Reinforce GPEN concepts with active-recall study cards covering all 15 blueprint domains. Each card shows the question on the front and the correct answer with a full explanation on the back.
Flashcards work through active recall — the process of retrieving information from memory rather than passively re-reading it. Research consistently shows that active recall produces stronger, longer-lasting memory than re-reading study guides. For GPEN preparation, this means flashcards are one of the highest-return study tools available.
Attempt recall first
Read the GPEN question on each card, pause, and attempt to formulate the answer in your own words before revealing. This retrieval attempt — even if wrong — dramatically strengthens memory compared to immediately reading the answer.
Review wrong cards again
When you get a card wrong, note it and add it back to your review pile. Spaced repetition — seeing difficult cards more frequently — is the mechanism that makes flashcard study far more efficient than linear reading.
Study by domain
Group your GPEN flashcard sessions by domain for the first 3–4 weeks. Master one domain before moving to the next. In the final week, shuffle all cards together to test cross-domain recall — which is what the real GPEN exam requires.
Short sessions beat marathon reviews
20–30 flashcard cards per session, done daily, produces better retention than a single 200-card marathon session. Five short daily sessions per week over 4 weeks gives you over 400 total card reviews — enough to reliably pass GPEN.
Sample cards from the GPEN flashcard bank. Read the question, think of the answer, then read the explanation below.
When conducting a penetration test, why is it critical to assess the hashing algorithm used for storing passwords rather than focusing solely on the password policy itself?
Weak algorithms allow rapid recovery of passwords once a breach occurs.
Even with a strong password policy, an organization remains vulnerable if the hashing algorithm is cryptographically broken or lacks proper salting. A weak algorithm like MD5 or NTLM allows attackers to crack even complex passwords almost instantaneously using modern hardware. Evaluating the hashing implementation ensures that the organization is protected against offline attacks, providing a necessary layer of defense that policies alone cannot guarantee if the underlying data storage mechanism is compromised.
You are performing an offline attack against a password hash stored in an NTDS.dit file. You have successfully dumped the hashes using secretsdump.py. Given the format 'Username:RID:LMHash:NTHash:::', which hash should be targeted for a modern Windows environment to maximize cracking efficiency?
The NTHash, because it is the primary hash used by NTLM authentication.
Modern Windows systems prioritize NTLM authentication, which relies on the NTHash. The LM hash is deprecated, weak, and often stored as a null value or a fixed constant in modern systems. Targeting the NTHash allows for pass-the-hash attacks or brute-force attempts that align with the underlying authentication protocol. Understanding the structure of these hashes is crucial for penetration testers to select the correct dictionary or mask attack strategies during local account auditing.
You are performing a network audit and need to identify live hosts across a segmented network while minimizing the risk of triggering IDS alerts. Which Nmap technique is most appropriate for stealthy host discovery in a subnet where ICMP echo requests are filtered by the firewall?
Utilize TCP SYN ping (-PS) on common service ports.
Nmap's TCP SYN ping (-PS) is highly effective because it sends a small SYN packet to specified ports, like 80 or 443, which are typically open or acknowledged by firewalls. This bypasses ICMP filters while mimicking legitimate traffic. Understanding how to circumvent basic perimeter defenses is critical for penetration testers to ensure comprehensive discovery without alerting security systems that monitor for common ICMP-based scanning patterns or heavy traffic floods.
Which command in the Metasploit Framework allows a user to interact with a backgrounded session after a successful exploit execution?
sessions -i
The 'sessions' command is the primary method for managing active connections within Metasploit. Once an exploit establishes a payload, the session moves to the background. Using 'sessions -i <id>' connects the user to the specific meterpreter shell, enabling post-exploitation activities. This is crucial for maintaining persistence and executing lateral movement tasks in a penetration test, as it allows the operator to toggle between multiple compromised targets effectively.
A penetration tester is configuring an authenticated scan for a Windows environment. Which credential management strategy best minimizes the security impact while maintaining scan efficacy?
Create a dedicated service account with granular WMI and remote registry permissions.
Using dedicated, low-privilege service accounts with specific WMI and registry permissions minimizes the blast radius if credentials are intercepted. This approach adheres to the principle of least privilege, preventing the scanner from having full domain administrator access, which could be abused if the scanning server is compromised. Effective vulnerability management relies on deep system visibility without granting excessive authority to the scanning service.
An attacker has obtained the NTLM hash of a service account. They want to perform a Kerberoasting attack to escalate privileges. Why is this specific hash insufficient for standard Kerberoasting?
Kerberoasting targets the service account's password hash by requesting a TGS, not by leveraging existing NTLM hashes.
Kerberoasting requires requesting a Service Ticket (TGS) from the Key Distribution Center (KDC) for a specific Service Principal Name (SPN). The attacker then extracts the encrypted TGS blob from memory or network traffic to crack the service account's password offline. The NTLM hash is a separate credential format; having it allows for Pass-the-Hash or silver ticket creation, but does not involve the KDC-based SPN request process required for Kerberoasting.
Which of the following describes the purpose of using Google Dorks during the reconnaissance phase of a penetration test?
To identify publicly exposed sensitive files or directories.
Google Dorks are advanced search operators that allow testers to find sensitive information inadvertently indexed by search engines. This is a powerful form of passive reconnaissance that requires no interaction with the target infrastructure. By finding publicly exposed configuration files, logs, or login portals, testers can gain valuable intelligence. Mastering these operators is a fundamental skill for finding 'low hanging fruit' that often gets overlooked by automated scanning tools.
Which TWO methods are commonly used to achieve C2 persistence while ensuring the communication remains resilient against infrastructure takedowns?
Implementing Domain Generation Algorithms (DGA). / Utilizing cloud providers for domain fronting.
Resilient C2 infrastructure often relies on decentralized or dynamic components to ensure that the connection remains viable even if individual nodes are identified and blocked. By utilizing domain generation algorithms and cloud-based relay services, attackers create a moving target that is difficult for incident responders to fully dismantle in a timely manner. Mastery of these techniques is essential for assessing the robust nature of an organization's defense-in-depth posture.
During a penetration test, you successfully inject a payload into a web application that results in the server executing system commands with elevated privileges. Which phase of the exploitation lifecycle does this action primarily represent?
Exploitation
This scenario demonstrates the execution of arbitrary code, which is the core of the exploitation phase. Exploitation is the process of leveraging a vulnerability to gain unauthorized access or control over a target system. Understanding this transition from vulnerability discovery to exploitation is critical for testers to effectively assess the impact of security flaws and demonstrate real-world risk to stakeholders during the assessment reporting phase.
During an assessment, you discover a federated identity setup using AD FS. What is a common security risk associated with the reliance on the token-signing certificate in this architecture?
Compromise of the private signing key allows for the creation of unauthorized authentication tokens.
The token-signing certificate is the foundation of trust in a federated environment. If an attacker compromises the private key of this certificate, they can forge SAML tokens for any user in the directory. This bypasses Multi-Factor Authentication and allows for complete identity impersonation, making the protection of the AD FS server and its associated secrets a critical objective for both defenders and attackers.
During a post-exploitation phase, you identify an unquoted service path vulnerability on a Windows target. What is the most reliable way to escalate privileges through this misconfiguration?
Place a malicious binary at the first detected space-delimited path segment.
Unquoted service paths exist when the service binary path contains spaces and lacks quotes. Windows interprets the path incorrectly, searching for intermediate executables. Placing a malicious binary at the identified path allows it to execute with SYSTEM privileges upon service restart. This technique is critical for privilege escalation as it exploits inherent Windows path resolution logic, often bypassing standard user restrictions if the directory has weak permissions.
An attacker is performing reconnaissance on an Microsoft Entra ID tenant and notices that 'Guest' users can enumerate the directory. Which specific setting should be checked to remediate this?
External collaboration settings for Guest user access restrictions.
By default, Microsoft Entra ID allows guest users to see other users and groups in the directory. This is a common reconnaissance vector for attackers to map the organization's structure. Restricting this access is a critical step in hardening the tenant, ensuring that guest identities have limited visibility into the internal organizational structure during an initial compromise.
You have identified an SUID binary on a Linux system that executes a shell command without using an absolute path. What is the most effective way to exploit this for privilege escalation?
Modify the PATH variable to point to a malicious directory.
When a binary calls a command without an absolute path, it relies on the PATH environment variable to locate the executable. By modifying the PATH to include a directory under the attacker's control, the attacker can place a malicious executable with the same name as the target command. This forces the SUID binary to execute the malicious file instead of the intended system utility, resulting in command execution as the owner.
A penetration tester is performing an offline attack against a Windows domain. They have obtained the NTDS.dit file and the SYSTEM hive. Which tool is most effective for extracting the NTLM hashes for offline cracking?
secretsdump.py
Impacket's secretsdump.py is the industry standard for parsing NTDS.dit files and SYSTEM hives to extract domain credentials. It leverages the boot key stored in the SYSTEM hive to decrypt the encrypted hashes within the NTDS.dit database. Understanding this process is critical for penetration testers because it represents the most common method of achieving domain-wide compromise after gaining the necessary domain controller files.
An enterprise client insists on a blind 'black-box' penetration test where the testing team receives zero prior knowledge regarding network architecture, IP ranges, or applications. However, the client's primary objective is to thoroughly test deep-seated business logic vulnerabilities within a critical custom web application. Why is this planning approach fundamentally misaligned with the client's stated objective?
Discovery phases consume disproportionate time, leaving insufficient hours for the deep manual analysis required to uncover logic flaws.
Black-box testing forces testers to spend the majority of the engagement on reconnaissance and basic discovery rather than deep vulnerability analysis. To effectively evaluate complex business logic flaws, testers require white-box or gray-box scoping with documentation and credentials to achieve adequate depth within standard assessment timeframes.
The GPEN flashcard bank covers all 15 official blueprint domains published by GIAC. Cards are distributed proportionally, so domains with higher exam weight have more cards.
Domain Coverage
Attacking Password Hashes
Password Attacks and Formats
Scanning and Host Discovery
Metasploit
Vulnerability Scanning
Kerberos Attacks
Reconnaissance
Command and Control
Exploitation Fundamentals
Azure AD Integration
Domain Escalation and Persistence
Azure Apps and Attacks
Escalation and Exploitation
Advanced Password Attacks
Pen Test Planning
Both flashcards and practice questions are evidence-based study tools. The difference is in what they train:
Flashcards — concept retention
Best for memorising definitions, acronyms, protocol behaviours, command syntax, and conceptual distinctions. Use flashcards to build the foundational vocabulary that GPEN questions assume you know.
Best in: weeks 1–3
Practice tests — application
Best for applying concepts to realistic scenarios, eliminating distractors, and building exam stamina.GPEN questions test scenario reasoning — not just recall — so practice tests are essential.
Best in: weeks 3–6
The most effective GPEN study plan combines both: use flashcards for the first 2–3 weeks to build conceptual foundations, then shift to practice tests and mock exams in the final 2–3 weeks to apply and benchmark that knowledge. Most candidates who pass on their first attempt use both tools.
Yes. Courseiva provides free GPEN flashcards across all official exam domains. Every card includes the correct answer and a full explanation of why it is right and why the distractors are wrong. The platform also includes topic-based practice, mock exams, and readiness tracking — no account required.
Courseiva has 298+ original GPEN flashcards across all 15 exam blueprint domains. New cards are added regularly as the question bank grows. All cards are checked against the official GIAC exam objectives, with editorial oversight from an experienced network and security engineer.
Courseiva flashcards are purpose-built for IT certification exams. Unlike generic flashcard platforms where content quality varies, every Courseiva card is mapped to the official GPEN exam blueprint, written by engineers who hold the certification, and includes a full explanation of the correct answer and why the distractors are wrong. This explanation quality is what separates genuine learning from rote memorisation.
Courseiva is a web platform — an internet connection is required. For offline study, we recommend creating free Courseiva account, using the platform in your browser, and using your device's offline capabilities if your browser supports offline web apps.
Save your results, see which domains need more work, and get spaced repetition recommendations — all free.
Sign Up FreeFree forever · Every certification included