Courseiva

GPEN · topic practice

Exploitation Fundamentals practice questions

This domain covers turning a discovered weakness into actual access: payload delivery, command execution, and privilege escalation on Linux and Windows targets. GPEN questions present a short scenario and ask you to classify the phase, name the vulnerability class, pick exploit-selection criteria, or choose the correct enumeration command for the target OS.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Exploitation Fundamentals

What the exam tests

What to know about Exploitation Fundamentals

Be able to map a described action to the correct exploitation lifecycle phase, infer the vulnerability class from observable server behavior, and justify exploit selection by version and configuration. The single most important thing: match the exploit to the confirmed target version and service before running it.

Classifying actions into the exploitation lifecycle, from initial payload injection through post-exploitation and privilege escalation

Identifying vulnerability classes from server behavior, such as verbose errors revealing stack traces or database queries

Selecting exploits using target version, service configuration, and reliability factors to avoid crashing the target

Using Windows commands like wmic service get and sc qc to find unquoted service paths and weak permissions

Watch out for

Common Exploitation Fundamentals exam traps

  • ▸Confusing the exploitation phase with reconnaissance or scanning; command execution with elevated privileges is post-exploitation, not vulnerability discovery
  • ▸Treating any verbose error as proof of SQL injection when the stack trace may indicate a different flaw such as path disclosure or misconfiguration
  • ▸Choosing an exploit by CVE match alone without confirming the exact service version and configuration, causing a crash or failed attempt

Practice set

Exploitation Fundamentals questions

20 questions · select your answer, then reveal the explanation

When evaluating an exploit script found on a public repository, which THREE actions should a tester take before executing it against a production target?

You are attempting to exploit a buffer overflow vulnerability. The target is using Address Space Layout Randomization (ASLR). Which technique is most appropriate to bypass this protection?

Which THREE of the following are common indicators that an exploitation attempt has crashed a service?

You are exploiting a stack-based buffer overflow on a 32-bit Linux application. The binary has NX enabled but no ASLR. You have identified a 'pop eax; ret' gadget and a 'jmp esp' instruction. You need to execute your shellcode. Which technique should you use?

During an internal penetration test, you gain access to a Windows 10 workstation and need to escalate privileges to SYSTEM. You discover the host has not been patched since a critical local privilege escalation vulnerability was disclosed. You have a working exploit module in Metasploit. Which Metasploit payload type should you select to get a Meterpreter session that survives process restarts and allows you to migrate to a more stable process?

During a penetration test, you gain a low-privileged shell on a Windows 10 host. You notice the system has PowerShell v5 and the `SeImpersonatePrivilege` enabled for your user. Which exploitation technique is most appropriate to escalate privileges to SYSTEM?

You are conducting a penetration test against a Linux server and have obtained a low-privilege shell. You want to escalate privileges by exploiting a vulnerable SUID binary. Which TWO of the following commands are most useful for identifying SUID binaries that could be exploited? (Choose two.)

A penetration tester is exploiting a web application vulnerability that allows arbitrary file upload. The target server runs PHP and has `mod_security` with OWASP Core Rule Set (CRS) enabled. Which method is most likely to bypass the WAF and achieve remote code execution?

You are exploiting a stack-based buffer overflow on a Linux x86 binary with NX enabled and ASLR disabled. You have identified a suitable JMP ESP instruction in a non-ASLR module. However, the binary is compiled with stack canaries. Which approach is most likely to succeed in bypassing the stack canary and achieving code execution?

During an external penetration test, you have compromised a web server and established a reverse shell. You now need to escalate privileges on the Linux host. You discover that the /etc/passwd file is writable by your current user. Which method is most effective for privilege escalation in this scenario?

During a penetration test, you successfully inject a payload into a web application that results in the server executing system commands with elevated privileges. Which phase of the exploitation lifecycle does this action primarily represent?

When selecting an exploit for a target system, which TWO factors are most critical to ensure the exploit succeeds without crashing the target service?

Refer to the exhibit. Which step should a tester prioritize next based on the server header information?

Exhibit

HTTP/1.1 200 OK
Content-Type: text/html
Server: Apache/2.4.41 (Ubuntu)

<html>...</html>

Why is it important to use 'staged' payloads during a penetration test when the target has limited memory or strict filtering?

Which of the following describes the purpose of 'encoding' shellcode in an exploitation context?

Refer to the exhibit. What does this output indicate regarding the current exploitation attempt?

Exhibit

Error: Segmentation Fault (core dumped)
Stack Pointer: 0x7fffffffe000
Instruction Pointer: 0x41414141

Which technique is most effective for exploiting a heap-based buffer overflow compared to a stack-based overflow?

Which of the following is considered a 'client-side' exploitation scenario?

When planning an exploit that requires a specific memory address, which THREE techniques can a tester use to increase the reliability of the exploit?

What is the primary danger of using a 'bind shell' payload in a penetration test?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Exploitation Fundamentals sessions

Start a Exploitation Fundamentals only practice session

Every question in these sessions is drawn from the Exploitation Fundamentals domain — nothing else.

Related practice questions

Related GPEN topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GPEN exam test about Exploitation Fundamentals?
Be able to map a described action to the correct exploitation lifecycle phase, infer the vulnerability class from observable server behavior, and justify exploit selection by version and configuration. The single most important thing: match the exploit to the confirmed target version and service before running it.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Exploitation Fundamentals questions in a focused session?
Yes — the session launcher on this page draws every question from the Exploitation Fundamentals domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GPEN topics?
Use the topic links above to move to related areas, or go back to the GPEN question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GPEN exam covers. They are not copied from any real exam or dump site.