Sample questions
EC-Council Certified Penetration Testing Professional (CPENT) (CPENT) practice questions
Which THREE conditions or configurations make an Active Directory certificate template vulnerable to ESC3 (Enrollment Agent abuse)?
An auditor finds an Amazon S3 bucket configured with public read access enabled via an Access Control List (ACL), but the bucket policy explicitly denies public read access. How do…
An operator has identified an Active Directory domain trust relationship where a trusted forest has 'SID History' filtering disabled (Quarantined Domain Trust set to disabled/unfil…
During an Azure assessment, an attacker discovers that an App Service web application has Managed Identity enabled and the underlying application code is vulnerable to Server-Side…
Cloud And Hybrid Infrastructure SecuritymediumSee the answer and why each option is right or wrong →During an assessment of a Google Cloud Platform project, a penetration tester finds that a Cloud Storage bucket has the allUsers principal granted the Storage Object Viewer role. W…
Cloud And Hybrid Infrastructure SecuritymediumSee the answer and why each option is right or wrong →An administrator needs to secure communication between microservices running across different AWS Virtual Private Clouds (VPCs). Which native AWS networking feature provides privat…
When generating a Silver Ticket using Impacket's ticketer.py, what specific piece of cryptographic material is required instead of the KRBTGT hash?
Which THREE conditions must be met for a successful Resource-Based Constrained Delegation (RBCD) attack against a target computer object?
An ethical hacker has obtained the NTLM password hash of a local administrator account on a Windows workstation and wants to perform lateral movement using Pass-the-Hash (PtH). Whi…
An internal penetration tester is performing reconnaissance using BloodHound to map out attack paths in an Active Directory domain. Which automated data collection tool is official…
When conducting an advanced Active Directory penetration test, which THREE techniques can be used to extract or abuse credentials without interacting with LSASS directly on a domai…
An auditor reviews an Azure storage account and notes that 'Secure transfer required' is set to Disabled. What security risk does this misconfiguration introduce?
During a Red Team assessment against an enterprise network, an operator wants to execute a Silver Ticket attack against a specific service (e.g., CIFS) on a target server. What is…
Which TWO of the following Active Directory enumeration methods or tools can be used by an unprivileged domain user to identify accounts configured with 'Do not require Kerberos pr…
An ethical hacker has compromised a machine account and discovered that it has 'GenericAll' or 'WriteDacl' privileges over a privileged domain group (such as Domain Admins). Which…
A penetration tester has compromised an account that possesses the 'GenericAll' permission over a Group Policy Object (GPO) linked to the domain. How can this permission be leverag…
An operator captures a valid Ticket Granting Ticket (TGT) for a domain user from memory and wants to inject it into their current session to access network resources without re-aut…
An AWS administrator wants to prevent users from accidentally creating public Amazon S3 buckets across the entire AWS account. Which specific AWS feature should be enabled?
During a hybrid cloud assessment, a penetration tester examines the connection between an on-premises Active Directory and Azure AD. Which THREE of the following mechanisms or misc…
Cloud And Hybrid Infrastructure SecuritymediumSee the answer and why each option is right or wrong →An ICS penetration tester is auditing a substation utilizing the IEC 61850 standard for electrical substation automation. The tester captures Generic Object Oriented Substation Eve…
An auditor is evaluating cloud storage security across multiple cloud providers. Which TWO of the following settings indicate improper security configurations for cloud storage buc…
During an Active Directory security review, an assessor examines Kerberos delegation configurations. Which THREE delegation misconfigurations or vulnerabilities represent high-risk…
An AWS penetration tester discovers that an Amazon RDS database instance has the 'Publicly Accessible' flag set to true, and its security group allows inbound traffic from 0.0.0.0/…
An auditor reviews network security configurations in an AWS VPC. Which TWO of the following network configurations represent potential security risks? (Choose TWO)