Practice Exam 1
5 of this form’s 82 questions, drawn from across its domains, free. The explanation on every one of them is free too, at every tier, and always will be.
Question 1 of 5
Reconnaissance, Scanning, and Vulnerability DiscoveryA UDP scan of a client host reports many ports as open or filtered. What does that classification tell the tester about those ports?
Question 2 of 5
Exploitation and Privilege EscalationA team reviews a payload list and notices that one entry is described as staged rather than single. What does the staged form consist of?
Question 3 of 5
Password Attacks and HashesA defence team maps out where password guessing can happen against its estate. Which distinction separates an online attempt from an offline one?
Question 4 of 5
Domain Escalation, Kerberos, and PersistenceA tester watching a domain logon captures the reply a domain controller sends to a client's very first ticket request. Which key protects that reply?
Question 5 of 5
Azure Attacks and AD IntegrationA team proposes Conditional Access as the tenant's frontline block against a credential stuffing flood. At what point in a sign-in is a Conditional Access policy evaluated?
0 of 82 completed
The other 77 questions are the rest of this form: same 180 minute clock, same 73 cut score, and the same explanation on every question, which is never behind the wall. Practice Exam 1 of 1 on GPEN.
What this exam covers
- Penetration Test Planning8 questions / 10% of the exam
- Reconnaissance, Scanning, and Vulnerability Discovery15 questions / 18% of the exam
- Exploitation and Privilege Escalation16 questions / 20% of the exam
- Password Attacks and Hashes18 questions / 22% of the exam
- Domain Escalation, Kerberos, and Persistence15 questions / 18% of the exam
- Azure Attacks and AD Integration10 questions / 12% of the exam
Checking what you already have access to.
Every question is original, written from the published objectives. We never reproduce, paraphrase, or imitate real exam content, and neither should anything else you study from.