Examcollection offers free demo for GPEN exam. "GIAC Certified Penetration Tester", also known as GPEN exam, is a GIAC Certification. This set of posts, Passing the GIAC GPEN exam, will help you answer those questions. The GPEN Questions & Answers covers all the knowledge points of the real exam. 100% real GIAC GPEN exams and revised by experts!

Online GIAC GPEN free dumps demo Below:

NEW QUESTION 1

You are pen testing a Windows system remotely via a raw netcat shell. You want to quickly change directories to where the Windows operating system resides, what command could you use?

  • A. cd systemroot
  • B. cd-
  • C. cd /systemroot/
  • D. cd %systemroot%

Answer: B

NEW QUESTION 2

How does OWASP ZAP function when used for performing web application assessments?

  • A. It is a non-transparent proxy that sits between your web browser and the targetapplicatio
  • B. It is a transparent policy proxy that sits between Java servers and |SP web page
  • C. It is a non-transparent proxy that passively sniffs network traffic for HTTPvulnerabilitie
  • D. It is a transparent proxy that sits between a target application and the backenddatabas

Answer: D

NEW QUESTION 3

Which of the following statements about Fport is true?

  • A. It works as a process viewe
  • B. It works as a datapipe on Window
  • C. It works as a datapipe on Linu
  • D. It is a source port forwarder/redirecto

Answer: A

NEW QUESTION 4

Which of the following Web authentication techniques uses a single sign-on scheme?

  • A. NTLM authentication
  • B. Microsoft Passport authentication
  • C. Basic authentication
  • D. Digest authentication

Answer: B

NEW QUESTION 5

When attempting to crack a password using Rainbow Tables, what is the output of the
reduction function?

  • A. A new potential chain
  • B. A new potential table
  • C. A new potential password
  • D. A new potential hash

Answer: D

Explanation:
Reference:
http://en.wikipedia.org/wiki/Rainbow_table

NEW QUESTION 6

You suspect that system administrators In one part of the target organization are turning off their systems during the times when penetration tests are scheduled, what feature could you add to the ' Rules of engagement' that could help your team test that part of the target organization?

  • A. Un announced test
  • B. Tell response personnel the exact lime the test will occur
  • C. Test systems after normal business hours
  • D. Limit tests to business hours

Answer: C

NEW QUESTION 7

Which of the following techniques are NOT used to perform active OS fingerprinting?
Each correct answer represents a complete solution. Choose all that apply.

  • A. ICMP error message quoting
  • B. Analyzing email headers
  • C. Sniffing and analyzing packets
  • D. Sending FIN packets to open ports on the remote system

Answer: BC

NEW QUESTION 8

Which of the following tools is used to verify the network structure packets and confirm that the packets are constructed according to specification?

  • A. snort_inline
  • B. EtherApe
  • C. Snort decoder
  • D. AirSnort

Answer: C

NEW QUESTION 9

A penetration tester wishes to stop the Windows Firewall process on a remote host running Windows Vista She issues the following commands:
GPEN dumps exhibit
A check of the remote host indicates that Windows Firewall is still running. Why did the command fail?

  • A. The kernel prevented the command from being execute
  • B. The user does not have the access level needed to stop the firewal
  • C. The sc command needs to be passed the IP address of the targe
  • D. The remote server timed out and did not complete the comman

Answer: C

NEW QUESTION 10

You have been contracted to perform a black box pen test against the Internet facing servers for a company. They want to know, with a high level of confidence, if their servers are vulnerable to external attacks. Your contract states that you can use all tools available to you to pen test the systems. What course of action would you use to generate a report with the lowest false positive rate?

  • A. Use a port scanner to find open service ports and generate a report listing allvulnerabilities associated with those listening service
  • B. Use a vulnerability or port scanner to find listening services and then try to exploitthose service
  • C. Use a vulnerability scanner to generate a report of vulnerable service
  • D. Log into the system and record the patch levels of each service then generate areport that lists known vulnerabilities for all the running service

Answer: B

NEW QUESTION 11

You work as a Penetration Tester for the Infosec Inc. Your company takes the projects of
security auditing. Recently, your company has assigned you a project to test the security of the we-aresecure. com Web site. For this, you want to perform the idle scan so that you can get the ports open in the we-are-secure.com server. You are using Hping tool to perform the idle scan by using a zombie computer. While scanning, you notice that every IPID is being incremented on every query, regardless whether the ports are open or close. Sometimes, IPID is being incremented by more than one value. What may be the reason?

  • A. The zombie computer is not connected to the we-are-secure.com Web serve
  • B. The zombie computer is the system interacting with some other system besides your comp ute
  • C. Hping does not perform idle scannin
  • D. The firewall is blocking the scanning proces

Answer: B

NEW QUESTION 12

GSM uses either A5/1 or A5/2 stream cipher for ensuring over-the-air voice privacy. Which
of the following cryptographic attacks can be used to break both ciphers?

  • A. Man-in-the-middle attack
  • B. Ciphertext only attack
  • C. Known plaintext attack
  • D. Replay attack

Answer: B

NEW QUESTION 13

John, a novice web user, makes a new E-mail account and keeps his password as "apple", his favorite fruit. John's password is vulnerable to which of the following password cracking attacks?
Each correct answer represents a complete solution. Choose all that apply.

  • A. Brute Force attack
  • B. Dictionary attack
  • C. Hybrid attack
  • D. Rule based attack

Answer: ABC

NEW QUESTION 14

John works as a Professional Penetration Tester. He has been assigned a project to test the Website security of www.we-are-secure Inc. On the We-are-secure Website login page, he enters='or''=' as a username and successfully logs on to the user page of the Web site. Now, John asks the we-are-secure Inc. to improve the login page PHP script. Which of the following suggestions can John give to improve the security of the we-are-secure Website login page from the SQL injection attack?

  • A. Use the session_regenerate_id() function
  • B. Use the escapeshellcmd() function
  • C. Use the mysql_real_escape_string() function for escaping input
  • D. Use the escapeshellarg() function

Answer: C

NEW QUESTION 15

Which of the following enables an inventor to legally enforce his right to exclude others from using his invention?

  • A. Artistic license
  • B. Spam
  • C. Patent
  • D. Phishing

Answer: C

NEW QUESTION 16
......

P.S. Easily pass GPEN Exam with 385 Q&As Surepassexam Dumps & pdf Version, Welcome to Download the Newest Surepassexam GPEN Dumps: https://www.surepassexam.com/GPEN-exam-dumps.html (385 New Questions)