Courseiva
← Back to GIAC Penetration Tester questions

Scenario-based practice

Hard Difficulty Questions

Practise GIAC Penetration Tester practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
GPEN
exam code
GIAC
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related GPEN topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmulti select
Full question →

Which THREE of the following are valid methods to mitigate the risk of password spray attacks in an integrated Azure AD environment?

Question 2hardmultiple choice
Full question →

Refer to the exhibit. What does the Nmap status 'open|filtered' indicate about the target port, and why does this result commonly occur in penetration testing scenarios?

Exhibit

Nmap scan report for 10.0.0.1
PORT STATE SERVICE
80/tcp open|filtered http
Question 3hardmultiple choice
Full question →

You are analyzing the results of a passive reconnaissance scan using a tool that harvests metadata from files found on a company website. What is the primary security risk associated with this information disclosure?

Question 4hardmultiple choice
Full question →

A penetration tester is using Nmap to scan a target network and wants to identify open UDP ports. The tester runs a UDP scan but notices that many ports are reported as 'open|filtered'. Which technique can help determine whether these ports are actually open or filtered?

Question 5hardmulti select
Full question →

You have successfully obtained a copy of the NTDS.dit database and the SYSTEM registry hive during a domain controller compromise. Which TWO tools can you use offline to extract the password hashes from these files without relying on living-off-the-land binaries on a live system? (Choose TWO)

Question 6hardmultiple choice
Full question →

An attacker compromises a web application hosted in Azure App Service that utilizes a system-assigned managed identity to connect to an Azure SQL Database. How can the attacker pivot from the compromised web app to extract secrets or access backend resources?

Question 7hardmulti select
Full question →

A penetration tester is configuring a vulnerability scan against a large enterprise network. The tester needs to balance scan accuracy, speed, and impact on production systems. Which TWO of the following settings, when adjusted, will MOST directly reduce the risk of disrupting fragile network devices during the scan? (Choose two.)

Question 8hardmultiple choice
Full question →

You have gained execution on a workstation where a global administrator previously ran Azure CLI commands, leaving residual authentication tokens in the local user profile cache. You locate the refresh token files. What is the primary operational security limitation an attacker faces when attempting to replay these stolen Microsoft Entra ID refresh tokens from an external infrastructure IP address?

Question 9hardmulti select
Full question →

A penetration tester has captured a set of NTLMv2 challenge-response pairs from a network segment. The tester wants to crack these hashes offline using Hashcat. Which TWO of the following statements are true regarding the cracking of NTLMv2 hashes with Hashcat? (Choose two.)

Question 10hardmultiple choice
Full question →

An enterprise client insists on a blind 'black-box' penetration test where the testing team receives zero prior knowledge regarding network architecture, IP ranges, or applications. However, the client's primary objective is to thoroughly test deep-seated business logic vulnerabilities within a critical custom web application. Why is this planning approach fundamentally misaligned with the client's stated objective?

Question 11hardmultiple choice
Full question →

An attacker has compromised an Azure App Service and obtained the application's managed identity token. They want to use it to access an Azure SQL Database. The managed identity has been granted access to the SQL server. Which of the following is the correct way to authenticate to the SQL Database using the managed identity token?

Question 12hardmulti select
Full question →

You are analyzing a target environment and need to identify UDP services. Which THREE of the following are significant challenges associated with performing an accurate UDP scan compared to a TCP scan?

Question 13hardmulti select
Full question →

When selecting an exploit for a target system, which TWO factors are most critical to ensure the exploit succeeds without crashing the target service?

Question 14hardmulti select
Full question →

You are planning a penetration test for a financial institution that operates a large mainframe environment. The client wants to ensure that the test does not disrupt critical batch processing jobs. Which TWO of the following are the MOST important items to include in the Rules of Engagement (RoE) to address this concern? (Choose two.)

Question 15hardmultiple choice
Full question →

You have compromised a workstation and extracted the NTLM hash of a service account that is configured for unconstrained delegation. You want to craft a Silver Ticket to impersonate a domain administrator when accessing a specific file server. Which piece of information is absolutely required to forge this ticket?

Question 16hardmultiple choice
Full question →

Which TWO methods are commonly used to achieve C2 persistence while ensuring the communication remains resilient against infrastructure takedowns?

Question 17hardmultiple choice
Full question →

A penetration tester is reviewing an Azure Logic App that uses a managed identity to access an Azure SQL Database. The tester finds that the Logic App's workflow definition is stored in a storage account that is publicly accessible. The workflow includes a step that executes a stored procedure with parameters. Which of the following is the most significant risk of this misconfiguration?

Question 18hardmultiple choice
Full question →

During a penetration test for a multinational retailer, you discover that a legacy internal application in scope contains a hardcoded credential that also grants access to a payment processing system the client explicitly excluded from testing. You have not yet used the credential. What is the MOST appropriate course of action?

Question 19hardmulti select
Full question →

During a red team engagement, an operator successfully dumps the LSA secrets and NTDS.dit database from a Windows domain controller. Which TWO advanced password extraction and analysis techniques should the operator prioritize to uncover administrative access vectors? (Choose two)

Question 20hardmulti select
Full question →

Which TWO of the following are valid methods to identify Azure AD applications that have excessive permissions in a production environment?

These GPEN practice questions are part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style GPEN questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.