GPEN Vulnerability Scanning Practice Question
A penetration tester is configuring an authenticated scan for a Windows environment. Which credential management strategy best minimizes the security impact while maintaining scan efficacy?
⚠ Common exam trap
Candidates often choose 'Domain Admin' credentials for ease of scanning, failing to realize that this violates the principle of least privilege and significantly increases risk during a security assessment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a dedicated service account with granular WMI and remote registry permissions.
Using dedicated, low-privilege service accounts with specific WMI and registry permissions minimizes the blast radius if credentials are intercepted. This approach adheres to the principle of least privilege, preventing the scanner from having full domain administrator access, which could be abused if the scanning server is compromised. Effective vulnerability management relies on deep system visibility without granting excessive authority to the scanning service.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the scanner to use the Domain Administrator account for full registry access.
Why it's wrong here
Domain Administrator accounts provide excessive privileges that violate the principle of least privilege. If the scanner host is compromised, an attacker would gain immediate domain-wide control, significantly increasing the risk profile of the vulnerability scanning infrastructure itself during routine assessment tasks.
- ✗
Use a local account with no password to allow quick automated authentication.
Why it's wrong here
Local accounts without passwords are inherently insecure and are frequently disabled by default security policies. Attempting to use null sessions or blank passwords will likely fail on modern Windows systems, preventing the scanner from accessing necessary APIs to perform a comprehensive vulnerability assessment.
- ✓
Create a dedicated service account with granular WMI and remote registry permissions.
Why this is correct
Dedicated accounts with restricted permissions ensure that the scanner can query the necessary system information without broad administrative access. By limiting the scope of the account to WMI and registry read access, you maintain effective scan quality while significantly reducing overall risk.
- ✗
Store credentials in plain text in the scanner configuration file for easier automation.
Why it's wrong here
Plain text credential storage is a severe security vulnerability that allows anyone with file system access to extract valid administrative passwords. Modern scanners provide encrypted vaults or secure credential managers to protect sensitive data from unauthorized exposure on the scanning host.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.