID bit is set, the process runs as the owner of the file. If that owner is root, the process runs with root privileges. This behavior is intentional for specific system binaries, but it creates a vulnerability if the binary can be abused to perform unintended actions.
It enables the file to be readable by all users on the system.
It automatically encrypts the file contents at rest.
Which technique is most effective for maintaining persistence on a Windows domain-joined machine while remaining stealthy by avoiding common registry keys?
Adding a startup shortcut to the All Users Startup folder.
Creating a WMI event subscription for system events.
WMI event subscriptions allow attackers to execute code when specific system conditions are met. Because these subscriptions are stored in the WMI repository rather than standard registry keys, they evade basic persistence checks, making them a highly effective and stealthy method for maintaining long-term access to a Windows system.
Modifying the existing service binary to include a backdoor.
Running a scheduled task with a visible command prompt window.
Refer to the exhibit. Given this output, which action is most appropriate for a penetration tester?
Attempt to restart the system to reset privileges.
Use the privilege to dump process memory, such as LSASS.
SeDebugPrivilege allows a user to debug any process. By attaching to the Local Security Authority Subsystem Service (LSASS), you can dump the memory to extract clear-text passwords or NTLM hashes, which are essential for escalating privileges within the local system and moving laterally across the Windows domain environment.
Disable the privilege to ensure system stability.
Install a rootkit to hide the enabled privilege.
Which THREE of the following are valid techniques for privilege escalation on a Linux system?
Exploiting a binary with the SUID bit set to root.
SUID binaries owned by root execute with root privileges. If the binary is vulnerable to buffer overflows or path injection, an attacker can hijack the execution flow to launch a root shell. This is a classic and highly effective privilege escalation path on many legacy Linux systems.
Configuring a new user account with no password.
Abusing sudo permissions that allow specific command execution as root.
If a user has sudo access to specific binaries like 'find', 'vim', or 'less', they can often escape these applications to drop into a root shell. This is a common misconfiguration where administrators grant broad 'sudo' access to specific tools without considering the potential for shell escaping.
Exploiting kernel vulnerabilities to gain root-mode execution.
Kernel vulnerabilities often allow for local privilege escalation by permitting arbitrary code execution within the kernel context. Once kernel code execution is achieved, an attacker can easily overwrite the credentials structure of the current process to change the effective user ID to zero, representing the root user.
Renaming the /etc/passwd file to /etc/shadow.
Want more Domain Escalation and Persistence practice?
Practice this domainAn attacker is performing reconnaissance on an Microsoft Entra ID tenant and notices that 'Guest' users can enumerate the directory. Which specific setting should be checked to remediate this?
External collaboration settings for Guest user access restrictions.
This setting in the Microsoft Entra ID 'External Identities' configuration explicitly controls the visibility of guest users. By setting this to 'Limited access', guests can only see their own profile, which prevents them from enumerating other users, groups, or sensitive directory information.
Conditional Access policy for guest users.
The 'Enable Global Reader' role for guests.
The 'AppRoleAssignmentRequired' property of the tenant.
When conducting a penetration test on an Azure App Service, you discover an 'environment.js' file in the public directory containing a 'CLIENT_ID'. What is the risk associated with this finding?
The attacker can use the Client ID to authenticate as the application.
The attacker can use the Client ID to construct a tailored consent-phishing URL.
The Client ID is a required parameter for the OAuth2 authorization URL. By knowing the ID, an attacker can build a custom URL that directs users to the Microsoft identity platform to grant permissions to the application, making the phishing attempt look more legitimate to the target user.
The attacker can use the Client ID to reset the application's password.
The attacker can use the Client ID to bypass MFA for the application.
Which of the following describes the risk of 'App Role' over-assignment in Microsoft Entra ID?
It increases the likelihood of a brute-force attack on the tenant.
It allows an attacker to escalate privileges if a user account is compromised.
If a user is assigned an administrative app role, any attacker who compromises that user's account gains those high-level permissions within the application. This makes over-assignment a direct path to privilege escalation, allowing attackers to access features or data that the average user should never touch.
It automatically bypasses the need for Multi-Factor Authentication.
It prevents the application from using external OAuth2 scopes.
During an Azure penetration test, you discover an App Registration with an expired client secret that still has active refresh tokens issued prior to expiration. The application holds high-privilege directory roles. How do these leaked refresh tokens behave regarding Microsoft Entra ID security boundaries?
The refresh tokens are instantly invalidated the moment the underlying client secret expires or is rotated in the Azure portal.
The refresh tokens continue to function and can be exchanged for new access tokens until the refresh token's own lifetime expires or it is explicitly revoked.
Microsoft Entra ID architecture decouples token lifespans from credential lifespans once the session is established. A valid refresh token permits continuous generation of short-lived access tokens, enabling persistence even if the administrator deletes or rotates the original application secret.
The refresh tokens automatically convert into guest user sessions with restricted privileges to mitigate potential compromise of internal directory roles.
The refresh tokens fail immediately because Microsoft Entra ID enforces continuous access evaluation for all service principal API interactions.
Refer to the exhibit. During an Azure engagement, you query a service principal via the Microsoft Graph API and notice that 'appRoleAssignmentRequired' is set to 'false'. What security implication does this setting present for enterprise applications?
Only users explicitly assigned via Microsoft Entra ID Enterprise Applications can authenticate and access the application.
Any user in the Microsoft Entra ID tenant can authenticate to the application and obtain access tokens without prior assignment.
Setting this property to false bypasses the user assignment requirement entirely. This default setting means every member of the directory is authorized to log in, which can be dangerous if the application contains sensitive internal functionality.
The application is prohibited from utilizing OAuth 2.0 authorization code flows and must rely exclusively on client credentials.
Global administrators must manually approve every single sign-in attempt generated by standard users in the tenant.
During an Azure penetration test, you gain access to a Linux VM in a subnet that has a user-defined route forcing all traffic through a Network Virtual Appliance (NVA). You want to reach the Azure Instance Metadata Service (IMDS) to steal managed identity tokens. Which of the following best describes how you can access IMDS from this VM?
IMDS is reachable at 168.63.129.16, but the user-defined route will block access, requiring you to disable the route first.
IMDS is reachable at 169.254.169.254, and the user-defined route does not affect this link-local address, so you can query it directly from the VM.
This is correct because IMDS uses the link-local address 169.254.169.254, which is handled by the Azure platform and bypasses user-defined routes and NVAs. From the compromised VM, you can directly query IMDS to obtain managed identity tokens without any network appliance interfering, making it a reliable credential theft vector.
IMDS is reachable at 169.254.169.254, but the user-defined route will redirect the request to the NVA, so you must use a proxy to reach it.
IMDS is reachable only from within the Azure portal, so you must use the Azure CLI from your attacker workstation to query it.
Want more Azure Apps and Attacks practice?
Practice this domainYou have gained standard user execution rights on a hardened Windows 10 enterprise workstation and need to enumerate local privilege escalation vectors. Which TWO methods are most effective for identifying insecure file permissions or unquoted service paths? (Choose two)
Executing AccessChk from the Sysinternals suite to review discretionary access control lists on service executables.
AccessChk allows efficient command-line auditing of DACLs on files, directories, and services. Identifying weak permissions where standard users hold write or modify rights on service binaries enables successful replacement of legitimate executables with malicious payloads.
Querying the root certificate store via PowerShell to check for untrusted root certification authorities.
Using Windows Management Instrumentation to query the Win32_Service class for executable paths containing spaces without quotes.
Unquoted service paths with spaces cause Windows to search for executable components sequentially from the root directory if quotes are missing. If an attacker places a malicious executable earlier in the search path, the service will execute it with high privileges upon reboot.
Inspecting the local security policy database using the auditpol utility to check account lockout thresholds.
Reviewing the Active Directory group policy object inheritance tree using the Resultant Set of Policy tool.
You have identified an SUID binary on a Linux system that executes a shell command without using an absolute path. What is the most effective way to exploit this for privilege escalation?
Overflow the buffer of the binary.
Modify the PATH variable to point to a malicious directory.
By prepending a user-controlled directory to the PATH variable, the system searches the attacker's directory first. If the binary calls 'date' and the attacker has placed a malicious file named 'date' in their directory, the system executes the malicious file with the privileges of the SUID binary.
Use LD_PRELOAD to inject a shared object.
Inject arguments into the binary.
During a penetration test, you successfully exploit a web application via SQL injection. You want to use this access to achieve remote code execution (RCE) on the underlying Windows database server. Which feature should you look for to facilitate this?
Database backup functionality
Stored procedure execution via xp_cmdshell
xp_cmdshell is a powerful stored procedure in Microsoft SQL Server that spawns a Windows command shell and passes in a command string for execution. It is the primary target for testers attempting to escalate from SQL injection to remote code execution on the underlying database server host.
Database triggers on update
Database user enumeration
Which of the following is a primary goal during the 'Exploitation' phase of a penetration test?
To document all vulnerabilities found.
To gain unauthorized access or influence target systems.
The core objective of exploitation is to turn a vulnerability into an active exploit, gaining unauthorized access or executing code. This validates the risk assessment and demonstrates the impact of the identified security flaws in a controlled, safe manner that is consistent with the test's scope.
To scan the entire network for open ports.
To patch the vulnerabilities identified.
You are performing a penetration test and discover a service running as SYSTEM that is vulnerable to DLL hijacking. What is the most appropriate action to take to ensure the test is successful and safe?
Immediately drop a reverse shell.
Use a benign DLL to prove execution.
Using a benign DLL that launches a non-critical application or writes to a log file is the safest way to demonstrate the vulnerability. It proves code execution with SYSTEM privileges without causing service instability or creating a persistent backdoor that could be misused if detected by third parties.
Reboot the server to force the service to restart.
Modify the Windows Registry to disable the service.
When escalating privileges using a Kernel exploit, why is it considered a high-risk activity for a penetration test?
It requires the user to have administrative credentials.
It frequently causes system instability and crashes.
Kernel exploits manipulate memory structures at a very low level. Small errors in memory alignment or incorrect assumptions about the OS state lead to immediate kernel panics or crashes. This downtime is a major business impact, making kernel exploits the highest-risk category of penetration testing activities.
It is easily detected by standard antivirus software.
It can only be executed on outdated operating systems.
Want more Escalation and Exploitation practice?
Practice this domainA penetration tester is performing an offline attack against a Windows domain. They have obtained the NTDS.dit file and the SYSTEM hive. Which tool is most effective for extracting the NTLM hashes for offline cracking?
Hashcat
Mimikatz
secretsdump.py
Secretsdump.py is the definitive tool within the Impacket suite for performing local or remote secret extraction. By providing the NTDS.dit and SYSTEM hive files, it decrypts the database, allowing the tester to retrieve NTLM hashes for every user in the domain, which is essential for subsequent offline cracking attempts.
John the Ripper
Which attack targets service accounts by requesting a service ticket (TGS) from the domain controller and cracking the ticket offline?
Pass-the-Ticket
AS-REP Roasting
Kerberoasting
Kerberoasting is specifically defined as the process of requesting a service ticket for a service account and cracking the resulting TGS-REP hash offline. Since the ticket is encrypted with the service account's password hash, offline cracking reveals the service account password, often leading to significant privilege escalation.
Golden Ticket Attack
Which file in a Windows system is required, along with the NTDS.dit file, to decrypt cached credentials stored in the database?
SAM hive
SOFTWARE hive
SYSTEM hive
The SYSTEM hive contains the Boot Key (also known as the Syskey). This key is used to encrypt the database of Active Directory, NTDS.dit. Without this specific key, the hashes within the NTDS.dit file remain unreadable, making it impossible to perform any meaningful offline analysis of domain credentials.
SECURITY hive
Which of the following is a primary advantage of using a 'Golden Ticket' attack over other credential-based attacks?
It does not require administrative privileges to execute.
It provides persistent access even after the user changes their password.
Because the Golden Ticket is a forged TGT, it is independent of individual user accounts or passwords. Even if an administrator changes their password or resets their account, the attacker can continue to use the forged ticket to access resources until the KRBTGT password itself is reset.
It is easily detectable by standard antivirus software.
It is limited to a single service on the network.
In the context of password attacks, what is the primary purpose of a 'mask' in Hashcat?
To hide the password hash from security logs.
To define the structure and character sets to be tested.
A mask allows the tester to specify custom patterns, such as 'uppercase, lowercase, digit, symbol'. By defining these character sets and their positions, the tester restricts the search space to likely password structures, which dramatically increases the speed and efficiency of the cracking process compared to random guessing.
To decrypt hashes using a known public key.
To automatically rotate the password in the target account.
Which THREE conditions must be met for a successful AS-REP Roasting attack?
The account must have the 'Do not require Kerberos pre-authentication' flag set.
This is the core requirement for the attack. Normally, Kerberos requires pre-authentication to prevent offline cracking. If this flag is enabled, the KDC will provide the encrypted data without requiring the user to prove they know their password, allowing the attacker to capture the data for offline cracking.
The attacker must have Domain Admin credentials.
The attacker must have a valid username in the domain.
To request an AS-REP from the KDC, the attacker needs a valid username. While the account being roasted does not need high privileges, the attacker must be able to authenticate to the domain controller to initiate the request, making an initial valid account a prerequisite for the entire process.
The service account must have AES-256 encryption enabled.
The attacker must be able to communicate with the domain's KDC.
Direct network access to the Domain Controller (acting as the Key Distribution Center) is mandatory. Without this connectivity, the attacker cannot send the required request or receive the AS-REP response containing the encrypted data. Therefore, being within the internal network or having a proxy is a fundamental requirement.
Want more Advanced Password Attacks practice?
Practice this domainAn enterprise client insists on a blind 'black-box' penetration test where the testing team receives zero prior knowledge regarding network architecture, IP ranges, or applications. However, the client's primary objective is to thoroughly test deep-seated business logic vulnerabilities within a critical custom web application. Why is this planning approach fundamentally misaligned with the client's stated objective?
Black-box testing is legally prohibited under international cybersecurity standards for any application handling financial data.
Zero-knowledge assessments automatically violate standard industry rules of engagement by preventing the execution of automated scanners.
Discovery phases consume disproportionate time, leaving insufficient hours for the deep manual analysis required to uncover logic flaws.
Black-box testing prioritizes reconnaissance and asset discovery, severely restricting the time available for deep manual code or logic reviews. Gray or white-box scoping is necessary to bypass discovery overhead and focus directly on application logic.
Client stakeholders cannot legally authorize a penetration test without providing a complete network diagram and asset inventory.
During the scoping phase of a penetration test for a global e-commerce client, you identify that the client uses a cloud-based Content Delivery Network (CDN) to host static assets. Which action is the most critical for ensuring the engagement remains within the Rules of Engagement (RoE)?
Perform a SYN scan against the CDN IP ranges to identify open ports.
Incorporate the CDN provider's IP space into the primary target scope.
Verify if the client has explicit written permission from the CDN provider.
Verifying written permission is necessary because CDNs are external service providers. Testing them without authorization is a violation of the Rules of Engagement. Obtaining documented consent ensures that the testing activity is permitted under the provider's acceptable use policy, mitigating legal risks for both the tester and the client.
Bypass the CDN by mapping the origin server's IP address directly.
You are drafting the Rules of Engagement for an internal penetration test. Which TWO of the following items are considered mandatory for the 'Communication Plan' section?
A list of all vulnerabilities found during the previous year's audit.
The names and 24/7 contact information for designated incident response leads.
Providing 24/7 contact information for incident responders is mandatory to ensure that any potential service disruptions or critical system issues identified during the test can be addressed immediately. This prevents prolonged downtime and ensures that the client's internal security team can respond appropriately to testing activities.
The frequency and format of status updates throughout the engagement.
Establishing clear expectations for the frequency and format of status updates is vital for maintaining transparency. This ensures that the client is consistently informed about the testing progress, identifies any urgent findings early, and allows for adjustments to the testing approach based on the ongoing findings.
The specific exploit payloads that will be used during the test.
The estimated total cost of the project and payment schedule.
Refer to the exhibit. You are performing a penetration test based on this policy. You discover an unpatched SQL injection vulnerability on 192.168.10.20 that could be used to trigger a database lock-up. What is the most appropriate course of action?
Execute the SQL injection to prove the vulnerability exists.
Document the vulnerability and the risk of DoS without exploitation.
Reporting the vulnerability without exploiting it respects the 'Forbidden_Attacks' constraint. This allows the client to understand the risk and patch the issue without suffering the downtime associated with a successful exploitation. It demonstrates professional judgment by balancing the need for security assessment with operational constraints.
Attempt the exploit on the excluded host 192.168.10.50 to see if it is vulnerable.
Extend the testing window to allow for a safer, non-disruptive exploit.
Which document is primarily responsible for defining the 'Rules of Engagement' (RoE) in a penetration testing project?
The Statement of Work (SOW).
The Rules of Engagement (RoE) document.
The RoE document is specifically created to define the operational parameters of the assessment. It details the scope, prohibited actions, communication protocols, and escalation procedures, providing the technical team with a clear set of guidelines to follow while performing the assessment to ensure safety and compliance.
The Non-Disclosure Agreement (NDA).
The Service Level Agreement (SLA).
During planning, a client requests that you use a specific automated scanner that is known to produce false positives and potential system instability. What is the most professional way to handle this request?
Agree to use the tool but run it only during off-peak hours.
Refuse the request and insist on using your own proprietary toolset.
Document the risks, communicate them to the client, and propose a validated alternative.
Documenting the risks associated with the tool and proposing a safer alternative demonstrates professional competence. It protects the client from unnecessary downtime while ensuring the assessment quality remains high. This approach fulfills the ethical responsibility to provide the best service while minimizing potential harm to the client's environment.
Use the requested tool but ignore the potential instability issues.
Want more Pen Test Planning practice?
Practice this domainThe GPEN exam has 60–90 questions and must be completed in 120 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 15 domains: Attacking Password Hashes, Password Attacks and Formats, Scanning and Host Discovery, Metasploit, Vulnerability Scanning, Kerberos Attacks, Reconnaissance, Command and Control, Exploitation Fundamentals, Azure AD Integration, Domain Escalation and Persistence, Azure Apps and Attacks, Escalation and Exploitation, Advanced Password Attacks, Pen Test Planning. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official GIAC GPEN exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.