Courseiva

GIAC Penetration Tester (GPEN) — Questions 226–298

298 questions total · 4pages · All types, answers revealed

Page 3

Page 4 of 4

226
MCQmedium

Refer to the exhibit. What does this output indicate regarding the current exploitation attempt?

A.The application is secure from buffer overflow attacks.
B.The tester has successfully redirected execution flow.
C.The system is protected by DEP/NX.
D.The payload is too large for the allocated buffer.
AnswerB

The instruction pointer is pointing to the attacker-controlled buffer ('AAAA'). This confirms the tester has successfully hijacked the program counter, a prerequisite for code execution. The next phase involves crafting the payload to point this address to the shellcode instead of junk data.

Why this answer

The Instruction Pointer (EIP/RIP) being set to 0x41414141 (the hex representation of 'AAAA') proves that the tester has successfully overwritten the return address on the stack. This confirms the vulnerability is exploitable because the tester now has control over the execution flow. The next logical step is to replace the padding ('AAAA') with a valid memory address that points to the desired malicious shellcode.

Exam trap

Test-takers frequently assume that seeing '0x41414141' in the instruction pointer means the exploit was fully successful and shellcode executed, ignoring that control flow redirection is only the first step.

227
MCQmedium

A penetration tester is configuring an authenticated scan for a Windows environment. Which credential management strategy best minimizes the security impact while maintaining scan efficacy?

A.Configure the scanner to use the Domain Administrator account for full registry access.
B.Use a local account with no password to allow quick automated authentication.
C.Create a dedicated service account with granular WMI and remote registry permissions.
D.Store credentials in plain text in the scanner configuration file for easier automation.
AnswerC

Dedicated accounts with restricted permissions ensure that the scanner can query the necessary system information without broad administrative access. By limiting the scope of the account to WMI and registry read access, you maintain effective scan quality while significantly reducing overall risk.

Why this answer

Using dedicated, low-privilege service accounts with specific WMI and registry permissions minimizes the blast radius if credentials are intercepted. This approach adheres to the principle of least privilege, preventing the scanner from having full domain administrator access, which could be abused if the scanning server is compromised. Effective vulnerability management relies on deep system visibility without granting excessive authority to the scanning service.

Exam trap

Candidates often choose 'Domain Admin' credentials for ease of scanning, failing to realize that this violates the principle of least privilege and significantly increases risk during a security assessment.

228
MCQmedium

You are conducting an external penetration test against a client who uses a split-horizon DNS configuration. You want to identify internal hostnames and IP addresses without sending any traffic to the client's internal network. Which of the following techniques would best accomplish this?

A.Perform DNS cache snooping against the internal recursive resolver
B.Use DNS zone transfer requests against the external authoritative name servers
C.Analyze historical DNS data from passive DNS databases and certificate transparency logs
D.Query the internal DNS server directly using its private IP address
AnswerC

Passive DNS databases and certificate transparency logs aggregate historical DNS resolutions and SSL/TLS certificate issuances without sending any traffic to the target. They can reveal internal hostnames that were previously exposed in public certificates or DNS queries. This is a purely passive technique that aligns with the requirement to avoid internal network traffic.

Why this answer

Split-horizon DNS separates internal and external views, so external queries won't reveal internal names. Passive DNS and certificate transparency logs are public data sources that may contain leaked internal hostnames from misconfigured certificates or historical records. These sources require no interaction with the target's infrastructure, making them ideal for stealthy reconnaissance.

Exam trap

The trap here is assuming that any DNS query against the target's infrastructure is passive, when in fact only third-party data sources like passive DNS and CT logs avoid touching the target.

229
MCQmedium

During an internal penetration test, an operator intercepts an AS-REP response for a user account that does not have Kerberos pre-authentication enabled. What is the most efficient next step to recover the account password offline?

A.Run GetUserSPNs.py to request service ticket hashes for Kerberoasting against the domain controller.
B.Capture an NTLMv1 challenge-response handshake by forcing authentication over SMB using Responder.
C.Execute Hashcat with mode 13100 against the captured NTLM hash dumped from the local security authority subsystem service.
D.Use GetNPUsers.py to request the AS-REP ticket and crack the derived hash offline using Hashcat mode 18200.
AnswerD

With pre-authentication disabled, the domain controller returns an AS-REP encrypted with the user's password-derived key, so no valid credentials are needed. GetNPUsers.py harvests this ticket and extracts the crackable hash, which Hashcat mode 18200 attacks offline against wordlists, satisfying the efficiency constraint.

Why this answer

Disabling Kerberos pre-authentication allows any unauthenticated user to request an AS-REP for that account, containing a ticket encrypted with the user's secret key. Tools like Rubeus or GetNPUsers.py can harvest these tickets, which are formatted specifically for offline cracking using hashcat mode 18200 without requiring valid domain credentials initially.

Exam trap

Candidates often confuse AS-REP roasting with Kerberoasting, assuming a valid domain user account is required to request the ticket when AS-REP roasting explicitly targets accounts lacking pre-authentication.

230
MCQhard

During an internal penetration test, you capture a NetNTLMv2 challenge-response hash from a workstation. You attempt to crack it offline using Hashcat, but after several hours with a large wordlist and rules, the hash remains uncracked. Which factor most directly determines the feasibility of cracking this hash?

A.The length and complexity of the user's password
B.The version of the SMB protocol used during authentication
C.The network speed between the attacker and the victim
D.The amount of RAM available on the cracking machine
AnswerA

NetNTLMv2 cracking success depends on the entropy of the original password. Longer, more complex passwords exponentially increase the search space, making offline cracking infeasible. Even with large wordlists and rules, a high-entropy password will resist recovery, directly limiting the attack's success.

Why this answer

The feasibility of cracking a NetNTLMv2 hash offline is fundamentally governed by the password's entropy. NetNTLMv2 uses HMAC-MD5 with the user's NT hash and a server challenge, making it resistant to precomputation and requiring brute-force or dictionary attacks. If the password is long and complex, the search space becomes too large for practical cracking, regardless of hardware or network factors.

Exam trap

The trap here is attributing cracking difficulty to network or protocol factors, when in reality it is the password's strength that makes the hash resistant to recovery.

231
MCQmedium

During an internal assessment you obtain a Meterpreter session on a Windows Server 2016 host running as a low-privileged service account. You want to identify whether the host is missing security updates that could allow local privilege escalation without immediately running an exploit. Which Metasploit post-exploitation module should you use to enumerate installed hotfixes and compare them against known vulnerabilities?

A.post/multi/recon/local_exploit_suggester
B.post/windows/gather/enum_applications
C.post/windows/gather/win_privs
D.post/windows/gather/enum_patches
AnswerD

This module enumerates installed hotfixes on the target by querying the registry and WMI, then correlates them against the Microsoft vulnerability database to highlight missing patches. It runs safely without modifying the system, making it ideal for identifying kernel or component escalation candidates before attempting any exploit inside a production Windows Server 2016 engagement.

Why this answer

Enumerating installed hotfixes and comparing them to known Microsoft vulnerabilities is exactly what the enum_patches module provides, and it does so without triggering exploit code on a production server. The other modules either list applications, suggest exploits through active checks, or report current token privileges, none of which produce a patch-level inventory needed before selecting a kernel escalation path.

Exam trap

The trap here is assuming that any post module with 'enum' in the name will report missing Windows updates, when most only list applications, privileges, or sessions.

232
MCQmedium

You are setting up a C2 infrastructure for a penetration test. To protect the backend C2 server from direct exposure, you deploy a redirector. Which of the following best describes the primary function of a redirector in this context?

A.It generates random domain names for the C2 server to evade domain blacklisting.
B.It acts as a proxy that forwards only malicious traffic to the C2 server while blocking or misdirecting other traffic.
C.It load-balances incoming connections across multiple C2 servers to ensure high availability.
D.It encrypts all traffic between the compromised host and the C2 server, ensuring confidentiality.
AnswerB

A redirector is designed to filter incoming traffic, allowing only connections that match specific criteria (e.g., a secret header or specific URI) to reach the backend C2 server. Other traffic, such as from security researchers or scanners, is blocked or redirected to a benign site. This protects the C2 server's identity and location, making it harder for defenders to identify and block the actual C2 infrastructure.

Why this answer

A redirector's primary function is to act as a proxy that filters incoming traffic, forwarding only legitimate C2 traffic to the backend server while blocking or misdirecting other connections. This protects the C2 server's location and makes it more difficult for defenders to identify and block the actual C2 infrastructure. Encryption, load balancing, and domain generation are separate concerns handled by other components or techniques.

Exam trap

The trap here is confusing the redirector's filtering role with encryption or domain generation, which are separate C2 components.

233
Multi-Selecthard

A penetration tester is configuring a vulnerability scan against a large enterprise network. The tester needs to balance scan accuracy, speed, and impact on production systems. Which TWO of the following settings, when adjusted, will MOST directly reduce the risk of disrupting fragile network devices during the scan? (Choose two.)

Select 2 answers
A.Enable 'Safe Checks' in the scan policy.
B.Increase the maximum number of concurrent hosts scanned.
C.Reduce the scan's 'Max checks per host' value.
D.Disable 'Thorough tests' in the scan policy.
E.Set the scanner to use UDP instead of TCP for all checks.
AnswersA, C

Safe Checks prevents Nessus from running plugins that could crash services or devices, such as certain denial-of-service tests. On fragile devices like printers, VoIP phones, or legacy SCADA components, this setting avoids intrusive probes that might cause reboots or hangs. It directly reduces disruption risk while still allowing most vulnerability detection to proceed, making it a primary control for protecting production uptime.

Why this answer

The two settings that most directly reduce disruption are Safe Checks and Max checks per host. Safe Checks excludes plugins known to potentially crash services, while lowering Max checks per host throttles concurrent probes to each target. Together they limit both the type and the rate of intrusive traffic, protecting fragile production devices.

Other options either increase load or do not specifically target device stability.

Exam trap

The trap here is confusing scan depth settings like thorough tests with safety controls, when the real disruption risk comes from unsafe plugins and high concurrency.

234
MCQmedium

During an exploitation attempt against a web application, you inject a payload that causes the server to return a verbose error message containing a stack trace and database query. What is the most likely type of vulnerability you have discovered?

A.Cross-site request forgery (CSRF)
B.Remote file inclusion (RFI)
C.SQL injection
D.Cross-site scripting (XSS)
AnswerC

A verbose error with a database query and stack trace strongly indicates SQL injection. When user input is improperly sanitized, it can alter SQL queries, and errors often reveal database structure. This is a classic sign of SQLi, especially when the error includes SQL syntax details.

Why this answer

Verbose error messages that include database queries and stack traces are a hallmark of SQL injection. They occur when user input is not properly sanitized, allowing attackers to manipulate SQL statements and trigger errors that reveal backend details. This information can be used to further exploit the database.

Exam trap

The trap here is assuming any error message indicates a specific vulnerability without considering the content of the error.

235
MCQmedium

You are performing OSINT on a target and have collected a list of employee names from LinkedIn. You want to generate likely corporate email addresses and then verify which ones are valid without sending email to the target's mail servers. Which approach best accomplishes this?

A.Use the SMTP VRFY command against the organization's MX host for each candidate address
B.Query a breach-compilation or email-verification API that checks syntax, domain MX, and known breach data
C.Perform a DNS MX lookup for the domain and assume any address at that domain is valid
D.Send a test message to each candidate address and monitor for bounce-backs
AnswerB

Email-verification services and breach-compilation APIs check address syntax, confirm the domain has valid MX records, and cross-reference known breach corpora without contacting the target's mail servers. This approach validates candidate addresses passively, matching the requirement to avoid sending email to the target. It also scales well when you have many name permutations to test from the LinkedIn list.

Why this answer

Email-verification APIs and breach-compilation services evaluate candidate addresses using syntax checks, MX validation, and known breach data without contacting the target's mail servers. This keeps the activity passive while still filtering out invalid addresses. It is the only listed method that both validates individual addresses and avoids direct interaction with the target, satisfying the scenario's constraints.

Exam trap

The trap here is equating a valid MX record with a valid mailbox, when MX only proves the domain accepts mail, not that a specific address exists.

236
MCQmedium

During an Azure penetration test, you discover an App Registration with an expired client secret that still has active refresh tokens issued prior to expiration. The application holds high-privilege directory roles. How do these leaked refresh tokens behave regarding Azure AD security boundaries?

A.The refresh tokens are instantly invalidated the moment the underlying client secret expires or is rotated in the Azure portal.
B.The refresh tokens continue to function and can be exchanged for new access tokens until the refresh token's own lifetime expires or it is explicitly revoked.
C.The refresh tokens automatically convert into guest user sessions with restricted privileges to mitigate potential compromise of internal directory roles.
D.The refresh tokens fail immediately because Azure AD enforces continuous access evaluation for all service principal API interactions.
AnswerB

Azure AD architecture decouples token lifespans from credential lifespans once the session is established. A valid refresh token permits continuous generation of short-lived access tokens, enabling persistence even if the administrator deletes or rotates the original application secret.

Why this answer

Active refresh tokens bypass initial credential checks until they expire or are explicitly revoked, allowing prolonged unauthorized access to enterprise resources. Understanding this persistence mechanism is critical for penetration testers assessing token lifetime policies and identifying stealthy persistence vectors within enterprise environments.

Exam trap

Candidates often assume that rolling over or expiring a client secret immediately invalidates all previously issued OAuth tokens, forgetting that issued refresh tokens remain fully functional until their absolute lifetime is reached.

237
Multi-Selectmedium

A penetration tester has obtained a set of NTLM hashes from a Windows domain controller. The tester plans to perform an offline password cracking attack. Which two of the following techniques are most effective for increasing the success rate of cracking these hashes? (Choose two.)

Select 2 answers
A.Leveraging GPU acceleration with Hashcat
B.Conducting an online brute-force attack against the domain controller
C.Using a rule-based attack with a comprehensive wordlist
D.Performing a rainbow table attack using precomputed tables for NTLM
E.Using a dictionary attack with a list of common passwords only
AnswersA, C

GPU acceleration dramatically increases the number of hash computations per second compared to CPU-only cracking. Hashcat is optimized for GPU usage and can crack NTLM hashes at very high rates. This makes it a highly effective technique for offline attacks, reducing the time required to test large numbers of password candidates.

Why this answer

Rule-based attacks and GPU acceleration are both highly effective for offline cracking of NTLM hashes. Rule-based attacks expand the wordlist with common transformations, covering many user-chosen passwords. GPU acceleration with Hashcat maximizes computational speed, allowing millions of guesses per second.

Together, they significantly improve the success rate. Other options like rainbow tables or online attacks are either impractical or inefficient in this scenario.

Exam trap

The trap here is assuming that rainbow tables are always effective for unsalted hashes, but their size and lookup overhead make them less practical than rule-based GPU cracking.

238
MCQhard

An attacker has obtained a refresh token for an Azure AD application with the 'Mail.Read' delegated permission. The token was issued to a user who has since had their password reset and all refresh tokens revoked. The attacker attempts to use the refresh token to obtain a new access token. What is the expected outcome?

A.The refresh token will still work because it is not invalidated by password reset or token revocation.
B.The refresh token will fail because it was revoked, and the attacker must re-authenticate to obtain a new one.
C.The refresh token will work only if the application has the 'offline_access' permission.
D.The refresh token will fail because it is bound to the user's password hash, which changed.
AnswerB

When a password is reset or tokens are revoked, Azure AD invalidates all refresh tokens for that user. The attacker's refresh token is therefore useless. To regain access, the attacker would need to compromise the account again and perform a new authentication flow.

Why this answer

Azure AD invalidates all refresh tokens for a user when their password is reset or when tokens are explicitly revoked. This is a security measure to prevent token replay after credential compromise. The attacker's refresh token is therefore invalid, and any attempt to redeem it will result in an error.

The attacker would need to re-authenticate with valid credentials to obtain new tokens.

Exam trap

The trap here is believing that refresh tokens survive password resets or that they are tied to the password hash, when in fact they are simply revoked en masse.

239
MCQhard

During a penetration test on a Windows Server 2019 domain controller, you discover that the KRBTGT account password was last set 5 years ago. You extract the KRBTGT hash and create a Golden Ticket with a 10-year expiration. What is the primary reason this persistence method is particularly effective in this scenario?

A.The Golden Ticket can be used to authenticate to any service in the domain without additional tickets.
B.The KRBTGT account has a weak password that can be brute-forced.
C.The KRBTGT password is rarely changed, so the Golden Ticket remains valid for its full lifetime.
D.The Golden Ticket is automatically renewed by the domain controller, extending its validity.
AnswerC

Because the KRBTGT password has not been changed in 5 years, the extracted hash will remain valid for a long time, allowing the Golden Ticket to be used until the password is changed twice. This makes the persistence highly durable and stealthy, as no password change is imminent.

Why this answer

In this scenario, the KRBTGT password's extreme age means the hash is unlikely to be rotated soon. Since Golden Tickets remain valid until the KRBTGT password is changed twice, the attacker can maintain access for years, making this a highly effective and stealthy persistence method.

Exam trap

The trap here is assuming that a Golden Ticket is automatically renewed or that its effectiveness depends on brute-forcing, when in fact it relies on the KRBTGT hash remaining unchanged.

240
MCQmedium

A penetration tester is preparing to scan a network that includes a mix of traditional IT systems and industrial control systems (ICS). The tester wants to minimize the risk of disrupting ICS devices. Which scanning approach is MOST appropriate for the ICS segment?

A.Perform an aggressive Nmap scan with OS detection and version scanning.
B.Use a passive scanner that only listens to network traffic without sending packets.
C.Scan the ICS segment during a planned maintenance window with Safe Checks enabled.
D.Run a credentialed scan with default settings to get the most accurate results.
AnswerB

Passive scanning monitors existing traffic to identify devices and vulnerabilities without injecting any packets. This eliminates the risk of disrupting ICS devices, which may be sensitive to unexpected probes. Tools like Tenable Nessus Passive Scanner or Wireshark with protocol dissectors can inventory assets and detect issues. It is the safest approach for fragile OT environments where uptime is critical.

Why this answer

Passive scanning is the safest method for ICS because it does not send any traffic that could disrupt fragile devices. It relies on observing existing network traffic to identify assets and potential vulnerabilities. Active scanning, even with Safe Checks or during maintenance, carries inherent risk of causing outages.

For OT environments, passive monitoring is the recommended first step before any active testing.

Exam trap

The trap here is assuming that Safe Checks or a maintenance window makes active scanning safe for ICS, when only passive monitoring guarantees no disruption.

241
MCQmedium

Which of the following best describes the 'Gray-box' testing methodology?

A.Complete lack of knowledge about the target environment.
B.Full access to source code, network diagrams, and documentation.
C.Partial knowledge of internal systems and limited documentation.
D.Testing only the physical security controls of a facility.
AnswerC

Gray-box testing involves having partial information, such as IP ranges or high-level network diagrams, but not full access to source code or administrative credentials. This strikes a balance between the realism of black-box testing and the depth and efficiency of white-box testing for the security assessment.

Why this answer

Gray-box testing combines elements of both black-box and white-box testing. The tester has limited knowledge of the environment, such as network diagrams or internal documentation, but does not have full source code access. This approach is highly effective for simulating a sophisticated attacker, such as an insider or an attacker who has already gained an initial foothold, allowing for a more focused and efficient security assessment.

Exam trap

Candidates often confuse Gray-box with White-box testing, mistakenly assuming the tester has full access to source code or internal architectural diagrams, rather than just limited, partial knowledge of the environment.

242
MCQeasy

You have obtained a Meterpreter session on a Windows 10 host as a standard user. You want to escalate privileges by exploiting a vulnerable kernel driver. Which Metasploit module category would you use to search for suitable exploits?

A.exploit/windows/rdp
B.exploit/windows/smb
C.exploit/windows/local
D.exploit/windows/http
AnswerC

The 'exploit/windows/local' category contains local privilege escalation exploits for Windows, including kernel driver vulnerabilities. These modules are designed to run within an existing session to elevate privileges. By searching this category, you can find exploits that match the target's architecture and patch level. This is the correct place to look for kernel-based escalation modules in Metasploit.

Why this answer

Local privilege escalation exploits in Metasploit are found under the 'exploit/windows/local' category. These modules are specifically designed to run within a session and elevate privileges by exploiting vulnerabilities such as kernel driver flaws. Other categories like SMB, RDP, or HTTP are for remote exploitation and do not apply when you already have local access.

Exam trap

The trap here is confusing remote exploit categories with local privilege escalation modules, which are distinctly separated in Metasploit's directory structure.

243
MCQeasy

A client asks you to perform a penetration test on their web application. During the planning phase, they mention that the application is hosted on a third-party cloud provider and they do not have written permission from the provider to test the underlying infrastructure. What is the MOST appropriate action?

A.Limit testing to a static code review of the application source code to avoid any interaction with the cloud environment.
B.Perform the test anyway, since the client owns the application and has authorized you to test it.
C.Proceed with testing the application layer only, avoiding any tests that could impact the cloud infrastructure.
D.Request that the client obtain written authorization from the cloud provider before any testing begins.
AnswerD

The cloud provider's terms of service typically prohibit penetration testing without prior written consent. The client must obtain this authorization to ensure the engagement is legal. As the tester, you should insist on this before starting. It protects both you and the client from legal repercussions and ensures the testing is conducted within the provider's policies. This is the most appropriate and professional action.

Why this answer

The most appropriate action is to request that the client obtain written authorization from the cloud provider. This ensures the testing is legal and compliant with the provider's policies. Proceeding without it or limiting testing does not resolve the fundamental authorization gap and could expose both parties to legal and operational risks.

Exam trap

The trap here is assuming that the client's authorization is sufficient, when the cloud provider's permission is also required.

244
MCQeasy

What is the primary security advantage of utilizing salts in password hashing?

A.It increases the length of the password, making it harder to guess.
B.It prevents the use of precomputed rainbow tables.
C.It forces the hashing algorithm to use more CPU cycles.
D.It encrypts the password instead of hashing it.
AnswerB

Rainbow tables are precomputed databases of hashes for millions of common passwords. By adding a unique salt to every entry in a database, the hash of a password becomes unique to that specific salt, rendering static rainbow tables ineffective as they only contain non-salted or statically-salted hash results.

Why this answer

Salts are random strings added to passwords before they are hashed. This ensures that even if two users have the same password, their resulting hashes will be different. This prevents the use of precomputed lookup tables (rainbow tables) from successfully identifying passwords.

Protecting against rainbow tables is a fundamental security practice that forces attackers to crack each hash individually, significantly increasing the time and computational resources required for a successful breach.

Exam trap

Candidates often mistakenly believe salts increase the complexity of the password itself or slow down the hashing algorithm's execution time, rather than focusing on the prevention of precomputed table lookups.

245
Multi-Selecthard

A penetration tester has captured a set of NTLMv2 challenge-response pairs from a network segment. The tester wants to crack these hashes offline using Hashcat. Which TWO of the following statements are true regarding the cracking of NTLMv2 hashes with Hashcat? (Choose two.)

Select 2 answers
A.NTLMv2 hashes can be cracked using precomputed rainbow tables.
B.Hashcat mode 5600 is used for NTLMv2 hashes.
C.Cracking NTLMv2 requires the original server challenge to be included in the hash file.
D.Hashcat can crack NTLMv2 hashes without specifying a wordlist or mask.
E.NTLMv2 hashes are salted with the username, making them more resistant to cracking.
AnswersB, C

Hashcat mode 5600 is specifically designed for NetNTLMv2 hashes, which are the challenge-response pairs captured from network traffic. This mode correctly handles the format of NTLMv2 responses, including the server challenge and the HMAC-MD5 construction. Using the correct mode ensures that Hashcat can perform the necessary computations to test candidate passwords against the captured challenge-response.

Why this answer

NTLMv2 challenge-response pairs are cracked using Hashcat mode 5600, and the captured hash must include the server challenge for the computation to be possible. The challenge is unique per authentication, so precomputed tables are useless. The username is part of the hash but does not act as a salt.

An attack mode must always be specified.

Exam trap

The trap here is thinking that NTLMv2 hashes can be cracked with rainbow tables, but the inclusion of a unique server challenge per session prevents precomputation.

246
MCQhard

A penetration tester is targeting a web application that uses a custom authentication mechanism. After capturing network traffic, the tester notices that the application sends a challenge to the client and expects a response derived from the user's password. The tester wants to perform an offline brute-force attack against the captured challenge-response pairs. Which type of password attack is this?

A.Offline brute-force against challenge-response
B.Rainbow table attack
C.Credential stuffing
D.Pass-the-Hash
AnswerA

This scenario describes a challenge-response authentication protocol where the client proves knowledge of the password by responding to a challenge. Capturing these pairs allows an attacker to perform an offline brute-force attack, trying different passwords to see which one produces the correct response. This is a classic offline password attack against challenge-response mechanisms.

Why this answer

The attack involves capturing challenge-response pairs and then performing an offline brute-force to recover the password that generates the correct response. This is a form of offline password cracking against a challenge-response protocol. Other options like Pass-the-Hash, credential stuffing, or rainbow tables do not match the described scenario.

Exam trap

The trap here is assuming that any offline attack against authentication traffic is a hash-cracking attack, when challenge-response protocols require a different approach.

247
MCQeasy

A penetration tester is reviewing Kerberos traffic and notices that a user account has the DONT_REQ_PREAUTH flag set in its userAccountControl attribute. The tester wants to obtain crackable material for this account without any domain credentials. Which technique should the tester use?

A.Golden ticket creation by forging a TGT using the krbtgt hash obtained from the domain controller.
B.Kerberoasting by requesting a TGS for an SPN associated with the account and cracking the service ticket.
C.Silver ticket creation by forging a service ticket using the target account's NTLM hash.
D.AS-REP Roasting by sending an AS-REQ without pre-authentication and capturing the encrypted AS-REP.
AnswerD

When pre-authentication is disabled, the KDC returns an AS-REP containing data encrypted with the user's password-derived key without requiring the requester to prove knowledge of the password. An unauthenticated attacker can request this and crack the encrypted portion offline. This directly exploits the DONT_REQ_PREAUTH flag and requires no domain credentials.

Why this answer

The DONT_REQ_PREAUTH flag allows an unauthenticated attacker to request an AS-REP for the account and receive data encrypted with the user's key. Capturing that response enables offline password cracking without any domain credentials, directly exploiting the disabled pre-authentication setting.

Exam trap

The trap here is conflating AS-REP Roasting with Kerberoasting, when the absence of pre-authentication and lack of credentials point specifically to requesting an AS-REP for offline cracking.

248
MCQeasy

During a penetration test, a tester extracts the SAM database from a Windows system. Which of the following tools is specifically designed to extract password hashes from the SAM file?

A.John the Ripper
B.Mimikatz
C.Hashcat
D.secretsdump.py
AnswerD

secretsdump.py is part of the Impacket suite and is designed to extract secrets, including password hashes, from Windows systems. It can parse SAM, SYSTEM, and SECURITY registry hives offline to extract NTLM hashes. In this scenario, after extracting the SAM file, the tester can use secretsdump.py to retrieve the hashes, making it the correct tool for this purpose.

Why this answer

secretsdump.py is specifically designed to extract password hashes from Windows registry hives, including SAM, SYSTEM, and SECURITY. It can operate offline on extracted files, making it ideal for this scenario. Mimikatz is more for live memory extraction, while Hashcat and John the Ripper are cracking tools.

Thus, secretsdump.py is the correct choice for extracting hashes from a SAM file.

Exam trap

The trap here is confusing extraction tools with cracking tools, or assuming Mimikatz is always the go-to for any hash extraction, even offline.

249
MCQhard

An enterprise client insists on a blind 'black-box' penetration test where the testing team receives zero prior knowledge regarding network architecture, IP ranges, or applications. However, the client's primary objective is to thoroughly test deep-seated business logic vulnerabilities within a critical custom web application. Why is this planning approach fundamentally misaligned with the client's stated objective?

A.Black-box testing is legally prohibited under international cybersecurity standards for any application handling financial data.
B.Zero-knowledge assessments automatically violate standard industry rules of engagement by preventing the execution of automated scanners.
C.Discovery phases consume disproportionate time, leaving insufficient hours for the deep manual analysis required to uncover logic flaws.
D.Client stakeholders cannot legally authorize a penetration test without providing a complete network diagram and asset inventory.
AnswerC

Black-box testing prioritizes reconnaissance and asset discovery, severely restricting the time available for deep manual code or logic reviews. Gray or white-box scoping is necessary to bypass discovery overhead and focus directly on application logic.

Why this answer

Black-box testing forces testers to spend the majority of the engagement on reconnaissance and basic discovery rather than deep vulnerability analysis. To effectively evaluate complex business logic flaws, testers require white-box or gray-box scoping with documentation and credentials to achieve adequate depth within standard assessment timeframes.

Exam trap

Candidates often believe that black-box testing is inherently 'better' or 'more secure', ignoring the practical reality that it consumes time that should be spent on complex, deep-dive analysis.

250
MCQmedium

In the context of password attacks, what is the primary purpose of a 'mask' in Hashcat?

A.To hide the password hash from security logs.
B.To define the structure and character sets to be tested.
C.To decrypt hashes using a known public key.
D.To automatically rotate the password in the target account.
AnswerB

A mask allows the tester to specify custom patterns, such as 'uppercase, lowercase, digit, symbol'. By defining these character sets and their positions, the tester restricts the search space to likely password structures, which dramatically increases the speed and efficiency of the cracking process compared to random guessing.

Why this answer

A mask attack is a sophisticated form of brute-forcing where the tester defines the character set and structure of the password (e.g., ?d?d?d?d for a four-digit numeric password). By limiting the search space to patterns that are likely to be used, the tester can crack passwords significantly faster than a pure brute-force approach. This is an essential skill for optimizing cracking sessions against complex password policies.

Exam trap

Candidates frequently confuse a 'mask' with a 'dictionary' attack. They assume the mask is a list of passwords rather than a structural definition of character sets and patterns used to generate guesses.

251
MCQhard

An attacker has compromised an Azure App Service and obtained the application's managed identity token. They want to use it to access an Azure SQL Database. The managed identity has been granted access to the SQL server. Which of the following is the correct way to authenticate to the SQL Database using the managed identity token?

A.Use the token to call the Azure SQL REST API to execute queries.
B.Use the token as the password in a SQL connection string with 'Authentication=Active Directory Password'.
C.Use the token in the 'Access Token' property of a SqlConnection object with 'Authentication=Active Directory Access Token'.
D.Use the token to authenticate to the Azure SQL server's master database and then impersonate a user.
AnswerC

Azure SQL supports Azure AD access token authentication via the 'Access Token' property in SqlConnection. The token must be obtained for the resource https://database.windows.net/. This method allows the managed identity to authenticate without a password. It is the correct approach to leverage the token for SQL access.

Why this answer

The correct method is to use the managed identity's access token directly in the SqlConnection object with 'Authentication=Active Directory Access Token'. The token must be scoped to https://database.windows.net/. This allows the application to authenticate to Azure SQL using the managed identity, leveraging its assigned permissions.

Exam trap

The trap here is assuming that the token can be used as a password in a connection string, which is a common misconception but not how Azure AD token authentication works for SQL.

252
MCQmedium

A penetration tester is performing an offline attack against a Kerberos TGS-REP hash obtained via Kerberoasting. Which of the following Hashcat modes should be used?

A.19600
B.7500
C.13100
D.1000
AnswerC

Hashcat mode 13100 is specifically for Kerberos 5 TGS-REP etype 23 hashes, which are obtained through Kerberoasting. This mode implements the RC4-HMAC-MD5 algorithm used in etype 23. Using mode 13100 ensures Hashcat correctly parses the TGS-REP hash and performs the appropriate cracking operations, which involve decrypting the ticket with candidate passwords.

Why this answer

Kerberoasting produces a Kerberos 5 TGS-REP hash, typically using RC4 (etype 23). Hashcat mode 13100 is designed for this hash type. Other modes correspond to different Kerberos or NTLM hashes: 19600 for AES TGS-REP, 7500 for AS-REP, and 1000 for NTLM.

Using the correct mode is essential for efficient cracking.

Exam trap

The trap here is confusing Kerberoasting with AS-REP Roasting or assuming all Kerberos hashes use the same mode, but TGS-REP and AS-REP have distinct modes.

253
MCQmedium

A penetration tester has obtained a hash from a Linux system's /etc/shadow file: $6$rounds=656000$XyZ123$... The tester wants to crack this hash using John the Ripper. Which format should be specified to John to ensure correct cracking?

A.--format=bcrypt
B.--format=sha512crypt
C.--format=md5crypt
D.--format=descrypt
AnswerB

The hash prefix $6$ indicates SHA-512 crypt, which is the default for many Linux systems. John the Ripper uses the format name sha512crypt for this. Specifying this format ensures John applies the correct algorithm and iteration count (rounds). This is the correct choice for the given hash.

Why this answer

The hash begins with $6$, which is the identifier for SHA-512 crypt. John the Ripper's format for this is sha512crypt. The other formats correspond to different algorithms (bcrypt, md5crypt, descrypt) that do not match the $6$ prefix.

Therefore, specifying sha512crypt is necessary for successful cracking.

Exam trap

The trap here is assuming that any Linux shadow hash uses the same format, ignoring the $ prefix that specifies the algorithm.

254
MCQmedium

Which of the following describes the risk associated with cached credentials in the Windows operating system during a penetration test?

A.Cached credentials only store the user's username.
B.They allow offline authentication, but are stored in plain text.
C.They provide a target for offline cracking to recover domain passwords.
D.They are automatically wiped upon every system reboot.
AnswerC

Cached domain credentials (MSCASH or Domain Cached Credentials) can be dumped from the system and cracked offline. Since these are often cached for many users, an attacker can obtain a large number of domain hashes, significantly increasing the probability of compromising accounts within the target environment.

Why this answer

Windows caches credentials for domain accounts that have previously logged into a machine to allow users to sign in when the domain controller is unavailable. These cached entries, often stored in the registry, can be extracted by an attacker with administrative privileges. This provides a persistent source of credentials that, if cracked, could grant an attacker access to the domain even when the targeted user is not currently logged on.

Exam trap

Candidates often assume cached credentials are encrypted and therefore safe. They underestimate the ease with which an administrator can extract these hashes from the registry for offline cracking.

255
MCQhard

You are performing an authorized penetration test and have established a C2 channel using HTTPS. To evade network detection, you configure your C2 beacon to use domain fronting. Which of the following best describes how domain fronting masks the true destination of your C2 traffic?

A.The TLS SNI field contains the domain of a legitimate high-reputation service, while the HTTP Host header contains the actual C2 domain.
B.The C2 traffic is routed through multiple compromised hosts in a peer-to-peer network, making it difficult to trace back to the origin.
C.The TLS SNI field contains the actual C2 domain, while the HTTP Host header contains the domain of a legitimate service.
D.The C2 traffic is encapsulated within DNS queries to a legitimate domain, and the responses contain the C2 instructions.
AnswerA

Domain fronting exploits the difference between the TLS SNI (which is visible in the clear during the TLS handshake) and the HTTP Host header (which is encrypted). By setting the SNI to a legitimate domain hosted on a CDN and the Host header to the C2 domain also hosted on the same CDN, network observers see only the SNI and assume the traffic is to the legitimate domain. The CDN routes the request based on the Host header to the actual C2 server.

Why this answer

Domain fronting works by manipulating the TLS SNI and HTTP Host header. The SNI, visible during the TLS handshake, points to a legitimate domain hosted on a CDN, while the encrypted Host header points to the actual C2 domain also hosted on the same CDN. This makes the traffic appear to be destined for the legitimate domain to network observers, effectively hiding the C2 communication.

Exam trap

The trap here is reversing the SNI and Host header roles, or confusing domain fronting with other evasion techniques like DNS tunneling or P2P.

256
MCQeasy

A penetration tester has just obtained a Meterpreter session on a Linux web server and wants to keep it active while performing other tasks in msfconsole. Which command should the tester issue to return to the msfconsole prompt while leaving the session running in the background?

A.background
B.exit
C.suspend
D.detach
AnswerA

The background command, also available as bg, returns the tester to the msfconsole prompt while keeping the Meterpreter session alive and tracked by the framework. The session remains listed and can be resumed later with the sessions -i command. This is the standard way to multitask across multiple sessions without losing access.

Why this answer

The background command returns control to the msfconsole prompt while preserving the Meterpreter session in the framework's session list. The session continues to run and can be resumed later using sessions -i with the session identifier. Commands like exit or non-existent detach and suspend would either terminate the session or fail, so background is the correct choice.

Exam trap

The trap here is assuming exit or a detach-style command preserves the session, when only background returns to the console without terminating the connection.

257
MCQmedium

During an authorized penetration test, you have established a C2 session using a popular framework. Your goal is to maintain persistent access to a compromised Windows host even after the user logs off or the system reboots. You decide to use a service-based persistence mechanism. Which of the following commands, when executed on the compromised host, would create a new Windows service that runs your payload at startup?

A.wmic service create name='Updater' path='C:\Windows\Temp\payload.exe' startmode='Auto'
B.schtasks /create /tn "Updater" /tr "C:\Windows\Temp\payload.exe" /sc onlogon
C.sc create Updater binPath= "C:\Windows\Temp\payload.exe" start= auto
D.reg add HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v Updater /t REG_SZ /d "C:\Windows\Temp\payload.exe"
AnswerC

This command uses the Windows Service Control Manager to create a new service named 'Updater' that runs the specified payload executable automatically at system startup. The syntax with spaces after equals signs is required for sc.exe. This achieves persistence because the service will start each time Windows boots, maintaining the C2 channel without relying on user logon.

Why this answer

Creating a Windows service with sc.exe is a reliable method for achieving persistence because services can be configured to start automatically at boot, independent of user logon. The command must use the correct syntax with spaces after 'binPath=' and 'start='. Other options either rely on user logon or use invalid syntax, failing to meet the requirement of persistence across reboots without user interaction.

Exam trap

The trap here is confusing user-logon persistence (Run keys, onlogon tasks) with system-boot persistence (services), which does not require a user to log in.

258
MCQmedium

You are performing a penetration test on a Microsoft Entra ID tenant that uses federated authentication with Active Directory Federation Services (AD FS). You have obtained a user's credentials and want to maintain persistent access even if the user's password is changed. Which of the following methods would best achieve this?

A.Configure an Azure AD application with a client secret and assign it the 'Directory.Read.All' permission.
B.Create a new user account in Entra ID with Global Administrator privileges.
C.Forge a SAML token using the AD FS token-signing certificate.
D.Register a new device in Entra ID and use it to obtain a Primary Refresh Token (PRT).
AnswerC

In a federated environment, the AD FS token-signing certificate is used to sign SAML tokens. If an attacker can export this certificate's private key (e.g., from the AD FS server), they can forge SAML tokens for any user, including Global Administrators. These tokens are accepted by Entra ID as valid authentication, allowing persistent access regardless of password changes. This is a powerful persistence technique.

Why this answer

In AD FS federated environments, the token-signing certificate is the root of trust. If an attacker compromises the AD FS server and exports the token-signing certificate's private key, they can forge SAML tokens for any user. These tokens are accepted by Entra ID, providing persistent access even after password changes.

This is a critical persistence technique in federated identity setups.

Exam trap

The trap here is focusing on user-level persistence methods like device registration or app creation, while the most powerful persistence in federated environments is compromising the token-signing certificate.

259
Multi-Selecthard

You are analyzing a target environment and need to identify UDP services. Which THREE of the following are significant challenges associated with performing an accurate UDP scan compared to a TCP scan?

Select 3 answers
A.UDP is connectionless, requiring Nmap to wait for a response that may never come.
B.UDP ports must be scanned sequentially, preventing parallelization.
C.Many operating systems implement ICMP rate-limiting for port unreachable messages.
D.UDP packets are always blocked by stateful firewalls regardless of status.
E.UDP responses are not guaranteed, leading to high false-negative rates.
AnswersA, C, E

Because UDP does not utilize a handshake, the scanner must guess if a port is open based on the presence of a response or an ICMP port unreachable message. If the packet is simply dropped by the target, the status remains ambiguous, leading to significant delays and potential errors.

Why this answer

UDP is a connectionless protocol, which creates inherent difficulties in scanning. Because there is no handshake, responses are inconsistent, leading to unreliable results. Testers must be aware that UDP scanning is often significantly slower and prone to false negatives due to rate-limiting by target hosts.

Understanding these limitations is critical for reporting accurate service maps and knowing when to re-scan or verify results using alternative methods.

Exam trap

Test-takers frequently select answers assuming UDP scanning shares TCP's reliable handshake mechanics, forgetting that connectionless protocols cause high false-negative rates and rate-limiting issues.

260
MCQeasy

What is the primary purpose of the 'Scope' section in the Rules of Engagement?

A.To outline the payment terms for the penetration test.
B.To define the specific boundaries of the assessment.
C.To detail the specific tools to be used by the tester.
D.To list the names of all employees who will be interviewed.
AnswerB

Defining the boundaries ensures that only authorized systems are targeted. This prevents the penetration tester from accidentally testing infrastructure that does not belong to the client or that is not part of the current engagement, thus maintaining legal compliance and professional safety throughout the entire testing process.

Why this answer

The scope section is essential to clearly define the boundaries of the test. It explicitly identifies which systems, applications, and networks are authorized for testing, protecting both the client and the tester from potential legal issues. By delineating these boundaries, it prevents 'scope creep' and ensures that the testing effort is focused on the intended targets, maximizing the impact of the assessment while minimizing risk.

Exam trap

Candidates often confuse the 'Scope' with the 'Methodology' or 'Rules of Engagement', incorrectly selecting answers that describe how to test rather than where the testing is permitted to occur.

261
MCQeasy

A penetration tester is preparing to exploit a stack-based buffer overflow on a Linux target. The target binary has non-executable stack (NX) enabled. Which technique should the tester use to achieve code execution?

A.Use a NOP sled and jump to shellcode on the stack
B.Stack pivot to a writable and executable memory region
C.Return-to-libc (ret2libc) attack
D.Heap spraying
AnswerC

Return-to-libc bypasses NX by reusing existing executable code in libc, such as `system()`, to execute commands. It does not require injecting shellcode onto the stack. This technique is effective when the stack is non-executable and is a standard method for exploiting buffer overflows in modern Linux environments with NX enabled.

Why this answer

Return-to-libc is the correct technique because it leverages existing executable code in shared libraries to bypass the non-executable stack. It allows the tester to call functions like `system()` to execute commands without injecting shellcode. Other options either assume an executable stack or are not applicable to stack-based overflows on Linux with NX enabled.

Exam trap

The trap here is assuming that classic stack shellcode injection still works when NX is enabled, overlooking the need to reuse existing code.

262
MCQeasy

A penetration tester is analyzing a password hash captured from a web application's database. The hash is `5f4dcc3b5aa765d61d8327deb882cf99` and is 32 characters long. Which type of hash is this, and what is a common tool to crack it?

A.MD5, and Hashcat can be used with mode 0.
B.SHA-256, and Hashcat can be used with mode 1400.
C.SHA-1, and Hashcat can be used with mode 100.
D.NTLM, and Hashcat can be used with mode 1000.
AnswerA

The hash is 32 hexadecimal characters, characteristic of MD5. Hashcat mode 0 is specifically for raw MD5 hashes. This is a common scenario in penetration testing when web applications use MD5 without salts. The tester can use Hashcat with a wordlist or rules to crack it. The hash `5f4dcc3b5aa765d61d8327deb882cf99` is the MD5 of 'password', a well-known example.

Why this answer

The hash is 32 characters long, which is the length of an MD5 hash. Hashcat mode 0 is used for raw MD5 hashes. This is a straightforward identification task.

The hash `5f4dcc3b5aa765d61d8327deb882cf99` is a common example (MD5 of 'password'), but the key is recognizing the format. A penetration tester should use this knowledge to select the correct cracking mode and proceed with offline cracking.

Exam trap

The trap here is confusing MD5 with NTLM because both produce 32-character hashes, but context and known hash examples help differentiate.

263
MCQhard

While testing a Windows 10 workstation, you find that the account you compromised belongs to the Backup Operators group. You need to escalate to local administrator without installing third-party tools on disk. Which built-in capability of this group can you abuse to obtain administrative access?

A.SeBackupPrivilege allows reading any file, enabling extraction of the SAM and SYSTEM registry hives for offline credential dumping
B.Membership grants SeDebugPrivilege, permitting direct injection into a SYSTEM process to steal its token
C.SeTakeOwnershipPrivilege is granted, allowing ownership takeover of any object followed by full control
D.The group can modify the discretionary access control list on the local administrator account to reset its password
AnswerA

Backup Operators hold SeBackupPrivilege and SeRestorePrivilege, which bypass file ACLs. By copying the SAM and SYSTEM hives with a tool that honors the backup privilege, then parsing them offline, you can recover local account hashes including the administrator's, then authenticate or pass the hash to escalate without writing custom exploits to disk.

Why this answer

The Backup Operators group is powerful because SeBackupPrivilege and SeRestorePrivilege bypass file system ACLs. An attacker can therefore read protected files such as the SAM and SYSTEM hives, exfiltrate them, and recover local password hashes offline, then use those credentials to reach administrative access without dropping custom binaries onto the host.

Exam trap

The trap here is assuming Backup Operators receive SeDebugPrivilege or SeTakeOwnershipPrivilege, when their real power comes from backup and restore rights that bypass file ACLs.

264
Multi-Selectmedium

A penetration tester is conducting an offline password attack against a set of NTLM hashes extracted from a Windows domain. The tester wants to maximize the efficiency of the cracking process by using Hashcat. Which two techniques are most effective for this goal? (Choose two.)

Select 2 answers
A.Increasing the number of threads to exceed the number of CPU cores
B.Utilizing a rule-based attack with a comprehensive rule set like best64.rule
C.Using the --username option to ignore usernames during cracking
D.Employing a mask attack with a custom character set tailored to the organization's password policy
E.Running a pure brute-force attack with all printable ASCII characters up to 12 characters
AnswersB, D

Rule-based attacks apply transformations to dictionary words, significantly expanding the candidate space without requiring a larger wordlist. Using a well-curated rule set like best64.rule can efficiently cover common password mutations, increasing the chances of cracking NTLM hashes while maintaining reasonable processing speed.

Why this answer

Rule-based attacks and mask attacks are both highly effective for offline NTLM cracking because they intelligently reduce the search space by applying common transformations or adhering to known password policies. Pure brute-force is impractical for long passwords, while options like ignoring usernames or oversubscribing threads do not enhance cracking efficiency.

Exam trap

The trap here is assuming that more computational force (pure brute-force or more threads) is always better, when in fact targeted techniques like rules and masks are far more efficient for typical password patterns.

265
Multi-Selecthard

When selecting an exploit for a target system, which TWO factors are most critical to ensure the exploit succeeds without crashing the target service?

Select 2 answers
A.The exact version of the application or OS service.
B.The color scheme of the target's command shell.
C.The target system's CPU architecture (e.g., x86 vs x64).
D.The network bandwidth available to the target.
E.The number of users currently logged in.
AnswersA, C

Exploits are often highly specific to binary versions. An offset that works on version 1.2 may cause a segmentation fault on 1.3 due to recompiled libraries or different memory layouts. Matching the exact build ensures that memory addresses used in the payload are valid for the target.

Why this answer

Successful exploitation requires precise alignment between the exploit's memory address assumptions and the target's environment. Crashes typically occur when the exploit targets an incorrect memory offset or assumes a different architecture than the one present. By verifying target versioning and architectural requirements, a tester minimizes the risk of service instability, ensuring that the exploit fulfills its objective while maintaining the operational integrity of the production environment.

Exam trap

Testers often prioritize payload features over system compatibility, ignoring architecture mismatches that reliably cause services to crash rather than provide a stable shell.

266
MCQmedium

During an internal penetration test, you capture NTLMv2 hashes from a network segment. You want to crack these hashes using Hashcat on a dedicated GPU rig. Which Hashcat mode number corresponds directly to the NTLMv2 hash format commonly captured via LLMNR/NBT-NS poisoning?

A.Hashcat mode 1000 represents standard NTLM password hashes extracted from the Windows SAM database or NTDS.dit.
B.Hashcat mode 3000 handles LANMAN hashes, which are legacy Windows password hashes stored for backwards compatibility on older systems.
C.Hashcat mode 5600 targets NetNTLMv2 hashes captured during network authentication processes like SMB or HTTP challenges.
D.Hashcat mode 13100 is utilized for Kerberos 5 TGS-REP etype 23 hashes gathered through service ticket requests.
AnswerC

Mode 5600 is dedicated to NetNTLMv2, the challenge-response format captured during SMB or HTTP authentication after LLMNR/NBT-NS poisoning. The captured hash contains the server challenge, username and HMAC-MD5 response, which 5600 parses directly, matching the scenario's hash type.

Why this answer

Hashcat mode 5600 is specifically designed for NetNTLMv2 hashes, which are generated during SMB authentication challenges captured through poisoning tools like Responder. Understanding these specific hash modes is critical for pentesters to quickly transition from passive or active credential capture to offline brute-forcing and dictionary attacks against Windows domain environments.

Exam trap

Candidates frequently confuse mode 5600 with mode 1000, which is standard NTLM, leading to immediate cracking failures because Hashcat cannot parse the challenge-response structure of NetNTLMv2.

267
Multi-Selecthard

You are planning a penetration test for a financial institution that operates a large mainframe environment. The client wants to ensure that the test does not disrupt critical batch processing jobs. Which TWO of the following are the MOST important items to include in the Rules of Engagement (RoE) to address this concern? (Choose two.)

Select 2 answers
A.A clause allowing the tester to disable antivirus software on the mainframe during testing.
B.A provision to use only automated scanning tools to minimize manual intervention.
C.A list of emergency contacts for both the penetration testing team and the client's operations staff.
D.A detailed schedule of allowed testing windows that avoid batch processing periods.
E.A requirement that all testing be conducted from an external IP address.
AnswersC, D

Emergency contacts are essential for rapid communication if testing inadvertently affects batch processing. If a test causes an outage or performance degradation, both parties need to coordinate immediately to mitigate impact. The RoE should include names, phone numbers, and escalation procedures to ensure a swift response.

Why this answer

The most critical RoE elements to avoid disrupting batch processing are clearly defined testing windows and emergency contacts. Testing windows prevent conflicts with scheduled jobs, while emergency contacts enable quick resolution if problems arise. Together, they balance thorough testing with operational stability.

Exam trap

The trap here is focusing on technical controls or tool restrictions instead of the scheduling and communication mechanisms that directly prevent operational disruption.

268
MCQhard

An attacker uses a 'redirector' in their C2 infrastructure. What is the primary purpose of this architectural component?

A.To increase the bandwidth of the C2 connection.
B.To provide a layer of obfuscation for the C2 server.
C.To translate commands into local system calls.
D.To manage the encryption keys for the C2 channel.
AnswerB

Redirectors hide the true IP address of the C2 server by serving as a proxy. If a redirector is identified and blocked, the attacker can quickly pivot to a new redirector while the primary C2 server remains safely tucked away, ensuring the core infrastructure stays operational.

Why this answer

Redirectors act as a layer of separation between the compromised host and the actual C2 server. They proxy the incoming beacon traffic to the real server, masking the location of the true command infrastructure. This protects the C2 server from being directly identified and blacklisted, as the traffic appears to originate from the redirector node.

This is a critical component for maintaining a resilient and stealthy operational environment.

Exam trap

Candidates often assume a redirector is meant to increase connection speed or provide redundancy. They miss its primary tactical purpose: hiding the true location of the C2 server.

269
MCQmedium

During a penetration test, you successfully obtain an encrypted NTLM hash but are unable to crack it. What is the most effective alternative strategy to gain access to the system?

A.Attempt a brute-force attack on the Kerberos TGT.
B.Perform a Pass-the-Hash attack using the captured hash.
C.Use a social engineering attack to reset the password.
D.Re-run the cracking attack with a longer wordlist.
AnswerB

Pass-the-Hash allows an attacker to authenticate as the user without needing the plaintext password. If the hash was obtained from a valid source, it can be injected into an authentication request, allowing the attacker to access services as if they had successfully cracked the password.

Why this answer

When an NTLM hash cannot be cracked, the most effective alternative is a Pass-the-Hash (PtH) attack. Because NTLM authentication verifies the user based on the knowledge of the hash rather than the plaintext password, an attacker can use the captured hash to authenticate to various network services directly. This approach is highly effective for lateral movement, bypassing the need for plaintext recovery while maintaining the ability to compromise the target system.

Exam trap

Candidates often think an uncrackable hash renders the asset secure, forgetting that authentication mechanisms accept the hash directly without requiring plaintext recovery.

270
MCQmedium

A penetration tester is performing an offline attack against a Windows domain. They have obtained the NTDS.dit file and the SYSTEM hive. Which tool is most effective for extracting the NTLM hashes for offline cracking?

A.Hashcat
B.Mimikatz
C.secretsdump.py
D.John the Ripper
AnswerC

Secretsdump.py is the definitive tool within the Impacket suite for performing local or remote secret extraction. By providing the NTDS.dit and SYSTEM hive files, it decrypts the database, allowing the tester to retrieve NTLM hashes for every user in the domain, which is essential for subsequent offline cracking attempts.

Why this answer

Impacket's secretsdump.py is the industry standard for parsing NTDS.dit files and SYSTEM hives to extract domain credentials. It leverages the boot key stored in the SYSTEM hive to decrypt the encrypted hashes within the NTDS.dit database. Understanding this process is critical for penetration testers because it represents the most common method of achieving domain-wide compromise after gaining the necessary domain controller files.

Exam trap

Many candidates mistakenly select Mimikatz for this specific offline task. While Mimikatz is powerful, it is primarily an in-memory tool, whereas secretsdump.py is the dedicated utility for parsing offline files.

271
MCQhard

You have compromised a workstation and extracted the NTLM hash of a service account that is configured for unconstrained delegation. You want to craft a Silver Ticket to impersonate a domain administrator when accessing a specific file server. Which piece of information is absolutely required to forge this ticket?

A.The domain SID and the target user's RID
B.A valid TGT for the service account
C.The service account's NTLM hash or Kerberos key
D.The krbtgt account's NTLM hash
AnswerC

A Silver Ticket is a forged service ticket (TGS) encrypted with the target service account's key. To create it, you need the NTLM hash or Kerberos key (AES) of the account under which the service runs. In this scenario, you have the service account's NTLM hash, which is exactly what is needed to encrypt the ticket and have it accepted by the file server without contacting the KDC.

Why this answer

To forge a Silver Ticket, the attacker must have the target service account's NTLM hash or Kerberos key to encrypt the service ticket. The domain SID and user RID are needed for the PAC but are not the encryption key. A TGT is not required because the ticket is presented directly to the service.

The krbtgt hash is for Golden Tickets.

Exam trap

The trap here is mixing up the key material needed for a Silver Ticket versus a Golden Ticket; the Silver Ticket uses the service account's key, not the krbtgt key.

272
MCQmedium

Which of the following describes the 'AS-REP Roasting' attack?

A.It targets service accounts that are configured with SPNs.
B.It relies on the interception of a TGS request to obtain encrypted credentials.
C.It allows an attacker to crack user account passwords for accounts without pre-authentication.
D.It is a technique for escalating privileges using the KRBTGT account.
AnswerC

When pre-authentication is disabled, the KDC will provide an AS-REP ticket to anyone who asks. This ticket is encrypted with the user's password. The attacker can capture this response and perform an offline brute-force attack to recover the original password.

Why this answer

AS-REP Roasting targets user accounts that have 'Do not require Kerberos preauthentication' enabled. An attacker can request a TGT for such an account without providing a password. The KDC responds with an encrypted ticket (the AS-REP) that the attacker can then extract and crack offline, similar to how Kerberoasting works, to obtain the user's plaintext password.

Exam trap

Many candidates confuse AS-REP Roasting with Kerberoasting. They incorrectly believe it involves requesting service tickets from the KDC, failing to realize it specifically targets accounts where pre-authentication is disabled.

273
MCQhard

Which TWO methods are commonly used to achieve C2 persistence while ensuring the communication remains resilient against infrastructure takedowns?

A.Implementing Domain Generation Algorithms (DGA).
B.Hardcoding the IP address of the C2 server.
C.Utilizing cloud providers for domain fronting.
D.Using unencrypted HTTP for all C2 traffic.
E.Requiring manual operator interaction for beaconing.
AnswerA, C

DGA allows malware to generate a vast number of pseudo-random domain names daily. The attacker only needs to register a small subset of these to maintain connectivity. This provides massive redundancy, as defenders cannot easily block all potential future domains before they are registered by the adversary.

Why this answer

Resilient C2 infrastructure often relies on decentralized or dynamic components to ensure that the connection remains viable even if individual nodes are identified and blocked. By utilizing domain generation algorithms and cloud-based relay services, attackers create a moving target that is difficult for incident responders to fully dismantle in a timely manner. Mastery of these techniques is essential for assessing the robust nature of an organization's defense-in-depth posture.

Exam trap

Test-takers frequently confuse persistence mechanisms meant to survive reboots (like registry run keys) with techniques designed specifically for resilient C2 infrastructure takedown defense.

274
MCQmedium

You are finalizing the Rules of Engagement (RoE) for a penetration test of a regional hospital network. The client's legal counsel requires that any testing activity be immediately suspended if a life-safety system is affected. Which element should you add to the RoE to satisfy this requirement?

A.A liability waiver transferring all damages from the testing firm to the hospital.
B.A requirement that all findings be delivered in a written report within thirty days of testing.
C.A documented emergency stop procedure with named client contacts and a defined notification method.
D.An expanded scan window that limits intrusive testing to overnight hours only.
AnswerC

An emergency stop procedure names the exact client personnel authorized to halt testing and defines how that order is communicated, which is what counsel needs to guarantee immediate suspension around life-safety systems. It converts an abstract requirement into an executable, auditable action with accountability, and it removes ambiguity about who can stop the engagement and how the tester must confirm the halt.

Why this answer

An emergency stop procedure is the operational control that lets the hospital halt testing instantly when a life-safety system is at risk. It specifies authorized personnel, the notification channel, and the required acknowledgment, making the requirement enforceable and auditable. Scheduling limits, waivers, and reporting timelines all operate after or around the event rather than stopping it in real time.

Exam trap

The trap here is assuming that restricting testing hours or adding legal language somehow provides the real-time halt authority that only a named emergency stop procedure delivers.

275
MCQmedium

During an Azure penetration test, you gain access to a Linux VM in a subnet that has a user-defined route forcing all traffic through a Network Virtual Appliance (NVA). You want to reach the Azure Instance Metadata Service (IMDS) to steal managed identity tokens. Which of the following best describes how you can access IMDS from this VM?

A.IMDS is reachable at 168.63.129.16, but the user-defined route will block access, requiring you to disable the route first.
B.IMDS is reachable at 169.254.169.254, and the user-defined route does not affect this link-local address, so you can query it directly from the VM.
C.IMDS is reachable at 169.254.169.254, but the user-defined route will redirect the request to the NVA, so you must use a proxy to reach it.
D.IMDS is reachable only from within the Azure portal, so you must use the Azure CLI from your attacker workstation to query it.
AnswerB

This is correct because IMDS uses the link-local address 169.254.169.254, which is handled by the Azure platform and bypasses user-defined routes and NVAs. From the compromised VM, you can directly query IMDS to obtain managed identity tokens without any network appliance interfering, making it a reliable credential theft vector.

Why this answer

The Azure Instance Metadata Service is a REST endpoint at 169.254.169.254 that provides metadata and managed identity tokens to VMs. Because it uses a link-local address, traffic to it is intercepted by the Azure platform and is not subject to user-defined routes, NVAs, or network security groups. An attacker on a compromised VM can directly query IMDS to obtain access tokens for any managed identity assigned to that VM, enabling lateral movement or privilege escalation.

Exam trap

The trap here is assuming that user-defined routes or NVAs can intercept or block IMDS traffic, when in fact link-local traffic to 169.254.169.254 bypasses such routing.

276
Multi-Selectmedium

You are planning an external penetration test for a financial services firm. The client's legal team wants assurance that the engagement can be defended if law enforcement or regulators inquire about the testing. Which TWO of the following should be included in the Rules of Engagement to provide this assurance? (Choose two.)

Select 2 answers
A.The penetration tester's personal home address and after-hours phone number.
B.A detailed exploit payload library the testers plan to use against production systems.
C.A list of authorized source IP addresses from which testing will originate.
D.A guarantee that no production system will experience any disruption during testing.
E.The names and contact details of the client's authorized signatories who approved the test.
AnswersC, E

Listing the source IP addresses used by the testing team allows the client's security operations center and any external parties to distinguish authorized traffic from real attacks. If law enforcement or a third party detects the activity, the client can produce documentation showing those specific IPs were sanctioned. This is a standard element of defensible Rules of Engagement for external testing.

Why this answer

Authorized source IP addresses and named client signatories are the two elements that most directly support legal defensibility. The source IPs let the client and authorities distinguish sanctioned traffic from real attacks, while the signatories establish a documented chain of authorization. Together they demonstrate that the activity was explicitly approved by authorized parties and originated from known, approved infrastructure.

Exam trap

The trap here is assuming that detailed technical tooling or absolute non-disruption guarantees strengthen legal defensibility, when authorization and source identification are what actually matter.

277
MCQmedium

You are performing an offline attack against a password hash stored in an NTDS.dit file. You have successfully dumped the hashes using secretsdump.py. Given the format 'Username:RID:LMHash:NTHash:::', which hash should be targeted for a modern Windows environment to maximize cracking efficiency?

A.The LMHash, because it is shorter and faster to calculate.
B.The RID, because it provides the unique identifier for the account.
C.The NTHash, because it is the primary hash used by NTLM authentication.
D.The entire string, including the colons, to ensure format integrity.
AnswerC

The NTHash is a MD4 hash of the Unicode representation of the plaintext password. Since Windows Vista, NTLM has become the standard authentication protocol. Targeting the NTHash allows for direct pass-the-hash exploitation without needing the plaintext, making it the most effective target for modern penetration testing engagements.

Why this answer

Modern Windows systems prioritize NTLM authentication, which relies on the NTHash. The LM hash is deprecated, weak, and often stored as a null value or a fixed constant in modern systems. Targeting the NTHash allows for pass-the-hash attacks or brute-force attempts that align with the underlying authentication protocol.

Understanding the structure of these hashes is crucial for penetration testers to select the correct dictionary or mask attack strategies during local account auditing.

Exam trap

Test-takers frequently focus on legacy LM hashes or duplicate empty fields, forgetting that modern Windows environments exclusively rely on NTLM authentication and NTHashes.

278
Multi-Selectmedium

You are conducting a penetration test against a web application. During exploitation, you identify a SQL injection vulnerability that allows you to execute arbitrary SQL queries. You want to leverage this to gain remote code execution on the underlying database server. Which TWO of the following techniques are most likely to achieve this goal? (Choose two.)

Select 2 answers
A.Exploiting the SQL injection to write a web shell to the web server's root directory using INTO OUTFILE.
B.Injecting a stored procedure that uses the LOAD_FILE function to read sensitive files from the server.
C.Performing a blind SQL injection to infer the database schema and then using that information to craft a more targeted attack.
D.Using UNION-based SQL injection to extract data from the database and then cracking password hashes offline.
E.Using stacked queries to execute operating system commands via xp_cmdshell on a Microsoft SQL Server.
AnswersA, E

If the database user has FILE privileges and the web server directory is writable, you can use INTO OUTFILE to write a web shell (e.g., PHP) to a web-accessible location. This directly leads to remote code execution by accessing the shell via a browser. It is a common and effective technique when the database and web server are on the same host.

Why this answer

The two techniques that directly lead to remote code execution from SQL injection are writing a web shell via INTO OUTFILE and using xp_cmdshell on MSSQL. Both require specific privileges and configurations but are proven methods to escalate from SQL injection to full command execution on the server. Other options focus on data extraction or reading files, which do not directly achieve RCE.

Exam trap

The trap here is confusing data extraction techniques like UNION-based or blind SQL injection with methods that directly execute code, such as writing a web shell or using xp_cmdshell.

279
MCQmedium

A penetration tester has obtained a single NT hash for a domain user account during an internal engagement. The tester wants to authenticate to a remote Windows 10 workstation as that user without knowing the plaintext password. Which tool is designed to perform this authentication using only the NT hash?

A.Responder with the -w flag
B.Hydra with the -H option
C.Nmap with the smb-enum-users script
D.Mimikatz with the sekurlsa::pth module
AnswerD

Mimikatz's sekurlsa::pth module performs Pass-the-Hash by injecting the NT hash into a new logon session, allowing authentication to remote systems without the plaintext password. It is a standard tool for this scenario in internal penetration tests.

Why this answer

Pass-the-Hash uses the NT hash itself as the credential to authenticate to remote systems. Mimikatz's sekurlsa::pth module injects the hash into a new logon session, enabling the tester to access resources as the target user without recovering the plaintext password. Other tools listed perform different functions such as poisoning, enumeration, or online brute-force, and cannot authenticate with an NT hash.

Exam trap

The trap here is confusing tools that capture hashes with tools that use hashes to authenticate; Pass-the-Hash requires injecting the hash into a logon session, not just possessing it.

280
MCQmedium

You are conducting an internal penetration test for a client that uses Microsoft Entra ID with on-premises Active Directory. You have obtained Domain Admin credentials in the on-premises domain. The client has deployed Microsoft Entra Connect with Seamless Single Sign-On (SSO) enabled. Which of the following actions would allow you to authenticate as any synchronized user to cloud services like Microsoft 365 WITHOUT knowing their password?

A.Extract the AZUREADSSOACC computer account password hash from the on-premises Active Directory and forge Kerberos service tickets for the cloud service principal.
B.Retrieve the on-premises user's password hash from the domain controller and use it to authenticate to Microsoft Entra ID via password hash synchronization.
C.Leverage the Seamless SSO computer account to perform a Silver Ticket attack against the on-premises domain controller and then access cloud resources.
D.Use the Directory Synchronization Account credentials to modify the source anchor attribute of a targeted user to point to a new on-premises object.
AnswerA

The AZUREADSSOACC computer account is created in on-premises Active Directory when Seamless SSO is configured. Its password hash is used to sign Kerberos tickets for the Azure AD service principal. With Domain Admin rights, an attacker can extract this hash and forge service tickets, allowing authentication as any synchronized user without their password. This is a known attack path in hybrid identity environments.

Why this answer

With Domain Admin privileges, an attacker can extract the password hash of the AZUREADSSOACC computer account, which is used for Seamless Single Sign-On. This hash allows forging Kerberos service tickets for the Azure AD service principal, enabling authentication as any synchronized user without their password. This is a critical risk in hybrid identity configurations where Seamless SSO is enabled.

Exam trap

The trap here is assuming that password hash synchronization or directory synchronization account compromise directly allows cloud authentication, when actually Seamless SSO's AZUREADSSOACC account is the key target.

281
MCQeasy

A penetration tester has gained a foothold on a Windows host and wants to escalate privileges. They discover that the host has an unquoted service path vulnerability. Which command should they use to identify services with unquoted paths that contain spaces?

A.tasklist /svc | findstr /i "svchost"
B.sc query type= service state= all | findstr /i "SERVICE_NAME"
C.wmic service get name,displayname,pathname,startmode | findstr /i "auto" | findstr /i /v "c:\windows\\"
D.net start | findstr /i "service"
AnswerC

This wmic command lists services with their pathname and start mode, filters for auto-start services, and excludes those in the Windows directory. Unquoted service paths with spaces are a common privilege escalation vector. This command helps identify such services, making it a standard enumeration step.

Why this answer

Unquoted service paths with spaces allow a tester to place a malicious executable in a directory that Windows will search before the intended binary. The wmic command with the specified filters lists auto-start services and their paths, excluding Windows directory services, making it efficient for spotting vulnerable services.

Exam trap

The trap here is confusing service enumeration commands that list names with those that reveal binary paths.

282
MCQmedium

Which of the following actions is the best way to detect an attacker performing an offline hash-cracking operation within a corporate network?

A.Monitoring for high CPU usage on all workstations.
B.Logging access to the LSASS process and SAM hives.
C.Scanning for the use of the Hashcat tool on the network.
D.Monitoring for network traffic to known cracking websites.
AnswerB

Credential dumping tools must interact with the LSASS process or read the SAM registry hive to obtain hashes. Monitoring these specific, high-risk actions provides a direct alert for the activity that enables offline cracking, allowing security teams to respond before the hashes are successfully exfiltrated from the network.

Why this answer

Detecting an offline attack is challenging because the actual computation happens on the attacker's hardware. However, the initial phase—dumping the hashes from memory or the SAM file—requires access to sensitive system files or processes. By monitoring for access to the LSASS process or reading the SAM/SYSTEM registry hives, security teams can identify the signature of a credential dumping attempt, which is the necessary precursor to any offline attack.

Exam trap

Candidates mistakenly look for network traffic indicators of offline cracking, forgetting that the actual password guessing computation occurs entirely offline on the attacker's isolated machine.

283
MCQmedium

Which Kerberos feature is specifically exploited when an attacker uses 'constrained delegation' to escalate privileges?

A.The TGT's ability to be renewed indefinitely.
B.The S4U2Self and S4U2Proxy extensions.
C.The PAC validation performed by the Domain Controller.
D.The ability to use RC4 encryption for TGS requests.
AnswerB

S4U2Self allows a service to get a ticket for itself on behalf of a user, and S4U2Proxy allows the service to request a ticket to a second service on behalf of that user. These extensions are the technical foundation for constrained delegation in Active Directory.

Why this answer

Constrained delegation allows a service to impersonate a user to a specific set of other services, defined in the 'msDS-AllowedToDelegateTo' attribute. If an attacker compromises a service account configured for constrained delegation, they can request a service ticket for any user to the allowed target services. This allows the attacker to pivot throughout the network while impersonating high-privilege users without needing their credentials.

Exam trap

Candidates frequently select unconstrained delegation extensions or standard ticket-granting ticket options, confusing the specific S4U mechanisms used in constrained delegation attacks.

284
MCQeasy

During planning for a penetration test, the client states the goal is to evaluate how well the security operations center detects and responds to attacker activity. Which engagement type best aligns with this objective?

A.A vulnerability assessment that enumerates and rates missing patches across the environment.
B.A wireless survey mapping access point coverage and rogue device presence.
C.A compliance audit against a regulatory framework with control-by-control evidence collection.
D.A red team engagement that emulates adversary tactics and measures detection and response.
AnswerD

A red team engagement emulates realistic adversary behavior and is judged partly on whether the defensive team detects, investigates, and responds to that activity. Because the client explicitly wants to evaluate SOC detection and response rather than just find vulnerabilities, this objective-driven approach produces the telemetry and process observations needed to measure blue-team performance.

Why this answer

When the goal is evaluating detection and response, the engagement should generate realistic adversary activity that the defensive team can observe and act on. A red team engagement does exactly that, with objectives tied to whether the SOC detects, investigates, and contains the simulated intrusion, producing measurable findings about people and process rather than only technical weaknesses.

Exam trap

The trap here is equating the client's desire to test detection capability with a standard vulnerability assessment, when only an objective-driven adversary emulation exercises the SOC's response process.

285
MCQmedium

During a reconnaissance project, you use the 'theHarvester' tool against a target. What information is this tool designed to extract?

A.Internal employee passwords from active memory.
B.Emails, subdomains, and user names from public sources.
C.SQL injection vulnerabilities on web forms.
D.Full network topology maps including internal routers.
AnswerB

theHarvester excels at aggregating email addresses, subdomains, and potential usernames from various public sources like Google, Bing, and PGP servers. This data provides the tester with a list of potential targets and infrastructure endpoints, which is a critical initial step for any penetration test that involves social engineering.

Why this answer

theHarvester is a widely used OSINT tool designed to gather emails, subdomains, and hostnames from various public sources like search engines and PGP key servers. This information is vital for mapping the organization's digital footprint and identifying targets for social engineering. Its ability to aggregate this data from multiple sources makes it an essential tool for penetration testers aiming to build a comprehensive map of an organization's public-facing presence.

Exam trap

Candidates often assume the tool performs active scanning or credential brute-forcing, failing to recognize that it is strictly an OSINT tool for gathering information from public, passive sources.

286
Multi-Selecthard

You are performing passive reconnaissance on a target organization that uses a cloud-based email service. You want to gather information about the organization's email infrastructure and potential phishing targets without alerting the target. Which TWO of the following techniques would be most effective and appropriate for this goal? (Choose two.)

Select 2 answers
A.Run a brute-force attack on the target's OWA login page to guess passwords.
B.Perform a dictionary attack against the target's SMTP server to enumerate valid email addresses.
C.Use the Hunter.io API to discover email addresses associated with the target's domain.
D.Send test emails to common addresses like info@ and support@ to see which ones bounce.
E.Query the target's MX records using a public DNS resolver to identify the email provider.
AnswersC, E

Hunter.io aggregates email addresses from public sources such as websites, social media, and data breaches. Querying its API does not contact the target's servers, so it remains passive. It can reveal both generic and personal email addresses, which are useful for phishing simulations or social engineering. This technique is especially effective for cloud-based email services where addresses may not follow a predictable pattern.

Why this answer

Querying MX records via a public resolver reveals the email provider without touching the target. Using Hunter.io's API collects email addresses from third-party databases, also without target contact. Both techniques are passive, effective for mapping email infrastructure, and provide valuable data for phishing or social engineering while avoiding detection.

Exam trap

The trap here is assuming that any email-related enumeration is passive; techniques like SMTP VRFY or sending test emails actively engage the target and are not appropriate when stealth is required.

287
MCQeasy

You are tasked with gathering information about a target organization's employees to craft a phishing campaign. Which of the following tools is specifically designed to collect email addresses, subdomains, and hostnames from public sources like search engines and PGP key servers?

A.Recon-ng
B.Shodan
C.Maltego
D.theHarvester
AnswerD

theHarvester is a reconnaissance tool that gathers emails, subdomains, hosts, employee names, open ports, and banners from public sources. It queries search engines, PGP key servers, and other databases. This makes it ideal for collecting information to support social engineering or phishing campaigns.

Why this answer

theHarvester is specifically built to collect email addresses, subdomains, and hostnames from public sources such as search engines and PGP key servers. Its focused functionality makes it the most appropriate tool for gathering employee information to support a phishing campaign. Other tools may have overlapping capabilities but are not as specialized for this task.

Exam trap

The trap here is assuming that any OSINT tool can harvest emails, but theHarvester is uniquely streamlined for this purpose, whereas others like Maltego or Recon-ng require more configuration.

288
MCQmedium

Which of the following describes the risk of 'App Role' over-assignment in Azure AD?

A.It increases the likelihood of a brute-force attack on the tenant.
B.It allows an attacker to escalate privileges if a user account is compromised.
C.It automatically bypasses the need for Multi-Factor Authentication.
D.It prevents the application from using external OAuth2 scopes.
AnswerB

If a user is assigned an administrative app role, any attacker who compromises that user's account gains those high-level permissions within the application. This makes over-assignment a direct path to privilege escalation, allowing attackers to access features or data that the average user should never touch.

Why this answer

App Roles define what a user or application can do within a specific application context. If an administrator assigns 'Admin' roles to too many users, an attacker compromising any one of those users gains elevated privileges within that application. This lateral movement risk emphasizes the need to assign roles to groups rather than individual users and to audit role assignments periodically to ensure least privilege.

Exam trap

Candidates frequently confuse Azure AD global roles with application-specific roles, missing how localized app role over-assignment still permits significant lateral movement.

289
MCQmedium

You are configuring a Cobalt Strike beacon for a penetration test. The client's security team monitors for periodic beaconing patterns. You want to reduce the chance of detection by network behavior analysis. Which beacon setting should you adjust?

A.Change the user agent to match a common browser.
B.Use a self-signed certificate for the HTTPS listener.
C.Increase the sleep time and add jitter.
D.Enable the TCP beacon instead of HTTPS.
AnswerC

Increasing sleep time reduces the frequency of beacon check-ins, and adding jitter introduces randomness to the intervals. This makes the traffic less periodic and harder to detect via timing analysis. Network behavior analytics often flag regular intervals, so jitter helps break that pattern. This directly addresses the concern about periodic beaconing detection.

Why this answer

Adjusting sleep time and jitter directly modifies the beacon's communication schedule, making it less predictable. Longer sleep intervals reduce traffic volume, and jitter adds randomness, breaking the periodic pattern that network behavior analysis seeks. Other options affect different layers (application headers, transport, or TLS) but do not address the timing-based detection described.

Exam trap

The trap here is thinking that changing the user agent or certificate will hide the beacon, but the detection is based on timing patterns, not content.

290
MCQmedium

During an assessment, you discover a federated identity setup using AD FS. What is a common security risk associated with the reliance on the token-signing certificate in this architecture?

A.The certificate is public knowledge and can be used to decrypt all cloud traffic.
B.Compromise of the private signing key allows for the creation of unauthorized authentication tokens.
C.AD FS requires the certificate to be stored in an unsecured plaintext file on the web server.
D.The relying party cannot verify the identity if the certificate expires.
AnswerB

If the private key is exposed, an attacker can sign fraudulent SAML assertions. These assertions are trusted by Azure AD as valid identity claims, effectively allowing the attacker to sign in as any user without needing their password or passing the actual identity provider's authentication checks.

Why this answer

The token-signing certificate is the foundation of trust in a federated environment. If an attacker compromises the private key of this certificate, they can forge SAML tokens for any user in the directory. This bypasses Multi-Factor Authentication and allows for complete identity impersonation, making the protection of the AD FS server and its associated secrets a critical objective for both defenders and attackers.

Exam trap

Candidates often think about password cracking or brute force. They overlook that the signing certificate is the 'root of trust' for federated identities, making it the most critical target.

291
MCQeasy

Which of the following describes the 'Persistence' phase in the context of the cyber kill chain?

A.Gaining initial access to a target network via phishing.
B.Maintaining a presence on the system through system restarts.
C.Exfiltrating sensitive data to an external server.
D.Encrypting the system for ransomware purposes.
AnswerB

Persistence is specifically defined as the mechanism used to maintain a foothold on a system across reboots and other events. It allows the attacker to regain access without having to re-exploit the initial vulnerability, which might have been patched or otherwise remediated since the initial entry was gained.

Why this answer

Persistence ensures that an attacker maintains access to a system even after reboots, credential changes, or other disruptions. This is achieved through various techniques like scheduled tasks, registry modifications, or backdoored services. Persistence is vital for long-term intelligence gathering and ensures that the attacker remains within the environment to pursue their objectives despite potential detection or system maintenance activities performed by legitimate users.

Exam trap

Candidates frequently confuse persistence with lateral movement or privilege escalation, failing to recognize that persistence specifically refers to maintaining access across system disruptions like reboots or logouts.

292
MCQhard

A penetration tester is reviewing an Azure Logic App that uses a managed identity to access an Azure SQL Database. The tester finds that the Logic App's workflow definition is stored in a storage account that is publicly accessible. The workflow includes a step that executes a stored procedure with parameters. Which of the following is the most significant risk of this misconfiguration?

A.An attacker can modify the workflow to exfiltrate data from the SQL Database using the managed identity.
B.An attacker can disable the managed identity by deleting the Logic App.
C.An attacker can use the managed identity to authenticate to Azure AD and create new users.
D.An attacker can retrieve the managed identity's client secret from the workflow definition.
AnswerA

If the workflow definition is publicly accessible and can be modified, an attacker could alter the workflow to include malicious actions, such as querying sensitive data and sending it to an external endpoint. The managed identity would execute these actions with its permissions, leading to data exfiltration. This is a severe risk because the managed identity likely has access to the database, and the attacker can leverage that without needing credentials.

Why this answer

The most significant risk is that an attacker can modify the publicly accessible workflow definition to perform malicious actions using the managed identity's privileges. Since the managed identity can access the SQL Database, the attacker could alter the workflow to extract data and send it externally. This highlights the importance of securing Logic App definitions and limiting access to storage accounts.

Exam trap

The trap here is assuming that the managed identity's secret is exposed or that the attacker can delete resources, rather than focusing on the ability to modify the workflow to abuse the identity's permissions.

293
MCQmedium

During an internal penetration test, you capture an NTLMv2 hash challenge-response pair from a network segment. You want to crack the user's password using Hashcat. Which hashcat attack mode and hash format identifier should you use to crack this specific challenge-response pair efficiently on a modern GPU?

A.Mode 1000, which targets local Windows SAM NT hashes extracted from a compromised registry hive export.
B.Mode 5500, which is designed exclusively for cracking legacy NTLMv1 network authentication challenge-response pairs.
C.Mode 5600, which targets NetNTLMv2 hashes captured during network authentication events or LLMNR/NBT-NS spoofing attacks.
D.Mode 3000, which processes LanMan hashes historically found on very old Windows NT and 95 operating systems.
AnswerC

Mode 5600 targets the NetNTLMv2 challenge-response format, which is exactly what a captured NTLMv2 pair represents — not the stored NTLM hash (mode 1000). Hashcat reconstructs the HMAC-MD5 response using the captured server challenge, so GPU cracking proceeds efficiently against the network-captured pair.

Why this answer

Hashcat utilizes mode 5600 specifically for NetNTLMv2 hashes, which allows leveraging high-speed GPU acceleration to perform dictionary and mask attacks against captured enterprise authentication handshakes. Selecting the correct mode ensures hashcat parses the challenge, username, domain, and response fields accurately according to the standard NTLMv2 response format specification.

Exam trap

Candidates frequently confuse NTLMv1 and NTLMv2 modes in Hashcat, or attempt to use mode 1000 which is meant for the local SAM NT hash rather than network authentication captures.

294
MCQmedium

A penetration tester has obtained a password hash from a Windows system: `aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0`. They attempt to crack it using Hashcat with mode 1000 but are unable to recover any plaintext. What is the most likely explanation for this failure?

A.The hash is a domain cached credential and requires mode 2100.
B.The hash is salted, and Hashcat mode 1000 does not support salts.
C.The LM hash is empty, and the NT hash corresponds to a blank password.
D.The hash was captured from a Kerberos ticket and requires mode 13100.
AnswerC

The LM portion `aad3b435b51404eeaad3b435b51404ee` is the well-known constant for an empty LM hash, and the NT hash `31d6cfe0d16ae931b73c59d7e0c089c0` is the NT hash of an empty string. Hashcat mode 1000 targets NTLM, but cracking a blank password yields no plaintext because the password is empty; the tool may not output it by default. Thus, the failure is due to the password being blank, not a format mismatch.

Why this answer

The hash consists of an LM part and an NT part separated by a colon. The LM part `aad3b435b51404eeaad3b435b51404ee` is the constant for an empty LM hash, and the NT part `31d6cfe0d16ae931b73c59d7e0c089c0` is the NT hash of an empty password. Hashcat mode 1000 correctly handles NTLM, but since the password is blank, cracking yields an empty string, which may not be displayed.

Thus, the failure is due to the password being blank, not a mode or salt issue.

Exam trap

The trap here is assuming that a failure to crack indicates an unsupported hash format or missing salt, when the password is simply blank and the tool may not output an empty plaintext.

295
MCQmedium

During a penetration test, you successfully inject a payload into a web application that results in the server executing system commands with elevated privileges. Which phase of the exploitation lifecycle does this action primarily represent?

A.Reconnaissance
B.Vulnerability Assessment
C.Exploitation
D.Post-Exploitation
AnswerC

Exploitation involves the active use of a vulnerability to gain unauthorized access or elevated privileges on a target. In this case, injecting a payload to execute system commands directly maps to this phase, as the tester is leveraging an identified flaw to manipulate the application's runtime behavior.

Why this answer

This scenario demonstrates the execution of arbitrary code, which is the core of the exploitation phase. Exploitation is the process of leveraging a vulnerability to gain unauthorized access or control over a target system. Understanding this transition from vulnerability discovery to exploitation is critical for testers to effectively assess the impact of security flaws and demonstrate real-world risk to stakeholders during the assessment reporting phase.

Exam trap

Candidates frequently confuse the 'exploitation' phase with 'post-exploitation' or 'vulnerability assessment,' failing to recognize that the actual execution of the code is the definition of exploitation.

296
MCQmedium

You are conducting passive reconnaissance against a target that uses a Web Application Firewall (WAF) and a Content Delivery Network (CDN). You want to discover the origin IP address of the web server to bypass the CDN during later testing. Which technique is most likely to reveal the origin IP without sending any traffic to the target's domain?

A.Send HTTP requests with a spoofed Host header to the CDN edge servers.
B.Query the target's SPF record to find the origin IP.
C.Use a third-party service like SecurityTrails to view historical DNS records.
D.Perform a DNS zone transfer against the target's authoritative nameserver.
AnswerC

SecurityTrails and similar services maintain historical DNS data. Before the target adopted a CDN, its A records may have pointed directly to the origin IP. By querying these historical records, you can often find the original IP address. This is a passive technique because you are querying a third-party database, not the target. It is highly effective for discovering origin IPs that are now hidden behind a CDN.

Why this answer

Historical DNS records from services like SecurityTrails are a passive way to discover an origin IP that was used before the CDN was implemented. Because the data is stored by a third party, querying it does not touch the target's CDN or origin. This makes it a safe and effective method for bypassing CDN obfuscation during reconnaissance.

Exam trap

The trap here is assuming that any DNS query is passive; querying the target's nameserver directly is active, while querying a third-party historical database is passive.

297
Multi-Selecthard

You are using Cobalt Strike in an authorized penetration test. The target network uses a next-generation firewall that performs SSL inspection and blocks self-signed certificates. You need to configure your HTTPS beacon to blend in with legitimate traffic and avoid detection. (Choose two.)

Select 2 answers
A.Enable the TCP beacon instead of the HTTPS beacon.
B.Use a self-signed certificate but set the beacon's user agent to match a common browser.
C.Set the beacon's sleep time to 60 seconds with 30% jitter.
D.Configure the beacon to use a malleable C2 profile that mimics a known application like Microsoft Outlook Web Access.
E.Use a valid SSL certificate from a trusted certificate authority for the C2 listener.
AnswersD, E

A malleable C2 profile customizes the beacon's network traffic to resemble a legitimate application. By mimicking Outlook Web Access, the traffic's HTTP headers, URIs, and other characteristics match normal OWA usage. This helps evade deep packet inspection and application-based blocking, complementing the valid certificate. It makes the beacon traffic blend in with expected enterprise traffic, reducing the chance of detection.

Why this answer

To evade SSL inspection and blend in, using a valid certificate from a trusted CA ensures the TLS handshake is accepted, and a malleable C2 profile mimicking a known application like OWA makes the traffic appear legitimate at the application layer. Together, they address both certificate trust and traffic pattern detection. Other options do not resolve the certificate blocking or are less effective for blending.

Exam trap

The trap here is focusing solely on traffic shaping (sleep/jitter) or user agent strings while overlooking the need for a trusted certificate to pass SSL inspection.

298
MCQhard

During an authorized penetration test, you have gained a low-privileged shell on a Linux host. You discover that the kernel is version 4.4.0-116-generic and the system is missing several patches. You want to escalate privileges to root. Which of the following is the most reliable and safe method to achieve privilege escalation?

A.Run a kernel exploit such as Dirty COW (CVE-2016-5195) to overwrite /etc/passwd and add a root user.
B.Use Metasploit's local exploit suggester module to automatically find and run a suitable exploit.
C.Use a public exploit for CVE-2017-16995 (BPF verifier) to gain root, as it is known to work on this kernel version.
D.Search for misconfigured SUID binaries and exploit them using GTFOBins techniques.
AnswerD

This is often the most reliable and safe method because it leverages existing misconfigurations rather than exploiting kernel vulnerabilities. SUID binaries with known privilege escalation vectors (e.g., find, vim, nmap) can be exploited without causing system instability. It is also less likely to be detected by security controls and does not require kernel-specific exploits.

Why this answer

Privilege escalation via misconfigured SUID binaries is often the safest and most reliable because it exploits existing permissions rather than kernel vulnerabilities. Kernel exploits carry a higher risk of crashing the system and are version-dependent. Enumerating SUID binaries and using GTFOBins to identify exploitation vectors is a standard practice in penetration testing, allowing for privilege escalation without destabilizing the host.

Exam trap

The trap here is focusing on kernel exploits as the primary method, overlooking that misconfigurations like SUID binaries are often easier, safer, and more reliable for privilege escalation.

Page 3

Page 4 of 4

All pages