Courseiva

GPEN · domain

Exploitation Fundamentals

This domain covers turning a discovered weakness into actual access: payload delivery, command execution, and privilege escalation on Linux and Windows targets. GPEN questions present a short scenario and ask you to classify the phase, name the vulnerability class, pick exploit-selection criteria, or choose the correct enumeration command for the target OS.

20 questions3 easy11 medium6 hard

Focused practice

Practice Exploitation Fundamentals questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Exploitation Fundamentals

Be able to map a described action to the correct exploitation lifecycle phase, infer the vulnerability class from observable server behavior, and justify exploit selection by version and configuration. The single most important thing: match the exploit to the confirmed target version and service before running it.

Classifying actions into the exploitation lifecycle, from initial payload injection through post-exploitation and privilege escalation

Identifying vulnerability classes from server behavior, such as verbose errors revealing stack traces or database queries

Selecting exploits using target version, service configuration, and reliability factors to avoid crashing the target

Using Windows commands like wmic service get and sc qc to find unquoted service paths and weak permissions

Watch out for

Common Exploitation Fundamentals exam traps

  • ▸Confusing the exploitation phase with reconnaissance or scanning; command execution with elevated privileges is post-exploitation, not vulnerability discovery
  • ▸Treating any verbose error as proof of SQL injection when the stack trace may indicate a different flaw such as path disclosure or misconfiguration
  • ▸Choosing an exploit by CVE match alone without confirming the exact service version and configuration, causing a crash or failed attempt

Question index

All Exploitation Fundamentals questions (20)

Click any question to see the full explanation, or start a practice session above.

1

Which of the following describes the purpose of 'encoding' shellcode in an exploitation context?

Medium
2

Which of the following is considered a 'client-side' exploitation scenario?

Easy
3

You are performing a penetration test against a Windows domain and have obtained domain user credentials. You want to identify which domain controllers are vulnerable to a specific privilege escalation technique. Which TWO tools or techniques are most appropriate for enumerating domain controllers and their potential vulnerabilities? (Choose two.)

Hard
4

What is the primary danger of using a 'bind shell' payload in a penetration test?

Medium
5

During a penetration test against an internal Windows host, you use Metasploit's psexec module with a Meterpreter payload and receive a session. You then run the getuid command and see that you are running as NT AUTHORITY\SYSTEM. However, when you attempt to access a mapped network drive that the logged-on user had access to, you receive an access denied error. Which of the following best explains this behavior?

Medium
6

You are conducting a penetration test against a web application and have identified a potential SQL injection vulnerability in a login form. You want to confirm the vulnerability and extract the database schema without causing a denial of service. Which technique should you use to safely enumerate the database?

Medium
7

Which technique is most effective for exploiting a heap-based buffer overflow compared to a stack-based overflow?

Hard
8

During a penetration test, you have identified a Windows domain controller with SMB signing disabled and obtained valid domain user credentials. You want to perform a relay attack to gain administrative access to multiple hosts. Which two conditions are necessary for a successful SMB relay attack? (Choose two.)

Hard
9

You have identified a Windows Server 2019 target running a custom service that is vulnerable to a stack-based buffer overflow. You develop a working exploit and want to execute it during an authorized penetration test. After sending the payload, the service crashes and the target reboots. You need to minimize the impact on the production environment while still validating the vulnerability. Which approach should you take?

Medium
10

When planning an exploit that requires a specific memory address, which THREE techniques can a tester use to increase the reliability of the exploit?

Hard
11

Why is it important to use 'staged' payloads during a penetration test when the target has limited memory or strict filtering?

Medium
12

Refer to the exhibit. Which step should a tester prioritize next based on the server header information?

Medium
13

Refer to the exhibit. What does this output indicate regarding the current exploitation attempt?

Medium
14

During an exploitation attempt against a web application, you inject a payload that causes the server to return a verbose error message containing a stack trace and database query. What is the most likely type of vulnerability you have discovered?

Medium
15

A penetration tester is preparing to exploit a stack-based buffer overflow on a Linux target. The target binary has non-executable stack (NX) enabled. Which technique should the tester use to achieve code execution?

Easy
16

When selecting an exploit for a target system, which TWO factors are most critical to ensure the exploit succeeds without crashing the target service?

Hard
17

You are conducting a penetration test against a web application. During exploitation, you identify a SQL injection vulnerability that allows you to execute arbitrary SQL queries. You want to leverage this to gain remote code execution on the underlying database server. Which TWO of the following techniques are most likely to achieve this goal? (Choose two.)

Medium
18

A penetration tester has gained a foothold on a Windows host and wants to escalate privileges. They discover that the host has an unquoted service path vulnerability. Which command should they use to identify services with unquoted paths that contain spaces?

Easy
19

During a penetration test, you successfully inject a payload into a web application that results in the server executing system commands with elevated privileges. Which phase of the exploitation lifecycle does this action primarily represent?

Medium
20

During an authorized penetration test, you have gained a low-privileged shell on a Linux host. You discover that the kernel is version 4.4.0-116-generic and the system is missing several patches. You want to escalate privileges to root. Which of the following is the most reliable and safe method to achieve privilege escalation?

Hard

Frequently asked questions

What does the Exploitation Fundamentals domain cover on the GPEN exam?
Be able to map a described action to the correct exploitation lifecycle phase, infer the vulnerability class from observable server behavior, and justify exploit selection by version and configuration. The single most important thing: match the exploit to the confirmed target version and service before running it.
How many questions are in this domain?
This page lists all 20 Exploitation Fundamentals questions in the GPEN question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Exploitation Fundamentals questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gpen GIAC-GPEN exploitation fundamentals Practice Questions