Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free GIAC Certified Penetration Tester GPEN Exam Questions

Page: 1 / 27 Total 391 questions

Want more questions? Get Premium Access.

Question 1

The employees of EWS Inc. require remote access to the company's Web servers. In order to provide solid wireless security, the company uses EAP-TLS as the authentication protocol. Which of the following statements are true about EAP-TLS?

Each correct answer represents a complete solution. Choose all that apply.

Correct Answer: A. It is supported by all manufacturers of wireless LAN hardware and software.; B. It uses a public key certificate for server authentication.

Question 2

The employees of CCN Inc. require remote access to the company's proxy servers. In order to provide solid wireless security, the company uses LEAP as the authentication protocol. Which of the following is supported by the LEAP protocol?

Each correct answer represents a complete solution. Choose all that apply.

Correct Answer: B. Dynamic key encryption; C. Password hash for client authentication

Question 3

Which of the following are countermeasures to prevent unauthorized database access attacks?

Each correct answer represents a complete solution. Choose all that apply.

Correct Answer: A. Removing all stored procedures; B. Input sanitization; C. Applying strong firewall rules; D. Session encryption

Question 4

You want to retrieve password files (stored in the Web server's index directory) from various Web sites. Which of the following tools can you use to accomplish the task?

Correct Answer: D. Google

Question 5

This is a Windows-based tool that is used for the detection of wireless LANs using the IEEE 802.11a, 802.11b, and 802.11g standards. The main features of these tools are as follows:

It displays the signal strength of a wireless network, MAC address, SSID, channel details, etc.

It is commonly used for the following purposes:

a. War driving

b. Detecting unauthorized access points

c. Detecting causes of interference on a WLAN

d. WEP ICV error tracking

e. Making Graphs and Alarms on 802.11 Data, including Signal Strength

This tool is known as __________.

Correct Answer: C. NetStumbler

Question 6

John works as a contract Ethical Hacker. He has recently got a project to do security checking for www.we-are-secure.com. He wants to find out the operating system of the we-are-secure server in the information gathering step. Which of the following commands will he use to accomplish the task?

Each correct answer represents a complete solution. Choose two.

Correct Answer: B. nmap -v -O 208.100.2.25; D. nmap -v -O www.we-are-secure.com

Question 7

You want to run the nmap command that includes the host specification of 202.176.56-57.*. How many hosts will you scan?

Correct Answer: A. 512

Question 8

John works as a professional Ethical Hacker. He has been assigned the project of testing the security of www.we-are-secure.com. He has successfully performed the following steps of the preattack phase to check the security of the We-are-secure network:

Gathering information

Determining the network range

Identifying active systems

Now, he wants to find the open ports and applications running on the network. Which of the following tools will he use to accomplish his task?

Correct Answer: B. SuperScan

Question 9

You work as a Network Administrator for Tech Perfect Inc. The company has a TCP/IP-based network. Rick, your assistant, is configuring some laptops for wireless access. For security, WEP needs to be configured for wireless communication. By mistake, Rick configures different WEP keys in a laptop than that is configured on the Wireless Access Point (WAP). Which of the following statements is true in such situation?

Correct Answer: D. The laptop will not be able to access the wireless network.

Question 10

Which

of the following wireless security standards supported by Windows Vista provides the highest level of security?

Correct Answer: A. WPA2

Question 11

Which of the following is the frequency range to tune IEEE 802.11a network?

Correct Answer: B. 5.15-5.825 GHz

Question 12

Which of the following tools is used for vulnerability scanning and calls Hydra to launch a dictionary attack?

Correct Answer: D. Nessus

Question 13

Which of the following tools is spyware that makes Windows clients send their passwords as clear text?

Correct Answer: D. C2MYAZZ

Question 14

Which of the following is the default port value of beast Trojan?

Correct Answer: A. 6666

Question 15

Which of the following are the two different file formats in which Microsoft Outlook saves e-mail messages based on system configuration?

Each correct answer represents a complete solution. Choose two.

Correct Answer: B. .ost; C. .pst