GPEN Exam Questions
442 real GPEN exam questions with expert-verified answers and explanations. Page 5 of 9.
- Question #231Penetration Testing Foundations & Reconnaissance
Which of the following IEEE standards defines Wired Equivalent Privacy encryption scheme?
WEPIEEE 802.11wireless standardsencryption protocols - Question #232Vulnerability Discovery & Scanning
Which of the following tools is a wireless sniffer and analyzer that works on the Windows operating system?
wireless sniffingAeropeekwireless toolsnetwork analysis - Question #234Vulnerability Discovery & Scanning
Which of the following tools is NOT used for wireless sniffing?
wireless sniffingMiniStumblertool identificationwireless analysis - Question #235Exploitation & Post-Exploitation Techniques
Which of the following options holds the strongest password?
password strengthpassword complexityspecial charactersauthentication security - Question #237Penetration Testing Foundations & Reconnaissance
Victor wants to use Wireless Zero Configuration (WZC) to establish a wireless network connection using his computer running on Windows XP operating system. Which of the following a...
WZCevil twin attackwireless threatsnetwork probing - Question #238Penetration Testing Foundations & Reconnaissance
You want that some of your Web pages should not be crawled. Which one of the following options will you use to accomplish the task?
robots.txtweb crawlingweb reconnaissancesearch engine directives - Question #239Exploitation & Post-Exploitation Techniques
Which of the following tools can be used to automate the MITM attack?
MITM attackAirjackwireless attacksnetwork interception - Question #240Penetration Testing Foundations & Reconnaissance
The employees of CCN Inc. require remote access to the company's proxy servers. In order to provide solid wireless security, the company uses LEAP as the authentication protocol. W...
LEAPwireless authenticationdynamic key encryptionpassword hash - Question #242Exploitation & Post-Exploitation Techniques
You want to connect to your friend's computer and run a Trojan on it. Which of the following tools will you use to accomplish the task?
PSExecremote executionlateral movementpost-exploitation tools - Question #244Exploitation & Post-Exploitation Techniques
You want to perform an active session hijack against Secure Inc. You have found a target that allows Telnet session. You have also searched an active session due to the high level...
session hijackingTCP sequence numbersTelnetactive session - Question #245Web Application Penetration Testing
Which of the following Web authentication techniques uses a single sign-on scheme?
SSOMicrosoft Passportweb authenticationidentity management - Question #247Penetration Testing Foundations & Reconnaissance
Which of the following standards is used in wireless local area networks (WLANs)?
IEEE 802.11bWLANwireless standardsnetworking - Question #249Exploitation & Post-Exploitation Techniques
John works as a professional Ethical Hacker. He has been assigned the project of testing the description of the tool is as follows: Which of the following tools is John using to cr...
AirSnortWEP crackingwireless encryptionkey cracking - Question #250Exploitation & Post-Exploitation Techniques
LM hash is one of the password schemes that Microsoft LAN Manager and Microsoft Windows versions prior to the Windows Vista use to store user passwords that are less than 15 charac...
LM hashpassword hashingWindows authenticationhash analysis - Question #251Penetration Testing Foundations & Reconnaissance
You want to retrieve password files (stored in the Web server's index directory) from various Web sites. Which of the following tools can you use to accomplish the task?
Google hackingOSINTweb reconnaissancepassword files - Question #252Vulnerability Discovery & Scanning
You want to run the nmap command that includes the host specification of 202.176.56-57.*. How many hosts will you scan?
Nmaphost specificationIP rangesnetwork scanning - Question #253Cloud & Pivoting Techniques
Which of the following tools allow you to perform HTTP tunneling? Each correct answer represents a complete solution. Choose all that apply.
HTTP tunnelingfirewall evasiontraffic obfuscationnetwork pivoting - Question #255Penetration Testing Foundations & Reconnaissance
Which of the following penetration testing phases involves gathering data from whois, DNS, and network scanning, which helps in mapping a target network and provides valuable infor...
penetration testing phasespre-attack phasereconnaissanceOSINT - Question #256Penetration Testing Foundations & Reconnaissance
Which of the following wireless security standards supported by Windows Vista provides the highest level of security?
WPA2wireless securityencryption standardsauthentication protocols - Question #257Exploitation & Post-Exploitation Techniques
Which of the following are considered Bluetooth security violations? Each correct answer represents a complete solution. Choose two.
Bluetooth securitybluesnarfingbluebugwireless attacks - Question #260Penetration Testing Foundations & Reconnaissance
Which of the following layers of TCP/IP model is used to move packets between the Internet Layer interfaces of two different hosts on the same link?
TCP/IP modellink layernetwork fundamentalsdata link - Question #261Vulnerability Discovery & Scanning
John works as a professional Ethical Hacker. He has been assigned the project of testing the preattack phase to check the security of the We-are-secure network: Gathering informati...
port scanningSuperScanactive reconnaissancenetwork enumeration - Question #262Exploitation & Post-Exploitation Techniques
Which of the following are the countermeasures against WEP cracking? Each correct answer represents a part of the solution. Choose all that apply.
WEP crackingwireless securitycountermeasuresencryption keys - Question #263Penetration Testing Foundations & Reconnaissance
Which of the following is the correct sequence of packets to perform the 3-way handshake method?
TCP handshakeSYN SYN/ACK ACKconnection establishmentnetwork fundamentals - Question #265Vulnerability Discovery & Scanning
Which of the following nmap switches is used to perform ICMP netmask scanning?
nmapICMP scanningnetmask scanhost discovery - Question #266Penetration Testing Foundations & Reconnaissance
Which of the following tasks is NOT performed into the enumeration phase?
enumeration phaseNetBIOSmethodology phasesreconnaissance vs exploitation - Question #267Vulnerability Discovery & Scanning
Which of the following tools is based on the SATAN tool?
SAINTSATANvulnerability scannersecurity tools - Question #268Web Application Penetration Testing
Which of the following is an open source Web scanner?
Niktoweb scanneropen source toolsweb vulnerability scanning - Question #269Exploitation & Post-Exploitation Techniques
Which of the following statements about Fport is true?
Fportprocess viewerport-process mappingWindows tools - Question #270Exploitation & Post-Exploitation Techniques
Which of the following event logs contains traces of brute force attempts performed by an attacker?
Windows event logsSecEvent.Evtbrute force detectionlog analysis - Question #271Penetration Testing Foundations & Reconnaissance
Which of the following ports is used for NetBIOS null sessions?
NetBIOSnull sessionsport 139SMB - Question #272Penetration Testing Foundations & Reconnaissance
Which of the following TCSEC classes defines verified protection?
TCSECClass Averified protectionsecurity classification - Question #274Exploitation & Post-Exploitation Techniques
Which of the following is the correct syntax to create a null session?
null sessionIPC$net use commandWindows enumeration - Question #275Vulnerability Discovery & Scanning
Which of the following tools is a wireless sniffer and analyzer that works on the Windows operating system?
wireless snifferAeropeekpacket captureWindows wireless tools - Question #276Penetration Testing Foundations & Reconnaissance
Which of the following statements about SSID is NOT true?
SSIDwireless securitydefault configurationsWiFi fundamentals - Question #277Penetration Testing Foundations & Reconnaissance
Which of the following tools is an example of HIDS?
HIDSLog File Monitorintrusion detectionhost-based security - Question #278Exploitation & Post-Exploitation Techniques
Which of the following tools is not a BlueSnarf attacking tool?
BlueSnarf attackBluetooth attacksattack toolswireless exploitation - Question #279Penetration Testing Foundations & Reconnaissance
Which of the following tasks is NOT performed by antiviruses?
antivirus capabilitiessession hijackingheuristic scanningsecurity tool scope - Question #280Penetration Testing Foundations & Reconnaissance
Which of the following does NOT use a proxy software to protect users?
packet filteringproxy firewallstateful inspectionfirewall types - Question #281Exploitation & Post-Exploitation Techniques
You execute the following netcat command: c:\target\nc -1 -p 53 -d -e cmd.exe What action do you want to perform by issuing the above command?
netcatbind shellport 53command execution - Question #282Vulnerability Discovery & Scanning
TCP FIN scanning is a type of stealth scanning through which the attacker sends a FIN packet to the target port. If the port is closed, the victim assumes that this packet was sent...
TCP FIN scanstealth scanningOS fingerprintingRST response - Question #283Reporting & Remediation
You work as a professional Ethical Hacker. You are assigned a project to perform blackhat mechanic. You claim that someone from the office called you saying that there is some faul...
physical securitydisk encryptionlive CD attackBIOS password - Question #284Penetration Testing Foundations & Reconnaissance
Which of the following statements are true about KisMAC?
KisMACwireless discoveryWEP crackingpcap - Question #285Penetration Testing Foundations & Reconnaissance
A Web developer with your company wants to have wireless access for contractors that come in to work on various projects. The process of getting this approved takes time. So rather...
rogue access pointunauthorized WAPwireless securitynetwork intrusion - Question #287Penetration Testing Foundations & Reconnaissance
Which of the following statements are true about SSIDs? Each correct answer represents a complete solution. Choose all that apply.
SSIDwireless networkaccess point802.11 - Question #288Penetration Testing Foundations & Reconnaissance
Adam works on a Linux system. He is using Sendmail as the primary application to transmit emails. Linux uses Syslog to maintain logs of what has occurred on the system. Which of th...
Linux loggingSyslogSendmailmail log path - Question #289Exploitation & Post-Exploitation Techniques
You have inserted a Trojan on your friend's computer and you want to put it in the startup so that whenever the computer reboots the Trojan will start to run on the startup. Which...
Windows registrypersistencetrojan startupRunServices - Question #290Reporting & Remediation
You have just installed a Windows 2003 server. What action should you take regarding the default administrator and guest accounts for securing a computer?
Windows hardeningdefault accountsadministrator accountaccount security - Question #291Penetration Testing Foundations & Reconnaissance
Which of the following are the two different file formats in which Microsoft Outlook saves e-mail messages based on system configuration? Each correct answer represents a complete...
Microsoft OutlookPST fileOST fileemail storage - Question #292Reporting & Remediation
Which of the following statutes is enacted in the U.S., which prohibits creditors from collecting data from applicants, such as national origin, caste, religion etc?
US privacy lawECOAcredit data collectionlegal compliance