Courseiva
Back to EC-Council Certified Penetration Testing Professional (CPENT) (CPENT) questions

Scenario-based practice

Hard Difficulty Questions

Practise EC-Council Certified Penetration Testing Professional (CPENT) (CPENT) practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
CPENT
exam code
EC-Council
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related CPENT topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmulti select
Full question →

Which THREE conditions or configurations make an Active Directory certificate template vulnerable to ESC3 (Enrollment Agent abuse)?

Question 2hardmultiple choice
Full question →

An operator has identified an Active Directory domain trust relationship where a trusted forest has 'SID History' filtering disabled (Quarantined Domain Trust set to disabled/unfiltered). What attack does this enable?

Question 3hardmulti select
Full question →

Which THREE conditions must be met for a successful Resource-Based Constrained Delegation (RBCD) attack against a target computer object?

Question 4hardmulti select
Full question →

When conducting an advanced Active Directory penetration test, which THREE techniques can be used to extract or abuse credentials without interacting with LSASS directly on a domain controller?

Question 5hardmultiple choice
Study the full multicast explanation →

An ICS penetration tester is auditing a substation utilizing the IEC 61850 standard for electrical substation automation. The tester captures Generic Object Oriented Substation Events (GOOSE) messages on the network. Which Layer 2 Ethernet type hex value identifies GOOSE multicast frames?

Question 6hardmulti select
Full question →

During an Active Directory security review, an assessor examines Kerberos delegation configurations. Which THREE delegation misconfigurations or vulnerabilities represent high-risk attack vectors if exploited? (Choose THREE)

Question 7hardmulti select
Full question →

A penetration tester is analyzing an enterprise cloud infrastructure utilizing both AWS and Azure. Which THREE of the following attack vectors or misconfigurations are relevant to hybrid and cloud security assessments? (Choose THREE)

Question 8hardmultiple choice
Full question →

During a container security assessment, a penetration tester identifies a Kubernetes pod running with 'CAP_SYS_ADMIN' capabilities and the host's PID namespace shared ('hostPID: true'). Which technique allows the tester to escape the container and execute code on the host?

Question 9hardmultiple choice
Full question →

A penetration tester is evaluating a Kubernetes environment and discovers that the Kubernetes dashboard is deployed with cluster-admin privileges and is exposed to the internet via a NodePort service without authentication. How can this be exploited?

Question 10hardmulti select
Full question →

A penetration tester is assessing an advanced hybrid cloud and Kubernetes infrastructure. Which THREE of the following scenarios represent critical architecture or configuration flaws? (Choose THREE)

A pentester is performing a security review of a smart meter that utilizes an unencrypted CoAP (Constrained Application Protocol) service running over UDP. Using Python and Scapy, the tester crafts a packet to interact with the device. Which default UDP port should the tester target for standard unencrypted CoAP communications?

Question 12hardmultiple choice
Full question →

A security researcher is evaluating an industrial IoT gateway running Linux. During a filesystem audit of the extracted rootfs, the researcher finds that the '/etc/shadow' file contains weak password hashes for the root user. Which utility can the researcher use offline on their host machine to attempt password cracking via dictionary attack against the extracted hash?

Question 13hardmultiple choice
Full question →

An engineer is conducting a security audit on a smart grid device that uses CoAP over DTLS. The engineer attempts to intercept the handshake and notices pre-shared key (PSK) cipher suites are enabled. Which OpenSSL command can the engineer use to test connecting to the DTLS service using a specific Pre-Shared Key identifier and hex-encoded key?

Question 14hardmulti select
Review the full routing breakdown →

An IoT security analyst is performing a firmware security review of an embedded Linux router. Which TWO of the following static analysis techniques or tools should the analyst employ to identify hardcoded secrets and vulnerable binaries within the extracted root file system? (Choose TWO)

Question 15hardmulti select
Read the full wireless explanation →

An IoT penetration tester is analyzing the security of a Zigbee smart lighting installation. Which TWO of the following tools or frameworks are specifically utilized when assessing 802.15.4 and Zigbee wireless security? (Choose TWO)

Question 16hardmultiple choice
Full question →

A security analyst is performing a security assessment on a Siemens S7-1200 PLC. Using Nmap, which NSE script should the analyst run to gather detailed device information, including rack, slot, and firmware version via the S7 communication protocol?

Question 17hardmulti select
Full question →

An ethical hacker is evaluating a Bluetooth Low Energy (BLE) medical sensor. Which TWO of the following vulnerabilities or attack vectors are commonly associated with insecure BLE implementations in IoT devices? (Choose TWO)

Question 18hardmulti select
Read the full wireless explanation →

A penetration tester is evaluating a smart home hub communicating via Z-Wave protocol. Which TWO of the following characteristics or security mechanisms distinguish Z-Wave from standard Wi-Fi or Zigbee implementations? (Choose TWO)

Question 19hardmultiple choice
Full question →

A penetration tester is evaluating a Zigbee-based smart home lighting network. Using a Texas Instruments CC2531 USB dongle flashed with Sniffer firmware, the tester captures over-the-air packets. To decrypt the Zigbee application layer payload in Wireshark, what critical piece of cryptographic material must the tester input into Wireshark's Zigbee decryption settings?

Question 20hardmultiple choice
Review the full routing breakdown →

A penetration tester is analyzing an ARM-based IoT router firmware. The tester wants to statically analyze a compiled ELF binary named 'auth_service' to identify potential buffer overflows. Which open-source reverse engineering framework, developed by NSA, should the tester utilize to perform disassembly and decompilation of this binary?

These CPENT practice questions are part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style CPENT questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.