Courseiva

GIAC Penetration Tester (GPEN) — Questions 76–150

298 questions total · 4pages · All types, answers revealed

Page 1

Page 2 of 4

Page 3
76
MCQmedium

During an internal penetration test, you gain access to a Windows workstation and discover that a domain user's password hash is cached in the registry. You extract the hash and want to crack it offline. Which Hashcat mode should you use to attack the cached domain credential?

A.Hashcat mode 1000 (NTLM)
B.Hashcat mode 5500 (NetNTLMv2)
C.Hashcat mode 3000 (LM)
D.Hashcat mode 2100 (Domain Cached Credentials 2, MS Cache 2)
AnswerD

MSCache v2 hashes are stored in the registry under SECURITY\Cache and are used for offline domain logon. Hashcat mode 2100 is specifically designed to crack these Domain Cached Credentials 2 hashes. Since the scenario involves a cached domain credential from a workstation, mode 2100 is the correct mode to use for offline cracking.

Why this answer

Cached domain credentials are stored as MSCache v2 hashes in the SECURITY registry hive. Hashcat mode 2100 is purpose-built to crack these hashes offline. Other modes target different hash types such as NTLM, LM, or NetNTLMv2, which are not applicable here.

Using the correct mode ensures efficient and successful cracking of the cached credential.

Exam trap

The trap here is confusing cached domain credentials with NTLM hashes stored in the SAM database, leading to the selection of an incorrect Hashcat mode.

77
MCQhard

An attacker has gained access to an Azure VM and wants to escalate privileges by abusing the VM's managed identity. The managed identity has the 'Contributor' role on the subscription. Which of the following actions would allow the attacker to add a new user to an Azure AD group that has 'Global Administrator' role?

A.The attacker cannot perform this action because the 'Contributor' role does not grant permissions to modify Azure AD groups.
B.Use the managed identity to assign the 'User Access Administrator' role to itself, then add the user to the group.
C.Use the managed identity to call the Microsoft Graph API and add the user to the group.
D.Use the managed identity to create a new service principal with 'Global Administrator' role, then use it to add the user.
AnswerA

The 'Contributor' role on a subscription allows management of Azure resources but not Azure AD objects. Adding a user to an Azure AD group requires Azure AD permissions, which the managed identity lacks. Therefore, the attacker cannot perform this action with the given role.

Why this answer

Azure RBAC roles like 'Contributor' grant permissions to manage Azure resources, not Azure AD objects. Adding a user to an Azure AD group is an Azure AD operation that requires directory permissions. The managed identity does not have these permissions, so the attacker cannot escalate privileges this way.

The attacker would need to find a different path, such as compromising an account with Azure AD admin roles.

Exam trap

The trap here is conflating Azure RBAC roles with Azure AD roles, assuming that 'Contributor' allows modification of Azure AD groups, which it does not.

78
MCQmedium

Refer to the exhibit. Why did the EternalBlue exploit attempt fail despite the scanner identifying the target as vulnerable?

A.The RHOSTS value is configured incorrectly
B.The exploit module requires an active session
C.The target environment rejected the payload execution
D.The listener port is already in use by another process
AnswerC

Even if the target is vulnerable, the exploit might fail due to environmental factors like antivirus, system stability, or specific patch levels not caught by the scanner. This is a common real-world failure mode where the vulnerability check passes, but the actual payload delivery or execution is blocked by security controls.

Why this answer

The exhibit shows the module successfully detected vulnerability but failed exploitation. This often occurs due to differences in the target's operating system build, unexpected memory protection, or a race condition where the service crashed during the initial check. In professional testing, this highlights the instability of kernel-level exploits.

Even if a target appears vulnerable, environmental variables like patches, antivirus interference, or DEP/ASLR settings can prevent the shellcode from executing correctly in memory.

Exam trap

Candidates often assume that a positive vulnerability scan guarantees successful exploitation, forgetting that runtime environmental factors like patches, AV, or memory protections can crash payloads.

79
MCQhard

Refer to the exhibit. What is the primary purpose of the Nmap Scripting Engine (NSE) in the context of the output provided, and how does it improve upon standard port scanning?

A.To increase the speed of the port discovery phase.
B.To perform deep inspection of application-layer services.
C.To bypass firewalls by using script-based obfuscation.
D.To convert TCP scans into more reliable UDP scans.
AnswerB

The NSE is designed to interact with services on an application level, such as sending HTTP requests or querying databases. This provides context beyond simple port status, allowing testers to confirm if a service is actually functioning and to gather metadata like site titles or server versions.

Why this answer

The NSE allows for automated discovery of application-layer information, such as page titles, service versions, and even vulnerability checks. While basic scanning identifies that a port is open, the NSE probes the service to extract actionable intelligence. This is vital for penetration testers who need to quickly identify the function and potential risks of a service without manually interacting with every discovered endpoint during a large-scale reconnaissance operation.

Exam trap

Candidates often assume NSE is only for vulnerability scanning, failing to recognize its broader utility in application-layer service enumeration, which provides deeper context than basic port status information.

80
MCQhard

Which THREE of the following are primary reasons why the NTLM authentication protocol is considered insecure for modern enterprise environments?

A.Lack of mutual authentication allows for relay attacks.
B.The NTLM hash format does not utilize a salt.
C.NTLM requires a connection to a Domain Controller for every login.
D.The protocol uses hard-coded encryption keys for every session.
E.NTLM hashes are vulnerable to pass-the-hash attacks.
AnswerA, B, E

NTLM does not require the server to prove its identity to the client. This architectural flaw enables attackers to capture a client's authentication challenge and relay it to another server, effectively masquerading as the user without ever having to crack the password or hash.

Why this answer

NTLM is inherently insecure because it is a challenge-response protocol that does not provide mutual authentication, making it susceptible to relay attacks. Furthermore, the NTLM hash is stored in a format that does not include a salt, allowing for the use of precomputed tables. Finally, because NTLM hashes are treated as the 'equivalent' of a password in many contexts, once stolen, they can be reused without needing to crack them.

Exam trap

Candidates often mistakenly believe NTLM is insecure primarily because it is 'too old'. The actual technical reasons involve its fundamental design flaws, specifically the lack of salting and lack of mutual authentication.

81
MCQhard

You are performing a penetration test against a target that is behind a firewall configured to drop all TCP packets except those destined for port 443. You need to determine whether the firewall is stateful or stateless to plan your attack. Which Nmap scan technique will best help you make this determination?

A.TCP connect scan (-sT)
B.TCP ACK scan (-sA)
C.TCP Xmas scan (-sX)
D.TCP FIN scan (-sF)
AnswerB

The TCP ACK scan sends ACK packets to target ports. A stateless firewall will typically pass ACK packets or drop them based on simple rules, while a stateful firewall will drop unsolicited ACK packets because they do not belong to an established connection. By comparing responses to ACK packets on allowed and disallowed ports, you can infer whether the firewall is stateful.

Why this answer

The ACK scan is specifically designed to map firewall rulesets and determine if a firewall is stateful. By sending ACK packets, which are not part of a connection establishment, a stateful firewall will drop them, while a stateless firewall may allow them through based on port rules. This difference in behavior reveals the firewall's nature.

Exam trap

The trap here is confusing stealth scans like FIN or Xmas with firewall state detection; only the ACK scan is intended to probe stateful filtering behavior.

82
MCQmedium

What is the primary risk associated with storing credentials in plain text within scripts or configuration files?

A.It increases the complexity of the password hashes.
B.It prevents the use of multi-factor authentication.
C.It allows an attacker to bypass authentication without cracking.
D.It triggers an alert in the Windows Event Logs.
AnswerC

If a script contains a cleartext password, an attacker who reads the file can immediately authenticate as the user or service account without the need for any complex cracking or relaying. This bypasses all authentication controls, providing direct access to whatever resources that account has been granted.

Why this answer

Storing cleartext credentials is a critical security failure because it provides an immediate, usable password to any attacker who gains read access to the file system. This often leads to lateral movement and privilege escalation because these scripts are frequently used by administrators to automate tasks across multiple servers. Identifying these files is a major component of any internal penetration test's post-exploitation phase.

Exam trap

Candidates often overthink the risk as 'data leakage' or 'compliance violation.' While true, the technical impact in a penetration test is the ability to bypass authentication entirely without needing to perform cracking.

83
MCQmedium

During the reconnaissance phase, you notice a target is using an older, unpatched version of a popular CMS. What is the most appropriate next step?

A.Immediately run a Metasploit exploit module against the server.
B.Research known CVEs for the identified version.
C.Contact the organization's IT department to report the vulnerability.
D.Ignore the CMS and look for other systems.
AnswerB

Researching specific CVEs for the identified CMS version allows the tester to understand the vulnerability's nature and impact. This information is crucial for planning a safe and effective exploitation strategy. It ensures that the subsequent testing phase is focused on valid attack vectors, minimizing the risk of unnecessary system downtime.

Why this answer

Identifying a vulnerable version of a CMS is a major reconnaissance success. The next step is to research known vulnerabilities (CVEs) associated with that version. This allows the tester to plan an exploit strategy without immediately running active, loud scans that might tip off the security team.

This measured approach ensures that the eventual attack is precise, efficient, and well-supported by prior intelligence gathering efforts.

Exam trap

Examinees often jump straight to exploiting or aggressively scanning the CMS, forgetting that the proper reconnaissance step is to research known CVEs first.

84
Multi-Selectmedium

Which TWO of the following are common indicators that a Windows system has been compromised with persistence?

Select 2 answers
A.Presence of unknown services running as SYSTEM.
B.Increased usage of the CPU by the system kernel.
C.Unexpected files in the AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup folder.
D.Changes to the system's desktop wallpaper.
E.A high number of failed login attempts in the event log.
AnswersA, C

Malware often installs itself as a service to ensure it runs with high privileges upon system startup. An unrecognized service running as SYSTEM is a major red flag that warrants immediate investigation, as it is a common method for achieving both persistence and privilege escalation on Windows servers.

Why this answer

Indicators of persistence in Windows include unusual entries in startup folders, unrecognized services set to auto-start, and suspicious registry keys. Monitoring these areas is standard procedure for incident response and threat hunting. Detecting these markers early allows defenders to disrupt the attacker's ability to maintain access, effectively ending the persistence phase and forcing the attacker to re-establish a foothold, which increases the likelihood of detection.

Exam trap

Candidates often look only for obvious malware files. They fail to recognize that legitimate-looking services or startup entries running as SYSTEM are the most reliable indicators of persistent compromise.

85
MCQmedium

A penetration tester has obtained the NTLM hash of a domain user and wants to authenticate to a remote server without cracking the password. Which of the following techniques allows the tester to use the hash directly for authentication?

A.Golden Ticket attack using the KRBTGT hash
B.Pass-the-Hash (PtH) using Mimikatz sekurlsa::pth
C.Kerberoasting to request a service ticket
D.Rainbow table lookup to recover the plaintext password
AnswerB

Pass-the-Hash leverages the NTLM hash to authenticate to remote services without knowing the plaintext password. Mimikatz's sekurlsa::pth command injects the hash into a new session, enabling access to SMB shares or other services that accept NTLM authentication. This is a core technique in penetration testing, as it bypasses the need to crack the hash.

Why this answer

Pass-the-Hash allows an attacker to authenticate using the NTLM hash without cracking it. Tools like Mimikatz can inject the hash into a session, enabling lateral movement or access to resources. Other options involve cracking or forging tickets, which are different attack vectors.

The scenario emphasizes using the hash directly, making Pass-the-Hash the correct technique.

Exam trap

The trap here is confusing Pass-the-Hash with other hash-based attacks like Kerberoasting or Golden Ticket, which require different prerequisites and have different goals.

86
Multi-Selectmedium

You are performing a Kerberoasting attack against a domain. After requesting service tickets for accounts with SPNs, you extract the tickets and attempt to crack them offline. Which two factors most directly determine the success of cracking these tickets? (Choose two.)

Select 2 answers
A.The number of service tickets requested
B.The domain functional level
C.The encryption type used for the service ticket
D.The physical location of the domain controller
E.The complexity and length of the service account's password
AnswersC, E

The encryption type (e.g., RC4_HMAC_MD5 or AES256_CTS_HMAC_SHA1_96) determines the speed and difficulty of cracking. RC4 tickets are encrypted with the service account's NTLM hash, which is faster to crack than AES tickets that use stronger key derivation. Therefore, the encryption type directly impacts the cracking success rate and time.

Why this answer

The success of cracking Kerberoasted tickets hinges on the encryption type and the service account's password strength. RC4 tickets are faster to crack than AES, and weak passwords are vulnerable to dictionary attacks. Other factors like number of tickets, domain functional level, or DC location do not affect the cryptographic difficulty of cracking.

Exam trap

The trap here is assuming that requesting more tickets or having a higher domain functional level improves cracking success, when actually only the encryption type and password strength matter.

87
MCQmedium

An attacker has obtained the NTLM hash of a service account. They want to perform a Kerberoasting attack to escalate privileges. Why is this specific hash insufficient for standard Kerberoasting?

A.The NTLM hash is insufficient because it cannot be used to request a Ticket Granting Ticket (TGT).
B.The NTLM hash is only useful for Pass-the-Hash attacks and cannot facilitate any Kerberos interactions.
C.Kerberoasting targets the service account's password hash by requesting a TGS, not by leveraging existing NTLM hashes.
D.The NTLM hash must first be converted to a Kerberos AES-256 key before a TGS request can be initiated.
AnswerC

Kerberoasting relies on the KDC encrypting a service ticket with the target service account's password. The attacker requests this ticket and then attempts to brute-force the password offline. Possessing the NTLM hash of the account does not provide the encrypted TGS blob needed for this specific offline cracking methodology.

Why this answer

Kerberoasting requires requesting a Service Ticket (TGS) from the Key Distribution Center (KDC) for a specific Service Principal Name (SPN). The attacker then extracts the encrypted TGS blob from memory or network traffic to crack the service account's password offline. The NTLM hash is a separate credential format; having it allows for Pass-the-Hash or silver ticket creation, but does not involve the KDC-based SPN request process required for Kerberoasting.

Exam trap

Candidates often conflate NTLM hash usage (Pass-the-Hash) with Kerberoasting, failing to realize Kerberoasting requires a TGS ticket request from the KDC, not just an existing hash.

88
MCQhard

You are planning a penetration test for a healthcare provider that must comply with HIPAA. The client wants to ensure that any protected health information (PHI) accessed during testing is handled securely. Which of the following is the MOST critical element to include in the data handling plan?

A.A schedule of testing activities to avoid peak business hours.
B.A list of all IP addresses and hostnames that are in scope for testing.
C.A detailed procedure for encrypting any extracted PHI and securely destroying it after the engagement.
D.A requirement that all testers sign a non-disclosure agreement (NDA) before testing begins.
AnswerC

Under HIPAA, PHI must be protected with appropriate administrative, physical, and technical safeguards. If testers extract PHI as proof of vulnerability, they must encrypt it in transit and at rest, and securely destroy it when no longer needed. This procedure directly addresses the confidentiality and security of PHI, making it the most critical element. It ensures compliance and reduces the risk of a data breach during the penetration test.

Why this answer

The most critical element is a procedure for encrypting extracted PHI and securely destroying it after the engagement. This directly addresses HIPAA requirements for protecting PHI and minimizes the risk of unauthorized disclosure. Other elements like NDAs, scope, and scheduling are important but do not provide the necessary technical safeguards for PHI encountered during testing.

Exam trap

The trap here is equating an NDA with adequate data protection, when HIPAA requires specific technical safeguards for PHI.

89
MCQmedium

During an internal penetration test, an attacker successfully captures an NTLMv2 challenge-response authentication exchange from a network segment. The adversary wishes to perform an offline brute-force cracking attack against the captured hash using Hashcat. Which specific Hashcat attack mode and hash format identifier must be specified to successfully crack this captured challenge-response pair?

A.Mode 1000, targeting local SAM database NTLM hashes.
B.Mode 1300, targeting legacy Windows NT hashes.
C.Mode 5600, targeting NetNTLMv2 network authentication captures.
D.Mode 3000, targeting LM hashes with challenge data.
AnswerC

Mode 5600 is engineered precisely for cracking NetNTLMv2 hashes gathered via protocol coercion or LLMNR poisoning. It correctly structures the username, domain, server challenge, client challenge, and response fields so Hashcat can execute the required HMAC-MD5 cryptographic validation loops during brute-forcing.

Why this answer

Hashcat mode 5600 specifically targets NetNTLMv2 authentication exchanges captured during network sniffing or LLMNR/NBT-NS poisoning attacks. Using the correct mode ensures Hashcat formats the challenge, username, domain, and response fields properly for structural verification and decryption. Selecting incorrect modes results in immediate errors or zero matches during computation, making accurate identification of authentication protocols a vital pentesting skill.

Exam trap

Candidates frequently confuse NTLM (mode 1000, representing the static password hash stored in the Active Directory database) with NetNTLMv2 (mode 5600, representing dynamic network authentication traffic), leading to failed offline attacks.

90
MCQeasy

A penetration tester is assessing an Azure environment and discovers a function app with an HTTP trigger that does not require authentication. The function app has a system-assigned managed identity with Contributor role on the subscription. What is the most immediate risk?

A.The function app's source code can be downloaded, revealing secrets and connection strings.
B.The function app's logs can be accessed, revealing sensitive information.
C.The function app can be used to send emails or messages, leading to spam or phishing.
D.The function app can be used to perform actions on any resource in the subscription, potentially leading to full subscription compromise.
AnswerD

With Contributor role on the subscription, the managed identity can create, modify, or delete any resource. Since the HTTP trigger is unauthenticated, anyone can invoke the function and have it perform actions using that identity. This could allow an attacker to escalate privileges, deploy malicious resources, or delete critical assets.

Why this answer

The unauthenticated HTTP trigger allows anyone to invoke the function. If the function's managed identity has Contributor role on the subscription, an attacker can use the function to execute actions with that identity, effectively gaining Contributor-level access to the entire subscription. This is a severe privilege escalation.

Exam trap

The trap here is focusing on data exposure like source code or logs instead of the direct privilege escalation enabled by the managed identity's high permissions.

91
MCQmedium

You are conducting a penetration test against a web application and have identified a potential SQL injection vulnerability in a login form. You want to confirm the vulnerability and extract the database schema without causing a denial of service. Which technique should you use to safely enumerate the database?

A.Out-of-band SQL injection using DNS exfiltration
B.Error-based SQL injection by forcing detailed error messages
C.Time-based blind SQL injection using heavy delays
D.Union-based SQL injection to retrieve schema information
AnswerD

Union-based SQL injection allows you to append a second query to the original and directly retrieve data in the application's response. It is efficient and does not require delays or error triggering. By crafting a UNION SELECT statement, you can extract database schema, table names, and column names quickly. This method is safe if the number of columns matches and the data types are compatible.

Why this answer

Union-based SQL injection is the most direct and efficient method to extract database schema when the application returns query results in its response. It allows the tester to retrieve multiple rows of data in a single request without relying on delays or error messages. This minimizes impact on the application's performance and reduces the risk of triggering defensive mechanisms.

Other techniques like time-based or out-of-band are used when union is not possible, but they are slower and can be more disruptive.

Exam trap

The trap here is assuming that any SQL injection technique is equally safe, when in fact time-based blind injection with heavy delays can cause performance issues and potential denial of service.

92
MCQhard

Which technique is most effective for exploiting a heap-based buffer overflow compared to a stack-based overflow?

A.Overwriting the return address on the stack.
B.Manipulating heap metadata to achieve write-what-where.
C.Using a simple NOP sled to reach the shellcode.
D.Increasing the size of the input string.
AnswerB

Heap management structures store critical information about memory blocks. By corrupting these headers, an attacker can trick the allocator into writing data to an arbitrary memory location. This 'write-what-where' primitive is the foundational goal of heap exploitation, allowing for sophisticated control over the application's execution flow.

Why this answer

Heap overflows are significantly more complex because they involve manipulating heap management metadata (like chunk headers) rather than simply overwriting a return address on the stack. Techniques like 'unlink' or 'house of force' are used to corrupt the heap structures to gain arbitrary write-what-where primitives. Understanding this distinction is vital, as stack-based knowledge does not directly transfer to the more intricate heap exploitation landscape required for modern applications.

Exam trap

Candidates often assume heap overflows can be exploited the same way as stack overflows by simply overwriting return addresses, ignoring complex chunk metadata.

93
MCQmedium

A penetration tester is conducting a vulnerability scan against a web application and notices that the scanner reports a critical SQL injection vulnerability on a page that does not accept user input. The tester manually verifies the page and finds no input fields or parameters. What is the most likely cause of this false positive?

A.The scanner is using an outdated vulnerability database.
B.The scanner is configured to perform blind SQL injection tests by injecting payloads into HTTP headers.
C.The scanner is using a safe checks policy that skips destructive tests.
D.The scanner is unable to authenticate to the web application.
AnswerB

Some scanners test for SQL injection by injecting payloads into HTTP headers such as User-Agent or Referer, even if the page has no user input. If the application logs these headers into a database without proper sanitization, the scanner might detect a vulnerability. This can cause a false positive if the page itself is not vulnerable but the logging mechanism is, or if the scanner misinterprets the response.

Why this answer

The most likely cause is that the scanner injects payloads into HTTP headers, which the application may log into a database. If the logging is vulnerable, the scanner could detect SQL injection even though the page itself has no input. This is a common source of false positives in web application scanning.

Other options do not explain why a false positive would occur on a page with no user input.

Exam trap

The trap here is assuming that a page with no input cannot be vulnerable, overlooking that scanners may test HTTP headers or other vectors that are not visible in the UI.

94
Multi-Selecthard

A penetration tester is preparing to crack a set of NTLM hashes obtained from a Windows domain controller. The tester wants to maximize the chances of recovering plaintext passwords. Which TWO of the following techniques are most effective for this goal? (Choose two.)

Select 2 answers
A.Employing a hybrid attack that combines a wordlist with a mask for appending digits.
B.Using a rule-based attack with Hashcat, such as best64.rule, to mutate a wordlist.
C.Using a distributed cracking setup with multiple GPUs to increase hash rate.
D.Performing a brute-force attack with a mask that covers all possible 8-character combinations.
E.Utilizing a precomputed rainbow table for NTLM hashes.
AnswersA, B

A hybrid attack merges dictionary words with a mask, such as appending two digits to each word. This is highly effective against passwords that follow common patterns like 'password123'. Since NTLM hashes are fast to compute, hybrid attacks can quickly test a large number of combinations derived from common words. This technique balances efficiency and coverage, making it a preferred method for penetration testers aiming to recover passwords within a reasonable timeframe. It targets the human tendency to use predictable variations.

Why this answer

Rule-based attacks and hybrid attacks are the most effective because they leverage common password patterns and mutations, which are prevalent in real-world environments. Rule-based attacks apply transformations to wordlists, while hybrid attacks combine words with masks to cover predictable suffixes like digits. Both methods efficiently target likely passwords without the impractical computational cost of full brute-force.

Distributed cracking only increases speed, not the likelihood of success, and rainbow tables are limited and outdated.

Exam trap

The trap here is assuming that brute-force or rainbow tables are the best approaches, when in fact targeted rule-based and hybrid attacks are far more efficient for recovering real-world passwords.

95
Multi-Selecthard

You are conducting passive reconnaissance against a target organization and want to identify internet-facing systems and services without sending any packets to the target's own IP space. Which two techniques best satisfy this requirement? (Choose two.)

Select 2 answers
A.Running an Nmap SYN scan with a low timing template against the target's external ranges
B.Reviewing historical WHOIS and ASN data to map the organization's owned netblocks
C.Using a web application scanner to crawl the target's public website for hidden directories
D.Performing DNS zone transfer attempts against each authoritative name server
E.Querying Shodan for the organization's netblock to review indexed banners and open ports
AnswersB, E

WHOIS and ASN records are public registries that document which netblocks an organization owns or leases. Reviewing them requires queries to registry databases, not to the target's IP space, so the activity remains passive. The resulting netblock map is essential for scoping later queries against third-party scan databases and for understanding the organization's internet footprint.

Why this answer

Querying Shodan leverages a third-party scan database that already collected banners and port states, and reviewing WHOIS and ASN registries maps owned netblocks through public records. Neither technique sends packets to the target's IP space, so both remain passive. Together they provide a service inventory and an address inventory, which are the core outputs needed for passive internet-facing reconnaissance.

Exam trap

The trap here is treating a zone transfer attempt as passive because it is a single DNS query, when it actually reaches the target's authoritative name servers.

96
Multi-Selectmedium

Which TWO of the following are characteristics of 'Salted' hashes compared to 'Unsalted' hashes?

Select 2 answers
A.They enable the use of rainbow tables.
B.They prevent the identification of identical passwords.
C.They are inherently faster to crack than unsalted hashes.
D.They require the salt to be known for successful cracking.
E.They are usually stored in cleartext in the configuration file.
AnswersB, D

With a unique salt per entry, two users with the same password will have completely different hashes stored in the database. This obscures the fact that they are using the same password, which is a major security benefit when a database is compromised, as attackers cannot easily spot patterns.

Why this answer

Salted hashes introduce a unique, random string to the hashing process for every user, ensuring that identical passwords result in different hashes. This makes it impossible to use global rainbow tables. Unsalted hashes are inherently vulnerable to these tables, as the same plaintext always produces the same hash, allowing for near-instant cracking of common passwords across an entire database once a single table is computed.

Exam trap

Candidates often confuse salting with hashing algorithms themselves, mistakenly believing that salting makes the hash itself impossible to reverse rather than specifically preventing the use of precomputed rainbow tables for cracking.

97
MCQhard

A penetration tester has obtained Domain Admin credentials during an internal engagement and wants to establish long-term persistence that survives a Domain Admin password reset and reboots. The tester needs a method that remains stealthy and does not rely on leaving a binary on disk. Which technique best meets these requirements?

A.Deploy a Golden Ticket by forging a Kerberos TGT using the krbtgt account hash.
B.Install a service on a domain controller that runs as Local System and starts automatically.
C.Create a new user account with Domain Admin membership and hide it from the default Users container.
D.Add an ACL to the Domain Admins group granting Full Control to a controlled user account.
AnswerA

A Golden Ticket is a forged TGT signed with the krbtgt account's NTLM hash. It remains valid until the krbtgt password is changed twice, so it survives normal Domain Admin password resets and reboots. Because it is generated on demand and not written to disk, it is stealthy and does not rely on a persistent binary, matching the scenario's constraints precisely.

Why this answer

A Golden Ticket is forged from the krbtgt hash and validated by the domain's Kerberos service until the krbtgt password is reset twice. This makes it resilient to Domain Admin password changes and reboots, and because it is generated on demand without a persistent binary, it is stealthier than account creation, new services, or ACL modifications. It directly satisfies the scenario's requirements.

Exam trap

The trap here is assuming that any Domain Admin-level access survives a password reset; only techniques tied to the krbtgt hash or similar secrets withstand that specific remediation.

98
Multi-Selecthard

Which THREE of the following are valid techniques for privilege escalation on a Linux system?

Select 3 answers
A.Exploiting a binary with the SUID bit set to root.
B.Configuring a new user account with no password.
C.Abusing sudo permissions that allow specific command execution as root.
D.Exploiting kernel vulnerabilities to gain root-mode execution.
E.Renaming the /etc/passwd file to /etc/shadow.
AnswersA, C, D

SUID binaries owned by root execute with root privileges. If the binary is vulnerable to buffer overflows or path injection, an attacker can hijack the execution flow to launch a root shell. This is a classic and highly effective privilege escalation path on many legacy Linux systems.

Why this answer

Privilege escalation involves exploiting misconfigurations to gain higher access. Common vectors include exploiting SUID binaries, abusing SUDO rules that allow commands to run as root without passwords, and exploiting kernel vulnerabilities that allow arbitrary code execution in kernel mode. Understanding these vectors is crucial for identifying how an unprivileged user can transition to root and maintain control over the compromised Linux infrastructure.

Exam trap

Candidates often choose standard user permission configurations or weak password policies, failing to recognize specific structural mechanisms like SUID and sudoers entries.

99
MCQmedium

Why is it important to perform reconnaissance from a non-attributable source during a penetration test?

A.To improve the speed of data transfer during scans.
B.To avoid triggering security alerts that block the tester's IP.
C.To bypass the need for explicit written authorization.
D.To increase the accuracy of vulnerability detection tools.
AnswerB

Organizations often monitor for scanning activity and blacklist source IPs associated with malicious behavior. By using non-attributable sources, the tester ensures that if one source is detected and blocked, the testing engagement can continue from another, thus preventing a single block from prematurely ending the reconnaissance phase.

Why this answer

Using non-attributable sources, such as a VPN or a compromised proxy, prevents the target from tracing reconnaissance activities back to the testing firm or the specific tester. This protects the anonymity of the test, ensuring that the target's security response is triggered based on the activity itself, rather than by blocking a known testing IP. This is essential for simulating a realistic threat actor's behavior and avoiding early detection.

Exam trap

Students mistakenly think non-attributable sources are meant to bypass encryption or increase scan speed, rather than protecting the tester's IP from being blocked by security alerts.

100
MCQeasy

In Metasploit, what is the significance of the 'LHOST' parameter when setting up a reverse shell?

A.It defines the target's listening port
B.It identifies the attacker's IP address for the callback
C.It is used to scan the local network
D.It defines the exploit's remote host target
AnswerB

LHOST is the essential configuration setting that dictates where the victim machine should send the reverse connection. If this is incorrect, the target will attempt to connect to the wrong address, and the listener will never receive the connection, resulting in a failed exploitation attempt during the test.

Why this answer

The LHOST parameter is the IP address of the attacker's machine. It tells the target machine where to send its callback once the payload is executed. Misconfiguring this is a common point of failure for beginners.

Ensuring the correct LHOST is set is critical for establishing a stable connection between the target and the penetration tester's workstation during the exploitation phase of the engagement.

Exam trap

Many students mistakenly identify LHOST as the target machine's IP address, failing to understand that LHOST is the attacker's IP where the listener is waiting for the callback.

101
MCQhard

Refer to the exhibit. You are currently at 17:15. You have just identified a critical, easily exploitable vulnerability on 10.1.1.20. What is the correct next step?

A.Continue testing until you have fully compromised the system.
B.Wait until 08:00 the next day to report the vulnerability.
C.Immediately report the finding using the emergency contact procedure.
D.Run a full vulnerability scan on the remaining hosts to finish early.
AnswerC

The 'Escalation' field identifies the emergency contact form as the correct reporting channel. Since the finding is critical, the tester must escalate it immediately, even though it is outside the standard testing window. This balances the need for adherence to testing hours with the urgency of a critical finding.

Why this answer

The defined 'Testing_Time' is 08:00 to 17:00. Performing actions outside this window is a violation of the Rules of Engagement. Given the finding is critical, the tester should halt further testing immediately and notify the client using the established 'Escalation' procedure.

This prevents unauthorized testing outside the agreed window while ensuring the critical risk is brought to the client's attention promptly, maintaining both compliance and security awareness.

Exam trap

Candidates often prioritize the vulnerability over the Rules of Engagement, continuing to test past the agreed-upon hours, which is a major compliance violation regardless of the finding's severity.

102
Multi-Selecthard

You have gained standard user execution rights on a hardened Windows 10 enterprise workstation and need to enumerate local privilege escalation vectors. Which TWO methods are most effective for identifying insecure file permissions or unquoted service paths? (Choose two)

Select 2 answers
A.Executing AccessChk from the Sysinternals suite to review discretionary access control lists on service executables.
B.Querying the root certificate store via PowerShell to check for untrusted root certification authorities.
C.Using Windows Management Instrumentation to query the Win32_Service class for executable paths containing spaces without quotes.
D.Inspecting the local security policy database using the auditpol utility to check account lockout thresholds.
E.Reviewing the Active Directory group policy object inheritance tree using the Resultant Set of Policy tool.
AnswersA, C

AccessChk allows efficient command-line auditing of DACLs on files, directories, and services. Identifying weak permissions where standard users hold write or modify rights on service binaries enables successful replacement of legitimate executables with malicious payloads.

Why this answer

Discovering unquoted service paths and vulnerable file permissions represents a foundational step in local Windows privilege escalation. Penetration testers leverage tools and native commands to locate binaries running with SYSTEM privileges that can be modified or hijacked, allowing arbitrary code execution upon service restart.

Exam trap

Candidates often try to manually inspect every file on the system. They miss the efficiency of using built-in tools like AccessChk or WMI to automate the discovery of common misconfigurations.

103
MCQmedium

You are planning a penetration test for a healthcare provider that must comply with HIPAA. The client wants to test a new patient portal hosted on AWS. During the kickoff meeting, the client's legal team asks how you will handle any protected health information (PHI) that you might encounter. Which of the following is the most appropriate action to take before testing begins?

A.Encrypt all test data at rest and in transit, and avoid accessing any real patient data by using synthetic records.
B.Sign a Business Associate Agreement (BAA) with the client and ensure your testing infrastructure is covered under it.
C.Obtain written authorization from the client's CEO and proceed with testing without additional agreements.
D.Conduct the test only after hours to minimize the risk of encountering live patient data.
AnswerB

A BAA is required under HIPAA whenever a covered entity shares PHI with a business associate, including a penetration tester. By signing a BAA, you contractually agree to safeguard PHI and are legally permitted to access it during testing. Ensuring your infrastructure is covered prevents gaps if data is stored or processed on your systems.

Why this answer

Under HIPAA, a penetration tester acting as a business associate must sign a BAA before accessing systems that may contain PHI. This agreement establishes permissible uses and safeguards for protected health information. Without it, the engagement could be non-compliant regardless of technical precautions.

Exam trap

The trap here is assuming that technical safeguards like encryption or synthetic data can substitute for the legal requirement of a Business Associate Agreement.

104
MCQhard

Refer to the exhibit. Given the output from Mimikatz, what is the most appropriate interpretation of the 'LM NTLM' value provided for the administrator account?

A.The hash is a salt-based hash requiring a rainbow table.
B.The value represents the plaintext password in hex format.
C.The hash can be used directly for Pass-the-Hash authentication.
D.The session has expired and the hash is now unusable.
AnswerC

In an NTLM authentication flow, the hash is the credential. If an attacker possesses the hash, they can present it to an authentication service, and the service will accept it as proof of identity. This bypasses the need to know the plaintext password entirely.

Why this answer

The exhibit displays a captured NTLM hash. In modern Windows environments, the 'LM' (LAN Manager) portion is often empty or disabled for security, leaving only the NTLM hash. The value shown is a hexadecimal representation of the NTLM hash, which acts as the equivalent of a password for authentication.

A penetration tester can use this specific string to perform a Pass-the-Hash attack without needing to crack it to plaintext.

Exam trap

Candidates often assume they must crack the hash to gain access. They fail to recognize that the NTLM hash itself is sufficient for authentication, making cracking an unnecessary and time-consuming step.

105
MCQeasy

A penetration tester is reviewing a captured NTLMv2 challenge-response pair and wants to crack it offline using Hashcat. Which Hashcat mode should the tester use to attack this specific hash type?

A.Hashcat mode 0 (MD5)
B.Hashcat mode 5600 (NetNTLMv2)
C.Hashcat mode 13100 (Kerberos 5 TGS-REP)
D.Hashcat mode 1000 (NTLM)
AnswerB

Hashcat mode 5600 is specifically designed for NetNTLMv2 (also called NTLMv2) challenge-response pairs captured from network traffic. It correctly parses the username, domain, server challenge, and response fields to perform an offline dictionary or brute-force attack. This is the correct mode because the scenario involves a captured challenge-response pair, not a raw NT hash. Using the wrong mode would result in errors or no cracks.

Why this answer

Hashcat mode 5600 is the correct choice because it is tailored for NetNTLMv2 challenge-response pairs, which are commonly captured during penetration tests. This mode understands the structure of the NTLMv2 response, including the server challenge and the HMAC-MD5 computation. Other modes target different hash types, such as raw NT hashes or Kerberos tickets, and would not correctly parse or crack the captured NTLMv2 data.

Using the right mode ensures efficient and successful cracking.

Exam trap

The trap here is confusing raw NT hashes (mode 1000) with network-captured NTLMv2 challenge-response pairs (mode 5600), as both relate to NTLM but require different cracking approaches.

106
MCQmedium

During an internal penetration test, you have compromised a Windows workstation and need to establish a covert channel that will survive network address translation and filtering. You decide to use the Domain Name System (DNS) TXT record for command and control. Which tool should you use to create a DNS tunnel that encapsulates IP traffic over DNS queries and responses?

A.iodine
B.dnscat2
C.dns2tcp
D.iodine-client
AnswerA

iodine is a DNS tunneling tool that encodes IPv4 data within DNS queries and responses, typically using NULL or TXT record types. It creates a virtual network interface (dns0) and can tunnel IP traffic through a DNS server you control. It is specifically designed for this purpose and is widely used in penetration testing to bypass captive portals and egress filtering.

Why this answer

The correct tool for encapsulating IP traffic over DNS is iodine. It creates a virtual network interface and tunnels IPv4 packets inside DNS queries and responses, effectively providing a VPN over DNS. This allows the attacker to bypass network restrictions that only allow DNS traffic.

Other tools like dnscat2 and dns2tcp provide C2 channels but do not encapsulate IP traffic.

Exam trap

The trap here is confusing DNS tunneling tools that provide command-and-control channels with those that encapsulate IP traffic, such as iodine.

107
MCQmedium

During an internal network penetration test, you capture NetNTLMv2 challenge-response hashes. You decide to perform a relay attack rather than cracking them offline. Which protocol characteristic makes SMB relaying feasible against a target host?

A.The target machine enforces mandatory SMB signing across all network shares.
B.The target machine has disabled SMB signing, allowing challenge-response reuse.
C.The user account used for authentication has a blank password stored.
D.Kerberos protocol is exclusively enforced for all domain controller communications.
AnswerB

Disabling SMB signing permits valid authentication responses captured from one victim machine to be forwarded directly to the target system. The target accepts the relayed session because it does not cryptographically verify the message origin or session keys.

Why this answer

SMB relaying succeeds when message signing is disabled on the target server, allowing an attacker to intercept authentication requests and forward them to another machine. GPEN candidates must understand that signing protects the integrity of SMB sessions. Without it, session hijacking and relaying become trivial threats within local area networks.

Exam trap

Candidates often confuse SMB signing with password hashing algorithms, assuming that stronger hashes like NTLMv2 prevent relay attacks automatically. However, hashing strength only protects against offline brute-forcing, not active network relaying.

108
Multi-Selecthard

You are performing a penetration test on a Linux system and have obtained a low-privileged shell. You want to escalate privileges by exploiting misconfigured file permissions. Which two of the following file permission scenarios are most likely to allow privilege escalation? (Choose two.)

Select 2 answers
A.A world-readable configuration file that contains database credentials.
B.A world-writable file in /etc/ that is not used by any service or cron job.
C.A directory with permissions 755 owned by root, containing a script that is executed by root.
D.A world-writable script that is executed by a root cron job.
E.A root-owned SUID binary that calls a system command without an absolute path.
AnswersD, E

A world-writable script executed by a root cron job is a classic privilege escalation vector. Since any user can modify the script, you can inject commands that will run as root when the cron job executes. This directly leads to privilege escalation. Defenders should ensure that scripts executed by privileged cron jobs are not writable by unprivileged users. This scenario is highly likely to allow escalation.

Why this answer

The two scenarios most likely to allow privilege escalation are a world-writable script executed by root cron and a root-owned SUID binary that calls a command without an absolute path. The former allows direct code injection as root, while the latter allows PATH manipulation to execute malicious code as root. The other options either do not provide direct escalation or lack a trigger mechanism.

Exam trap

The trap here is assuming that any world-writable file or sensitive information disclosure automatically leads to privilege escalation, but without a privileged process consuming it, it does not.

109
Multi-Selecthard

A penetration tester is planning a vulnerability scan of a network that includes legacy systems and IoT devices. The tester needs to minimize the risk of disrupting these fragile devices while still gathering useful vulnerability data. Which two actions should the tester take? (Choose two.)

Select 2 answers
A.Configure the scanner to throttle network traffic and reduce the number of concurrent hosts scanned.
B.Increase the scan's maximum number of concurrent checks per host to speed up the scan.
C.Enable 'Safe checks' in the scan policy to avoid tests that could cause denial-of-service.
D.Use a TCP SYN scan instead of a TCP connect scan to reduce the number of packets sent.
E.Disable host discovery and scan all IP addresses in the range.
AnswersA, C

Throttling and reducing concurrency lower the load on the network and target devices. This helps prevent overwhelming legacy systems and IoT devices, which may have low bandwidth or processing power. By pacing the scan, the tester can avoid disruptions while still collecting vulnerability data over a longer period.

Why this answer

Enabling safe checks and throttling network traffic are the two actions that directly reduce the risk of disrupting legacy systems and IoT devices. Safe checks avoid potentially harmful tests, while throttling and reduced concurrency prevent overwhelming devices with too much traffic. The other options either increase load, broaden the scan unnecessarily, or do not address the specific fragility of these devices.

Exam trap

The trap here is thinking that increasing concurrency or using a SYN scan will speed things up without considering the impact on fragile devices; the key is to throttle and use safe checks.

110
MCQeasy

When conducting a penetration test, why is it critical to assess the hashing algorithm used for storing passwords rather than focusing solely on the password policy itself?

A.Password policies are easily bypassed by users sharing credentials.
B.Weak algorithms allow rapid recovery of passwords once a breach occurs.
C.Passwords are always transmitted in plain text over the network.
D.The password policy is only effective for local accounts.
AnswerB

If the hashing algorithm is weak or lacks a salt, an attacker can crack the database in bulk regardless of the complexity enforced by the policy. A strong hashing algorithm acts as the final line of defense, rendering stolen hash files useless even when the database is fully compromised.

Why this answer

Even with a strong password policy, an organization remains vulnerable if the hashing algorithm is cryptographically broken or lacks proper salting. A weak algorithm like MD5 or NTLM allows attackers to crack even complex passwords almost instantaneously using modern hardware. Evaluating the hashing implementation ensures that the organization is protected against offline attacks, providing a necessary layer of defense that policies alone cannot guarantee if the underlying data storage mechanism is compromised.

Exam trap

Candidates often assume that if a password policy is sufficiently strict, the underlying hashing algorithm becomes irrelevant. They fail to realize that offline attacks bypass policy enforcement entirely by targeting stored hashes.

111
MCQmedium

Which of the following is a key advantage of using a 'Scheduled Task' for persistence on Windows systems?

A.They automatically bypass all firewall rules.
B.They allow for granular control over execution triggers.
C.They hide the task from the Task Scheduler GUI.
D.They are the only way to execute scripts at boot.
AnswerB

Scheduled tasks offer diverse triggers like system startup, user login, or specific time intervals. This granularity allows attackers to time their activity for periods of low system usage or to ensure their code runs reliably after reboots, maximizing the longevity of the persistent connection to the target system.

Why this answer

Scheduled tasks are highly configurable, allowing attackers to define specific triggers, user contexts, and repeat intervals. They are natively supported by Windows and appear as legitimate tasks, making them appear less suspicious than custom registry modifications. The ability to run tasks as SYSTEM or as a specific user provides attackers with flexibility in executing their payloads while maintaining a low profile within the system's management tools.

Exam trap

Candidates often think scheduled tasks are only for running things at specific times, failing to realize they offer granular control over triggers like idle time or network connectivity.

112
Multi-Selectmedium

When planning for an engagement involving sensitive data, which TWO of the following must be included in the data handling plan?

Select 2 answers
A.The encryption standards for data at rest and in transit.
B.The public keys of all developers involved in the project.
C.A secure, verifiable process for the destruction of client data.
D.The names of all servers used to store the data.
E.A list of all public websites the testers use for research.
AnswersA, C

Specifying the encryption standards ensures that the sensitive data collected during the test is protected from unauthorized access at all times. By documenting these standards, both the client and the tester agree on the security measures required to protect the information throughout the duration of the engagement.

Why this answer

Data handling is paramount when managing sensitive information during a penetration test. The tester must ensure that data is encrypted at rest and in transit, and that it is securely destroyed once the project concludes. These protocols protect the client from data breaches caused by the testing activity itself, maintaining the integrity and confidentiality of the sensitive information processed during the course of the engagement.

Exam trap

Test-takers frequently focus only on data collection during a pentest while forgetting the critical post-engagement requirement of secure data destruction.

113
MCQmedium

What is the primary objective of a 'Kerberos Armoring' (FAST) implementation?

A.To prevent the domain controller from logging failed authentication attempts.
B.To protect the initial authentication exchange from interception and modification.
C.To force all service accounts to use AES-256 encryption for tickets.
D.To bypass the need for a TGT during service authentication.
AnswerB

FAST (Flexible Authentication Secure Tunneling) establishes a secure tunnel between the client and the KDC for the AS-REQ/AS-REP exchange. This prevents attackers from sniffing credentials or tampering with the initial ticket request process, hardening the domain against several common Kerberos-based attacks.

Why this answer

Kerberos Armoring, or Flexible Authentication Secure Tunneling (FAST), protects the exchange between the client and the KDC by creating a secure, encrypted tunnel using a separate key. This protects the AS-REQ and AS-REP packets from interception and tampering, effectively neutralizing attacks that rely on sniffing or modifying the initial authentication traffic.

Exam trap

Test-takers often assume Kerberos Armoring is designed to encrypt ticket-granting service sessions or hide group memberships, missing its focus on the initial AS exchange.

114
Multi-Selectmedium

During a penetration test, you are performing passive reconnaissance against a target organization. You want to gather information about the organization's public-facing infrastructure without directly interacting with their systems. Which two of the following techniques are considered passive reconnaissance? (Choose two.)

Select 2 answers
A.Querying WHOIS databases for domain registration details
B.Performing a DNS zone transfer against the target's name server
C.Using Shodan to search for exposed services on the target's IP addresses
D.Browsing the target's public website and analyzing its content
E.Conducting a TCP SYN scan on the target's public IP addresses
AnswersA, C

Querying WHOIS databases is a passive technique because it retrieves information from third-party registries, not the target's systems. This can reveal registrar details, name servers, and contact information without alerting the target. It is a standard part of passive reconnaissance.

Why this answer

Passive reconnaissance involves gathering information without directly interacting with the target's systems. Querying WHOIS databases and using Shodan both rely on third-party data sources, so they do not send traffic to the target. In contrast, DNS zone transfers and TCP SYN scans directly interact with the target's infrastructure, making them active techniques.

Browsing a website, while often low-risk, still involves direct interaction and may be logged.

Exam trap

The trap here is thinking that any reconnaissance that doesn't use intrusive tools is passive; however, even a simple DNS query to the target's name server is active because it touches their infrastructure.

115
MCQhard

During a penetration test, a tester obtains a Kerberos TGS ticket for a service account and wants to crack it offline. The ticket is encrypted with RC4-HMAC. Which of the following best describes the primary reason this attack, known as Kerberoasting, is effective?

A.The TGS ticket contains the service account's plaintext password, which can be read directly from the ticket.
B.The TGS ticket is encrypted with the KRBTGT account's hash, allowing the attacker to forge golden tickets.
C.The TGS ticket is encrypted with the service account's NT hash, which can be cracked offline without contacting the domain controller.
D.The TGS ticket is signed with the domain's private key, which can be cracked to reveal the domain administrator's password.
AnswerC

Kerberoasting is effective because the TGS ticket is encrypted with the service account's NT hash (for RC4-HMAC). An attacker who requests a service ticket can extract it and attempt to crack the encryption offline, without further interaction with the domain controller. This allows stealthy password recovery. The scenario specifies RC4-HMAC encryption, which is particularly vulnerable because it uses the NT hash directly as the key, making it a prime target for offline cracking.

Why this answer

Kerberoasting works by requesting a TGS ticket for a service account with a registered SPN. The ticket is encrypted with the service account's NT hash, and because RC4-HMAC uses the NT hash directly as the encryption key, an attacker can extract the ticket and crack it offline. This avoids detection and does not require further domain controller interaction.

The other options misidentify the encryption key or the attack's goal, such as forging golden tickets or extracting plaintext passwords, which are not part of Kerberoasting.

Exam trap

The trap here is confusing Kerberoasting with Golden Ticket attacks, where the former targets service account TGS tickets encrypted with the service account's hash, while the latter forges TGTs using the KRBTGT hash.

116
MCQmedium

During a penetration test, you successfully dump the LSASS memory space and extract a set of NTLM hashes. Which of the following is the most efficient next step if the goal is to determine the plaintext password of a high-value administrator account?

A.Use the hashes to perform a Pass-the-Hash attack on every server.
B.Submit the hashes to an online cloud-based cracking service.
C.Run Hashcat with a combination of wordlists and mask attacks.
D.Reverse the MD4 algorithm to recover the original string.
AnswerC

Hashcat is the industry standard for offline cracking. By using dictionary files for common passwords and mask attacks for complexity patterns, a tester can efficiently find the password. This method is highly scalable and leverages GPU hardware to test millions of variations per second.

Why this answer

Once NTLM hashes are acquired, the most efficient method to recover the password is using an optimized GPU-based cracking tool like Hashcat. By employing a hybrid attack strategy—starting with a dictionary list supplemented by mask-based brute forcing—the tester can maximize the likelihood of recovering passwords that follow common corporate complexity patterns. This is significantly faster than manual analysis and allows for rapid testing against high-value target accounts.

Exam trap

Candidates often select manual analysis or basic dictionary attacks alone, overlooking the efficiency of hybrid wordlist and mask attacks executed via optimized GPU tools like Hashcat.

117
Multi-Selectmedium

Which TWO of the following methods are commonly used by attackers to achieve persistence on a Linux system via cron jobs?

Select 2 answers
A.Creating a new file in /etc/cron.d/ with an execution trigger.
B.Modifying the /etc/shadow file to grant root access.
C.Adding an entry to the crontab of a high-privilege service account.
D.Replacing the bash shell binary with a malicious version.
E.Setting a boot-time delay in the global /etc/environment file.
AnswersA, C

Files placed in /etc/cron.d/ are automatically parsed by the cron daemon. This is a common method for attackers to inject persistent tasks because it does not require modifying existing crontab entries, making it slightly more stealthy and easier to manage during the post-exploitation phase of an engagement.

Why this answer

Cron is a time-based job scheduler. Attackers utilize /etc/crontab or specific user crontabs to execute malicious scripts at defined intervals. This ensures that even if a session is terminated, the attacker's payload re-executes.

Monitoring cron directories and user-specific crontab files is essential for detection, as these are frequent targets for maintaining persistent access on Linux servers.

Exam trap

Candidates often assume cron persistence only involves modifying the user crontab. They overlook system-wide directories like /etc/cron.d/, which run as root and are frequently used for stealthy persistence.

118
MCQhard

You are conducting a penetration test and have gained access to a target's internal network. You want to perform reconnaissance to identify other live hosts and services without using traditional port scanning that might trigger IDS alerts. Which of the following techniques would be most effective for low-noise host discovery on the internal network?

A.TCP SYN scan using nmap
B.UDP scan using nmap
C.ARP scanning using arp-scan
D.ICMP ping sweep using fping
AnswerC

ARP scanning sends ARP requests to all IPs in a subnet. Since ARP is a Layer 2 protocol, it does not traverse routers and is not typically monitored by IDS. It is fast, accurate, and stealthy for discovering live hosts on the local subnet. This makes it ideal for low-noise internal reconnaissance.

Why this answer

ARP scanning is a Layer 2 technique that discovers live hosts by sending ARP requests. Since ARP is essential for local network communication, it is rarely filtered or monitored by IDS. This makes it a stealthy and effective method for internal host discovery.

The other techniques involve IP or TCP/UDP packets that can be detected or blocked, making them less suitable for low-noise reconnaissance.

Exam trap

The trap here is assuming that any scan with nmap is stealthy, but on a local network, ARP scanning is far less likely to trigger alerts than TCP or ICMP-based scans.

119
MCQhard

You are analyzing the results of a passive reconnaissance scan using a tool that harvests metadata from files found on a company website. What is the primary security risk associated with this information disclosure?

A.The files can be used to execute arbitrary commands on the client machine.
B.It discloses internal network naming conventions and software versions.
C.It indicates the current load on the corporate web server.
D.It bypasses the need for an external vulnerability assessment.
AnswerB

Metadata often contains fields like 'creator' or 'last modified by,' which can reveal internal usernames. Furthermore, the software version used to generate the file can indicate the patching level of the workstations. This provides attackers with concrete targets for crafting specialized phishing lures or identifying vulnerable software versions used internally.

Why this answer

Metadata in files like PDFs or Word documents often includes internal paths, printer names, software versions used for creation, and author usernames. This information is a goldmine for an attacker attempting to build a social engineering lure or profile the target's workstation environment. Understanding that reconnaissance extends beyond network headers to document analysis is a hallmark of an advanced penetration tester who understands holistic information leakage.

Exam trap

Test-takers frequently choose generic malware infection or data loss answers, missing that document metadata specifically exposes internal architecture naming conventions and software versions.

120
MCQeasy

What is the fundamental difference between Golden Ticket and Silver Ticket attacks?

A.Golden Tickets require communicating with the KDC, whereas Silver Tickets do not.
B.Golden Tickets target the domain controller, while Silver Tickets target user workstations.
C.Golden Tickets grant access to any service in the domain, while Silver Tickets only grant access to one service.
D.Silver Tickets are more powerful because they are harder to detect than Golden Tickets.
AnswerC

Golden Tickets are forged TGTs, acting as a master key for the domain. Silver Tickets are forged TGS tickets for a specific service. By using the service account's password hash, the attacker can only successfully authenticate to the service associated with that specific account.

Why this answer

The primary difference lies in the level of access and the secret used to forge the ticket. Golden Tickets use the KRBTGT hash to forge a TGT, granting access to any service in the domain. Silver Tickets use the service account hash to forge a TGS, granting access only to the specific service associated with that account.

Golden Tickets require a higher level of initial privilege to obtain the KRBTGT hash.

Exam trap

Candidates often confuse the scope of access, incorrectly assuming a Silver Ticket provides domain-wide admin access, whereas it is strictly limited to the specific service account's permissions.

121
MCQmedium

If a penetration tester discovers a vulnerability that could compromise a third-party hosted service during an engagement, what is the correct professional responsibility?

A.Contact the third-party service provider immediately to warn them.
B.Report the finding to the client and let them handle vendor disclosure.
C.Ignore the finding as it is outside the client's direct control.
D.Publish the finding on a public bug bounty site for remediation.
AnswerB

Reporting the vulnerability to the client is the correct path. It respects the contractual agreement and allows the client to handle their relationship with the third-party provider. This ensures that the client is aware of the risk and can manage their vendor dependencies effectively and legally.

Why this answer

The tester must report this finding only to the primary client, as they are the contractual entity. The tester should not contact the third-party provider directly, as this could violate the engagement's legal agreements. The client is responsible for coordinating with their third-party vendors.

Professional ethics require that testers respect the chain of command and the contractual structure established at the start of the engagement.

Exam trap

Candidates often feel compelled to notify the vendor directly, failing to realize that doing so likely violates the contractual agreement and bypasses the client's established communication and legal protocols.

122
MCQhard

Refer to the exhibit. What does the Nmap status 'open|filtered' indicate about the target port, and why does this result commonly occur in penetration testing scenarios?

A.The port is definitely open but the response was malformed.
B.The port is likely closed and the firewall is silently dropping traffic.
C.The port is likely open but the scanner is not receiving a clear response.
D.The port is definitely filtered and the service is unreachable.
AnswerC

This result occurs when Nmap sends a probe and receives no response. It could be that the port is open and the service is not replying, or that a firewall is filtering the traffic. The lack of feedback prevents Nmap from giving a definitive status, creating a state of uncertainty.

Why this answer

The 'open|filtered' state means Nmap cannot determine if the port is open or filtered. This happens when the port sends no response to a probe, which is typical behavior for firewalls that drop packets rather than rejecting them. Understanding this distinction is critical for testers, as it implies that the port might be open but protected, necessitating further probing to determine the true state of the service behind the security boundary.

Exam trap

Candidates often assume 'open|filtered' means the port is definitely open, ignoring that it is an indeterminate state caused by dropped packets, which prevents Nmap from confirming the port's true status.

123
MCQhard

You have identified an SUID binary on a Linux system that executes a shell command without using an absolute path. What is the most effective way to exploit this for privilege escalation?

A.Overflow the buffer of the binary.
B.Modify the PATH variable to point to a malicious directory.
C.Use LD_PRELOAD to inject a shared object.
D.Inject arguments into the binary.
AnswerB

By prepending a user-controlled directory to the PATH variable, the system searches the attacker's directory first. If the binary calls 'date' and the attacker has placed a malicious file named 'date' in their directory, the system executes the malicious file with the privileges of the SUID binary.

Why this answer

When a binary calls a command without an absolute path, it relies on the PATH environment variable to locate the executable. By modifying the PATH to include a directory under the attacker's control, the attacker can place a malicious executable with the same name as the target command. This forces the SUID binary to execute the malicious file instead of the intended system utility, resulting in command execution as the owner.

Exam trap

Candidates often try to exploit missing absolute paths by changing ownership of the binary or attempting direct code injection, forgetting that manipulating the PATH environment variable is the standard vector.

124
MCQhard

You are scanning a target from a host on the same Ethernet segment. You run 'nmap -sS -p 445 192.168.1.50' and receive a response indicating the port is open. You then run the same scan from a different subnet across a router and receive no response at all, even though the service is confirmed running. Which statement best explains this difference?

A.The SYN scan relies on receiving a RST or SYN/ACK, but the router may be filtering or dropping the return traffic, causing the port to appear filtered from the remote subnet.
B.The -sS scan requires the --send-eth option when crossing subnets, otherwise Nmap uses IP packets that routers cannot forward.
C.Nmap SYN scans only work on the local subnet because they require layer-2 adjacency to receive responses.
D.A firewall or ACL between the subnets is blocking TCP/445, so the SYN packets never reach the target or the responses never return, resulting in a filtered or no-response state.
AnswerD

When the same service responds locally but not across a router, the most likely explanation is an intermediate firewall or ACL dropping TCP/445. The scan itself is valid; the network path is filtering the probe or its response, which is why the port appears filtered or unreachable from the remote subnet.

Why this answer

The discrepancy between local and remote scan results points to a network-level filter rather than a scanning limitation. SYN scans are routable, so when TCP/445 is reachable on the LAN but silent across a router, an intermediate firewall or ACL is the most probable cause of the filtered result.

Exam trap

The trap here is blaming the scan type for a routing or filtering issue, when SYN scans work fine across routers and the real cause is usually an intermediate firewall or ACL.

125
Multi-Selecthard

You have obtained a Meterpreter session as a standard user on an Ubuntu 20.04 server during an authorized penetration test. You want to identify reliable local privilege escalation vectors. Which two findings most directly indicate a path to root? (Choose two.)

Select 2 answers
A.The /etc/hosts file is writable by the standard user account you compromised.
B.A systemd service unit that runs a script located in /opt/backup, and the /opt/backup directory is world-writable.
C.The sudoers file grants the account the right to run /usr/bin/find with the NOPASSWD tag.
D.The target runs an SSH server on port 22 that permits password authentication for all local accounts.
E.The host has an outdated OpenSSL library version recorded in the package manifest.
AnswersB, C

A service unit that executes a script from a world-writable directory lets any local user replace that script with arbitrary code. Because the service runs as root under systemd, the replacement executes with root privileges on the next service start or restart. This is a direct and reliable escalation path from a standard user to root on the host.

Why this answer

Two findings give direct root: a root-run service executing a script from a world-writable directory, allowing script replacement, and passwordless sudo for find, whose -exec flag spawns arbitrary commands. Both convert standard user access into root on the same host. The remaining findings are hygiene or lateral-movement issues that do not, by themselves, elevate privileges locally.

Exam trap

The trap here is treating any writable file or outdated package as an escalation, when only writable paths reachable by a root-owned execution context or sudo rights with command-injection flags actually yield root.

126
MCQmedium

During a penetration test against an Active Directory environment, you extract the NTLM hash of a domain user from a memory dump. You attempt to crack it with Hashcat using mode 1000 but fail after several hours. You suspect the password is longer than 12 characters and contains symbols. Which adjustment to your cracking strategy is most likely to succeed within a reasonable timeframe?

A.Switch to a rule-based attack using the best64.rule with a large wordlist.
B.Utilize a rainbow table specific to NTLM hashes.
C.Perform a combinator attack using two separate wordlists of common passwords.
D.Use a mask attack with a custom charset targeting the estimated length and character set.
AnswerD

A mask attack allows you to define the exact length and character set, drastically reducing the keyspace compared to a full brute-force. If you have intelligence suggesting the password is at least 13 characters and includes symbols, a mask attack focusing on that length and charset can be feasible, especially with optimized hardware. It directly targets the suspected structure without wasting time on shorter or simpler candidates.

Why this answer

The password is suspected to be long and complex, so a targeted mask attack that specifies the exact length and character set is the most efficient use of cracking resources. Rule-based and combinator attacks rely on existing wordlists and transformations, which may not cover the required length and symbol diversity. Rainbow tables are infeasible for such a large keyspace.

Thus, the mask attack is the best choice.

Exam trap

The trap here is assuming that any rule-based or hybrid attack will eventually hit a long complex password, when in reality the keyspace explosion makes mask attacks the only practical option when length and charset are known.

127
MCQeasy

A healthcare client hires your team for an internal penetration test. During the kickoff meeting, the client's compliance officer asks which document formally defines the specific systems, time windows, and testing techniques that are authorized for the engagement. Which document should you reference?

A.The Statement of Work
B.The master services agreement
C.The Rules of Engagement
D.The Non-Disclosure Agreement
AnswerC

The Rules of Engagement is the governing document that specifies authorized targets, testing windows, allowed techniques, emergency contacts, and handling of sensitive findings. It translates the Statement of Work into operational boundaries. For a healthcare client with compliance concerns, the Rules of Engagement provides the auditable record that testing stayed within agreed limits, satisfying both legal and regulatory expectations.

Why this answer

The Rules of Engagement is the document that operationalizes the engagement by listing authorized targets, permitted techniques, testing windows, escalation contacts, and data handling requirements. It bridges contractual documents like the Statement of Work and the actual execution of testing, giving compliance and legal stakeholders a clear, auditable definition of what is and is not allowed.

Exam trap

The trap here is confusing high-level contractual documents such as the Statement of Work or master services agreement with the operational Rules of Engagement that actually govern testing boundaries.

128
MCQmedium

When using Metasploit to perform a vulnerability scan, which module type should be selected?

A.Exploit modules
B.Auxiliary modules
C.Post-exploitation modules
D.Payload modules
AnswerB

Auxiliary modules are the correct choice for non-intrusive tasks like port scanning, service enumeration, and vulnerability identification. They provide a safe and effective way to gather information about the target environment without the risk of triggering an unintended exploitation attempt, which is essential for professional and methodical penetration testing engagements.

Why this answer

Metasploit includes auxiliary modules specifically designed for scanning, reconnaissance, and enumeration. These modules do not necessarily exploit a vulnerability but rather test for their presence or collect information about the target environment. Being proficient with these is crucial for the early reconnaissance phase of a penetration test, allowing the tester to map the target network and identify potential entry points before attempting to launch more invasive exploit modules.

Exam trap

Candidates often confuse Metasploit exploit modules with auxiliary modules, incorrectly thinking that exploitation is always required to scan networks or enumerate services during the initial reconnaissance phase.

129
MCQhard

A penetration tester captures a NetNTLMv2 hash from a network segment using Responder. The tester wants to crack this hash using Hashcat. Which Hashcat mode should be used?

A.2500
B.1000
C.13100
D.5600
AnswerD

Hashcat mode 5600 is specifically for NetNTLMv2 hashes. NetNTLMv2 is the challenge-response protocol used in NTLMv2 authentication, and captured hashes from tools like Responder are in this format. Using mode 5600 ensures Hashcat correctly parses the hash and applies the appropriate cracking algorithm, which involves HMAC-MD5 operations.

Why this answer

NetNTLMv2 hashes captured from network traffic require Hashcat mode 5600. This mode is tailored to the NetNTLMv2 challenge-response format, which uses HMAC-MD5. Other modes correspond to different hash types: 1000 for NTLM, 2500 for NetNTLMv1, and 13100 for Kerberos TGS-REP.

Using the correct mode is essential for successful cracking.

Exam trap

The trap here is assuming all NTLM-related hashes use the same Hashcat mode, but NetNTLMv2, NTLM, and NetNTLMv1 each have distinct modes.

130
MCQhard

A penetration tester is using Nmap with the NSE script 'vulners' to identify vulnerabilities on a target. The scan returns a list of CVEs for detected services, but the tester notices that some CVEs have a low confidence score. What is the MOST accurate interpretation of these low-confidence findings?

A.They indicate that the CVE is not in the NVD database and is therefore invalid.
B.They indicate that the vulnerability is likely a false positive and should be ignored.
C.They are potential matches based on version correlation and should be manually verified before reporting.
D.They represent vulnerabilities that require authentication to exploit and are therefore lower risk.
AnswerC

The vulners NSE script correlates detected service versions with CVE databases. A low confidence score means the match is approximate, often due to version string ambiguity or missing patch information. These findings are leads that require manual verification, such as checking the exact build or testing the vulnerability, before being included in a report.

Why this answer

Low confidence in vulners output signals an approximate version-to-CVE match. Because service banners can be incomplete or versions backported, the script cannot be certain the vulnerability exists. The correct response is to treat these as potential findings and manually verify the service's exact version and patch state before reporting.

This avoids both false positives and false negatives.

Exam trap

The trap here is equating low confidence with false positive, when it actually means the version match is uncertain and needs verification.

131
Multi-Selecthard

During a penetration test, you have identified a Windows domain controller with SMB signing disabled and obtained valid domain user credentials. You want to perform a relay attack to gain administrative access to multiple hosts. Which two conditions are necessary for a successful SMB relay attack? (Choose two.)

Select 2 answers
A.The attacker must have administrative credentials on the domain controller.
B.The target hosts must have the same local administrator password.
C.SMB signing must be disabled on the target hosts.
D.The attacker must be able to intercept and relay authentication attempts from a privileged user.
E.The attacker must have a valid NTLM hash for a domain administrator.
AnswersC, D

SMB signing must be disabled on the target hosts for a relay attack to succeed, as signing prevents tampering with relayed authentication. If signing is enabled, the attacker cannot relay the authentication to another service. This condition is critical for the attack to work, making it a necessary requirement.

Why this answer

The necessary conditions for a successful SMB relay attack are that SMB signing is disabled on the target hosts and that the attacker can intercept and relay authentication from a privileged user. These two factors allow the attacker to forward authentication to a target and gain access as that privileged user. Other options are either not required or describe different attack techniques.

Exam trap

The trap here is confusing SMB relay with pass-the-hash or assuming that administrative credentials are needed upfront, when the attack actually relies on relaying live authentication from a privileged user.

132
MCQhard

During a penetration test, an operator compromises a workstation where a domain administrator has an active logon session. The operator wants to extract the domain administrator's Kerberos TGT from LSASS and reuse it to access other systems without knowing the administrator's password. Which of the following techniques is specifically designed for this purpose?

A.Kerberoasting by requesting service tickets for SPNs associated with the domain administrator account.
B.Silver Ticket creation by forging a service ticket with the domain administrator's NTLM hash.
C.Pass-the-Ticket using tools such as Mimikatz's sekurlsa::tickets /export and kerberos::ptt.
D.Overpass-the-Hash using Mimikatz's sekurlsa::pth with the administrator's NTLM hash.
AnswerC

Pass-the-Ticket extracts a valid Kerberos ticket (including a TGT) from LSASS using sekurlsa::tickets and injects it into the current logon session with kerberos::ptt. This allows the operator to authenticate as the administrator to other services without the password or hash, directly satisfying the scenario's requirement of reusing the captured TGT.

Why this answer

Pass-the-Ticket is the technique that extracts and reuses a Kerberos ticket from a compromised host. When a domain administrator has an active session, their TGT resides in LSASS and can be exported and injected into another session. This grants the operator the administrator's access without needing the password or hash, perfectly matching the scenario's constraints.

Exam trap

The trap here is assuming that any Kerberos attack requires the account's password or hash; Pass-the-Ticket instead reuses a ticket already present in memory.

133
MCQhard

During a penetration test, an operator captures a network authentication attempt using the NTLMv2 protocol. The operator wants to crack the captured challenge-response offline using Hashcat. Which hash mode should the operator select to correctly process the captured NetNTLMv2 hash?

A.5600
B.5500
C.13100
D.1000
AnswerA

Hashcat mode 5600 is specifically designed for NetNTLMv2 hashes. These hashes are captured from network authentication attempts and consist of the username, domain, server challenge, and the HMAC-MD5 response. Selecting this mode ensures Hashcat correctly parses the format and applies the appropriate cracking algorithm. Using any other mode would result in errors or incorrect cracking attempts.

Why this answer

NetNTLMv2 hashes require Hashcat mode 5600. This mode is optimized for the NetNTLMv2 challenge-response format, which includes the username, domain, server challenge, and HMAC-MD5 response. Using the correct mode is essential for successful offline cracking.

Other modes correspond to different hash types and will not work with NetNTLMv2 captures.

Exam trap

The trap here is confusing NetNTLMv1 and NetNTLMv2 hash modes, as both are network authentication hashes but require different Hashcat modes.

134
MCQmedium

When mapping a target's network infrastructure, why is it important to use multiple WHOIS and regional internet registry (RIR) databases?

A.To increase the speed of the DNS resolution process.
B.To bypass the need for an active port scan.
C.To identify all netblocks owned by the target organization.
D.To automatically detect if a server is running an exploit.
AnswerC

Organizations often own IP ranges registered under different regional authorities depending on their global footprint. Using multiple WHOIS databases allows the tester to aggregate these records and build a complete picture of the organization's publicly registered network assets, which is essential for ensuring comprehensive testing of all in-scope infrastructure.

Why this answer

Different RIRs manage different geographic segments of IP address space. Relying on a single database may result in an incomplete mapping of the organization's network assets. By aggregating data from various sources like ARIN, RIPE, or APNIC, a tester ensures a more accurate inventory of the target's netblocks.

This reconnaissance step is critical for defining the scope of the assessment and identifying infrastructure that might be hosted by third-party providers.

Exam trap

Students often assume WHOIS is used for finding domain names or DNS records, losing sight of the fact that multiple RIR databases are queried specifically to locate all netblocks.

135
MCQeasy

You have a shell as www-data on an Ubuntu 20.04 web server and notice a cron job that runs every minute as root executing a script located in /opt/backup/run.sh. The script is writable by the www-data user. What is the most direct way to escalate privileges in this situation?

A.Change the permissions on /bin/bash to SUID root so any user can spawn a privileged shell
B.Append a reverse shell command to run.sh so the next cron execution spawns a root shell back to your listener
C.Use the writable script to add www-data to the sudoers file and then run sudo su
D.Replace run.sh with a symbolic link to /etc/passwd so cron overwrites the password file with a new root entry
AnswerB

Because the cron job executes the script as root every minute and the file is writable by www-data, modifying its contents means your injected commands run with root privileges at the next scheduled interval. Appending a reverse shell payload is a direct, reliable escalation path that requires no exploit or kernel vulnerability.

Why this answer

When a root-owned cron job executes a script that a lower-privileged user can write to, the attacker effectively controls code that will run as root. Appending a reverse shell to that script is the simplest and most reliable escalation, since it leverages the scheduler's existing root context rather than requiring a separate vulnerability.

Exam trap

The trap here is overcomplicating the path with symlink or SUID tricks when direct modification of the root-executed script already yields code execution as root.

136
Multi-Selecthard

A financial services client engages you for an external penetration test and wants contractual protection before testing begins. Which TWO items belong in a master services agreement or statement of work to limit the firm's legal exposure while authorizing the work? (Choose two.)

Select 2 answers
A.A signed authorization and consent to test that identifies the in-scope assets and the permitted time window.
B.A get-out-of-jail-free authorization letter signed only by the tester's project manager.
C.A limitation of liability clause that caps damages and excludes consequential losses for both parties.
D.A confidentiality clause that allows the tester to publish anonymized findings at will.
E.A verbal agreement recorded in meeting minutes that testing may proceed as discussed.
AnswersA, C

A signed authorization naming the in-scope assets and time window is the core legal instrument that distinguishes authorized testing from unauthorized access. It establishes the client's consent, bounds the activity to specific systems and hours, and is the first document an investigator or court examines when testing activity is questioned, making it essential contractual protection.

Why this answer

Legal protection for a penetration engagement rests on a signed authorization that identifies in-scope assets and permitted testing windows, paired with a limitation of liability clause that caps damages and excludes consequential losses. Together they establish consent and bound financial exposure. One-sided letters, publication rights, and verbal permissions do not create enforceable authority or meaningful risk transfer.

Exam trap

The trap here is treating any written or verbal nod from the client as sufficient authorization, when only a signed, asset-specific consent document actually establishes lawful authority to test.

137
Multi-Selectmedium

Which TWO of the following password cracking techniques are considered 'offline' attacks?

Select 2 answers
A.Brute-forcing an SSH service via an internet-facing portal.
B.Running a dictionary attack against a SAM database file.
C.Spraying common passwords against an O365 login portal.
D.Attacking an NTLM hash dump using Hashcat.
E.Phishing users to submit credentials into a fake form.
AnswersB, D

Accessing the SAM database file directly allows for offline processing. Since the cracking happens entirely on the tester's machine, there is zero network interaction with the target, thus preventing account lockouts, avoiding detection by intrusion detection systems, and allowing for massively parallelized computation using high-end GPU hardware.

Why this answer

Offline attacks involve obtaining a copy of the password hashes and processing them on the attacker's own hardware. This is stealthy as it avoids account lockout policies and audit logging generated by failed login attempts on the target system. Understanding the distinction between online and offline attacks is vital for penetration testers to choose methods that minimize detection while maximizing the probability of successful credential recovery within a controlled and limited engagement timeframe.

Exam trap

Candidates often misclassify spraying attacks or brute-force logins against active services as offline attacks, confusing interactive network authentication with local hash cracking.

138
MCQhard

During an engagement, a penetration tester obtains a password hash that starts with `$2y$10$`. The client's security policy requires passwords to be at least 12 characters and include complexity. The tester wants to crack the hash using a rule-based attack. Which Hashcat mode should be used, and what is the primary advantage of this hash format?

A.Mode 1000 (NTLM), and the advantage is that it is the default Windows hash format, making it widely applicable.
B.Mode 3200 (bcrypt), and the advantage is that the cost factor makes brute-force attacks significantly slower.
C.Mode 500 (md5crypt), and the advantage is that it is fast to compute, allowing more guesses per second.
D.Mode 1800 (sha512crypt), and the advantage is that the salt prevents rainbow table attacks.
AnswerB

The `$2y$` prefix indicates bcrypt, and the `10` is the cost factor (2^10 iterations). Hashcat mode 3200 is correct for bcrypt. The cost factor increases the computational effort per guess, making brute-force and rule-based attacks much slower. This is the primary defensive advantage of bcrypt, and the tester must account for it when planning the attack.

Why this answer

The hash prefix `$2y$10$` is characteristic of bcrypt, with the cost factor 10. Hashcat mode 3200 is designed for bcrypt. The cost factor exponentially increases the number of iterations, making each guess computationally expensive.

This slows down brute-force and rule-based attacks, which is the main security benefit. A penetration tester must recognize this and adjust expectations for cracking speed and time.

Exam trap

The trap here is confusing bcrypt's cost factor with a simple iteration count, leading to underestimating the time required for cracking.

139
MCQeasy

Which of the following describes the purpose of using Google Dorks during the reconnaissance phase of a penetration test?

A.To bypass the target organization's firewall.
B.To identify publicly exposed sensitive files or directories.
C.To execute remote code on the target's web server.
D.To perform a brute-force attack on user credentials.
AnswerB

Google Dorks utilize specific search operators like 'filetype:' or 'inurl:' to locate files like PDFs, spreadsheets, or configuration backups that were accidentally indexed. This helps in identifying sensitive information exposure, such as directory listings or login pages, without ever interacting directly with the target server's network infrastructure.

Why this answer

Google Dorks are advanced search operators that allow testers to find sensitive information inadvertently indexed by search engines. This is a powerful form of passive reconnaissance that requires no interaction with the target infrastructure. By finding publicly exposed configuration files, logs, or login portals, testers can gain valuable intelligence.

Mastering these operators is a fundamental skill for finding 'low hanging fruit' that often gets overlooked by automated scanning tools.

Exam trap

Test-takers frequently confuse active vulnerability scanning with passive Google Dorking, assuming search operators directly exploit systems rather than merely identifying exposed files and directories.

140
MCQmedium

A penetration tester needs to scan a large enterprise network for vulnerabilities but has only a short maintenance window. The tester wants to maximize scan coverage while minimizing the impact on production systems. Which Nessus scan policy setting should the tester adjust to balance speed and accuracy?

A.Enable 'Safe checks' to prevent denial-of-service conditions.
B.Increase the 'Max concurrent checks per host' value.
C.Disable 'Thorough tests' to reduce scan time.
D.Adjust the 'Performance' settings to use a 'Custom' scan with optimized timeouts and throttling.
AnswerD

Custom performance settings allow fine-tuning of timeouts, throttling, and concurrent checks to balance speed and accuracy. This enables the tester to complete the scan within the window while reducing false negatives caused by timeouts. It is the most flexible approach to meet both coverage and impact constraints in a production environment.

Why this answer

The correct answer involves adjusting performance settings to a custom configuration. This allows the tester to optimize timeouts, throttling, and concurrency to complete the scan within the maintenance window while maintaining sufficient accuracy. Other options either focus solely on safety, risk disruption, or reduce coverage, failing to balance speed and accuracy as required.

Exam trap

The trap here is assuming that enabling 'Safe checks' or increasing concurrency alone will balance speed and accuracy, when in fact a custom performance profile is needed for fine-grained control.

141
MCQeasy

You are performing a penetration test and need to identify all live hosts on a subnet without performing a port scan. Which Nmap command should you use to accomplish this?

A.nmap -sS 192.168.1.0/24
B.nmap -sn 192.168.1.0/24
C.nmap -sV 192.168.1.0/24
D.nmap -sU 192.168.1.0/24
AnswerB

The -sn option tells Nmap to perform host discovery only, without port scanning. It sends probes like ICMP echo, TCP SYN to port 443, TCP ACK to port 80, and ICMP timestamp to determine if hosts are up. This is exactly what is needed to identify live hosts on a subnet without scanning ports.

Why this answer

The -sn flag is specifically designed for ping scans, also known as host discovery. It instructs Nmap to send discovery probes and report which hosts are up, without proceeding to port scanning. This meets the requirement of identifying live hosts on a subnet while avoiding unnecessary port scans.

Exam trap

The trap here is selecting a scan type that includes port scanning, such as -sS or -sU, when only host discovery is needed.

142
MCQeasy

Which term best describes the stage of a cyberattack where a compromised host signals a remote server to request instructions or transmit stolen data?

A.Privilege escalation
B.Command and control
C.Reconnaissance
D.Log clearing
AnswerB

Command and control is the industry-standard term for the maintenance of a communication channel between a compromised asset and an external adversary. This phase allows the attacker to maintain presence, send operational commands, and monitor the progress of their mission within the target environment.

Why this answer

The command and control (C2) phase represents the ongoing communication channel between the attacker's infrastructure and the compromised system. It is the tactical link that allows the adversary to remotely manage the infection, deploy additional tools, and exfiltrate information. Recognizing C2 traffic is fundamental to incident response because it is the primary vector for controlling the adversary's actions within the network environment.

Exam trap

Examinees often confuse the command and control phase with initial access, lateral movement, or data exfiltration, missing the definition of ongoing management communication.

143
MCQmedium

During an internal penetration test of a hybrid Microsoft Entra ID environment, you compromise a standard on-premises user account. You notice that the account's on-premises userPrincipalName is jdoe@corp.local, but the corresponding cloud account has the userPrincipalName jdoe@corp.com. Which attribute should you modify on-premises to change the cloud sign-in address for this synchronized user?

A.sAMAccountName
B.proxyAddresses
C.mail
D.userPrincipalName
AnswerD

The userPrincipalName attribute in the on-premises directory is synchronized to Microsoft Entra ID as the user's sign-in name, provided the domain is verified. Changing it to match the desired cloud UPN (e.g., jdoe@corp.com) will update the cloud userPrincipalName after synchronization. This is the correct attribute to modify to control the cloud sign-in address.

Why this answer

In a hybrid Microsoft Entra ID environment, the on-premises userPrincipalName attribute is synchronized to the cloud as the user's sign-in name, provided the domain is verified. Changing this attribute to the desired cloud UPN will update the cloud sign-in address after synchronization. Other attributes like proxyAddresses, mail, and sAMAccountName do not control the cloud UPN.

Exam trap

The trap here is confusing the mail attribute or proxyAddresses with the userPrincipalName, assuming that email-related attributes control the cloud sign-in address.

144
MCQmedium

Which attack targets service accounts by requesting a service ticket (TGS) from the domain controller and cracking the ticket offline?

A.Pass-the-Ticket
B.AS-REP Roasting
C.Kerberoasting
D.Golden Ticket Attack
AnswerC

Kerberoasting is specifically defined as the process of requesting a service ticket for a service account and cracking the resulting TGS-REP hash offline. Since the ticket is encrypted with the service account's password hash, offline cracking reveals the service account password, often leading to significant privilege escalation.

Why this answer

Kerberoasting exploits the nature of Kerberos service tickets, which are encrypted using the hash of the target service account's password. Because the ticket is encrypted with the service account's hash, an attacker who can request a ticket can attempt to brute-force or dictionary-attack that ticket offline. This is a highly stealthy method because no malicious traffic is sent to the target service itself.

Exam trap

Candidates often confuse Kerberoasting with AS-REP Roasting. They fail to realize Kerberoasting specifically targets service tickets (TGS) by requesting them from the KDC, whereas AS-REP Roasting targets account pre-authentication flags.

145
MCQeasy

A penetration tester has compromised a host in a restricted network that only allows outbound DNS queries to a specific internal resolver. The tester needs to establish a command and control channel that can traverse this restriction. Which C2 technique is most appropriate?

A.SMTP beaconing
B.ICMP tunneling
C.HTTPS beaconing
D.DNS tunneling
AnswerD

DNS tunneling encapsulates C2 data within DNS queries and responses, which are allowed through the restricted network. Since only DNS traffic to the internal resolver is permitted, this technique can bypass the egress filtering. Tools like dnscat2 or iodine can establish a covert channel over DNS. This directly addresses the scenario's constraint and is a common method for C2 in heavily restricted environments.

Why this answer

DNS tunneling is the only technique that can operate within a network that only allows DNS queries to an internal resolver. It encapsulates C2 traffic within DNS packets, which are forwarded by the resolver to external authoritative servers. This makes it ideal for bypassing strict egress filtering.

Other techniques require protocols or ports that are not permitted in this scenario.

Exam trap

The trap here is assuming that common web-based C2 like HTTPS will work, but the network only permits DNS traffic to a specific resolver.

146
Multi-Selectmedium

You are configuring a C2 listener to use a malleable profile to blend in with legitimate traffic. Which two of the following are key benefits of using a malleable C2 profile in a penetration test? (Choose two.)

Select 2 answers
A.It enables the C2 server to automatically generate new domain names for each beacon, avoiding domain blacklisting.
B.It provides a mechanism to define how the C2 server responds to specific requests, including error pages and other decoy content.
C.It encrypts the C2 traffic using a unique, randomly generated key for each session, ensuring perfect forward secrecy.
D.It allows the C2 traffic to be routed through multiple redirectors without additional configuration.
E.It allows you to customize the HTTP headers, URIs, and other request parameters to mimic a specific application or service.
AnswersB, E

Malleable C2 profiles allow operators to specify server responses, such as HTTP status codes, headers, and body content. This can include decoy pages or error messages that make the C2 server appear as a legitimate web server. By controlling responses, operators can further blend in and mislead defenders. This is a key benefit for maintaining stealth during a penetration test.

Why this answer

Malleable C2 profiles are used to customize the network traffic generated by a C2 framework to evade detection. They allow operators to define request and response structures, including headers, URIs, and body content, so that the traffic mimics legitimate services. This customization helps in blending with normal network activity and avoiding signature-based detection, making it a valuable tool during penetration tests.

Exam trap

The trap here is assuming malleable profiles provide encryption or domain generation, which are separate techniques, rather than focusing on traffic shaping and customization.

147
MCQmedium

Which of the following is the most effective way to detect C2 beacons that use jitter and randomized timing?

A.Blocking all traffic to unknown IP addresses.
B.Applying statistical analysis to traffic patterns.
C.Scanning for specific byte signatures in the payloads.
D.Monitoring for high-bandwidth bursts in the network.
AnswerB

Statistical analysis looks for patterns that emerge over time, such as the mean interval between connections. Even with jitter, the underlying periodicity remains detectable. This method allows security teams to identify the 'pulse' of a C2 channel even when it is intentionally obfuscated by random timing variations.

Why this answer

Since jitter and randomized timing break the simple periodic heartbeat, security teams must use statistical analysis to identify the traffic. By calculating the frequency distribution of connections over a long time window, analysts can identify the underlying regularity that persists despite the jitter. This behavioral approach is significantly more effective than static threshold-based alerts, which are easily defeated by the randomness built into modern C2 communication protocols.

Exam trap

Candidates often assume that because jitter makes beacons appear non-periodic, simple detection methods like frequency analysis are useless, failing to realize that statistical aggregation over long periods still reveals underlying regularity.

148
MCQhard

Refer to the exhibit. You are performing a penetration test based on this policy. You discover an unpatched SQL injection vulnerability on 192.168.10.20 that could be used to trigger a database lock-up. What is the most appropriate course of action?

A.Execute the SQL injection to prove the vulnerability exists.
B.Document the vulnerability and the risk of DoS without exploitation.
C.Attempt the exploit on the excluded host 192.168.10.50 to see if it is vulnerable.
D.Extend the testing window to allow for a safer, non-disruptive exploit.
AnswerB

Reporting the vulnerability without exploiting it respects the 'Forbidden_Attacks' constraint. This allows the client to understand the risk and patch the issue without suffering the downtime associated with a successful exploitation. It demonstrates professional judgment by balancing the need for security assessment with operational constraints.

Why this answer

Adhering strictly to the defined scope and allowed attack types is the cornerstone of professional pentesting. Since 'DoS' is explicitly forbidden, any exploit that causes service instability must be avoided. The tester must report the vulnerability as a high-risk finding without executing the destructive payload, as the client's policy prioritizes service availability over demonstrating the full potential of an exploit that risks system uptime.

Exam trap

Candidates often prioritize the technical 'proof of concept' by exploiting the vulnerability, forgetting that the Rules of Engagement explicitly prohibit any activity that causes a Denial of Service.

149
MCQeasy

During a penetration test, you are reviewing the results of a WHOIS query for a target domain. You notice the registrant's email address is privacy-protected, but the technical contact email is a generic address at a third-party hosting company. What is the most likely explanation for this finding, and what should you do next to gather more information about the target's infrastructure?

A.The target is using a privacy protection service; you should query the same WHOIS data from a different regional internet registry (RIR) to find the real contact.
B.The target is hiding its true identity; you should attempt to subpoena the hosting provider for the real customer information.
C.The target has outsourced domain management to a hosting provider; you should examine the hosting provider's IP ranges and look for other domains hosted on the same server.
D.The WHOIS data is corrupted; you should use a different WHOIS tool to retrieve the correct registrant information.
AnswerC

A technical contact at a hosting company indicates the domain's DNS and possibly web hosting are managed by that provider. By examining the hosting provider's IP ranges, you can identify other domains hosted on the same infrastructure, which may reveal shared hosting or additional targets. This is a common reconnaissance technique to expand the attack surface and find related assets that might be less protected.

Why this answer

A technical contact at a hosting company typically means the domain is managed by that provider. Examining the hosting provider's IP ranges and looking for other domains on the same server can reveal shared infrastructure, additional targets, and potential weaknesses. This is a standard passive reconnaissance pivot that expands the scope without directly alerting the target.

Exam trap

The trap here is thinking that privacy protection or hosting contacts are dead ends; in reality, they are pivots to the hosting provider's infrastructure, which can yield more targets.

150
MCQmedium

You are planning a penetration test for a client with a large wireless network. The client wants to assess the security of their WPA3-Enterprise deployment. Which of the following should be included in the Rules of Engagement to address the risk of disrupting legitimate wireless users?

A.A schedule for testing during off-peak hours and a maximum number of deauthentication frames to send per minute.
B.A requirement to use only passive wireless scanning techniques and avoid any active attacks.
C.A requirement to perform all wireless testing only during business hours to blend in with normal traffic.
D.A predefined list of authorized MAC addresses for testing devices to prevent accidental disconnections.
AnswerA

Off-peak testing reduces the number of users affected, and limiting deauthentication frames prevents overwhelming the network and causing widespread disconnections. This directly addresses the risk of disrupting legitimate wireless users. It is a specific, measurable control that can be included in the Rules of Engagement. This approach balances the need to test wireless security with the need to maintain network availability.

Why this answer

The most appropriate inclusion is a schedule for off-peak testing and a limit on deauthentication frames. This minimizes the number of users affected and prevents network instability. It directly mitigates the risk of disrupting legitimate wireless users while still allowing active testing of WPA3-Enterprise security.

Other options either do not sufficiently reduce risk or limit testing effectiveness.

Exam trap

The trap here is thinking that passive scanning is sufficient for a thorough wireless penetration test, when active attacks are often needed to validate WPA3-Enterprise.

Page 1

Page 2 of 4

Page 3

All pages