GPEN Escalation and Exploitation Practice Question
During a Windows assessment you obtain a low-privileged domain user's credentials. Enumeration reveals a Group Policy Preference file on a readable SYSVOL share containing a cpassword value. What is the most effective next step to escalate privileges?
⚠ Common exam trap
The trap here is treating the cpassword value as a hash that must be cracked or relayed, when it is reversibly encrypted with a public key.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Decrypt the cpassword value using the publicly known AES key and authenticate as the account it protects.
Credentials in Group Policy Preferences were encrypted with a static AES key that Microsoft published, so a cpassword value found on SYSVOL can be decrypted immediately with tools like gpp-decrypt. The recovered plaintext often belongs to a privileged account, and because no cracking or protocol interaction is required, decryption is the fastest route to privilege escalation from the low-privileged credentials already held.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Decrypt the cpassword value using the publicly known AES key and authenticate as the account it protects.
Why this is correct
Group Policy Preferences stored credentials in cpassword fields encrypted with a static AES key that Microsoft published in MS14-025 documentation. Tools such as gpp-decrypt recover the plaintext instantly, and the recovered credential often belongs to a privileged account. Because the key is fixed and public, no cracking is required, making decryption the direct and effective escalation step.
- ✗
Crack the cpassword value with hashcat using the NTLM hash mode.
Why it's wrong here
The cpassword field is not an NTLM hash and is not processed by hashcat's NTLM mode. It is AES-encrypted with a static key, so treating it as a crackable hash misidentifies the data format. Even if cracking were attempted, it would be unnecessary because the encryption key is publicly known and decryption is immediate.
- ✗
Relay the cpassword value to an SMB service to obtain a session on a file server.
Why it's wrong here
Relaying requires a live NetNTLM authentication from a victim, not a static encrypted value found in a file. The cpassword blob cannot be replayed as an authentication because it is not a protocol response. Recommending relay confuses stored-credential recovery with an active man-in-the-middle technique and would not produce a session.
- ✗
Use the cpassword value directly in a pass-the-hash authentication against a domain controller.
Why it's wrong here
Pass-the-hash requires an NT hash in the LM:NT format, which cpassword is not. The cpassword string is an encrypted credential blob, not a hash accepted by NTLM authentication. Attempting to pass it directly will fail, and the correct approach is to decrypt it first to recover the underlying plaintext password before authenticating.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
About these practice questions
One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.