Free practice test

GPEN

Free GIAC Penetration Tester Certification (GPEN) practice test

10 original GPEN questions, playable right now. No account, no card, no email gate. Every answer opens the full explanation: the concept, why the right option is right, and why each wrong option is wrong, cited to the authoritative documentation behind it.

Sample question 1 of 10

Password Attacks and Hashes

A defence team maps out where password guessing can happen against its estate. Which distinction separates an online attempt from an offline one?

Sample question 2 of 10

Exploitation and Privilege Escalation

A team reviews a payload list and notices that one entry is described as staged rather than single. What does the staged form consist of?

Sample question 3 of 10

Domain Escalation, Kerberos, and Persistence

A tester watching a domain logon captures the reply a domain controller sends to a client's very first ticket request. Which key protects that reply?

Sample question 4 of 10

Reconnaissance, Scanning, and Vulnerability Discovery

A UDP scan of a client host reports many ports as open or filtered. What does that classification tell the tester about those ports?

Sample question 5 of 10

Azure Attacks and AD Integration

A team proposes Conditional Access as the tenant's frontline block against a credential stuffing flood. At what point in a sign-in is a Conditional Access policy evaluated?

Sample question 6 of 10

Penetration Test Planning

A client judges its payroll database too critical for intrusive testing but wants the rest of the estate covered. How should the plan record that decision?

Sample question 7 of 10

Password Attacks and Hashes

A team hardens a login flow and asks whether transport encryption alone covers password protection. Which pair of obligations does the verifier actually carry?

Sample question 8 of 10

Exploitation and Privilege Escalation

An analyst reads a claim that token theft carried an operator from a standard user account to SYSTEM. What precondition does token stealing actually require?

Sample question 9 of 10

Domain Escalation, Kerberos, and Persistence

An analyst asks what a defender can still recover when an implant wraps its own encryption around a channel rather than trusting the protocol's. What weakens that layer?

Sample question 10 of 10

Reconnaissance, Scanning, and Vulnerability Discovery

A client wants missing patches and host misconfigurations reported at the greatest possible depth. Which scanning arrangement gives that level of detail on each host?

Full GPEN question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

What this test covers

These 10 questions are drawn across the published exam blueprint rather than from one chapter: this set touches Password Attacks and Hashes, Exploitation and Privilege Escalation, Domain Escalation, Kerberos, and Persistence, Reconnaissance, Scanning, and Vulnerability Discovery, Azure Attacks and AD Integration, Penetration Test Planning. Every question is original, written from the official objectives, and verified against a cited vendor page before it serves. None are recalled exam content, which is why the explanations can cite their sources.

A 10-question sample tells you where you stand, not whether you are ready. The full experience is numbered practice exams: 82 questions apportioned to the official domain weightings, sat under the real 180-minute clock and scored against the published cut score.

Keep reading

Every guide and cost breakdown, by vendor