Courseiva

GPEN · domain

scenario questions

Practise GIAC Penetration Tester scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

298 questions49 easy162 medium87 hard

Focused practice

Practice scenario questions questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about scenario questions

scenario questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common scenario questions exam traps

  • ▸Answering from memory before reading the full scenario.
  • ▸Missing a constraint such as cost, availability, security, scope or command context.
  • ▸Choosing a broad answer when the question asks for the most specific fix.
  • ▸Ignoring why the wrong options are tempting.

Question index

All scenario questions questions (298)

Click any question to see the full explanation, or start a practice session above.

1

Refer to the exhibit. What is the most likely cause of the 'Connection reset by peer' error when using the PsExec module?

Hard
2

A client asks you to perform a penetration test on their internal network. During the planning phase, they provide you with a list of IP addresses and ask you to sign a document that limits your testing to those addresses. Which of the following best describes the purpose of this document?

Easy
3

During the planning phase of a penetration test for a multinational corporation, you discover that the client's legal department requires all testing activities to comply with the laws of each country where their offices are located. The client has offices in Germany, Brazil, and Japan. Which of the following is the MOST important consideration when planning the engagement?

Hard
4

When analyzing C2 traffic, which characteristic of a TLS/SSL certificate is most indicative of a potentially malicious beaconing endpoint?

Medium
5

You are performing a penetration test against a web server that is protected by a network-based intrusion prevention system (IPS). You need to conduct a port scan while minimizing the chance of being blocked. Which two Nmap options should you use to evade the IPS? (Choose two.)

Medium
6

During an internal assessment, a tester uses the auxiliary scanner auxiliary/scanner/smb/smb_version and receives the result 'Host is running Windows Server 2016'. The tester then selects exploit/windows/smb/ms17_010_eternalblue but the exploit reports 'The target is not vulnerable'. Which Metasploit feature should the tester use to determine why the exploit check failed and what SMB dialect the target actually supports?

Hard
7

You are drafting the Rules of Engagement (RoE) for a penetration test of a client's internal network. The client wants to ensure that the engagement is legally sound and that all parties understand their responsibilities. Which TWO of the following items are essential to include in the RoE? (Choose two.)

Medium
8

A penetration tester has captured a password hash from a Linux system and identifies it as a SHA-512 crypt hash. Which Hashcat mode should be used to crack this hash?

Easy
9

During an internal assessment, a tester has valid domain credentials for a standard user and captures Kerberos traffic with Wireshark. The tester notices several TGS-REQ packets for service principal names ending in "/MSSQLSvc" across multiple hosts. The tester wants to identify which accounts are vulnerable to offline password cracking without triggering account lockouts. Which action should the tester take next?

Medium
10

A penetration tester is using Nessus to scan a large subnet and needs to avoid overwhelming older printers that are known to crash when too many simultaneous connections are made. The tester also wants to ensure the scan completes in a reasonable timeframe. Which Nessus scan policy setting should be adjusted to control the number of simultaneous hosts being scanned?

Medium
11

Which of the following is a classic characteristic of 'beaconing' behavior observed in C2 traffic?

Medium
12

During an authorized penetration test, you compromise a Windows host in a restricted network segment that only permits outbound DNS (UDP 53) to an internal resolver. You need to establish a command-and-control channel that can survive reboots and provide interactive shell access while blending with normal DNS traffic. Which of the following is the MOST appropriate technique to achieve this?

Medium
13

During a Windows assessment you obtain a low-privileged domain user's credentials. Enumeration reveals a Group Policy Preference file on a readable SYSVOL share containing a cpassword value. What is the most effective next step to escalate privileges?

Hard
14

Which TWO of the following scenarios are most indicative of a successful Kerberoasting attack occurring within a network?

Medium
15

During the reconnaissance phase of a penetration test, you are examining a target's public-facing web application. You notice that the application returns detailed error messages that include full file paths and database query snippets. Which of the following best describes the primary risk associated with this finding?

Easy
16

When conducting an advanced credential harvesting assessment against an Active Directory environment, a penetration tester attempts Kerberoasting. Which TWO actions or conditions are required to successfully extract and crack service tickets using this technique? (Choose TWO)

Hard
17

During a penetration test, you gain access to a server and want to add a new SSH key for persistent access. Where should you place the key in the user's home directory?

Medium
18

Why does the Kerberos 'PAC' (Privilege Attribute Certificate) pose a security risk in the context of ticket forgery attacks?

Medium
19

Which of the following describes the purpose of 'encoding' shellcode in an exploitation context?

Medium
20

A penetration tester is preparing to run a credentialed vulnerability scan against a mixed environment of Windows Server 2019 and Ubuntu 20.04 hosts on an internal /24 subnet. The tester wants to reduce scan duration and network load while still detecting missing patches and misconfigurations. Which two scanning techniques should the tester implement to achieve these goals? (Choose two.)

Medium
21

A penetration tester has obtained a low-privileged domain user's cleartext credentials. During reconnaissance, the tester wants to enumerate which accounts in the domain are configured with Service Principal Names (SPNs) and are therefore candidates for Kerberoasting, without triggering a lockout or modifying the directory. Which of the following approaches best accomplishes this?

Medium
22

During a penetration test, you successfully exploit a web application via SQL injection. You want to use this access to achieve remote code execution (RCE) on the underlying Windows database server. Which feature should you look for to facilitate this?

Medium
23

You are performing a network audit and need to identify live hosts across a segmented network while minimizing the risk of triggering IDS alerts. Which Nmap technique is most appropriate for stealthy host discovery in a subnet where ICMP echo requests are filtered by the firewall?

Medium
24

Which of the following describes the function of the 'msfvenom' tool within the Metasploit ecosystem?

Medium
25

You are performing a penetration test and discover a service running as SYSTEM that is vulnerable to DLL hijacking. What is the most appropriate action to take to ensure the test is successful and safe?

Medium
26

During OSINT gathering, you are investigating a target's presence on social media and professional networking sites. Which TWO of the following methods are effective for gathering metadata about employees to facilitate future social engineering attacks?

Hard
27

During a penetration test, a tester compromises a workstation and extracts a Kerberos TGT for a domain user from memory. The tester wants to use this TGT to access a file share on a remote server without knowing the user's password. Which action should the tester take?

Medium
28

A software-as-a-service provider engages your team for a penetration test of its production environment. The client wants testing to occur during business hours so its engineers can observe. Which planning consideration is MOST important to address in the Rules of Engagement before testing begins?

Medium
29

You are conducting a penetration test for a client and need to enumerate subdomains of example.com to map their external attack surface. During this reconnaissance phase, you decide to use a tool that performs DNS zone transfers. Which of the following is the most appropriate tool to attempt a DNS zone transfer?

Medium
30

Which technique is most effective for maintaining persistence on a Windows domain-joined machine while remaining stealthy by avoiding common registry keys?

Medium
31

During a penetration test on a Linux system, you have gained root access and want to ensure that your backdoor survives system reboots. Which of the following methods is the most reliable and commonly used for this purpose?

Easy
32

Which of the following is considered a 'client-side' exploitation scenario?

Easy
33

A penetration tester has completed an unauthenticated vulnerability scan of a web server and received a report listing several critical CVEs. Before including these in the final report, the tester wants to validate that the findings are not false positives. Which action is the MOST appropriate next step?

Easy
34

Which phase of a vulnerability assessment typically involves comparing the output against a known database of CVEs?

Medium
35

You are performing a penetration test against a web server and want to identify the exact version of the HTTP service running on port 80. Which Nmap command should you use?

Easy
36

During a penetration test, you have gained access to a Microsoft Entra ID tenant with Global Administrator privileges. You want to establish a backdoor that allows you to authenticate as any user in the tenant without knowing their password, even if your Global Administrator account is removed. Which of the following methods would best achieve this?

Hard
37

You are scanning a target that resides behind a firewall configured to drop TCP packets with the ACK flag set. You want to determine whether the firewall is stateful or stateless. Which Nmap scan type should you use to help make this determination by analyzing the responses to ACK packets?

Hard
38

A penetration tester has compromised a workstation and obtained a Kerberos TGT for a low-privileged domain user. The tester wants to abuse unconstrained delegation configured on a member server named APP01 to escalate privileges. Which two actions are required to achieve this? (Choose two.)

Hard
39

You are conducting external reconnaissance against a target that uses a split-horizon DNS configuration. From the public internet, you query the organization's authoritative name server for the A record of vpn.contoso.com and receive NXDOMAIN. However, you have obtained a leaked internal zone file that shows the same hostname resolving to 10.10.10.50. Which technique would best allow you to identify additional internal-only hostnames without sending traffic to the target's internal network?

Medium
40

During a penetration test, you obtain a password hash from a Linux system's /etc/shadow file. The hash starts with '$6$'. Which Hashcat mode should you use to crack it?

Easy
41

You are performing a penetration test against a Windows domain and have obtained domain user credentials. You want to identify which domain controllers are vulnerable to a specific privilege escalation technique. Which TWO tools or techniques are most appropriate for enumerating domain controllers and their potential vulnerabilities? (Choose two.)

Hard
42

What is the primary risk of using 'Domain Fronting' in a C2 architecture during a penetration test?

Hard
43

When escalating privileges using a Kernel exploit, why is it considered a high-risk activity for a penetration test?

Hard
44

Refer to the exhibit. What does this error log suggest regarding the C2 connection attempt?

Medium
45

You are performing a reconnaissance task and need to identify the physical location or ownership of an organization's IP space. Which TWO of the following services are standard for this task?

Medium
46

What is the purpose of the 'meterpreter' payload in the Metasploit framework?

Easy
47

Which THREE of the following are valid methods to mitigate the risk of password spray attacks in an integrated Azure AD environment?

Hard
48

During a penetration test on a Linux server, you find a cron job that runs every minute as root: '*/1 * * * * root /usr/local/bin/backup.sh'. The script is owned by root but has permissions 777. You are a low-privileged user. What is the most direct way to escalate privileges?

Hard
49

When conducting a network scan, you notice that many hosts are not responding to ping requests, even though they are known to be online. What is the most appropriate Nmap flag to use to ensure these hosts are still scanned for open ports?

Easy
50

During an internal assessment, you gain a foothold as a low-privileged domain user on a Windows Server 2019 host that is a member of an Active Directory domain. You run whoami /priv and observe SeImpersonatePrivilege enabled in your token. You need to escalate to NT AUTHORITY\SYSTEM on this host. Which technique is most appropriate?

Medium
51

A penetration tester is performing a password audit and has obtained a set of NTLM hashes from a Windows system. The tester wants to use Hashcat to crack these hashes but needs to choose the correct mode. Which Hashcat mode should be used for NTLM hashes?

Easy
52

During a post-exploitation phase, you identify an unquoted service path vulnerability on a Windows target. What is the most reliable way to escalate privileges through this misconfiguration?

Medium
53

Why are GPUs significantly more effective than CPUs for brute-forcing unsalted NTLM hashes?

Hard
54

During a vulnerability scan of a web application, the scanner reports a critical SQL injection vulnerability on a login form. A manual test using a single quote in the username field returns a generic error page with no database details. The scanner's evidence shows a time-based blind SQL injection payload that caused a five-second delay. Which action should the penetration tester take next to validate the finding?

Hard
55

A penetration tester obtains a password hash from a Linux system's /etc/shadow file that begins with $6$. Which statement correctly describes this hash and its implications for cracking?

Easy
56

You are the lead penetration tester for a financial services client. During the scoping meeting, the client states they want to test their external perimeter but are concerned about accidental disruption to production trading systems. They ask you to propose a testing approach that minimizes operational risk while still validating exploitable vulnerabilities. Which of the following is the MOST appropriate recommendation?

Medium
57

When evaluating the security of an organization's C2 detection capabilities, which log source is the most valuable for detecting DNS-based C2?

Medium
58

What is the primary purpose of a 'delta' or 'differential' vulnerability scan?

Easy
59

When performing a penetration test, why is it safer to crack hashes offline rather than online?

Medium
60

You are conducting an internal penetration test for a client that uses Microsoft Entra ID (Azure AD) with on-premises Active Directory. You have obtained a low-privileged domain user's credentials. You want to enumerate Entra ID users and groups without triggering sign-in logs on the compromised user. Which of the following techniques would be MOST effective for this goal?

Medium
61

When a reverse shell connection fails to reach the listener, what is the best first step for troubleshooting?

Hard
62

A penetration tester uses msfvenom to generate a Linux ELF reverse shell payload. The tester wants the payload to connect back to 192.168.1.50 on port 4444 and to embed an encoder that removes null bytes and other bad characters to survive transmission through a constrained channel. Which msfvenom command line correctly produces this payload?

Hard
63

During an assessment, you find that 'Device Writeback' is enabled. What is the security concern regarding the registration of these devices in Azure AD?

Hard
64

Refer to the exhibit. You executed an Nmap scan against a host and received the output shown. Which scanning technique was most likely used to produce this specific state-based output while avoiding the completion of a full TCP three-way handshake?

Hard
65

You are performing a penetration test and need to scan a large Class B network (10.0.0.0/16) for live hosts. You want to minimize the scan time while still getting accurate results. Which Nmap option should you use to perform a ping sweep without port scanning?

Easy
66

What is the primary danger of using a 'bind shell' payload in a penetration test?

Medium
67

During an internal penetration test, an attacker compromises a standard user account in a hybrid Azure AD environment. The organization synchronizes on-premises identities using Azure AD Connect with Pass-Through Authentication enabled. Which technique allows the attacker to compromise additional cloud and on-premises identities without triggering standard cloud MFA prompts?

Medium
68

During an internal penetration test, you need to discover live hosts on a flat Layer 2 network segment. The client's IDS is known to alert on TCP SYN packets sent to closed ports. You want to minimize the chance of triggering an alert while still identifying as many hosts as possible. Which Nmap host discovery technique should you use?

Medium
69

During a penetration test against an internal Windows host, you use Metasploit's psexec module with a Meterpreter payload and receive a session. You then run the getuid command and see that you are running as NT AUTHORITY\SYSTEM. However, when you attempt to access a mapped network drive that the logged-on user had access to, you receive an access denied error. Which of the following best explains this behavior?

Medium
70

During a red team engagement, an operator successfully dumps the LSA secrets and NTDS.dit database from a Windows domain controller. Which TWO advanced password extraction and analysis techniques should the operator prioritize to uncover administrative access vectors? (Choose two)

Hard
71

A penetration tester has captured a NetNTLMv2 challenge-response hash from a Windows workstation over SMB. The tester plans to recover the plaintext password offline using Hashcat on a workstation with a dedicated GPU. The hash file is saved as 'capture.txt' in the format 'username::domain:challenge:response:blob'. Which Hashcat mode should the tester specify to correctly crack this hash?

Medium
72

You are scanning a target and need to avoid triggering a network IPS that signatures on TCP connect scans. You have root privileges and want to perform a stealthy scan that does not complete the TCP three-way handshake. Which Nmap scan type should you use?

Medium
73

During a penetration test, you capture network traffic and obtain an MS-CHAPv2 challenge-response handshake. You want to crack it offline to recover the user's password. Which tool and mode combination is most appropriate for this task?

Easy
74

During an internal penetration test you need to enumerate live hosts on a /24 subnet that you suspect is protected by a stateful firewall dropping ICMP echo requests. You want the scan to be fast and you have administrative (root) privileges on your Kali system. Which Nmap command best accomplishes host discovery in this scenario?

Medium
75

A client asks for an 'unannounced' penetration test to test their incident response team. What is the most important preparatory step before commencing this exercise?

Medium
76

During an internal penetration test, you gain access to a Windows workstation and discover that a domain user's password hash is cached in the registry. You extract the hash and want to crack it offline. Which Hashcat mode should you use to attack the cached domain credential?

Medium
77

An attacker has gained access to an Azure VM and wants to escalate privileges by abusing the VM's managed identity. The managed identity has the 'Contributor' role on the subscription. Which of the following actions would allow the attacker to add a new user to an Azure AD group that has 'Global Administrator' role?

Hard
78

Refer to the exhibit. Why did the EternalBlue exploit attempt fail despite the scanner identifying the target as vulnerable?

Medium
79

Refer to the exhibit. What is the primary purpose of the Nmap Scripting Engine (NSE) in the context of the output provided, and how does it improve upon standard port scanning?

Hard
80

Which THREE of the following are primary reasons why the NTLM authentication protocol is considered insecure for modern enterprise environments?

Hard
81

You are performing a penetration test against a target that is behind a firewall configured to drop all TCP packets except those destined for port 443. You need to determine whether the firewall is stateful or stateless to plan your attack. Which Nmap scan technique will best help you make this determination?

Hard
82

What is the primary risk associated with storing credentials in plain text within scripts or configuration files?

Medium
83

During the reconnaissance phase, you notice a target is using an older, unpatched version of a popular CMS. What is the most appropriate next step?

Medium
84

Which TWO of the following are common indicators that a Windows system has been compromised with persistence?

Medium
85

A penetration tester has obtained the NTLM hash of a domain user and wants to authenticate to a remote server without cracking the password. Which of the following techniques allows the tester to use the hash directly for authentication?

Medium
86

You are performing a Kerberoasting attack against a domain. After requesting service tickets for accounts with SPNs, you extract the tickets and attempt to crack them offline. Which two factors most directly determine the success of cracking these tickets? (Choose two.)

Medium
87

An attacker has obtained the NTLM hash of a service account. They want to perform a Kerberoasting attack to escalate privileges. Why is this specific hash insufficient for standard Kerberoasting?

Medium
88

You are planning a penetration test for a healthcare provider that must comply with HIPAA. The client wants to ensure that any protected health information (PHI) accessed during testing is handled securely. Which of the following is the MOST critical element to include in the data handling plan?

Hard
89

During an internal penetration test, an attacker successfully captures an NTLMv2 challenge-response authentication exchange from a network segment. The adversary wishes to perform an offline brute-force cracking attack against the captured hash using Hashcat. Which specific Hashcat attack mode and hash format identifier must be specified to successfully crack this captured challenge-response pair?

Medium
90

A penetration tester is assessing an Azure environment and discovers a function app with an HTTP trigger that does not require authentication. The function app has a system-assigned managed identity with Contributor role on the subscription. What is the most immediate risk?

Easy
91

You are conducting a penetration test against a web application and have identified a potential SQL injection vulnerability in a login form. You want to confirm the vulnerability and extract the database schema without causing a denial of service. Which technique should you use to safely enumerate the database?

Medium
92

Which technique is most effective for exploiting a heap-based buffer overflow compared to a stack-based overflow?

Hard
93

A penetration tester is conducting a vulnerability scan against a web application and notices that the scanner reports a critical SQL injection vulnerability on a page that does not accept user input. The tester manually verifies the page and finds no input fields or parameters. What is the most likely cause of this false positive?

Medium
94

A penetration tester is preparing to crack a set of NTLM hashes obtained from a Windows domain controller. The tester wants to maximize the chances of recovering plaintext passwords. Which TWO of the following techniques are most effective for this goal? (Choose two.)

Hard
95

You are conducting passive reconnaissance against a target organization and want to identify internet-facing systems and services without sending any packets to the target's own IP space. Which two techniques best satisfy this requirement? (Choose two.)

Hard
96

Which TWO of the following are characteristics of 'Salted' hashes compared to 'Unsalted' hashes?

Medium
97

A penetration tester has obtained Domain Admin credentials during an internal engagement and wants to establish long-term persistence that survives a Domain Admin password reset and reboots. The tester needs a method that remains stealthy and does not rely on leaving a binary on disk. Which technique best meets these requirements?

Hard
98

Which THREE of the following are valid techniques for privilege escalation on a Linux system?

Hard
99

Why is it important to perform reconnaissance from a non-attributable source during a penetration test?

Medium
100

In Metasploit, what is the significance of the 'LHOST' parameter when setting up a reverse shell?

Easy
101

Refer to the exhibit. You are currently at 17:15. You have just identified a critical, easily exploitable vulnerability on 10.1.1.20. What is the correct next step?

Hard
102

You have gained standard user execution rights on a hardened Windows 10 enterprise workstation and need to enumerate local privilege escalation vectors. Which TWO methods are most effective for identifying insecure file permissions or unquoted service paths? (Choose two)

Hard
103

You are planning a penetration test for a healthcare provider that must comply with HIPAA. The client wants to test a new patient portal hosted on AWS. During the kickoff meeting, the client's legal team asks how you will handle any protected health information (PHI) that you might encounter. Which of the following is the most appropriate action to take before testing begins?

Medium
104

Refer to the exhibit. Given the output from Mimikatz, what is the most appropriate interpretation of the 'LM NTLM' value provided for the administrator account?

Hard
105

A penetration tester is reviewing a captured NTLMv2 challenge-response pair and wants to crack it offline using Hashcat. Which Hashcat mode should the tester use to attack this specific hash type?

Easy
106

During an internal penetration test, you have compromised a Windows workstation and need to establish a covert channel that will survive network address translation and filtering. You decide to use the Domain Name System (DNS) TXT record for command and control. Which tool should you use to create a DNS tunnel that encapsulates IP traffic over DNS queries and responses?

Medium
107

During an internal network penetration test, you capture NetNTLMv2 challenge-response hashes. You decide to perform a relay attack rather than cracking them offline. Which protocol characteristic makes SMB relaying feasible against a target host?

Medium
108

You are performing a penetration test on a Linux system and have obtained a low-privileged shell. You want to escalate privileges by exploiting misconfigured file permissions. Which two of the following file permission scenarios are most likely to allow privilege escalation? (Choose two.)

Hard
109

A penetration tester is planning a vulnerability scan of a network that includes legacy systems and IoT devices. The tester needs to minimize the risk of disrupting these fragile devices while still gathering useful vulnerability data. Which two actions should the tester take? (Choose two.)

Hard
110

When conducting a penetration test, why is it critical to assess the hashing algorithm used for storing passwords rather than focusing solely on the password policy itself?

Easy
111

Which of the following is a key advantage of using a 'Scheduled Task' for persistence on Windows systems?

Medium
112

When planning for an engagement involving sensitive data, which TWO of the following must be included in the data handling plan?

Medium
113

What is the primary objective of a 'Kerberos Armoring' (FAST) implementation?

Medium
114

During a penetration test, you are performing passive reconnaissance against a target organization. You want to gather information about the organization's public-facing infrastructure without directly interacting with their systems. Which two of the following techniques are considered passive reconnaissance? (Choose two.)

Medium
115

During a penetration test, a tester obtains a Kerberos TGS ticket for a service account and wants to crack it offline. The ticket is encrypted with RC4-HMAC. Which of the following best describes the primary reason this attack, known as Kerberoasting, is effective?

Hard
116

During a penetration test, you successfully dump the LSASS memory space and extract a set of NTLM hashes. Which of the following is the most efficient next step if the goal is to determine the plaintext password of a high-value administrator account?

Medium
117

Which TWO of the following methods are commonly used by attackers to achieve persistence on a Linux system via cron jobs?

Medium
118

You are conducting a penetration test and have gained access to a target's internal network. You want to perform reconnaissance to identify other live hosts and services without using traditional port scanning that might trigger IDS alerts. Which of the following techniques would be most effective for low-noise host discovery on the internal network?

Hard
119

You are analyzing the results of a passive reconnaissance scan using a tool that harvests metadata from files found on a company website. What is the primary security risk associated with this information disclosure?

Hard
120

What is the fundamental difference between Golden Ticket and Silver Ticket attacks?

Easy
121

If a penetration tester discovers a vulnerability that could compromise a third-party hosted service during an engagement, what is the correct professional responsibility?

Medium
122

Refer to the exhibit. What does the Nmap status 'open|filtered' indicate about the target port, and why does this result commonly occur in penetration testing scenarios?

Hard
123

You have identified an SUID binary on a Linux system that executes a shell command without using an absolute path. What is the most effective way to exploit this for privilege escalation?

Hard
124

You are scanning a target from a host on the same Ethernet segment. You run 'nmap -sS -p 445 192.168.1.50' and receive a response indicating the port is open. You then run the same scan from a different subnet across a router and receive no response at all, even though the service is confirmed running. Which statement best explains this difference?

Hard
125

You have obtained a Meterpreter session as a standard user on an Ubuntu 20.04 server during an authorized penetration test. You want to identify reliable local privilege escalation vectors. Which two findings most directly indicate a path to root? (Choose two.)

Hard
126

During a penetration test against an Active Directory environment, you extract the NTLM hash of a domain user from a memory dump. You attempt to crack it with Hashcat using mode 1000 but fail after several hours. You suspect the password is longer than 12 characters and contains symbols. Which adjustment to your cracking strategy is most likely to succeed within a reasonable timeframe?

Medium
127

A healthcare client hires your team for an internal penetration test. During the kickoff meeting, the client's compliance officer asks which document formally defines the specific systems, time windows, and testing techniques that are authorized for the engagement. Which document should you reference?

Easy
128

When using Metasploit to perform a vulnerability scan, which module type should be selected?

Medium
129

A penetration tester captures a NetNTLMv2 hash from a network segment using Responder. The tester wants to crack this hash using Hashcat. Which Hashcat mode should be used?

Hard
130

A penetration tester is using Nmap with the NSE script 'vulners' to identify vulnerabilities on a target. The scan returns a list of CVEs for detected services, but the tester notices that some CVEs have a low confidence score. What is the MOST accurate interpretation of these low-confidence findings?

Hard
131

During a penetration test, you have identified a Windows domain controller with SMB signing disabled and obtained valid domain user credentials. You want to perform a relay attack to gain administrative access to multiple hosts. Which two conditions are necessary for a successful SMB relay attack? (Choose two.)

Hard
132

During a penetration test, an operator compromises a workstation where a domain administrator has an active logon session. The operator wants to extract the domain administrator's Kerberos TGT from LSASS and reuse it to access other systems without knowing the administrator's password. Which of the following techniques is specifically designed for this purpose?

Hard
133

During a penetration test, an operator captures a network authentication attempt using the NTLMv2 protocol. The operator wants to crack the captured challenge-response offline using Hashcat. Which hash mode should the operator select to correctly process the captured NetNTLMv2 hash?

Hard
134

When mapping a target's network infrastructure, why is it important to use multiple WHOIS and regional internet registry (RIR) databases?

Medium
135

You have a shell as www-data on an Ubuntu 20.04 web server and notice a cron job that runs every minute as root executing a script located in /opt/backup/run.sh. The script is writable by the www-data user. What is the most direct way to escalate privileges in this situation?

Easy
136

A financial services client engages you for an external penetration test and wants contractual protection before testing begins. Which TWO items belong in a master services agreement or statement of work to limit the firm's legal exposure while authorizing the work? (Choose two.)

Hard
137

Which TWO of the following password cracking techniques are considered 'offline' attacks?

Medium
138

During an engagement, a penetration tester obtains a password hash that starts with `$2y$10$`. The client's security policy requires passwords to be at least 12 characters and include complexity. The tester wants to crack the hash using a rule-based attack. Which Hashcat mode should be used, and what is the primary advantage of this hash format?

Hard
139

Which of the following describes the purpose of using Google Dorks during the reconnaissance phase of a penetration test?

Easy
140

A penetration tester needs to scan a large enterprise network for vulnerabilities but has only a short maintenance window. The tester wants to maximize scan coverage while minimizing the impact on production systems. Which Nessus scan policy setting should the tester adjust to balance speed and accuracy?

Medium
141

You are performing a penetration test and need to identify all live hosts on a subnet without performing a port scan. Which Nmap command should you use to accomplish this?

Easy
142

Which term best describes the stage of a cyberattack where a compromised host signals a remote server to request instructions or transmit stolen data?

Easy
143

During an internal penetration test of a hybrid Microsoft Entra ID environment, you compromise a standard on-premises user account. You notice that the account's on-premises userPrincipalName is jdoe@corp.local, but the corresponding cloud account has the userPrincipalName jdoe@corp.com. Which attribute should you modify on-premises to change the cloud sign-in address for this synchronized user?

Medium
144

Which attack targets service accounts by requesting a service ticket (TGS) from the domain controller and cracking the ticket offline?

Medium
145

A penetration tester has compromised a host in a restricted network that only allows outbound DNS queries to a specific internal resolver. The tester needs to establish a command and control channel that can traverse this restriction. Which C2 technique is most appropriate?

Easy
146

You are configuring a C2 listener to use a malleable profile to blend in with legitimate traffic. Which two of the following are key benefits of using a malleable C2 profile in a penetration test? (Choose two.)

Medium
147

Which of the following is the most effective way to detect C2 beacons that use jitter and randomized timing?

Medium
148

Refer to the exhibit. You are performing a penetration test based on this policy. You discover an unpatched SQL injection vulnerability on 192.168.10.20 that could be used to trigger a database lock-up. What is the most appropriate course of action?

Hard
149

During a penetration test, you are reviewing the results of a WHOIS query for a target domain. You notice the registrant's email address is privacy-protected, but the technical contact email is a generic address at a third-party hosting company. What is the most likely explanation for this finding, and what should you do next to gather more information about the target's infrastructure?

Easy
150

You are planning a penetration test for a client with a large wireless network. The client wants to assess the security of their WPA3-Enterprise deployment. Which of the following should be included in the Rules of Engagement to address the risk of disrupting legitimate wireless users?

Medium
151

During the scoping phase of a penetration test for a global e-commerce client, you identify that the client uses a cloud-based Content Delivery Network (CDN) to host static assets. Which action is the most critical for ensuring the engagement remains within the Rules of Engagement (RoE)?

Medium
152

Which document is primarily responsible for defining the 'Rules of Engagement' (RoE) in a penetration testing project?

Easy
153

Which of the following is a primary advantage of using a 'Golden Ticket' attack over other credential-based attacks?

Medium
154

Refer to the exhibit. An Nmap scan returns output indicating a web server is responding, but the `http-enum` script fails to identify common directories. Which action should the tester take to improve detection?

Medium
155

During a penetration test, a tester runs an OpenVAS scan against a web server and receives a report indicating a high-severity vulnerability with a CVE identifier. Before including it in the final report, the tester wants to verify if the vulnerability is actually exploitable. Which action should the tester take next?

Hard
156

Which of the following is a primary goal during the 'Exploitation' phase of a penetration test?

Easy
157

A penetration tester needs to generate a standalone Windows executable payload that will connect back to the tester's machine at 10.10.14.5 on port 4444. The tester wants to avoid depending on the Metasploit console during payload generation. Which msfvenom command should be used?

Easy
158

A penetration tester extracts a domain user's NT hash from the SAM database of a workstation and wants to authenticate to a file share on a different server without knowing the plaintext password. Which of the following techniques should the tester use?

Medium
159

You have identified a Windows Server 2019 target running a custom service that is vulnerable to a stack-based buffer overflow. You develop a working exploit and want to execute it during an authorized penetration test. After sending the payload, the service crashes and the target reboots. You need to minimize the impact on the production environment while still validating the vulnerability. Which approach should you take?

Medium
160

Which of the following actions is the most appropriate step after discovering a critical vulnerability that is currently being exploited in the wild?

Medium
161

You are reviewing the scope of an upcoming penetration test and need to identify the organization's mail exchangers and the servers authoritative for its DNS zones using only publicly available records. Which DNS record types should you query to obtain this information directly?

Easy
162

Refer to the exhibit. Given this output, which action is most appropriate for a penetration tester?

Medium
163

You are planning a penetration test for a client that has a hybrid cloud environment. The client's security team wants to ensure that the test does not violate the shared responsibility model of their cloud provider. Which of the following should you do FIRST to align the test with the cloud provider's policies?

Medium
164

What is the primary risk associated with 'Unconstrained Delegation' in Active Directory?

Hard
165

Which of the following describes the risk of 'Guest User' accounts in an Azure AD integration scenario?

Medium
166

When conducting a penetration test on an Azure App Service, you discover an 'environment.js' file in the public directory containing a 'CLIENT_ID'. What is the risk associated with this finding?

Medium
167

During an internal penetration test, a tester gains access to a Windows domain controller and extracts the NTDS.dit file along with the SYSTEM registry hive. The tester wants to extract all domain user password hashes for offline cracking. Which tool, when used with the appropriate arguments, can parse these files to retrieve the hashes?

Hard
168

A penetration tester is configuring a vulnerability scanner to assess a sensitive production network. The tester wants to avoid causing service disruptions or overwhelming network devices. Which scanner setting should be adjusted to best achieve this?

Easy
169

A penetration tester is conducting a password attack against a Windows Active Directory environment. The tester has obtained a list of usernames and wants to perform a password spraying attack to avoid account lockouts. Which two considerations are most important when executing this attack? (Choose two.)

Medium
170

When attempting to escalate privileges on a Linux system, what is the significance of the SUID bit on a file owned by root?

Hard
171

A penetration tester has obtained a set of Linux shadow file hashes. The hashes begin with $6$ and the tester intends to perform an offline brute-force attack using Hashcat. Which mode should the tester select to ensure Hashcat correctly interprets these hashes?

Medium
172

During a penetration test, you obtain a memory dump from a Windows Server 2016 system. You suspect that a domain administrator recently logged on and left credentials in memory. Which tool is specifically designed to extract plaintext passwords and hashes from Windows memory dumps?

Medium
173

A penetration tester is analyzing a Kerberos attack that involved forging a ticket to gain access to a specific server. The ticket was encrypted with the server's machine account hash and did not involve communication with the domain controller. Which type of attack does this describe?

Easy
174

Which of the following is a primary benefit of using Managed Identities for Azure resources?

Medium
175

A penetration tester is performing a password attack against an Active Directory environment and has obtained a list of domain user accounts. The tester wants to perform a password spraying attack to identify weak passwords while minimizing the risk of account lockouts. Which TWO of the following are best practices for conducting a password spraying attack in this scenario? (Choose two.)

Medium
176

You are designing a resilient command-and-control (C2) infrastructure for an authorized penetration test. The client's network has strict egress filtering and monitors for anomalous traffic. You need to ensure that your C2 channel can survive the takedown of a single server and adapt to changing network conditions. Which two of the following techniques should you implement? (Choose two.)

Medium
177

During a Linux assessment you find a root-owned binary with the SUID bit set that calls the system() function using a relative path, such as system("cat /etc/hostname"). The binary's directory is not writable, but your current directory is. Which technique is most likely to let you execute arbitrary code as root?

Hard
178

When analyzing a hybrid identity environment, you notice the use of 'Seamless Single Sign-On'. What is the potential impact if the 'AZUREADSSOACC' computer object in the on-premises Active Directory is compromised?

Hard
179

Why is 'Password Writeback' considered a significant security risk in hybrid identity integrations?

Medium
180

What is the primary benefit of using passive reconnaissance before initiating active scanning?

Easy
181

Refer to the exhibit. Which command allows the tester to switch their interaction focus from session 1 to session 2?

Medium
182

You are the lead penetration tester for an engagement at a regional bank. The client's legal team has approved testing of their external IP range, but the Statement of Work does not mention the third-party core banking platform hosted by a vendor on a shared subnet. During reconnaissance, you discover that one of the client's external IPs routes directly into the vendor's shared environment. What is the MOST appropriate action before conducting any exploitation?

Medium
183

During planning, a client requests that you use a specific automated scanner that is known to produce false positives and potential system instability. What is the most professional way to handle this request?

Medium
184

You have obtained domain administrator credentials during a penetration test. To maintain stealthy persistence on a Windows domain controller, you decide to abuse Kerberos. Which method allows you to authenticate as any user without knowing their password, and is a known persistence technique?

Medium
185

You compromise a Windows workstation and extract the NTLM hash of a local administrator account that is reused across many workstations in the domain. You want to authenticate to remote hosts without cracking the hash. Which technique should you use?

Medium
186

You are conducting a penetration test against a target that employs a next-generation firewall (NGFW) with SSL inspection. Your C2 channel uses a custom protocol over TCP port 8443 with a self-signed certificate. The NGFW is blocking your traffic. You need to modify your C2 configuration to evade detection while maintaining command and control. Which of the following changes is MOST likely to succeed?

Hard
187

When planning an exploit that requires a specific memory address, which THREE techniques can a tester use to increase the reliability of the exploit?

Hard
188

During an internal penetration test, you capture an NTLMv2 challenge-response pair using Responder. You want to crack it offline to obtain the user's password. Which Hashcat mode should you use?

Medium
189

A penetration tester gains Global Administrator privileges in a Microsoft Entra ID tenant and needs to establish persistent access that survives credential resets and standard administrative remediation. Which TWO methods can the tester implement to maintain covert administrative access?

Hard
190

You are using a C2 framework that supports malleable C2 profiles. Your current profile uses a default HTTP GET beacon with a fixed User-Agent and a URI of /submit.php. The target's network monitoring has flagged this traffic as suspicious. You need to modify the profile to better blend with legitimate traffic. Which of the following changes is the MOST effective for evading network-based detection?

Hard
191

Why is it important to use 'staged' payloads during a penetration test when the target has limited memory or strict filtering?

Medium
192

During an internal penetration test, you have obtained cleartext credentials for a low-privileged Active Directory user. You want to enumerate which user accounts do not require Kerberos preauthentication so you can request AS-REP messages and crack them offline. Which Impacket tool and command should you use?

Medium
193

During a penetration test, you have established a C2 channel using a domain fronting technique with a CDN. The target organization's proxy logs show connections to a high-reputation domain, but the actual C2 traffic is destined for your backend server. Which component is essential for this setup to function?

Hard
194

A penetration tester is reviewing Active Directory for Kerberos delegation misconfigurations that could allow privilege escalation. Which of the following TWO configurations should the tester flag as directly enabling an attacker to impersonate a domain administrator to a target service? (Choose two.)

Medium
195

A penetration tester is using Nmap to scan a target subnet and wants to identify all hosts that are up without performing port scanning. The tester also wants to avoid sending TCP SYN packets to reduce noise. Which Nmap option should the tester use?

Hard
196

Which command in the Metasploit Framework allows a user to interact with a backgrounded session after a successful exploit execution?

Medium
197

A tester has compromised a Windows host and wants to use Metasploit to harvest credentials from memory without uploading additional tools. Which Metasploit post-exploitation module should be used to extract password hashes from the LSASS process?

Medium
198

Refer to the exhibit. What is the primary purpose of the 'jitter' parameter in this C2 configuration?

Medium
199

What is the primary danger of leaving a 'backdoor' account on a compromised system after a penetration test?

Medium
200

Refer to the exhibit. During an Azure engagement, you query a service principal via the Microsoft Graph API and notice that 'appRoleAssignmentRequired' is set to 'false'. What security implication does this setting present for enterprise applications?

Medium
201

A penetration tester extracts a password hash from a compromised Linux system. The hash format is `$6$rounds=5000$abcdefgh$...`. Which hashing algorithm and configuration does this represent?

Medium
202

Why do many C2 frameworks include a 'sleep' command that can be configured by the operator?

Medium
203

What is the primary security benefit of implementing Group Managed Service Accounts (gMSAs) in an environment vulnerable to Kerberoasting?

Medium
204

Which file in a Windows system is required, along with the NTDS.dit file, to decrypt cached credentials stored in the database?

Medium
205

What is the primary function of 'rules' in tools like Hashcat when performing a dictionary attack?

Medium
206

During a penetration test for a multinational retailer, you discover that a legacy internal application in scope contains a hardcoded credential that also grants access to a payment processing system the client explicitly excluded from testing. You have not yet used the credential. What is the MOST appropriate course of action?

Hard
207

During a penetration test of a Microsoft Entra ID environment, you discover that an on-premises user account has the ms-DS-ConsistencyGuid attribute set to a value that matches the ImmutableID of a cloud user with higher privileges. What is the most likely security implication of this configuration?

Medium
208

Which THREE conditions must be met for a successful AS-REP Roasting attack?

Hard
209

When defining the 'Scope' for a penetration test, which THREE factors are critical to document to ensure the engagement is legally and operationally sound?

Medium
210

Refer to the exhibit. Which step should a tester prioritize next based on the server header information?

Medium
211

An attacker is performing reconnaissance on an Azure AD tenant and notices that 'Guest' users can enumerate the directory. Which specific setting should be checked to remediate this?

Medium
212

You are conducting an internal penetration test and have obtained a set of NTLM hashes from a compromised server. You want to crack them using Hashcat on a dedicated GPU rig. Which hash mode should you use?

Medium
213

A penetration tester is reviewing the results of a vulnerability scan and sees a finding labeled 'SSL Certificate Expired' on a web server. The tester confirms that the certificate is indeed expired. What is the most appropriate next step according to typical penetration testing methodology?

Easy
214

A penetration tester has obtained a hash from a Linux system: `$1$salt$hash`. The tester wants to crack it using John the Ripper. Which format should be specified, and what is the main weakness of this hash type?

Medium
215

What is the main risk associated with storing cleartext credentials in environment variables or configuration files?

Medium
216

Which document should a penetration tester consult to determine the allowed scope and rules of engagement for a vulnerability scan?

Easy
217

You are drafting the Rules of Engagement for an internal penetration test. Which TWO of the following items are considered mandatory for the 'Communication Plan' section?

Medium
218

During an internal penetration test, you need to sweep a /24 subnet for live hosts using Nmap. The client's security team has confirmed that ICMP echo requests are blocked at the host firewall on all workstations, but they want you to use a technique that still elicits responses from hosts that are up without relying on ICMP. Which Nmap host discovery option should you use to maximize host detection in this environment?

Medium
219

During an internal penetration test, you capture an NTLMv2 net-NTLM hash using LLMNR/NBT-NS poisoning. You attempt to crack the hash offline using Hashcat with a standard rockyou.txt wordlist, but the operation yields no plaintext. What is the most effective next step to recover the credentials given that the password complexity requirements were met?

Medium
220

Which attack type is most effective when an attacker has a list of usernames and a single password that they believe might be reused across multiple accounts?

Medium
221

You have obtained Domain Admin credentials during an internal penetration test. To ensure continued access even if the compromised user's password is changed, you decide to create a Golden Ticket. Which artifact is required to forge a Golden Ticket?

Medium
222

During a penetration test, a tester obtains a Meterpreter session on a Windows host but the session dies immediately after the initial connection. The tester suspects that the payload is being terminated by endpoint protection. Which Meterpreter feature should the tester use to migrate the session into a more stable process?

Hard
223

During an internal penetration test, an attacker intercepts an Active Directory Kerberos AS-REQ for a user account that does not have Kerberos pre-authentication enabled. What is the most effective post-exploitation technique for the operator to perform offline credential cracking against this captured artifact?

Medium
224

A penetration tester is using Nmap to scan a target network and wants to identify open UDP ports. The tester runs a UDP scan but notices that many ports are reported as 'open|filtered'. Which technique can help determine whether these ports are actually open or filtered?

Hard
225

A penetration tester is analyzing the results of a vulnerability scan and needs to prioritize remediation efforts. Which two factors should be considered when determining the criticality of a vulnerability? (Choose two.)

Medium
226

Refer to the exhibit. What does this output indicate regarding the current exploitation attempt?

Medium
227

A penetration tester is configuring an authenticated scan for a Windows environment. Which credential management strategy best minimizes the security impact while maintaining scan efficacy?

Medium
228

You are conducting an external penetration test against a client who uses a split-horizon DNS configuration. You want to identify internal hostnames and IP addresses without sending any traffic to the client's internal network. Which of the following techniques would best accomplish this?

Medium
229

During an internal penetration test, an operator intercepts an AS-REP response for a user account that does not have Kerberos pre-authentication enabled. What is the most efficient next step to recover the account password offline?

Medium
230

During an internal penetration test, you capture a NetNTLMv2 challenge-response hash from a workstation. You attempt to crack it offline using Hashcat, but after several hours with a large wordlist and rules, the hash remains uncracked. Which factor most directly determines the feasibility of cracking this hash?

Hard
231

During an internal assessment you obtain a Meterpreter session on a Windows Server 2016 host running as a low-privileged service account. You want to identify whether the host is missing security updates that could allow local privilege escalation without immediately running an exploit. Which Metasploit post-exploitation module should you use to enumerate installed hotfixes and compare them against known vulnerabilities?

Medium
232

You are setting up a C2 infrastructure for a penetration test. To protect the backend C2 server from direct exposure, you deploy a redirector. Which of the following best describes the primary function of a redirector in this context?

Medium
233

A penetration tester is configuring a vulnerability scan against a large enterprise network. The tester needs to balance scan accuracy, speed, and impact on production systems. Which TWO of the following settings, when adjusted, will MOST directly reduce the risk of disrupting fragile network devices during the scan? (Choose two.)

Hard
234

During an exploitation attempt against a web application, you inject a payload that causes the server to return a verbose error message containing a stack trace and database query. What is the most likely type of vulnerability you have discovered?

Medium
235

You are performing OSINT on a target and have collected a list of employee names from LinkedIn. You want to generate likely corporate email addresses and then verify which ones are valid without sending email to the target's mail servers. Which approach best accomplishes this?

Medium
236

During an Azure penetration test, you discover an App Registration with an expired client secret that still has active refresh tokens issued prior to expiration. The application holds high-privilege directory roles. How do these leaked refresh tokens behave regarding Azure AD security boundaries?

Medium
237

A penetration tester has obtained a set of NTLM hashes from a Windows domain controller. The tester plans to perform an offline password cracking attack. Which two of the following techniques are most effective for increasing the success rate of cracking these hashes? (Choose two.)

Medium
238

An attacker has obtained a refresh token for an Azure AD application with the 'Mail.Read' delegated permission. The token was issued to a user who has since had their password reset and all refresh tokens revoked. The attacker attempts to use the refresh token to obtain a new access token. What is the expected outcome?

Hard
239

During a penetration test on a Windows Server 2019 domain controller, you discover that the KRBTGT account password was last set 5 years ago. You extract the KRBTGT hash and create a Golden Ticket with a 10-year expiration. What is the primary reason this persistence method is particularly effective in this scenario?

Hard
240

A penetration tester is preparing to scan a network that includes a mix of traditional IT systems and industrial control systems (ICS). The tester wants to minimize the risk of disrupting ICS devices. Which scanning approach is MOST appropriate for the ICS segment?

Medium
241

Which of the following best describes the 'Gray-box' testing methodology?

Medium
242

You have obtained a Meterpreter session on a Windows 10 host as a standard user. You want to escalate privileges by exploiting a vulnerable kernel driver. Which Metasploit module category would you use to search for suitable exploits?

Easy
243

A client asks you to perform a penetration test on their web application. During the planning phase, they mention that the application is hosted on a third-party cloud provider and they do not have written permission from the provider to test the underlying infrastructure. What is the MOST appropriate action?

Easy
244

What is the primary security advantage of utilizing salts in password hashing?

Easy
245

A penetration tester has captured a set of NTLMv2 challenge-response pairs from a network segment. The tester wants to crack these hashes offline using Hashcat. Which TWO of the following statements are true regarding the cracking of NTLMv2 hashes with Hashcat? (Choose two.)

Hard
246

A penetration tester is targeting a web application that uses a custom authentication mechanism. After capturing network traffic, the tester notices that the application sends a challenge to the client and expects a response derived from the user's password. The tester wants to perform an offline brute-force attack against the captured challenge-response pairs. Which type of password attack is this?

Hard
247

A penetration tester is reviewing Kerberos traffic and notices that a user account has the DONT_REQ_PREAUTH flag set in its userAccountControl attribute. The tester wants to obtain crackable material for this account without any domain credentials. Which technique should the tester use?

Easy
248

During a penetration test, a tester extracts the SAM database from a Windows system. Which of the following tools is specifically designed to extract password hashes from the SAM file?

Easy
249

An enterprise client insists on a blind 'black-box' penetration test where the testing team receives zero prior knowledge regarding network architecture, IP ranges, or applications. However, the client's primary objective is to thoroughly test deep-seated business logic vulnerabilities within a critical custom web application. Why is this planning approach fundamentally misaligned with the client's stated objective?

Hard
250

In the context of password attacks, what is the primary purpose of a 'mask' in Hashcat?

Medium
251

An attacker has compromised an Azure App Service and obtained the application's managed identity token. They want to use it to access an Azure SQL Database. The managed identity has been granted access to the SQL server. Which of the following is the correct way to authenticate to the SQL Database using the managed identity token?

Hard
252

A penetration tester is performing an offline attack against a Kerberos TGS-REP hash obtained via Kerberoasting. Which of the following Hashcat modes should be used?

Medium
253

A penetration tester has obtained a hash from a Linux system's /etc/shadow file: $6$rounds=656000$XyZ123$... The tester wants to crack this hash using John the Ripper. Which format should be specified to John to ensure correct cracking?

Medium
254

Which of the following describes the risk associated with cached credentials in the Windows operating system during a penetration test?

Medium
255

You are performing an authorized penetration test and have established a C2 channel using HTTPS. To evade network detection, you configure your C2 beacon to use domain fronting. Which of the following best describes how domain fronting masks the true destination of your C2 traffic?

Hard
256

A penetration tester has just obtained a Meterpreter session on a Linux web server and wants to keep it active while performing other tasks in msfconsole. Which command should the tester issue to return to the msfconsole prompt while leaving the session running in the background?

Easy
257

During an authorized penetration test, you have established a C2 session using a popular framework. Your goal is to maintain persistent access to a compromised Windows host even after the user logs off or the system reboots. You decide to use a service-based persistence mechanism. Which of the following commands, when executed on the compromised host, would create a new Windows service that runs your payload at startup?

Medium
258

You are performing a penetration test on a Microsoft Entra ID tenant that uses federated authentication with Active Directory Federation Services (AD FS). You have obtained a user's credentials and want to maintain persistent access even if the user's password is changed. Which of the following methods would best achieve this?

Medium
259

You are analyzing a target environment and need to identify UDP services. Which THREE of the following are significant challenges associated with performing an accurate UDP scan compared to a TCP scan?

Hard
260

What is the primary purpose of the 'Scope' section in the Rules of Engagement?

Easy
261

A penetration tester is preparing to exploit a stack-based buffer overflow on a Linux target. The target binary has non-executable stack (NX) enabled. Which technique should the tester use to achieve code execution?

Easy
262

A penetration tester is analyzing a password hash captured from a web application's database. The hash is `5f4dcc3b5aa765d61d8327deb882cf99` and is 32 characters long. Which type of hash is this, and what is a common tool to crack it?

Easy
263

While testing a Windows 10 workstation, you find that the account you compromised belongs to the Backup Operators group. You need to escalate to local administrator without installing third-party tools on disk. Which built-in capability of this group can you abuse to obtain administrative access?

Hard
264

A penetration tester is conducting an offline password attack against a set of NTLM hashes extracted from a Windows domain. The tester wants to maximize the efficiency of the cracking process by using Hashcat. Which two techniques are most effective for this goal? (Choose two.)

Medium
265

When selecting an exploit for a target system, which TWO factors are most critical to ensure the exploit succeeds without crashing the target service?

Hard
266

During an internal penetration test, you capture NTLMv2 hashes from a network segment. You want to crack these hashes using Hashcat on a dedicated GPU rig. Which Hashcat mode number corresponds directly to the NTLMv2 hash format commonly captured via LLMNR/NBT-NS poisoning?

Medium
267

You are planning a penetration test for a financial institution that operates a large mainframe environment. The client wants to ensure that the test does not disrupt critical batch processing jobs. Which TWO of the following are the MOST important items to include in the Rules of Engagement (RoE) to address this concern? (Choose two.)

Hard
268

An attacker uses a 'redirector' in their C2 infrastructure. What is the primary purpose of this architectural component?

Hard
269

During a penetration test, you successfully obtain an encrypted NTLM hash but are unable to crack it. What is the most effective alternative strategy to gain access to the system?

Medium
270

A penetration tester is performing an offline attack against a Windows domain. They have obtained the NTDS.dit file and the SYSTEM hive. Which tool is most effective for extracting the NTLM hashes for offline cracking?

Medium
271

You have compromised a workstation and extracted the NTLM hash of a service account that is configured for unconstrained delegation. You want to craft a Silver Ticket to impersonate a domain administrator when accessing a specific file server. Which piece of information is absolutely required to forge this ticket?

Hard
272

Which of the following describes the 'AS-REP Roasting' attack?

Medium
273

Which TWO methods are commonly used to achieve C2 persistence while ensuring the communication remains resilient against infrastructure takedowns?

Hard
274

You are finalizing the Rules of Engagement (RoE) for a penetration test of a regional hospital network. The client's legal counsel requires that any testing activity be immediately suspended if a life-safety system is affected. Which element should you add to the RoE to satisfy this requirement?

Medium
275

During an Azure penetration test, you gain access to a Linux VM in a subnet that has a user-defined route forcing all traffic through a Network Virtual Appliance (NVA). You want to reach the Azure Instance Metadata Service (IMDS) to steal managed identity tokens. Which of the following best describes how you can access IMDS from this VM?

Medium
276

You are planning an external penetration test for a financial services firm. The client's legal team wants assurance that the engagement can be defended if law enforcement or regulators inquire about the testing. Which TWO of the following should be included in the Rules of Engagement to provide this assurance? (Choose two.)

Medium
277

You are performing an offline attack against a password hash stored in an NTDS.dit file. You have successfully dumped the hashes using secretsdump.py. Given the format 'Username:RID:LMHash:NTHash:::', which hash should be targeted for a modern Windows environment to maximize cracking efficiency?

Medium
278

You are conducting a penetration test against a web application. During exploitation, you identify a SQL injection vulnerability that allows you to execute arbitrary SQL queries. You want to leverage this to gain remote code execution on the underlying database server. Which TWO of the following techniques are most likely to achieve this goal? (Choose two.)

Medium
279

A penetration tester has obtained a single NT hash for a domain user account during an internal engagement. The tester wants to authenticate to a remote Windows 10 workstation as that user without knowing the plaintext password. Which tool is designed to perform this authentication using only the NT hash?

Medium
280

You are conducting an internal penetration test for a client that uses Microsoft Entra ID with on-premises Active Directory. You have obtained Domain Admin credentials in the on-premises domain. The client has deployed Microsoft Entra Connect with Seamless Single Sign-On (SSO) enabled. Which of the following actions would allow you to authenticate as any synchronized user to cloud services like Microsoft 365 WITHOUT knowing their password?

Medium
281

A penetration tester has gained a foothold on a Windows host and wants to escalate privileges. They discover that the host has an unquoted service path vulnerability. Which command should they use to identify services with unquoted paths that contain spaces?

Easy
282

Which of the following actions is the best way to detect an attacker performing an offline hash-cracking operation within a corporate network?

Medium
283

Which Kerberos feature is specifically exploited when an attacker uses 'constrained delegation' to escalate privileges?

Medium
284

During planning for a penetration test, the client states the goal is to evaluate how well the security operations center detects and responds to attacker activity. Which engagement type best aligns with this objective?

Easy
285

During a reconnaissance project, you use the 'theHarvester' tool against a target. What information is this tool designed to extract?

Medium
286

You are performing passive reconnaissance on a target organization that uses a cloud-based email service. You want to gather information about the organization's email infrastructure and potential phishing targets without alerting the target. Which TWO of the following techniques would be most effective and appropriate for this goal? (Choose two.)

Hard
287

You are tasked with gathering information about a target organization's employees to craft a phishing campaign. Which of the following tools is specifically designed to collect email addresses, subdomains, and hostnames from public sources like search engines and PGP key servers?

Easy
288

Which of the following describes the risk of 'App Role' over-assignment in Azure AD?

Medium
289

You are configuring a Cobalt Strike beacon for a penetration test. The client's security team monitors for periodic beaconing patterns. You want to reduce the chance of detection by network behavior analysis. Which beacon setting should you adjust?

Medium
290

During an assessment, you discover a federated identity setup using AD FS. What is a common security risk associated with the reliance on the token-signing certificate in this architecture?

Medium
291

Which of the following describes the 'Persistence' phase in the context of the cyber kill chain?

Easy
292

A penetration tester is reviewing an Azure Logic App that uses a managed identity to access an Azure SQL Database. The tester finds that the Logic App's workflow definition is stored in a storage account that is publicly accessible. The workflow includes a step that executes a stored procedure with parameters. Which of the following is the most significant risk of this misconfiguration?

Hard
293

During an internal penetration test, you capture an NTLMv2 hash challenge-response pair from a network segment. You want to crack the user's password using Hashcat. Which hashcat attack mode and hash format identifier should you use to crack this specific challenge-response pair efficiently on a modern GPU?

Medium
294

A penetration tester has obtained a password hash from a Windows system: `aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0`. They attempt to crack it using Hashcat with mode 1000 but are unable to recover any plaintext. What is the most likely explanation for this failure?

Medium
295

During a penetration test, you successfully inject a payload into a web application that results in the server executing system commands with elevated privileges. Which phase of the exploitation lifecycle does this action primarily represent?

Medium
296

You are conducting passive reconnaissance against a target that uses a Web Application Firewall (WAF) and a Content Delivery Network (CDN). You want to discover the origin IP address of the web server to bypass the CDN during later testing. Which technique is most likely to reveal the origin IP without sending any traffic to the target's domain?

Medium
297

You are using Cobalt Strike in an authorized penetration test. The target network uses a next-generation firewall that performs SSL inspection and blocks self-signed certificates. You need to configure your HTTPS beacon to blend in with legitimate traffic and avoid detection. (Choose two.)

Hard
298

During an authorized penetration test, you have gained a low-privileged shell on a Linux host. You discover that the kernel is version 4.4.0-116-generic and the system is missing several patches. You want to escalate privileges to root. Which of the following is the most reliable and safe method to achieve privilege escalation?

Hard

Frequently asked questions

What does the scenario questions domain cover on the GPEN exam?
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 298 scenario questions questions in the GPEN question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only scenario questions questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.