GPEN › Vulnerability Scanning
This domain covers planning, executing, and interpreting vulnerability scans within authorized engagements. GPEN tests your ability to scope scans via rules of engagement, configure authenticated scanning with least-privilege credentials, tune Nmap UDP scanning to resolve open|filtered ambiguity, and rank findings by exploitability and asset criticality rather than raw CVSS alone.
GPEN Vulnerability Scanning — All 30 Questions
Every question in this domain with answers and detailed explanations.
Attacking Password Hashes
Password Attacks and Formats
Scanning and Host Discovery
Metasploit
Kerberos Attacks
Reconnaissance
Command and Control
Exploitation Fundamentals
Azure AD Integration
Domain Escalation and Persistence
Azure Apps and Attacks
Escalation and Exploitation
Advanced Password Attacks
Pen Test Planning