Courseiva

GPEN Exploitation Fundamentals Practice Question

Which of the following is considered a 'client-side' exploitation scenario?

⚠ Common exam trap

Candidates often confuse client-side attacks with server-side service exploitation, failing to realize that client-side attacks require user interaction to trigger the vulnerability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Tricking a user into opening a malicious PDF.

Client-side exploitation involves targeting an application running on a user's machine, such as a browser, document viewer, or email client. Unlike server-side exploitation, which targets a persistent service, client-side attacks rely on tricking a user into interacting with a malicious resource. This shift in vector requires testers to consider social engineering and user behavior as key components of the attack chain, which is distinct from direct network-based vulnerability exploitation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Exploiting an unpatched web server service.

    Why it's wrong here

    Exploiting a web server is a server-side attack. The service is listening for incoming connections, and the attacker initiates the exploit by sending a request directly to the server. This does not involve any user-side interaction or client application exploitation, making it a classic server-side testing scenario.

  • ✓

    Tricking a user into opening a malicious PDF.

    Why this is correct

    Opening a document in a client application like a PDF viewer is a quintessential client-side attack. The attacker leverages a vulnerability in the client software that is triggered by the user's action, effectively gaining control over the user's local machine through their interaction with the malicious file.

  • ✗

    Attacking an open database port.

    Why it's wrong here

    Databases are server-side infrastructure. Attacking an open database port is a direct network-based attack against a server. It does not involve any client-side software, user interaction, or the exploitation of a client application, placing it firmly in the category of server-side exploitation during a penetration test.

  • ✗

    Brute-forcing an SSH login on a server.

    Why it's wrong here

    SSH brute-forcing is an attack against a server-side authentication service. It involves direct interaction between the attacker and the server's listening port. No client software is exploited, and no user action beyond the initial request is required, making this clearly a server-side activity, not client-side.

About these practice questions

This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.