Courseiva

GPEN · topic practice

Scenario practice questions

Practise GIAC Penetration Tester Scenario practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Scenario

What the exam tests

What to know about Scenario

Scenario questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Scenario exam traps

  • ▸Answering from memory before reading the full scenario.
  • ▸Missing a constraint such as cost, availability, security, scope or command context.
  • ▸Choosing a broad answer when the question asks for the most specific fix.
  • ▸Ignoring why the wrong options are tempting.

Practice set

Scenario questions

20 questions · select your answer, then reveal the explanation

Question 1hardmultiple choice
Read the full Scenario explanation →

Refer to the exhibit. What does the Nmap status 'open|filtered' indicate about the target port, and why does this result commonly occur in penetration testing scenarios?

Exhibit

Nmap scan report for 10.0.0.1
PORT STATE SERVICE
80/tcp open|filtered http
Question 2mediummultiple choice
Read the full Scenario explanation →

During a penetration test, you successfully inject a payload into a web application that results in the server executing system commands with elevated privileges. Which phase of the exploitation lifecycle does this action primarily represent?

Question 3mediummultiple choice
Read the full Scenario explanation →

You are performing OSINT on a target and have collected a list of employee names from LinkedIn. You want to generate likely corporate email addresses and then verify which ones are valid without sending email to the target's mail servers. Which approach best accomplishes this?

Question 4easymultiple choice
Read the full Scenario explanation →

During a penetration test, a tester extracts the SAM database from a Windows system. Which of the following tools is specifically designed to extract password hashes from the SAM file?

Question 5easymultiple choice
Read the full Scenario explanation →

A penetration tester is performing a password audit and has obtained a set of NTLM hashes from a Windows system. The tester wants to use Hashcat to crack these hashes but needs to choose the correct mode. Which Hashcat mode should be used for NTLM hashes?

Question 6mediummulti select
Read the full Scenario explanation →

Which TWO of the following scenarios are most indicative of a successful Kerberoasting attack occurring within a network?

Question 7mediummulti select
Read the full Scenario explanation →

A penetration tester has obtained a set of NTLM hashes from a Windows domain controller. The tester plans to perform an offline password cracking attack. Which two of the following techniques are most effective for increasing the success rate of cracking these hashes? (Choose two.)

Question 8mediummultiple choice
Read the full Scenario explanation →

A penetration tester has obtained the NTLM hash of a domain user and wants to authenticate to a remote server without cracking the password. Which of the following techniques allows the tester to use the hash directly for authentication?

Question 9mediummultiple choice
Read the full Scenario explanation →

A penetration tester extracts a domain user's NT hash from the SAM database of a workstation and wants to authenticate to a file share on a different server without knowing the plaintext password. Which of the following techniques should the tester use?

Question 10hardmultiple choice
Review the full subnetting walkthrough →

A penetration tester is using Nmap to scan a target subnet and wants to identify all hosts that are up without performing port scanning. The tester also wants to avoid sending TCP SYN packets to reduce noise. Which Nmap option should the tester use?

Question 11mediummultiple choice
Read the full Scenario explanation →

A penetration tester has captured a NetNTLMv2 challenge-response hash from a Windows workstation over SMB. The tester plans to recover the plaintext password offline using Hashcat on a workstation with a dedicated GPU. The hash file is saved as 'capture.txt' in the format 'username::domain:challenge:response:blob'. Which Hashcat mode should the tester specify to correctly crack this hash?

Question 12hardmultiple choice
Read the full Scenario explanation →

A penetration tester has obtained Domain Admin credentials during an internal engagement and wants to establish long-term persistence that survives a Domain Admin password reset and reboots. The tester needs a method that remains stealthy and does not rely on leaving a binary on disk. Which technique best meets these requirements?

Question 13mediummultiple choice
Read the full Scenario explanation →

During a penetration test, you obtain a memory dump from a Windows Server 2016 system. You suspect that a domain administrator recently logged on and left credentials in memory. Which tool is specifically designed to extract plaintext passwords and hashes from Windows memory dumps?

Question 14hardmultiple choice
Read the full Scenario explanation →

A penetration tester is targeting a web application that uses a custom authentication mechanism. After capturing network traffic, the tester notices that the application sends a challenge to the client and expects a response derived from the user's password. The tester wants to perform an offline brute-force attack against the captured challenge-response pairs. Which type of password attack is this?

Question 15hardmultiple choice
Read the full Scenario explanation →

During a penetration test on a Windows Server 2019 domain controller, you discover that the KRBTGT account password was last set 5 years ago. You extract the KRBTGT hash and create a Golden Ticket with a 10-year expiration. What is the primary reason this persistence method is particularly effective in this scenario?

Question 16easymultiple choice
Read the full DNS explanation →

A penetration tester has compromised a host in a restricted network that only allows outbound DNS queries to a specific internal resolver. The tester needs to establish a command and control channel that can traverse this restriction. Which C2 technique is most appropriate?

Question 17mediummultiple choice
Read the full DNS explanation →

During an authorized penetration test, you compromise a Windows host in a restricted network segment that only permits outbound DNS (UDP 53) to an internal resolver. You need to establish a command-and-control channel that can survive reboots and provide interactive shell access while blending with normal DNS traffic. Which of the following is the MOST appropriate technique to achieve this?

Question 18hardmulti select
Read the full Scenario explanation →

You are performing a penetration test on a Linux system and have obtained a low-privileged shell. You want to escalate privileges by exploiting misconfigured file permissions. Which two of the following file permission scenarios are most likely to allow privilege escalation? (Choose two.)

Question 19mediummulti select
Read the full Scenario explanation →

A penetration tester is performing a password attack against an Active Directory environment and has obtained a list of domain user accounts. The tester wants to perform a password spraying attack to identify weak passwords while minimizing the risk of account lockouts. Which TWO of the following are best practices for conducting a password spraying attack in this scenario? (Choose two.)

Question 20hardmultiple choice
Read the full Scenario explanation →

Refer to the exhibit. What is the most likely cause of the 'Connection reset by peer' error when using the PsExec module?

Exhibit

msf6 exploit(windows/smb/psexec) > set RHOSTS 10.10.10.5
msf6 exploit(windows/smb/psexec) > set SMBUser admin
msf6 exploit(windows/smb/psexec) > set SMBPass 328d3f1c12d2...[truncated]
msf6 exploit(windows/smb/psexec) > run
[*] Started reverse TCP handler on 10.10.10.2:4444
[*] 10.10.10.5:445 - Connecting to the target...
[*] 10.10.10.5:445 - Authenticating with 10.10.10.5:445 as user 'admin'...
[-] 10.10.10.5:445 - Exploit failed: RubySMB::Error::CommunicationError: Connection reset by peer

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Scenario sessions

Start a Scenario only practice session

Every question in these sessions is drawn from the Scenario domain — nothing else.

Related practice questions

Related GPEN topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GPEN exam test about Scenario?
Scenario questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Scenario questions in a focused session?
Yes — the session launcher on this page draws every question from the Scenario domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GPEN topics?
Use the topic links above to move to related areas, or go back to the GPEN question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GPEN exam covers. They are not copied from any real exam or dump site.