GIAC · Penetration Tester GPEN

GIAC Penetration Tester GPEN Exam Practice Questions

385 questionsInstant PDF downloadUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 385 questions in this pack

Question 1

ACME corporation has decided to setup wireless (IEEE 802.11) network in it's sales branch at Tokyo and found that channels 1, 6, 9,11 are in use by the neighboring offices. Which is the best channel they can use?

  1. 4
  2. 5
  3. 10
  4. 2
Show answer and explanation

Correct answer: A. 4

In IEEE 802.11b/g the US non-overlapping channels are 1, 6, and 11. With channels 1, 6, 9, and 11 already occupied, no truly clean channel remains, so the goal is the least overlap. Channel 4 sits farthest from the busy channels, giving the most separation available. It is the best remaining choice among the options offered.

Why the other options are wrong

  • B. Channel 5 is too close to channel 6, which is already in use.
  • C. Channel 10 is too close to channel 9 and 11, both occupied.
  • D. Channel 2 is too close to channel 1, which is already in use.

Question 2

Which Metasploitvncinject stager will allow VNC communications from the attacker to a listening port of the attacker's choosing on the victim machine?

  1. Vncinject/find.lag
  2. Vncinject/reverse.tcp
  3. Vncinject/reverse-http
  4. Vncinject /bind.tcp
Show answer and explanation

Correct answer: D. Vncinject /bind.tcp

The vncinject/bind.tcp stager creates a listening port on the victim machine that the attacker connects to, allowing VNC communication from attacker to victim on a port of the attacker's choosing. This matches the requirement of 'VNC communications from the attacker to a listening port of the attacker's choosing on the victim machine.'

Why the other options are wrong

  • A. The option 'vncinject/find.lag' is not a valid Metasploit stager.
  • B. The reverse.tcp stager creates a connection from victim back to attacker, opposite of the requirement.
  • C. The reverse-http stager uses HTTP for communication and reverses the connection direction.

Question 3

What is the MOST important document to obtain before beginning any penetration testing?

  1. Project plan
  2. Exceptions document
  3. Project contact list
  4. A written statement of permission
Show answer and explanation

Correct answer: D. A written statement of permission

A written statement of permission is the most critical document before beginning any penetration testing. This legal authorization protects both the tester and the organization, clearly defines scope, and ensures that all testing activities are legitimate and authorized. Without this, any testing could be considered unauthorized access and illegal.

Why the other options are wrong

  • A. A project plan is important but secondary to obtaining explicit written permission first.
  • B. An exceptions document is useful but not obtained before testing begins.
  • C. A project contact list is administrative but not as critical as written authorization.

See all 10 free questions Get the full pack, US$39

385 practice questions for GIAC Penetration Tester (GPEN), with full explanations.

Every question comes with the correct answer and a clear explanation. Mapped to the current GPEN exam objectives.

  • 385 questions mapped to the GPEN exam objectives
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

The GPEN costs US$999 per attempt. This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 385 questions

What makes the GPEN hard

The GPEN tests whether a candidate can actually conduct a penetration test, not just talk about one. It is 82 questions in three hours, open book, with a 73% pass mark.

The exam covers the full attack lifecycle: scoping and reconnaissance, scanning and enumeration, exploitation, password attacks, privilege escalation, lateral movement, persistence, and web application attacks. It is methodology driven, so knowing individual techniques is not enough; the pieces need to fit together across a real engagement. With only 82 questions, every one carries more than a full percentage point of the score.

This pack has 385 practice questions for the GPEN, useful for finding the gaps before GIAC does, especially in areas candidates tend to underestimate, such as post-exploitation methodology and reporting requirements.

About the exam

The GPEN validates hands-on skill in planning and executing penetration tests against enterprise targets. It covers the full attack lifecycle using real tools and techniques, making it one of the most respected offensive security certifications available. It is aligned to SANS SEC560 and mapped to DoD 8140.

Exam topics

  • Penetration testing methodology: scoping, rules of engagement, reporting
  • Reconnaissance: passive and active information gathering
  • Scanning and enumeration: identifying targets, services, and vulnerabilities
  • Exploitation: attacking systems using known vulnerabilities and misconfigurations
  • Password attacks: cracking, spraying, and credential reuse techniques
  • Post-exploitation: privilege escalation, lateral movement, persistence
  • Web application attacks: common application-layer exploitation techniques

82 questions, 3 hours, passing score 73%, open book, US$999 per attempt, valid 4 years, maps to DoD 8140.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the GIAC Penetration Tester GPEN pack?

385 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Straight away. The full PDF and a questions-only copy are emailed to you the moment your payment goes through, and the same links are on your order page.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.