Sample questions
GIAC Penetration Tester practice questions
Which THREE of the following are valid methods to mitigate the risk of password spray attacks in an integrated Azure AD environment?
What is the main risk associated with storing cleartext credentials in environment variables or configuration files?
Which document should a penetration tester consult to determine the allowed scope and rules of engagement for a vulnerability scan?
What is the primary risk associated with storing credentials in plain text within scripts or configuration files?
During an internal penetration test, an attacker successfully captures an NTLMv2 challenge-response authentication exchange from a network segment. The adversary wishes to perform…
Which TWO of the following are characteristics of 'Salted' hashes compared to 'Unsalted' hashes?
During a penetration test, you successfully dump the LSASS memory space and extract a set of NTLM hashes. Which of the following is the most efficient next step if the goal is to d…
Refer to the exhibit. What does the Nmap status 'open|filtered' indicate about the target port, and why does this result commonly occur in penetration testing scenarios?
You are analyzing the results of a passive reconnaissance scan using a tool that harvests metadata from files found on a company website. What is the primary security risk associat…
Which of the following is the most effective way to detect C2 beacons that use jitter and randomized timing?
Which document is primarily responsible for defining the 'Rules of Engagement' (RoE) in a penetration testing project?
During an internal penetration test, you capture an NTLMv2 net-NTLM hash using LLMNR/NBT-NS poisoning. You attempt to crack the hash offline using Hashcat with a standard rockyou.t…
You are performing a penetration test against a web server and want to identify the exact version of the HTTP service running on port 80. Which Nmap command should you use?
What is the primary benefit of using passive reconnaissance before initiating active scanning?
Which command in the Metasploit Framework allows a user to interact with a backgrounded session after a successful exploit execution?
A penetration tester is configuring an authenticated scan for a Windows environment. Which credential management strategy best minimizes the security impact while maintaining scan…
During an internal penetration test, an attacker intercepts an Active Directory Kerberos AS-REQ for a user account that does not have Kerberos pre-authentication enabled. What is t…
A penetration tester is using Nmap to scan a target network and wants to identify open UDP ports. The tester runs a UDP scan but notices that many ports are reported as 'open|filte…
A penetration tester is analyzing the results of a vulnerability scan and needs to prioritize remediation efforts. Which two factors should be considered when determining the criti…
During a penetration test, you successfully inject a payload into a web application that results in the server executing system commands with elevated privileges. Which phase of th…
You are conducting an external penetration test against a client who uses a split-horizon DNS configuration. You want to identify internal hostnames and IP addresses without sendin…
During an internal penetration test, an operator intercepts an AS-REP response for a user account that does not have Kerberos pre-authentication enabled. What is the most efficient…
Refer to the exhibit. During an Azure engagement, you query a service principal via the Microsoft Graph API and notice that 'appRoleAssignmentRequired' is set to 'false'. What secu…
A penetration tester is configuring a vulnerability scan against a large enterprise network. The tester needs to balance scan accuracy, speed, and impact on production systems. Whi…