GPEN · domain
Exploitation Fundamentals
This domain covers turning a discovered weakness into actual access: payload delivery, command execution, and privilege escalation on Linux and Windows targets. GPEN questions present a short scenario and ask you to classify the phase, name the vulnerability class, pick exploit-selection criteria, or choose the correct enumeration command for the target OS.
Focused practice
Practice Exploitation Fundamentals questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Exploitation Fundamentals
Be able to map a described action to the correct exploitation lifecycle phase, infer the vulnerability class from observable server behavior, and justify exploit selection by version and configuration. The single most important thing: match the exploit to the confirmed target version and service before running it.
Classifying actions into the exploitation lifecycle, from initial payload injection through post-exploitation and privilege escalation
Identifying vulnerability classes from server behavior, such as verbose errors revealing stack traces or database queries
Selecting exploits using target version, service configuration, and reliability factors to avoid crashing the target
Using Windows commands like wmic service get and sc qc to find unquoted service paths and weak permissions
Watch out for
Common Exploitation Fundamentals exam traps
- ▸Confusing the exploitation phase with reconnaissance or scanning; command execution with elevated privileges is post-exploitation, not vulnerability discovery
- ▸Treating any verbose error as proof of SQL injection when the stack trace may indicate a different flaw such as path disclosure or misconfiguration
- ▸Choosing an exploit by CVE match alone without confirming the exact service version and configuration, causing a crash or failed attempt
Question index
All Exploitation Fundamentals questions (20)
Click any question to see the full explanation, or start a practice session above.
Which of the following describes the purpose of 'encoding' shellcode in an exploitation context?
Medium2Which of the following is considered a 'client-side' exploitation scenario?
Easy3You are performing a penetration test against a Windows domain and have obtained domain user credentials. You want to identify which domain controllers are vulnerable to a specific privilege escalation technique. Which TWO tools or techniques are most appropriate for enumerating domain controllers and their potential vulnerabilities? (Choose two.)
Hard4What is the primary danger of using a 'bind shell' payload in a penetration test?
Medium5During a penetration test against an internal Windows host, you use Metasploit's psexec module with a Meterpreter payload and receive a session. You then run the getuid command and see that you are running as NT AUTHORITY\SYSTEM. However, when you attempt to access a mapped network drive that the logged-on user had access to, you receive an access denied error. Which of the following best explains this behavior?
Medium6You are conducting a penetration test against a web application and have identified a potential SQL injection vulnerability in a login form. You want to confirm the vulnerability and extract the database schema without causing a denial of service. Which technique should you use to safely enumerate the database?
Medium7Which technique is most effective for exploiting a heap-based buffer overflow compared to a stack-based overflow?
Hard8During a penetration test, you have identified a Windows domain controller with SMB signing disabled and obtained valid domain user credentials. You want to perform a relay attack to gain administrative access to multiple hosts. Which two conditions are necessary for a successful SMB relay attack? (Choose two.)
Hard9You have identified a Windows Server 2019 target running a custom service that is vulnerable to a stack-based buffer overflow. You develop a working exploit and want to execute it during an authorized penetration test. After sending the payload, the service crashes and the target reboots. You need to minimize the impact on the production environment while still validating the vulnerability. Which approach should you take?
Medium10When planning an exploit that requires a specific memory address, which THREE techniques can a tester use to increase the reliability of the exploit?
Hard11Why is it important to use 'staged' payloads during a penetration test when the target has limited memory or strict filtering?
Medium12Refer to the exhibit. Which step should a tester prioritize next based on the server header information?
Medium13Refer to the exhibit. What does this output indicate regarding the current exploitation attempt?
Medium14During an exploitation attempt against a web application, you inject a payload that causes the server to return a verbose error message containing a stack trace and database query. What is the most likely type of vulnerability you have discovered?
Medium15A penetration tester is preparing to exploit a stack-based buffer overflow on a Linux target. The target binary has non-executable stack (NX) enabled. Which technique should the tester use to achieve code execution?
Easy16When selecting an exploit for a target system, which TWO factors are most critical to ensure the exploit succeeds without crashing the target service?
Hard17You are conducting a penetration test against a web application. During exploitation, you identify a SQL injection vulnerability that allows you to execute arbitrary SQL queries. You want to leverage this to gain remote code execution on the underlying database server. Which TWO of the following techniques are most likely to achieve this goal? (Choose two.)
Medium18A penetration tester has gained a foothold on a Windows host and wants to escalate privileges. They discover that the host has an unquoted service path vulnerability. Which command should they use to identify services with unquoted paths that contain spaces?
Easy19During a penetration test, you successfully inject a payload into a web application that results in the server executing system commands with elevated privileges. Which phase of the exploitation lifecycle does this action primarily represent?
Medium20During an authorized penetration test, you have gained a low-privileged shell on a Linux host. You discover that the kernel is version 4.4.0-116-generic and the system is missing several patches. You want to escalate privileges to root. Which of the following is the most reliable and safe method to achieve privilege escalation?
HardOther domains
All GPEN exam domains
Frequently asked questions
- What does the Exploitation Fundamentals domain cover on the GPEN exam?
- Be able to map a described action to the correct exploitation lifecycle phase, infer the vulnerability class from observable server behavior, and justify exploit selection by version and configuration. The single most important thing: match the exploit to the confirmed target version and service before running it.
- How many questions are in this domain?
- This page lists all 20 Exploitation Fundamentals questions in the GPEN question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Exploitation Fundamentals questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.