GIAC Penetration Tester (GPEN) Practice Test

180 प्रश्न उपलब्ध

GIAC Penetration Tester (GPEN) के लिए अपना आत्मविश्वास बढ़ाएँ। अवधारणाओं का अभ्यास करें, उत्तरों को समझें और हर सवाल के साथ अपना ज्ञान मज़बूत करें।

एक नमूना सवाल आज़माएँ
5 मुफ्त प्रश्न आज़माएँ
खाते की ज़रूरत नहीं। एक मुफ्त खाते में इस परीक्षा के लिए 20 प्रश्न शामिल हैं।
सर्टिफिकेशन परीक्षा
115 परीक्षा प्रश्न
5 घंटे समय सीमा
आपका अभ्यास
180 अभ्यास सवाल
3 घंटे अभ्यास समय
5 मुफ्त प्रश्न आज़माएँ
खाते की ज़रूरत नहीं। एक मुफ्त खाते में इस परीक्षा के लिए 20 प्रश्न शामिल हैं।
पार करने की सीमा 74 इस प्रमाणन के लिए प्रकाशित उत्तीर्णांक।
परीक्षा के विषय जानें GIAC से आधिकारिक उद्देश्य
GIAC180 अभ्यास प्रश्न
ब्लूप्रिंट सत्यापितGIAC official objectives के साथ जाँचा गयामेटाडेटा सत्यापित 2026-06-11हम कैसे सत्यापित करते हैं

परीक्षा का परिचय और विवरण

The GIAC Penetration Tester (GPEN) certification is a globally recognized, performance-based credential that validates a professional's ability to conduct authorized penetration tests using a structured, ethical methodology. Administered by the Global Information Assurance Certification (GIAC) and aligned with the SANS SEC560: Network Penetration Testing and Ethical Hacking course, GPEN certifies that holders possess the practical skills to effectively identify, exploit, and document security vulnerabilities in enterprise networks. The exam rigorously tests knowledge across the entire penetration testing lifecycle, from initial reconnaissance and enumeration to exploitation, post-exploitation, and professional reporting. Earning the GPEN demonstrates not only technical proficiency with modern attack tools and techniques but also a deep understanding of the legal frameworks, scoping requirements, and ethical considerations that define professional security assessments. This certification is a cornerstone for cybersecurity professionals seeking to establish or advance their careers in offensive security, providing tangible proof of hands-on competency to employers, clients, and regulatory bodies.

नमूना प्रश्न

अभ्यास कैसे काम करता है, यह जानने के लिए एक उत्तर चुनें और व्याख्या देखें।

Exploitation Fundamentals

A healthcare provider has approved a scoped internal assessment, but the rules of engagement prohibit disruption of clinical systems and require clear notes for every finding. The finding under review is cross-site scripting finding, and the client asks for the safest next recommendation that still supports the assessment objective. What should the tester recommend?

Domain Escalation and Persistence Attacks

A university permits limited active testing against named systems and asks the tester to explain findings in language the infrastructure team can act on. The finding under review is DCSync-capable privilege, and the client asks for the safest next recommendation that still supports the assessment objective. What should the tester recommend?

Kerberos Attacks

An energy cooperative asks for a focused validation of exposure found by its vulnerability team, while legal requires that all tests stay inside the signed target list. The notes show a service accepts Kerberos tickets without contacting the DC for every authorization decision. Which interpretation best matches the evidence for a GPEN-style report?

Metasploit

A SaaS company gives the tester production and staging ranges, a change-freeze calendar, and read-only cloud review access for the engagement. The notes show the tester must select between staged and stageless payloads for a restrictive network path. Which interpretation best matches the evidence for a GPEN-style report?

Metasploit

A manufacturer requests a GPEN-style assessment after a merger, with separate Active Directory forests, legacy services, and strict written authorization boundaries. The finding under review is session upgrade, and the client asks for the safest next recommendation that still supports the assessment objective. What should the tester recommend?

करियर के अवसर और वेतन

मध्य वेतन: $129,180US मार्केट– Information Security Analysts

स्रोत: BLS Occupational Employment and Wage Statistics, May 2025 -- Information Security Analysts (SOC 15-1212), US national. Occupation median, not a certification salary. (2025)

Information Security Analysts

जब तक लोकल रेंज न दिखे, ये US मार्केट के आंकड़े हैं।

इस परीक्षा में क्या शामिल है

01Advanced Password Attacks

विषय

  • Advanced Password Attacks
  • Attacking Password Hashes

सीखने के उद्देश्य

  • Advanced Password Attacks: The candidate will be able to use additional methods to attack password hashes and authenticate
  • Attacking Password Hashes: The candidate will be able to obtain and attack password hashes and other password representations

02Azure Overview, Integration, and Attacks, and In-Depth Password Attacks

विषय

  • Azure Overview, Attacks, and AD Integration
  • Azure Applications and Attack Strategies
  • Password Attacks

सीखने के उद्देश्य

  • Azure Overview, Attacks, and AD Integration: The candidate will demonstrate an understanding of Entra ID implementation fundamentals, common Entra ID attacks, and Azure authentication techniques
  • Azure Applications and Attack Strategies: The candidate will demonstrate an understanding of Azure applications and the attacks against them including federated and single sign-on environments and Azure AD authentication protocols
  • Password Attacks: The candidate will understand types of password attacks, formats, defenses, and the circumstances under which to use each password attack variation. The candidate will be able to conduct password guessing attacks

03Command and Control (C2)

विषय

  • Command and Control (C2)

सीखने के उद्देश्य

  • Command and Control (C2): The candidate will demonstrate an understanding of the design, application, and use of Command and Control (C2) and common C2 Frameworks

04Comprehensive Pen Test Planning, Scoping, and Recon

विषय

  • Penetration Test Planning

सीखने के उद्देश्य

  • Penetration Test Planning: The candidate will be able to demonstrate the fundamental concepts associated with pen-testing, and utilize a process-oriented approach to penetration testing and reporting

05Domain Escalation and Persistence Attacks

विषय

  • Domain Escalation and Persistence Attacks

सीखने के उद्देश्य

  • Domain Escalation and Persistence Attacks: The candidate will demonstrate an understanding of common Windows privilege escalation attacks and Kerberos attack techniques that are used to consolidate and persist administrative access to Active Directory

06In-Depth Scanning and Exploitation, Post-Exploitation, and Pivoting

विषय

  • Scanning and Host Discovery
  • Exploitation Fundamentals
  • Escalation and Exploitation

सीखने के उद्देश्य

  • Scanning and Host Discovery: The candidate will be able to use the appropriate technique to scan a network for potential targets, and to conduct port, operating system and service version scans and analyze the results
  • Exploitation Fundamentals: The candidate will be able to demonstrate the fundamental concepts associated with the exploitation phase of a pentest
  • Escalation and Exploitation: The candidate will be able to demonstrate the fundamental concepts of exploitation, data exfiltration from compromised hosts and pivoting to exploit other hosts within a target network

07Kerberos Attacks

विषय

  • Kerberos Attacks

सीखने के उद्देश्य

  • Kerberos Attacks: The candidate will demonstrate an understanding of attacks against Active Directory including Kerberos attacks

08Metasploit

विषय

  • Metasploit

सीखने के उद्देश्य

  • Metasploit: The candidate will be able to use and configure the Metasploit Framework at an intermediate level

09Password Formats and Hashes

विषय

  • Password Formats and Hashes

सीखने के उद्देश्य

  • Password Formats and Hashes: The candidate will demonstrate an understanding of common password hashes and formats for storing password data

10Reconnaissance

विषय

  • Reconnaissance

सीखने के उद्देश्य

  • Reconnaissance: The candidate will understand the fundamental concepts of reconnaissance and will understand how to obtain basic, high level information about the target organization and network, often considered information leakage, including but not limited to technical and non technical public contacts, IP address ranges, document formats, and supported systems

11Vulnerability Scanning

विषय

  • Vulnerability Scanning

सीखने के उद्देश्य

  • Vulnerability Scanning: The candidate will be able to conduct vulnerability scans and analyze the results

परीक्षा विवरण GPEN | $949 USD | 5 घंटे

परीक्षा कोड GPEN
विक्रेता GIAC
परीक्षा शुल्क $949 USD
उत्तीर्ण अंक 74
समय सीमा 5 घंटे
परीक्षा प्रश्न 115
प्रश्न प्रकार मल्टिपल चॉइस (100%)
पुनः परीक्षा नीति Two free practice tests are included with each exam registration. Candidates have a 4-month window to take the exam after registration. Retake fees apply after the first failed attempt. Contact GIAC for specific retake waiting periods.
परीक्षा प्रारूप Multiple Choice
ऑनलाइन निगरानी उपलब्ध

अक्सर पूछे जाने वाले प्रश्न

GPEN परीक्षा देने के लिए क्या पूर्वापेक्षाएँ हैं?

GPEN परीक्षा का प्रारूप क्या है, और इसे कैसे स्कोर किया जाता है?

GPEN अन्य पेनिट्रेशन टेस्टिंग प्रमाणपत्रों जैसे OSCP या CEH से कैसे भिन्न है?

GPEN प्रमाणपत्र की वैधता कितनी है, और नवीनीकरण की आवश्यकताएँ क्या हैं?

GPEN परीक्षा के लिए तैयारी करने का सबसे अच्छा तरीका क्या है?