Courseiva

GPEN · topic practice

Escalation and Exploitation practice questions

This GPEN domain covers turning limited access into root or SYSTEM: kernel exploits, Windows privilege abuse, and service misconfigurations. Questions are scenario-based, asking you to pick the correct escalation path, tool, or built-in Windows feature, and to recognize why an action is risky or destructive during a sanctioned penetration test.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Escalation and Exploitation

What the exam tests

What to know about Escalation and Exploitation

Given a foothold, identify the fastest reliable path to root or SYSTEM using the target's own features, then execute it without destabilizing the host. The critical skill is matching the misconfiguration or privilege to the correct built-in escalation technique.

Kernel exploit risk: crashes, instability, and potential denial of service on production hosts

SQL injection to RCE via xp_cmdshell on Microsoft SQL Server

Windows Backup Operators abusing SeBackupPrivilege and built-in utilities like robocopy or diskshadow

Linux cron jobs running writable scripts as root for privilege escalation

Watch out for

Common Escalation and Exploitation exam traps

  • ▸Running kernel exploits on production without confirming the exact kernel build and having a rollback plan, causing crashes.
  • ▸Assuming Backup Operators can read files directly; the privilege must be enabled and used via a backup-aware tool.
  • ▸Overlooking that xp_cmdshell is disabled by default and requires sysadmin rights or sp_configure to re-enable.

Practice set

Escalation and Exploitation questions

20 questions · select your answer, then reveal the explanation

During an internal network penetration test, you compromise a Linux workstation and discover plaintext credentials for a domain service account cached in memory. You want to move laterally to a critical database server using Pass-the-Hash without triggering Kerberos logging anomalies. Which technique is most appropriate for establishing this lateral movement?

You are assessing a Linux web server and have discovered a local file inclusion (LFI) vulnerability in a parameter used to load template files. The application runs with standard web user privileges, but you notice that cron is executing a script owned by root every minute. How can you leverage this situation for privilege escalation?

During an assessment of a corporate Active Directory environment, you discover that a user account has the GenericAll access right over a specific security group. What does this permission enable the penetration tester to achieve?

You are performing a post-exploitation task on a Windows host and successfully obtain a user's cleartext password from LSASS memory. Which technique is most appropriate to leverage this credential to move laterally to a remote target using only standard Windows authentication protocols?

Which TWO of the following Linux configuration files or directories, if writable by a low-privileged user, represent a critical privilege escalation vector?

When attempting to escalate privileges on a Windows system, what is the significance of the 'AlwaysInstallElevated' registry setting?

Which THREE of the following are common indicators that a service is vulnerable to an Unquoted Service Path escalation attack?

While exploiting a vulnerable web application on a Windows host, you achieve remote code execution and want to establish a reliable, encrypted command-and-control channel that survives intermittent connectivity. Which Meterpreter payload characteristic best supports this requirement?

During a penetration test on a Windows Server 2019 host, you gain a low-privileged shell as the user 'webuser'. You discover that the service 'Apache2.4' runs as LocalSystem and its binary path is 'C:\Program Files\Apache Group\Apache2\bin\httpd.exe'. You have write access to the 'C:\Program Files\Apache Group\Apache2\bin' directory. What is the most reliable way to escalate privileges to SYSTEM?

You have a Meterpreter session on a Windows host running as a service account with SeImpersonatePrivilege enabled. You want to elevate to SYSTEM. Which two techniques are valid for abusing this privilege on a modern Windows system? (Choose two.)

You have gained access to a Windows domain workstation as a standard user. You discover that the user account has the 'SeImpersonatePrivilege' enabled. Which technique can you use to escalate privileges to SYSTEM?

During an internal penetration test you compromise a Linux host and obtain a low-privileged shell. You notice that the current user belongs to the docker group. What is the most direct way to escalate to root on this host?

You have a low-privileged shell on a Windows Server 2019 host. Enumeration shows the machine has the SeImpersonatePrivilege assigned to your service account and runs an outdated build. Which TWO techniques are most appropriate to escalate to SYSTEM? (Choose two.)

While exploiting a Linux web application, you find a page that passes a user-supplied filename directly to a PHP include() call. You want to convert this local file inclusion into remote code execution. Which approach is most reliable?

You have gained standard user execution rights on a hardened Windows 10 enterprise workstation and need to enumerate local privilege escalation vectors. Which TWO methods are most effective for identifying insecure file permissions or unquoted service paths? (Choose two)

You have identified an SUID binary on a Linux system that executes a shell command without using an absolute path. What is the most effective way to exploit this for privilege escalation?

During a penetration test, you successfully exploit a web application via SQL injection. You want to use this access to achieve remote code execution (RCE) on the underlying Windows database server. Which feature should you look for to facilitate this?

Which of the following is a primary goal during the 'Exploitation' phase of a penetration test?

You are performing a penetration test and discover a service running as SYSTEM that is vulnerable to DLL hijacking. What is the most appropriate action to take to ensure the test is successful and safe?

When escalating privileges using a Kernel exploit, why is it considered a high-risk activity for a penetration test?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Escalation and Exploitation sessions

Start a Escalation and Exploitation only practice session

Every question in these sessions is drawn from the Escalation and Exploitation domain — nothing else.

Related practice questions

Related GPEN topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GPEN exam test about Escalation and Exploitation?
Given a foothold, identify the fastest reliable path to root or SYSTEM using the target's own features, then execute it without destabilizing the host. The critical skill is matching the misconfiguration or privilege to the correct built-in escalation technique.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Escalation and Exploitation questions in a focused session?
Yes — the session launcher on this page draws every question from the Escalation and Exploitation domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GPEN topics?
Use the topic links above to move to related areas, or go back to the GPEN question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GPEN exam covers. They are not copied from any real exam or dump site.