Courseiva
← Back to GIAC Penetration Tester questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise GIAC Penetration Tester practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
GPEN
exam code
GIAC
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related GPEN topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmulti select
Full question →

Which THREE of the following are valid methods to mitigate the risk of password spray attacks in an integrated Azure AD environment?

Question 2mediummulti select
Full question →

Which TWO of the following are characteristics of 'Salted' hashes compared to 'Unsalted' hashes?

Question 3mediummulti select
Full question →

A penetration tester is analyzing the results of a vulnerability scan and needs to prioritize remediation efforts. Which two factors should be considered when determining the criticality of a vulnerability? (Choose two.)

Question 4hardmulti select
Full question →

A penetration tester is configuring a vulnerability scan against a large enterprise network. The tester needs to balance scan accuracy, speed, and impact on production systems. Which TWO of the following settings, when adjusted, will MOST directly reduce the risk of disrupting fragile network devices during the scan? (Choose two.)

Question 5hardmulti select
Full question →

A penetration tester has captured a set of NTLMv2 challenge-response pairs from a network segment. The tester wants to crack these hashes offline using Hashcat. Which TWO of the following statements are true regarding the cracking of NTLMv2 hashes with Hashcat? (Choose two.)

Question 6hardmulti select
Full question →

You are analyzing a target environment and need to identify UDP services. Which THREE of the following are significant challenges associated with performing an accurate UDP scan compared to a TCP scan?

Question 7hardmulti select
Full question →

When selecting an exploit for a target system, which TWO factors are most critical to ensure the exploit succeeds without crashing the target service?

Question 8hardmulti select
Full question →

You are planning a penetration test for a financial institution that operates a large mainframe environment. The client wants to ensure that the test does not disrupt critical batch processing jobs. Which TWO of the following are the MOST important items to include in the Rules of Engagement (RoE) to address this concern? (Choose two.)

Question 9hardmulti select
Full question →

During a red team engagement, an operator successfully dumps the LSA secrets and NTDS.dit database from a Windows domain controller. Which TWO advanced password extraction and analysis techniques should the operator prioritize to uncover administrative access vectors? (Choose two)

Question 10mediummulti select
Full question →

You are drafting the Rules of Engagement for an internal penetration test. Which TWO of the following items are considered mandatory for the 'Communication Plan' section?

Question 11mediummulti select
Full question →

Which TWO of the following scenarios are most indicative of a successful Kerberoasting attack occurring within a network?

Question 12mediummulti select
Full question →

A penetration tester has obtained a set of NTLM hashes from a Windows domain controller. The tester plans to perform an offline password cracking attack. Which two of the following techniques are most effective for increasing the success rate of cracking these hashes? (Choose two.)

Question 13hardmulti select
Full question →

You are conducting passive reconnaissance against a target organization and want to identify internet-facing systems and services without sending any packets to the target's own IP space. Which two techniques best satisfy this requirement? (Choose two.)

Question 14hardmulti select
Full question →

You are performing a penetration test against a Windows domain and have obtained domain user credentials. You want to identify which domain controllers are vulnerable to a specific privilege escalation technique. Which TWO tools or techniques are most appropriate for enumerating domain controllers and their potential vulnerabilities? (Choose two.)

Question 15mediummulti select
Full question →

You are planning an external penetration test for a financial services firm. The client's legal team wants assurance that the engagement can be defended if law enforcement or regulators inquire about the testing. Which TWO of the following should be included in the Rules of Engagement to provide this assurance? (Choose two.)

Question 16mediummulti select
Review the full subnetting walkthrough →

A penetration tester is preparing to run a credentialed vulnerability scan against a mixed environment of Windows Server 2019 and Ubuntu 20.04 hosts on an internal /24 subnet. The tester wants to reduce scan duration and network load while still detecting missing patches and misconfigurations. Which two scanning techniques should the tester implement to achieve these goals? (Choose two.)

Question 17mediummulti select
Full question →

You are performing a penetration test against a web server that is protected by a network-based intrusion prevention system (IPS). You need to conduct a port scan while minimizing the chance of being blocked. Which two Nmap options should you use to evade the IPS? (Choose two.)

Question 18mediummulti select
Full question →

A penetration tester is conducting an offline password attack against a set of NTLM hashes extracted from a Windows domain. The tester wants to maximize the efficiency of the cracking process by using Hashcat. Which two techniques are most effective for this goal? (Choose two.)

Question 19hardmulti select
Full question →

A penetration tester is preparing to crack a set of NTLM hashes obtained from a Windows domain controller. The tester wants to maximize the chances of recovering plaintext passwords. Which TWO of the following techniques are most effective for this goal? (Choose two.)

Question 20hardmulti select
Full question →

A penetration tester is planning a vulnerability scan of a network that includes legacy systems and IoT devices. The tester needs to minimize the risk of disrupting these fragile devices while still gathering useful vulnerability data. Which two actions should the tester take? (Choose two.)

These GPEN practice questions are part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style GPEN questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.