GXPN Sample Questions

GXPN Sample Questions & Answers

Fourteen evenly weighted topics span Linux and Windows memory-protection bypasses, endpoint evasion, privilege escalation, intercepting network traffic after gaining access, building shellcode and ROP chains, cryptographic flaws, and Python-based offensive tooling.

Launch the full GXPN simulator →

Showing 10 of 20 free samples.

  1. Question 1Advanced

    Endpoint Control Evasions and Escalation · PowerShell constrained language mode

    A security analyst is testing a Windows environment where PowerShell is configured in Constrained Language Mode (CLM). The analyst attempts to run a script that utilizes .NET reflection to load a DLL into memory but receives an error stating the type cannot be created.

    What is the primary technical reason this script fails in CLM?

    Show answer & explanation

    Correct answer: D

    Constrained Language Mode (CLM) is designed to limit the capabilities of PowerShell to prevent abuse. It restricts access to critical .NET types (like System.Reflection or System.Runtime.InteropServices) and methods that allow memory manipulation or interaction with unmanaged code. Only a subset of 'safe' types is permitted.

  2. Question 2Intermediate

    Establishing Network Access · 802.1X authentication bypass

    You are performing a physical penetration test and encounter a network port secured with 802.1X. You have a physical device that can bridge connections. You disconnect the victim PC, connect your bridge device to the wall, and connect the victim PC to the bridge. You wait for the victim to authenticate.

    Once the victim authenticates, what specific action must your attack device take to successfully piggyback on the session without triggering a port security violation?

    Show answer & explanation

    Correct answer: D

    In an 802.1X bypass scenario using a bridge (like a 'Phantom' or 'Shadow' attack), the attacker waits for the victim to authenticate. Once authenticated, the switch port allows traffic from the victim's MAC. The attacker must spoof the victim's MAC address to inject traffic. Crucially, the attacker must also drop EAPOL Logoff packets from the victim to keep the session alive if the victim disconnects or reboots.

  3. Question 3Beginner

    Establishing Network Access · VLAN hopping

    A penetration tester is connected to a switch port assigned to VLAN 10 (Native VLAN 1). The tester wishes to reach a target server on VLAN 20. The switch is configured with 802.1Q trunking to an upstream switch.

    Which technique involves crafting a packet with two VLAN tags, where the first tag matches the native VLAN of the trunk, allowing the packet to be stripped of the first tag and forwarded to the second VLAN on the next switch?

    Show answer & explanation

    Correct answer: A

    Double Tagging (VLAN Hopping) involves sending a frame with two 802.1Q tags. The outer tag matches the native VLAN of the trunk port. The first switch strips this outer tag (as is standard for native VLAN traffic) and forwards the frame. The receiving switch then sees the second (inner) tag and forwards the packet to the target VLAN. This is a unidirectional attack.

  4. Question 4Intermediate

    Infrastructure Manipulation and Exploitation · HSRP/VRRP attacks

    You are auditing a network that uses HSRP (Hot Standby Router Protocol) for gateway redundancy. You discover that HSRP authentication is set to the default cleartext password 'cisco'. You launch an attack to become the active router.

    After successfully injecting a higher priority HSRP packet and becoming the Active router, what critical step must be taken to ensure traffic still reaches the internet and the users do not experience a denial of service?

    Show answer & explanation

    Correct answer: B

    When hijacking the HSRP Active role, your machine claims the Virtual IP (VIP). Clients will send all internet-bound traffic to you. If you simply drop this traffic, it's a DoS. To perform a Man-in-the-Middle (MITM) attack, you must route the received traffic back to the real router (the one you displaced) so it can reach the WAN. This often involves enabling IP forwarding and setting a static route.

  5. Question 5Advanced

    Infrastructure Manipulation and Exploitation · OSPF attacks

    Which of the following routing protocol attacks allows an attacker to inject a false route into an OSPF area by establishing a full adjacency with a legitimate neighbor, often requiring knowledge or cracking of the MD5 authentication key?

    Show answer & explanation

    Correct answer: B

    LSA Injection involves an attacker establishing a neighbor relationship (adjacency) with a legitimate OSPF router. Once adjacent, the attacker can flood Link State Advertisements (LSAs) claiming to have the best metrics to specific networks, manipulating the routing tables of all routers in the area. This typically requires bypassing authentication.

  6. Question 6Intermediate

    Linux Execution, Memory, and Shellcode Foundations · x86/x64 assembly for shellcode

    You are writing x64 shellcode for a Linux exploit. The input buffer is processed by a strcpy function, which terminates on a null byte (0x00). You need to set the rax register to value 59 (execve syscall) without introducing null bytes.

    Which assembly instruction sequence achieves this most efficiently while avoiding null bytes?

    Show answer & explanation

    Correct answer: D

    mov rax, 59 compiles to machine code containing null bytes because rax is 64-bit and 59 is small. To avoid this, xor rax, rax clears the register (creating 0 without null bytes in opcode), and add rax, 59 sets the value. Alternatively, push 59; pop rax or using the lower 8-bit register al (mov al, 59) after clearing rax are common techniques.

  7. Question 7Beginner

    Linux Execution, Memory, and Shellcode Foundations · Process memory layout

    In a standard Linux process memory layout on x86 architecture, towards which direction does the Stack grow and towards which direction does the Heap grow?

    Show answer & explanation

    Correct answer: B

    In the standard virtual memory layout, the Stack is located at high memory addresses and grows 'down' towards lower addresses. The Heap is located above the Data/BSS segments and grows 'up' towards higher memory addresses. They grow towards each other.

  8. Question 8Intermediate

    Network Interception and Traffic Manipulation · Packet crafting and injection

    Case Study: You are conducting a penetration test on an IPv6-enabled internal network. You notice that hosts are configuring their addresses using Stateless Address Autoconfiguration (SLAAC). You decide to perform a Man-in-the-Middle (MITM) attack by advertising yourself as a rogue router.

    Which specific ICMPv6 message type must you craft and broadcast to the local segment to convince clients to route traffic through your machine?

    Show answer & explanation

    Correct answer: A

    In IPv6 SLAAC, routers send Router Advertisement (RA, Type 134) messages to inform clients of network prefixes and gateway information. By spoofing RA packets with a high priority, an attacker can designate themselves as the default gateway for the segment, enabling traffic interception.

  9. Question 9Beginner

    Network Interception and Traffic Manipulation · ARP poisoning for MITM

    When performing an ARP Cache Poisoning attack using a tool like arpspoof or ettercap, why is it critical to enable IP forwarding on the attacker's machine?

    Show answer & explanation

    Correct answer: B

    ARP poisoning redirects the victim's traffic to the attacker's machine. If IP forwarding is not enabled, the attacker's kernel will drop packets destined for other IP addresses, cutting the victim off from the network (DoS). Enabling IP forwarding ensures the packets are routed to the legitimate gateway after interception.

  10. Question 10Advanced

    Practical Cryptography · Padding oracle attacks

    A Padding Oracle attack against CBC mode encryption relies on the server leaking information about whether a decrypted ciphertext has valid PKCS#7 padding.

    If you modify the last byte of the second-to-last ciphertext block ($C_{N-1}$) and send it to the oracle, what information are you attempting to deduce about the last block ($C_N$)?

    Show answer & explanation

    Correct answer: A

    In CBC mode, decryption involves decrypting the ciphertext block and then XORing with the previous ciphertext block. By modifying bytes in $C_{N-1}$, the attacker changes the input to the XOR operation for $P_N$. By iterating through 256 possibilities and observing padding errors, the attacker can deduce the 'Intermediate State' (the output of the block cipher decryption before the XOR). Knowing the Intermediate State and the original $C_{N-1}$ allows calculating the plaintext $P_N$.

Ready for the real thing?

The full GXPN simulator has every exam-style question, timed mode, and instant scoring.

Go to the GXPN simulator →