GPEN › Command and Control
This domain covers establishing and maintaining covert channels between compromised hosts and attacker infrastructure, including beacon configuration, jitter, redirectors, and fallback channels. GPEN tests it through scenario questions on C2 frameworks like Metasploit and Cobalt Strike, asking you to configure listeners, interpret beacon parameters, choose resilient persistence methods, and identify which log sources reveal DNS or HTTP-based command and control.
GPEN Command and Control — All 30 Questions
Every question in this domain with answers and detailed explanations.
Attacking Password Hashes
Password Attacks and Formats
Scanning and Host Discovery
Metasploit
Vulnerability Scanning
Kerberos Attacks
Reconnaissance
Exploitation Fundamentals
Azure AD Integration
Domain Escalation and Persistence
Azure Apps and Attacks
Escalation and Exploitation
Advanced Password Attacks
Pen Test Planning