20+ practice questions focused on Escalation and Exploitation — one of the most tested topics on the GIAC Penetration Tester exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Escalation and Exploitation PracticeDuring an internal network penetration test, you compromise a Linux workstation and discover plaintext credentials for a domain service account cached in memory. You want to move laterally to a critical database server using Pass-the-Hash without triggering Kerberos logging anomalies. Which technique is most appropriate for establishing this lateral movement?
Explanation: Utilizing NTLM hashes directly via Pass-the-Hash bypasses the requirement for plain-text passwords during authentication. This technique is favored in penetration testing because service accounts often retain local administrator privileges across multiple internal systems, enabling rapid expansion of access without generating new Kerberos ticket-granting ticket requests that might alert monitoring analysts.
You are assessing a Linux web server and have discovered a local file inclusion (LFI) vulnerability in a parameter used to load template files. The application runs with standard web user privileges, but you notice that cron is executing a script owned by root every minute. How can you leverage this situation for privilege escalation?
Explanation: Local File Inclusion vulnerabilities can sometimes be escalated to remote code execution or local privilege escalation if they permit reading configuration files or logs that interact with system processes. When cron jobs execute scripts insecurely or depend on world-writable include files, local users can exploit these conditions to execute arbitrary commands.
During an assessment of a corporate Active Directory environment, you discover that a user account has the GenericAll access right over a specific security group. What does this permission enable the penetration tester to achieve?
Explanation: GenericAll is a powerful Active Directory extended access right that grants full control over an object, equivalent to ownership. When applied to a security group, it allows the attacker to modify group membership directly, granting themselves or an accomplice access to sensitive domain resources associated with that group.
You are performing a post-exploitation task on a Windows host and successfully obtain a user's cleartext password from LSASS memory. Which technique is most appropriate to leverage this credential to move laterally to a remote target using only standard Windows authentication protocols?
Explanation: Pass-the-Hash (PtH) and Pass-the-Ticket (PtT) are common, but since you have the cleartext password, Pass-the-Password is not a standard protocol term. Executing a remote process via WinRM or SMB with credentials is the standard approach. This matters because knowing the difference between cleartext capabilities and hash-based capabilities allows testers to select the most reliable authentication method for lateral movement without alerting defensive monitoring systems.
Which TWO of the following Linux configuration files or directories, if writable by a low-privileged user, represent a critical privilege escalation vector?
Explanation: Writable system files allow an attacker to inject malicious code or configurations that execute with root privileges upon system events. Identifying these vectors is crucial for penetration testers because they often provide the most direct path to full system compromise. If a user can modify these files, they can effectively bypass all standard Linux permission controls and establish persistence or gain elevated access during the next service restart.
+15 more Escalation and Exploitation questions available
Practice all Escalation and Exploitation questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Escalation and Exploitation. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Escalation and Exploitation questions on the GPEN frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Escalation and Exploitation is tested as part of the GIAC Penetration Tester blueprint. Practicing with targeted Escalation and Exploitation questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free GPEN practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Escalation and Exploitation is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Escalation and Exploitation practice session with instant scoring and detailed explanations.
Start Escalation and Exploitation Practice →