Courseiva

CompTIA PenTest+ (PT0-003) (PT0-003) — Questions 451–525

777 questions total · 11pages · All types, answers revealed

Page 6

Page 7 of 11

Page 8
451
MCQhard

A penetration tester has gained a low-privileged shell on a Linux server and discovers a binary with the SUID bit set owned by root. The binary executes a system command using a relative path without sanitizing user input. Which of the following techniques would the tester MOST likely use to escalate privileges?

A.Exploit a kernel vulnerability to gain root
B.Modify the PATH environment variable to point to a malicious script with the same name as the command called by the binary
C.Impersonate the root user using sudo
D.Preload a shared library using LD_PRELOAD
AnswerB

PATH hijacking leverages the SUID binary's use of a relative path; by placing a malicious executable earlier in PATH, the binary executes it with root privileges.

Why this answer

The SUID binary executes a system command using a relative path without sanitizing user input. By modifying the PATH environment variable to include a directory containing a malicious script with the same name as the command, the tester can cause the binary to execute the attacker-controlled script instead of the intended system command, thereby escalating privileges to root when the SUID binary runs.

Exam trap

The trap here is that candidates may think kernel exploitation (Option A) is always the go-to for privilege escalation, but the question specifically describes a misconfigured SUID binary with a relative path and unsanitized input, making PATH hijacking the most direct and likely technique.

How to eliminate wrong answers

Option A is wrong because exploiting a kernel vulnerability is a different technique that does not leverage the specific misconfiguration of the SUID binary with a relative path and unsanitized input; it would be used if no such binary existed or if kernel exploits were available, but the question explicitly describes a binary that can be exploited via PATH hijacking. Option C is wrong because impersonating the root user using sudo requires the tester to already have sudo privileges or know the root password, which is not the case here; the tester has a low-privileged shell and cannot simply use sudo without proper authorization.

452
MCQmedium

A penetration tester gains a low-privilege shell on a Linux server. Using 'sudo -l', the tester finds that they can run '/usr/bin/vi' as root without a password. Which technique would the tester MOST likely use to escalate privileges?

A.Exploit a kernel vulnerability
B.Use vi to execute a shell as root
C.Modify a cron script
D.Perform PATH hijacking
AnswerB

If the low-privilege user is in the sudoers file with permissions to run vi as root, vi's interactive ex-mode command ':!/bin/bash' will launch a shell with root privileges. This works because vi passes the rest of the ex command line to the system shell, and since vi is running as root, the spawned bash inherits that elevated UID. This is a classic sudo misconfiguration and the intended escalation vector in this scenario.

Why this answer

GTFOBins lists vi as having a sudo escape, allowing privilege escalation by spawning a root shell. Other options are not directly applicable.

453
MCQeasy

A client requests a penetration test but only provides network diagrams and application credentials. Which type of test is being scoped?

A.Red team
B.Black box
C.Grey box
D.White box
AnswerC

Grey box testing occupies the middle ground between black and white box, giving the tester limited but realistic information such as network diagrams, IP ranges, and low-privileged credentials. This approach mirrors an insider or partially compromised external attacker and is the standard for many commercial penetration tests because it balances thoroughness with real-world conditions. The client's provision of network diagrams and credentials exactly matches this limited-information model, making Grey box the correct answer.

Why this answer

A grey box test provides the tester with limited information such as network diagrams and credentials, which matches the scenario. Black box tests provide no information, white box tests provide full information, and red team engagements are a type of test, not a box color.

454
MCQhard

During a penetration test, you find a web application that uses JavaScript to make API calls. You want to discover hidden API endpoints and potential secrets (e.g., API keys) embedded in the client-side code. Which approach is most appropriate?

A.Download and analyze the JavaScript files
B.Perform a DNS zone transfer
C.Run a Nikto scan against the application
D.Use theHarvester to search for API endpoints
AnswerA

Downloading and analyzing the JavaScript files is the correct approach because client-side web applications commonly expose API endpoints, authentication logic, and hardcoded secrets within their scripts. By fetching every .js file referenced by the page (including bundled and lazy-loaded modules), you can inspect source maps, search for strings like 'api/', 'token', 'secret', or 'Bearer', and reconstruct the application's internal routing. Tools like Burp Suite, Chrome DevTools, and JSParser can automate extraction, and even minified code can be beautified to reveal hidden functionality that is not visible in normal page interaction.

Why this answer

JavaScript files in client-side web applications often contain hardcoded API endpoints, API keys, and other secrets that developers inadvertently leave in the source code. By downloading and analyzing these files (e.g., via browser developer tools or wget), you can discover hidden endpoints and sensitive tokens that are not exposed in the HTML or network traffic alone.

Exam trap

The trap here is that candidates may confuse information gathering techniques (e.g., DNS zone transfer or OSINT) with client-side code analysis, assuming that API endpoints must be found through network scanning rather than by examining the application's own source code.

How to eliminate wrong answers

Option B is wrong because DNS zone transfer is a network-level technique used to enumerate DNS records (e.g., subdomains) from a DNS server, not to extract API endpoints or secrets from client-side code. Option C is wrong because Nikto is a web server vulnerability scanner that checks for known vulnerabilities and misconfigurations, but it does not parse JavaScript files to find hidden API endpoints or embedded secrets. Option D is wrong because theHarvester is an OSINT tool designed to gather emails, subdomains, and other public information from search engines and PGP servers, not to analyze client-side JavaScript for API endpoints or secrets.

455
MCQmedium

While exploiting a Windows machine, a tester gains a shell with limited privileges. They attempt to escalate privileges using a tool that exploits the SeImpersonatePrivilege. Which tool is specifically designed for this purpose on modern Windows versions?

A.Mimikatz
B.JuicyPotato
C.PrintSpoofer
D.PowerUp
AnswerC

PrintSpoofer is the correct tool for Windows 10/Server 2016 and later when the compromised account holds SeImpersonatePrivilege. It works by tricking the Print Spooler service into impersonating the user via its named pipe, then using that impersonated token to launch a SYSTEM process (e.g., cmd.exe). Unlike JuicyPotato's DCOM-based NTLM relay, PrintSpoofer doesn't rely on outdated COM handshakes, making it far more reliable on modern builds. Its name is misleading—it's not exploiting a vulnerability in the spooler, but abusing an advertised impersonation feature to elevate privileges.

Why this answer

PrintSpoofer exploits SeImpersonatePrivilege on Windows 10/Server 2016+ to gain SYSTEM.

456
MCQhard

A penetration tester has gained a low-privilege shell on a Windows server and discovered that the SeImpersonatePrivilege is enabled. Which of the following tools would be most appropriate to escalate privileges to SYSTEM-level access?

A.pth-winexe
B.PrintSpoofer
C.Responder
D.CrackMapExec
AnswerB

PrintSpoofer is a local privilege escalation tool that abuses the SeImpersonatePrivilege or SeAssignPrimaryTokenPrivilege commonly granted to Windows service accounts. It leverages the Print Spooler service's named pipe to capture a SYSTEM token and then impersonates it, spawning a process as NT AUTHORITY\SYSTEM. This directly escalates the existing low-privilege shell to full system privileges on the same host, making it the correct choice for this scenario.

Why this answer

SeImpersonatePrivilege allows token impersonation. Tools like PrintSpoofer exploit this to gain SYSTEM privileges. Potato attacks (JuicyPotato) also work, but PrintSpoofer is more modern and reliable.

457
Multi-Selectmedium

A penetration tester is conducting an internal network assessment. The tester wants to perform a man-in-the-middle attack to capture credentials. Which TWO tools can be used for ARP spoofing?

Select 2 answers
A.Ettercap
B.Responder
C.Nmap
D.Bettercap
E.Hashcat
AnswersA, D

Ettercap is a dedicated MITM framework that implements ARP poisoning natively, allowing an attacker to redirect LAN traffic by sending forged ARP replies that map the target's IP to the attacker's MAC. It supports both interactive and plugin-based attacks, including session hijacking and packet filtering, making it specifically suited for ARP-based interception.

Why this answer

Bettercap and Ettercap are both capable of ARP spoofing.

458
MCQhard

Refer to the exhibit. A penetration tester is presenting this finding to a non-technical executive. Which improvement should be made to the description?

A.Include the CVSS vector
B.List the exact database tables affected
C.Add a proof-of-concept screenshot
D.Describe the business impact in plain language
AnswerD

Describing the business impact in plain language translates the technical vulnerability into outcomes such as financial loss, legal non-compliance, or reputational damage. For example, instead of saying 'SQL injection in the login form,' state 'an attacker could access customer payment records, leading to potential fines and loss of customer confidence.' This approach aligns the technical finding with the organization's strategic objectives and risk tolerance, enabling executives to make informed decisions about resource allocation and remediation priorities.

Why this answer

Describing the business impact in plain language helps executives understand the risk without technical jargon.

459
MCQhard

A client wants a penetration test that includes testing of their internal network, external perimeter, and wireless. However, they have a very limited budget. Which approach would best meet the client's needs while staying within budget?

A.Use vulnerability scanners for all three areas
B.Conduct a targeted test focusing on high-risk areas identified through threat modeling
C.Only test internal and external
D.Only test external and wireless
AnswerB

A targeted test driven by threat modeling is the correct balance because it aligns the scope with the client's actual risk profile, focusing time and budget on the assets and attack paths that matter most. Threat modeling (e.g., STRIDE, DREAD, or attack trees) identifies high-value targets such as internet-facing applications, sensitive data stores, and internal systems reachable via phishing or lateral movement. By prioritizing these areas, the tester can apply manual exploitation techniques and deeper verification on the highest-risk components while still covering all three requested domains (internal, external, wireless) in a scoped manner. This approach is more effective than blind scanning or omitting a requested area, as it delivers actionable findings tied to business impact rather than a generic checklist.

Why this answer

Conducting a targeted test focused on high-risk areas identified through threat modeling allows coverage of all three areas with limited depth, maximizing value within budget. Skipping areas or using only automated tools may not meet the client's full requirements.

460
MCQmedium

A penetration tester is performing a vulnerability scan on a target network. The tester uses Nmap with the default NSE scripts against a web server. The scan report shows several 'http-vuln-cve2017-5638' findings. What does this indicate?

A.The target is vulnerable to Apache Struts2 remote code execution
B.The target is vulnerable to the Heartbleed bug in OpenSSL
C.The target is vulnerable to the Shellshock Bash vulnerability
D.The target has a SQL injection vulnerability
AnswerA

The http-vuln-cve2017-5638 NSE script is purpose-built to detect CVE-2017-5638, an Apache Struts2 vulnerability in the Jakarta Multipart parser that allows unauthenticated remote code execution. The script sends a crafted Content-Type header embedded with an OGNL expression and checks for a response that indicates the command was executed. A positive result from this script therefore directly confirms the target is vulnerable to Apache Struts2 RCE, not any other issue.

Why this answer

The Nmap script 'http-vuln-cve2017-5638' specifically targets the Apache Struts2 remote code execution vulnerability (CVE-2017-5638). This vulnerability exists in the Jakarta Multipart parser used by Apache Struts2, allowing an attacker to execute arbitrary commands via crafted Content-Type headers. The presence of this finding in the scan report indicates the web server is running a vulnerable version of Apache Struts2.

Exam trap

The trap here is that candidates may confuse the CVE number or the technology name, assuming any 'http-vuln-cve' script refers to a generic web vulnerability, when in fact each script is tied to a specific software and CVE, such as Apache Struts2 for CVE-2017-5638.

How to eliminate wrong answers

Option B is wrong because the Heartbleed bug (CVE-2014-0160) is a vulnerability in OpenSSL, not Apache Struts2, and is detected by Nmap scripts like 'ssl-heartbleed', not 'http-vuln-cve2017-5638'. Option C is wrong because the Shellshock Bash vulnerability (CVE-2014-6271) affects the Bash shell and is typically exploited via CGI scripts, not through Apache Struts2's Jakarta Multipart parser, and is detected by scripts such as 'http-shellshock'.

461
MCQeasy

A penetration tester needs to provide a metric that communicates the financial risk of the identified vulnerabilities to the client's CFO. Which metric is most appropriate?

A.Annual Loss Expectancy (ALE).
B.CVSS base score.
C.Number of critical findings.
D.Technical difficulty of exploitation.
AnswerA

ALE is the expected monetary loss per year from a specific risk, calculated as Single Loss Expectancy (SLE) multiplied by Annualized Rate of Occurrence (ARO), where SLE equals asset value times exposure factor. Because it expresses risk in tangible financial terms, the CFO can directly compare potential losses across assets and threats, prioritize remediation based on cost-benefit analysis, and justify security spending or risk transfer such as cyber insurance. This metric is the only answer that translates technical vulnerability context into the business language of dollars and cents.

Why this answer

Annual Loss Expectancy (ALE) is the most appropriate metric for communicating financial risk to a CFO because it quantifies the expected monetary loss per year from a vulnerability, calculated as ALE = Single Loss Expectancy (SLE) × Annualized Rate of Occurrence (ARO). This directly translates technical risk into financial terms, enabling informed budget decisions for remediation. CVSS base scores and critical finding counts lack a financial dimension, making them unsuitable for executive-level risk communication.

Exam trap

CompTIA often tests the misconception that technical severity scores (like CVSS) are sufficient for executive reporting, but the trap here is that financial risk requires a dollar-based metric like ALE, not a technical or count-based measure.

How to eliminate wrong answers

Option B is wrong because CVSS base score is a technical severity metric (0-10) based on exploitability and impact factors, not a financial measure; it does not incorporate asset value or loss frequency, so it cannot express monetary risk to a CFO. Option C is wrong because the number of critical findings is a raw count of high-severity vulnerabilities without any financial context; it ignores asset valuation, likelihood of exploitation, and potential loss, making it irrelevant for financial risk communication.

462
MCQeasy

A client wants a penetration test of their internal network. They are concerned about causing any disruption to the production systems. The tester should include which of the following in the rules of engagement to address this concern?

A.A list of all tools that will be used during the test
B.A clear definition of the testing window and contact information for emergency stop
C.A requirement for the client to disable their antivirus software
D.A statement that the tester will not be liable for any damages
AnswerB

Defining the testing window creates a mutually agreed time boundary that limits the potential blast radius of unintended disruption, while the emergency stop contact gives the client a direct, immediate channel to halt all active testing if systems become unstable. This is a core element of the Rules of Engagement (RoE) and is standard practice in penetration testing, because even scheduled scans can trigger resource exhaustion or trip failover mechanisms. The contact must be reachable 24/7 during the engagement, and the emergency stop procedure should include a clear order to cease all active tools, drop sessions, and confirm shutdown. This directly aligns with the client's stated concern by providing both temporal constraints and a real-time abort capability.

Why this answer

A clearly defined testing window with emergency stop contact information directly addresses the client's concern about production disruption. This ensures the tester can immediately halt activities if any instability is detected, aligning with the principle of minimizing operational impact during a penetration test.

Exam trap

The trap here is that candidates may mistakenly think listing tools or disabling antivirus is necessary for a thorough test, but the core concern is disruption prevention, which is directly addressed by the testing window and emergency stop clause in the RoE.

How to eliminate wrong answers

Option A is wrong because listing all tools used during the test does not prevent or mitigate disruption to production systems; it only provides transparency about the testing methodology. Option C is wrong because requiring the client to disable antivirus software would actually increase the risk of disruption, as it removes a critical security control that could detect and block malicious activity, potentially leading to unintended system instability or compromise.

463
MCQhard

A penetration tester receives pushback from a client's technical team regarding a finding, claiming it is not exploitable. Which of the following is the best response?

A.Escalate the issue to the executive without further discussion.
B.Provide additional evidence and offer to demonstrate the exploit in a controlled environment.
C.Downgrade the severity to low.
D.Remove the finding from the report to avoid conflict.
AnswerB

This is the correct approach because it directly addresses the client's skepticism by strengthening the evidence chain with concrete artifacts such as packet captures, screenshots, and a repeatable step-by-step reproduction guide. A controlled demonstration in a non-production or isolated environment proves exploitability without jeopardizing live systems, providing irrefutable confirmation that the finding is real. This method shifts the conversation from opinion to verified fact and allows the client to see the impact firsthand, reducing ambiguity about severity.

Why this answer

Providing evidence and offering to demonstrate helps validate the finding and address concerns professionally.

464
MCQeasy

Which of the following tools would best assist a penetration tester in identifying known vulnerabilities in a WordPress installation?

A.OpenVAS
B.WPScan
C.Nessus
D.Nikto
AnswerB

WPScan queries the WordPress vulnerability database and enumerates core version, plugins and themes, matching each against known CVEs. That directly satisfies the stem's requirement to identify known vulnerabilities in a WordPress installation, unlike generic scanners that lack WordPress-specific signature data.

Why this answer

WPScan is specifically designed to enumerate and identify vulnerabilities in WordPress installations, including outdated plugins, themes, and core files. It uses a comprehensive database of WordPress CVEs and security issues, making it the most targeted tool for this task.

Exam trap

The trap here is that candidates often choose a general-purpose vulnerability scanner like Nessus or OpenVAS because they are familiar with them, but the question specifically asks for the best tool to identify known vulnerabilities in a WordPress installation, which requires a specialized scanner like WPScan.

How to eliminate wrong answers

Option A (OpenVAS) is wrong because it is a general-purpose vulnerability scanner that covers a wide range of systems and services, but it lacks the specialized WordPress-focused checks and plugin/theme enumeration that WPScan provides. Option C (Nessus) is wrong because, while it can detect some WordPress vulnerabilities, it is a broad-scope scanner that does not offer the deep, WordPress-specific fingerprinting and database of known vulnerabilities that WPScan does. Option D (Nikto) is wrong because it is a web server scanner that checks for common misconfigurations and outdated server software, but it does not perform the detailed WordPress core, plugin, and theme version analysis that WPScan excels at.

465
MCQeasy

A client wants to conduct a penetration test of their web application, but they are concerned about potential service disruption. They request that the tester avoid using any techniques that could cause the application to crash or become unresponsive. Which of the following should the tester include in the rules of engagement to address this requirement?

A.Specify that the tester will only use ACK scans and never send data payloads.
B.Include a clause that prohibits denial-of-service attacks and rate-limits all automated tools.
C.State that the tester will not use any automated tools and will perform only manual testing.
D.Do not include any specific limitation; the tester assumes responsibility for any outages.
AnswerB

Including a clause that explicitly prohibits denial-of-service attacks and rate-limits automated tools directly mitigates the client's concern about service disruption by setting a contractual maximum on traffic intensity. Rate limiting—such as capping packets per second or concurrent connections—ensures that vulnerability scanners and other automated tools cannot unintentionally overwhelm the web application or its backend infrastructure. This is the standard rules-of-engagement practice that balances thorough testing with operational safety, making it the correct choice.

Why this answer

It directly addresses the client's concern by prohibiting denial-of-service attacks and implementing rate-limiting on automated tools. Rate-limiting prevents overwhelming the web application with requests, which could cause resource exhaustion or unresponsiveness, while the prohibition on DoS ensures no intentional disruption occurs. This aligns with the rules of engagement (RoE) requirement to scope the test safely.

Exam trap

The trap here is that candidates confuse 'avoiding service disruption' with 'avoiding all automated tools' or 'avoiding all payloads,' when the correct approach is to control the intensity of testing through rate-limiting and explicit prohibitions on disruptive techniques like DoS.

How to eliminate wrong answers

Option A is wrong because ACK scans are a type of port scan that can still cause service disruption if sent at high rates or to vulnerable services, and the statement 'never send data payloads' is overly restrictive and irrelevant to preventing crashes—many safe techniques (e.g., SQL injection payloads) require data but can be rate-limited. Option C is wrong because it unnecessarily bans all automated tools, which would severely limit the test's effectiveness; manual testing alone cannot efficiently cover a large web application, and automated tools can be safely used with rate-limiting and proper configuration.

466
Multi-Selectmedium

Which TWO of the following are appropriate ways to handle sensitive data discovered during a penetration test when producing the final report? (Select TWO.)

Select 2 answers
A.Include the raw sensitive data in an appendix with restricted distribution.
B.Encrypt the report with a strong password and email it to all stakeholders.
C.Label the entire report as 'Sensitive' and leave data unaltered.
D.Securely delete any copies of sensitive data after the report is delivered.
E.Redact or mask the sensitive data in the report.
AnswersD, E

Secure deletion after delivery operationalizes data minimization: once stakeholders have the sanitized report, retaining raw sensitive data only increases the risk of exposure and conflicts with retention policies. Methods like cryptographic erasure, secure overwrite, or physical destruction make recovery computationally infeasible, ensuring the data cannot later be extracted from old disks, backups, or cloud snapshots. This is a post-engagement control that aligns with the principle that no more sensitive data should exist than is absolutely necessary.

Why this answer

Option E is correct because redacting or masking sensitive data (e.g., replacing credit card numbers with tokens or showing only the last four digits) preserves the finding's evidentiary value while preventing unnecessary exposure of PII, credentials, or other confidential information to report readers. Option D is correct because once the engagement ends and the report is delivered, retaining raw copies of sensitive data increases the attack surface and violates data-minimization principles; securely deleting them (e.g., using cryptographic erasure or tools like shred/secure wipe) limits liability and complies with privacy regulations. Option A is not appropriate because including raw sensitive data, even in a restricted appendix, still creates a persistent exposure risk and is generally discouraged in favor of redaction.

Option B is wrong because emailing an encrypted report to all stakeholders distributes sensitive material too broadly and email is not a secure delivery channel for such data. Option C is wrong because labeling the report 'Sensitive' without altering the data does nothing to reduce the actual exposure of the sensitive information.

467
MCQeasy

Which section of a penetration testing report should include screenshots, affected systems, and remediation steps?

A.Technical findings
B.Scope and methodology
C.Appendices
D.Executive summary
AnswerA

Technical findings document the evidence and detail: each vulnerability's affected hosts, reproduction screenshots, and specific remediation guidance. This satisfies the stem's requirement for all three elements in one section, unlike the executive summary, which stays high-level and omits screenshots and per-system remediation.

Why this answer

The technical findings section is where the penetration tester documents each discovered vulnerability with supporting evidence — screenshots, affected hostnames/IPs, reproduction steps, and specific remediation guidance. This is the actionable core of the report that the client's engineers use to fix issues.

Exam trap

PT0-003 often tests the confusion between the executive summary (business-level, no technical detail) and technical findings (evidence and remediation), so candidates pick the executive summary because it sounds comprehensive.

How to eliminate wrong answers

Option B is wrong because scope and methodology describes what was tested, when, and how (rules of engagement, tools, limitations), not the findings themselves. Option C is wrong because appendices hold supplementary raw data (tool output, logs, scan exports) that supports but does not replace the findings narrative. Option D is wrong because the executive summary is a non-technical overview for leadership that summarizes risk posture without screenshots or detailed remediation steps.

468
MCQmedium

A penetration tester is recommending remediation for a critical vulnerability. Which of the following is the best example of a specific, actionable remediation step?

A.Apply security patches.
B.Upgrade Apache from version 2.4.49 to 2.4.51.
C.Update the software to the latest version.
D.Fix the vulnerability.
AnswerB

This is the correct, specific remediation because it precisely names the vulnerable software (Apache HTTP Server), the affected version (2.4.49), and the exact fixed version (2.4.51). Upgrading from 2.4.49 to 2.4.51 directly addresses path traversal and remote code execution vulnerabilities tracked as CVE-2021-41773 and CVE-2021-42013. This concrete instruction is testable, verifiable, and provides clear guidance for the client's system administration team.

Why this answer

Effective remediation should be specific, including exact versions or commands.

469
MCQeasy

A penetration tester is preparing the executive summary of a report for a client's board of directors. Which of the following metrics would be MOST valuable for this audience to understand the overall security posture?

A.The exact CVSS score for each vulnerability found
B.A heat map showing the number of vulnerabilities by severity (Critical, High, Medium, Low)
C.A detailed list of commands used during exploitation
D.The names of the operating systems and applications that were tested
AnswerB

A heat map visually encodes severity distribution—typically using color intensity or a matrix with rows like Critical, High, Medium, and Low—so readers can instantly grasp whether the environment is mostly green or dominated by red. It aligns with common executive risk-reporting practices and supports trend comparisons against prior assessments. For non-technical stakeholders, this is far more effective than a table of CVSS vectors because it translates technical severity into a quick, memorable snapshot of the organization's security posture.

Why this answer

The board of directors needs a high-level, risk-based overview of the security posture, not technical details. A heat map with vulnerability counts by severity (Critical, High, Medium, Low) provides an immediate visual representation of risk distribution, enabling strategic decisions without requiring technical expertise. This aligns with the PT0-002 objective of tailoring reporting to the audience.

Exam trap

The trap here is that candidates may think exact CVSS scores (Option A) are more precise and therefore more valuable, but the board needs actionable risk summaries, not technical precision.

How to eliminate wrong answers

Option A is wrong because exact CVSS scores (e.g., 7.5) are too granular for a board audience; they require context and are better suited for technical remediation teams. Option C is wrong because a detailed list of commands used during exploitation is operational data for technical staff, not strategic information for executives, and would obscure the overall risk picture.

470
Multi-Selecthard

A penetration tester is scoping a test for a client that uses a hybrid identity system. The client wants to ensure that the test does not affect production authentication. Which TWO actions should the tester recommend?

Select 2 answers
A.Test using non-production accounts
B.Conduct testing during off-peak hours
C.Use a separate domain for testing
D.Perform password spraying against all users
E.Disable MFA for test accounts
AnswersA, C

Using non-production accounts is the correct scoping choice because it creates synthetic identities that exist only in the test environment, preventing test traffic from contaminating production user data or triggering lockouts on real accounts. These accounts can be provisioned with known credentials in a dedicated test OU or group, enabling clean credential rotation and teardown after the engagement without touching production identity stores.

Why this answer

Using non-production accounts and a separate test domain isolate the test from production identity systems. Password spraying against all users could disrupt accounts, and disabling MFA may weaken security. Off-peak scheduling reduces impact but does not prevent direct interaction with production systems.

471
MCQeasy

A penetration tester is preparing a deliverable for a client. Which of the following should be included in the final report?

A.Executive summary, technical findings, and remediation guidance
B.The tester's personal notes and observations
C.Only the technical findings
D.Only the executive summary
AnswerA

The standard penetration test deliverable comprises an executive summary for non-technical stakeholders, detailed technical findings for security engineers, and remediation guidance to address identified vulnerabilities. This structure ensures every audience—from management to IT—receives actionable information tailored to their role. It aligns with industry best practices such as the PTES report format and enables the client to prioritize and fix issues effectively.

Why this answer

A standard penetration testing report includes an executive summary, technical findings, and remediation guidance.

472
MCQeasy

A penetration tester is performing a network attack and wants to intercept traffic between two hosts on the same local network. Which technique should the tester use to redirect traffic through their machine?

A.DNS poisoning
B.LLMNR poisoning
C.ARP spoofing
D.SSL stripping
AnswerC

ARP spoofing is the correct technique for intercepting traffic on a local Ethernet network because ARP is stateless and lacks authentication. An attacker sends forged ARP replies to the target host and the default gateway, mapping the attacker's MAC address to the gateway's IP (and vice versa), which causes the target to send its frames to the attacker rather than directly to the gateway. This creates a man-in-the-middle position at the data-link layer, allowing the attacker to sniff, modify, or drop the traffic, and it is the foundational step for many subsequent attacks like session hijacking or credential theft.

Why this answer

ARP spoofing allows an attacker to associate their MAC address with the IP address of another host, intercepting traffic intended for that host.

473
MCQeasy

A penetration tester is conducting an internal assessment of a company's web application. The application provides a file upload feature that accepts images but does not validate the file type on the server side. The tester has identified that the application runs on an Apache server with PHP support. The tester wants to execute a command on the server to establish a reverse shell. The tester has a Linux client and has already crafted a PHP reverse shell payload. The tester has also verified that outbound connections are allowed from the server. After uploading the malicious PHP file, the tester attempts to access it via a browser but receives a 404 error. The tester suspects the uploaded file may have been renamed or moved. Which of the following steps should the tester take next to achieve code execution?

A.Modify the PHP payload to avoid detection by antivirus on the server.
B.Use a directory listing tool to scan for hidden files in the upload directory.
C.Re-upload the file with a different extension like .php5 or .phtml.
D.Check the web server access and error logs to identify the actual path where the file was saved.
AnswerD

Web server access and error logs are the definitive source for reconstructing the actual stored path: the access log shows the HTTP GET/POST requests and response codes, while the error log may show 'File does not exist' messages with the full filesystem path. If the upload handler renamed the file, moved it to a different directory (e.g., /uploads/avatars/), or appended a timestamp, those logs will reveal the effective URL that was served. A 404 in the application response corresponds to a specific resource in the logs, letting you deduce the renamed filename and directly request it to trigger the payload.

Why this answer

The correct option is D: check the web server access and error logs to identify the actual path where the file was saved. Since the upload succeeded but the tester gets a 404, the most likely cause is that the file was renamed or relocated by the application, and Apache's access/error logs will reveal the real request path and any 404 entries pointing to the actual stored location. This is a reconnaissance step that directly addresses the suspected rename/move before attempting further exploitation.

Option A is irrelevant because antivirus detection would not produce a 404, and no AV behavior has been indicated. Option B is unlikely to help because the file is not hidden but stored under a different name or directory, and directory listing is often disabled. Option C is unnecessary because PHP support is already confirmed and the issue is path/name, not extension handling.

474
MCQmedium

After gaining initial access to a Windows host, you want to escalate privileges by exploiting a service that runs as SYSTEM but has an unquoted service path. What is the attack vector?

A.Token impersonation
B.AlwaysInstallElevated
C.Unquoted service path
D.DLL hijacking
AnswerC

When the ImagePath value of a Windows service is an unquoted string containing spaces, the Service Control Manager (or CreateProcess) interprets each space as a potential path separator and tries successive prefixes as executable candidates. For example, 'C:\Program Files\MyApp\Service.exe' leads Windows to attempt 'C:\Program.exe' and 'C:\Program Files\MyApp\Service.exe' in order. If an attacker can write to a directory earlier in the path, they can place a malicious binary named to match a truncated component, such as 'My.exe' or 'Program.exe', which then executes with the service's privilege level when the service starts. This is the exact privilege escalation mechanism caused by an unquoted service path.

Why this answer

Unquoted service path vulnerability allows an attacker to place an executable in a path that the service will execute due to ambiguous path parsing.

475
MCQhard

A penetration tester is performing active reconnaissance on a target network and wants to enumerate SNMP devices to gather system information. The tester uses snmpwalk with a common community string. Which community string is most likely to provide read-write access if misconfigured?

A.private
B.public
C.internal
D.manager
AnswerA

'private' is the default read-write community string in SNMP v1 and v2c, granting full write access to the device's MIB tree. With this string, an attacker can alter configuration parameters, change routing tables, disable interfaces, or even cause a denial of service by modifying system settings. In active reconnaissance, discovering 'private' is a high-severity finding because it signals complete administrative control over the SNMP-managed device, which is exactly why it is the correct answer here.

Why this answer

SNMP community strings are like passwords. 'public' is the default read-only community string, 'private' is the default read-write community string. 'internal' and 'manager' are less common defaults. The tester should try 'private' for potential read-write access.

476
MCQeasy

During an internal penetration test, a tester wants to capture NTLMv2 hashes by poisoning LLMNR and NBT-NS traffic. Which tool should the tester use?

A.ntlmrelayx
B.Bettercap
C.Hashcat
D.Responder
AnswerD

Responder operates by listening for Link-Local Multicast Name Resolution (LLMNR) and NetBIOS Name Service (NBT-NS) queries, then spoofing responses to redirect authentication attempts to the attacker’s machine, thereby capturing NTLMv2 challenge-response hashes. This directly satisfies the stem’s requirement to poison those specific protocols during an internal test, unlike tools that target different layers or authentication mechanisms.

Why this answer

Responder is specifically designed to respond to LLMNR and NBT-NS queries and capture NetNTLM hashes.

477
MCQmedium

After a penetration test, the client's development team requires detailed, step-by-step instructions to reproduce a SQL injection vulnerability found in the user login functionality. In which section of the standard penetration testing report should this information be included?

A.Executive Summary
B.Technical Findings
C.Recommendations
D.Risk Rating
AnswerB

Technical Findings is the section that provides the exhaustive vulnerability catalogue, including affected endpoints, exact reproduction steps, proof-of-concept commands, and observed technical impact. This is precisely what a development team requires to independently recreate and understand the flaw before implementing a fix. It is written for a technical audience and is the standard location for disclosure of exploit mechanics.

Why this answer

The Technical Findings section is the correct location because it provides detailed, step-by-step reproduction steps for vulnerabilities, including the exact SQL injection payloads, input fields, and HTTP request parameters used to exploit the login functionality. This section is intended for technical audiences (e.g., developers) who need to understand and remediate the issue, not for high-level summaries or general advice.

Exam trap

The trap here is that candidates often confuse the purpose of the Recommendations section, thinking it should include step-by-step reproduction steps, when in fact it only contains high-level remediation guidance, while the Technical Findings section is the proper place for detailed exploitation procedures.

How to eliminate wrong answers

Option A is wrong because the Executive Summary is a high-level overview for non-technical stakeholders, containing business impact, risk ratings, and strategic recommendations, not step-by-step technical reproduction instructions. Option C is wrong because the Recommendations section provides high-level remediation advice (e.g., 'use parameterized queries') but does not include the detailed, step-by-step reproduction steps needed by the development team to verify and fix the specific vulnerability.

478
MCQhard

A penetration tester has discovered a local file inclusion (LFI) vulnerability in a PHP web application. The vulnerable code uses the following pattern: include($_GET['page']);. The application runs on a Linux server with Apache and PHP. The tester wants to achieve remote code execution (RCE). Which technique is most likely to succeed given this LFI?

A.Use the php://input wrapper and send PHP code in the POST body.
B.Use the file:// wrapper to read sensitive files like /etc/passwd.
C.Use the data:// wrapper with a base64-encoded PHP payload.
D.Set allow_url_include to On in php.ini via the LFI.
AnswerA

php://input reads the raw POST data. When included, the PHP interpreter will execute any code contained in the POST body. This is a common technique to turn LFI into RCE, and it does not require allow_url_include to be enabled.

Why this answer

The correct technique is to use the php://input wrapper because it allows the attacker to pass arbitrary PHP code in the HTTP POST body, which the include() function will execute as PHP. Since the vulnerable code directly includes user input without sanitization, the php://input stream reads the raw POST data and processes it as a PHP script, achieving remote code execution.

Exam trap

The trap here is that candidates often assume data:// is the most direct way to inject code, but they overlook that php://input is more reliable because it does not require allow_url_include to be enabled, which is a common security hardening measure.

How to eliminate wrong answers

Option B is wrong because the file:// wrapper only reads local files and does not allow code execution; it would only read sensitive files like /etc/passwd, not achieve RCE. Option C is wrong because while the data:// wrapper can execute PHP code if the allow_url_include directive is enabled, it is often disabled by default in modern PHP configurations, making it less reliable than php://input, which is more commonly available and does not require allow_url_include to be enabled for this purpose.

479
MCQmedium

During a penetration test, the tester performs a SYN scan with Nmap on a target network. The results show that port 443 is open on a web server. The tester then runs a service version detection scan and discovers the server is running Apache 2.4.41. Which Nmap flags were used in sequence?

A.nmap -A then nmap -O
B.nmap -sS then nmap -sV
C.nmap -sV then nmap -sS
D.nmap -sS then nmap -sC
AnswerB

This is the correct sequential approach: -sS performs a half-open SYN scan to quickly and quietly identify which TCP ports are open, while -sV then sends targeted service probes and performs banner grabs on those exact open ports to enumerate application versions. Separating discovery from version detection allows the tester to control scope and avoid wasting time probing closed or filtered ports. This two-phase methodology is a foundational best practice in network service enumeration.

Why this answer

The tester first performed a SYN scan with -sS to identify open ports, then used -sV for service version detection. -sC runs default scripts, -O is for OS detection, and -A enables aggressive scanning (includes OS detection, version detection, script scanning, and traceroute).

480
Multi-Selecthard

Which THREE of the following are important elements to include in the remediation section of a penetration test report? (Select THREE.)

Select 3 answers
A.Priority levels (e.g., Critical, High, Medium) based on risk.
B.A list of all external parties notified about the vulnerabilities.
C.Step-by-step instructions to fix each vulnerability.
D.CVE identifiers or references to industry best practices.
E.Detailed timeline of when each finding was discovered.
AnswersA, C, D

Priority levels are a core component of a remediation plan because they translate technical severity into business risk. By classifying each vulnerability as Critical, High, Medium, or Low (often derived from CVSS scores, asset criticality, and exploitability), the client can focus on the most urgent issues first and allocate resources efficiently. Without clear prioritization, the client may waste effort on low-impact flaws while critical exposures remain unpatched.

Why this answer

Options A, C, and D are correct. Remediation should include specific steps, reference to industry standards, and priority based on risk. Option B is not a standard part of remediation; it's for methodology.

Option E is about disclosure, not remediation.

481
MCQeasy

Which of the following is the primary audience for the executive summary of a penetration test report?

A.Executives and management
B.Developers
C.External auditors
D.System administrators
AnswerA

Executives and management require the executive summary to make informed risk-acceptance or remediation-budget decisions without reviewing technical exploit chains or low-level findings. This satisfies the stem’s constraint that the primary audience must be the stakeholder who needs a high-level, non-technical overview of business impact, not the technical team that would implement fixes. The summary therefore prioritises strategic risk posture over operational detail.

Why this answer

The executive summary is written for non-technical stakeholders such as executives and managers, using business language and focusing on risk and strategic recommendations.

482
Multi-Selectmedium

A penetration testing firm is scoping a network penetration test for a client. The client has provided a list of IP ranges and subnets. Which TWO of the following should the tester consider when defining the scope?

Select 2 answers
A.Identify any third-party hosted services within the provided IP ranges and obtain explicit permission
B.Define which IP ranges are out of scope and document them
C.All IP addresses owned by the client are in scope
D.Test all IP addresses regardless of ownership to ensure complete coverage
E.Include all subnets that are routable from the internet
AnswersA, B

When an IP range is provided for a network penetration test, it may contain addresses owned by the client but operated by third parties, such as cloud providers, CDNs, or SaaS vendors. Testing those systems requires separate written authorization from the actual owner, because the client's permission does not extend to third-party infrastructure. You must therefore proactively identify any third-party hosted services within the provided ranges and obtain explicit permission before active testing to stay within legal and ethical boundaries.

Why this answer

Scoping must distinguish in-scope vs out-of-scope assets and address third-party services that require permission.

483
MCQhard

A penetration tester is enumerating SMB shares on a Windows host during an internal assessment. The tester has valid domain credentials for a low-privileged user and wants to list shares and identify accessible files without triggering account lockouts. Which tool and approach is most appropriate?

A.Use smbclient with the -L option and the low-privileged credentials to list shares, then connect to accessible shares
B.Run Nmap with the smb-enum-shares script using the guest account
C.Use enum4linux with the -a option to perform all enumeration checks without credentials
D.Run a brute-force SMB login attack with Medusa using a password list against the low-privileged account
AnswerA

smbclient with -L lists shares using provided credentials and does not perform password guessing, so it will not cause lockouts. It allows the tester to connect to shares the low-privileged user can access and browse files. This approach respects the credential constraint and avoids brute-force behavior that could lock the account.

Why this answer

smbclient with the -L option uses the supplied low-privileged credentials to list shares without password guessing, avoiding lockouts. It then allows connecting to shares the user can access to browse files. Brute-forcing is unnecessary and risky, unauthenticated enumeration may be blocked, and using the guest account ignores available valid credentials.

Exam trap

The trap here is assuming brute-forcing or unauthenticated enumeration is needed, when valid low-privileged credentials already allow safe, authenticated SMB share enumeration.

484
MCQhard

A penetration tester is writing a report and needs to assign a custom severity rating for a vulnerability that has high business impact but low likelihood of exploitation. Using a custom severity based on business context (impact + likelihood), which rating is most appropriate?

A.Critical
B.High
C.Medium
D.Low
AnswerC

The combination of high impact and low likelihood yields a Medium rating because the expected loss is a product of both factors. While a successful exploit would cause significant damage, its rarity or required conditions reduce the urgency of remediation. This is consistent with standard likelihood-impact scoring models, where one high and one low factor balances to an intermediate severity.

Why this answer

High impact but low likelihood typically results in a medium severity when combining both factors.

485
Multi-Selecteasy

Which THREE of the following are common components of a pre-engagement agreement between a penetration tester and a client?

Select 3 answers
A.List of all employee passwords
B.Rules of Engagement (RoE)
C.Statement of Work (SOW)
D.Non-Disclosure Agreement (NDA)
E.Full source code of the target application
AnswersB, C, D

RoE is a critical pre-engagement document that defines the authorized testing boundaries, including allowed techniques, testing windows, IP ranges, emergency contacts, and prohibited actions. It establishes the legal and operational limits for the penetration test, such as whether social engineering or denial-of-service attacks are permitted. This ensures both client and tester agree on acceptable behavior, preventing scope creep and misunderstandings.

Why this answer

Pre-engagement typically includes SOW, RoE, NDA, permission letters, emergency contacts, and communication plans.

486
MCQeasy

After completing a penetration test, you present the findings to the client's technical team. During the debrief meeting, the technical lead argues that one of the identified vulnerabilities is not exploitable in their environment and should be removed from the report. The evidence you have shows it is exploitable. What is the BEST response?

A.Immediately remove the finding to maintain good client relations
B.Challenge the technical lead and insist it stays
C.Document the disagreement and include both perspectives in the report
D.Offer to demonstrate the exploit to confirm
AnswerC

Documenting the disagreement and including both perspectives in the report is the industry-standard practice because it maintains report integrity and gives the client an honest view of analytical uncertainty. The client's risk management team benefits from seeing the technical lead's and tester's differing interpretations, allowing them to make an informed decision about mitigation priorities. This approach aligns with professional guidelines that mandate transparency in pentest deliverables, ensuring that no data is undisclosed due to internal conflict. It also protects the testing team from allegations of bias or negligence, as the report explicitly acknowledges the dissenting view and the reasoning behind it.

Why this answer

Option C is correct because a penetration tester's report must remain factually accurate while also capturing the client's risk context, so documenting the disagreement and presenting both the tester's evidence and the client's position preserves integrity and gives decision-makers full information. Since the evidence shows the vulnerability is exploitable, removing it (A) would falsify the assessment, and merely insisting it stays (B) ignores legitimate environmental context the client may have. Option D, offering a live demonstration, can be useful for validation but is not the best primary response because it does not itself resolve how the finding and the dispute are recorded in the final deliverable.

487
MCQeasy

A tester has exploited a Linux system and gained a low-privilege shell. The tester runs 'sudo -l' and sees that the current user can run /usr/bin/find as root without a password. Which privilege escalation technique should the tester use?

A.SUID binary exploitation
B.PATH manipulation
C.Kernel exploit
D.GTFOBins technique for find
AnswerD

This is a classic GTFOBins technique: when `sudo` permits a user to run `find` as root, the `-exec` or `-execdir` actions can execute arbitrary commands with elevated privileges. For example, `sudo find . -exec /bin/sh \;` spawns a root shell because `find` runs as root under sudo. GTFOBins enumerates such built-in command-execution mechanisms for common binaries, making this the correct method to escalate from the low-privileged user.

Why this answer

The find command can be used to execute other commands via its -exec parameter, allowing privilege escalation.

488
MCQhard

During a penetration test, the tester discovers evidence that an external attacker is actively exploiting a vulnerability in the client's environment. Which of the following is the MOST appropriate action?

A.Document the evidence and ignore it
B.Attempt to block the attacker's activities
C.Immediately notify the client and stop testing
D.Continue testing and include the finding in the final report
AnswerC

When evidence indicates an ongoing attack, the tester must immediately stop testing to avoid compounding the incident and notify the client so they can activate their incident response plan. Continuing to test could interfere with forensic preservation or accidentally interact with the attacker's C2 infrastructure, so halting all intrusive actions and delivering a clear, time-sensitive briefing is the only defensible course.

Why this answer

If there is evidence of a live attack or criminal activity, the tester should stop testing and immediately notify the client so they can take appropriate action.

489
MCQeasy

When writing the executive summary of a penetration test report, which of the following is the most appropriate language to use?

A.A list of all vulnerabilities sorted by CVSS score without context.
B.Raw output from scanning tools and network packet captures.
C.Business-oriented language focusing on risk, impact, and high-level recommendations.
D.Detailed technical descriptions of each vulnerability and exploit code used.
AnswerC

The executive summary is written for decision-makers who care about exposure, not exploit syntax; it translates technical test results into business risk terms such as potential financial loss, regulatory fines, IP theft, or operational downtime, and pairs each high-level finding with a recommended strategic direction. By focusing on risk, impact, and high-level recommendations, it gives executives the context they need to authorize remediation efforts and aligns the pentest's outcome with organizational priorities.

Why this answer

The executive summary should be written in business language, avoiding technical jargon, to convey the overall risk and strategic recommendations to non-technical stakeholders.

490
MCQeasy

A penetration tester wants to crack NTLM hashes captured during an internal test. Which hashcat mode should the tester use for NTLM hashes?

A.0
B.22000
C.1000
D.13100
AnswerC

Mode 1000 is the correct Hashcat mode for NTLM hashes, which are computed as MD4(UTF-16LE(password)). This mode directly tells Hashcat to treat the input as an NTLM hash and attempt password recovery using the correct algorithm, making it the only valid choice among the listed options for cracking captured NTLM hashes.

Why this answer

Hashcat mode 1000 is specifically for NTLM hashes.

491
MCQeasy

A penetration tester discovers a critical vulnerability on a client's web server and wants to communicate it immediately. Which of the following is the most appropriate action?

A.Notify the client's point of contact immediately.
B.Include the finding in the report without prior communication.
C.Wait until the final report is complete.
D.Post the findings on a public forum for disclosure.
AnswerA

Immediate notification of a critical vulnerability is mandated by responsible disclosure and most penetration testing contracts because the window of exploitability is open right now. Escalating to the client's point of contact by phone or secure message enables incident response, temporary mitigation, or emergency patching before attackers can leverage the flaw. This action also preserves the tester's duty of care and ensures the client can make informed risk decisions without waiting for formal documentation.

Why this answer

Immediate notification of critical findings ensures the client can take urgent steps to mitigate risk.

492
MCQmedium

A penetration tester is writing a Python script to send a crafted TCP packet to a target. Which Python library should the tester use for low-level packet crafting and injection?

A.requests
B.impacket
C.scapy
D.socket
AnswerC

Scapy lets the tester construct and inject raw TCP packets at layer 3/4, defining flags, sequence numbers and payloads directly. Socket alone lacks this crafting depth, and requests operates at HTTP level, so scapy fits low-level packet manipulation.

Why this answer

Scapy is the correct choice because it is a powerful Python library specifically designed for low-level packet crafting, manipulation, and injection. It allows the tester to construct arbitrary TCP packets at the raw socket level, control individual flags, sequence numbers, and payloads, and send them directly over the wire using Layer 2 or Layer 3 sockets. This makes it ideal for tasks like SYN flooding, TCP handshake manipulation, or custom protocol fuzzing.

Exam trap

CompTIA often tests the distinction between high-level protocol libraries (requests, impacket) and low-level packet crafting tools (scapy), trapping candidates who confuse 'network scripting' with 'raw packet manipulation'.

How to eliminate wrong answers

Option A is wrong because the 'requests' library is a high-level HTTP client library used for sending and receiving HTTP requests; it operates at the application layer and cannot craft or inject raw TCP packets. Option B is wrong because 'impacket' is a collection of Python classes for working with network protocols, particularly SMB and Kerberos, but it is not designed for low-level packet crafting and injection; it focuses on protocol-level interactions rather than raw packet manipulation. Option D is wrong because the 'socket' library provides low-level networking interfaces (e.g., raw sockets) but lacks the high-level abstractions, protocol dissection, and packet-building utilities that Scapy offers; using raw sockets alone would require manually constructing all packet headers and handling checksums, which is error-prone and far less efficient.

493
MCQhard

A penetration tester is conducting a wireless assessment and needs to capture the four-way handshake to perform offline WPA cracking. Which tool is best suited for capturing the handshake?

A.aircrack-ng
B.aireplay-ng
C.Airmon-ng
D.airodump-ng
AnswerD

airodump-ng is the dedicated packet capture tool in the aircrack-ng suite, capable of placing the wireless interface into monitor mode and recording raw 802.11 frames to a pcap file. It actively hops channels, probes for access points, and lists associated clients, and it specifically captures the EAPOL four-way handshake frames when a client associates or reconnects. Its output is the direct input for aircrack-ng's offline cracking, making it the correct choice for this capture stage.

Why this answer

Airodump-ng (option D) is the correct tool for capturing the four-way handshake because it passively monitors wireless traffic and can save captured packets to a file (e.g., .cap or .pcap). The four-way handshake occurs during the WPA/WPA2 authentication process between a client and an access point, and airodump-ng's ability to filter on a specific channel and BSSID allows the tester to isolate and record the handshake frames for offline cracking.

Exam trap

The trap here is that candidates confuse airodump-ng (capture tool) with aircrack-ng (cracking tool) or aireplay-ng (injection tool), leading them to pick a tool that cannot actually capture the handshake.

How to eliminate wrong answers

Option A (aircrack-ng) is wrong because it is a WEP/WPA key cracking tool that uses captured handshake files, not a packet capture tool; it cannot capture the handshake itself. Option B (aireplay-ng) is wrong because it is used for packet injection and replay attacks (e.g., deauthentication attacks to force a client to reconnect), not for passively capturing the handshake. Option C (airmon-ng) is wrong because it is a utility to enable or disable monitor mode on a wireless interface, not a packet capture tool; it prepares the interface for capture but does not capture frames.

494
MCQeasy

During the scoping phase of a penetration test, a client wants to test a third-party API that is integral to their web application. However, they do not have permission from the third-party provider. Which of the following should the tester do first?

A.Proceed with testing the API but restrict the test to read-only operations
B.Exclude the third-party API from the scope and document the limitation
C.Contact the third-party provider directly to obtain permission
D.Include the API in the scope and note the legal risks in the report
AnswerB

Excluding the third-party API from the scope and documenting the limitation is the correct approach because the client cannot legally grant authorization for systems they do not own. The scoping document and rules of engagement must explicitly list out-of-scope assets, preventing any ambiguity during testing. This also creates a clear record that the client was informed of the limitation, which they can use to seek independent authorization or a separate contract with the API provider. Such documentation is essential for maintaining legal and professional defensibility of the penetration test.

Why this answer

Testing a third-party API without explicit permission from the provider violates legal and ethical boundaries, potentially constituting unauthorized access under laws like the Computer Fraud and Abuse Act (CFAA). The penetration tester must first document this limitation in the scope to ensure the client understands the risk and to maintain the test's legality. Proceeding without permission could lead to liability for both the tester and the client.

Exam trap

The trap here is that candidates may assume 'read-only' testing is safe or that direct contact with the third party is proactive, but the exam emphasizes that scope limitations must be documented and that the client, not the tester, is responsible for obtaining permissions.

How to eliminate wrong answers

Option A is wrong because restricting testing to read-only operations does not grant legal permission; any interaction with the third-party API without authorization, even read-only, can still be considered unauthorized access and may violate the provider's terms of service or applicable laws. Option C is wrong because the tester should not contact the third-party provider directly, as this is the client's responsibility; the tester lacks the contractual relationship to negotiate permissions and doing so could breach confidentiality or scope agreements.

495
MCQeasy

A penetration tester is reviewing a Bash script that contains the following command: 'openssl s_client -connect target:443 -servername target 2>/dev/null | openssl x509 -noout -text'. What is the primary purpose of this command?

A.Extract the SSL certificate in text form.
B.Perform a man-in-the-middle attack.
C.Test for weak cipher suites.
D.Verify the certificate's revocation status.
AnswerA

The command chain `openssl s_client -connect host:port -showcerts | openssl x509 -noout -text` establishes a real TLS connection to the specified server and pipes the server's presented certificate (or chain) into `x509 -text`, which decodes the DER-encoded fields and displays them in a human-readable, structured text format. This is a standard, quick way to inspect certificate details such as subject, issuer, validity period, and extensions.

Why this answer

The command uses `openssl s_client` to establish a TLS connection to `target:443` and then pipes the certificate output to `openssl x509 -noout -text`, which decodes and prints the certificate in human-readable text form. The primary purpose is to retrieve and display the SSL/TLS certificate details (e.g., issuer, subject, validity dates, SANs) for inspection, not to attack or test cipher suites.

Exam trap

The trap here is that candidates may confuse certificate retrieval with cipher suite testing or assume any use of `openssl s_client` implies an attack, when in fact the command is a standard diagnostic tool for inspecting certificate content.

How to eliminate wrong answers

Option B is wrong because the command does not intercept or modify traffic between two parties; it simply connects to the server and displays its certificate, which is a normal client operation, not a man-in-the-middle attack. Option C is wrong because testing for weak cipher suites requires specifying cipher lists or using tools like `sslscan` or `nmap --script ssl-enum-ciphers`; this command only retrieves the certificate and does not enumerate or test cipher negotiation.

496
MCQmedium

A penetration tester is conducting a vulnerability assessment of a Linux web server. The tester runs a scan with Nikto and receives a finding indicating that the server is potentially vulnerable to a cross-site scripting (XSS) attack on a specific parameter. To confirm the finding, the tester wants to manually verify the XSS vulnerability. Which action should the tester take?

A.Use a SQL injection tool like sqlmap to test the parameter for injection flaws
B.Run a full port scan with Nmap to check for open ports related to the web service
C.Perform a directory brute-force with Gobuster to find hidden files
D.Use a web browser to inject a benign script payload into the parameter and observe if it executes
AnswerD

Manual verification of XSS involves injecting a harmless script, such as <script>alert(1)</script>, into the vulnerable parameter and checking if the browser executes it. This confirms the vulnerability without causing harm. In this scenario, the tester should use a browser or proxy to inject the payload and observe the response. This is the standard method to validate XSS findings.

Why this answer

To confirm an XSS vulnerability, the tester must inject a script payload into the vulnerable parameter and observe if it executes in the context of the application. This manual verification is crucial because automated scanners like Nikto can produce false positives. Using a browser or an intercepting proxy to inject a benign alert script is the most direct and reliable method.

It confirms that the application fails to sanitize input and that the payload is reflected or stored and executed.

Exam trap

The trap here is relying on other automated tools or scans to confirm XSS, when manual injection with a harmless payload is the definitive verification method.

497
MCQeasy

A penetration tester is using a vulnerability scanner that reports a 'Critical' severity for an 'SMBv1 vulnerability' on a Windows server. Which of the following is the correct remediation recommendation?

A.Apply the latest Windows security patches
B.Disable SMBv1 on the server
C.Enable SMB signing
D.Enable SMB encryption
AnswerB

Disabling SMBv1 on the server completely eliminates the protocol's attack surface, stopping all SMBv1-specific transmission methods including EternalBlue-style remote code execution and pass-the-hash attacks. This aligns with Microsoft's guidance to remove SMBv1 unless there is an explicit legacy compatibility need, making it the most effective and durable remediation for a scanner finding that marks SMBv1 as enabled.

Why this answer

The correct remediation for an SMBv1 vulnerability is to disable SMBv1 on the server. SMBv1 is a legacy protocol that lacks modern security features and is known to be exploited by malware like EternalBlue (used in WannaCry). Disabling SMBv1 eliminates the attack surface without affecting SMBv2 or SMBv3, which are secure and still functional.

Exam trap

The trap here is that candidates assume patching (Option A) is sufficient for all vulnerabilities, but for SMBv1, the protocol itself is deprecated and must be disabled rather than just patched.

How to eliminate wrong answers

Option A is wrong because applying the latest Windows security patches only addresses specific CVEs but does not remove the inherently insecure SMBv1 protocol; patches can be bypassed or incomplete, whereas disabling SMBv1 is the definitive fix. Option C is wrong because enabling SMB signing provides integrity and authentication for SMB traffic but does not mitigate the SMBv1 protocol's fundamental vulnerabilities, such as buffer overflow exploits. Option D is wrong because enabling SMB encryption protects data in transit but does not disable or patch the SMBv1 protocol itself, leaving the server still vulnerable to SMBv1-specific attacks.

498
MCQhard

During an internal test, a penetration tester discovers a web application that is vulnerable to Server-Side Template Injection (SSTI). The application uses a template engine that does not sandbox user input. Which of the following payloads would be MOST effective to achieve remote code execution on the server?

A.{{7*7}}
B.<script>alert('xss')</script>
C.${7*7}
D.{{config.__class__.__init__.__globals__['os'].popen('id').read()}}
AnswerD

This is the canonical Jinja2 SSTI-to-RCE payload. It chains Python object introspection: config (a Jinja2 global) → __class__ (its class) → __init__ (constructor) → __globals__ (dictionary of global variables) to reach the 'os' module, then calls popen('id').read() to execute a system command and return its output. This abuses the fact that Jinja2 allows attribute access and method calls on Python objects without proper sandboxing, granting full server-side code execution.

Why this answer

It exploits Python's object model to access the `os` module via `__class__.__init__.__globals__`, bypassing the template engine's lack of sandboxing. This allows the attacker to execute arbitrary system commands like `id` on the server, achieving remote code execution (RCE). The payload is specific to Jinja2 or similar Python-based template engines that expose built-in objects.

Exam trap

The trap here is that candidates confuse SSTI with simple template injection tests (like `{{7*7}}`) or XSS, failing to recognize that the correct payload must chain object introspection to access system commands for RCE.

How to eliminate wrong answers

Option A is wrong because `{{7*7}}` is a simple math expression that only tests for SSTI vulnerability (returning 49) but does not achieve RCE. Option B is wrong because `<script>alert('xss')</script>` is a Cross-Site Scripting (XSS) payload, not an SSTI payload, and it targets client-side execution, not server-side RCE. Option C is wrong because `${7*7}` is a Java Expression Language (EL) injection syntax, not applicable to Python-based template engines; it would not execute in a Jinja2 context and does not lead to RCE.

499
MCQhard

During a penetration test, a tester gains access to a Linux system and runs 'sudo -l', which reveals that the user can run /usr/bin/python with root privileges without a password. Which resource should the tester consult to find a method to escalate privileges using this configuration?

A.PayloadsAllTheThings
B.GTFOBins
C.HackTricks
D.Exploit-DB
AnswerB

GTFOBins is the correct resource because it is a curated catalog of Unix binaries that can be abused to bypass local security restrictions, escalate privileges, or spawn shells — exactly what you need after running `sudo -l` and seeing a non-standard binary. It provides specific command snippets for each binary, categorized by functions like 'sudo', 'suid', and 'capabilities', so you can quickly match the binary you have access to with a privilege escalation vector. For a Linux penetration test, GTFOBins is the definitive reference for converting a misconfigured sudo entry into a root shell.

Why this answer

GTFOBins is a curated list of Unix binaries that can be used to bypass local security restrictions. It provides techniques for privilege escalation using binaries like python. GTFOBins is specifically for Unix privilege escalation.

500
MCQmedium

A penetration tester is analyzing a Python script that uses the 'subprocess' module to execute shell commands. The tester notices that the script passes user-supplied input directly to the shell without any sanitization or validation. Which vulnerability class is most likely present in this script?

A.Command injection
B.SQL injection
C.Path traversal
D.Buffer overflow
AnswerA

This is command injection because the script passes unsanitized user input directly to a shell interpreter. When subprocess is called with shell=True or os.system, metacharacters such as semicolons, ampersands, or pipes allow an attacker to terminate the intended command and chain arbitrary OS commands. The subprocess module's shell=True feature is a classic sink for this vulnerability, and the lack of input validation or escaping makes it exploitable for remote code execution.

Why this answer

The script uses the `subprocess` module to execute shell commands with user-supplied input passed directly to the shell without sanitization. This allows an attacker to inject arbitrary shell metacharacters (e.g., `;`, `|`, `&&`) to execute unintended commands, which is the classic definition of command injection. The vulnerability arises because the input is concatenated into a command string rather than passed as a list of arguments, bypassing the shell's argument separation.

Exam trap

The trap here is that candidates may confuse command injection with SQL injection because both involve untrusted input, but the key differentiator is the execution context—shell commands versus database queries—and the specific module (`subprocess`) indicates shell execution, not database interaction.

How to eliminate wrong answers

Option B is wrong because SQL injection requires the input to be passed to a database query (e.g., via SQL statements), not to a shell command via the `subprocess` module. Option C is wrong because path traversal involves manipulating file paths to access restricted directories (e.g., using `../`), which is unrelated to executing arbitrary shell commands through the `subprocess` module.

501
MCQeasy

A penetration tester wants to perform DNS brute-force enumeration to discover subdomains of a target domain. Which tool is specifically designed for this purpose?

A.nmap
B.dnsrecon
C.Wireshark
D.Hydra
AnswerB

dnsrecon is a dedicated DNS enumeration tool with a built-in brute-force module that cycles through a wordlist appended to the target domain to discover subdomains. It supports multiple record types (A, AAAA, MX, TXT, etc.), recursion, and threads, and can output results in various formats. This purpose-built design makes it the ideal choice for DNS brute-forcing among the listed options.

Why this answer

B is correct because dnsrecon is a specialized DNS enumeration tool that includes a brute-force mode for discovering subdomains. It uses a wordlist to query DNS servers for common subdomain names, leveraging the DNS protocol's inherent structure to map out a target's domain hierarchy without relying on zone transfers.

Exam trap

The trap here is that candidates often confuse nmap's general DNS script (e.g., dns-brute.nse) with a dedicated tool, but the question specifically asks for a tool 'designed for this purpose,' and dnsrecon is purpose-built for DNS enumeration, whereas nmap's script is an add-on.

How to eliminate wrong answers

Option A is wrong because nmap is a network scanning tool focused on port discovery and service fingerprinting, not DNS-specific brute-force enumeration; while it can perform DNS queries via scripts, it lacks the dedicated subdomain brute-force functionality of dnsrecon. Option C is wrong because Wireshark is a packet analyzer used for capturing and inspecting network traffic, not for actively generating DNS queries to enumerate subdomains.

502
MCQmedium

A penetration tester has completed the test and is preparing the final report. The client requested a risk rating for each vulnerability. Which of the following frameworks is MOST commonly used to standardize vulnerability severity ratings in penetration testing reports?

A.OWASP Top 10
B.CVSS
C.CVE
D.NIST SP 800-115
AnswerB

The Common Vulnerability Scoring System (CVSS) is the correct choice because it provides a standardized, repeatable methodology for assigning severity scores to individual vulnerabilities. CVSS uses metric groups (base, temporal, and environmental) with vectors such as attack vector, attack complexity, privileges required, user interaction, and impact to produce a numerical score from 0.0 to 10.0. This allows pentesters to communicate vulnerability severity consistently and objectively, enabling stakeholders to prioritize remediation efforts across different systems and findings.

Why this answer

CVSS (Common Vulnerability Scoring System) is the industry-standard framework for assigning numeric severity scores (0-10) to vulnerabilities based on metrics like attack vector, complexity, and impact. Penetration testers use CVSS scores to provide consistent, quantitative risk ratings that clients can compare across findings. OWASP Top 10 is a list of web application risk categories, not a scoring system, and CVE is a vulnerability identifier database, not a rating framework.

Exam trap

The trap here is that candidates confuse OWASP Top 10 (a risk categorization list) with a scoring framework, or mistake CVE (an identifier system) for a severity rating system, when CVSS is the only option that provides a standardized numerical severity scale for individual vulnerabilities.

How to eliminate wrong answers

Option A is wrong because OWASP Top 10 is a periodic awareness document that ranks broad categories of web application security risks (e.g., injection, broken authentication), not a framework for assigning individual vulnerability severity scores. Option C is wrong because CVE (Common Vulnerabilities and Exposures) is a dictionary of unique identifiers for publicly known vulnerabilities, with no scoring or rating mechanism—it simply names and describes the flaw.

503
MCQmedium

During a penetration test, a tester discovers a web application that uses JavaScript to load API endpoints dynamically. Which technique would be most effective for discovering hidden API endpoints?

A.Analyzing JavaScript files for API endpoints
B.Performing a DNS zone transfer
C.Running a Nikto scan
D.Using Nmap to scan for open ports and services
AnswerA

Analyzing JavaScript files is the definitive technique here because modern single-page applications bundle most of their client-side logic into JavaScript. Static analysis of the code (or dynamic inspection via browser DevTools' Network tab) can reveal backend API URLs, request parameters, authentication tokens, and webpack chunk references that are never publicly documented. Source maps, if left exposed, can even reconstruct the original source to expose hidden or internal endpoints that network scanners cannot see.

Why this answer

JavaScript analysis involves inspecting JavaScript files for hardcoded API endpoints, secrets, and other useful information, making it effective for discovering hidden API endpoints.

504
MCQeasy

A penetration testing firm is hired to assess a mobile banking application. The client wants to test both Android and iOS versions, but only the production environment. Which of the following is the MOST important scoping consideration to include in the rules of engagement?

A.Requiring jailbroken/rooted devices for testing
B.Specifying the number of concurrent users during testing
C.Defining the test window to avoid peak hours
D.Excluding the backend API from testing
AnswerA

Rooting/jailbreaking the test device is critical for a mobile app assessment because many security controls—such as root detection, SSL certificate pinning, and integrity checks—only activate under a compromised OS environment. Only on a jailbroken/rooted device can a tester bypass these protections (e.g., with Frida or Cycript), inspect in-memory data, and perform runtime patching to uncover hidden vulnerabilities. Without this requirement, the scope would be artificially limited to the app's behavior in a trusted environment, which is not representative of real-world threats.

Why this answer

Requiring jailbroken or rooted devices is the most important scoping consideration because mobile banking applications often implement runtime integrity checks (e.g., MagiskHide, Frida detection) that prevent the app from running on compromised devices. Without explicit authorization to bypass these controls, the penetration tester cannot perform deep dynamic analysis, such as hooking API calls or inspecting encrypted local storage, which is essential for a thorough security assessment of the production environment.

Exam trap

The trap here is that candidates often confuse operational scheduling (Option C) with technical feasibility, overlooking that without a jailbroken/rooted device, the tester cannot bypass runtime integrity checks and thus cannot perform the most critical parts of the mobile app assessment.

How to eliminate wrong answers

Option B is wrong because specifying the number of concurrent users is irrelevant for a mobile application penetration test; load testing is a performance concern, not a security scoping consideration, and the rules of engagement focus on authorization boundaries, not throughput metrics. Option C is wrong because defining the test window to avoid peak hours is an operational consideration to minimize business impact, but it is not the most important scoping factor; the core technical constraint for mobile app testing is the device's integrity state, as production apps often refuse to run on jailbroken/rooted devices, making authorization to use such devices a prerequisite for any meaningful testing.

505
MCQmedium

A penetration tester is preparing a report and wants to include proof-of-concept code to demonstrate a vulnerability. Which of the following is the best practice for including such code?

A.Include fully automated exploit scripts that could be used for attacks.
B.Include code that extracts sensitive data to prove impact.
C.Provide code that demonstrates the vulnerability in a responsible manner without destructive payloads.
D.Omit code and only describe the vulnerability verbally.
AnswerC

Providing code that demonstrates the vulnerability in a responsible manner is the correct approach because it gives the client concrete, reproducible proof of the flaw without enabling real damage. A responsible proof-of-concept might use a benign payload, such as a crafted HTTP request that returns an error message indicating SQL injection, or a script that triggers a 200 vs 500 response to show an access control issue. This balances the need for evidence with the ethics of disclosure, allowing developers to reproduce and fix the issue without causing data loss or system compromise.

Why this answer

Proof-of-concept code should prove the vulnerability is exploitable without causing harm to the client's environment.

506
MCQeasy

Which of the following tools is most commonly used for passive reconnaissance by querying certificate transparency logs to discover subdomains?

A.crt.sh
B.Censys
C.theHarvester
D.Shodan
AnswerA

crt.sh is a dedicated web service and API that aggregates and searches public Certificate Transparency (CT) logs, making it the most commonly used tool for passively discovering subdomains by querying issued SSL/TLS certificates. Because it queries the CT logs directly, it requires no interaction with the target's infrastructure and returns a comprehensive list of subdomains for free without API keys. This passive approach is a standard first step in reconnaissance during penetration testing and bug bounty engagements.

Why this answer

crt.sh is a certificate transparency log search tool that can be used to find subdomains by querying SSL/TLS certificates issued for a domain.

507
MCQmedium

During a web application test, a penetration tester intercepts requests between the browser and server and modifies them in real time. Which Burp Suite tool is designed for this purpose?

A.Repeater
B.Sequencer
C.Intruder
D.Proxy
AnswerD

Burp Proxy is the component that acts as an intercepting forward proxy between the tester's browser and the target web application. With intercept mode enabled, it captures each HTTP/S request, lets the tester pause, inspect, modify, and forward it before the server sees it, and performs the same for responses. This live, bidirectional control over traffic in real time is exactly what makes Proxy the correct tool for request interception during a web application penetration test.

Why this answer

Burp Proxy intercepts and allows modification of HTTP/HTTPS requests.

508
MCQmedium

A penetration tester discovers that a previously reported vulnerability from a prior test has not been remediated. How should this be communicated in the current report?

A.Only mention it in the executive summary, referencing the past report.
B.Include it as a recurring finding and note the lack of remediation.
C.Omit the finding to avoid repetition.
D.Reduce the severity rating because it was already reported.
AnswerB

Correctly documenting a recurring finding means including it in the detailed technical findings with an explicit note that this was previously reported and is still unresolved. This is a professional standard because it provides a clear audit trail, measures the client's remediation progress, and underscores that the risk persisted rather than being re-discovered anew. By stating the lack of remediation, the report highlights the client's vulnerability-management gap and justifies follow-up action or escalated priority.

Why this answer

Penetration testing standards (e.g., PTES, OWASP) require that previously identified vulnerabilities that remain unpatched be documented as recurring findings with explicit reference to the prior report. This ensures the client understands the risk persists and can track remediation progress over time. Including the finding with a note on lack of remediation maintains the integrity of the current risk assessment and supports compliance with reporting frameworks like NIST SP 800-115.

Exam trap

The trap here is that candidates mistakenly think repeating a finding is redundant or that the executive summary is sufficient, but CompTIA expects the finding to be fully documented in the technical body of the report with a clear note on recurrence.

How to eliminate wrong answers

Option A is wrong because relegating a recurring vulnerability solely to the executive summary omits the technical details, evidence, and risk context needed for the technical audience to act on the finding. Option C is wrong because omitting the finding violates the principle of full disclosure and could lead to legal liability if the client assumes the vulnerability was fixed. Option D is wrong because reducing the severity rating based solely on prior reporting is a logical fallacy; the risk to the environment remains unchanged unless compensating controls have been verified.

509
MCQeasy

Which penetration testing standard provides a methodology that includes pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting?

A.OSSTMM
B.NIST SP 800-115
C.OWASP Testing Guide
D.PTES
AnswerD

PTES is the correct answer because it defines a complete penetration testing methodology with seven distinct phases, including pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting. This structure explicitly incorporates both technical execution and business/legal considerations, providing a comprehensive standard that fully covers the penetration testing lifecycle from initial scoping to final client deliverable.

Why this answer

The Penetration Testing Execution Standard (PTES) is the only standard among the options that explicitly defines a full penetration testing methodology with the phases listed: pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting. PTES provides a structured, seven-phase framework designed specifically for penetration testers, making it the correct choice for this question.

Exam trap

The trap here is that candidates often confuse the OWASP Testing Guide (Option C) as a general penetration testing standard because it is widely known, but it is strictly limited to web application security and does not cover the full lifecycle of a penetration test as defined in the question.

How to eliminate wrong answers

Option A is wrong because the Open Source Security Testing Methodology Manual (OSSTMM) focuses on operational security metrics and channel-based testing (e.g., human, physical, wireless, telecommunications, and data networks) rather than a sequential penetration testing methodology with the specific phases listed. Option B is wrong because NIST SP 800-115 is a technical guide for information security testing and assessment, but it does not prescribe a formal penetration testing methodology with phases like pre-engagement interactions or post-exploitation; it is more of a general assessment framework. Option C is wrong because the OWASP Testing Guide is specifically focused on web application security testing and does not cover the full scope of a penetration test, including pre-engagement interactions, threat modeling in the context of network or system testing, or post-exploitation activities beyond web applications.

510
MCQmedium

A penetration tester is performing a man-in-the-middle attack on a network using ARP spoofing. What is the primary purpose of ARP spoofing?

A.To assign a fake IP address to the attacker's device
B.To associate the attacker's MAC address with the IP address of a legitimate host
C.To modify the routing table of the target
D.To poison the DNS cache of the target
AnswerB

This is the core of an ARP spoofing attack: the attacker sends unsolicited ARP replies (or broadcasts) asserting that the legitimate host's IP address corresponds to the attacker's MAC address. The victim's ARP cache then updates, causing frames destined for that IP to be sent to the attacker's network interface instead of the real host. The attacker can silently intercept, inspect, or forward those frames to the actual host, creating a transparent layer-2 man-in-the-middle position.

Why this answer

ARP spoofing works by sending forged ARP replies to associate the attacker's MAC address with the IP address of a legitimate host (e.g., the default gateway). This causes traffic destined for that IP to be sent to the attacker instead, enabling interception and manipulation of network communications.

Exam trap

The trap here is that candidates confuse ARP spoofing with IP address spoofing or DNS poisoning, but the exam specifically tests that ARP spoofing manipulates MAC-to-IP mappings at Layer 2, not IP addresses or higher-layer caches.

How to eliminate wrong answers

Option A is wrong because ARP spoofing does not assign a fake IP to the attacker; the attacker retains their own IP and instead manipulates the IP-to-MAC mapping on other hosts. Option C is wrong because ARP spoofing operates at Layer 2 (Data Link) and does not modify routing tables, which are Layer 3 constructs managed by protocols like RIP or OSPF. Option D is wrong because DNS cache poisoning targets the DNS resolver's cache (Layer 7), whereas ARP spoofing targets the ARP cache (Layer 2) to redirect traffic at the network access layer.

511
MCQmedium

A penetration tester is conducting an internal network test. During the engagement, the tester discovers a critical vulnerability that could be exploited to gain domain admin privileges. According to best practices, how should the tester communicate this finding to the client?

A.Immediately notify the client's point of contact via a secure channel
B.Only communicate it if the client asks for a status update
C.Wait until the end of the test to include it in the formal report
D.Exploit the vulnerability to demonstrate impact and then fix it before reporting
AnswerA

A domain-admin escalation path poses immediate, severe risk to the client's environment, so the tester must report it promptly through the agreed secure channel. This satisfies the duty to disclose critical findings without waiting for the final report.

Why this answer

Option A is correct because best practices for penetration testing require immediately notifying the client's designated point of contact through a secure channel when a critical vulnerability—such as one enabling domain admin compromise—is discovered, so the client can begin remediation and risk mitigation without delay. This aligns with standard engagement rules of conduct and responsible disclosure, which prioritize urgent communication of high-impact findings over waiting for a scheduled report. Option B is wrong because critical findings must be proactively escalated, not withheld until the client requests a status update.

Option C is wrong because waiting until the final report could leave the domain exposed to exploitation for the remainder of the engagement. Option D is wrong because exploiting the vulnerability to demonstrate impact and then attempting to "fix" it exceeds the tester's authorized scope and could cause damage or legal issues.

512
Multi-Selectmedium

A penetration tester is performing active reconnaissance on a target web application. Which TWO tools are specifically designed for directory and file enumeration? (Select TWO.)

Select 2 answers
A.Wappalyzer
B.Feroxbuster
C.Nmap
D.Gobuster
E.WhatWeb
AnswersB, D

Feroxbuster is a Rust-based recursive content discovery tool specifically engineered for fast directory and file brute-forcing. It supports wordlist-driven scanning, multiple file extensions, recursion, and automatic filtering of irrelevant status codes and response sizes, allowing penetration testers to efficiently map out hidden web resources. Its speed and recursive crawling make it an excellent choice for active reconnaissance on web applications.

Why this answer

Gobuster and Feroxbuster are both tools specifically designed for directory and file brute-forcing on web servers.

513
MCQeasy

Which of the following should be included in the appendix section of a penetration testing report?

A.Raw tool output and scan results
B.Remediation steps for each finding
C.Executive summary
D.Key findings and overall risk rating
AnswerA

Correct — raw tool output and scan results are exactly the kind of bulky, unprocessed data that belongs in an appendix. They provide supporting evidence and reproducibility for the findings discussed in the report body, without cluttering the narrative. An appendix is the standard location for this material, along with configuration files, endpoint lists, and detailed command output that stakeholders can consult if needed.

Why this answer

Appendices contain supporting details like scope, methodology, and raw tool output.

514
Multi-Selectmedium

A penetration tester has obtained a meterpreter session on a Windows target. The tester wants to escalate privileges to SYSTEM and then dump password hashes. Which two meterpreter commands should the tester use in sequence? (Choose TWO.)

Select 2 answers
A.getuid
B.getsystem
C.shell
D.hashdump
E.sysinfo
AnswersB, D

The getsystem command invokes Meterpreter's built-in token impersonation and named-pipe duplication attacks to shift the session's security context to NT AUTHORITY\SYSTEM. This is the direct privilege escalation step in a typical post-exploitation sequence, bridging a limited or admin token to full system-level access. It does not return or display hash values; instead, it grants the elevated rights required by later commands such as hashdump.

Why this answer

First, use getsystem to attempt privilege escalation to SYSTEM (via token stealing or other techniques). Then, use hashdump to dump the SAM database hashes. getuid shows current user, sysinfo shows system info.

515
MCQmedium

A penetration tester is tasked with performing active reconnaissance on an internal network. The tester wants to identify live hosts and their open ports efficiently while minimizing noise. Which Nmap scan type should be used first to quickly discover which hosts are online?

A.nmap -sS -sV 192.168.1.0/24
B.nmap -A 192.168.1.0/24
C.nmap -sn 192.168.1.0/24
D.nmap -sT 192.168.1.0/24
AnswerC

Correct. Ping sweep quickly identifies live hosts.

Why this answer

The `-sn` flag (ping scan) sends ICMP echo requests, TCP SYN to port 443, TCP ACK to port 80, and ICMP timestamp requests by default to determine if hosts are online without performing port scans. This minimizes network noise and quickly identifies live hosts on the subnet, which is the first step in active reconnaissance before deeper scanning.

Exam trap

Candidates often choose full port scans (-sS or -sT) for initial discovery, overlooking that -sn is specifically designed for low-noise host discovery.

How to eliminate wrong answers

Option A is wrong because `-sS` (SYN stealth scan) combined with `-sV` (version detection) performs a full port scan and service fingerprinting on every host, generating excessive traffic and noise for initial host discovery. Option B is wrong because `-A` enables aggressive scanning (OS detection, version detection, script scanning, traceroute), which is heavy and inappropriate for a quick live-host discovery phase. Option D is wrong because `-sT` (TCP connect scan) completes the full three-way handshake for each port, creating more noise and connection logs than a simple ping sweep.

516
MCQmedium

You are performing a vulnerability scan on an internal network using an authenticated scanner. Which of the following is a primary benefit of authenticated scanning compared to unauthenticated scanning?

A.It eliminates false positives entirely
B.It reduces network traffic
C.It provides more accurate identification of vulnerabilities that require credentials
D.It avoids detection by intrusion detection systems
AnswerC

With valid credentials, the scanner can log in to the target and perform local checks, such as inspecting installed patches, configuration files, running services, and file permissions, rather than relying solely on remote banner grabbing and version inference. This enables the scanner to identify vulnerabilities that only manifest post-authentication, such as weak local security policies or missing cumulative updates, with far greater accuracy.

Why this answer

Authenticated scanning provides deeper insight by checking for missing patches, misconfigurations, and vulnerabilities that require valid credentials to detect, such as local privilege escalation issues.

517
MCQmedium

A penetration tester is analyzing a Ruby script that uses the 'metasploit-framework' gem. The script includes a line: `Msf::Simple::Framework.create` and then calls `run_single('use exploit/multi/handler')`. What is the primary purpose of this script?

A.Automate a port scan across multiple targets
B.Set up a Metasploit payload handler to catch reverse shells
C.Create a Metasploit resource script for automated attacks
D.Load and execute a local exploit against a specified target
AnswerB

This is exactly the intended function of the multi/handler module: it acts as a generic payload handler that waits for a reverse connection from an exploited target. By instantiating Msf::Exploit::Remote::MultiHandler in Ruby, setting a payload (e.g., windows/meterpreter/reverse_tcp) and binding to an LHOST/LPORT, the script establishes a listener that captures incoming sessions for post-exploitation. This is a common programmatic way to set up a handler outside the interactive msfconsole, especially when automating staged payload delivery or managing multiple listeners concurrently.

Why this answer

The script uses `Msf::Simple::Framework.create` to instantiate a Metasploit Framework instance and then calls `run_single('use exploit/multi/handler')` to load the multi/handler module. This module is specifically designed to listen for incoming connections from payloads (e.g., reverse shells) that have been executed on a target, making the script's primary purpose to set up a handler to catch reverse shells.

Exam trap

The trap here is that candidates may confuse the `use exploit/multi/handler` command with a generic exploit or attack automation, when in fact it is purely a listener for incoming reverse connections, not an active exploit or scanning tool.

How to eliminate wrong answers

Option A is wrong because the script does not include any port scanning logic or calls to modules like `auxiliary/scanner/portscan`; it only loads a handler module. Option C is wrong because the script directly executes a Metasploit command via `run_single` rather than writing or generating a resource script (`.rc` file) for later automated execution.

518
MCQhard

Refer to the exhibit. A penetration tester used a vulnerability scanner and obtained the above result. What is the BEST way to represent this finding in the report to ensure the client can reproduce and fix it?

A.Include only the URL and parameter name.
B.Include the full request with the exact payload and evidence.
C.Provide the exact error message from the database.
D.List the vulnerability scanner used and its version.
AnswerB

Reproducibility requires the exact HTTP request, including headers, parameters and payload, plus the observed response as evidence. This lets the client replay the request against their own system and confirm the vulnerability before remediating it.

Why this answer

Option B is correct because including the full HTTP request with the exact payload and supporting evidence gives the client everything needed to reproduce the finding and verify a fix, which is the standard for a professional penetration test report. The full request preserves the method, endpoint, headers, cookies, and parameter values, while the payload and evidence demonstrate the actual exploitability rather than just asserting it. Option A is insufficient because a URL and parameter name alone omit the request method, headers, and payload needed to trigger the issue.

Option C is too narrow, since a database error message is only one possible piece of evidence and may not be present or may not show how to reproduce the flaw. Option D is irrelevant to reproduction, as naming the scanner and version does not provide the request details or proof required to confirm and remediate the vulnerability.

519
Multi-Selecthard

A penetration tester has gained initial access to a Linux server and wants to establish persistence. Which THREE of the following methods are commonly used for persistence on Linux systems?

Select 3 answers
A.Installing an SSH authorized_key for the attacker
B.Adding a cron job that executes a reverse shell
C.Using schtasks to create a scheduled task
D.Modifying the Windows Registry Run key
E.Creating a systemd service that runs on boot
AnswersA, B, E

Installing an SSH authorized_key for the attacker is a Linux persistence technique that involves appending the attacker's public key to the target user's ~/.ssh/authorized_keys file. This permits the attacker to authenticate over SSH without a password, even after system reboots. It is stealthy because it requires no new process or scheduled task, blending in with normal user configuration files, and remains effective indefinitely unless explicitly removed.

Why this answer

Cron jobs, SSH authorized_keys, and systemd services are common persistence mechanisms.

520
Multi-Selectmedium

A penetration tester is using Metasploit to pivot from a compromised host to an internal network. Which THREE Metasploit features can facilitate pivoting?

Select 3 answers
A.Exploit/multi/handler
B.Metasploit route command
C.SSH local port forwarding
D.Autoroute post module
E.Metasploit socks proxy
AnswersB, D, E

The `route` command is the core Metasploit pivot primitive: `route add <subnet> <netmask> <session_id>` tells Metasploit's dispatcher to send any packets destined for that subnet through the specified session, typically a Meterpreter or shell session on a compromised host. This allows all built-in modules (scanners, exploits, auxiliary) to reach otherwise inaccessible internal networks via the session's existing connection. It is a manual, session-dependent routing entry, making it the correct classic answer for Metasploit-based pivoting.

Why this answer

The 'route' command adds routes through a session, and Metasploit's socks proxy (auxiliary/server/socks4a) can be used. Autoroute is a post module. Exploit/multi/handler is for reverse shells, not directly for pivoting.

Port forwarding via SSH is external to Metasploit.

521
MCQhard

A penetration tester discovers that a web application uses a vulnerable Java deserialization endpoint. The classpath includes the Apache Commons Collections library. Which attack technique is most likely to achieve remote code execution?

A.Java deserialization of untrusted data (RCE via Commons Collections).
B.SQL injection.
C.Cross-site scripting.
D.Command injection.
AnswerA

The vulnerability is Java deserialization of untrusted data: the endpoint accepts a serialized Java object and passes it directly to ObjectInputStream.readObject() without input validation or class filtering. Because the application's classpath includes Apache Commons Collections, an attacker can use a tool like ysoserial to generate a malicious object graph that chains gadget classes (e.g., InvokerTransformer, TransformedMap) to execute arbitrary system commands during deserialization. This yields remote code execution on the application server, making it the direct and most impactful attack vector.

Why this answer

The presence of the Apache Commons Collections library in the classpath, combined with a vulnerable Java deserialization endpoint, enables the classic 'gadget chain' attack. Attackers craft a malicious serialized object that, when deserialized, invokes methods in Commons Collections (e.g., InvokerTransformer) to execute arbitrary system commands, achieving remote code execution (RCE). This is a well-documented exploit chain (e.g., CVE-2015-7501) that directly leverages the library's reflection-based classes.

Exam trap

The trap here is that candidates may confuse deserialization attacks with other input-based attacks like SQLi or XSS, failing to recognize that the specific vulnerability is the unsafe deserialization of Java objects using a known gadget library (Commons Collections) to achieve server-side RCE.

How to eliminate wrong answers

Option B is wrong because SQL injection targets database queries via input manipulation, not Java deserialization of objects; it does not exploit the deserialization endpoint or the Commons Collections library. Option C is wrong because cross-site scripting (XSS) injects client-side scripts into web pages, not server-side code execution via deserialization; it cannot achieve RCE through Java object deserialization.

522
MCQeasy

A penetration tester is hired to assess the security of a company's internal network. The client provides the tester with full network diagrams, credentials, and source code. Which type of penetration test is being performed?

A.Grey box
B.Black box
C.Red team
D.White box
AnswerD

White box testing, also called clear box or open box testing, gives the tester full knowledge of the target environment, including source code, architecture diagrams, configuration files, and administrative credentials. This comprehensive visibility allows the pentester to perform detailed code review, identify programming flaws, and validate configuration hardening with maximum efficiency. When the engagement premise states the tester is provided complete system details, white box is the only correct classification.

Why this answer

White box testing provides the tester with full knowledge and credentials, which matches the scenario.

523
MCQmedium

A penetration tester is performing active reconnaissance on a web application and wants to discover hidden directories and files. Which tool would be most effective for brute-forcing directory names based on a wordlist?

A.Gobuster
B.Nikto
C.theHarvester
D.WPScan
AnswerA

It's a brute-force tool that uses wordlists to discover directories and files on web servers by sending HTTP requests and matching status codes. Unlike vulnerability scanners, Gobuster focuses purely on resource enumeration, making it ideal for mapping an application's structure. In active reconnaissance, it directly interacts with the target to reveal hidden paths.

Why this answer

Gobuster is a tool used for directory/file brute-forcing using wordlists. Dirb is similar but older; gobuster is more modern and flexible.

524
MCQhard

A penetration tester uses the CVSS base score to rate a vulnerability. The tester finds that the vulnerability has a high CVSS score but the affected system is isolated from the internet and has no sensitive data. Which approach should the tester take when assigning an overall severity rating?

A.Increase the severity because the system is isolated and may be overlooked.
B.Adjust the severity lower to reflect the reduced business impact.
C.Remove the finding from the report since the system is isolated.
D.Use the CVSS score as the final severity rating.
AnswerB

Adjusting the severity downward is correct because CVSS's base score captures the intrinsic characteristics of the vulnerability in a generic context, not the actual business context. Using the environmental score, the tester would modify impact metrics to reflect an isolated system and low data sensitivity, lowering the overall rating. This alignment of severity to business impact is exactly how a penetration test adds value beyond a raw scanner CVSS number.

Why this answer

CVSS is a good starting point but should be adjusted based on business context such as impact and likelihood in the specific environment.

525
Multi-Selectmedium

A penetration tester is performing host discovery on a subnet. Which TWO of the following Nmap options can be used to discover live hosts?

Select 2 answers
A.-sn
B.-O
C.-sP
D.-sV
E.-sS
AnswersA, C

The -sn flag tells Nmap to skip port scanning entirely and perform only host discovery, sending ICMP echo requests, TCP SYN to port 443, TCP ACK to port 80, and an ICMP timestamp request by default when run as root. It is the canonical ping sweep option for enumerating live hosts on a subnet without probing open ports, making it the correct choice for host discovery.

Why this answer

Both -sn (ping sweep) and -sP (older alias for ping sweep) perform host discovery without port scanning. -sS and -sV are for port scanning and version detection respectively, not host discovery.

Page 6

Page 7 of 11

Page 8

All pages