GPEN › Scanning and Host Discovery
This domain covers Nmap-driven host discovery and port scanning: interpreting port states like open|filtered, selecting scan types (SYN, UDP, version detection), and sweeping subnets when ICMP is blocked. GPEN questions present scenarios with exhibits or command output and require you to choose correct Nmap syntax and explain scan behavior and limitations.
GPEN Scanning and Host Discovery — All 29 Questions
Every question in this domain with answers and detailed explanations.
Attacking Password Hashes
Password Attacks and Formats
Metasploit
Vulnerability Scanning
Kerberos Attacks
Reconnaissance
Command and Control
Exploitation Fundamentals
Azure AD Integration
Domain Escalation and Persistence
Azure Apps and Attacks
Escalation and Exploitation
Advanced Password Attacks
Pen Test Planning