20+ practice questions focused on Exploitation Fundamentals — one of the most tested topics on the GIAC Penetration Tester exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Exploitation Fundamentals PracticeWhen evaluating an exploit script found on a public repository, which THREE actions should a tester take before executing it against a production target?
Explanation: Executing unvetted code in a production environment is dangerous and irresponsible. A tester must analyze the code to understand its functionality, ensure it does not contain malicious side effects, and verify it will not cause system instability. Testing in a sandbox or isolated lab environment is the standard practice to validate that the exploit behaves exactly as intended, protecting the client's assets from accidental damage or unintended data loss.
You are attempting to exploit a buffer overflow vulnerability. The target is using Address Space Layout Randomization (ASLR). Which technique is most appropriate to bypass this protection?
Explanation: ASLR randomizes memory addresses, making it difficult to predict the location of shellcode or useful functions. Return-Oriented Programming (ROP) bypasses this by using existing code fragments (gadgets) already present in executable memory. By chaining these gadgets together, a tester can execute arbitrary commands without needing to know the absolute memory addresses, effectively neutralizing the protection provided by ASLR during the exploitation phase of the assessment.
Which THREE of the following are common indicators that an exploitation attempt has crashed a service?
Explanation: Monitoring service stability is crucial to avoid causing unintended downtime during an engagement. Indicators like lost connections, non-responsive ports, or error logs are the primary signals of a service failure. If these occur immediately following an exploit attempt, it suggests the target was disrupted, necessitating an immediate pause in testing to assess the impact and ensure the stability of the environment before proceeding further.
You are exploiting a stack-based buffer overflow on a 32-bit Linux application. The binary has NX enabled but no ASLR. You have identified a 'pop eax; ret' gadget and a 'jmp esp' instruction. You need to execute your shellcode. Which technique should you use?
Explanation: With NX enabled, the stack is non-executable, so placing shellcode on the stack and jumping to it will fail. The correct approach is ret2libc, which reuses existing executable code in libc to call system() with a pointer to '/bin/sh'. This bypasses NX by executing code from an executable memory region rather than the stack.
During an internal penetration test, you gain access to a Windows 10 workstation and need to escalate privileges to SYSTEM. You discover the host has not been patched since a critical local privilege escalation vulnerability was disclosed. You have a working exploit module in Metasploit. Which Metasploit payload type should you select to get a Meterpreter session that survives process restarts and allows you to migrate to a more stable process?
Explanation: The requirement is for a Meterpreter session that can survive process restarts and allow migration. Meterpreter is a sophisticated payload that operates in memory and includes the migrate command to move the session into another process. This migration ensures that if the originally exploited process crashes or is restarted, the session remains active. Other payload types, such as staged, bind, or encoded shells, do not offer these post-exploitation capabilities.
+15 more Exploitation Fundamentals questions available
Practice all Exploitation Fundamentals questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Exploitation Fundamentals. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Exploitation Fundamentals questions on the GPEN frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Exploitation Fundamentals is tested as part of the GIAC Penetration Tester blueprint. Practicing with targeted Exploitation Fundamentals questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free GPEN practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Exploitation Fundamentals is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Exploitation Fundamentals practice session with instant scoring and detailed explanations.
Start Exploitation Fundamentals Practice →