Courseiva
Vulnerability Scanning →mediumMultiple Choice

GPEN Vulnerability Scanning Practice Question

A penetration tester is configuring an authenticated scan for a Windows environment. Which credential management strategy best minimizes the security impact while maintaining scan efficacy?

⚠ Common exam trap

Candidates often choose 'Domain Admin' credentials for ease of scanning, failing to realize that this violates the principle of least privilege and significantly increases risk during a security assessment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a dedicated service account with granular WMI and remote registry permissions.

Using dedicated, low-privilege service accounts with specific WMI and registry permissions minimizes the blast radius if credentials are intercepted. This approach adheres to the principle of least privilege, preventing the scanner from having full domain administrator access, which could be abused if the scanning server is compromised. Effective vulnerability management relies on deep system visibility without granting excessive authority to the scanning service.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the scanner to use the Domain Administrator account for full registry access.

    Why it's wrong here

    Domain Administrator accounts provide excessive privileges that violate the principle of least privilege. If the scanner host is compromised, an attacker would gain immediate domain-wide control, significantly increasing the risk profile of the vulnerability scanning infrastructure itself during routine assessment tasks.

  • ✗

    Use a local account with no password to allow quick automated authentication.

    Why it's wrong here

    Local accounts without passwords are inherently insecure and are frequently disabled by default security policies. Attempting to use null sessions or blank passwords will likely fail on modern Windows systems, preventing the scanner from accessing necessary APIs to perform a comprehensive vulnerability assessment.

  • ✓

    Create a dedicated service account with granular WMI and remote registry permissions.

    Why this is correct

    Dedicated accounts with restricted permissions ensure that the scanner can query the necessary system information without broad administrative access. By limiting the scope of the account to WMI and registry read access, you maintain effective scan quality while significantly reducing overall risk.

  • ✗

    Store credentials in plain text in the scanner configuration file for easier automation.

    Why it's wrong here

    Plain text credential storage is a severe security vulnerability that allows anyone with file system access to extract valid administrative passwords. Modern scanners provide encrypted vaults or secure credential managers to protect sensitive data from unauthorized exposure on the scanning host.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.