Courseiva

CPENT · topic practice

Privilege Escalation Lateral Movement And Post Exploitation practice questions

Practise EC-Council Certified Penetration Testing Professional (CPENT) (CPENT) Privilege Escalation Lateral Movement And Post Exploitation practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Privilege Escalation Lateral Movement And Post Exploitation

What the exam tests

What to know about Privilege Escalation Lateral Movement And Post Exploitation

Privilege Escalation Lateral Movement And Post Exploitation questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Privilege Escalation Lateral Movement And Post Exploitation exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Privilege Escalation Lateral Movement And Post Exploitation questions

20 questions · select your answer, then reveal the explanation

A penetration tester is analyzing a Linux system and finds that the binary /bin/ping has the SUID bit set along with root ownership. What is the security implication of this finding?

During an internal engagement, a penetration tester attempts to perform pass-the-hash using Mimikatz, but receives an error indicating that Credential Guard is enabled. Which exploitation technique bypasses this limitation by forcing LSASS to interact with a compromised RPC endpoint?

A penetration tester is performing post-exploitation on a Linux system and wants to exploit an NFS share with the 'no_root_squash' option enabled. Which of the following steps must the tester perform from their attacking machine to successfully write a SUID shell to the share?

An operator has compromised a Linux server and wants to establish persistence via a Cron job that runs every 5 minutes as the root user. Where should the persistence mechanism be placed to ensure execution without modifying /etc/crontab directly?

A tester discovers that an internal Windows host has the AlwaysInstallElevated registry key set to 1 in both HKCU and HKLM. How can the tester leverage this misconfiguration to escalate privileges?

An operator has compromised an Active Directory domain and wants to establish persistence using a Golden Ticket. What critical piece of information from the domain is required to forge this ticket?

During a post-exploitation phase, a penetration tester wants to perform lateral movement using WMI (Windows Management Instrumentation) from a compromised Windows workstation to a domain controller. Which network port must be accessible through host and network firewalls to initiate the WMI connection?

A penetration tester has gained a standard user shell on a Windows machine and wants to check for unquoted service paths. Which PowerShell command should they run to identify services with unquoted paths and spaces in their names without administrative privileges?

During a Windows privilege escalation assessment, a tester discovers that the local 'SeImpersonatePrivilege' is enabled on the current service account token. Which exploitation tool class is best suited for abusing this privilege?

A penetration tester reviewing a Windows machine identifies that a scheduled task executes a script with administrative privileges, but the script file has weak permissions allowing standard users to modify it. What type of privilege escalation vector does this represent?

An operator has compromised a Linux server and wants to establish persistence that survives kernel reboots and operates stealthily by hooking system calls or modifying kernel memory. Which persistence mechanism matches this description?

A penetration tester executing lateral movement in a Windows domain wants to hide their network activity and command execution by using WinRM (Windows Remote Management). Which PowerShell cmdlet is specifically designed to execute commands on a remote trusted host via WinRM?

A tester gains code execution on a Linux host inside a Docker container and discovers they can access the Docker socket (/var/run/docker.sock) from within the container. How can the tester exploit this to escape the container and compromise the host?

During an internal penetration test, an operator wants to perform lateral movement using PsExec. Which underlying Windows mechanism does PsExec rely on to deploy and execute its service binary on the remote target?

A penetration tester is analyzing a compromised Windows system and wants to check for stored credentials in the Windows Credential Manager. Which command-line utility can be used to list saved credentials?

Question 16hardmultiple choice
Read the full DNS explanation →

A penetration tester has obtained execution on a Linux host and needs to exfiltrate a sensitive archive file through a tightly restricted firewall that only permits outbound DNS traffic. Which tool and technique should the tester use?

A penetration tester has gained initial access to a Windows system and needs to enumerate local users and groups to identify high-privileged accounts for potential escalation. Which TWO built-in Windows command-line commands can be used to list local user accounts? Choose two.

During a lateral movement assessment in an Active Directory environment, a penetration tester wants to verify if SMB signing is disabled on internal subnet hosts to assess vulnerability to NTLM relay attacks. Which TWO tools or methods can be used to identify systems with SMB signing disabled? Choose two.

An operator has compromised an Active Directory domain and wants to extract domain user password hashes without directly dumping LSASS memory on the Domain Controller. Which technique allows this from a machine with Domain Admin privileges?

A penetration tester is performing post-exploitation reconnaissance on a Linux machine. Which THREE files or directories should the tester examine to identify potential sensitive configuration data, credentials, or cron jobs? Choose three.

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Privilege Escalation Lateral Movement And Post Exploitation sessions

Start a Privilege Escalation Lateral Movement And Post Exploitation only practice session

Every question in these sessions is drawn from the Privilege Escalation Lateral Movement And Post Exploitation domain — nothing else.

Related practice questions

Related CPENT topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CPENT exam test about Privilege Escalation Lateral Movement And Post Exploitation?
Privilege Escalation Lateral Movement And Post Exploitation questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Privilege Escalation Lateral Movement And Post Exploitation questions in a focused session?
Yes — the session launcher on this page draws every question from the Privilege Escalation Lateral Movement And Post Exploitation domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CPENT topics?
Use the topic links above to move to related areas, or go back to the CPENT question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CPENT exam covers. They are not copied from any real exam or dump site.