Courseiva
Exploitation Fundamentals →mediumMultiple Choice

GPEN Exploitation Fundamentals Practice Question

Exhibit

HTTP/1.1 200 OK
Content-Type: text/html
Server: Apache/2.4.41 (Ubuntu)

<html>...</html>

Refer to the exhibit. Which step should a tester prioritize next based on the server header information?

⚠ Common exam trap

Testers often attempt to brute-force or perform manual discovery before checking for known CVEs, wasting time on manual enumeration when a simple version-based exploit search would suffice.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Search for known vulnerabilities for Apache 2.4.41.

The server header indicates a specific version of Apache running on Ubuntu. A tester should cross-reference this version with known vulnerabilities, such as CVEs in the Apache HTTP Server. This is a foundational step in identifying applicable exploits. Knowing the specific version allows for targeted research into public or private exploit modules, increasing the probability of a successful engagement by focusing on documented, verifiable weaknesses within that specific software build.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run a brute-force password attack against the server.

    Why it's wrong here

    Brute-forcing should not be the immediate next step. Exploiting known software vulnerabilities discovered via banner grabbing is generally more effective and less noisy than credential stuffing. Relying on software flaws is a more precise approach that requires less time and minimizes the risk of account lockouts.

  • ✓

    Search for known vulnerabilities for Apache 2.4.41.

    Why this is correct

    Identifying the service and version is a prerequisite for vulnerability research. By mapping this version to known security advisories or CVE databases, a tester can determine if public exploits exist for this specific configuration, effectively narrowing the attack surface to the most likely points of failure.

  • ✗

    Immediately deploy a rootkit on the server.

    Why it's wrong here

    Deploying a rootkit without initial access or a confirmed vulnerability is impossible. Rootkits require existing administrative or system-level access to install. A tester must first identify a vulnerability and successfully exploit it before considering post-exploitation persistence mechanisms like rootkits, which are highly invasive and easily detected.

  • ✗

    Close the connection and report the server as secure.

    Why it's wrong here

    The presence of a specific version number is a potential information disclosure vulnerability itself, and certainly not an indication of security. Assuming a server is secure just because it responds correctly is dangerous, as many services with known vulnerabilities appear to function normally until exploited.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.