GPEN Exam Questions
442 real GPEN exam questions with expert-verified answers and explanations. Page 3 of 9.
- Question #105Exploitation & Post-Exploitation Techniques
Which of the following statements are true about NTLMv1? Each correct answer represents a complete solution. Choose all that apply.
NTLMv1challenge-response authenticationLANMAN hashWindows authentication - Question #106Web Application Penetration Testing
Which of the following can be used as a countermeasure against the SQL injection attack? Each correct answer represents a complete solution. Choose two.
SQL injectioninput sanitizationprepared statementsweb security - Question #107Penetration Testing Foundations & Reconnaissance
You send SYN packets with the exact TTL of the target system starting at port 1 and going up to port 1024 using hping2 utility. This attack is known as __________.
firewalkinghping2TTL manipulationfirewall evasion - Question #108Exploitation & Post-Exploitation Techniques
Which of the following tools connects to and executes files on remote systems?
PsExecremote executionlateral movementWindows tools - Question #109Penetration Testing Foundations & Reconnaissance
You are concerned about rogue wireless access points being connected to your network. What is the best way to detect and prevent these?
rogue access pointwireless securitysite surveynetwork monitoring - Question #110Penetration Testing Foundations & Reconnaissance
How many bits encryption does SHA-1 use?
SHA-1hash algorithmscryptography basicsdigest length - Question #111Penetration Testing Foundations & Reconnaissance
You work as a professional Computer Hacking Forensic Investigator for DataEnet Inc. You want to investigate e-mail information of an employee of the company. The suspected employee...
email forensicsbrowser artifactstemporary internet filesdigital investigation - Question #112Exploitation & Post-Exploitation Techniques
You run the rdisk /s command to retrieve the backup SAM file on a computer. Where should you go on the computer to find the file?
SAM filepassword hashWindows credential storagerdisk - Question #113Exploitation & Post-Exploitation Techniques
You want to use a Windows-based GUI tool which can perform MITM attacks, along with sniffing and ARP poisoning. Which of the following tools will you use?
Cain and AbelARP poisoningMITM attacknetwork sniffing - Question #115Vulnerability Discovery & Scanning
Which of the following commands can be used for port scanning?
netcatport scanningnc -z flagnetwork reconnaissance - Question #116Penetration Testing Foundations & Reconnaissance
Which of the following tools allows you to download World Wide Web sites from the Internet to a local computer?
HTTrackwebsite mirroringpassive reconnaissanceOSINT - Question #117Penetration Testing Foundations & Reconnaissance
Which of the following are the countermeasures against WEP cracking? Each correct answer represents a part of the solution. Choose all that apply.
WEP crackingwireless securityencryption keysSSID - Question #118Penetration Testing Foundations & Reconnaissance
Adam is a novice Internet user. He is using Google search engine to search documents of his interest. Adam wants to search the text present in the link of a Website. Which of the f...
Google dorkinginanchor operatorOSINTsearch operators - Question #119Vulnerability Discovery & Scanning
You want to retrieve the default security report of nessus. Which of the following google search queries will you use?
Google dorkingfiletype operatorNessusOSINT - Question #120Web Application Penetration Testing
You run the following command while using Nikto Web scanner: perl nikto.pl -h 192.168.0.1 -p 443 What action do you want to perform?
Niktoweb vulnerability scannerHTTP scanningweb application testing - Question #121Penetration Testing Foundations & Reconnaissance
John works as a professional Ethical Hacker. He has been assigned the project of testing the preattack phase successfully: Information gathering Determination of network range Iden...
OS fingerprintingreconnaissance methodologypre-attack phase sequenceethical hacking workflow - Question #122Web Application Penetration Testing
Which of the following statements are true about session hijacking? Each correct answer represents a complete solution. Choose all that apply.
session hijackingTCP session takeoversession token securityunauthorized access - Question #123Reporting & Remediation
You work as a Network Administrator for Tech-E-book Inc. You are configuring the ISA Server 2006 firewall to provide your company with a secure wireless intranet. You want to accep...
ISA Serverpublishing rulesSMTP relayfirewall configuration - Question #124Exploitation & Post-Exploitation Techniques
John, a novice web user, makes a new E-mail account and keeps his password as "apple", his favorite fruit. John's password is vulnerable to which of the following password cracking...
brute force attackdictionary attackhybrid attackpassword cracking - Question #125Vulnerability Discovery & Scanning
Which of the following scanning methods is most accurate and reliable, although it is easily detectable and hence avoided by a hacker?
TCP scanningSYN ACK scanfull connect scanport scanning accuracy - Question #126Penetration Testing Foundations & Reconnaissance
Which of the following layers of TCP/IP model is used to move packets between the Internet Layer interfaces of two different hosts on the same link?
TCP/IP modellink layernetwork layersdata link - Question #127Exploitation & Post-Exploitation Techniques
Which of the following password cracking tools can work on the Unix and Linux environment?
password crackingJohn the RipperLinux toolsoffline attack - Question #129Vulnerability Discovery & Scanning
Which of the following tools can be used to enumerate networks that have blocked ICMP Echo packets, however, failed to block timestamp or information packet or not performing sniff...
ICMP enumerationpacket spoofingnetwork scanningfirewall evasion - Question #131Penetration Testing Foundations & Reconnaissance
Which of the following tools are used for footprinting? Each correct answer represents a complete solution. Choose all that apply.
footprintingOSINTWhoisTraceroute - Question #132Vulnerability Discovery & Scanning
You work as a Network Administrator in the Secure Inc. Your company is facing various network attacks due to the insecure wireless network. You are assigned a task to secure your w...
wireless securitySSID cloakingDHCP802.11 - Question #133Web Application Penetration Testing
John works as a Penetration Tester in a security service providing firm named you-are-secure Inc. Recently, John's company has got a project to test the security of a promotional W...
XSScross-site scriptingscript injectionweb application attacks - Question #134Reporting & Remediation
Which of the following laws or acts, formed in Australia, enforces prohibition against cyber stalking?
cyberstalking lawAustralian legislationlegal frameworkscompliance - Question #135Web Application Penetration Testing
John works as a professional Ethical Hacker. He has been assigned a project to test the security and successfully logs in to the user page of the Web site. The We-are-secure login...
SQL injectionauthentication bypasslogin securityweb application attacks - Question #136Penetration Testing Foundations & Reconnaissance
You want to retrieve password files (stored in the Web server's index directory) from various Web sites. Which of the following tools can you use to accomplish the task?
Google hackingOSINTinformation gatheringweb server enumeration - Question #138Penetration Testing Foundations & Reconnaissance
John works as a professional Ethical Hacker. He has been assigned the project of testing the enters the following command on the command prompt: However, he receives an incomplete...
tracerouteICMPfirewallnetwork troubleshooting - Question #139Vulnerability Discovery & Scanning
You work as a Penetration Tester for the Infosec Inc. Your company takes the projects of security auditing. Recently, your company has assigned you a project to test the security o...
TCP wrappersport scanningtelnetLinux access control - Question #141Exploitation & Post-Exploitation Techniques
How many bits does SYSKEY use for encryption?
SYSKEYWindows encryptionpassword storage128-bit key - Question #142Vulnerability Discovery & Scanning
Which of the following is a Windows-based tool that is used for the detection of wireless LANs using the IEEE 802.11a, 802.11b, and 802.11g standards and also detects wireless netw...
NetStumblerwireless LAN detection802.11GPS mapping - Question #143Exploitation & Post-Exploitation Techniques
In which of the following attacking methods does an attacker distribute incorrect IP address?
DNS poisoningIP spoofingDNS cachenetwork attacks - Question #144Exploitation & Post-Exploitation Techniques
LM hash is one of the password schemes that Microsoft LAN Manager and Microsoft Windows versions prior to the Windows Vista use to store user passwords that are less than 15 charac...
LM hashpassword hashingWindows authenticationNTLM - Question #145Exploitation & Post-Exploitation Techniques
You are using the dsniff tool to intercept communications between two entities and establish credentials with both sides of the connections. These entities do not notice that you w...
man-in-the-middledsniffcredential interceptionnetwork sniffing - Question #147Penetration Testing Foundations & Reconnaissance
John works as a professional Ethical Hacker. He is assigned a project to test the security of connected to the server or not. Which of the following will he use to ping these compu...
ping sweephost discoverynetwork reconnaissanceICMP - Question #149Penetration Testing Foundations & Reconnaissance
You work as a Network Security Analyzer. You got a suspicious email while working on a forensic project. Now, you want to know the IP address of the sender so that you can analyze...
email header analysisIP tracingOSINTsender attribution - Question #150Exploitation & Post-Exploitation Techniques
Which of the following tools can be used to automate the MITM attack?
MITM automationAirjackwireless attack toolsnetwork interception - Question #151Exploitation & Post-Exploitation Techniques
You have changed the RestrictAnonymous registry setting from 0 to 1 on your servers to secure your Windows 2000 system so that any malicious user cannot establish a null session on...
null sessionRestrictAnonymousWindows registry hardeninganonymous enumeration - Question #152Reporting & Remediation
You are a Web Administrator of Millennium Inc. The company has hosted its Web site within its network. The management wants the company's vendors to be able to connect to the corpo...
VPNremote access securitydata encryptionnetwork remediation - Question #153Penetration Testing Foundations & Reconnaissance
Which of the following federal laws are related to hacking activities? Each correct answer represents a complete solution. Choose three.
federal lawCFAAcomputer crime statuteslegal frameworks - Question #154Vulnerability Discovery & Scanning
Which of the following statements are true about the Enum tool? Each correct answer represents a complete solution. Choose all that apply.
Enum toolNetBIOS enumerationNULL sessionsWindows enumeration - Question #156Penetration Testing Foundations & Reconnaissance
Which of the following security protocols can be used to support MS-CHAPv2 for wireless client authentication? Each correct answer represents a complete solution. Choose two.
MS-CHAPv2PEAPPPTPwireless authentication - Question #157Exploitation & Post-Exploitation Techniques
Which of the following tools automates password guessing in the NetBIOS session?
NetBIOSpassword guessingLegion toolbrute force - Question #159Vulnerability Discovery & Scanning
In which of the following scanning methods does an attacker send SYN packets and then a RST packet?
TCP SYN scanport scanningscan typespacket flags - Question #161Vulnerability Discovery & Scanning
Which of the following tools is used for vulnerability scanning and calls Hydra to launch a dictionary attack?
Nessusvulnerability scanningHydradictionary attack - Question #162Penetration Testing Foundations & Reconnaissance
GSM uses either A5/1 or A5/2 stream cipher for ensuring over-the-air voice privacy. Which of the following cryptographic attacks can be used to break both ciphers?
GSM encryptionstream cipherciphertext-only attackcryptanalysis - Question #163Exploitation & Post-Exploitation Techniques
You run the following command on the remote Windows server 2003 computer: c:\reg add HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v nc /t REG_SZ /d "c:\windows\nc.exe -d 192...
NetcatWindows registry persistencebackdoorpost-exploitation - Question #164Exploitation & Post-Exploitation Techniques
John works as a professional Ethical Hacker. He is assigned a project to test the security of placed a backdoor in the network. Now, he wants to clear all event logs related to pre...
event log clearingelsave.exeWinZapperanti-forensics