Simulate the real GIAC Penetration Tester exam with full-length timed sessions. Questions drawn proportionally from all 15 official blueprint domains — the same mix you'll face on test day.
Simulate real exam conditions
For the most realistic GPEN simulation, start a 60 or 120-question session, put away all notes, set a timer matching the real exam duration (90 minutes), and commit to each answer before moving forward. This trains the time management and decision-making skills the real exam tests.
This free GPEN mock exam uses the same question distribution as the real GIAC Penetration Tester exam. Each session draws questions proportionally from all 15 official blueprint domains published by GIAC, so the topic mix you see accurately reflects what you'll face on test day.
GPEN Domain Distribution
Attacking Password Hashes
Password Attacks and Formats
Scanning and Host Discovery
Metasploit
Vulnerability Scanning
Kerberos Attacks
Reconnaissance
Command and Control
Exploitation Fundamentals
Azure AD Integration
Domain Escalation and Persistence
Azure Apps and Attacks
Escalation and Exploitation
Advanced Password Attacks
Pen Test Planning
Every question is checked against the 2026 GPENexam objectives and published under the editorial oversight of an engineer with 12+ years' experience. These are original practice questions — not dumps — so you build real understanding rather than memorising answers.
Both the mock exam and practice test use the same question bank. The difference is in how you use them — and when to use each during your GPEN study plan.
Practice test — for learning
Use the GPEN practice test when you are studying a domain. Answer questions, read every explanation immediately, and build understanding. Do 10–30 questions per domain per session. This is your primary study tool for the first 4 weeks.
Go to practice test →Mock exam — for simulation
Use the GPEN mock exam in the final 1–2 weeks before your test date. Complete a 60 or 120-question session without stopping, manage your time, then review all results at the end. This builds exam-day stamina and surfaces final weak spots.
Start 120-question mock →Try these sample questions from the mock exam bank. Commit to an answer before revealing the explanation.
When conducting a penetration test, why is it critical to assess the hashing algorithm used for storing passwords rather than focusing solely on the password policy itself?
Select an answer to reveal the explanation
You are performing an offline attack against a password hash stored in an NTDS.dit file. You have successfully dumped the hashes using secretsdump.py. Given the format 'Username:RID:LMHash:NTHash:::', which hash should be targeted for a modern Windows environment to maximize cracking efficiency?
Select an answer to reveal the explanation
You are performing a network audit and need to identify live hosts across a segmented network while minimizing the risk of triggering IDS alerts. Which Nmap technique is most appropriate for stealthy host discovery in a subnet where ICMP echo requests are filtered by the firewall?
Select an answer to reveal the explanation
Which command in the Metasploit Framework allows a user to interact with a backgrounded session after a successful exploit execution?
Select an answer to reveal the explanation
A penetration tester is configuring an authenticated scan for a Windows environment. Which credential management strategy best minimizes the security impact while maintaining scan efficacy?
Select an answer to reveal the explanation
An attacker has obtained the NTLM hash of a service account. They want to perform a Kerberoasting attack to escalate privileges. Why is this specific hash insufficient for standard Kerberoasting?
Select an answer to reveal the explanation
Which of the following describes the purpose of using Google Dorks during the reconnaissance phase of a penetration test?
Select an answer to reveal the explanation
Which TWO methods are commonly used to achieve C2 persistence while ensuring the communication remains resilient against infrastructure takedowns?
Select an answer to reveal the explanation
During a penetration test, you successfully inject a payload into a web application that results in the server executing system commands with elevated privileges. Which phase of the exploitation lifecycle does this action primarily represent?
Select an answer to reveal the explanation
During an assessment, you discover a federated identity setup using AD FS. What is a common security risk associated with the reliance on the token-signing certificate in this architecture?
Select an answer to reveal the explanation
During a post-exploitation phase, you identify an unquoted service path vulnerability on a Windows target. What is the most reliable way to escalate privileges through this misconfiguration?
Select an answer to reveal the explanation
An attacker is performing reconnaissance on an Azure AD tenant and notices that 'Guest' users can enumerate the directory. Which specific setting should be checked to remediate this?
Select an answer to reveal the explanation
You have identified an SUID binary on a Linux system that executes a shell command without using an absolute path. What is the most effective way to exploit this for privilege escalation?
Select an answer to reveal the explanation
A penetration tester is performing an offline attack against a Windows domain. They have obtained the NTDS.dit file and the SYSTEM hive. Which tool is most effective for extracting the NTLM hashes for offline cracking?
Select an answer to reveal the explanation
An enterprise client insists on a blind 'black-box' penetration test where the testing team receives zero prior knowledge regarding network architecture, IP ranges, or applications. However, the client's primary objective is to thoroughly test deep-seated business logic vulnerabilities within a critical custom web application. Why is this planning approach fundamentally misaligned with the client's stated objective?
Select an answer to reveal the explanation
Answer all 15 questions to see your domain score breakdown
Sitting the GPEN under real exam conditions is a skill in itself. Candidates who underperform often do so not because of knowledge gaps, but because of poor time management or test anxiety. Use your final mock exam sessions to address both.
The GPEN exam lasts 90 minutes. Do not spend more than 90 seconds on any single question on the first pass. Flag difficult ones and return to them after completing the rest.
On every question, immediately eliminate obviously wrong choices. Even if you are unsure between two options, narrowing to two doubles your odds. Most GPEN distractors contain a subtle error — re-read the scenario constraint before committing to the answer that sounds most familiar.
GIAC writes many GPEN questions as realistic scenarios. Read the final sentence first — it tells you what is being asked. Then re-read the scenario with the question in mind to avoid wasting time on irrelevant details.
The real GPEN is a mental marathon lasting 90 minutes. In the week before your exam, complete at least two full timed mock sessions on separate days to build concentration stamina. If you cannot stay focused for 90 minutes in practice, you will struggle on exam day.
Questions
~298
On the real exam
Time limit
90 min
Official exam duration
Passing score
700/1000
Scaled scoring
The GPEN uses scaled scoring — your raw percentage correct is converted to a score out of 1000. Consistently scoring above 80% on mock exams puts you well above the 700/1000 threshold, giving you a buffer for any unexpected question types on the real exam.
Yes. Courseiva provides free GPEN mock exam questions across all official exam domains. The platform includes timed simulation, per-domain score breakdown, missed-question review, and readiness tracking. No account required — free forever, supported by advertising.
The practice test is optimised for learning: you see explanations after each question immediately. The mock exam is optimised for simulation: you answer all questions under time pressure and review at the end. Use practice tests for studying and mock exams for benchmarking.
Aim for consistent scores of 80% or above on full-length GPEN mock exams before booking your test date. The official passing score of 700/1000 corresponds to roughly 72–75% correct answers, so an 80% buffer accounts for difficulty variation and question styles on the real exam.
Most candidates who pass GPEN on their first attempt complete 3–5 full-length mock exams in the two weeks before their test. This is enough to identify final weak spots, build stamina, and verify readiness without over-stressing or running out of fresh questions.
No — all Courseiva questions are original, AI-assisted and checked against the public GIAC exam blueprints, with editorial oversight from an experienced network and security engineer. Exam dumps are memorised real exam questions shared illegally. Using dumps violates your GIAC certification agreement and can result in your certification being revoked. Our questions make you genuinely competent, not just test-day lucky.
Track your mock exam scores, see per-domain analytics, and benchmark readiness across every certification.
Sign Up FreeFree forever · Every certification included