GPEN Pen Test Planning Practice Question
Exhibit
TARGET_POLICY: { "Scope": ["192.168.10.0/24"], "Exclusions": ["192.168.10.50"], "Methodology": "Black-box", "Testing_Window": "2023-10-01 to 2023-10-05", "Allowed_Attacks": ["Injection", "XSS"], "Forbidden_Attacks": ["DoS", "Social_Engineering"] }Refer to the exhibit. You are performing a penetration test based on this policy. You discover an unpatched SQL injection vulnerability on 192.168.10.20 that could be used to trigger a database lock-up. What is the most appropriate course of action?
⚠ Common exam trap
Candidates often prioritize the technical 'proof of concept' by exploiting the vulnerability, forgetting that the Rules of Engagement explicitly prohibit any activity that causes a Denial of Service.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Document the vulnerability and the risk of DoS without exploitation.
Adhering strictly to the defined scope and allowed attack types is the cornerstone of professional pentesting. Since 'DoS' is explicitly forbidden, any exploit that causes service instability must be avoided. The tester must report the vulnerability as a high-risk finding without executing the destructive payload, as the client's policy prioritizes service availability over demonstrating the full potential of an exploit that risks system uptime.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Execute the SQL injection to prove the vulnerability exists.
Why it's wrong here
Executing an exploit that causes a database lock-up directly violates the 'Forbidden_Attacks' clause regarding DoS. Even if the intent is to prove the vulnerability, the resulting service interruption is unacceptable under the provided policy, and the tester would be liable for the resulting business impact.
- ✓
Document the vulnerability and the risk of DoS without exploitation.
Why this is correct
Reporting the vulnerability without exploiting it respects the 'Forbidden_Attacks' constraint. This allows the client to understand the risk and patch the issue without suffering the downtime associated with a successful exploitation. It demonstrates professional judgment by balancing the need for security assessment with operational constraints.
- ✗
Attempt the exploit on the excluded host 192.168.10.50 to see if it is vulnerable.
Why it's wrong here
The host 192.168.10.50 is explicitly listed in the 'Exclusions' field of the policy. Any interaction with this host, regardless of the vulnerability detected, constitutes a breach of the scope, which can lead to significant legal and professional repercussions for the testing team and the firm.
- ✗
Extend the testing window to allow for a safer, non-disruptive exploit.
Why it's wrong here
Extending the testing window without explicit written approval from the client is a violation of the project constraints. The methodology and timeline must be strictly followed, and modifying them unilaterally is unprofessional. The priority should always be reporting the finding within the constraints defined in the policy.
About these practice questions
Courseiva writes every GPEN question from scratch — 298 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.