Courseiva

CCNA Exploitation Fundamentals Questions

20 questions · Exploitation Fundamentals · All types, answers revealed

1
MCQmedium

Which of the following describes the purpose of 'encoding' shellcode in an exploitation context?

A.To increase the execution speed of the exploit.
B.To bypass character-based filters and detection systems.
C.To encrypt the traffic for legal compliance.
D.To permanently store the payload on the target's disk.
AnswerB

Security systems often scan for known shellcode patterns or restricted characters like null bytes (0x00). Encoding the payload allows it to pass through these filters by obfuscating the malicious bytes into a benign-looking format, which is later decoded by a small stub upon reaching memory.

Why this answer

Encoding is used to transform shellcode to bypass security filters, such as Intrusion Detection Systems (IDS) or character filtering (like null bytes). By changing the signature of the payload, it avoids triggering pattern-based detection. This is a fundamental technique for ensuring the payload reaches its intended execution point without being sanitized or blocked by input validation controls that inspect data for known malicious sequences.

Exam trap

Candidates frequently confuse shellcode encoding with encryption, assuming it provides confidentiality against analysts rather than modifying bytes to bypass character filters.

2
MCQeasy

Which of the following is considered a 'client-side' exploitation scenario?

A.Exploiting an unpatched web server service.
B.Tricking a user into opening a malicious PDF.
C.Attacking an open database port.
D.Brute-forcing an SSH login on a server.
AnswerB

Opening a document in a client application like a PDF viewer is a quintessential client-side attack. The attacker leverages a vulnerability in the client software that is triggered by the user's action, effectively gaining control over the user's local machine through their interaction with the malicious file.

Why this answer

Client-side exploitation involves targeting an application running on a user's machine, such as a browser, document viewer, or email client. Unlike server-side exploitation, which targets a persistent service, client-side attacks rely on tricking a user into interacting with a malicious resource. This shift in vector requires testers to consider social engineering and user behavior as key components of the attack chain, which is distinct from direct network-based vulnerability exploitation.

Exam trap

Candidates often confuse client-side attacks with server-side service exploitation, failing to realize that client-side attacks require user interaction to trigger the vulnerability.

3
Multi-Selecthard

You are performing a penetration test against a Windows domain and have obtained domain user credentials. You want to identify which domain controllers are vulnerable to a specific privilege escalation technique. Which TWO tools or techniques are most appropriate for enumerating domain controllers and their potential vulnerabilities? (Choose two.)

Select 2 answers
A.BloodHound with SharpHound collector
B.Nmap with the smb-enum-shares script
C.PowerView's Get-NetDomainController
D.Metasploit's auxiliary/scanner/smb/smb_version
E.Responder with LLMNR poisoning
AnswersA, C

BloodHound uses graph theory to reveal hidden relationships and attack paths in Active Directory. SharpHound collects data such as users, groups, computers, and sessions. It can identify domain controllers and potential privilege escalation paths, such as unconstrained delegation or ACL misconfigurations. This is a powerful tool for enumerating domain controllers and their vulnerabilities from a domain user perspective.

Why this answer

BloodHound with SharpHound and PowerView's Get-NetDomainController are both designed to enumerate Active Directory environments, including domain controllers. BloodHound maps attack paths and can highlight misconfigurations like unconstrained delegation, while PowerView directly queries domain controller information. Other tools like Nmap SMB scripts, Metasploit SMB scanner, and Responder focus on different aspects such as share enumeration, version scanning, or credential capture, and do not provide the specific domain controller vulnerability enumeration required.

Exam trap

The trap here is confusing general SMB enumeration tools with those that specifically map Active Directory attack paths and domain controller misconfigurations.

4
MCQmedium

What is the primary danger of using a 'bind shell' payload in a penetration test?

A.It is always detected by local antivirus.
B.It opens a listening port that is easily discovered.
C.It requires the target to have an internet connection.
D.It automatically crashes the target's kernel.
AnswerB

A bind shell makes the target machine a server, opening a port that is visible to any network scan. This increases the risk that other attackers or internal security tools will detect the unexpected listener, and it may be blocked by ingress firewall rules designed to prevent such connections.

Why this answer

A bind shell opens a listening port on the target machine, which is highly visible to firewalls and network monitoring. This makes it an insecure choice, as it allows anyone else on the network to potentially connect to the listener. In a professional engagement, using a reverse shell is preferred, as it initiates the connection from the target back to the tester, which is far more likely to bypass perimeter firewalls.

Exam trap

Candidates often select bind shells because they are easier to configure locally, forgetting that inbound ports are routinely blocked by perimeter firewalls.

5
MCQmedium

During a penetration test against an internal Windows host, you use Metasploit's psexec module with a Meterpreter payload and receive a session. You then run the getuid command and see that you are running as NT AUTHORITY\SYSTEM. However, when you attempt to access a mapped network drive that the logged-on user had access to, you receive an access denied error. Which of the following best explains this behavior?

A.The Meterpreter session is running in the security context of the SYSTEM account, which has no network credentials for the mapped drive.
B.The psexec module drops the payload into a temporary directory that lacks the necessary permissions to access network shares.
C.The mapped drive was disconnected when the psexec service was created, and you must re-map it manually from the Meterpreter shell.
D.The firewall on the target is blocking SMB traffic from the SYSTEM account, preventing access to the mapped drive.
AnswerA

SYSTEM has no user credentials, so it cannot authenticate to remote resources that require the logged-on user's token. This is why mapped drives and network shares tied to the interactive user are inaccessible from a SYSTEM-level session unless you migrate or steal a token.

Why this answer

When psexec runs a payload as a service, the resulting process runs as NT AUTHORITY\SYSTEM. SYSTEM has no user credentials, so it cannot access network resources that require the logged-on user's authentication. To access those resources, the tester must migrate into a process running under the user's context or steal a token.

Exam trap

The trap here is assuming that SYSTEM-level access automatically grants access to all resources the logged-on user could reach.

6
MCQmedium

You are conducting a penetration test against a web application and have identified a potential SQL injection vulnerability in a login form. You want to confirm the vulnerability and extract the database schema without causing a denial of service. Which technique should you use to safely enumerate the database?

A.Out-of-band SQL injection using DNS exfiltration
B.Error-based SQL injection by forcing detailed error messages
C.Time-based blind SQL injection using heavy delays
D.Union-based SQL injection to retrieve schema information
AnswerD

Union-based SQL injection allows you to append a second query to the original and directly retrieve data in the application's response. It is efficient and does not require delays or error triggering. By crafting a UNION SELECT statement, you can extract database schema, table names, and column names quickly. This method is safe if the number of columns matches and the data types are compatible.

Why this answer

Union-based SQL injection is the most direct and efficient method to extract database schema when the application returns query results in its response. It allows the tester to retrieve multiple rows of data in a single request without relying on delays or error messages. This minimizes impact on the application's performance and reduces the risk of triggering defensive mechanisms.

Other techniques like time-based or out-of-band are used when union is not possible, but they are slower and can be more disruptive.

Exam trap

The trap here is assuming that any SQL injection technique is equally safe, when in fact time-based blind injection with heavy delays can cause performance issues and potential denial of service.

7
MCQhard

Which technique is most effective for exploiting a heap-based buffer overflow compared to a stack-based overflow?

A.Overwriting the return address on the stack.
B.Manipulating heap metadata to achieve write-what-where.
C.Using a simple NOP sled to reach the shellcode.
D.Increasing the size of the input string.
AnswerB

Heap management structures store critical information about memory blocks. By corrupting these headers, an attacker can trick the allocator into writing data to an arbitrary memory location. This 'write-what-where' primitive is the foundational goal of heap exploitation, allowing for sophisticated control over the application's execution flow.

Why this answer

Heap overflows are significantly more complex because they involve manipulating heap management metadata (like chunk headers) rather than simply overwriting a return address on the stack. Techniques like 'unlink' or 'house of force' are used to corrupt the heap structures to gain arbitrary write-what-where primitives. Understanding this distinction is vital, as stack-based knowledge does not directly transfer to the more intricate heap exploitation landscape required for modern applications.

Exam trap

Candidates often assume heap overflows can be exploited the same way as stack overflows by simply overwriting return addresses, ignoring complex chunk metadata.

8
Multi-Selecthard

During a penetration test, you have identified a Windows domain controller with SMB signing disabled and obtained valid domain user credentials. You want to perform a relay attack to gain administrative access to multiple hosts. Which two conditions are necessary for a successful SMB relay attack? (Choose two.)

Select 2 answers
A.The attacker must have administrative credentials on the domain controller.
B.The target hosts must have the same local administrator password.
C.SMB signing must be disabled on the target hosts.
D.The attacker must be able to intercept and relay authentication attempts from a privileged user.
E.The attacker must have a valid NTLM hash for a domain administrator.
AnswersC, D

SMB signing must be disabled on the target hosts for a relay attack to succeed, as signing prevents tampering with relayed authentication. If signing is enabled, the attacker cannot relay the authentication to another service. This condition is critical for the attack to work, making it a necessary requirement.

Why this answer

The necessary conditions for a successful SMB relay attack are that SMB signing is disabled on the target hosts and that the attacker can intercept and relay authentication from a privileged user. These two factors allow the attacker to forward authentication to a target and gain access as that privileged user. Other options are either not required or describe different attack techniques.

Exam trap

The trap here is confusing SMB relay with pass-the-hash or assuming that administrative credentials are needed upfront, when the attack actually relies on relaying live authentication from a privileged user.

9
MCQmedium

You have identified a Windows Server 2019 target running a custom service that is vulnerable to a stack-based buffer overflow. You develop a working exploit and want to execute it during an authorized penetration test. After sending the payload, the service crashes and the target reboots. You need to minimize the impact on the production environment while still validating the vulnerability. Which approach should you take?

A.Use a bind shell payload to gain a command shell and then immediately patch the service.
B.Use a staged payload that downloads a second stage, as this reduces the initial payload size and prevents crashes.
C.Debug the exploit locally in a lab environment that mirrors the target to identify the correct offset and payload, then test again.
D.Modify the exploit to use a reverse shell payload and execute it during off-peak hours.
AnswerC

This is the correct approach because it isolates the exploit development from production. By replicating the target environment, you can safely determine the exact offset, test payloads, and ensure stability. Only after confirming a reliable exploit should you consider testing against the production system, ideally with a non-destructive proof-of-concept.

Why this answer

The safest way to develop and validate an exploit is to replicate the target environment in a lab. This allows you to debug the exploit, find the correct offset, and test payloads without risking production systems. Once the exploit is stable, you can perform a controlled test on the target, but only after ensuring it will not crash the service.

This approach aligns with penetration testing best practices.

Exam trap

The trap here is assuming that using a different payload type or timing will prevent crashes, when the real issue is often an incorrect offset or exploit logic that must be fixed in a lab first.

10
Multi-Selecthard

When planning an exploit that requires a specific memory address, which THREE techniques can a tester use to increase the reliability of the exploit?

Select 3 answers
A.Heap spraying to fill memory with the payload.
B.Using a large NOP sled before the shellcode.
C.Disabling the target's operating system logging.
D.Employing ROP gadgets to bypass ASLR/DEP.
E.Increasing the network MTU size.
AnswersA, B, D

Heap spraying involves allocating many large chunks of memory containing the shellcode. This increases the probability that the instruction pointer will land on the payload, even if the exact destination address is unknown. It is a powerful technique for overcoming the unpredictability of randomized memory allocation.

Why this answer

Memory reliability is the primary hurdle in binary exploitation. Techniques like heap spraying, NOP sleds, and ROP gadgets are designed to circumvent the uncertainty of memory addresses. By using these methods, a tester creates a more robust exploit that does not rely on perfect, single-point accuracy, which is almost impossible to achieve in modern systems with complex memory management and various active security mitigations.

Exam trap

Candidates often select incorrect options like static DLL injection or standard brute forcing, failing to recognize that NOP sleds, heap spraying, and ROP gadgets directly address memory unpredictability.

11
MCQmedium

Why is it important to use 'staged' payloads during a penetration test when the target has limited memory or strict filtering?

A.To bypass the system's firewall rules permanently.
B.To fit within small buffer constraints during initial exploitation.
C.To automatically upgrade the shell to root privileges.
D.To increase the target's CPU usage for testing stability.
AnswerB

Many vulnerabilities, such as stack-based buffer overflows, have limited space for shellcode. A staged payload uses a small 'stager' to initiate the connection and pull down the 'stage' (the full payload), allowing the exploit to succeed even when the available memory for shellcode injection is very small.

Why this answer

Staged payloads are split into a small initial stub and a larger secondary component. The small stub fits into tight buffer constraints or bypasses initial inspection, then downloads the rest of the shellcode. This is crucial for environments with limited memory or security products that block large, anomalous network traffic, as it allows for stealthy, efficient exploitation where a full-sized monolithic payload would fail or trigger an alarm.

Exam trap

Candidates often think staged payloads are chosen strictly for stealth against antivirus, overlooking their crucial role in overcoming strict buffer size limitations during initial exploitation.

12
MCQmedium

Refer to the exhibit. Which step should a tester prioritize next based on the server header information?

A.Run a brute-force password attack against the server.
B.Search for known vulnerabilities for Apache 2.4.41.
C.Immediately deploy a rootkit on the server.
D.Close the connection and report the server as secure.
AnswerB

Identifying the service and version is a prerequisite for vulnerability research. By mapping this version to known security advisories or CVE databases, a tester can determine if public exploits exist for this specific configuration, effectively narrowing the attack surface to the most likely points of failure.

Why this answer

The server header indicates a specific version of Apache running on Ubuntu. A tester should cross-reference this version with known vulnerabilities, such as CVEs in the Apache HTTP Server. This is a foundational step in identifying applicable exploits.

Knowing the specific version allows for targeted research into public or private exploit modules, increasing the probability of a successful engagement by focusing on documented, verifiable weaknesses within that specific software build.

Exam trap

Testers often attempt to brute-force or perform manual discovery before checking for known CVEs, wasting time on manual enumeration when a simple version-based exploit search would suffice.

13
MCQmedium

Refer to the exhibit. What does this output indicate regarding the current exploitation attempt?

A.The application is secure from buffer overflow attacks.
B.The tester has successfully redirected execution flow.
C.The system is protected by DEP/NX.
D.The payload is too large for the allocated buffer.
AnswerB

The instruction pointer is pointing to the attacker-controlled buffer ('AAAA'). This confirms the tester has successfully hijacked the program counter, a prerequisite for code execution. The next phase involves crafting the payload to point this address to the shellcode instead of junk data.

Why this answer

The Instruction Pointer (EIP/RIP) being set to 0x41414141 (the hex representation of 'AAAA') proves that the tester has successfully overwritten the return address on the stack. This confirms the vulnerability is exploitable because the tester now has control over the execution flow. The next logical step is to replace the padding ('AAAA') with a valid memory address that points to the desired malicious shellcode.

Exam trap

Test-takers frequently assume that seeing '0x41414141' in the instruction pointer means the exploit was fully successful and shellcode executed, ignoring that control flow redirection is only the first step.

14
MCQmedium

During an exploitation attempt against a web application, you inject a payload that causes the server to return a verbose error message containing a stack trace and database query. What is the most likely type of vulnerability you have discovered?

A.Cross-site request forgery (CSRF)
B.Remote file inclusion (RFI)
C.SQL injection
D.Cross-site scripting (XSS)
AnswerC

A verbose error with a database query and stack trace strongly indicates SQL injection. When user input is improperly sanitized, it can alter SQL queries, and errors often reveal database structure. This is a classic sign of SQLi, especially when the error includes SQL syntax details.

Why this answer

Verbose error messages that include database queries and stack traces are a hallmark of SQL injection. They occur when user input is not properly sanitized, allowing attackers to manipulate SQL statements and trigger errors that reveal backend details. This information can be used to further exploit the database.

Exam trap

The trap here is assuming any error message indicates a specific vulnerability without considering the content of the error.

15
MCQeasy

A penetration tester is preparing to exploit a stack-based buffer overflow on a Linux target. The target binary has non-executable stack (NX) enabled. Which technique should the tester use to achieve code execution?

A.Use a NOP sled and jump to shellcode on the stack
B.Stack pivot to a writable and executable memory region
C.Return-to-libc (ret2libc) attack
D.Heap spraying
AnswerC

Return-to-libc bypasses NX by reusing existing executable code in libc, such as `system()`, to execute commands. It does not require injecting shellcode onto the stack. This technique is effective when the stack is non-executable and is a standard method for exploiting buffer overflows in modern Linux environments with NX enabled.

Why this answer

Return-to-libc is the correct technique because it leverages existing executable code in shared libraries to bypass the non-executable stack. It allows the tester to call functions like `system()` to execute commands without injecting shellcode. Other options either assume an executable stack or are not applicable to stack-based overflows on Linux with NX enabled.

Exam trap

The trap here is assuming that classic stack shellcode injection still works when NX is enabled, overlooking the need to reuse existing code.

16
Multi-Selecthard

When selecting an exploit for a target system, which TWO factors are most critical to ensure the exploit succeeds without crashing the target service?

Select 2 answers
A.The exact version of the application or OS service.
B.The color scheme of the target's command shell.
C.The target system's CPU architecture (e.g., x86 vs x64).
D.The network bandwidth available to the target.
E.The number of users currently logged in.
AnswersA, C

Exploits are often highly specific to binary versions. An offset that works on version 1.2 may cause a segmentation fault on 1.3 due to recompiled libraries or different memory layouts. Matching the exact build ensures that memory addresses used in the payload are valid for the target.

Why this answer

Successful exploitation requires precise alignment between the exploit's memory address assumptions and the target's environment. Crashes typically occur when the exploit targets an incorrect memory offset or assumes a different architecture than the one present. By verifying target versioning and architectural requirements, a tester minimizes the risk of service instability, ensuring that the exploit fulfills its objective while maintaining the operational integrity of the production environment.

Exam trap

Testers often prioritize payload features over system compatibility, ignoring architecture mismatches that reliably cause services to crash rather than provide a stable shell.

17
Multi-Selectmedium

You are conducting a penetration test against a web application. During exploitation, you identify a SQL injection vulnerability that allows you to execute arbitrary SQL queries. You want to leverage this to gain remote code execution on the underlying database server. Which TWO of the following techniques are most likely to achieve this goal? (Choose two.)

Select 2 answers
A.Exploiting the SQL injection to write a web shell to the web server's root directory using INTO OUTFILE.
B.Injecting a stored procedure that uses the LOAD_FILE function to read sensitive files from the server.
C.Performing a blind SQL injection to infer the database schema and then using that information to craft a more targeted attack.
D.Using UNION-based SQL injection to extract data from the database and then cracking password hashes offline.
E.Using stacked queries to execute operating system commands via xp_cmdshell on a Microsoft SQL Server.
AnswersA, E

If the database user has FILE privileges and the web server directory is writable, you can use INTO OUTFILE to write a web shell (e.g., PHP) to a web-accessible location. This directly leads to remote code execution by accessing the shell via a browser. It is a common and effective technique when the database and web server are on the same host.

Why this answer

The two techniques that directly lead to remote code execution from SQL injection are writing a web shell via INTO OUTFILE and using xp_cmdshell on MSSQL. Both require specific privileges and configurations but are proven methods to escalate from SQL injection to full command execution on the server. Other options focus on data extraction or reading files, which do not directly achieve RCE.

Exam trap

The trap here is confusing data extraction techniques like UNION-based or blind SQL injection with methods that directly execute code, such as writing a web shell or using xp_cmdshell.

18
MCQeasy

A penetration tester has gained a foothold on a Windows host and wants to escalate privileges. They discover that the host has an unquoted service path vulnerability. Which command should they use to identify services with unquoted paths that contain spaces?

A.tasklist /svc | findstr /i "svchost"
B.sc query type= service state= all | findstr /i "SERVICE_NAME"
C.wmic service get name,displayname,pathname,startmode | findstr /i "auto" | findstr /i /v "c:\windows\\"
D.net start | findstr /i "service"
AnswerC

This wmic command lists services with their pathname and start mode, filters for auto-start services, and excludes those in the Windows directory. Unquoted service paths with spaces are a common privilege escalation vector. This command helps identify such services, making it a standard enumeration step.

Why this answer

Unquoted service paths with spaces allow a tester to place a malicious executable in a directory that Windows will search before the intended binary. The wmic command with the specified filters lists auto-start services and their paths, excluding Windows directory services, making it efficient for spotting vulnerable services.

Exam trap

The trap here is confusing service enumeration commands that list names with those that reveal binary paths.

19
MCQmedium

During a penetration test, you successfully inject a payload into a web application that results in the server executing system commands with elevated privileges. Which phase of the exploitation lifecycle does this action primarily represent?

A.Reconnaissance
B.Vulnerability Assessment
C.Exploitation
D.Post-Exploitation
AnswerC

Exploitation involves the active use of a vulnerability to gain unauthorized access or elevated privileges on a target. In this case, injecting a payload to execute system commands directly maps to this phase, as the tester is leveraging an identified flaw to manipulate the application's runtime behavior.

Why this answer

This scenario demonstrates the execution of arbitrary code, which is the core of the exploitation phase. Exploitation is the process of leveraging a vulnerability to gain unauthorized access or control over a target system. Understanding this transition from vulnerability discovery to exploitation is critical for testers to effectively assess the impact of security flaws and demonstrate real-world risk to stakeholders during the assessment reporting phase.

Exam trap

Candidates frequently confuse the 'exploitation' phase with 'post-exploitation' or 'vulnerability assessment,' failing to recognize that the actual execution of the code is the definition of exploitation.

20
MCQhard

During an authorized penetration test, you have gained a low-privileged shell on a Linux host. You discover that the kernel is version 4.4.0-116-generic and the system is missing several patches. You want to escalate privileges to root. Which of the following is the most reliable and safe method to achieve privilege escalation?

A.Run a kernel exploit such as Dirty COW (CVE-2016-5195) to overwrite /etc/passwd and add a root user.
B.Use Metasploit's local exploit suggester module to automatically find and run a suitable exploit.
C.Use a public exploit for CVE-2017-16995 (BPF verifier) to gain root, as it is known to work on this kernel version.
D.Search for misconfigured SUID binaries and exploit them using GTFOBins techniques.
AnswerD

This is often the most reliable and safe method because it leverages existing misconfigurations rather than exploiting kernel vulnerabilities. SUID binaries with known privilege escalation vectors (e.g., find, vim, nmap) can be exploited without causing system instability. It is also less likely to be detected by security controls and does not require kernel-specific exploits.

Why this answer

Privilege escalation via misconfigured SUID binaries is often the safest and most reliable because it exploits existing permissions rather than kernel vulnerabilities. Kernel exploits carry a higher risk of crashing the system and are version-dependent. Enumerating SUID binaries and using GTFOBins to identify exploitation vectors is a standard practice in penetration testing, allowing for privilege escalation without destabilizing the host.

Exam trap

The trap here is focusing on kernel exploits as the primary method, overlooking that misconfigurations like SUID binaries are often easier, safer, and more reliable for privilege escalation.

Ready to test yourself?

Try a timed practice session using only Exploitation Fundamentals questions.