GSEC Practice Question: Vulnerability Scanning and Penetration Testing
During an authorized penetration test, a tester obtains a low-privilege shell on a Windows server and wants to identify missing patches and insecure configurations that a remote unauthenticated scan may have missed. Which action BEST supports this goal?
⚠ Common exam trap
A common mix-up: candidates confuse remote vulnerability scanning with local post-exploitation enumeration, and assuming that any network-based technique will reveal host patch levels once a shell is obtained.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Upload and execute a local enumeration script such as WinPEAS or Seatbelt
After gaining a foothold, a penetration tester should perform local enumeration to find patch gaps and misconfigurations that remote scanning cannot see. WinPEAS and Seatbelt are purpose-built for this, collecting system, patch, and configuration data directly from the host. The other options either require additional credentials, focus on network discovery, or capture traffic without addressing local vulnerability state.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform a TCP SYN scan of the internal subnet from the compromised host
Why it's wrong here
A SYN scan maps open ports and services on other hosts but does not reveal missing patches or local insecure configurations on the host where the shell resides. It also generates significant network traffic that could trigger detection. This technique addresses network reconnaissance, not the local vulnerability discovery the scenario requires.
- ✗
Run a credentialed vulnerability scan from the scanner appliance using domain admin credentials
Why it's wrong here
Credentialed scanning from an external appliance provides deep visibility, but it requires valid administrative credentials and network access to the scanner. In this scenario the tester already has a shell and wants local, post-exploitation discovery. Using domain admin credentials is also a privilege escalation risk that may exceed the authorized scope and does not leverage the existing foothold.
- ✗
Capture traffic with tcpdump on the compromised host for several hours
Why it's wrong here
Packet capture can reveal cleartext credentials or interesting protocols traversing the host, but it does not enumerate installed patches or configuration weaknesses. It also requires storage and time, and the results are unrelated to the specific goal of identifying missing updates and insecure local settings. This is a network analysis technique, not host vulnerability enumeration.
- ✓
Upload and execute a local enumeration script such as WinPEAS or Seatbelt
Why this is correct
Local enumeration tools like WinPEAS and Seatbelt run from the compromised host and collect patch levels, missing updates, weak service permissions, saved credentials, and misconfigurations that remote scans often miss. Because the tester already has a shell, this approach directly answers the goal of finding local vulnerabilities without needing additional credentials or scanner access.
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.