Browse all practice questions for the SANS560 GIAC Penetration Tester (GPEN) Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

SANS560 GIAC Penetration Tester (GPEN) Practice Test course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • Which tool can Scapy invoke to visually analyze captured traffic?
  • Which attack injects input that contains a browser script, which if the target site is vulnerable to XSS, will be passed to the site's users?
  • Which tool is described as one of the easiest ways to execute commands on a remote machine, with no preloading required?
  • Why record plugin configuration before testing?
  • Which command pattern is commonly used to perform a ping sweep by iterating over IP addresses?
  • In a pass-the-hash scenario, what credential is used to authenticate without providing plaintext passwords?
  • Which legacy password storage method is commonly used on many UNIX flavors?
  • When you discover an urgent issue, high risk vulnerability, or evidence of a previous intrusion, what should you have in place during a penetration engagement?
  • Which statement best describes Metasploit payloads that reside in memory and disappear on reboot?
  • How many letters should you type to identify a command in PowerShell?
  • What is the purpose of the 'multi' directory in Metasploit's exploit structure?
  • Which standard is commonly used as the basis for testing and assessing security controls?
  • Hashcat is best described as which tool?
  • In the context of restricted scans, which option represents a method to narrow the port set during a large environment?
  • NetCat Listener can capture connection strings from clients to reveal software types, versions, and protocols.
  • What must be accomplished before you can download new Nessus plugins?
  • Which Scapy function reads packets from a capture file?
  • Which command prints the current working directory in a Unix-like shell?
  • Which Meterpreter command lists compatible webcams on the target machine?
  • Which resource provides a free, downloadable Open Source Vulnerability Database tool that can be stored locally and accessed offline?
  • What does Metasploit's database primarily store to enable advanced queries?
  • Scapy can see more than how many protocols?
  • Which Meterpreter command shows the system name and OS type of the compromised machine?
  • In NTLMv2, what is used as the key in the first HMAC-MD5 operation?
  • In Hashcat rule syntax, what is the effect of whitespace within a rule?
  • For large-scale password cracking, what is the legal and practical alternative to using a botnet?
  • In Nikto, which option is used to specify the website to scan when virtual hosting is enabled on the target?
  • Exploit Database (Exploit-db) hosts more than how many exploits?
  • How is HackerStorm defined in these notes?
  • Which tool can operate as a Nessus plugin while focusing on web server vulnerabilities?
  • What does the Code Execution module do in Empire?
  • Pass-the-ticket attacks exploit which authentication mechanism by using tickets in memory?
  • Which option best describes LANMAN Challenge / Response?
  • Which NetCat option sets a timeout for connections (-w)?
  • For a pass-the-hash attack to work, what must the attacker obtain?
  • What is Nessus primarily used for in a network security assessment?
  • Why is the hashcat.potfile considered sensitive?
  • Which Meterpreter command terminates a given process?
  • War dialing involves what activity?
  • In Linux, what does a password field value of 'x' in /etc/passwd indicate?
  • What does the hashcat -show option do?
  • OSSTMM focuses on which of the following in security testing?
  • What does CIDR notation enable in Scapy when specifying destinations?
  • What is the impact of interruption of production processing?
  • How are port ranges specified in Scapy when crafting a packet?
  • Which command directs traffic from a target subnet through a Meterpreter session to another victim?
  • What is another common name for NMAP's host discovery sweep?
  • Which Nikto test category looks for resources that allow an attacker to execute shell commands or gain a remote shell?
  • Why would testers perform exploits during engagement?
  • Which vulnerability scanner is derived from SATAN and is considered the original vulnerability scanner?
  • What difficulty is noted when reviewing a collaborative PowerShell session?
  • In Linux, if a password field has an 'x' in /etc/passwd, where are the actual password hashes stored?
  • Which OSINT activity is described as gathering publicly available information about the target?
  • Which statement best describes the 'shell_bind_tcp' payload?
  • Which statement describes the 'reverse_http' payload?
  • In PowerShell, where are environment variables stored?
  • What type of sensitive information might be obtained from a configured wireless LAN profile on a compromised machine?
  • Strategy Maps help communicate strategy to the entire organization.
  • Which activity aims to discern the topology of the target network by drawing a network map?
  • Which function sends a packet and waits to receive a response from the target?
  • Which action helps avoid third-party malicious activity during testing?
  • Which topics are typically outlined within the contract of work?
  • FSDB stands for which database?
  • Meterpreter is best described as:
  • Which password hash types are listed as crackable by John the Ripper?
  • If the password is shorter than 14 characters, what happens to the password hash?
  • What technique might be used to prevent scanners from waiting for timeouts by altering firewall rules for closed ports?
  • Which insurance coverage is typically carried by pen test companies alongside liability?
  • Approximately how many iterations are performed in the described MD5-based password hashing process?
  • LANMAN C/R and NTLMv1 use the same padding, splitting, and encrypting steps. What is different between them?
  • Cmdlet Aliases in PowerShell provide what?
  • Which command recursively searches the file system for a specific file, listing full path?
  • The '30/60/90' framework describes what?
  • Which script category checks for malware or backdoors?
  • In an executive summary, how should high-risk findings be presented?
  • Which tactic is commonly used in red teaming to gain access to devices such as modems?
  • Netcat can grab multiple service strings from a series of ports on a target by connecting to ports in a specific sequence. This sequence starts at port Y and decrements by 1 until reaching port X. Which description best matches this port sequence?
  • What is a typical objective of post-exploitation activities?
  • In Nikto, which option allows scanning on ports other than the default HTTP port (80)?
  • Business Model describes how you operate, generate revenue and profit, and deliver value at a reasonable cost. Which option completes this description?
  • Which are common backend databases for web apps?
  • How many forces are defined in Porter's Five Forces framework?
  • If the password is 15 characters or longer, Windows stores encrypted padding for that user's hash. What is the effect?
  • What is a likely admin response to deliberate backdoors during testing?
  • Which shell operator is used to execute a second command only if the first succeeds?
  • Which method can be used to harvest documents for metadata analysis?
  • Which cmdlet lists the contents of a directory in PowerShell?
  • Which function sends packets at Layer 3 and does not wait for a response?
  • By default, how often does Nessus schedule plugin updates?
  • Veil-Evasion is used for what purpose in penetration testing?
  • Pass the Hash is a technique used to authenticate using what?
  • The text notes that p0f can support which form of command injection?
  • Approximately how many known flawed scripts does Nikto scan for?
  • Which PowerShell cmdlet can inspect internal variables and environment variables?
  • If you lock out an account during testing, which action is recommended?
  • Which factor describes how the number of customers, their importance to the business, and the cost of switching customers affect a firm?
  • Recon-NG is best described as what?
  • Cain's sniffer can decode which VOIP-related protocols?
  • Which statement best describes Nikto's scanning scope?
  • What are the two main XSS vulnerability categories mentioned?
  • Which command displays account lockout statistics on Windows?
  • Nikto: Web Server Vuln Scanner is written in which programming language?
  • What information is commonly stored in a document's metadata?
  • What does the 'db_import' command do in Metasploit?
  • Cains: Password Cracking which Cain module contains password cracking features for most password types a tester could encounter?
  • Which SIMD extension is associated with speed improvements for multimedia operations and is mentioned alongside SSE2?
  • What does ls(packet) do in Scapy?
  • In the described agreement, liability is capped at what value?
  • What best describes local privilege escalation on a target system?
  • If you remove a host entry in the Metasploit database, what happens to related services and vulnerabilities?
  • Which force evaluates the level of competition among existing firms and their capabilities?
  • Which NetCat option puts NetCat into listen mode?
  • In a password guessing test, what action helps mitigate risk of lockouts while testing?
  • Within Nikto's focusing tests, which category covers file upload vulnerabilities?
  • Which file contains the actual password hashes on modern Linux systems?
  • Which term defines the boundaries and limitations of an engagement?
  • In Meterpreter, which command dumps a file to standard output (the screen)?
  • Which force addresses how easy it is for new competitors to enter the market and threaten incumbents?
  • Extreme Emergency procedures in case of testing incidents typically involve which action?
  • The Metasploit database stores data across several tables; which of the following are among the key tables used to track discovered network information?
  • How is exploitation defined in this context?
  • Which directive reveals contents within a directory when directory indexing is enabled?
  • What does the idletime Meterpreter command report?
  • What does the norecurse option do in NSLookup?
  • Which command shows the Windows firewall settings, including all profiles?
  • What is the difference between a full zone transfer (AXFR) and an incremental zone transfer (IXFR) in DNS?
  • Which command shows the cracked passwords recorded by John the Ripper?
  • ARIN will respond with summary records if there are any matches. Each summary line includes a link for more detailed information. What does the summary record provide at a minimum?
  • What is the definition of lockout threshold?
  • Which NetCat option disables hostname resolution?
  • Which section describes the process used and results from each stage?
  • Which tool is described as a framework for collaboration and reporting in information security assessments?
  • Which hashing algorithm is used to create NT hashes?
  • In a rules of engagement, what information should typically be limited to after compromising a target host?
  • Hydra can be used against which scope?
  • In NTLMv1, what differs from LANMAN besides the hash used?
  • After exploitation, what factors determine the choice of file transfer methods?
  • Which tool pulls information about locked-out accounts from Active Directory?
  • Which sources can reveal client-side programs used by the target's users?
  • Which term describes the process of deep analysis of the state of the business and threats faced by the organization?
  • Which statement about Scapy's destination addressing is true?
  • Which Windows utility can invoke the services GUI?
  • What is the function of 'reverse_tcp_allports'?
  • Which command displays the contents of a file on Standard Output?
  • After password-cracking tests, what data-handling practice is essential for sensitive credential files and cracking results?
  • Which statement about Netcat is true?
  • Which script category is designed for minimal impact on target systems?
  • Which statement accurately contrasts Vertical and Horizontal business models?
  • Finer-Grained NMAP Timing Options generally refer to what?
  • Which of the following is described as a plausible method to gain internal access?
  • Into how many parts is the LM hash divided after padding, and what are these parts called?
  • What does the 'shell_reverse_tcp' payload do?
  • As a leader you must strive to lead, motivate, and inspire your team members and colleagues to accomplish their goals of the overall strategic planning process.
  • Which statement about sniffing the challenge/response traffic is true?
  • Crystal Box testing is described as more cost-effective because attackers don't have to figure out their way through the network, whereas Black Box testing can take longer due to scans and reconnaissance. Which option best represents Crystal Box testing?
  • Which attack uses Kerberos tickets stolen in memory to authenticate to services on a target system?
  • What is the purpose of NMAP's badsum scans?
  • Besides scheduled updates, how can Nessus plugin updates be applied?
  • Which protocol moves files with no authentication between a TFTP client and tftpd using UDP port 69?
  • What does the uict1 Meterpreter command control?
  • Which Meterpreter feature provides techniques for local privilege escalation to SYSTEM-level access on a Windows machine?
  • In Nikto, which option directs scan results to a file?
  • What is a recommended practice to observe network traffic during scanning?
  • What is a key risk when using a fast TCP SYN scanning tool like ScanRand?
  • Which Empire module category provides a way for an agent to survive across logoff or reboot actions by modifying Run Registry keys, logon scripts, or system boot programs?
  • What is the primary purpose of the Windows Service Controller command (sc) in a security test?
  • Which capability is highlighted as part of Cain's sniffer?
  • Which function sends and receives packets using Layer 2 components you specify?
  • Which NMAP feature prints live status messages about packet send/receive, protocol, and IP addresses?
  • What capability describes how PsExec channels the command's Standard Input and Standard Output between attacker and target?
  • Which function allows Scapy to loop through a series of packets and send the same packet repeatedly?
  • Findings are typically categorized into which severity levels?
  • Which is an advantage of pass-the-hash attacks?
  • Which statement describes an injection attack?
  • Which command is a common alias for Get-ChildItem when listing directory items?
  • What is the purpose of db_connect and db_status in Metasploit's database integration?
  • Which lab focuses on NMAP usage including OS detection and service version detection?
  • Which command turns the program you want to run into a service on a target machine?
  • The browser-script attack concept is attributed to which researcher?
  • What is the primary purpose of maintaining an inventory during testing, such as a spreadsheet including system name, IP address, and OS?
  • Which PowerShell feature provides examples and usage details for commands?
  • The source notes a web client capable of fetching a file from a web server. In reconnaissance, what is the primary use of such a web client?
  • In Meterpreter keystroke logging, what does keyscan_start do?
  • Which types of data are commonly found in document metadata?
  • Which mode enables writing your own C code to formulate guesses?
  • Which method combination can yield passwords without cracking, as described in the material?
  • Which concept focuses on executing the plan by navigating internal values and culture, developing a business case to get support and funding, and promoting your activities?
  • If a hash has already been cracked, what does John the Ripper do when you run it again?
  • In command-line redirection, what does the sequence "command 2>>errorfile.txt" accomplish?
  • What may the Introduction section include regarding tools/processes?
  • In Metasploit, which identifiers link a service or vulnerability record to its host?
  • Which information is typically included for findings discovered during the test?
  • In Nikto's focusing tests, which category corresponds to remote file retrieval?
  • Why might an tester review open job postings for a target organization?
  • Auto configures agents, setting them up to call back listeners with a minimal need to fine tune settings. Which warning capability is included?
  • Which item is not one of Porter's Five Forces?
  • Which practice improves PowerShell usability by shortening flags?
  • Which NetCat option specifies the local port to use?
  • Cain's ARP-Poisoned Routing feature enables what action?
  • Which capability allows Empire to operate without launching a PowerShell executable by injecting into other processes?
  • What is the documented speed boost range for MMX and SSE2?
  • What is the primary purpose of the Compromise & Pivot phase in a penetration test?
  • Lockout duration is defined as:
  • Which product provides a GUI for Metasploit and integrates scanning with exploitation components?
  • Which technique provides remote VNC control of the target's GUI?
  • Which NMAP option performs a host discovery sweep to identify live hosts?
  • In Meterpreter, what is the role of Encoders?
  • What is the primary purpose of the crypt(3) library on UNIX-like systems?
  • Which credential technique involves authenticating using a hash instead of a password?
  • Which Meterpreter command can be used to migrate the session to another process via DLL injection?
  • Within the rules of engagement, what must be defined to bound testing time?
  • What is the purpose of Open MPI in password cracking?
  • What file is used to record plugin feed information before testing in Nessus?
  • Strategy Maps highlight gaps in strategy implementation.
  • In DNS, AXFR transfers are used to perform what type of transfer?
  • Which command can control most aspects of Windows networking, including IP address, bridging, and routing?
  • Which command adds or sets a registry value?
  • Which type of DNS server data file includes information about hostnames and IP addresses?
  • When is the SYSKEY password used during system operation?
  • Which approach involves limiting scans to ports approved by the firewall configuration, but may be invasive and not assess firewall failures?
  • Which description best captures the purpose of Porter's Five Forces framework?
  • What is a key consideration when conducting pen testing from the cloud?
  • Which statement best describes an injection attack?
  • Which Windows PowerShell cmdlet lists all running processes on the local system?
  • The SQL Server system objects table includes entries with xtype that correspond to which objects when xtype equals U?
  • Which activity best describes gathering publicly available information about a target organization’s major businesses, products/services, leadership, competitors, locations, and recent press releases?
  • Which command-line option in Hashcat is used to specify a rules file?
  • Which scheduling behavior is correct for AT and SCHTASKS on Windows?
  • In Scapy, responses are divided into two sets labeled what?
  • Hydra is best described as which type of tool?
  • WMIC stands for which of the following?
  • Which command shows environmental variables within the shell?
  • Which WMIC command lists all processes on a remote system?
  • What best describes the overall security posture of LANMAN/NTLMv1 Challenge/Response as described?
  • Which tool is commonly used to execute commands remotely on Windows hosts during a penetration test?
  • What is Upexec used for?
  • Which mode is brute-force with default rules starting near keyboard neighbors?
  • Which NMAP option enables OS detection?
  • Which command-line tool is used to view all services running on a Windows system?
  • How is the scanning phase best described?
  • Which type of test must be explicitly stated prior to starting?
  • Which tool is commonly used for offline password cracking and supports various hash formats and rulesets?
  • In NetCat, what does Zero-I/O mode (-z) achieve?
  • Which term describes the practice of using computer attack techniques with permission to find security flaws and improve security?
  • Which project focuses purely on web application testing?
  • Which tool can provide a complete inventory during client-side assessments?
  • Which DNS tool can perform zone transfers on modern Linux distributions?
  • What architectural feature enables NMAP to scan multiple targets in parallel?
  • Which Windows command shows current TCP/UDP port usage on the machine?
  • How does 'bind_ipv6_tcp' differ from 'bind_tcp'?
  • Which tool is identified as the lead for developing the Penetration Testing Execution Standard (PTES)?
  • What is the effect of the -vv option in NetCat?
  • GHDB stands for which of the following?
  • What is the filename of NMAP's script database mentioned?
  • Which database is not listed as supported by the SearchDiggity Suite in the notes?
  • John the Ripper is primarily used to do what with password data?
  • Which parameter enables recursive listing with Get-ChildItem?
  • Which password-guessing tool is described as operating primarily via the command line across many network services?
  • Which vulnerability occurs when web input is passed to a system command without proper validation?
  • In the Metasploit PsExec module, what sequence of actions enables remote code execution on the target system?
  • To avoid issues, which command would you run to drop an SMB session before trying to connect as another user?
  • What does Ether() enable when building packets in Scapy?
  • Which section of a formal security report typically provides a brief overview of the document and highlights major findings?
  • Which Cain feature helps decrypt SAM and AD password information by decoding SYSKEY?
  • What is the purpose of illustrating findings with screenshots in a penetration test report?
  • What specific transformation does LANMAN apply to passwords before hashing?
  • Single Crack mode uses variations of which fields?
  • What best describes the role of 'Gather Competitive Intel' during reconnaissance?
  • What describes pivoting in post-exploitation?
  • The Empire framework is best described as:
  • Which option adjusts the timing of NMAP scans?
  • Which vulnerability scanner is noted for having a commercial version that is roughly 50% faster and offers more plugins?
  • If a target system logs failed login attempts, what is a typical outcome of password cracking attempts?
  • Which statement best describes the purpose of the Discover group in Recon-NG?
  • Which NMAP option enables sending packets with intentionally bad checksums?
  • What is the term used for building packets in parts and then assembling them?
  • Which practice should you follow to capture screenshots and illustrate findings while testing?
  • Which statement best describes building packets in Scapy?
  • What is MSFMap in the Meterpreter context?
  • Which browser is frequently targeted by client-side exploits?
  • PowerSploit includes which capabilities?
  • Which option is used by -F to check popular ports?
  • Which feature does NMAP provide besides port scanning?
  • Which stages are mentioned as part of the testing process?
  • Which command deletes a user from a local group in Windows?
  • During an NMAP scan, which key can you press to enable packet tracing after the scan has started?
  • SYSKEY is described as a 128-bit key protecting password hashes on the hard drive. Which description best matches its function?
  • Which regulatory requirement triggers public disclosure when a company exposes customer health, finance, or education information?
  • In Metasploit, a Meterpreter session is best described as:
  • When presenting vulnerability findings to stakeholders, what is best practice?
  • What is NMAP's default behavior regarding probing a target address before performing a scan?
  • What capability does the -A option enable in Nmap?
  • What is NMAP primarily recognized as?
  • OSSTMM covers which topics?
  • In PsExec, which option causes the command to be copied to the remote system before execution?
  • Which Meterpreter command exits the session and removes it from memory?
  • Which organization maintains the Common Vulnerabilities and Exposures (CVE) repository?
  • What is the purpose of the WhatIf option in destructive commands?
  • After gaining access to a victim machine, what is a typical use of that compromised box?
  • Which Meterpreter command runs a program with the privileges of the Meterpreter's process?
  • SIP is used in which type of communication?
  • Which term describes security planning that shows the percentages of breaches per threat action?
  • Which commands would you run on Windows to display local users and groups and identify administrators?
  • What capability does the commercial version auto-detect in terms of processor features?
  • NetCat is commonly used in assessments to:
  • The PsExec module in Metasploit uses which protocol to perform remote code execution?
  • In Metasploit, which category includes auxiliary scanners like portscan/tcp and portscan/syn?
  • Which scan targets UDP ports?
  • Approximately how many Recon-NG modules are available?
  • Which command helps identify an IPv6 address?
  • Which default category includes scripts that run by default with -sC or -A?
  • After padding, the LANMAN hash is divided into how many parts, and what are their sizes?
  • When making recommendations, what should you identify first?
  • What is Trollsploit primarily used for in Empire?
  • Which tool provides a nontransparent proxy that enables detailed manipulation of HTTP/HTTPS requests and responses for web app testing?
  • What is a recommended use of Nessus results in terms of verification?
  • How does password cracking differ from a password attack in terms of data handling?
  • Strategic objectives are typically based on understanding which factors?
  • Which statement best describes exploitation phase risks?
  • What is the purpose of salt in password hashing?
  • Which technique allows remotely determining the target's operating system by analyzing network packets?
  • Which script, designed by Robin Wood, is used to merge Nessus results and convert them into a CSV file?
  • Who developed the Veil Framework?
  • In a TCP connect scan, what indicates an open port?
  • In N-based Hashcat rules (such as TN or DN), what is the index of the first character in the password?
  • Which Metasploit module performs UDP sweeps by sending UDP packets to common ports to elicit a response?
  • How is LANMAN generally described in terms of security?
  • Which document types are considered rich in metadata?
  • What term describes the practice of performing password cracking across multiple CPUs or machines using distributed architectures?
  • Which NetCat option enables zero-I/O mode, where no data is sent or received?
  • Which activity involves finding target systems on a network, looking for openings in their operating systems and available network services, and exploiting them remotely to assess internal networks or DMZ security?
  • Which action is explicitly not recommended during testing due to risk of exposing the system to malicious traffic?
  • Which tool is described as a free passive OS fingerprinting tool that focuses on TCP SYN packets?
  • Which factor is included as part of Understanding the business framework?
  • Which tool can scan for vulnerabilities and offers exploit code to compromise a target?
  • Why can Black Box testing take longer than Crystal Box testing according to the notes?
  • Which payload is commonly used to establish an interactive remote session after gaining foothold on a Windows network?
  • In Nessus architecture, which component conducts all scanning?
  • Which statement best describes how password cracking is typically performed during a test?
  • Before performing external network testing, what should you do with your Internet Service Provider?
  • Which Scapy function writes packets to a pcap file?
  • Which flag invokes TCP connect scan in Nmap?
  • In a post-exploitation scenario, what is the primary purpose of establishing a Meterpreter session on a foothold host?
  • In cloud-based password cracking, what primarily determines the cost and computational power of a given instance?
  • Hashcat uses which parallel computing framework to run on CPUs and GPUs?
  • What is the most valuable part of exploitation from a tester's perspective?
  • Empire exploitation includes exploits for which middleware and interpreter?
  • Which module is typically used for account lockout in Linux/UNIX environments?
  • Which statement describes the 'reverse_tcp' payload in Windows Singles?
  • Which tactic involves compiling malware from source and choosing different compiler options to avoid AV detection?
  • Which Unix password files commonly store password hashes that authentication relies on?
  • Which network proximity approach is described to speed up large scans?
  • What is the primary purpose of the Findings section in a security assessment report?
  • Which practice helps organize discovered targets during testing?
  • In Metasploit, what is the 'Modules' directory responsible for?
  • Which scenario describes reputational risk when a public-facing website is defaced?
  • What is the primary purpose of the Conclusions and Future Considerations section in a security assessment report?
  • Hashcat supports word mangling rules similar to John the Ripper (JtR).
  • Which flag corresponds to a SYN Scan?
  • Which file format is commonly used to export Nessus scan results for further analysis?
  • Which Meterpreter command shows the complete process list for the target machine?
  • For NMAP OS fingerprinting, which networking field is commonly analyzed to help determine the target's OS in the 2nd Gen tests?
  • What is Meterpreter in Metasploit?
  • NetCat can be used to reveal service information by connecting to a target service to obtain banners.
  • In PowerShell, which cmdlet displays the properties and methods of objects passed through the pipeline?
  • Hashcat supports rule-based attacks that transform candidate credentials during cracking. Which statement is true?
  • What best describes Meterpreter in the context of post-exploitation?
  • What best defines a Vertical Business Model?
  • TCP and UDP belong to which protocol category?
  • How can NetCat be used to forward SSH traffic in a pivot scenario?
  • Which of the following is NOT a capability of Scapy as described?
  • Which tool can Scapy invoke from the prompt?
  • Which PowerShell command lists all services on a Windows host?
  • In Empire module categories, injecting hashes into the Local Security Authority Subsystem Service (LSASS) is described as part of which category?
  • What is a potential risk when password guessing triggers failed-login thresholds on a system?
  • Which command lets a Meterpreter user read from or write to the Windows Registry?
  • Pen Test Preparation typically provides which of the following?
  • The Scanning section may provide which information?
  • What routine communication is recommended to confirm detections and align teams, even if it must be brief?
  • Which statement best describes NetCat's use in network tests?
  • Which Scapy command shows the most detail about a single packet?
  • Which statement best describes the advantage of having separate exploit and payload modules in Metasploit's arsenal?
  • Which statement describes the challenge of large-scoped testing where the scope is expansive and workload grows quickly?
  • Which statement about dllinject is correct?
  • During scoping, decisions on potentially dangerous tests should be documented in the scoping document. Which phrasing best describes this requirement?
  • In Nessus, the collection of plugin groups and their configurations used during a scan is referred to as what?
  • Which protocol is commonly used to move files between UNIX/Linux systems and uses port 204 by default?
  • What does the multi-handler do in Metasploit?
  • Reconnaissance is defined as what?
  • Scapy can read packets from which type of file?
  • How can you build a packet with specific settings, including Layer 2?
  • What is the term for NMAP's OS fingerprinting method that actively sends crafted packets to identify the OS, replacing older generation methods?
  • Which Hashcat -m hash type code corresponds to salted SHA512 (sha512crypt)?
  • Which tactic involves encoding malware so it doesn't match signatures?
  • Which keyboard shortcuts in NMAP increase output detail during a scan?
  • Which statement best describes the purpose of Strategy Maps?
  • On Windows, what is the default behavior of the built-in administrator account with respect to lockout?
  • Which statement about Scapy's packet capture methods is true?
  • Which config file stores cracking modes and rules on Linux?
  • Which feature prompts 'Not Opsec Safe' warnings before taking actions against a target?
  • What suffix does the built-in Administrator account's SID usually have?
  • Organizational Transformation requires understanding not only security threats and capabilities but also a deep understanding of the business environment & organizational goals.
  • What type of network traffic can be sniffed to obtain credentials when mounting a file share and authenticating to a domain?
  • What is Scapy primarily used for?
  • What practice is recommended before conducting testing to reduce risk of external interference?
  • Which Meterpreter command displays the process ID of the process that Meterpreter runs inside?
  • Which author is associated with a long list of entries not found in GHDB and with searches to find vulnerable systems using Microsoft's Bing search engine?
  • Which mode applies a dictionary attack with rules for guessing?
  • In Metasploit, which module can perform pass-the-hash authentication by using an administrator's hash for SMB login?
  • Which manual intervention technique is described to test user interaction with external links while on a call?
  • What are Stagers in Metasploit payload architecture?
  • Which statement best describes OSINT during reconnaissance?
  • Why should you avoid password guessing attacks in some contexts?
  • Which capability allows Hashcat to use more than one dictionary file at the command line?
  • Which database provides official address assignments including IPv4, IPv6, and AS numbers?
  • Which site is described as hosting an archive of attack and defense tools spanning over a decade?
  • What is the typical aim of local privilege escalation exploits?
  • What should you do with successfully cracked passwords during a project?
  • Who is credited as the author of OSSTMM?
  • What term is used for security testing of shrink-wrapped software in a lab?
  • In PowerShell, what does the symbol % represent in the pipeline?
  • Which of the following are described as parts of a Business Model?
  • What is a potential security risk when organizations synchronize passwords or provide single sign-on across systems?
  • Which PowerShell cmdlet is used to search for strings or regular expressions inside files and command output, similar to grep?
  • What is suggested as an alternative to relying solely on password guessing during a test?
  • To view an individual field in a Scapy packet, which option is used?
  • Which of the following is NOT listed as part of Understanding the business?
  • Lockout Observation Window refers to:
  • What is a primary defense against Pass the Hash attacks?
  • Which tool is known for extracting password hashes from Windows memory (LSASS)?
  • What is the primary benefit of limiting scope to a representative subset of targets in a large environment?
  • How many words are in the payware version word list?
  • How can you add data to Metasploit's database for tables such as vulns, creds, and loot?
  • In Nikto's focusing tests, which category indicates an authentication bypass vulnerability?
  • In PowerShell, which command applies a command to each object in a pipeline and requires a script block?
  • Which statement correctly describes the difference between the service-side exploits and client-side exploits?
  • Which tactic is described as enabling access when firewall rules restrict inbound connectivity?
  • Which redirection operator is used to append lines to a file when building it incrementally?
  • Which attack is generally more resource-efficient according to the material: sniffing or cracking the LANMAN hash?
  • What does CEWL do in the context of password cracking preparation?
  • Which command provides interactive DNS lookup within Empire's prompt?
  • How can you load the Privilege Escalation module manually in Meterpreter?
  • Which assessment type focuses on bypassing or breaking encryption on data at rest or in transit and may evaluate DRM strength?
  • Which NetCat option specifies a program to execute after a connection is established?
  • If the registry key already exists, what happens when you run reg add?
  • Which Meterpreter command dumps the local SAM database to the screen?
  • What is FOR /F commonly used for in Windows batch scripting?
  • Before performing a network pen test, what is essential to secure with the network owner/organization?
  • Why is it beneficial to provide multiple recommendations with trade-offs?
  • Which function sends a packet at Layer 3, grabs the first response, and returns it?
  • Which expression provides a brief summary of a Scapy packet?
  • In NTLMv2, which elements form the final response along with the server challenge?
  • Nikto scans across the network for vulnerabilities primarily in which component?
  • Why should a tester review code found on a compromised machine, such as scripts used by the sysadmin?
  • Which drive stores variables other than environment variables?
  • Which statement best describes a ping sweep in network discovery?
  • Which tool is used to extract authentication credentials from memory (LSASS) on Windows, and has a Meterpreter module?
  • Which statement describes the rdpcap function?
  • Which sections are included in the recommended report format?
  • Recursive DNS lookup is best described as:
  • Beyond IPv4/IPv6 addresses, what additional information may some IP address assignment databases provide?
  • Which DNS utility and syntax is used to request a zone transfer (AXFR) from a DNS server?
  • Which PowerShell module focuses on account information, domain information, and shares?
  • Which flag performs an ACK scan?
  • Which Windows-based, free-to-download tool focused on password cracking with sniffers and ARP cache poisoning tools is described in the material?
  • p0f is a free tool that focuses on which technique for OS identification?
  • Which statement about Hashcat's handling of usernames and GECOS fields is accurate?
  • Which term describes a condition where two actions occur in an indeterminate order, producing different results depending on timing?
  • Which option provides help for using NMAP scripts from the command line?
  • What is the primary goal of NMAP's network probe/sweep feature?
  • When the db_nmap command is used, Metasploit invokes which tool for scanning?
  • Which command can be used to find the exact service name on Windows?
  • Client-side testing is designed to find vulnerabilities in which area?
  • In Metasploit, what are 'Stages'?
  • What is a risk of lowering port scan timeouts too much?
  • George Santayana quote 'Those who cannot remember the past are condemned to repeat it' is attributed to which author?
  • Which Meterpreter command alters dates and timestamps associated with files in NTFS partitions?
  • Which vulnerability involves injecting crafted input into an SQL query to manipulate database behavior?
  • Which command dumps the system's ARP cache showing hosts on the same subnet that have sent packets to or from the target machine?
  • Which Meterpreter command captures a JPEG image of the target machine's desktop?
  • Porter's Five Forces analysis is used to assess what?
  • Which option is explicitly described as a GUI alternative for configuring Hydra settings?
  • What are the three most important tables in the Metasploit database?
  • Which test identifies which addresses are in use by sending probe packets to all addresses in the target range?
  • What risk does automated shunning in ROE pose?
  • When using a Pen Testing Framework, which is true about cloud-based platforms?
  • In limited-scope scanning, what is the main rationale for focusing on the most interesting and commonly open ports?
  • Which Metasploit feature allows you to automate a sequence of commands from a file?
  • Which text identifier indicates an MD5-based password scheme in Unix password strings?
  • Which Metasploit component is the primary interactive interface for exploring modules and running commands?
  • Which statement best describes Cross-Site Scripting (XSS)?
  • In pentesting, what is the bundle of commands that is executed together called?
  • Which Meterpreter file-system commands allow transferring files between the attacker and the target?
  • Which service allows creating a copy of the Active Directory database (ntds.dit) for offline analysis?
  • After exploit, what should you ensure you stay within to limit actions?
  • RTP is primarily used for which purpose?
  • In Cain's Password & Sniffer Helpers, a passive sniffer will see which traffic?
  • To read a registry key from the Windows command line, which command is used?
  • To what length is the LANMAN hash padded?
  • Which force concerns how easily suppliers can influence prices, considering product uniqueness and supplier power?
  • Which Windows batch construct is used to repeat commands with a numeric sequence?
  • In the password-cracking tool output, what does c/s stand for?
  • Which risk is associated with exploitation in many assessment contexts?
  • Red Teaming is best described as what?
  • Which file-sharing protocols and port ranges are used by Windows file sharing via NetBIOS/SMB?
  • In a spear-phishing engagement, what is a primary legal risk if a victim outside the test scope is attacked after forwarding the email?
  • Which command can generate an inventory of installed programs and their last update as part of an assessment?
  • Which function is used to send packets at Layer 2 when you have an L2 header, and does not wait for a response?
  • DNS servers can provide detailed information about a target organization's servers. What is the primary value of querying DNS in reconnaissance?
  • What feature allows PS to complete commands after typing a few letters?
  • Strategy Maps show how to turn strategy into tangible outcomes.
  • When reporting password cracking activities, which metric should be documented for each account to help assess timing against policy?
  • Which report is cited in the material and is known for data breach analysis?
  • In Metasploit, which module is commonly used to dump Windows password hashes after compromising a host?
  • Which directive searches for specific terms in the URL of a site?
  • Which Porter's Five Forces element concerns the threat posed by customers switching to substitute products?
  • What does a Maimon scan reveal about certain BSD-derived TCP stacks when port is closed?
  • Hashcat can achieve speeds of over 18 million combinations per second on CPU and over a billion on some GPUs, and it supports around 245 hash algorithms. Which statement best describes this performance claim?
  • In IPv4, which header field controls the maximum hops and can aid topology discovery?
  • In IPv6, which header field is decremented at each hop and is equivalent to TTL?
  • Which time window is commonly used for testing to avoid disrupting regular operations?
  • Which command is described as capable of scheduling a command to run later?
  • How is risk defined in this context?
  • Which product is BeyondTrust's comprehensive network security scanner?
  • What does the related: directive show?
  • Which search engine is mentioned as being used to locate vulnerable systems in Biondi's work?
  • In a penetration testing project overview, which information should be included about personnel?
  • Which statement about wrppcap is correct?
  • Before starting a penetration test, what is required regarding the ROE?
  • What is the relationship between an exploit and a payload in Metasploit?
  • What is the primary purpose of automating service string information gathering in a penetration test?
  • Which flag performs a NULL scan?
  • What is the recommended approach to building dictionaries for password cracking projects?
  • Which component of the SearchDiggity Suite uses Google's AJAX API to submit queries?
  • What is the purpose of the db_export feature in Metasploit?
  • Which command lists Windows services and their states from the command line?
  • NSE scripts are written in which language and extend Nmap with automated checks?
  • Finalize Pen test plan ensures which of the following?
  • What is the length of the LANMAN hash before padding?
  • When Windows Syskey is used, what does the hashdump script attempt to recover from the Registry?
  • Which project authored a presentation on port scanning using this technique?
  • What does the Meterpreter 'cd' command do?
  • Which Porter's force refers to the ability of customers to find substitute products or easier ways to meet the same need?
  • Which of the following is a common tactic attackers use to cover their tracks on a system?
  • What should you verify with administrators about lockout during testing?
  • In NTLMv1 authentication, what primarily differs from LANMAN-based authentication?
  • Client-side exploits rely on which network condition to deliver an attack?
  • What is the recommended approach instead of trying to bypass all AVs?
  • Lateral Movement in Empire can use which techniques to move to another target?
  • In TCP port scanning, what does receiving a SYN-ACK indicate?
  • When you discover a significant finding during testing, what should you do?
  • Which remote command execution tool is described as free but not natively installed on all Windows machines?
  • What is a recommended approach to vulnerability scanning findings?
  • What does the Jikto tool do?
  • Which tactic is described as accelerating large-scale scans to complete more quickly?
  • Which NMAP script category tests for authentication issues?
  • What does the Recon module primarily do in Empire?
  • Which techniques are commonly used by attackers to hide their activities on a system?
  • Which flag performs a FIN scan?
  • Which scan type uses different arbitrary control bits via a --scanflags option?
  • Which vulnerability management tool supports internet-wide scanning and internal intranet scanning via an on-premises appliance?
  • In Windows batch scripting, how are loop variables denoted when used inside a script?
  • When passwords are synchronized across systems, what variation is commonly observed?
  • Which tool can combine /etc/passwd and /etc/shadow into a single file for cracking?
  • In PowerShell, what does the expression 1..10 | % {echo $_} do?
  • Which is the dominant form of user authentication in most environments?
  • Which tool is well known for sniffing NTLM credentials on a Windows network and can crack hashes?
  • What term describes deciding to accept a risk identified during a test rather than mitigating the vulnerability?
  • When using cloud-based pen testing infrastructure, which statement correctly reflects IP considerations?
  • Which file stores cracked passwords and hashes for John the Ripper?
  • What is the recommended practice when handling password hashes during a pentest to avoid impacting the target system?
  • EXIFTOOL is a tool that focuses on what?
  • During testing across the internet, which factor may cause inbound/outbound packets to be blocked and lead to inaccurate results?
  • Which statement correctly describes AT scheduling behavior?
  • What is the purpose of the john.rec file in John the Ripper?
  • Where are password representations stored on Linux/UNIX systems?
  • In Hashcat, the code 500 is used to specify which hash type?
  • Which Empire module category includes scanning the network for additional hosts, ports, shares, and more?
  • Which encryption algorithm is used during the transformation step in LANMAN/NTLMv1 challenge/response?
  • What is the purpose of ROE and scope description in a penetration test document?
  • Which tool provides detailed web app analysis via a nontransparent proxy for intercepting and manipulating requests?
  • If a target machine sends back RESETs or ICMP Port Unreachable, what happens?
  • Which tactic is described for automating phishing communications during testing?
  • Which statement about TTL in a ping reply is correct?
  • Which of the following best describes the range of mitigations you might recommend?
  • In Windows batch scripting, FOR /F loops are primarily used to process which of the following?
  • Which statement best describes a Horizontal Business Model?
  • Which scan is AKA 'half-open' or 'SYN Stealth'?
  • What is PowerShell Empire primarily described as?
  • Regarding the scope of a pen test, what is essential?
  • Which option shows step-by-step output for NMAP scripts?
  • Which WMIC command kills a running process by PID?
  • How are fine-grained options specified in Scapy's send functions?
  • Which attack involves injecting content onto a third-party site that causes the victim's browser to perform actions on another site?
  • Which tool is noted as being created in an environment based on the Python programming language?
  • Which NetCat option enables UDP mode?
  • Porter's Five Forces was developed by which author and in what year?
  • Which command lists the contents of the current directory?
  • Which statement about testing permission and law is most accurate?
  • What risk does scope creep introduce in a testing project?
  • Web applications are typically accessed using which protocols?
  • Which vulnerability management tool can deploy an internal intranet-scanning appliance and provide reports via a web portal?
  • What database contains the collection of Google Dorks used for exploring vulnerabilities?
  • Understanding the business framework includes which item?
  • Which Recon-NG module group focuses on tasks a penetration tester would perform to gather information?
  • What does NMAP version scanning help determine?
  • On Linux, which combination of commands provides the same information as Windows netstat -na and arp -a?
  • Which flag performs a Xmas Tree scan?
  • Which attack involves injecting a browser script into a website that runs in the victim's browser and can perform actions on the target site on behalf of the user?
  • Web app architecture commonly includes which components?
  • In Nmap, what is the primary purpose of the Nmap Scripting Engine (NSE)?
  • What is contained in the hashcat.potfile, as described in the notes?
  • What does the site: directive do in Google searches?
  • What approach can reduce effort for large networks by focusing on a representative subset of hosts and ports?
  • Which statement best describes the Strategic planning step?
  • Why is IPv6 support useful for NMAP?
  • What can the NMAP Scripting Engine enable?
  • Which tool can transfer files using arbitrary TCP/UDP ports, provided it is installed on the machine?
  • What term describes starting with a dictionary word and then making variations to guess passwords?
  • How can Scapy target multiple destinations with a single packet structure?
  • What best describes scope creep in a penetration test?
  • What language is used for NMAP scripting?
  • Approximately how many services are defined in the NMAP service file?
  • Which technique is explicitly suggested to speed up large scans?
  • Compared to performing offline password cracking on the attacker’s turf, what is typically observed on the target network?
  • PsExec was created by which individual and distributed by which suite?
  • What best describes the purpose of driving engagement in a leadership context?
  • Which tools are mentioned as options for collaborative recording and analysis during a pen test?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy