GPEN › Pen Test Planning
The Pen Test Planning domain covers scoping, legal authorization, and engagement design before any exploitation begins. GPEN questions present client scenarios and ask you to select the correct document, testing methodology, or escalation path. Expect to reason about Rules of Engagement, authorization boundaries, third-party hosting, and how target knowledge shapes test design and reporting.
GPEN Pen Test Planning — All 31 Questions
Every question in this domain with answers and detailed explanations.
Attacking Password Hashes
Password Attacks and Formats
Scanning and Host Discovery
Metasploit
Vulnerability Scanning
Kerberos Attacks
Reconnaissance
Command and Control
Exploitation Fundamentals
Azure AD Integration
Domain Escalation and Persistence
Azure Apps and Attacks
Escalation and Exploitation
Advanced Password Attacks