GPEN Exam Questions
442 real GPEN exam questions with expert-verified answers and explanations. Page 7 of 9.
- Question #349
Anonymizers are the services that help make a user's own Web surfing anonymous. An anonymizer removes all the identifying information from a user's computer while the user surfs th...
- Question #350
You configure a wireless router at your home. To secure your home Wireless LAN (WLAN), you implement WEP. Now you want to connect your client computer to the WLAN. Which of the fol...
- Question #351
Which of the following vulnerability scanner scans from CGI, IDA, Unicode, and Nimda vulnerabilities?
- Question #352
You work as a Network Administrator in the SecureTech Inc. The SecureTech Inc. is using Linuxbased server. Recently, you have updated the password policy of the company in which th...
- Question #353
Which of the following is the correct sequence of packets to perform the 3-way handshake method?
- Question #354
John is a black hat hacker. FBI arrested him while performing some email scams. Under which of the following US laws will john be charged?
- Question #355
Which of the following is a person-to-person attack in which an attacker convinces the target that he or she has a problem or might have a certain problem in the future and that he...
- Question #356
As a professional hacker, you want to crack the security of secureserver.com. For this, in the information gathering step, you performed scanning with the help of nmap utility to r...
- Question #357
Which of the following tools is a Windows-based commercial wireless LAN analyzer for IEEE802.11b and supports all high level protocols such as TCP/IP, NetBEUI, and IPX?
- Question #358
Which of the following tools will you use to prevent from session hijacking? Each correct answer represents a complete solution. Choose all that apply.
- Question #359
Which of the following tools can be used to assign, display, or modify ACLs (access control lists) to files or folders and could also be used within batch files in Windows NT/2000/...
- Question #360
You have received a file named new.com in your email as an attachment. When you execute this file in your laptop, you get the following message: 'EICAR-STANDARD-ANTIVIRUS-TEST-FILE...
- Question #361
You work as a Network Administrator for Tech Perfect Inc. The company has a TCP/IP-based network. Rick, your assistant, is configuring some laptops for wireless access. For securit...
- Question #362
Which of the following security policies will you implement to keep safe your data when you connect your Laptop to the office network over IEEE 802.11 WLANs? Each correct answer re...
- Question #363
Adam works as a professional Computer Hacking Forensic Investigator. A project has been assigned to him to investigate a multimedia enabled mobile phone, which is suspected to be u...
- Question #364
John works as a professional Ethical Hacker. He has been assigned a project to test the security server. Now, he suggests some countermeasures to avoid such brute force attacks on...
- Question #365
Which of the following attacks allows an attacker to recover the key in an RC4 encrypted stream from a large number of messages in that stream?
- Question #367
One of the sales people in your company complains that sometimes he gets a lot of unsolicited messages on his PDA. After asking a few questions, you determine that the issue only o...
- Question #368
You are concerned about attackers simply passing by your office, discovering your wireless network, and getting into your network via the wireless connection. Which of the followin...
- Question #369
You work as a Network Administrator for Tech Perfect Inc. The company has a Windows Active Directory-based single domain single forest network. The functional level of the forest i...
- Question #370
You work as a Network Administrator for Tech Perfect Inc. The company has a Windows Active Directory-based single domain single forest network. The functional level of the forest i...
- Question #371
Which of the following are considered Bluetooth security violations? Each correct answer represents a complete solution. Choose two.
- Question #372
John works as a professional Ethical Hacker. He has been assigned the project of testing the and applications running on the We-are-secure server. For this purpose, he wants to ini...
- Question #373
Which of the following methods can be used to detect session hijacking attack?
- Question #374
Which of the following is generally practiced by the police or any other recognized governmental authority?
- Question #375
Victor wants to use Wireless Zero Configuration (WZC) to establish a wireless network connection using his computer running on Windows XP operating system. Which of the following a...
- Question #376
Which of the following tools can be used by a user to hide his identity? Each correct answer represents a complete solution. Choose all that apply.
- Question #377
Which of the following techniques are NOT used to perform active OS fingerprinting? Each correct answer represents a complete solution. Choose all that apply.
- Question #378
Victor works as a professional Ethical Hacker for SecureEnet Inc. He wants to scan the wireless network of the company. He uses a tool that is a free open-source utility for networ...
- Question #379
John works as a professional Ethical Hacker. He is assigned a project to test the security of Weare- secure Web site and receives the following error message: Microsoft OLE DB Prov...
- Question #380
Which of the following ports must you filter to check null sessions on your network?
- Question #382
Which of the following tools can be used to perform Windows password cracking, Windows enumeration, and VoIP session sniffing?
- Question #383
You enter the following URL on your Web browser: af../windows/system32/cmd.exe?/c+dir+c:\ What task do you want to perform?
- Question #385
ACME corporation has decided to setup wireless (IEEE 802.11) network in it's sales branch at Tokyo and found that channels 1, 6, 9,11 are in use by the neighboring offices. Which i...
- Question #386
Which Metasploitvncinject stager will allow VNC communications from the attacker to a listening port of the attacker's choosing on the victim machine?
- Question #387
What is the MOST important document to obtain before beginning any penetration testing?
- Question #388
While reviewing traffic from a tcpdump capture, you notice the following commands being sent from a remote system to one of your web servers: C:\>sc winternet.host.com create ncser...
- Question #389
Which of the following best describes a client side exploit?
- Question #390
Which of the following TCP packet sequences are common during a SYN (or half-open) scan? (a) The source computer sends SYN and the destination computer responds with RST (b) The so...
- Question #391
Which of the following describes the direction of the challenges issued when establishing a wireless (IEEE 802.11) connection?
- Question #392
You have gained shell on a Windows host and want to find other machines to pivot to, but the rules of engagement state that you can only use tools that are already available. How c...
- Question #393
A penetration tester obtains telnet access to a target machine using a captured credential. While trying to transfer her exploit to the target machine, the network intrusion detect...
- Question #394
What section of the penetration test or ethical hacking engagement final report is used to detail and prioritize the results of your testing?
- Question #395
You are pen testing a Windows system remotely via a raw netcat shell. You want to quickly change directories to where the Windows operating system resides, what command could you u...
- Question #396
A client with 7200 employees in 14 cities (all connected via high speed WAN connections) has suffered a major external security breach via a desktop which cost them more than SI 72...
- Question #397
Which Metasploit payload includes simple upload and download functionality for moving files to and from compromised systems?
- Question #398
A junior penetration tester at your firm is using a non-transparent proxy for the first time to test a web server. He sees the web site In his browser but nothing shows up In the p...
- Question #399
Which of the following describe the benefits to a pass-the-hash attack over traditional password cracking?
- Question #400
You are pen testing a Linux target from your windows-based attack platform. You just moved a script file from the windows system to the Linux target, but it will not execute proper...
- Question #401
Which of the following is the JavaScript variable used to store a cookie?