GPEN Exam Questions
442 real GPEN exam questions with expert-verified answers and explanations. Page 8 of 9.
- Question #402
Analyze the command output below. Given this information, which is the appropriate next step for the tester? Starting Nmap4.53 (hnp://insecure.org I at2010-09-30 19:13 EDT interest...
- Question #403
The resulting business impact, of the penetration test or ethical hacking engagement is explained in what section of the final report?
- Question #404
You have been contracted to map me network and try to compromise the servers for a client. Which of the following would be an example of scope creep' with respect to this penetrati...
- Question #405
You are running a vulnerability scan on a remote network and the traffic Is not making It to the target system. You investigate the connection issue and determine that the traffic...
- Question #406
Identify the network activity shown below;
- Question #407
You have compromised a Windows workstation using Metasploit and have injected the Meterpreter payload into the svchost process. After modifying some files to set up a persistent ba...
- Question #408
How can web server logs be leveraged to perform Cross-Site Scripting (XSSI?
- Question #409
What is the impact on pre-calculated Rainbow Tables of adding multiple salts to a set of passwords?
- Question #410
You are done pen testing a Windows system and need to clean up some of the changes you have made. You created an account `pentester' on the system, what command would you use to de...
- Question #411
Your company has decided that the risk of performing a penetration test Is too great. You would like to figure out other ways to find vulnerabilities on their systems, which of the...
- Question #412
Analyze the command output below, what action is being performed by the tester?
- Question #413
Raw netcat shells and telnet terminals share which characteristic?
- Question #414
How can a non-privileged user on a Unix system determine if shadow passwords are being used?
- Question #415
When DNS is being used for load balancing, why would a penetration tester choose to identify a scan target by its IP address rather than its host name?
- Question #416
What problem occurs when executing the following command from within a netcat raw shell? sudo cat /etc/shadow
- Question #417
You are pen testing a Windows system remotely via a raw netcat shell. You want to get a listing of all the local users in the administrators group, what command would you use?
- Question #418
Analyze the screenshot below. What type of vulnerability is being attacked?
- Question #419
You have compromised a Windows workstation using Metasploit and have injected the Meterpreter payload into the smss process. You want to dump the SAM database of the remote system...
- Question #420
Which of the following is the feature that separates the use of Rainbow Tables from other applications such as Cain or John the Ripper?
- Question #421
You suspect that system administrators In one part of the target organization are turning off their systems during the times when penetration tests are scheduled, what feature coul...
- Question #422
You are conducting a penetration test for a private contractor located in Singapore. The scope extends to all internal hosts controlled by the company, you have gathered necessary...
- Question #423
Which of the following is a WEP weakness that makes it easy to Inject arbitrary clear text packets onto a WEP network?
- Question #424
During a penetration test we determine that TCP port 22 is listening on a target host. Knowing that SSHD is the typical service that listens on that port we attempt to validate tha...
- Question #425
Which type of Cross-Sire Scripting (XSS> vulnerability is hardest for automated testing tools to detect, and for what reason?
- Question #426
You are using the Nmap Scripting Engine and want detailed output of the script as it runs. Which option do you include in the command string?
- Question #427
What is the purpose of the following command? C:\>wmic /node:[target IP] /user:[admin-user] /password:[password] process call create [command]
- Question #428
Approximately how many packets are usually required to conduct a successful FMS attack onWEP?
- Question #429
What is the most likely cause of the responses on lines 10 and 11 of the output below?
- Question #430
A penetration tester wishes to stop the Windows Firewall process on a remote host running Windows Vista She issues the following commands: A check of the remote host indicates that...
- Question #431
By default Active Directory Controllers store password representations in which file?
- Question #432
192.168.116.9 Is an IP address forvvww.scanned-server.com. Why are the results from the two scans, shown below, different?
- Question #433
You have been contracted to perform a black box pen test against the Internet facing servers for a company. They want to know, with a high level of confidence, if their servers are...
- Question #434
You successfully compromise a target system's web application using blind command injection. The command you injected is ping-n 1 192.168.1.200. Assuming your machine is 192.168.1...
- Question #435
When a DNS server transfers its zone file to a remote system, what port does it typically use?
- Question #436
Which of the following modes describes a wireless interface that is configured to passively grab wireless frames from one wireless channel and pass them to the operating system?
- Question #437
In the screen shot below, which selections would you need click in order to intercept and alter all http traffic passing through OWASP ZAP?
- Question #438
Which of the following file transfer programs will automatically convert end-of line characters between different platforms when placed in ASCII Mode?
- Question #439
Analyze the command output below. What information can the tester infer directly from the Information shown?
- Question #440
All of the following are advantages of using the Metasploitpriv module for dumping hashes from a local Windows machine EXCEPT:
- Question #441
What command will correctly reformat the Unix passwordcopy and shadowcopy Tiles for input to John The Ripper?
- Question #442
Which of the following best explains why you would warn to clear browser slate (history. cache, and cookies) between examinations of web servers when you've been trapping and alter...
- Question #443
You are performing a wireless penetration lest and are currently looking for rogue access points in one of their large facilities. You need to select an antenna that you can setup...
- Question #444
Analyze the command output below. What information can the tester infer directly from the information shown?
- Question #445
What concept do Rainbow Tables use to speed up password cracking?
- Question #446
When sniffing wireless frames, the interface mode plays a key role in successfully collecting traffic. Which of the mode or modes are best used for sniffing wireless traffic?
- Question #447
Given the following Scapy information, how is default Layer 2 information derived?
- Question #448
A customer has asked for a scan or vulnerable SSH servers. What is the penetration tester attempting to accomplish using the following Nmap command?
- Question #449
While performing an assessment on a banking site, you discover the following link: hnps://mybank.com/xfer.aspMer_toMaccount_number]&amount-[dollars] Assuming authenticated banking...
- Question #450
You are conducting a penetration test for a private company located in the UK. The scope extends to all internal and external hosts controlled by the company. You have gathered nec...
- Question #451
While performing a code audit, you discover a SQL injection vulnerability assuming the following vulnerable query, what user input could be injected to make the query true and retu...