GIAC Exploit Researcher and Advanced Penetration Tester Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 218 questions. Use the simulator for timed and flashcard mode.

Try Simulator

GXPN Sample Questions

  1. Question 1

    Q1

    You are analyzing a compromised Linux server and discover a custom binary that is vulnerable to a buffer overflow. The binary has the NX (No-Execute) bit enabled, preventing execution of shellcode on the stack. You decide to employ a Return-to-Libc (ret2libc) attack. You have successfully calculated the base address of libc and the offsets for the system() function and the string "/bin/sh".

    To successfully execute system("/bin/sh") on a 32-bit x86 architecture, how must the stack be constructed at the moment the vulnerable function returns?

    Show answer & explanation

    Correct answer: B

    In a standard 32-bit x86 ret2libc attack, the stack must be arranged so that the return address of the vulnerable function points to the system() function. Immediately following this must be the return address where system() should return after completion (often exit()), followed by the arguments for system() (the pointer to "/bin/sh"). The calling convention dictates that arguments are pushed onto the stack before the call.

  2. Question 2

    Q2

    A penetration tester is attempting to exploit a heap-based vulnerability in a Linux service. The service forks a new process for every incoming connection. The tester suspects a stack canary (SSP) is in place, as the application crashes with "*** stack smashing detected ***" when the buffer is overflowed.

    Which technique is most appropriate to bypass the stack canary in this specific forking server scenario?

    Show answer & explanation

    Correct answer: B

    In a forking server architecture on Linux, the parent process's memory layout, including the stack canary value, is inherited by the child processes. Because the canary remains constant across forks until the parent restarts, an attacker can brute-force the canary one byte at a time. If a byte is incorrect, the child crashes; if correct, it does not. This allows determining the full canary value.

  3. Question 3

    Q3

    You are developing an exploit for a Windows application compiled with SafeSEH. You have control over the stack and can overwrite the SEH record, but you need a valid pop pop ret gadget to redirect execution to your shellcode.

    Which condition must be met for a pop pop ret gadget to be usable in a SafeSEH environment?

    Show answer & explanation

    Correct answer: B

    SafeSEH validates exception handlers against a table of registered handlers within the module. To bypass this, attackers look for gadgets (like pop pop ret) in modules loaded by the application that were compiled without SafeSEH (or have it disabled). Addresses in these non-SafeSEH modules are not validated against the SafeSEH table, allowing execution flow redirection.

  4. Question 4

    Q4

    Which Windows 10 exploit mitigation mechanism validates indirect calls by checking a target address against a bitmap of valid function entry points before execution, effectively breaking most standard ROP chains that rely on arbitrary gadgets?

    Show answer & explanation

    Correct answer: C

    Control Flow Guard (CFG) is a compiler-enabled security feature that adds checks before every indirect call (like function pointers). It verifies that the destination address is a valid entry point for a function, significantly restricting the ability to jump to arbitrary ROP gadgets in the middle of functions.

  5. Question 5

    Q5

    A penetration tester has obtained user-level access to a Windows workstation protected by AppLocker in 'Enforce' mode. The Default Rule is enabled, blocking all executables in non-standard directories. The tester needs to execute a custom C# payload.

    Which 'Living off the Land' binary could be used to bypass AppLocker by executing the payload contained within a specially crafted .log or .txt file via the Uninstall method?

    Show answer & explanation

    Correct answer: B

    InstallUtil.exe is a Microsoft .NET framework utility often whitelisted by default. It can be used to bypass AppLocker by executing code embedded in the Uninstall method of a compiled .NET assembly (or sometimes text-based inputs if configured). This is a classic AppLocker bypass technique.

  6. Question 6

    Q6

    A security analyst is testing a Windows environment where PowerShell is configured in Constrained Language Mode (CLM). The analyst attempts to run a script that utilizes .NET reflection to load a DLL into memory but receives an error stating the type cannot be created.

    What is the primary technical reason this script fails in CLM?

    Show answer & explanation

    Correct answer: B

    Constrained Language Mode (CLM) is designed to limit the capabilities of PowerShell to prevent abuse. It restricts access to critical .NET types (like System.Reflection or System.Runtime.InteropServices) and methods that allow memory manipulation or interaction with unmanaged code. Only a subset of 'safe' types is permitted.

  7. Question 7

    Q7

    You are performing a physical penetration test and encounter a network port secured with 802.1X. You have a physical device that can bridge connections. You disconnect the victim PC, connect your bridge device to the wall, and connect the victim PC to the bridge. You wait for the victim to authenticate.

    Once the victim authenticates, what specific action must your attack device take to successfully piggyback on the session without triggering a port security violation?

    Show answer & explanation

    Correct answer: A

    In an 802.1X bypass scenario using a bridge (like a 'Phantom' or 'Shadow' attack), the attacker waits for the victim to authenticate. Once authenticated, the switch port allows traffic from the victim's MAC. The attacker must spoof the victim's MAC address to inject traffic. Crucially, the attacker must also drop EAPOL Logoff packets from the victim to keep the session alive if the victim disconnects or reboots.

  8. Question 8

    Q8

    A penetration tester is connected to a switch port assigned to VLAN 10 (Native VLAN 1). The tester wishes to reach a target server on VLAN 20. The switch is configured with 802.1Q trunking to an upstream switch.

    Which technique involves crafting a packet with two VLAN tags, where the first tag matches the native VLAN of the trunk, allowing the packet to be stripped of the first tag and forwarded to the second VLAN on the next switch?

    Show answer & explanation

    Correct answer: C

    Double Tagging (VLAN Hopping) involves sending a frame with two 802.1Q tags. The outer tag matches the native VLAN of the trunk port. The first switch strips this outer tag (as is standard for native VLAN traffic) and forwards the frame. The receiving switch then sees the second (inner) tag and forwards the packet to the target VLAN. This is a unidirectional attack.

  9. Question 9

    Q9

    You are auditing a network that uses HSRP (Hot Standby Router Protocol) for gateway redundancy. You discover that HSRP authentication is set to the default cleartext password 'cisco'. You launch an attack to become the active router.

    After successfully injecting a higher priority HSRP packet and becoming the Active router, what critical step must be taken to ensure traffic still reaches the internet and the users do not experience a denial of service?

    Show answer & explanation

    Correct answer: A

    When hijacking the HSRP Active role, your machine claims the Virtual IP (VIP). Clients will send all internet-bound traffic to you. If you simply drop this traffic, it's a DoS. To perform a Man-in-the-Middle (MITM) attack, you must route the received traffic back to the real router (the one you displaced) so it can reach the WAN. This often involves enabling IP forwarding and setting a static route.

  10. Question 10

    Q10

    Which of the following routing protocol attacks allows an attacker to inject a false route into an OSPF area by establishing a full adjacency with a legitimate neighbor, often requiring knowledge or cracking of the MD5 authentication key?

    Show answer & explanation

    Correct answer: B

    LSA Injection involves an attacker establishing a neighbor relationship (adjacency) with a legitimate OSPF router. Once adjacent, the attacker can flood Link State Advertisements (LSAs) claiming to have the best metrics to specific networks, manipulating the routing tables of all routers in the area. This typically requires bypassing authentication.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the GXPN sample set.

Lifetime One

Own this practice test forever.

$
$79.99
one-time
  • Full access to 218 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon