Courseiva

GPEN Escalation and Exploitation Practice Question

When escalating privileges using a Kernel exploit, why is it considered a high-risk activity for a penetration test?

⚠ Common exam trap

Candidates often focus on the 'success' of the exploit rather than the 'risk' to the system, ignoring that kernel crashes are a primary concern in production environments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It frequently causes system instability and crashes.

Kernel exploits target the core of the operating system. If the exploit fails or contains errors, it frequently leads to a system crash (Blue Screen of Death). This causes significant downtime for the client, which is usually prohibited. Because kernel-level code runs with the highest possible privilege, any mistake results in immediate system instability, making it one of the most dangerous vectors to test in a production environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It requires the user to have administrative credentials.

    Why it's wrong here

    Kernel exploits are specifically used to obtain administrative or SYSTEM privileges from a low-privileged state. If you already had administrative credentials, you would not need a kernel exploit to escalate your privileges. The exploit itself targets vulnerabilities in kernel-mode drivers or the operating system kernel.

  • ✓

    It frequently causes system instability and crashes.

    Why this is correct

    Kernel exploits manipulate memory structures at a very low level. Small errors in memory alignment or incorrect assumptions about the OS state lead to immediate kernel panics or crashes. This downtime is a major business impact, making kernel exploits the highest-risk category of penetration testing activities.

  • ✗

    It is easily detected by standard antivirus software.

    Why it's wrong here

    While kernel exploits are often detected by modern EDRs, the primary risk is not detection, but system instability. Antivirus detection is a concern for any exploit, but the unique danger of kernel-level testing is the potential for unplanned downtime that cannot be easily reversed without a reboot.

  • ✗

    It can only be executed on outdated operating systems.

    Why it's wrong here

    While kernel exploits are more common on legacy systems, they are still found in modern OS kernels. The difficulty of writing them does not change the fact that they are inherently risky. Regardless of the system's age, the impact of a crash remains a critical concern for testers.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.