Courseiva
← Back to GIAC Penetration Tester questions

Scenario-based practice

Refer to the Exhibit Practice Questions

Practise GIAC Penetration Tester practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

15
scenario questions
GPEN
exam code
GIAC
vendor

Scenario guide

How to approach refer to the exhibit practice questions

Practise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer.

Quick answer

Exhibit-style questions test whether you can read a topology, command output, diagram or table before choosing the best answer.

How to extract the relevant detail from an exhibit.

How topology, command output or routing information affects the answer.

How to avoid answering from memory before reading the evidence.

How to map the exhibit back to the exam objective.

Related practice questions

Related GPEN topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

Refer to the exhibit. What does the Nmap status 'open|filtered' indicate about the target port, and why does this result commonly occur in penetration testing scenarios?

Exhibit

Nmap scan report for 10.0.0.1
PORT STATE SERVICE
80/tcp open|filtered http
Question 2mediummultiple choice
Full question →

Refer to the exhibit. During an Azure engagement, you query a service principal via the Microsoft Graph API and notice that 'appRoleAssignmentRequired' is set to 'false'. What security implication does this setting present for enterprise applications?

Network Topology
az restmethod GETurl "https://graph.microsoft.com/v1.0/servicePrincipals?$filter=appId eq '1bfefa11-0000-0000-0000-000000000000'""value": ["id": "c2d3e4f5-1111-2222-3333-444455556666","appId": "1bfefa11-0000-0000-0000-000000000000","displayName": "Azure AD PowerShell","appRoleAssignmentRequired": false,"servicePrincipalType": "Application"
Question 3mediummultiple choice
Full question →

Refer to the exhibit. What is the primary purpose of the 'jitter' parameter in this C2 configuration?

Exhibit

C2-Policy: { 'method': 'HTTPS', 'beacon_interval': '60s', 'jitter': '20%', 'encoding': 'base64', 'user_agent': 'Mozilla/5.0 (Windows NT 10.0)' }
Question 4mediummultiple choice
Full question →

Refer to the exhibit. Which step should a tester prioritize next based on the server header information?

Exhibit

HTTP/1.1 200 OK
Content-Type: text/html
Server: Apache/2.4.41 (Ubuntu)

<html>...</html>
Question 5mediummultiple choice
Full question →

Refer to the exhibit. What does this output indicate regarding the current exploitation attempt?

Exhibit

Error: Segmentation Fault (core dumped)
Stack Pointer: 0x7fffffffe000
Instruction Pointer: 0x41414141
Question 6mediummultiple choice
Full question →

Refer to the exhibit. What does this error log suggest regarding the C2 connection attempt?

Exhibit

Error Log: [2023-10-12 14:02:11] SSL_connect failed: error:14094418:SSL routines:ssl3_read_bytes:tlsv1 alert unknown ca
Question 7mediummultiple choice
Full question →

Refer to the exhibit. An Nmap scan returns output indicating a web server is responding, but the `http-enum` script fails to identify common directories. Which action should the tester take to improve detection?

Network Topology
nmap -sV -p 80script=http-enum
Question 8hardmultiple choice
Full question →

Refer to the exhibit. What is the most likely cause of the 'Connection reset by peer' error when using the PsExec module?

Exhibit

msf6 exploit(windows/smb/psexec) > set RHOSTS 10.10.10.5
msf6 exploit(windows/smb/psexec) > set SMBUser admin
msf6 exploit(windows/smb/psexec) > set SMBPass 328d3f1c12d2...[truncated]
msf6 exploit(windows/smb/psexec) > run
[*] Started reverse TCP handler on 10.10.10.2:4444
[*] 10.10.10.5:445 - Connecting to the target...
[*] 10.10.10.5:445 - Authenticating with 10.10.10.5:445 as user 'admin'...
[-] 10.10.10.5:445 - Exploit failed: RubySMB::Error::CommunicationError: Connection reset by peer
Question 9hardmultiple choice
Full question →

Refer to the exhibit. You are currently at 17:15. You have just identified a critical, easily exploitable vulnerability on 10.1.1.20. What is the correct next step?

Exhibit

CLIENT_CONFIG: { "Targets": ["10.1.1.0/24"], "Blacklist": ["10.1.1.5"], "Testing_Time": "08:00 - 17:00", "Reporting": "Weekly", "Escalation": "Emergency_Contact_Form" }
Question 10hardmultiple choice
Full question →

Refer to the exhibit. Given the output from Mimikatz, what is the most appropriate interpretation of the 'LM NTLM' value provided for the administrator account?

Exhibit

C:\> mimikatz.exe

mimikatz # privilege::debug
Privilege '20' OK

mimikatz # sekurlsa::logonpasswords

[...]
Authentication Id : 0 ; 123456 (00000000:0001e240)
Session           : Interactive from 1
User Name         : admin
Domain            : CORP
Logon Server      : DC01
LM NTLM           : a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6
Question 11mediummultiple choice
Full question →

Refer to the exhibit. Given this output, which action is most appropriate for a penetration tester?

Exhibit

C:\> whoami /priv

PRIVILEGES INFORMATION
----------------------

Privilege Name           Description                          State
======================== ==================================== ========
SeDebugPrivilege         Debug programs and processes         Enabled
Question 12hardmultiple choice
Full question →

Refer to the exhibit. You executed an Nmap scan against a host and received the output shown. Which scanning technique was most likely used to produce this specific state-based output while avoiding the completion of a full TCP three-way handshake?

Exhibit

Starting Nmap 7.92 at 2023-10-01 10:00 UTC
Nmap scan report for 192.168.1.10
Host is up (0.0012s latency).
PORT   STATE SERVICE
22/tcp open  ssh
80/tcp open  http
443/tcp open https
Question 13hardmultiple choice
Full question →

Refer to the exhibit. What is the primary purpose of the Nmap Scripting Engine (NSE) in the context of the output provided, and how does it improve upon standard port scanning?

Exhibit

Starting Nmap 7.92
NSE: Loaded 145 scripts for scanning.
NSE: Script scan: 192.168.1.5:80 -> GET / HTTP/1.0
PORT STATE SERVICE
80/tcp open http
|_http-title: Site under construction
Question 14mediummultiple choice
Full question →

Refer to the exhibit. Why did the EternalBlue exploit attempt fail despite the scanner identifying the target as vulnerable?

Exhibit

msf6 > search type:exploit platform:windows smb
msf6 > use exploit/windows/smb/ms17_010_eternalblue
msf6 exploit(windows/smb/ms17_010_eternalblue) > set RHOSTS 192.168.1.50
msf6 exploit(windows/smb/ms17_010_eternalblue) > exploit
[*] Started reverse TCP handler on 192.168.1.10:4444
[*] 192.168.1.50:445 - Using auxiliary/scanner/smb/smb_ms17_010 as check
[*] 192.168.1.50:445 - Host is likely VULNERABLE to MS17-010!
[*] 192.168.1.50:445 - Scanned 1 of 1 hosts (1 succeeded to be vulnerable)
[*] 192.168.1.50:445 - Starting exploit
[!] Error: Exploit failed: The target is not exploitable.
Question 15hardmultiple choice
Full question →

Refer to the exhibit. You are performing a penetration test based on this policy. You discover an unpatched SQL injection vulnerability on 192.168.10.20 that could be used to trigger a database lock-up. What is the most appropriate course of action?

Exhibit

TARGET_POLICY: { "Scope": ["192.168.10.0/24"], "Exclusions": ["192.168.10.50"], "Methodology": "Black-box", "Testing_Window": "2023-10-01 to 2023-10-05", "Allowed_Attacks": ["Injection", "XSS"], "Forbidden_Attacks": ["DoS", "Social_Engineering"] }

These GPEN practice questions are part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style GPEN questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.