Courseiva

GPEN Exploitation Fundamentals Practice Question

You are performing a penetration test against a Windows domain and have obtained domain user credentials. You want to identify which domain controllers are vulnerable to a specific privilege escalation technique. Which TWO tools or techniques are most appropriate for enumerating domain controllers and their potential vulnerabilities? (Choose two.)

⚠ Common exam trap

A common mix-up: candidates confuse general SMB enumeration tools with those that specifically map Active Directory attack paths and domain controller misconfigurations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

BloodHound with SharpHound collector

BloodHound with SharpHound and PowerView's Get-NetDomainController are both designed to enumerate Active Directory environments, including domain controllers. BloodHound maps attack paths and can highlight misconfigurations like unconstrained delegation, while PowerView directly queries domain controller information. Other tools like Nmap SMB scripts, Metasploit SMB scanner, and Responder focus on different aspects such as share enumeration, version scanning, or credential capture, and do not provide the specific domain controller vulnerability enumeration required.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    BloodHound with SharpHound collector

    Why this is correct

    BloodHound uses graph theory to reveal hidden relationships and attack paths in Active Directory. SharpHound collects data such as users, groups, computers, and sessions. It can identify domain controllers and potential privilege escalation paths, such as unconstrained delegation or ACL misconfigurations. This is a powerful tool for enumerating domain controllers and their vulnerabilities from a domain user perspective.

  • ✗

    Nmap with the smb-enum-shares script

    Why it's wrong here

    Nmap's smb-enum-shares script enumerates SMB shares on a host. While it can discover shares on domain controllers, it does not provide detailed information about domain controller roles or privilege escalation vulnerabilities. It is limited to share enumeration and does not map attack paths or identify misconfigurations like delegation settings. It is not the most appropriate for this scenario.

  • ✓

    PowerView's Get-NetDomainController

    Why this is correct

    PowerView is a PowerShell tool for network and domain enumeration. Get-NetDomainController specifically lists domain controllers in the domain. It can also retrieve properties that may indicate vulnerabilities, such as whether a DC allows unconstrained delegation. Combined with other PowerView functions, it helps identify potential privilege escalation vectors. This is a direct and efficient method for enumerating domain controllers.

  • ✗

    Metasploit's auxiliary/scanner/smb/smb_version

    Why it's wrong here

    This Metasploit module scans for SMB version information. While it can identify Windows versions and potentially missing patches, it does not specifically enumerate domain controllers or their privilege escalation vulnerabilities. It provides a broad scan but lacks the granularity to identify domain controller roles and misconfigurations. It is not the best choice for targeted domain controller enumeration.

  • ✗

    Responder with LLMNR poisoning

    Why it's wrong here

    Responder is used to poison LLMNR, NBT-NS, and mDNS queries to capture hashes. It is not an enumeration tool for domain controllers. It can be used to capture credentials, but it does not enumerate domain controllers or identify privilege escalation vulnerabilities. Using it in this scenario would not directly help in identifying vulnerable domain controllers.

About these practice questions

This GPEN question is part of Courseiva's 298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.