Courseiva

GPEN Escalation and Exploitation Practice Question

During a Windows assessment you obtain a low-privileged domain user's credentials. Enumeration reveals a Group Policy Preference file on a readable SYSVOL share containing a cpassword value. What is the most effective next step to escalate privileges?

⚠ Common exam trap

The trap here is treating the cpassword value as a hash that must be cracked or relayed, when it is reversibly encrypted with a public key.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Decrypt the cpassword value using the publicly known AES key and authenticate as the account it protects.

Credentials in Group Policy Preferences were encrypted with a static AES key that Microsoft published, so a cpassword value found on SYSVOL can be decrypted immediately with tools like gpp-decrypt. The recovered plaintext often belongs to a privileged account, and because no cracking or protocol interaction is required, decryption is the fastest route to privilege escalation from the low-privileged credentials already held.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Decrypt the cpassword value using the publicly known AES key and authenticate as the account it protects.

    Why this is correct

    Group Policy Preferences stored credentials in cpassword fields encrypted with a static AES key that Microsoft published in MS14-025 documentation. Tools such as gpp-decrypt recover the plaintext instantly, and the recovered credential often belongs to a privileged account. Because the key is fixed and public, no cracking is required, making decryption the direct and effective escalation step.

  • ✗

    Crack the cpassword value with hashcat using the NTLM hash mode.

    Why it's wrong here

    The cpassword field is not an NTLM hash and is not processed by hashcat's NTLM mode. It is AES-encrypted with a static key, so treating it as a crackable hash misidentifies the data format. Even if cracking were attempted, it would be unnecessary because the encryption key is publicly known and decryption is immediate.

  • ✗

    Relay the cpassword value to an SMB service to obtain a session on a file server.

    Why it's wrong here

    Relaying requires a live NetNTLM authentication from a victim, not a static encrypted value found in a file. The cpassword blob cannot be replayed as an authentication because it is not a protocol response. Recommending relay confuses stored-credential recovery with an active man-in-the-middle technique and would not produce a session.

  • ✗

    Use the cpassword value directly in a pass-the-hash authentication against a domain controller.

    Why it's wrong here

    Pass-the-hash requires an NT hash in the LM:NT format, which cpassword is not. The cpassword string is an encrypted credential blob, not a hash accepted by NTLM authentication. Attempting to pass it directly will fail, and the correct approach is to decrypt it first to recover the underlying plaintext password before authenticating.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.