GPEN Exam Questions
442 real GPEN exam questions with expert-verified answers and explanations. Page 6 of 9.
- Question #293Exploitation & Post-Exploitation Techniques
John works as a professional Ethical Hacker. He is assigned a project to test the security of placed a backdoor in the network. Now, he wants to clear all event logs related to pre...
log clearingWindows event logscovering trackselsave WinZapper - Question #294Exploitation & Post-Exploitation Techniques
Alice wants to prove her identity to Bob. Bob requests her password as proof of identity, which Alice dutifully provides (possibly after some transformation like a hash function);...
replay attackauthentication bypasscredential thefteavesdropping - Question #295Penetration Testing Foundations & Reconnaissance
A war dialer is a tool that is used to scan thousands of telephone numbers to detect vulnerable modems. It provides an attacker unauthorized access to a computer. Which of the foll...
war dialingmodem scanningTHC-ScanToneLoc - Question #296Penetration Testing Foundations & Reconnaissance
Mark works as a Network Administrator for Infonet Inc. The company has a Windows 2000 Active Directory domain-based network. The domain contains one hundred Windows XP Professional...
WEPSSID broadcastMAC filtering802.11 authentication - Question #297Penetration Testing Foundations & Reconnaissance
John works as a Network Security Professional. He is assigned a project to test the security of with netcat and sends a bad html request in order to retrieve information about the...
banner grabbingnetcatservice fingerprintingHTTP request - Question #298Penetration Testing Foundations & Reconnaissance
John works as a professional Ethical Hacker. He has been assigned the project of testing the preattack phase: Information gathering Determining network range Identifying active mac...
network mappingTracerouteNeoTraceCheops - Question #299Penetration Testing Foundations & Reconnaissance
You work as a Network Administrator for McNeil Inc. The company has a Windows Active Directory-based single domain single forest network. The functional level of the forest is Wind...
EAP-TLSsmart card authentication802.1Xwireless security - Question #301Penetration Testing Foundations & Reconnaissance
You see the career section of a company's Web site and analyze the job profile requirements. You conclude that the company wants professionals who have a sharp knowledge of Windows...
OSINTpassive reconnaissancefootprintinghacking phases - Question #302Exploitation & Post-Exploitation Techniques
John works as a professional Ethical Hacker. He has been assigned the project of testing the and observes that the server crashes. Which of the following is the most likely cause o...
Teardrop attackIP fragmentationoverlapping fragmentsDoS - Question #303Penetration Testing Foundations & Reconnaissance
The 3-way handshake method is used by the TCP protocol to establish a connection between a client and the server. It involves three steps: 1. In the first step, a SYN message is se...
TCP 3-way handshakesequence numbersISNnetwork protocols - Question #304Exploitation & Post-Exploitation Techniques
Which of the following tools crashes computers running Windows 2000/XP/NT by sending crafted SMB requests?
SMB exploitationSMBDieWindows vulnerabilitydenial of service - Question #305Penetration Testing Foundations & Reconnaissance
Which of the following penetration testing phases involves gathering data from whois, DNS, and network scanning, which helps in mapping a target network and provides valuable infor...
penetration testing phasespre-attack reconnaissanceDNS enumerationnetwork scanning - Question #306Vulnerability Discovery & Scanning
John works as a professional Ethical Hacker. He has been assigned the project of testing the Weare- secure network. Which of the following IEEE-based traffic can be sniffed with Ki...
Kismetwireless sniffing802.11 standardspassive reconnaissance - Question #307Reporting & Remediation
Which of the following are countermeasures to prevent unauthorized database access attacks? Each correct answer represents a complete solution. Choose all that apply.
database securityinput sanitizationstored proceduresSQL injection countermeasures - Question #308Penetration Testing Foundations & Reconnaissance
You work as an IT Technician for PassGuide Inc. You have to take security measures for the wireless network of the company. You want to prevent other computers from accessing the c...
MAC filteringwireless access controlhardware addressnetwork security - Question #309Reporting & Remediation
Which of the following wireless security features provides the best wireless security mechanism?
WPA 802.1Xwireless security standardsEAP authenticationwireless hardening - Question #310Vulnerability Discovery & Scanning
Wired Equivalent Privacy (WEP) is a security protocol for wireless local area networks (WLANs). It has two components, authentication and encryption. It provides security equivalen...
WEP weaknessesRC4 encryptioninitialization vectorAirSnort - Question #311Penetration Testing Foundations & Reconnaissance
You want to search Microsoft Outlook Web Access Default Portal using Google search on the Internet so that you can perform the brute force attack and get unauthorized access. What...
Google dorkingOSINTOutlook Web Accesssearch operators - Question #312Penetration Testing Foundations & Reconnaissance
Mark works as a Network Administrator for NetTech Inc. Several employees of the company work from the remote locations. The company provides a dial-up connection to employees to co...
PPP protocolremote accessdial-up callbacknetwork protocols - Question #313Exploitation & Post-Exploitation Techniques
You want to connect to your friend's computer and run a Trojan on it. Which of the following tools will you use to accomplish the task?
PSExecremote code executionlateral movementTrojan deployment - Question #314Penetration Testing Foundations & Reconnaissance
Which of the following protocols uses a combination of public key and symmetric encryption to provide communication privacy, authentication, and message integrity for secure browsi...
SSL/TLSpublic key encryptionsymmetric encryptionsecure communication - Question #315Penetration Testing Foundations & Reconnaissance
Which of the following wireless security standards supported by Windows Vista provides the highest level of security?
WPA2wireless security standardsauthenticationWindows security - Question #316Web Application Penetration Testing
John visits an online shop that stores the IDs and prices of the items to buy in a cookie. After selecting the items that he wants to buy, the attacker changes the price of the ite...
cookie poisoningsession manipulationweb application attacksprice tampering - Question #318Reporting & Remediation
Which of the following attacks can be overcome by applying cryptography?
cryptographysniffing countermeasuresencryptionnetwork eavesdropping - Question #320Reporting & Remediation
You are auditing the security of a client company. You find that their password policy only requires a minimum of 5 characters with letters and numbers. What, if anything, is wrong...
password policyauthentication strengthsecurity auditpassword complexity - Question #321Penetration Testing Foundations & Reconnaissance
In which of the following security tests does the security testing team simulate as an employee or other person with an authorized connection to the organization's network?
local network testingpenetration testing typesinsider threat simulationsecurity assessment - Question #322Exploitation & Post-Exploitation Techniques
You have detected what appears to be an unauthorized wireless access point on your network. However this access point has the same MAC address as one of your real access points and...
evil twin attackrogue access pointMAC spoofingwireless attacks - Question #323Vulnerability Discovery & Scanning
In which of the following scanning methods do Windows operating systems send only RST packets irrespective of whether the port is open or closed?
TCP FIN scanport scanningWindows RST behaviorstealth scanning - Question #324Exploitation & Post-Exploitation Techniques
In which of the following IDS evasion techniques does an attacker deliver data in multiple small sized packets, which makes it very difficult for an IDS to detect the attack signat...
session splicingIDS evasionpacket fragmentationintrusion detection bypass - Question #325Exploitation & Post-Exploitation Techniques
You work as a Network Administrator in the Secure Inc. You often need to send PDF documents that contain secret information, such as, client password, their credit card details, em...
brute force attackspassword crackingPDF securityencryption weaknesses - Question #326Exploitation & Post-Exploitation Techniques
Which of the following tasks can be performed by using netcat utility? Each correct answer represents a complete solution. Choose all that apply.
netcatbackdoor creationport scanningfirewall testing - Question #327Exploitation & Post-Exploitation Techniques
You work as a Network Penetration tester in the Secure Inc. Your company takes the projects to test the security of various companies. Recently, Secure Inc. has assigned you a proj...
EttercapFTP sniffingcredential capturenetwork sniffing - Question #328Penetration Testing Foundations & Reconnaissance
Peter, a malicious hacker, obtains e-mail addresses by harvesting them from postings, blogs, DNS listings, and Web pages. He then sends large number of unsolicited commercial e-mai...
email spamemail harvestingOSINTUCE - Question #329Vulnerability Discovery & Scanning
John works as a professional Ethical Hacker. He has been assigned the project of testing the preattack phase to check the security of the We-are-secure network: l Gathering informa...
SuperScanport scanningservice identificationreconnaissance - Question #331Vulnerability Discovery & Scanning
You work as a Penetration Tester for the Infosec Inc. Your company takes the projects of security auditing. Recently, your company has assigned you a project to test the security o...
idle scanIPID analysisHpingzombie scanning - Question #332Penetration Testing Foundations & Reconnaissance
Joseph works as a Network Administrator for WebTech Inc. He has to set up a centralized area on the network so that each employee can share resources and documents with one another...
intranetnetwork administrationresource sharing - Question #333Penetration Testing Foundations & Reconnaissance
Adam works as a professional Computer Hacking Forensic Investigator. He works with the local police. A project has been assigned to him to investigate an iPod, which was seized fro...
digital forensicsiPod investigationMac OSforensic tools - Question #334Web Application Penetration Testing
Which of the following tools is an automated tool that is used to implement SQL injections and to retrieve data from Web server databases?
SQL injectionAbsintheautomated exploitationweb database - Question #335Penetration Testing Foundations & Reconnaissance
Which of the following methods will free up bandwidth in a Wireless LAN (WLAN)?
WLANSSID broadcastwireless bandwidthnetwork configuration - Question #336Penetration Testing Foundations & Reconnaissance
Which of the following is a passive information gathering tool?
Whoispassive reconnaissanceOSINTinformation gathering - Question #339Penetration Testing Foundations & Reconnaissance
Mark works as a Network Administrator for NetTech Inc. The company has a Windows 2003 Active Directory domain-based network. The domain consists of a domain controller, two Windows...
PEAPWEPwireless authenticationEAP - Question #340Exploitation & Post-Exploitation Techniques
You work as a professional Ethical Hacker. You are assigned a project to perform blackhat mechanic. You claim that someone from the office called you saying that there is some faul...
physical securitydisk encryptionKnoppix Live CDboot attack - Question #341Vulnerability Discovery & Scanning
You want to run the nmap command that includes the host specification of 202.176.56-57.*. How many hosts will you scan?
nmapIP range notationhost count calculationnetwork scanning - Question #342Exploitation & Post-Exploitation Techniques
John works as a professional Ethical Hacker. He has been assigned a project to test the security secure.c Considering the above scenario, which of the following statements are true...
Linux file permissionsoctal permissionschmodaccess control - Question #343Web Application Penetration Testing
John works as a Professional Penetration Tester. He has been assigned a project to test the ='or''=' as a username and successfully logs on to the user page of the Web site. Now, J...
SQL injectioninput sanitizationmysql_real_escape_stringPHP security - Question #344Web Application Penetration Testing
Which of the following Web authentication techniques uses a single sign-on scheme?
single sign-onMicrosoft Passportweb authenticationSSO - Question #345Exploitation & Post-Exploitation Techniques
Which of the following tools is spyware that makes Windows clients send their passwords as clear text?
C2MYAZZspywarecleartext credentialspassword interception - Question #346Cloud & Pivoting Techniques
Which of the following tools allow you to perform HTTP tunneling? Each correct answer represents a complete solution. Choose all that apply.
HTTP tunnelingproxy toolstraffic encapsulationanonymization - Question #347Penetration Testing Foundations & Reconnaissance
You want to create a binary log file using tcpdump. Which of the following commands will you use?
tcpdumppacket capturebinary loggingnetwork sniffing - Question #348Penetration Testing Foundations & Reconnaissance
Which of the following standards is used in wireless local area networks (WLANs)?
IEEE 802.11bwireless standardsWLANnetworking fundamentals