GPEN Exam Questions
442 real GPEN exam questions with expert-verified answers and explanations. Page 9 of 9.
- Question #452
You have compromised a Windows XP system and Injected the Meterpreter payload into the lsass process. While looking over the system you notice that there is a popular password mana...
- Question #453
When attempting to crack a password using Rainbow Tables, what is the output of the reduction function?
- Question #454
You are performing a vulnerability assessment using Nessus and your clients printers begin printing pages of random text and showing error messages. The client is not happy with th...
- Question #455
As pan or a penetration lest, your team is tasked with discovering vulnerabilities that could be exploited from an inside threat vector. Which of the following activities fall with...
- Question #456
Which of the following is the number of bits of encryption that 64-bit Wired Equivalent Privacy (WEP) effectively provides?
- Question #457
Which of the following is a method of gathering user names from a Linux system?
- Question #458
While scanning a remote system that is running a web server with a UDP scan and monitoring the scan with a sniffer, you notice that the target is responding with ICMP Port Unreacha...
- Question #459
Based on the partial appdefstrig rile listed below, which port scan signature is classified by AMap as harmful?
- Question #460
Why is OSSTMM beneficial to the pen tester?
- Question #461
You have connected to a Windows system remotely and have shell access via netcat. While connected to the remote system you notice that some Windows commands work normally while oth...
- Question #462
If the privacy bit is set in the 802.11 header, what does it indicate?
- Question #463
You suspect that a firewall or IPS exists between you and the target machine. Which nmap option will elicit responses from some firewalls and IPSs while being silently dropped by t...
- Question #464
A client has asked for a vulnerability scan on an internal network that does not have internet access. The rules of engagement prohibits any outside connection for the Nessus scann...
- Question #465
You are pen testing a network and have shell access to a machine via Netcat. You try to use ssh to access another machine from the first machine. What is the expected result?
- Question #466
A pen tester is able to pull credential information from memory on a Windows system. Based on the command and output below, what advantage does this technique give a penetration te...
- Question #467
During a penetration test you discover a valid set of SSH credentials to a remote system. How can this be used to your advantage in a Nessus scan?
- Question #468
Where are Netcat's own network activity messages, such as when a connection occurs, sent?
- Question #469
You've been contracted by the owner of a secure facility to try and break into their office in the middle of the night. Your client requested photographs of any sensitive informati...
- Question #470
Which of the following is possible in some SQL injection vulnerabilities on certain types of databases that affects the underlying server OS?
- Question #471
You are pen testing a system and want to use Metasploit 3.X to open a listening port on the system so you can access it via a netcat shell. Which stager would you use to have the s...
- Question #472
Which of the following best describes a server side exploit?
- Question #473
You are conducting a penetration test for a private company located in Canada. The scope extends to all internal-facing hosts controlled by the company. You have gathered necessary...
- Question #474
What is the purpose of die following command: nc.exe -I -p 2222 -e cmd.exe
- Question #475
A tester has been contracted to perform a penetration test for a corporate client. The scope of the test is limited to end-user workstations and client programs only. Which of die...
- Question #476
Why is it important to have a cheat sheet reference of database system tables when performing SQL Injection?
- Question #477
Analyze the command output below. What action is being performed by the tester?
- Question #478
How does OWASP ZAP function when used for performing web application assessments?
- Question #479
You've been asked to test a non-transparent proxy lo make sure it is working. After confirming the browser is correctly pointed at the proxy, you try to browse a web site. The brow...
- Question #480
A penetration tester used a client-side browser exploit from metasploit to get an unprivileged shell prompt on the target Windows desktop. The penetration tester then tried using t...
- Question #481
Analyze the screenshot below. What event is depicted?
- Question #482
Analyze the excerpt from a packet capture between the hosts 192.168.116.9 and 192.168.116.101. What factual conclusion can the tester draw from this output?
- Question #483
What is the main difference between LAN MAN and NTLMv1 challenge/responses?
- Question #484
You have been contracted to penetration test an e-mail server for a client that wants to know for sure if the sendmail service is vulnerable to any known attacks. You have permissi...
- Question #485
What will the following scapy commands do?
- Question #486
You want to find out what ports a system is listening on. What Is the correct command on a Linux system?
- Question #487
You have obtained the hash below from the /etc/shadow file. What are you able to discern simply by looking at this hash?
- Question #488
What difference would you expect to result from running the following commands; (I). S dig _s domain.com target.com -t AXFR and (2). S dig _s.domain.com target.com -t IXFR=10022003...
- Question #490
Analyze the screenshot below, which of the following sets of results will be retrieved using this search?
- Question #491
Which of the following United States laws protects stored electronic information?
- Question #492
Analyze the output of the two commands below: Which of the following can be factually inferred from the results of these commands?
- Question #493
Which protocol would need to be available on a target in order for Nmap to identify services like IMAPS and POP3S?
- Question #494
What is the sequence in which packets are sent when establishing a connection to a secured network?