GXPN Practice Questions
Prepare for GXPN with more than an answer.
- Exam fee
- $979 USD
- Level
- Practitioner
- Valid for
- 4 years
Domains covered on the exam 14
- Bypassing Linux Exploit Mitigations7%
- Bypassing Windows Memory Protections7%
- Endpoint Control Evasions and Escalation7%
- Establishing Network Access7%
- Infrastructure Manipulation and Exploitation7%
- Linux Execution, Memory, and Shellcode Foundations7%
- Network Interception and Traffic Manipulation7%
- Practical Cryptography7%
- Practical Scripting for Offensive Operations7%
- Product Security Testing and Fuzzing Foundations7%
- Return Oriented Stack-Based Exploits7%
- Source Code Based Fuzzing Techniques7%
- Windows Execution and Memory Foundations7%
- Windows Overflows and Execution Control7%
- 1
Which cryptographic vulnerability allows an attacker to append data to a message and generate a valid new signature/hash without knowing the secret key, provided the hashing algorithm (like MD5 or SHA-1) uses the Merkle-Damgård construction?
Show answer details
Correct answer: D
A Hash Length Extension attack works on Merkle-Damgård hashes (MD5, SHA1, SHA2). If an application validates integrity as
Hash(Secret + Message), an attacker knowingHash(Secret + Message)and the length of the message can initialize the hash function with the existing hash state and continue hashing new data, effectively generatingHash(Secret + Message + Padding + NewData)without knowingSecret. - 2
You are writing a Python script using the Scapy library to fuzz a proprietary TCP protocol. You want to send a packet with a randomized TCP Sequence Number.
Which Scapy syntax correctly generates a TCP packet with a random sequence number between 1000 and 5000 sent to IP 192.168.1.50?
Show answer details
Correct answer: B
In Scapy, packets are constructed by layering protocols using the
/operator. TheIP()layer specifies the destination, and theTCP()layer handles ports and sequence numbers.RandNum(min, max)is a Scapy volatility object that generates a random number within the specified range for each packet sent. - 3
You are developing a Python script to interact with the Windows API to allocate memory and execute shellcode. Which standard Python library allows you to load DLLs (like
kernel32.dll) and call C data types and functions directly?Show answer details
Correct answer: C
The
ctypeslibrary is a foreign function library for Python. It provides C compatible data types and allows calling functions in DLLs or shared libraries. It is extensively used in offensive Python scripting to interact with the Windows API (e.g.,VirtualAlloc,CreateThread). - 4
In the context of the Sulley or Boofuzz fuzzing frameworks, what is the primary purpose of defining a
s_block_startands_block_endstructure?Show answer details
Correct answer: D
Blocks in Sulley/Boofuzz allow grouping of data primitives. This is essential for handling dynamic fields. For example, a
s_sizeprimitive can reference a block to automatically calculate and insert the length of the data inside that block during fuzzing generation. Without blocks, calculating lengths of fuzzed (mutated) data would be impossible. - 5
Which of the following statements accurately describes the key difference between Generation-based and Mutation-based fuzzing?
Show answer details
Correct answer: C
Generation-based (Smart) fuzzing constructs data from the ground up using a model or grammar of the protocol (e.g., Sulley/Boofuzz). Mutation-based (Dumb) fuzzing takes valid captured traffic or files and applies random changes (bit flipping, byte swapping) without necessarily understanding the structure (e.g., zzf).
- 6
You are analyzing a compromised Linux server and discover a custom binary that is vulnerable to a buffer overflow. The binary has the NX (No-Execute) bit enabled, preventing execution of shellcode on the stack. You decide to employ a Return-to-Libc (ret2libc) attack. You have successfully calculated the base address of libc and the offsets for the
system()function and the string "/bin/sh".To successfully execute
system("/bin/sh")on a 32-bit x86 architecture, how must the stack be constructed at the moment the vulnerable function returns?Show answer details
Correct answer: D
In a standard 32-bit x86 ret2libc attack, the stack must be arranged so that the return address of the vulnerable function points to the
system()function. Immediately following this must be the return address wheresystem()should return after completion (oftenexit()), followed by the arguments forsystem()(the pointer to "/bin/sh"). The calling convention dictates that arguments are pushed onto the stack before the call. - 7
A penetration tester is attempting to exploit a heap-based vulnerability in a Linux service. The service forks a new process for every incoming connection. The tester suspects a stack canary (SSP) is in place, as the application crashes with "*** stack smashing detected ***" when the buffer is overflowed.
Which technique is most appropriate to bypass the stack canary in this specific forking server scenario?
Show answer details
Correct answer: B
In a forking server architecture on Linux, the parent process's memory layout, including the stack canary value, is inherited by the child processes. Because the canary remains constant across forks until the parent restarts, an attacker can brute-force the canary one byte at a time. If a byte is incorrect, the child crashes; if correct, it does not. This allows determining the full canary value.
- 8
You are developing an exploit for a Windows application compiled with SafeSEH. You have control over the stack and can overwrite the SEH record, but you need a valid
pop pop retgadget to redirect execution to your shellcode.Which condition must be met for a
pop pop retgadget to be usable in a SafeSEH environment?Show answer details
Correct answer: D
SafeSEH validates exception handlers against a table of registered handlers within the module. To bypass this, attackers look for gadgets (like
pop pop ret) in modules loaded by the application that were compiled without SafeSEH (or have it disabled). Addresses in these non-SafeSEH modules are not validated against the SafeSEH table, allowing execution flow redirection. - 9
Which Windows 10 exploit mitigation mechanism validates indirect calls by checking a target address against a bitmap of valid function entry points before execution, effectively breaking most standard ROP chains that rely on arbitrary gadgets?
Show answer details
Correct answer: B
Control Flow Guard (CFG) is a compiler-enabled security feature that adds checks before every indirect call (like function pointers). It verifies that the destination address is a valid entry point for a function, significantly restricting the ability to jump to arbitrary ROP gadgets in the middle of functions.
- 10
A penetration tester has obtained user-level access to a Windows workstation protected by AppLocker in 'Enforce' mode. The Default Rule is enabled, blocking all executables in non-standard directories. The tester needs to execute a custom C# payload.
Which 'Living off the Land' binary could be used to bypass AppLocker by executing the payload contained within a specially crafted
.logor.txtfile via theUninstallmethod?Show answer details
Correct answer: C
InstallUtil.exe is a Microsoft .NET framework utility often whitelisted by default. It can be used to bypass AppLocker by executing code embedded in the Uninstall method of a compiled .NET assembly (or sometimes text-based inputs if configured). This is a classic AppLocker bypass technique.
