Courseiva
Reconnaissance →mediumMultiple Choice

GPEN Reconnaissance Practice Question

During the reconnaissance phase, you notice a target is using an older, unpatched version of a popular CMS. What is the most appropriate next step?

⚠ Common exam trap

Examinees often jump straight to exploiting or aggressively scanning the CMS, forgetting that the proper reconnaissance step is to research known CVEs first.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Research known CVEs for the identified version.

Identifying a vulnerable version of a CMS is a major reconnaissance success. The next step is to research known vulnerabilities (CVEs) associated with that version. This allows the tester to plan an exploit strategy without immediately running active, loud scans that might tip off the security team. This measured approach ensures that the eventual attack is precise, efficient, and well-supported by prior intelligence gathering efforts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Immediately run a Metasploit exploit module against the server.

    Why it's wrong here

    Launching an exploit before fully understanding the risk and testing environment is reckless. It could crash the service or trigger an alert without having a secondary plan. Reconnaissance should lead to structured research, where the tester understands the vulnerability before attempting to exploit it in a controlled manner.

  • ✓

    Research known CVEs for the identified version.

    Why this is correct

    Researching specific CVEs for the identified CMS version allows the tester to understand the vulnerability's nature and impact. This information is crucial for planning a safe and effective exploitation strategy. It ensures that the subsequent testing phase is focused on valid attack vectors, minimizing the risk of unnecessary system downtime.

  • ✗

    Contact the organization's IT department to report the vulnerability.

    Why it's wrong here

    A penetration tester is hired to test the security of an organization, not to provide immediate remediation services during the reconnaissance phase. Reporting the issue directly is outside the scope of the engagement contract unless specifically requested by the client. The tester must follow the agreed-upon reporting process.

  • ✗

    Ignore the CMS and look for other systems.

    Why it's wrong here

    An unpatched CMS is a significant finding that could provide an easy initial foothold into the target's network. Ignoring it is a missed opportunity for a thorough assessment. Every discovered vulnerability should be documented and evaluated for its potential to contribute to the overall success of the test.

About these practice questions

This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.