GIAC Penetration Tester (GPEN) Exam Prep
Free practice questions

Free GPEN Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,050-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

The GPEN exam has 82 questions and runs 3 hours.

These 10 free GPEN questions are organized by exam domain, so you can see how each part of the GIAC Penetration Tester (GPEN) blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Advanced Password Attacks

Question 1

Before an external engagement begins, a penetration tester wants a single document that authorizes the testing activity and provides legal protection if their activity is questioned by law enforcement or a third party. Which document serves this purpose?

Show answer & explanation

Correct answer: B - A signed authorization / permission memo, often called a "get-out-of-jail-free" letter

Domain 2: Attacking Password Hashes

Question 2

During reconnaissance, a tester issues a DNS AXFR request to a target's name server and receives a complete list of the domain's host records. What has the tester discovered?

Show answer & explanation

Correct answer: C - A misconfigured server that permits an unauthorized full zone transfer of records

Domain 3: Azure Applications and Attack Strategies

Question 3

A tester runs `nmap -sn 10.10.0.0/24` against a target range. What does this command do?

Show answer & explanation

Correct answer: A - Discovers which hosts are alive without scanning any of their ports

Question 4

An Nmap scan returns a port in the `filtered` state. What is the most accurate interpretation of this result?

Show answer & explanation

Correct answer: D - A packet filter is likely dropping the probes, so Nmap cannot tell if it is open

Domain 4: Azure Overview, Attacks, and AD Integration

Question 5

A vulnerability scanner reports a critical finding on a host, but manual verification shows the affected service is not actually exploitable in this environment. Separately, the team notes that authenticated scans of the same host consistently reveal far more issues than unauthenticated ones. Which pair of concepts do these two observations illustrate?

Show answer & explanation

Correct answer: C - A false positive requiring validation, and the greater depth of credentialed scanning

Domain 5: Command and Control (C2)

Question 6

A tester compromises a host that sits behind a firewall blocking all inbound connections, though outbound traffic is permitted. To obtain interactive shell access, which approach will work?

Show answer & explanation

Correct answer: B - A reverse shell that connects outbound from the host back to the tester's listener

Domain 6: Domain Escalation and Persistence Attacks

Question 7

Within the Metasploit Framework, which module category is used to perform tasks such as port scanning, service enumeration, and login brute-forcing without delivering a payload to the target?

Show answer & explanation

Correct answer: A - Auxiliary

Question 8

A tester is choosing between the payloads `windows/meterpreter/reverse_tcp` and `windows/meterpreter_reverse_tcp`. What is the practical difference signaled by the slash versus the underscore?

Show answer & explanation

Correct answer: D - The slash version is staged and sent in parts; the underscore version is stageless

Domain 7: Escalation and Exploitation

Question 9

After compromising a dual-homed host, a tester needs their local tools to reach an internal subnet that is only routable from that host. They want to tunnel arbitrary tools through the foothold using a proxy. Which SSH option sets up the dynamic SOCKS proxy needed for this?

Show answer & explanation

Correct answer: C - The `-D` option, which stands up a dynamic SOCKS proxy for pivoting to many hosts

Domain 8: Exploitation Fundamentals

Question 10

A tester wants to attack Active Directory accounts over the network but must avoid triggering account lockouts. Which password attack is specifically designed to stay under lockout thresholds?

Show answer & explanation

Correct answer: A - Password spraying, which tries one common password across many different accounts

The rest of the GPEN blueprint

The GPEN exam also covers these domains. Drill them in the full free practice test:

That's 10 of 1,050

The full bank has 1,040 more GPEN questions with explanations.

Continue in the free practice test →

View plans