GIAC Penetration Tester (GPEN) Practice Test

180 preguntas disponibles

Gana confianza para GIAC Penetration Tester (GPEN). Practica los conceptos, comprende las respuestas y refuerza tus conocimientos pregunta a pregunta.

Probar una pregunta
Prueba 5 preguntas gratis
No necesitas cuenta. Una cuenta gratuita incluye 20 preguntas de este examen.
Examen de certificación
115 Preguntas del examen
5 horas Límite de Tiempo
Tu práctica
180 Preguntas de práctica
3 horas Tiempo de Práctica
Prueba 5 preguntas gratis
No necesitas cuenta. Una cuenta gratuita incluye 20 preguntas de este examen.
El listón a superar 74 Puntuación mínima publicada para obtener esta certificación.
Explora los temas del examen Objetivos oficiales de GIAC
GIAC180 preguntas de práctica
Temario verificadoVerificado con GIAC official objectivesMetadatos verificados 2026-06-11Cómo verificamos

Descripción y detalles del examen

The GIAC Penetration Tester (GPEN) certification is a globally recognized, performance-based credential that validates a professional's ability to conduct authorized penetration tests using a structured, ethical methodology. Administered by the Global Information Assurance Certification (GIAC) and aligned with the SANS SEC560: Network Penetration Testing and Ethical Hacking course, GPEN certifies that holders possess the practical skills to effectively identify, exploit, and document security vulnerabilities in enterprise networks. The exam rigorously tests knowledge across the entire penetration testing lifecycle, from initial reconnaissance and enumeration to exploitation, post-exploitation, and professional reporting. Earning the GPEN demonstrates not only technical proficiency with modern attack tools and techniques but also a deep understanding of the legal frameworks, scoping requirements, and ethical considerations that define professional security assessments. This certification is a cornerstone for cybersecurity professionals seeking to establish or advance their careers in offensive security, providing tangible proof of hands-on competency to employers, clients, and regulatory bodies.

Preguntas de Muestra

Elige una respuesta y consulta la explicación para ver cómo funciona la práctica.

Exploitation Fundamentals

A healthcare provider has approved a scoped internal assessment, but the rules of engagement prohibit disruption of clinical systems and require clear notes for every finding. The finding under review is cross-site scripting finding, and the client asks for the safest next recommendation that still supports the assessment objective. What should the tester recommend?

Domain Escalation and Persistence Attacks

A university permits limited active testing against named systems and asks the tester to explain findings in language the infrastructure team can act on. The finding under review is DCSync-capable privilege, and the client asks for the safest next recommendation that still supports the assessment objective. What should the tester recommend?

Kerberos Attacks

An energy cooperative asks for a focused validation of exposure found by its vulnerability team, while legal requires that all tests stay inside the signed target list. The notes show a service accepts Kerberos tickets without contacting the DC for every authorization decision. Which interpretation best matches the evidence for a GPEN-style report?

Metasploit

A SaaS company gives the tester production and staging ranges, a change-freeze calendar, and read-only cloud review access for the engagement. The notes show the tester must select between staged and stageless payloads for a restrictive network path. Which interpretation best matches the evidence for a GPEN-style report?

Metasploit

A manufacturer requests a GPEN-style assessment after a merger, with separate Active Directory forests, legacy services, and strict written authorization boundaries. The finding under review is session upgrade, and the client asks for the safest next recommendation that still supports the assessment objective. What should the tester recommend?

Oportunidades profesionales y salario

Salario medio: $129,180mercado de EE. UU.– Information Security Analysts

Fuente: BLS Occupational Employment and Wage Statistics, May 2025 -- Information Security Analysts (SOC 15-1212), US national. Occupation median, not a certification salary. (2025)

Information Security Analysts

Los rangos son cifras del mercado de EE. UU. salvo que se muestre un rango local.

Qué temas cubre este examen

01Advanced Password Attacks

Temas

  • Advanced Password Attacks
  • Attacking Password Hashes

Objetivos de aprendizaje

  • Advanced Password Attacks: The candidate will be able to use additional methods to attack password hashes and authenticate
  • Attacking Password Hashes: The candidate will be able to obtain and attack password hashes and other password representations

02Azure Overview, Integration, and Attacks, and In-Depth Password Attacks

Temas

  • Azure Overview, Attacks, and AD Integration
  • Azure Applications and Attack Strategies
  • Password Attacks

Objetivos de aprendizaje

  • Azure Overview, Attacks, and AD Integration: The candidate will demonstrate an understanding of Entra ID implementation fundamentals, common Entra ID attacks, and Azure authentication techniques
  • Azure Applications and Attack Strategies: The candidate will demonstrate an understanding of Azure applications and the attacks against them including federated and single sign-on environments and Azure AD authentication protocols
  • Password Attacks: The candidate will understand types of password attacks, formats, defenses, and the circumstances under which to use each password attack variation. The candidate will be able to conduct password guessing attacks

03Command and Control (C2)

Temas

  • Command and Control (C2)

Objetivos de aprendizaje

  • Command and Control (C2): The candidate will demonstrate an understanding of the design, application, and use of Command and Control (C2) and common C2 Frameworks

04Comprehensive Pen Test Planning, Scoping, and Recon

Temas

  • Penetration Test Planning

Objetivos de aprendizaje

  • Penetration Test Planning: The candidate will be able to demonstrate the fundamental concepts associated with pen-testing, and utilize a process-oriented approach to penetration testing and reporting

05Domain Escalation and Persistence Attacks

Temas

  • Domain Escalation and Persistence Attacks

Objetivos de aprendizaje

  • Domain Escalation and Persistence Attacks: The candidate will demonstrate an understanding of common Windows privilege escalation attacks and Kerberos attack techniques that are used to consolidate and persist administrative access to Active Directory

06In-Depth Scanning and Exploitation, Post-Exploitation, and Pivoting

Temas

  • Scanning and Host Discovery
  • Exploitation Fundamentals
  • Escalation and Exploitation

Objetivos de aprendizaje

  • Scanning and Host Discovery: The candidate will be able to use the appropriate technique to scan a network for potential targets, and to conduct port, operating system and service version scans and analyze the results
  • Exploitation Fundamentals: The candidate will be able to demonstrate the fundamental concepts associated with the exploitation phase of a pentest
  • Escalation and Exploitation: The candidate will be able to demonstrate the fundamental concepts of exploitation, data exfiltration from compromised hosts and pivoting to exploit other hosts within a target network

07Kerberos Attacks

Temas

  • Kerberos Attacks

Objetivos de aprendizaje

  • Kerberos Attacks: The candidate will demonstrate an understanding of attacks against Active Directory including Kerberos attacks

08Metasploit

Temas

  • Metasploit

Objetivos de aprendizaje

  • Metasploit: The candidate will be able to use and configure the Metasploit Framework at an intermediate level

09Password Formats and Hashes

Temas

  • Password Formats and Hashes

Objetivos de aprendizaje

  • Password Formats and Hashes: The candidate will demonstrate an understanding of common password hashes and formats for storing password data

10Reconnaissance

Temas

  • Reconnaissance

Objetivos de aprendizaje

  • Reconnaissance: The candidate will understand the fundamental concepts of reconnaissance and will understand how to obtain basic, high level information about the target organization and network, often considered information leakage, including but not limited to technical and non technical public contacts, IP address ranges, document formats, and supported systems

11Vulnerability Scanning

Temas

  • Vulnerability Scanning

Objetivos de aprendizaje

  • Vulnerability Scanning: The candidate will be able to conduct vulnerability scans and analyze the results

Detalles del Examen GPEN | $949 USD | 5 horas

Código del Examen GPEN
Proveedor GIAC
Costo del Examen $949 USD
Puntaje Mínimo 74
Límite de Tiempo 5 horas
Preguntas del examen 115
Tipos de Preguntas Opción múltiple (100%)
Política de Repetición Two free practice tests are included with each exam registration. Candidates have a 4-month window to take the exam after registration. Retake fees apply after the first failed attempt. Contact GIAC for specific retake waiting periods.
Formato del Examen Multiple Choice
Supervisión en Línea Disponible

Preguntas Frecuentes

¿Cuáles son los requisitos previos para presentar el examen GPEN?

¿Cuál es el formato del examen GPEN y cómo se califica?

¿En qué se diferencia GPEN de otras certificaciones de pruebas de penetración como OSCP o CEH?

¿Cuánto tiempo es válida la certificación GPEN y cuáles son los requisitos de renovación?

¿Cuál es la mejor manera de prepararse para el examen GPEN?