Courseiva

GPEN · domain

Escalation and Exploitation

This GPEN domain covers turning limited access into root or SYSTEM: kernel exploits, Windows privilege abuse, and service misconfigurations. Questions are scenario-based, asking you to pick the correct escalation path, tool, or built-in Windows feature, and to recognize why an action is risky or destructive during a sanctioned penetration test.

17 questions3 easy5 medium9 hard

Focused practice

Practice Escalation and Exploitation questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Escalation and Exploitation

Given a foothold, identify the fastest reliable path to root or SYSTEM using the target's own features, then execute it without destabilizing the host. The critical skill is matching the misconfiguration or privilege to the correct built-in escalation technique.

Kernel exploit risk: crashes, instability, and potential denial of service on production hosts

SQL injection to RCE via xp_cmdshell on Microsoft SQL Server

Windows Backup Operators abusing SeBackupPrivilege and built-in utilities like robocopy or diskshadow

Linux cron jobs running writable scripts as root for privilege escalation

Watch out for

Common Escalation and Exploitation exam traps

  • ▸Running kernel exploits on production without confirming the exact kernel build and having a rollback plan, causing crashes.
  • ▸Assuming Backup Operators can read files directly; the privilege must be enabled and used via a backup-aware tool.
  • ▸Overlooking that xp_cmdshell is disabled by default and requires sysadmin rights or sp_configure to re-enable.

Question index

All Escalation and Exploitation questions (17)

Click any question to see the full explanation, or start a practice session above.

1

During a Windows assessment you obtain a low-privileged domain user's credentials. Enumeration reveals a Group Policy Preference file on a readable SYSVOL share containing a cpassword value. What is the most effective next step to escalate privileges?

Hard
2

During a penetration test, you successfully exploit a web application via SQL injection. You want to use this access to achieve remote code execution (RCE) on the underlying Windows database server. Which feature should you look for to facilitate this?

Medium
3

You are performing a penetration test and discover a service running as SYSTEM that is vulnerable to DLL hijacking. What is the most appropriate action to take to ensure the test is successful and safe?

Medium
4

When escalating privileges using a Kernel exploit, why is it considered a high-risk activity for a penetration test?

Hard
5

During a penetration test on a Linux server, you find a cron job that runs every minute as root: '*/1 * * * * root /usr/local/bin/backup.sh'. The script is owned by root but has permissions 777. You are a low-privileged user. What is the most direct way to escalate privileges?

Hard
6

During an internal assessment, you gain a foothold as a low-privileged domain user on a Windows Server 2019 host that is a member of an Active Directory domain. You run whoami /priv and observe SeImpersonatePrivilege enabled in your token. You need to escalate to NT AUTHORITY\SYSTEM on this host. Which technique is most appropriate?

Medium
7

You have gained standard user execution rights on a hardened Windows 10 enterprise workstation and need to enumerate local privilege escalation vectors. Which TWO methods are most effective for identifying insecure file permissions or unquoted service paths? (Choose two)

Hard
8

You are performing a penetration test on a Linux system and have obtained a low-privileged shell. You want to escalate privileges by exploiting misconfigured file permissions. Which two of the following file permission scenarios are most likely to allow privilege escalation? (Choose two.)

Hard
9

You have identified an SUID binary on a Linux system that executes a shell command without using an absolute path. What is the most effective way to exploit this for privilege escalation?

Hard
10

You have obtained a Meterpreter session as a standard user on an Ubuntu 20.04 server during an authorized penetration test. You want to identify reliable local privilege escalation vectors. Which two findings most directly indicate a path to root? (Choose two.)

Hard
11

You have a shell as www-data on an Ubuntu 20.04 web server and notice a cron job that runs every minute as root executing a script located in /opt/backup/run.sh. The script is writable by the www-data user. What is the most direct way to escalate privileges in this situation?

Easy
12

Which of the following is a primary goal during the 'Exploitation' phase of a penetration test?

Easy
13

During a Linux assessment you find a root-owned binary with the SUID bit set that calls the system() function using a relative path, such as system("cat /etc/hostname"). The binary's directory is not writable, but your current directory is. Which technique is most likely to let you execute arbitrary code as root?

Hard
14

You compromise a Windows workstation and extract the NTLM hash of a local administrator account that is reused across many workstations in the domain. You want to authenticate to remote hosts without cracking the hash. Which technique should you use?

Medium
15

During an internal assessment you obtain a Meterpreter session on a Windows Server 2016 host running as a low-privileged service account. You want to identify whether the host is missing security updates that could allow local privilege escalation without immediately running an exploit. Which Metasploit post-exploitation module should you use to enumerate installed hotfixes and compare them against known vulnerabilities?

Medium
16

You have obtained a Meterpreter session on a Windows 10 host as a standard user. You want to escalate privileges by exploiting a vulnerable kernel driver. Which Metasploit module category would you use to search for suitable exploits?

Easy
17

While testing a Windows 10 workstation, you find that the account you compromised belongs to the Backup Operators group. You need to escalate to local administrator without installing third-party tools on disk. Which built-in capability of this group can you abuse to obtain administrative access?

Hard

Frequently asked questions

What does the Escalation and Exploitation domain cover on the GPEN exam?
Given a foothold, identify the fastest reliable path to root or SYSTEM using the target's own features, then execute it without destabilizing the host. The critical skill is matching the misconfiguration or privilege to the correct built-in escalation technique.
How many questions are in this domain?
This page lists all 17 Escalation and Exploitation questions in the GPEN question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Escalation and Exploitation questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gpen GIAC-GPEN escalation and exploitation Practice Questions