Courseiva

PT0-003 · topic practice

Attacks and Exploits practice questions

Domain 4 of PT0-003 covers exploiting hosts, services, and credentials during engagements. You are tested on recognizing attack techniques, selecting the right tool for a scenario, and interpreting output, with emphasis on SQL injection variants, SMB enumeration and remote execution, pass-the-hash, and LLMNR/NBT-NS spoofing to capture NTLMv2 hashes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Attacks and Exploits

What the exam tests

What to know about Attacks and Exploits

Be able to match each scenario to the correct technique and tool: time-based SQLi for delay inference, CrackMapExec or Impacket for SMB, pass-the-hash for NTLM authentication, and Responder for LLMNR spoofing. The key is identifying the protocol and credential type before picking a tool.

Blind SQL injection variants, including time-based inference using database delay functions like SLEEP or WAITFOR DELAY.

SMB enumeration and remote command execution with tools such as CrackMapExec, Impacket psexec, and smbclient.

Pass-the-hash authentication to Windows using captured NTLM hashes with Impacket or CrackMapExec.

LLMNR/NBT-NS spoofing with Responder to capture NTLMv2 hashes and relay or crack them.

Watch out for

Common Attacks and Exploits exam traps

  • ▸Confusing time-based blind SQL injection with boolean-based or error-based, when the question specifically mentions response delay as the inference channel.
  • ▸Choosing a general port scanner or vulnerability scanner for SMB share enumeration and remote execution instead of a dedicated SMB/Impacket tool.
  • ▸Attempting to crack an NTLM hash before recognizing that pass-the-hash allows authentication without recovering the plaintext password.

Practice set

Attacks and Exploits questions

20 questions · select your answer, then reveal the explanation

A penetration tester has successfully compromised a Windows machine and wants to perform lateral movement to another machine using captured NTLM hashes. Which tool would allow the tester to pass the hash and execute commands remotely?

During a penetration test, a tester identifies that a web application is vulnerable to Server-Side Request Forgery (SSRF). The tester attempts to access the AWS metadata endpoint to retrieve temporary credentials. Which IP address is commonly used for the cloud metadata endpoint?

A penetration tester is exploiting a SQL injection vulnerability in a login page. The tester wants to extract data from another table without returning data in the original query. Which SQL injection technique should the tester use?

A penetration tester is assessing a web application that uses JSON Web Tokens (JWT) for authentication. The tester discovers that the server does not validate the signature algorithm properly. Which attack should the tester attempt to forge a valid token?

Which Metasploit command is used to interact with an established session on a compromised host?

A tester is performing a Cross-Site Request Forgery (CSRF) attack on a web application that uses SameSite cookies. Which SameSite attribute value is most likely to prevent the attack?

During a penetration test of a web application, you want to test for Cross-Site Request Forgery (CSRF) vulnerabilities. Which TWO conditions are necessary for a CSRF attack to succeed?

You have gained a foothold on a Linux server and identified a SUID binary that can be exploited to read arbitrary files. Which THREE techniques could be used to escalate privileges or gather sensitive information?

A penetration tester wants to pivot from a compromised Linux host to attack internal network resources that are not directly accessible. Which THREE tools or techniques can be used for pivoting?

A penetration tester obtains a meterpreter session on a Windows target. Which command would the tester use to check the current user's privileges and potentially escalate privileges if SeImpersonatePrivilege is enabled?

A tester finds a Linux binary with the SUID bit set that is owned by root and can be executed by any user. The binary is known to have a vulnerability that allows arbitrary code execution. Which command does the tester use to find all SUID binaries on the system?

A penetration tester has compromised a Linux server and wants to establish persistence. Which TWO of the following methods are commonly used for persistence on Linux?

A penetration tester is assessing an Active Directory environment and wants to perform Kerberoasting to obtain service account passwords. Which TWO conditions are required for a successful Kerberoasting attack?

During a penetration test, the tester captured an NTLM hash using Responder and wants to pass the hash to gain access to a remote Windows system. Which tool would be most appropriate to perform a pass-the-hash attack?

A penetration tester is performing a SQL injection test on a web application. The tester sends the payload ' OR '1'='1 and receives the same response as with a normal request. However, when sending ' OR '1'='2, the response differs. Which type of SQL injection is most likely present?

During a penetration test, the tester discovers a Linux binary with the SUID bit set owned by root. The binary is a custom script that executes 'cp' to copy files. The tester can control the source file path via an environment variable. Which privilege escalation technique should the tester attempt?

A penetration tester is performing a web application test and identifies an endpoint that is vulnerable to Server-Side Request Forgery (SSRF). Which of the following actions can the tester perform using this vulnerability? (Choose TWO.)

During a Windows privilege escalation attempt, a penetration tester discovers that the always elevated installation policy is enabled. Which of the following actions can the tester take to exploit this misconfiguration? (Choose TWO.)

While testing a Linux system, the tester finds a binary with the SUID bit set owned by root. The binary executes a command based on user input without verifying the path. Which privilege escalation technique does this exemplify?

A tester identifies a SQL injection vulnerability in a login form. The application responds with different error messages for valid and invalid queries. Which type of SQL injection is most likely present, and what tool could automate exploitation?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Attacks and Exploits sessions

Start a Attacks and Exploits only practice session

Every question in these sessions is drawn from the Attacks and Exploits domain — nothing else.

Related practice questions

Related PT0-003 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the PT0-003 exam test about Attacks and Exploits?
Be able to match each scenario to the correct technique and tool: time-based SQLi for delay inference, CrackMapExec or Impacket for SMB, pass-the-hash for NTLM authentication, and Responder for LLMNR spoofing. The key is identifying the protocol and credential type before picking a tool.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Attacks and Exploits questions in a focused session?
Yes — the session launcher on this page draws every question from the Attacks and Exploits domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other PT0-003 topics?
Use the topic links above to move to related areas, or go back to the PT0-003 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the PT0-003 exam covers. They are not copied from any real exam or dump site.