GPEN › Reconnaissance
Reconnaissance on the GPEN exam covers passive and active information gathering against a target before exploitation. You must know how OSINT, DNS interrogation, metadata harvesting, and email/username enumeration work, which tools produce which artifacts, and how to interpret findings like leaked hostnames or internal IPs without touching the client's internal network.
GPEN Reconnaissance — All 31 Questions
Every question in this domain with answers and detailed explanations.
Attacking Password Hashes
Password Attacks and Formats
Scanning and Host Discovery
Metasploit
Vulnerability Scanning
Kerberos Attacks
Command and Control
Exploitation Fundamentals
Azure AD Integration
Domain Escalation and Persistence
Azure Apps and Attacks
Escalation and Exploitation
Advanced Password Attacks
Pen Test Planning