Courseiva

CCNA Escalation and Exploitation Questions

17 questions · Escalation and Exploitation · All types, answers revealed

1
MCQhard

During a Windows assessment you obtain a low-privileged domain user's credentials. Enumeration reveals a Group Policy Preference file on a readable SYSVOL share containing a cpassword value. What is the most effective next step to escalate privileges?

A.Decrypt the cpassword value using the publicly known AES key and authenticate as the account it protects.
B.Crack the cpassword value with hashcat using the NTLM hash mode.
C.Relay the cpassword value to an SMB service to obtain a session on a file server.
D.Use the cpassword value directly in a pass-the-hash authentication against a domain controller.
AnswerA

Group Policy Preferences stored credentials in cpassword fields encrypted with a static AES key that Microsoft published in MS14-025 documentation. Tools such as gpp-decrypt recover the plaintext instantly, and the recovered credential often belongs to a privileged account. Because the key is fixed and public, no cracking is required, making decryption the direct and effective escalation step.

Why this answer

Credentials in Group Policy Preferences were encrypted with a static AES key that Microsoft published, so a cpassword value found on SYSVOL can be decrypted immediately with tools like gpp-decrypt. The recovered plaintext often belongs to a privileged account, and because no cracking or protocol interaction is required, decryption is the fastest route to privilege escalation from the low-privileged credentials already held.

Exam trap

The trap here is treating the cpassword value as a hash that must be cracked or relayed, when it is reversibly encrypted with a public key.

2
MCQmedium

During a penetration test, you successfully exploit a web application via SQL injection. You want to use this access to achieve remote code execution (RCE) on the underlying Windows database server. Which feature should you look for to facilitate this?

A.Database backup functionality
B.Stored procedure execution via xp_cmdshell
C.Database triggers on update
D.Database user enumeration
AnswerB

xp_cmdshell is a powerful stored procedure in Microsoft SQL Server that spawns a Windows command shell and passes in a command string for execution. It is the primary target for testers attempting to escalate from SQL injection to remote code execution on the underlying database server host.

Why this answer

Database features like 'xp_cmdshell' in Microsoft SQL Server allow for the execution of arbitrary operating system commands from within a SQL query. If the database service account has sufficient privileges, this allows an attacker to pivot from SQL injection to full system command execution. Checking for this feature is a critical step in escalating database access to server-level administrative control.

Exam trap

Candidates often look for generic web shell upload methods instead of focusing on native database administrative features specific to Microsoft SQL Server like xp_cmdshell.

3
MCQmedium

You are performing a penetration test and discover a service running as SYSTEM that is vulnerable to DLL hijacking. What is the most appropriate action to take to ensure the test is successful and safe?

A.Immediately drop a reverse shell.
B.Use a benign DLL to prove execution.
C.Reboot the server to force the service to restart.
D.Modify the Windows Registry to disable the service.
AnswerB

Using a benign DLL that launches a non-critical application or writes to a log file is the safest way to demonstrate the vulnerability. It proves code execution with SYSTEM privileges without causing service instability or creating a persistent backdoor that could be misused if detected by third parties.

Why this answer

DLL hijacking involves placing a malicious DLL in a directory that a process searches before the legitimate DLL. To do this safely, you must ensure the DLL does not crash the service, which would cause a denial of service. Using a benign payload, such as one that launches a notepad process or logs a specific action, confirms the vulnerability without disrupting the client's business operations.

Exam trap

Candidates often rush to deploy full reverse shell payloads during DLL hijacking, risking service crashes and unintended denial of service on high-privilege system applications.

4
MCQhard

When escalating privileges using a Kernel exploit, why is it considered a high-risk activity for a penetration test?

A.It requires the user to have administrative credentials.
B.It frequently causes system instability and crashes.
C.It is easily detected by standard antivirus software.
D.It can only be executed on outdated operating systems.
AnswerB

Kernel exploits manipulate memory structures at a very low level. Small errors in memory alignment or incorrect assumptions about the OS state lead to immediate kernel panics or crashes. This downtime is a major business impact, making kernel exploits the highest-risk category of penetration testing activities.

Why this answer

Kernel exploits target the core of the operating system. If the exploit fails or contains errors, it frequently leads to a system crash (Blue Screen of Death). This causes significant downtime for the client, which is usually prohibited.

Because kernel-level code runs with the highest possible privilege, any mistake results in immediate system instability, making it one of the most dangerous vectors to test in a production environment.

Exam trap

Candidates often focus on the 'success' of the exploit rather than the 'risk' to the system, ignoring that kernel crashes are a primary concern in production environments.

5
MCQhard

During a penetration test on a Linux server, you find a cron job that runs every minute as root: '*/1 * * * * root /usr/local/bin/backup.sh'. The script is owned by root but has permissions 777. You are a low-privileged user. What is the most direct way to escalate privileges?

A.Create a malicious shared library and use LD_PRELOAD in the script's environment.
B.Use the cron job to copy /etc/shadow to a world-readable location.
C.Modify the backup.sh script to include a reverse shell command.
D.Replace the /usr/local/bin/backup.sh with a symbolic link to /bin/bash.
AnswerC

Since the script is world-writable (777), you can edit it to execute arbitrary commands. The cron job runs as root every minute, so your modified script will execute with root privileges. Adding a reverse shell or copying /bin/bash with SUID will grant you root access. This is a direct and reliable escalation because you control the script's content and it runs as root without any additional checks.

Why this answer

The most direct escalation is to modify the world-writable script because it runs as root every minute. By adding a command to create a reverse shell or copy /bin/bash with SUID permissions, you gain root access. Other methods like LD_PRELOAD or symlinking are less reliable or indirect.

The writable script is a clear privilege escalation vector.

Exam trap

The trap here is overcomplicating the escalation when a simple file write to a root-executed script is available; testers sometimes overlook the obvious writable script.

6
MCQmedium

During an internal assessment, you gain a foothold as a low-privileged domain user on a Windows Server 2019 host that is a member of an Active Directory domain. You run whoami /priv and observe SeImpersonatePrivilege enabled in your token. You need to escalate to NT AUTHORITY\SYSTEM on this host. Which technique is most appropriate?

A.Run a Kerberoasting attack against all service accounts and crack the resulting RC4 hashes offline to obtain a domain administrator password.
B.Extract cached domain credentials from the registry using reg save on the SAM and SYSTEM hives and crack them with hashcat.
C.Abuse SeImpersonatePrivilege with a token impersonation tool such as JuicyPotato, RoguePotato, or PrintSpoofer, depending on the OS build.
D.Perform an unquoted service path attack by placing a malicious executable in a directory whose path contains a space and is writable.
AnswerC

SeImpersonatePrivilege lets a process impersonate a token handed to it by a client, and tools like PrintSpoofer or the Potato family coerce a SYSTEM-privileged service into authenticating so the token can be captured and reused. On Server 2019 the classic JuicyPotato CLSID path is patched, so PrintSpoofer or RoguePotato is the working variant here.

Why this answer

SeImpersonatePrivilege allows a process to take on the security context of a token it receives, and privileged Windows services can be coerced into connecting to an attacker-controlled listener. Tools such as PrintSpoofer and RoguePotato exploit that behavior to obtain a SYSTEM token on modern Windows builds where older Potato techniques no longer work. Because the privilege is already present in the token, this is the direct escalation route.

Exam trap

The trap here is assuming any Potato tool works on any Windows build, when patched builds like Server 2019 require PrintSpoofer or RoguePotato instead of the classic JuicyPotato CLSID abuse.

7
Multi-Selecthard

You have gained standard user execution rights on a hardened Windows 10 enterprise workstation and need to enumerate local privilege escalation vectors. Which TWO methods are most effective for identifying insecure file permissions or unquoted service paths? (Choose two)

Select 2 answers
A.Executing AccessChk from the Sysinternals suite to review discretionary access control lists on service executables.
B.Querying the root certificate store via PowerShell to check for untrusted root certification authorities.
C.Using Windows Management Instrumentation to query the Win32_Service class for executable paths containing spaces without quotes.
D.Inspecting the local security policy database using the auditpol utility to check account lockout thresholds.
E.Reviewing the Active Directory group policy object inheritance tree using the Resultant Set of Policy tool.
AnswersA, C

AccessChk allows efficient command-line auditing of DACLs on files, directories, and services. Identifying weak permissions where standard users hold write or modify rights on service binaries enables successful replacement of legitimate executables with malicious payloads.

Why this answer

Discovering unquoted service paths and vulnerable file permissions represents a foundational step in local Windows privilege escalation. Penetration testers leverage tools and native commands to locate binaries running with SYSTEM privileges that can be modified or hijacked, allowing arbitrary code execution upon service restart.

Exam trap

Candidates often try to manually inspect every file on the system. They miss the efficiency of using built-in tools like AccessChk or WMI to automate the discovery of common misconfigurations.

8
Multi-Selecthard

You are performing a penetration test on a Linux system and have obtained a low-privileged shell. You want to escalate privileges by exploiting misconfigured file permissions. Which two of the following file permission scenarios are most likely to allow privilege escalation? (Choose two.)

Select 2 answers
A.A world-readable configuration file that contains database credentials.
B.A world-writable file in /etc/ that is not used by any service or cron job.
C.A directory with permissions 755 owned by root, containing a script that is executed by root.
D.A world-writable script that is executed by a root cron job.
E.A root-owned SUID binary that calls a system command without an absolute path.
AnswersD, E

A world-writable script executed by a root cron job is a classic privilege escalation vector. Since any user can modify the script, you can inject commands that will run as root when the cron job executes. This directly leads to privilege escalation. Defenders should ensure that scripts executed by privileged cron jobs are not writable by unprivileged users. This scenario is highly likely to allow escalation.

Why this answer

The two scenarios most likely to allow privilege escalation are a world-writable script executed by root cron and a root-owned SUID binary that calls a command without an absolute path. The former allows direct code injection as root, while the latter allows PATH manipulation to execute malicious code as root. The other options either do not provide direct escalation or lack a trigger mechanism.

Exam trap

The trap here is assuming that any world-writable file or sensitive information disclosure automatically leads to privilege escalation, but without a privileged process consuming it, it does not.

9
MCQhard

You have identified an SUID binary on a Linux system that executes a shell command without using an absolute path. What is the most effective way to exploit this for privilege escalation?

A.Overflow the buffer of the binary.
B.Modify the PATH variable to point to a malicious directory.
C.Use LD_PRELOAD to inject a shared object.
D.Inject arguments into the binary.
AnswerB

By prepending a user-controlled directory to the PATH variable, the system searches the attacker's directory first. If the binary calls 'date' and the attacker has placed a malicious file named 'date' in their directory, the system executes the malicious file with the privileges of the SUID binary.

Why this answer

When a binary calls a command without an absolute path, it relies on the PATH environment variable to locate the executable. By modifying the PATH to include a directory under the attacker's control, the attacker can place a malicious executable with the same name as the target command. This forces the SUID binary to execute the malicious file instead of the intended system utility, resulting in command execution as the owner.

Exam trap

Candidates often try to exploit missing absolute paths by changing ownership of the binary or attempting direct code injection, forgetting that manipulating the PATH environment variable is the standard vector.

10
Multi-Selecthard

You have obtained a Meterpreter session as a standard user on an Ubuntu 20.04 server during an authorized penetration test. You want to identify reliable local privilege escalation vectors. Which two findings most directly indicate a path to root? (Choose two.)

Select 2 answers
A.The /etc/hosts file is writable by the standard user account you compromised.
B.A systemd service unit that runs a script located in /opt/backup, and the /opt/backup directory is world-writable.
C.The sudoers file grants the account the right to run /usr/bin/find with the NOPASSWD tag.
D.The target runs an SSH server on port 22 that permits password authentication for all local accounts.
E.The host has an outdated OpenSSL library version recorded in the package manifest.
AnswersB, C

A service unit that executes a script from a world-writable directory lets any local user replace that script with arbitrary code. Because the service runs as root under systemd, the replacement executes with root privileges on the next service start or restart. This is a direct and reliable escalation path from a standard user to root on the host.

Why this answer

Two findings give direct root: a root-run service executing a script from a world-writable directory, allowing script replacement, and passwordless sudo for find, whose -exec flag spawns arbitrary commands. Both convert standard user access into root on the same host. The remaining findings are hygiene or lateral-movement issues that do not, by themselves, elevate privileges locally.

Exam trap

The trap here is treating any writable file or outdated package as an escalation, when only writable paths reachable by a root-owned execution context or sudo rights with command-injection flags actually yield root.

11
MCQeasy

You have a shell as www-data on an Ubuntu 20.04 web server and notice a cron job that runs every minute as root executing a script located in /opt/backup/run.sh. The script is writable by the www-data user. What is the most direct way to escalate privileges in this situation?

A.Change the permissions on /bin/bash to SUID root so any user can spawn a privileged shell
B.Append a reverse shell command to run.sh so the next cron execution spawns a root shell back to your listener
C.Use the writable script to add www-data to the sudoers file and then run sudo su
D.Replace run.sh with a symbolic link to /etc/passwd so cron overwrites the password file with a new root entry
AnswerB

Because the cron job executes the script as root every minute and the file is writable by www-data, modifying its contents means your injected commands run with root privileges at the next scheduled interval. Appending a reverse shell payload is a direct, reliable escalation path that requires no exploit or kernel vulnerability.

Why this answer

When a root-owned cron job executes a script that a lower-privileged user can write to, the attacker effectively controls code that will run as root. Appending a reverse shell to that script is the simplest and most reliable escalation, since it leverages the scheduler's existing root context rather than requiring a separate vulnerability.

Exam trap

The trap here is overcomplicating the path with symlink or SUID tricks when direct modification of the root-executed script already yields code execution as root.

12
MCQeasy

Which of the following is a primary goal during the 'Exploitation' phase of a penetration test?

A.To document all vulnerabilities found.
B.To gain unauthorized access or influence target systems.
C.To scan the entire network for open ports.
D.To patch the vulnerabilities identified.
AnswerB

The core objective of exploitation is to turn a vulnerability into an active exploit, gaining unauthorized access or executing code. This validates the risk assessment and demonstrates the impact of the identified security flaws in a controlled, safe manner that is consistent with the test's scope.

Why this answer

The primary goal during exploitation is to prove the existence of a vulnerability by successfully executing code or accessing unauthorized data. It is not just about finding the vulnerability; it is about demonstrating its impact. This confirms the risk to the client and allows for a more accurate assessment of the potential consequences if the flaw were exploited by a real-world attacker.

Exam trap

Candidates often confuse the exploitation phase goal with vulnerability discovery or information gathering, forgetting that exploitation specifically requires demonstrating impact through unauthorized access.

13
MCQhard

During a Linux assessment you find a root-owned binary with the SUID bit set that calls the system() function using a relative path, such as system("cat /etc/hostname"). The binary's directory is not writable, but your current directory is. Which technique is most likely to let you execute arbitrary code as root?

A.Use LD_PRELOAD to inject a shared library into the SUID process and hook the system() call
B.Create a malicious executable named cat in your current directory and manipulate PATH so it is found before /bin
C.Set the SUID bit on /bin/cat so the command runs as root when invoked
D.Overwrite the SUID binary with a copy of /bin/sh to inherit its root ownership
AnswerB

Because the SUID binary invokes system() with a relative command name, the shell resolves cat using the inherited PATH. If you place a malicious cat earlier in PATH, it executes with the binary's effective root privileges. This is the classic PATH hijacking escalation for SUID programs that call commands without absolute paths.

Why this answer

A root-owned SUID binary that calls system() with a relative command name inherits the caller's PATH, so a low-privileged user can place a malicious executable earlier in PATH and have it run as root. This PATH hijacking is the intended escalation for the described weakness, and the unwritable binary directory does not prevent it.

Exam trap

The trap here is reaching for LD_PRELOAD or SUID-on-a-system-binary tricks, when the loader strips LD_PRELOAD for SUID programs and you cannot modify root-owned files anyway.

14
MCQmedium

You compromise a Windows workstation and extract the NTLM hash of a local administrator account that is reused across many workstations in the domain. You want to authenticate to remote hosts without cracking the hash. Which technique should you use?

A.Use the hash as input to an offline brute-force tool to recover the plaintext password.
B.Kerberoast service accounts to obtain crackable service ticket hashes.
C.Perform a pass-the-hash attack using the extracted NTLM hash to authenticate to remote SMB services.
D.Run a relay attack with Responder to capture and forward NetNTLM authentications.
AnswerC

Pass-the-hash exploits the fact that NTLM authentication accepts the hash itself as proof of identity, so the plaintext password is unnecessary. Tools such as Impacket's psexec or wmiexec accept an LM:NT hash pair and establish an authenticated session. Because the local administrator credential is reused, this yields access to many workstations without cracking the hash.

Why this answer

NTLM authentication treats possession of the hash as sufficient proof of identity, so the extracted local administrator hash can be supplied directly to tools that establish SMB or WMI sessions. Because that local account is reused across workstations, pass-the-hash grants access to many systems immediately, with no cracking step and no dependency on the plaintext password.

Exam trap

The trap here is believing the plaintext password must be recovered before an NTLM hash can be used for authentication.

15
MCQmedium

During an internal assessment you obtain a Meterpreter session on a Windows Server 2016 host running as a low-privileged service account. You want to identify whether the host is missing security updates that could allow local privilege escalation without immediately running an exploit. Which Metasploit post-exploitation module should you use to enumerate installed hotfixes and compare them against known vulnerabilities?

A.post/multi/recon/local_exploit_suggester
B.post/windows/gather/enum_applications
C.post/windows/gather/win_privs
D.post/windows/gather/enum_patches
AnswerD

This module enumerates installed hotfixes on the target by querying the registry and WMI, then correlates them against the Microsoft vulnerability database to highlight missing patches. It runs safely without modifying the system, making it ideal for identifying kernel or component escalation candidates before attempting any exploit inside a production Windows Server 2016 engagement.

Why this answer

Enumerating installed hotfixes and comparing them to known Microsoft vulnerabilities is exactly what the enum_patches module provides, and it does so without triggering exploit code on a production server. The other modules either list applications, suggest exploits through active checks, or report current token privileges, none of which produce a patch-level inventory needed before selecting a kernel escalation path.

Exam trap

The trap here is assuming that any post module with 'enum' in the name will report missing Windows updates, when most only list applications, privileges, or sessions.

16
MCQeasy

You have obtained a Meterpreter session on a Windows 10 host as a standard user. You want to escalate privileges by exploiting a vulnerable kernel driver. Which Metasploit module category would you use to search for suitable exploits?

A.exploit/windows/rdp
B.exploit/windows/smb
C.exploit/windows/local
D.exploit/windows/http
AnswerC

The 'exploit/windows/local' category contains local privilege escalation exploits for Windows, including kernel driver vulnerabilities. These modules are designed to run within an existing session to elevate privileges. By searching this category, you can find exploits that match the target's architecture and patch level. This is the correct place to look for kernel-based escalation modules in Metasploit.

Why this answer

Local privilege escalation exploits in Metasploit are found under the 'exploit/windows/local' category. These modules are specifically designed to run within a session and elevate privileges by exploiting vulnerabilities such as kernel driver flaws. Other categories like SMB, RDP, or HTTP are for remote exploitation and do not apply when you already have local access.

Exam trap

The trap here is confusing remote exploit categories with local privilege escalation modules, which are distinctly separated in Metasploit's directory structure.

17
MCQhard

While testing a Windows 10 workstation, you find that the account you compromised belongs to the Backup Operators group. You need to escalate to local administrator without installing third-party tools on disk. Which built-in capability of this group can you abuse to obtain administrative access?

A.SeBackupPrivilege allows reading any file, enabling extraction of the SAM and SYSTEM registry hives for offline credential dumping
B.Membership grants SeDebugPrivilege, permitting direct injection into a SYSTEM process to steal its token
C.SeTakeOwnershipPrivilege is granted, allowing ownership takeover of any object followed by full control
D.The group can modify the discretionary access control list on the local administrator account to reset its password
AnswerA

Backup Operators hold SeBackupPrivilege and SeRestorePrivilege, which bypass file ACLs. By copying the SAM and SYSTEM hives with a tool that honors the backup privilege, then parsing them offline, you can recover local account hashes including the administrator's, then authenticate or pass the hash to escalate without writing custom exploits to disk.

Why this answer

The Backup Operators group is powerful because SeBackupPrivilege and SeRestorePrivilege bypass file system ACLs. An attacker can therefore read protected files such as the SAM and SYSTEM hives, exfiltrate them, and recover local password hashes offline, then use those credentials to reach administrative access without dropping custom binaries onto the host.

Exam trap

The trap here is assuming Backup Operators receive SeDebugPrivilege or SeTakeOwnershipPrivilege, when their real power comes from backup and restore rights that bypass file ACLs.

Ready to test yourself?

Try a timed practice session using only Escalation and Exploitation questions.