GPEN Exam Questions
442 real GPEN exam questions with expert-verified answers and explanations. Page 8 of 9.
- Question #402Vulnerability Discovery & Scanning
Analyze the command output below. Given this information, which is the appropriate next step for the tester? Starting Nmap4.53 (hnp://insecure.org I at2010-09-30 19:13 EDT interest...
Nmap output analysisSMB enumerationNetBIOSnetwork reconnaissance - Question #403Reporting & Remediation
The resulting business impact, of the penetration test or ethical hacking engagement is explained in what section of the final report?
pentest report structureexecutive summarybusiness impactreporting - Question #404Penetration Testing Foundations & Reconnaissance
You have been contracted to map me network and try to compromise the servers for a client. Which of the following would be an example of scope creep' with respect to this penetrati...
scope creeprules of engagementengagement boundariespentest ethics - Question #405Vulnerability Discovery & Scanning
You are running a vulnerability scan on a remote network and the traffic Is not making It to the target system. You investigate the connection issue and determine that the traffic...
firewall troubleshootingNATvulnerability scan connectivitynetwork path analysis - Question #406Exploitation & Post-Exploitation Techniques
Identify the network activity shown below;
ARP spoofinggateway impersonationMITM attacknetwork traffic analysis - Question #407Exploitation & Post-Exploitation Techniques
You have compromised a Windows workstation using Metasploit and have injected the Meterpreter payload into the svchost process. After modifying some files to set up a persistent ba...
Meterpretertimestompinganti-forensicspost-exploitation - Question #408Web Application Penetration Testing
How can web server logs be leveraged to perform Cross-Site Scripting (XSSI?
log injectionXSSXSSIweb server logs - Question #409Exploitation & Post-Exploitation Techniques
What is the impact on pre-calculated Rainbow Tables of adding multiple salts to a set of passwords?
rainbow tablespassword saltinghash tablespassword cracking - Question #410Exploitation & Post-Exploitation Techniques
You are done pen testing a Windows system and need to clean up some of the changes you have made. You created an account `pentester' on the system, what command would you use to de...
Windows commandsnet useraccount cleanuppost-exploitation - Question #411Penetration Testing Foundations & Reconnaissance
Your company has decided that the risk of performing a penetration test Is too great. You would like to figure out other ways to find vulnerabilities on their systems, which of the...
penetration testing alternativesrisk assessmentvulnerability managementscope - Question #412Penetration Testing Foundations & Reconnaissance
Analyze the command output below, what action is being performed by the tester?
user enumerationWindows reconnaissanceaccount discoverycommand analysis - Question #413Exploitation & Post-Exploitation Techniques
Raw netcat shells and telnet terminals share which characteristic?
netcattelnetraw shellsterminal emulation - Question #414Penetration Testing Foundations & Reconnaissance
How can a non-privileged user on a Unix system determine if shadow passwords are being used?
shadow passwordsUnix authentication/etc/passwdcredential storage - Question #415Vulnerability Discovery & Scanning
When DNS is being used for load balancing, why would a penetration tester choose to identify a scan target by its IP address rather than its host name?
DNS load balancingIP scanningtarget identificationscan accuracy - Question #416Exploitation & Post-Exploitation Techniques
What problem occurs when executing the following command from within a netcat raw shell? sudo cat /etc/shadow
netcat shellsudo TTYprivilege escalationshell limitations - Question #417Exploitation & Post-Exploitation Techniques
You are pen testing a Windows system remotely via a raw netcat shell. You want to get a listing of all the local users in the administrators group, what command would you use?
net localgroupWindows commandslocal administratorsuser enumeration - Question #418Exploitation & Post-Exploitation Techniques
Analyze the screenshot below. What type of vulnerability is being attacked?
browser exploitationInternet Explorerclient-side vulnerabilityMetasploit - Question #419Exploitation & Post-Exploitation Techniques
You have compromised a Windows workstation using Metasploit and have injected the Meterpreter payload into the smss process. You want to dump the SAM database of the remote system...
MeterpreterSAM databasepassword dumpingMetasploit modules - Question #420Exploitation & Post-Exploitation Techniques
Which of the following is the feature that separates the use of Rainbow Tables from other applications such as Cain or John the Ripper?
rainbow tablespre-calculated hashespassword crackingCain and Abel - Question #421Penetration Testing Foundations & Reconnaissance
You suspect that system administrators In one part of the target organization are turning off their systems during the times when penetration tests are scheduled, what feature coul...
rules of engagementtest schedulingpenetration testing methodologyscope definition - Question #422Penetration Testing Foundations & Reconnaissance
You are conducting a penetration test for a private contractor located in Singapore. The scope extends to all internal hosts controlled by the company, you have gathered necessary...
Computer Misuse ActSingapore lawlegal liabilityscope compliance - Question #423Exploitation & Post-Exploitation Techniques
Which of the following is a WEP weakness that makes it easy to Inject arbitrary clear text packets onto a WEP network?
WEPwireless securityCRC32 weaknesspacket injection - Question #424Vulnerability Discovery & Scanning
During a penetration test we determine that TCP port 22 is listening on a target host. Knowing that SSHD is the typical service that listens on that port we attempt to validate tha...
version scanningservice identificationNmapport scanning - Question #425Web Application Penetration Testing
Which type of Cross-Sire Scripting (XSS> vulnerability is hardest for automated testing tools to detect, and for what reason?
stored XSSreflected XSSautomated scanningXSS detection - Question #426Vulnerability Discovery & Scanning
You are using the Nmap Scripting Engine and want detailed output of the script as it runs. Which option do you include in the command string?
Nmap NSEscript tracingscan verbositycommand options - Question #427Exploitation & Post-Exploitation Techniques
What is the purpose of the following command? C:\>wmic /node:[target IP] /user:[admin-user] /password:[password] process call create [command]
WMICremote command executionlateral movementWindows management - Question #428Exploitation & Post-Exploitation Techniques
Approximately how many packets are usually required to conduct a successful FMS attack onWEP?
WEPFMS attackwireless cryptanalysisIV attack - Question #429Penetration Testing Foundations & Reconnaissance
What is the most likely cause of the responses on lines 10 and 11 of the output below?
tracerouteICMP TTLnetwork topologyfirewall detection - Question #430Exploitation & Post-Exploitation Techniques
A penetration tester wishes to stop the Windows Firewall process on a remote host running Windows Vista She issues the following commands: A check of the remote host indicates that...
Windows Firewallsc commandremote administrationpost-exploitation - Question #431Exploitation & Post-Exploitation Techniques
By default Active Directory Controllers store password representations in which file?
Active Directoryntds.ditcredential storageWindows - Question #432Exploitation & Post-Exploitation Techniques
192.168.116.9 Is an IP address forvvww.scanned-server.com. Why are the results from the two scans, shown below, different?
John the Ripperpassword crackingrestore filetool configuration - Question #433Penetration Testing Foundations & Reconnaissance
You have been contracted to perform a black box pen test against the Internet facing servers for a company. They want to know, with a high level of confidence, if their servers are...
penetration testing methodologyfalse positivesvulnerability validationblack box testing - Question #434Web Application Penetration Testing
You successfully compromise a target system's web application using blind command injection. The command you injected is ping-n 1 192.168.1.200. Assuming your machine is 192.168.1...
blind command injectionICMPcommand executionweb application - Question #435Penetration Testing Foundations & Reconnaissance
When a DNS server transfers its zone file to a remote system, what port does it typically use?
DNSzone transferAXFRTCP 53 - Question #436Penetration Testing Foundations & Reconnaissance
Which of the following modes describes a wireless interface that is configured to passively grab wireless frames from one wireless channel and pass them to the operating system?
wireless modesmonitor modepacket capturewireless interface - Question #437Web Application Penetration Testing
In the screen shot below, which selections would you need click in order to intercept and alter all http traffic passing through OWASP ZAP?
OWASP ZAPHTTP interceptionweb proxytraffic manipulation - Question #438Exploitation & Post-Exploitation Techniques
Which of the following file transfer programs will automatically convert end-of line characters between different platforms when placed in ASCII Mode?
FTPASCII modefile transferend-of-line conversion - Question #439Penetration Testing Foundations & Reconnaissance
Analyze the command output below. What information can the tester infer directly from the Information shown?
OSINTdocument enumerationnaming conventionsinformation gathering - Question #440Exploitation & Post-Exploitation Techniques
All of the following are advantages of using the Metasploitpriv module for dumping hashes from a local Windows machine EXCEPT:
Metasploithash dumpingcredential accessWindows - Question #441Exploitation & Post-Exploitation Techniques
What command will correctly reformat the Unix passwordcopy and shadowcopy Tiles for input to John The Ripper?
John the RipperunshadowUnix passwordspassword cracking - Question #442Web Application Penetration Testing
Which of the following best explains why you would warn to clear browser slate (history. cache, and cookies) between examinations of web servers when you've been trapping and alter...
web proxybrowser cookiesHTTP interceptionweb testing methodology - Question #443Penetration Testing Foundations & Reconnaissance
You are performing a wireless penetration lest and are currently looking for rogue access points in one of their large facilities. You need to select an antenna that you can setup...
wireless antennadirectional antennarogue AP detectionwireless reconnaissance - Question #444Penetration Testing Foundations & Reconnaissance
Analyze the command output below. What information can the tester infer directly from the information shown?
SambaSMBnull sessionsservice enumeration - Question #445Exploitation & Post-Exploitation Techniques
What concept do Rainbow Tables use to speed up password cracking?
rainbow tablestime-memory tradeoffhash crackingpassword cracking - Question #446Penetration Testing Foundations & Reconnaissance
When sniffing wireless frames, the interface mode plays a key role in successfully collecting traffic. Which of the mode or modes are best used for sniffing wireless traffic?
RFMONwireless sniffingmonitor modewireless interface - Question #447Exploitation & Post-Exploitation Techniques
Given the following Scapy information, how is default Layer 2 information derived?
ScapyLayer 2packet craftingnetwork stack - Question #448Vulnerability Discovery & Scanning
A customer has asked for a scan or vulnerable SSH servers. What is the penetration tester attempting to accomplish using the following Nmap command?
NmapSSH scanningprotocol versionservice detection - Question #449Web Application Penetration Testing
While performing an assessment on a banking site, you discover the following link: hnps://mybank.com/xfer.aspMer_toMaccount_number]&amount-[dollars] Assuming authenticated banking...
CSRFcross-site request forgeryHTML injectionweb authentication - Question #450Penetration Testing Foundations & Reconnaissance
You are conducting a penetration test for a private company located in the UK. The scope extends to all internal and external hosts controlled by the company. You have gathered nec...
Computer Misuse Actlegal liabilityscope definitionpassword cracking - Question #451Web Application Penetration Testing
While performing a code audit, you discover a SQL injection vulnerability assuming the following vulnerable query, what user input could be injected to make the query true and retu...
SQL injectionauthentication bypassinput validationquery manipulation