Question 1
Which command shows the Windows firewall settings, including all profiles?
Correct Answer:
netsh advfirewall show allprofiles
Explanation:
To view Windows Firewall settings for every network profile, you need the Advanced Firewall context and request all profiles in one command. The correct command is netsh advfirewall show allprofiles. The advfirewall namespace is the modern interface for Windows Firewall with Advanced Security, and show allprofiles returns the settings for Domain, Private, and Public profiles in one view, giving a complete picture of how the firewall is configured across all contexts. The other options use older or incorrect syntax—netsh firewall is deprecated on newer Windows versions, and showing the current profile only returns just the active profile, not all of them.
Question 2
Which practice improves PowerShell usability by shortening flags?
Correct Answer:
Command flag shortening
Explanation:
PowerShell can accept shortened, unambiguous parameter names, so you can type a shorter flag instead of the full parameter name. This directly speeds how you specify options because the shell will bind to the intended parameter as long as the prefix you type uniquely identifies it. For example, if a cmdlet has a parameter named Recurse, you can often use Rec as long as no other parameter starts with Rec, and PowerShell will treat it as -Recurse. This reduces keystrokes and friction when building commands, which is exactly what shortening flags aims to achieve. Tab Autocomplete helps you type faster by filling in the rest after you start typing, but it’s a broader usability aid rather than shortening the flag itself. Profile scripts and verbose output don’t address shortening the flags you type.
Question 3
In Metasploit, which module can perform pass-the-hash authentication by using an administrator's hash for SMB login?
Correct Answer:
psexec
Explanation:
Pass-the-hash authentication uses an NTLM hash to prove identity to Windows services (like SMB) without needing the plaintext password. For performing remote command execution over SMB using a hash in Metasploit, the module that fits this purpose is the psexec module. It connects to the target via SMB (often through the admin$ share) and runs the payload using the provided credentials, which can be an administrator’s NTLM hash instead of a cleartext password. This makes it the best fit for logins authenticated with a hash and immediate remote execution. Hashdump is used after you have access to dump password hashes from the target; smb_login is for testing login viability against an SMB service and doesn’t provide the remote execution flow with a hash; windows/gather/credentials collects credentials but isn’t focused on performing pass-the-hash authentication for SMB login.
Question 4
What does the related: directive show?
Correct Answer:
Pages that have similar content and links to the searched page
Explanation:
The related: operator is a search tool that returns pages Google considers connected to a given page. It bases this on how similar the content is and how pages link to or from the target page. So it’s about finding pages with similar topics and/or pages that are linked to the searched page, not about being in the same directory, nor about terms in the URL, nor about the site’s robots.txt.
Question 5
What should you verify with administrators about lockout during testing?
Correct Answer:
Whether account lockout is utilized on the target network.
Explanation:
Understanding whether account lockout is in place and how it works is essential when testing authentication. Verifying this with administrators helps you avoid unintentionally locking out real users and ensures you stay within authorized, safe boundaries. You want to know if the system enforces a lockout after a certain number of failed logins, the exact threshold, how long the lockout lasts, and how the counter resets. Also clarify any exemptions for privileged or service accounts, whether there are maintenance windows or special rules, and the approved procedure if a lockout occurs during testing. It’s important to align on whether temporary disabling, targeted testing windows, or active monitoring is permitted, and to have written authorization in place. The other options listed aren’t related to login security and wouldn’t help you manage lockout risk.
Question 1
Exam overview

About this Exam

Prepare with the SANS560 GIAC Penetration Tester (GPEN) Practice Test practice quiz. This question bank includes 10 questions covering target, command, shows, sans560, and giac. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

More details

Additional Information

SANS560 GIAC Penetration Tester (GPEN) Practice Test

This practice set contains 10 questions from the matching question bank and focuses on target, command, shows, sans560, and giac. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions