Courseiva

OffSec PEN-200 / OSCP Concepts (PEN-200) — Questions 1–75

285 questions total · 4pages · All types, answers revealed

Page 1 of 4

Page 2
1
MCQhard

During enumeration you discover a DNS server that allows zone transfers to any client. What is the most valuable outcome of performing a successful AXFR against this server?

A.Decrypting previously captured DNS query traffic between clients and the server.
B.Gaining administrative control over the DNS server's configuration files.
C.Obtaining a complete list of hostnames and IP addresses defined in the zone, revealing internal naming and structure.
D.Retrieving the server's private TLS keys used to sign DNSSEC records.
AnswerC

A successful AXFR returns every record in the zone, exposing hostnames, subdomains, mail servers, and address mappings that are normally hidden. This comprehensive inventory reveals internal naming conventions and network layout, giving an attacker a detailed map of reachable systems far beyond what individual queries would disclose.

Why this answer

An unrestricted AXFR hands over the entire zone contents, including internal hostnames, address records, and service pointers that are otherwise difficult to enumerate. This produces a detailed map of the organization's naming scheme and reachable systems. It does not grant server control, expose signing keys, or decrypt past traffic, so the real value lies in the breadth of hostname and address intelligence revealed.

Exam trap

The trap here is inflating a zone transfer into full server compromise, when it actually only discloses the zone's public record data.

2
MCQhard

You are tasked with delivering a Meterpreter payload to a Windows Server 2019 target protected by a next-generation antivirus that performs userland API hooking on NtAllocateVirtualMemory and NtProtectVirtualMemory. Your current C loader uses these APIs directly and is detected. Which technique is most appropriate to bypass the userland hooks without requiring kernel-level privileges?

A.Install a kernel-mode driver to remove the hooks from ntdll and restore original bytes.
B.Encrypt the payload with AES and decrypt it in memory just before execution.
C.Direct system calls by manually constructing the syscall stub and invoking the syscall instruction.
D.Use PowerShell's Add-Type to compile the loader in memory, relying on the .NET runtime to bypass native hooks.
AnswerC

Manually building the syscall stub bypasses userland hooks because the hook resides in ntdll's exported function, not in the kernel transition path. By placing the syscall number in EAX and executing the syscall instruction directly, the loader skips the modified ntdll code entirely. This works without kernel privileges and is a standard PEN-200 technique for evading EDR hooks on memory allocation and protection APIs.

Why this answer

Direct system calls bypass userland API hooks because the hooks are placed in ntdll's exported functions, and invoking the syscall instruction directly skips that code. The other options either require kernel privileges, still transit the hooked APIs, or only address static detection rather than the behavioral hooks causing the detection.

Exam trap

The trap here is believing that in-memory compilation or payload encryption changes the API call path, when both still invoke the hooked ntdll functions.

3
MCQeasy

When performing a password spraying attack, why is it considered best practice to use a single common password against many accounts rather than many passwords against one account?

A.It increases the number of accounts that can be compromised simultaneously.
B.It is faster for the tool to process a single password.
C.It prevents the detection of the attack by network firewalls.
D.It guarantees that the password will be found for every user.
AnswerA

Spraying a single common password across many accounts increases the statistical likelihood of hitting at least one user who utilizes that password. This method is specifically designed to maximize credential acquisition while staying beneath the radar of lockout policies that are configured to monitor individual account failures.

Why this answer

Password spraying leverages the low frequency of attempts per account to evade account lockout thresholds while maximizing the probability of finding at least one compromised credential. This approach is highly effective in enterprise environments where account policies restrict the number of failed login attempts per user. By spreading attempts, an attacker bypasses these security controls, whereas targeted brute-forcing of a single user would quickly trigger a lockout and alert security teams.

Exam trap

Test-takers frequently confuse password spraying with brute-forcing, incorrectly assuming the goal is to guess one user's password through massive volume.

4
MCQmedium

Based on the exhibit, what is the primary risk if your shellcode contains the byte \x0d?

A.The memory address becomes non-executable
B.The application terminates the input string early
C.The JMP ESP instruction fails to trigger
D.The CPU enters an infinite loop state
AnswerB

Many string-handling functions, like strcpy or those used in network socket communication, interpret \x0d as a carriage return, signaling the end of an input stream. If the shellcode contains this byte, the program stops copying input to the buffer, leaving the exploit payload incomplete and effectively preventing successful execution.

Why this answer

The exhibit lists \x0d as a bad character, which often acts as a carriage return in various network protocols or string-handling functions. If shellcode contains this byte, the application may truncate the input buffer prematurely, preventing the full payload from reaching the stack. This truncation causes the exploit to fail, as the shellcode becomes malformed or incomplete before the CPU can execute it during the return sequence.

5
MCQeasy

A penetration tester modifies a known exploit's payload by changing variable names and adding junk instructions. Despite these changes, the antivirus software still flags the file as 'Trojan.Generic' immediately upon being written to disk. What is the most likely reason for this detection?

A.The antivirus is using signature-based detection on the specific junk code.
B.Heuristic analysis identified suspicious code patterns or structures.
C.The file's entropy was too low, triggering an automatic quarantine.
D.The junk instructions were identified as malicious shellcode by the CPU.
AnswerB

Heuristic engines look for characteristics and behaviors rather than exact byte sequences. By identifying that the file structure or the sequence of API calls closely resembles known malware, the antivirus can make an educated guess that the file is malicious, even if the specific strings and variables have been altered by the penetration tester.

Why this answer

While simple obfuscation like renaming variables can bypass basic string-matching signatures, modern antivirus engines use heuristic analysis to identify suspicious patterns or structures common to malware. If the core logic or the arrangement of functional code blocks remains recognizable, the heuristic engine will flag the file based on its similarity to known malicious software families even without an exact match.

Exam trap

Candidates often believe that simple obfuscation like renaming variables is sufficient to bypass modern antivirus, failing to realize that heuristic engines analyze the logic and structure of the code.

6
MCQmedium

Why is it often effective to check for 'Capabilities' on Linux binaries when SUID is not present?

A.Capabilities are automatically granted to all users on a system.
B.They allow a binary to perform privileged operations without full root UID.
C.Capabilities only work on binaries that have the SUID bit set.
D.They enable the user to bypass the sudo password prompt.
AnswerB

Capabilities break down root privileges into smaller units. If a binary is granted the 'CAP_DAC_OVERRIDE' capability, for example, it can bypass file permission checks even if the binary itself isn't running as root. This allows for privilege escalation by leveraging the binary's authorized, high-level permissions.

Why this answer

Linux capabilities allow for fine-grained control over privileged operations, such as network raw socket access or file modification, without requiring the full root user. If a binary has excessive capabilities assigned, it can be abused to perform privileged actions. This is a subtle but powerful alternative to SUID that is frequently overlooked during security assessments, making it a valuable path for privilege escalation when traditional SUID targets are unavailable.

Exam trap

Students often ignore binaries lacking the SUID bit entirely, assuming they are secure, and completely overlook alternative mechanisms like Linux capabilities during enumeration.

7
MCQhard

You are building a malicious Microsoft Word document for a phishing campaign. You need the embedded macro to execute automatically as soon as the document is opened, without requiring the victim to click an additional button or dismiss a prompt beyond the initial security warning. Which document element must the macro reside in to achieve automatic execution?

A.An Auto_Close macro stored in a standard module
B.A UserForm's Initialize event
C.The ThisDocument object's Document_Open event handler
D.A standard module inside the VBA project
AnswerC

Placing the payload in the ThisDocument module's Document_Open routine causes Word to execute it as part of loading the document, once macros are enabled. This is the standard way to achieve automatic execution without any further user interaction. It directly satisfies the scenario's requirement for immediate, hands-off execution.

Why this answer

The ThisDocument object exposes document-level event handlers, and Document_Open runs automatically when Word loads the file, provided macros are enabled. That combination gives the operator code execution without an additional click. Storing the payload elsewhere requires a separate trigger, which undermines the goal of immediate execution.

Exam trap

The trap here is assuming any VBA code in the project runs on open, when only document-level event handlers such as Document_Open are invoked automatically by Word.

8
MCQeasy

You download a public exploit archive from an unknown source. Before using it in the PEN-200 lab, which step best protects your own attacking machine from a trojanized exploit?

A.Scan the archive with the antivirus installed on your host before extracting it.
B.Read the exploit's comments and README to confirm the author claims it is safe.
C.Check the exploit's file hash against an online malware database and proceed if it is unknown.
D.Run the exploit inside a disposable virtual machine with no shared folders and no host network bridging.
AnswerD

An isolated disposable VM confines any malicious behavior to a system you can discard, while the lack of shared folders and bridged networking prevents the malware from reaching your host files or the broader network. This containment strategy is the most reliable protection when the trustworthiness of an exploit archive cannot be established.

Why this answer

Isolating the exploit in a disposable VM without shared folders or bridged networking contains any malicious behavior and prevents it from reaching the host or other lab systems. Antivirus scans, hash lookups, and author claims all fail to prove safety because a trojanized exploit is designed to evade exactly those checks.

Exam trap

The trap here is trusting a clean antivirus scan or an unknown-hash result as evidence of safety, when both are consistent with a trojanized exploit.

9
Multi-Selecthard

When auditing a Windows host for privilege escalation vectors during a PEN-200 assessment, you discover that the machine has AlwaysInstallElevated enabled in the Windows Registry. Which TWO conditions must be verified simultaneously to successfully weaponize this misconfigured policy?

Select 2 answers
A.The AlwaysInstallElevated value must be set to 1 in HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Installer.
B.The AlwaysInstallElevated value must be set to 1 in HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Installer.
C.The local security policy must allow standard users to bypass User Account Control prompts via group policy objects.
D.The target user account must possess local Administrator group membership prior to executing the malicious MSI package.
E.The Task Scheduler service must be configured to permit interactive logons for disabled service accounts.
AnswersA, B

The Windows Installer policy check evaluates both the current user hive and the local machine hive before executing installations. Setting this specific registry key to 1 in the user hive informs the operating system that packages run by this user should receive elevated rights.

Why this answer

AlwaysInstallElevated allows low-privileged users to install malicious MSI packages with elevated NT AUTHORITY\SYSTEM privileges. However, exploitation requires both registry hive keys to be properly configured to enabled values. Verifying both keys ensures the Windows Installer service honors the elevated installation flag for all packages regardless of user context.

Exam trap

Candidates frequently check only the HKLM key, forgetting that the HKCU policy must also be enabled. Both keys are required for the Windows Installer to honor the elevated privilege flag.

10
MCQmedium

During post-exploitation on a Linux target, you discover a binary with the SUID bit set owned by root. Running 'strings' on the binary reveals it calls 'system("ps")' without specifying an absolute path. Which of the following techniques is most likely to allow you to escalate privileges by exploiting this behavior?

A.Overwrite the /bin/ps binary with a malicious script, then run the SUID binary.
B.Modify the binary to replace system("ps") with system("/bin/sh"), then run it.
C.Use LD_PRELOAD to inject a shared library that hijacks the system() call.
D.Create a malicious 'ps' executable in a directory earlier in the PATH, then run the SUID binary.
AnswerD

The binary uses system("ps"), which invokes the shell to run the command. If the PATH environment variable includes a writable directory before /bin, you can place a malicious 'ps' there. When the SUID binary runs, it will execute your 'ps' as root, granting escalation. This is a classic PATH hijacking attack.

Why this answer

The SUID binary calls system("ps") without an absolute path, meaning it relies on the PATH environment variable to locate the ps command. If an attacker can prepend a writable directory to PATH and place a malicious ps script there, the SUID binary will execute it with root privileges. This is a classic PATH hijacking privilege escalation.

Exam trap

The trap here is assuming that LD_PRELOAD or binary modification is needed, while overlooking the simpler PATH hijacking due to the relative command invocation.

11
MCQeasy

Which of the following is a common symptom of a Command Injection vulnerability?

A.The web page displays a SQL syntax error message.
B.The application returns the output of a command like 'whoami' or 'id'.
C.The login page takes a long time to respond to requests.
D.Users are redirected to an external, malicious website.
AnswerB

If an application executes OS commands based on user input, injecting common Linux commands like 'whoami' will cause the application to return the current user's identity. This direct reflection of command results is the most clear proof-of-concept for a command injection vulnerability.

Why this answer

Command injection occurs when an application passes unsafe user input to a system shell. The vulnerability allows an attacker to execute arbitrary OS commands, often revealed by the application outputting the results of the command directly. Understanding this helps security professionals recognize when an input field is interacting with the underlying operating system, necessitating strict input sanitation to prevent severe system compromise.

Exam trap

Candidates often look for complex error messages or system crashes, failing to realize that the most direct confirmation of command injection is simply receiving the output of a basic command.

12
Multi-Selecthard

A penetration tester is investigating scheduled tasks for potential privilege escalation. Which TWO conditions must be met for a scheduled task to be successfully exploited for gaining SYSTEM privileges?

Select 2 answers
A.The task is configured to run under the context of the SYSTEM account or a member of the Administrators group.
B.The task must have a trigger set to 'At log on' for any user on the system.
C.The attacker has permissions to modify the binary or script executed by the task, or can rewrite the task's action path.
D.The 'Hidden' attribute must be enabled in the task settings to bypass Windows Defender detection.
E.The task must be part of the default Windows installation rather than a third-party application.
AnswersA, C

Privilege escalation requires moving from a lower privilege level to a higher one. If the task runs as the current low-privilege user, executing code through it provides no elevation. Targeting tasks that run as SYSTEM ensures that once the execution path is hijacked, the resulting shell or command will possess maximum system authority.

Why this answer

Scheduled tasks are a common persistence and escalation vector. For escalation, the task must execute with higher privileges than the current user, typically as SYSTEM or an Administrator. Additionally, the attacker must have the ability to influence what the task executes, either by modifying the executable file, a script it calls, or the task configuration itself to point to a malicious file.

Exam trap

A common mistake is assuming that any task running as SYSTEM is exploitable. Without the ability to modify the action or the underlying file, the task is secure regardless of its privileges.

13
MCQmedium

Which attack involves an attacker capturing NTLM authentication traffic from a user and relaying it to another machine to gain unauthorized access?

A.Kerberoasting
B.DCSync
C.NTLM Relay
D.Golden Ticket
AnswerC

NTLM Relay is the process of intercepting authentication requests and forwarding them to a target machine. If successful, the attacker gains access to the target host with the privileges of the authenticated user. This attack is highly effective against environments where SMB signing is not enforced on network servers.

Why this answer

NTLM Relay involves capturing authentication requests from a client and forwarding them to a target server. If the target server allows NTLM authentication and does not have protections like SMB signing enabled, the server will accept the relayed authentication as if it came from the original user. This allows the attacker to impersonate the user and execute commands or access files on the target server.

Exam trap

Candidates often confuse NTLM relaying with credential harvesting. Relaying is a real-time attack that forwards authentication traffic to a target, whereas harvesting involves offline cracking of captured hashes.

14
MCQeasy

Which of the following describes the primary difference between a Golden Ticket and a Silver Ticket attack in an Active Directory environment?

A.Golden tickets are for NTLM, whereas Silver tickets are for Kerberos.
B.Golden tickets require the KRBTGT hash, while Silver tickets require a service account hash.
C.Silver tickets grant domain admin access, while Golden tickets are restricted to workstations.
D.Only Silver tickets require active communication with the Domain Controller.
AnswerB

Golden tickets require the hash of the KRBTGT account, which allows the forging of TGTs for any resource. Silver tickets require the hash of a specific service account (e.g., MSSQL or CIFS), allowing the forgery of TGS tickets for that specific service, which is much more targeted and quieter.

Why this answer

The distinction between Golden and Silver tickets is fundamental to understanding post-exploitation persistence. Golden tickets involve the KRBTGT account, granting access to the entire domain, while Silver tickets target specific service accounts. Mastering this difference is essential for determining the scope of an attack and the level of stealth required, as Silver tickets are often safer to deploy as they avoid triggering certain domain controller alerts related to TGT requests.

Exam trap

Candidates often believe both tickets provide identical access. However, Golden tickets grant domain-wide persistence via the KRBTGT account, while Silver tickets are limited to specific services, offering less overall control.

15
MCQeasy

When performing SSH dynamic port forwarding with the -D flag, what is the primary benefit compared to local port forwarding (-L)?

A.It provides a faster connection speed than local forwarding.
B.It enables routing to multiple internal hosts dynamically.
C.It is more secure because it disables encryption.
D.It allows the user to run commands on the remote machine.
AnswerB

Dynamic port forwarding acts as a SOCKS proxy, allowing client applications to route traffic through the SSH server to any destination reachable by that server. This eliminates the need to create individual -L tunnels for every specific internal IP or service, providing much greater flexibility during network enumeration.

Why this answer

Dynamic port forwarding creates a SOCKS proxy, which allows the user to route traffic to any destination reachable by the remote jump host. Unlike local port forwarding, which requires specifying a target IP and port upfront, dynamic forwarding is flexible. This is essential during the discovery phase of a penetration test, as it allows tools like Nmap or browser-based tools to explore an entire internal network segment without individual tunnel configurations.

Exam trap

Candidates often confuse dynamic port forwarding with local port forwarding, assuming they need to create a new tunnel every time they want to access a different internal service.

16
MCQeasy

You are developing a proof-of-concept exploit for a Linux x86 UDP service that crashes when sent a long string of 'B's. Before attempting to redirect execution, you want to determine whether the crash gives you control of the instruction pointer. Which single action best confirms that the saved return address on the stack has been overwritten?

A.Use netcat to send 5000 'B's and observe that the service process terminates.
B.Run the service under strace and check for a SIGSEGV signal in the output.
C.Send a unique, non-repeating pattern (e.g., generated by pattern_create) and inspect the value of EIP in the debugger after the crash.
D.Attach a packet sniffer to the loopback interface and look for the string '41414141' in the UDP payload.
AnswerC

A cyclic pattern lets you map the exact bytes that land in EIP. When the service crashes, the value in EIP will be a recognizable slice of that pattern, proving you control the saved return address and revealing the precise offset. This is the standard first step in PEN-200 buffer overflow methodology before selecting a jump instruction or encoding shellcode.

Why this answer

Sending a unique cyclic pattern and inspecting EIP in a debugger is the definitive way to prove control of the instruction pointer and calculate the exact offset. The other actions only show that a crash or delivery occurred, which is insufficient to establish exploitability. This step precedes choosing a jump instruction or placing shellcode.

Exam trap

The trap here is assuming that any crash after a long input proves EIP control, when only debugger inspection of the overwritten return address can confirm it.

17
MCQhard

Which of the following describes the danger of a service that runs as 'LocalSystem' but does not have the 'Interactive' flag enabled?

A.The service is immune to DLL hijacking.
B.The service cannot be exploited.
C.The service is still fully capable of performing administrative actions.
D.The service only runs when a user is logged in.
AnswerC

The 'LocalSystem' account is inherently privileged. Whether a service is 'interactive' or not only dictates its ability to show a desktop window. The underlying privileges remain the same, meaning an attacker gaining control of the service process still gains full administrative control over the host.

Why this answer

Even without the 'Interactive' flag, a service running as 'LocalSystem' has the highest possible privileges on the local machine. The flag only determines if the service can display a GUI to the logged-in user. Attackers can still interact with these services via command-line exploits or by injecting code into them, making the 'Interactive' flag irrelevant for determining the security risk of the service account.

Exam trap

Candidates incorrectly assume that a service lacking the 'Interactive' flag is less privileged or cannot be exploited, failing to realize it still runs with full LocalSystem administrative rights.

18
MCQmedium

You have captured a NetNTLMv2 hash during a man-in-the-middle attack. What is the most effective approach to use this hash to gain access to the target machine?

A.Attempt to relay the hash to another system that has SMB signing disabled.
B.Use the hash directly in a pass-the-hash attack against an RDP session.
C.The hash can be used to authenticate to the Domain Controller for domain persistence.
D.Directly inject the hash into the LSASS process to create a new user session.
AnswerA

NetNTLMv2 hashes are highly effective when used in SMB relay attacks. If the target system has SMB signing disabled, an attacker can relay the hash to authenticate as the victim, gaining immediate access to the system without ever needing to know the user's actual password.

Why this answer

NetNTLMv2 hashes are challenge-response hashes, not password hashes. They cannot be used in a pass-the-hash attack. Instead, they must be cracked offline to obtain the plaintext password or relayed to a target that supports NTLM authentication.

Recognizing the distinction between NetNTLM and NTLM is a critical concept in OSCP-level testing, as it prevents the misuse of these credentials during lateral movement.

Exam trap

Students commonly attempt a direct pass-the-hash attack using a captured NetNTLMv2 challenge-response hash, failing to realize these cannot be used like local NTLM password hashes.

19
Multi-Selectmedium

You are assessing a web application that uses a relational database backend. During manual testing, you suspect a UNION-based SQL injection vulnerability in a product category parameter. Which two of the following steps are necessary to successfully extract data using a UNION-based SQL injection attack? (Choose two.)

Select 2 answers
A.Determine the number of columns returned by the original query.
B.Identify which columns can display string data from the database.
C.Encode the payload using Base64 to bypass web application firewalls.
D.Ensure the database user has file write privileges to create a web shell.
E.Use a time delay function to confirm the vulnerability before extracting data.
AnswersA, B

A UNION-based SQL injection requires that the injected SELECT statement returns the same number of columns as the original query. Without knowing the column count, the database will throw an error and the injection will fail. Testers typically use ORDER BY clauses or UNION SELECT with increasing numbers of NULLs to determine the column count. This step is fundamental to crafting a valid UNION query that retrieves data.

Why this answer

UNION-based SQL injection requires matching the number of columns in the original query and finding columns that can display string data. These two steps allow the attacker to craft a valid UNION SELECT statement that returns additional data in the application's response. Without knowing the column count, the query will fail; without string-compatible columns, extracted data may not be visible.

Other steps like encoding or time delays are not necessary for this attack type.

Exam trap

The trap here is assuming that additional obfuscation or blind techniques are required for UNION-based injection, when the core requirements are simply column count and data type compatibility.

20
MCQeasy

Why is using the default 'msfvenom' encoders like 'shikata_ga_nai' often insufficient for bypassing modern antivirus solutions?

A.They only work on 32-bit systems and are ignored by 64-bit AV.
B.The encoders increase the file size, making it look suspicious.
C.The decoding stubs have well-known, static signatures.
D.They use encryption that is easily decrypted by the AV engine.
AnswerC

Antivirus vendors include the signatures for common Metasploit encoder stubs in their databases. Even though the payload itself is 'randomized' by the encoder, the small piece of code that decrypts that payload remains recognizable. Since this stub must run first, the antivirus identifies it immediately and blocks the execution before the payload is even unpacked.

Why this answer

Metasploit encoders were originally designed to remove 'bad characters' from shellcode to ensure it would run correctly in an exploit. They were not primarily intended for antivirus evasion. Because these encoders are open-source and widely used, antivirus vendors have had years to develop highly accurate signatures for the decoding stubs they generate, making them easily detectable.

Exam trap

Candidates mistakenly believe msfvenom encoders are security features. They are functional tools for payload delivery, and their signatures are widely known by AV engines.

21
MCQhard

You are testing a Java-based web application that uses the Spring framework. The application has an endpoint /api/users/{id} that returns user details in JSON. When you request /api/users/123, you receive your own details. You then request /api/users/124 and receive another user's details. The application uses a session cookie but does not implement any role-based checks on this endpoint. What is the MOST appropriate next step to demonstrate the impact of this vulnerability?

A.Perform a cross-site scripting attack by injecting a script into the user details that are reflected back.
B.Attempt to inject SQL payloads into the id parameter to extract the entire database.
C.Enumerate a range of user IDs to identify administrative accounts and retrieve their sensitive information.
D.Use the session cookie to perform a session fixation attack and hijack an administrator's session.
AnswerC

The endpoint is vulnerable to insecure direct object reference (IDOR). By enumerating IDs, you can access other users' data, including potentially administrators. This demonstrates the impact and is a standard penetration testing step to prove the vulnerability. It is ethical because you are authorized and should avoid modifying data.

Why this answer

The endpoint lacks authorization checks, allowing any authenticated user to access other users' details by changing the user ID. This is an IDOR vulnerability. The most direct way to demonstrate impact is to enumerate IDs to find sensitive accounts, such as administrators, and retrieve their information.

Other attacks like SQL injection or XSS are not indicated by the scenario and would not directly prove the IDOR.

Exam trap

The trap here is to overcomplicate the attack by assuming a more complex vulnerability like SQL injection or session fixation, when the scenario clearly describes an IDOR that can be exploited by simple ID enumeration.

22
Multi-Selectmedium

You are adapting a public Python exploit for a Windows target. The exploit was written for a different architecture and uses a hardcoded payload. Which TWO actions are MOST appropriate to make the exploit work reliably? (Choose two.)

Select 2 answers
A.Rewrite the exploit in C to improve execution speed against the target.
B.Change the exploit's delivery mechanism from HTTP to SMB to bypass network filtering.
C.Disable the target's firewall to allow the reverse shell to connect back.
D.Update the exploit's target IP address and port variables to match your listener and the victim host.
E.Replace the hardcoded payload with one generated for the target's architecture and operating system.
AnswersD, E

Hardcoded network parameters are common in public exploits. If the target IP or callback port does not match your environment, the exploit either fails to reach the vulnerable service or the payload connects to the wrong host. Correcting these variables aligns the exploit with your engagement setup and ensures the reverse connection returns to your listener.

Why this answer

Public exploits frequently contain hardcoded payloads and network settings from the original author's environment. Regenerating the payload for the target's architecture and OS, and updating the target and callback addresses, are the two changes that directly make the exploit function against your specific host. Other modifications are unnecessary or require prior access.

Exam trap

The trap here is focusing on rewriting or re-engineering the exploit when the actual blockers are a mismatched payload architecture and incorrect network parameters.

23
MCQeasy

What is the primary danger of using a public exploit without first auditing the source code?

A.The script might use too much disk space.
B.The script might contain hidden malicious payloads.
C.The script will always work perfectly as intended.
D.The script might be written in an obscure language.
AnswerB

Auditing the code is the only way to ensure the exploit is not performing unauthorized actions, like installing a backdoor on your own machine. This is a critical security practice for any penetration tester who wants to maintain a secure and professional testing environment.

Why this answer

Public exploits are often shared without security vetting. They may contain hidden payloads designed to compromise the researcher's system, execute unauthorized commands, or send sensitive information to a third-party server. Auditing the code ensures you understand exactly what the script does, protecting your own infrastructure and confirming that the exploit is safe and focused only on the intended target system during your assessment.

Exam trap

Candidates often focus exclusively on whether an exploit works against the target, overlooking the severe risk that malicious third-party scripts can compromise the attacker's system.

24
MCQmedium

Which Linux kernel feature, if misconfigured or outdated, allows an unprivileged user to gain root access by exploiting a vulnerability in the handling of user namespaces?

A.AppArmor profile confinement
B.Unprivileged user namespace clone functionality
C.Shared memory segment access via IPC
D.Extended file attributes (xattr)
AnswerB

The 'unshare' or 'clone' syscalls allow creating new namespaces without root. Exploits often target how the kernel handles these namespaces to escalate privileges. Because these features are often exposed to all users, they serve as a critical vector for local privilege escalation attacks on outdated kernels.

Why this answer

User namespaces allow unprivileged processes to behave as root within a confined environment. Vulnerabilities in how the kernel manages these namespaces, such as improper capability checks, can be exploited to gain full root access on the host system. This highlights the importance of kernel patching and minimizing the attack surface by disabling unnecessary namespace features on production servers to prevent escapes.

Exam trap

Candidates often confuse user namespace features with standard file permissions or misconfigured SUID binaries, looking in the wrong places for kernel-level escalation vectors.

25
MCQhard

When performing a kernel exploit for privilege escalation, what is the most significant risk to the stability of the target system?

A.The system will automatically log the attacker's IP address.
B.The system might experience a kernel panic, causing a complete crash.
C.The exploit will permanently delete all data on the disk.
D.The system firewall will automatically block the user account.
AnswerB

Because kernel exploits manipulate sensitive memory structures and CPU instructions, any mistake or unexpected state will trigger a kernel panic. This results in an immediate and total system crash, which is a major risk when attempting privilege escalation on live systems that need to remain operational.

Why this answer

Kernel exploits operate at the lowest level of the operating system. If the exploit code contains errors or interacts incorrectly with kernel memory structures, it can lead to a kernel panic, crashing the entire system. This is a significant operational risk, as it results in downtime and potentially triggers alerts that lead to discovery, emphasizing the need for caution and testing exploits in isolated environments before deployment on production targets.

Exam trap

Candidates often fear being 'caught' by an IDS/IPS. While that is a risk, the immediate, most significant technical risk of a kernel exploit is crashing the target machine entirely.

26
Multi-Selecthard

You have compromised a domain user account and discovered that the domain controller is running Windows Server 2016. You want to extract the KRBTGT account hash to create a Golden Ticket. Which two conditions are necessary to successfully perform a DCSync attack to obtain the KRBTGT hash? (Choose two.)

Select 2 answers
A.The compromised user account must have the Replicating Directory Changes All permission on the domain object.
B.The compromised account must have the Replicating Directory Changes permission on the domain object.
C.The compromised user account must be a member of the Domain Admins group.
D.The attacker must have local administrator access on the domain controller.
E.The domain functional level must be at least Windows Server 2008 or higher.
AnswersA, B

DCSync abuses the Directory Replication Service (DRS) protocol by impersonating a domain controller. To do so, the account must have the Replicating Directory Changes All extended right on the domain partition, which allows it to request replication of directory data including password hashes. Without this permission, the DRS request will be denied, making this a necessary condition.

Why this answer

To perform DCSync, the compromised account must possess both the Replicating Directory Changes and Replicating Directory Changes All permissions on the domain object. These permissions allow the account to impersonate a domain controller and request replication of directory data, including password hashes. While Domain Admins have these by default, any account with these delegated rights can execute the attack.

Exam trap

The trap here is assuming that Domain Admin membership or local admin access on the DC is required, when in fact only the specific replication permissions are necessary.

27
MCQmedium

During a penetration test, you obtain a Kerberos TGS-REP hash for a service account. You want to crack this hash offline to recover the service account's password. Which of the following tools is most appropriate for this task?

A.John the Ripper with the krb5tgs format
B.Hydra with the kerberos module
C.Hashcat with mode 13100
D.Aircrack-ng with the -K option
AnswerC

Hashcat mode 13100 is specifically for cracking Kerberos 5 TGS-REP etype 23 (RC4) hashes. These hashes are obtained through Kerberoasting. Using this mode allows efficient offline cracking with wordlists or brute-force, making it the correct choice for this scenario.

Why this answer

Kerberoasting yields TGS-REP hashes that can be cracked offline. Hashcat mode 13100 is designed for RC4-encrypted TGS-REP hashes, providing efficient GPU-accelerated cracking. John the Ripper can also do it but is less optimized.

Aircrack-ng and Hydra are not appropriate for offline Kerberos hash cracking. Therefore, Hashcat with mode 13100 is the best choice.

Exam trap

The trap here is selecting a tool that can attack Kerberos online rather than one designed for offline cracking of captured TGS-REP hashes.

28
MCQmedium

You are performing reconnaissance and want to identify if a target website uses a specific CMS like WordPress. What is the most effective approach?

A.Manually inspect every image on the site.
B.Use tools like whatweb or Wappalyzer.
C.Perform a denial-of-service attack.
D.Guess the CMS by looking at the page title.
AnswerB

Whatweb and Wappalyzer are specialized reconnaissance tools that automatically detect the software stack, including the CMS, by analyzing server headers and page source code. This is the professional standard for quickly identifying the application framework, which is essential for tailoring your exploitation strategy to the specific target platform.

Why this answer

Automated tools like 'wappalyzer' or 'whatweb' are highly effective at identifying the underlying technology stack of a web application. They analyze HTTP headers, source code patterns, and common file paths to detect CMS platforms. Identifying the CMS is critical because it allows the tester to focus on known vulnerabilities associated with that specific platform, rather than spending time on generic web assessments that may yield fewer results.

Exam trap

Candidates often suggest manual source code inspection. Automated tools are far more efficient and reliable for identifying the CMS signature across various HTTP headers and file paths.

29
MCQeasy

During a penetration test on a Windows Server 2019 host, you obtain a low-privileged shell as user 'webuser'. You run 'whoami /priv' and observe that the account has SeImpersonatePrivilege enabled. Which exploitation technique is most directly applicable?

A.Schedule a task to run as SYSTEM using schtasks with the /RU SYSTEM flag.
B.Use a token impersonation attack such as JuicyPotato or PrintSpoofer to impersonate a SYSTEM token.
C.Modify a service binary that runs as SYSTEM to execute a reverse shell.
D.Extract password hashes from the SAM database using Mimikatz and pass-the-hash.
AnswerB

SeImpersonatePrivilege allows a process to impersonate a token, and tools like JuicyPotato or PrintSpoofer abuse this by coercing a privileged service to authenticate, then capturing and impersonating its token. This directly leverages the privilege to escalate to SYSTEM without needing to modify files or registry keys.

Why this answer

SeImpersonatePrivilege permits a process to impersonate another user's token. Attackers exploit this by forcing a privileged service to authenticate to a controlled endpoint, then impersonating its token to gain SYSTEM-level access. Tools like JuicyPotato, RoguePotato, or PrintSpoofer automate this.

The other options require permissions not granted by this privilege, such as file write or administrative task creation.

Exam trap

The trap here is assuming that SeImpersonatePrivilege alone allows direct token theft from any process, when it actually requires coercing a privileged service to authenticate first.

30
MCQmedium

A penetration tester discovers that the current user can write to a script located in /opt/backup/ that is executed every minute by a cron job running as root. The script has permissions `-rwxr-xr-x 1 root root`. What is the MOST reliable way to escalate privileges?

A.Use the `at` command to schedule a script that modifies the cron job.
B.Change the script's permissions to 777 and then execute it manually.
C.Create a symbolic link to /etc/passwd in the same directory and modify the script to write to it.
D.Modify the script to add a reverse shell command, then wait for the cron job to execute.
AnswerD

This is correct. Since the script is writable by the current user and executed by root via cron, modifying it to include a reverse shell or a command that creates a SUID binary will execute with root privileges. Waiting for the next cron interval triggers the escalation.

Why this answer

Because the script is writable and executed by root, an attacker can insert arbitrary commands that run with root privileges. Modifying the script to spawn a reverse shell or create a SUID backdoor is the most direct and reliable method. The cron job will execute the modified script as root, granting escalation.

Exam trap

The trap here is overcomplicating the attack with symlinks or permission changes when the script is already directly writable and executed by root.

31
MCQhard

Which of the following describes the risk associated with using a password manager that lacks a master password and relies solely on local file encryption?

A.The vault is vulnerable to dictionary attacks due to the lack of a salt in the local file.
B.The encryption keys are stored in a predictable location or memory, allowing for easy extraction.
C.The lack of a master password prevents the use of multi-factor authentication for the vault.
D.The file format will be incompatible with standard password cracking software like John the Ripper.
AnswerB

When a master password is not required, the application must derive the decryption key from static sources, such as registry keys, machine GUIDs, or environment variables. An attacker with access to the system can easily locate these sources to decrypt the vault, rendering the 'encryption' effectively transparent to them.

Why this answer

Password managers are designed to consolidate credentials, but they are only as secure as their master secret. Without a master password, the vault relies on the security of the host filesystem. If an attacker gains local access or performs a memory dump, the keys are easily extractable.

This concept is vital for understanding how credential storage mechanisms can be exploited when the primary authentication factor is absent or bypassed.

Exam trap

Candidates often assume that local file encryption is sufficient for security. They ignore that if the master key is stored in memory or a predictable location, it can be easily extracted.

32
MCQeasy

During a client-side assessment, you find that an application accepts a user-supplied URL parameter and later uses it to redirect the browser away from the site without validating the destination. Which vulnerability class does this behavior represent, and what is its most direct client-side impact?

A.Open redirect, because the browser can be sent to an attacker-controlled destination for phishing or credential harvesting
B.CSRF, because the redirect causes the victim to submit a forged request
C.Clickjacking, because the redirect overlays a transparent frame on the page
D.DOM-based XSS, because the redirect executes script in the victim's browser
AnswerA

When a parameter controls a navigation target without validation, the site becomes an open redirect. Attackers abuse the trusted domain to send victims to a lookalike login page or malware host, which is especially convincing in phishing. This matches the described behavior and its most direct client-side consequence.

Why this answer

An unvalidated redirect parameter turns the trusted application into an open redirect. Because the link points at the legitimate domain, victims are more likely to trust it, and the attacker can land them on a credential-harvesting page or malicious download. The key impact is phishing facilitation, not script execution or request forgery.

Exam trap

The trap here is assuming any client-side URL handling must be XSS, when an unvalidated redirect produces navigation rather than script execution.

33
MCQmedium

You have captured an NTLM hash of a domain user. Why is performing a Pass-the-Hash (PtH) attack often more effective than attempting to crack the hash for the cleartext password?

A.It requires less network traffic than a standard login
B.The hash is accepted directly by the authentication service
C.Cracking the hash is prohibited by corporate policy
D.The hash provides access to all domain controllers
AnswerB

NTLM authentication protocols authenticate using the NTLM hash directly. By providing the hash to the authentication process, the attacker can successfully impersonate the user without needing to crack the hash to reveal the cleartext password, making it an immediate and highly effective method for lateral movement.

Why this answer

Pass-the-Hash relies on the fact that Windows authentication protocols (NTLM) use the hash itself as a form of credential. By injecting the hash into the authentication process, the attacker can authenticate as the user without ever knowing the cleartext password. This bypasses complexity requirements and is immune to password cracking speeds, making it an extremely efficient method for lateral movement within a domain.

Exam trap

Candidates incorrectly believe cracking a hash is necessary to authenticate. In Windows NTLM authentication, the hash itself is treated as the proof of identity, rendering cracking unnecessary for successful login.

34
MCQhard

You are exploiting a 32-bit Linux buffer overflow and have overwritten EIP with the address of a `JMP ESP` instruction located in a non-ASLR module. However, when you run the exploit, the program crashes with a segmentation fault, and no shell is obtained. You verify that the offset is correct and the JMP ESP address is accurate. What is the most likely reason for the failure?

A.The shellcode contains bad characters that were not filtered, causing it to be truncated.
B.The JMP ESP instruction address contains a null byte, which terminates the string copy.
C.The offset to EIP was miscalculated, so the return address is overwritten with an incorrect value.
D.The stack is not executable, so the shellcode placed on the stack cannot run.
AnswerD

Modern Linux systems often have the NX (No-eXecute) bit enabled, marking the stack as non-executable. Even if EIP is redirected to JMP ESP, the jump lands on the stack where shellcode resides, but the CPU refuses to execute it due to NX. This results in a segmentation fault. To bypass NX, you would need to use return-oriented programming (ROP) or another technique to mark the stack executable or call mprotect.

Why this answer

The most likely reason is that the stack is non-executable (NX enabled). Even with a correct JMP ESP and offset, the CPU cannot execute shellcode on the stack, leading to a segmentation fault. This is a common obstacle on modern Linux systems.

The other options are ruled out because the scenario confirms the offset and JMP ESP address are correct, and bad characters would not prevent the JMP ESP from executing.

Exam trap

The trap here is focusing on payload corruption instead of considering memory protection mechanisms like NX, which prevent execution even with a correct control-flow hijack.

35
MCQmedium

When analyzing the memory of a compromised system, you find that your shellcode is being detected by behavioral monitoring. What is the most effective approach to reduce the likelihood of detection by EDR systems during process injection?

A.Increasing the sleep interval between shellcode execution stages.
B.Utilizing indirect syscalls to execute memory operations without triggering API hooks.
C.Injecting the shellcode into a low-privilege process to minimize impact.
D.Replacing the shellcode with an equivalent set of PowerShell commands.
AnswerB

Indirect syscalls bypass the user-mode hooks installed by EDRs in common Windows APIs like NtAllocateVirtualMemory. By invoking the kernel directly from the assembly, the shellcode avoids passing through monitored functions, effectively blinding the EDR to the memory allocation process, which is the primary indicator of malicious injection.

Why this answer

Behavioral detection focuses on suspicious API calls, such as VirtualAllocEx and WriteProcessMemory, being called by an unauthorized or unexpected process. By using indirect syscalls or alternative memory allocation methods, you can bypass the hooks that security products place on high-level Windows APIs. This is critical in modern testing because EDRs monitor process interactions in real-time, making standard injection techniques trivial for security software to identify and block immediately.

Exam trap

Candidates frequently confuse direct API calls with evasion techniques, assuming standard process injection methods are stealthy enough to bypass modern EDR behavioral monitoring without modifications.

36
MCQmedium

During a Linux privilege escalation assessment, you obtain a low-privileged shell as user 'student'. You run 'id' and see the user belongs to the 'docker' group. Which command will most reliably escalate to root on this host?

A.newgrp docker
B.unshare -Ur
C.docker run -v /:/mnt --rm -it alpine chroot /mnt sh
D.sudo -u root /bin/bash
AnswerC

Members of the docker group can control the Docker daemon, effectively giving root-level access to the host. This command starts a container, mounts the host's root filesystem at /mnt inside the container, and then uses chroot to change the root to /mnt, spawning a shell with root privileges on the host's filesystem. This is a classic and reliable privilege escalation technique when docker group membership is present.

Why this answer

Docker group membership allows a user to interact with the Docker daemon, which runs as root. By mounting the host root filesystem into a container and chrooting into it, an attacker can effectively gain root-level access to the host. This technique is well-known and reliable, as it leverages the daemon's privileges to bypass filesystem permissions.

The other commands either require existing sudo rights, only change group context, or create isolated namespaces without host root privileges.

Exam trap

The trap here is assuming that docker group membership only allows managing containers, when in fact it provides a direct path to host root via filesystem mounts.

37
MCQeasy

You are analyzing a target web application that reflects user input directly into an HTML attribute without proper sanitization. Which vulnerability class should you primarily investigate for exploitation?

A.SQL Injection
B.Cross-Site Scripting (XSS)
C.Remote Code Execution
D.Cross-Site Request Forgery
AnswerB

Reflected XSS targets client-side execution by injecting malicious JavaScript through unvalidated parameters that get rendered immediately. This vulnerability allows attackers to steal session cookies, capture keystrokes, or perform actions on behalf of the authenticated user when they click a crafted link.

Why this answer

Reflected Cross-Site Scripting occurs when untrusted user input is immediately processed and returned by a web application in an unsafe context, such as within an HTML attribute. Identifying this flaw allows attackers to craft malicious URLs that execute arbitrary JavaScript in the victim browser.

Exam trap

Candidates often confuse Reflected XSS with Stored XSS or SQL Injection. They forget that the vulnerability is specifically triggered by the immediate reflection of input in a browser-rendered context.

38
MCQmedium

A tester is targeting a Windows machine and notices that a specific legitimate application regularly looks for a COM object that is missing from the HKEY_CURRENT_USER (HKCU) registry hive, eventually falling back to HKEY_LOCAL_MACHINE (HKLM). How can this be exploited for evasion?

A.By performing a privilege escalation to modify the HKLM hive.
B.By hijacking the COM object to execute code under a trusted process.
C.By using the missing key to trigger a buffer overflow in the application.
D.By deleting the HKLM key to force the application to use HKCU.
AnswerB

Because the application searches HKCU first, it will find and use the attacker's malicious COM mapping instead of the legitimate one in HKLM. This results in the trusted application loading the attacker's DLL. This is an effective evasion technique because the malicious activity is masked by the legitimate process's identity.

Why this answer

This scenario describes COM Hijacking. By creating the missing registry key in HKCU, the attacker can redirect the application to load a malicious DLL. Since HKCU is searchable before HKLM and can be modified without administrative privileges, this allows for persistent execution of code within a trusted process while bypassing alerts that might trigger on more obvious persistence methods.

Exam trap

Candidates often confuse this with DLL Hijacking. While the mechanism uses a malicious DLL, the core exploit here is the manipulation of the registry to redirect COM object loading.

39
MCQeasy

You have compromised a Linux host and extracted the /etc/shadow file. The file contains a hash starting with `$6$`. Which hashing algorithm does this prefix indicate?

A.MD5crypt
B.SHA-512crypt
C.SHA-256crypt
D.bcrypt
AnswerB

The `$6$` prefix in /etc/shadow indicates SHA-512crypt, a widely used password hashing algorithm on Linux systems. It is based on the SHA-512 algorithm and includes a salt to protect against rainbow table attacks. Knowing the algorithm is crucial for selecting the correct cracking mode in tools like Hashcat (mode 1800) or John the Ripper (format sha512crypt). This prefix is part of the modular crypt format used by many Unix-like systems.

Why this answer

In the modular crypt format, the prefix before the second `$` indicates the hashing algorithm. `$6$` is the standard identifier for SHA-512crypt, which is commonly used on modern Linux systems for storing password hashes in /etc/shadow. Recognizing this prefix allows a penetration tester to choose the correct cracking tool and mode, such as Hashcat mode 1800 or John the Ripper's sha512crypt format, to efficiently recover plaintext passwords.

Exam trap

The trap here is mixing up the numeric prefixes for different crypt algorithms, such as `$5$` for SHA-256crypt or `$1$` for MD5crypt.

40
MCQhard

You have obtained a low-privileged shell on a Windows Server 2016 machine. While enumerating, you notice that the 'SeImpersonatePrivilege' is enabled for your user account. You also find that the machine is running a service with a named pipe '\\.\pipe\svcctl' that is accessible. Which tool is specifically designed to exploit this privilege to escalate to SYSTEM?

A.WinPEAS
B.JuicyPotato
C.PowerUp
D.Mimikatz
AnswerB

JuicyPotato exploits SeImpersonatePrivilege by tricking a privileged process into connecting to a malicious named pipe, then impersonating its token. It is specifically designed for Windows systems where SeImpersonate is enabled. The tool leverages COM object hijacking and is effective on many Windows versions, including Server 2016. It directly addresses the scenario.

Why this answer

JuicyPotato is designed to exploit SeImpersonatePrivilege by coercing a privileged process to authenticate to a malicious named pipe, then impersonating its token. This allows escalation to SYSTEM. PowerUp and WinPEAS are enumeration tools, and Mimikatz is for credential dumping, not privilege escalation via token impersonation.

Exam trap

The trap here is confusing enumeration tools like WinPEAS or PowerUp with exploitation tools that actually leverage SeImpersonatePrivilege.

41
Multi-Selectmedium

When modifying a public exploit to fit your specific target, which TWO of the following actions are considered best practices? (Choose TWO)

Select 2 answers
A.Updating the hardcoded IP address and port to match your target.
B.Changing the exploit code to use a different programming language entirely.
C.Replacing the default payload with your own reverse shell payload.
D.Deleting all comments to make the exploit run faster.
E.Adding complex obfuscation to bypass all possible firewalls.
AnswersA, C

Hardcoded values in public exploits are specific to the original researcher's environment. Updating these to match your current target is mandatory for the exploit to reach the intended destination. Failing to do this will result in the exploit attempting to connect to an irrelevant host.

Why this answer

Modifying public exploits is a common task that requires precision to ensure the exploit succeeds without crashing the service. Adjusting parameters like the payload and connection information is essential for success. Properly testing these changes in a lab environment first prevents accidental service downtime or triggering defensive alerts during the actual assessment, ensuring the exploitation process is methodical, predictable, and aligned with your testing objectives.

Exam trap

Candidates often suggest running the exploit exactly as downloaded. You must always update connection parameters and payloads to match your specific target environment to ensure success and avoid crashes.

42
MCQeasy

When using Searchsploit, what is the purpose of the '-m' flag?

A.To move the exploit file to the root directory.
B.To mirror (copy) the exploit to the current directory.
C.To mark the exploit as malicious.
D.To monitor the exploit for execution errors.
AnswerB

The '-m' flag is specifically designed to mirror an exploit file into your current directory, making it accessible for modification. This is an essential step for any tester who needs to customize an exploit before execution, ensuring the original database remains untouched for future use.

Why this answer

The '-m' flag in Searchsploit is used to mirror or copy an exploit file from the local database into your current working directory. This is highly useful because it allows you to easily edit and configure the exploit script without modifying the original source files, keeping your environment organized and enabling quick modifications to fit specific target requirements during a penetration test.

Exam trap

Candidates often think it executes the exploit. The flag is strictly for copying the file so it can be modified without corrupting the original exploit database file.

43
MCQmedium

You are conducting a client-side attack using a weaponized Microsoft Office document containing a malicious VBA macro. Which user interaction and application setting combination is required for the macro to execute successfully by default?

A.The user must double-click the document while holding down the Shift key to bypass AutoOpen restrictions
B.The file must be saved in the local startup directory and the user must open the application normally
C.The user must click 'Enable Content' in the security banner after the file opens in Protected View
D.The target workstation must have macro auditing disabled via Group Policy Objects before execution
AnswerC

Modern Microsoft Office suites isolate downloaded documents in Protected View and display a yellow security banner warning about active content. Execution only occurs if the user explicitly overrides these security controls by clicking the enable button.

Why this answer

By default, modern Microsoft Office applications block macros in files obtained from the internet using Office Protected View and Antimalware Scan Interface integrations. Users must explicitly click 'Enable Content' in the Security Warning banner after opening the file for the VBA code to run.

44
Multi-Selectmedium

Which THREE 'Living off the Land' (LotL) binaries are frequently used by penetration testers to download or execute malicious code while bypassing basic antivirus restrictions?

Select 3 answers
A.certutil.exe
B.mshta.exe
C.regsvr32.exe
D.calc.exe
E.notepad.exe
AnswersA, B, C

Certutil is a command-line program for managing certificates, but it includes a '-urlcache -split -f' parameter that allows it to download files from the internet. Because it is a trusted system utility, many basic antivirus programs and firewall rules do not flag it when it initiates a network connection to retrieve a file.

Why this answer

Living off the Land binaries (LoLBins) are legitimate, pre-installed Windows tools that can be repurposed for malicious activities. Using these tools is effective for evasion because they are signed by Microsoft and are often whitelisted by security policies. Certutil, Mshta, and Regsvr32 are classic examples that can fetch remote files or execute scripts while appearing as normal system operations.

Exam trap

Candidates often include tools like 'mimikatz.exe' or 'netcat.exe'. These are not LoLBins because they are not signed, native Windows binaries. Stick to Microsoft-signed tools.

45
MCQmedium

You have identified an outdated version of a web application running on a target. You found a public exploit script for this version on Exploit-DB. Which step is most critical before executing the exploit script against the target?

A.Immediately run the script with root privileges to ensure full access.
B.Upload the script directly to the target system via a browser-based upload form.
C.Review the source code to verify target parameters and modify hardcoded configurations.
D.Convert the script into a binary executable using a compiler to hide its nature.
AnswerC

Reviewing source code allows you to identify hardcoded variables such as LHOST, LPORT, or specific file paths that must align with your attack machine. Customizing the script ensures that the reverse shell or exploit payload reaches the correct destination without being blocked or routed to an incorrect internal address.

Why this answer

Validating the exploit code is essential because public scripts often contain hardcoded IP addresses, paths, or shellcode that may not match your environment. Modifying the script ensures it executes properly, avoids unintended network traffic, and prevents potential instability on the target service. Failure to review code can lead to silent failure, false positives, or accidental service crashes, hindering your overall progress during an assessment.

Exam trap

Test-takers often assume public exploit scripts work out-of-the-box and neglect to review target parameters, leading to unintended service crashes or execution failures in custom environments.

46
MCQmedium

Refer to the exhibit. You have scanned a target and obtained these results. Which step is most logical to perform next to effectively enumerate the web service?

A.Immediately attempt to exploit the FTP service with anonymous login.
B.Perform directory busting using tools like ffuf or gobuster.
C.Brute-force the SSH service using a list of common passwords.
D.Run a full vulnerability scanner against the entire target IP.
AnswerB

Directory busting helps discover unlinked files and directories that could contain sensitive information, backups, or administrative interfaces. This enumeration phase is vital because many web applications rely on security by obscurity, and finding these hidden paths often provides the necessary leverage for a successful penetration test and further exploitation.

Why this answer

After identifying open ports, the next logical step is to enumerate the specific services running. For port 80, web directory brute-forcing is essential to uncover hidden administrative panels or configuration files that might not be linked on the home page. This systematic approach ensures no low-hanging fruit is missed, providing a deeper understanding of the target's attack surface before attempting any vulnerability exploitation against the identified web application or services.

Exam trap

Candidates often attempt to immediately brute-force web login pages or run heavy vulnerability scanners without first discovering hidden directories and files.

47
MCQmedium

You are enumerating a Linux host and discover TCP port 2049 open. You need to determine what is being exported and to whom before deciding on any exploitation path. Which action most directly answers that question?

A.Run showmount -e <target> to list exported filesystems and permitted clients.
B.Run smbclient -L //<target> -N to list available SMB shares.
C.Use ftp <target> 2049 and authenticate anonymously to browse the share.
D.Connect with rdesktop <target>:2049 to inspect the remote desktop session.
AnswerA

Port 2049 is NFS, and showmount -e queries the target's mount daemon to display each exported share along with the host or subnet allowed to mount it. That output directly answers what is exported and to whom, which is exactly the reconnaissance objective. It is a lightweight, standard query that does not modify anything on the server, making it the most direct and appropriate next step.

Why this answer

NFS enumeration centers on the mount protocol, which advertises exported directories and the client hosts or networks authorized to mount them. The showmount utility with the -e flag performs exactly that query against the target. Other tools suggested here speak SMB, RDP, or FTP, none of which correspond to the NFS service listening on port 2049, so they cannot reveal export details or access restrictions.

Exam trap

The trap here is treating any open file-sharing port as SMB and reaching for smbclient instead of matching the tool to the NFS service on port 2049.

48
MCQeasy

Which of the following describes a stored Cross-Site Scripting (XSS) attack?

A.A script is reflected in the URL parameters of a request.
B.A script is injected into a database and served to future users.
C.A script is executed purely on the client-side without reaching the server.
D.An attacker uses a brute-force attack to guess user passwords.
AnswerB

Stored XSS involves injecting malicious code into persistent storage like a database, forum post, or profile field. When other users view the page, the server delivers the stored payload to their browsers, which then execute it. This allows for persistent, widespread impact across all users visiting the compromised page.

Why this answer

Stored XSS occurs when malicious scripts are permanently saved on the target server, such as in a database or comment section. Every user who visits the affected page subsequently executes the script in their browser. This is highly dangerous because the attack propagates automatically to all users, often allowing attackers to steal session cookies, perform unauthorized actions, or redirect users to malicious domains without any interaction from the victim.

Exam trap

Candidates often confuse stored XSS with reflected XSS, failing to recognize that stored payloads reside permanently within a database to affect multiple visiting users.

49
MCQmedium

During a penetration test against a web application, you identify a parameter vulnerable to Blind SQL Injection. The backend database is Microsoft SQL Server, and the application does not return any error messages or query results. Which technique should you use to exfiltrate data character by character based on application behavior?

A.Injecting UNION SELECT statements combined with string concatenation to dump table contents directly into the main HTTP response body
B.Leveraging stacked queries with xp_cmdshell to execute operating system commands and retrieve files via a reverse shell connection
C.Using conditional statements paired with database delay functions like WAITFOR DELAY to measure response time variations
D.Triggering detailed database syntax errors to leak table names and column definitions through the application error handler
AnswerC

Microsoft SQL Server supports conditional execution using IF statements combined with the WAITFOR DELAY command. By measuring how long the web server takes to respond, you can infer whether your injected logical condition evaluated to true or false.

Why this answer

Time-based blind SQL injection relies on database-specific delay functions like WAITFOR DELAY in Microsoft SQL Server to force the server to pause execution when a logical condition is true. This technique is critical during assessments when out-of-band channels are blocked and standard response inspection fails, allowing testers to systematically recover sensitive information through latency measurements.

Exam trap

Candidates often confuse boolean-based blind injection with time-based injection, attempting to look for page content changes when the application response is completely static and only execution speed varies.

50
MCQmedium

You have obtained credentials for a domain user and want to enumerate Active Directory to find misconfigured ACLs that allow privilege escalation. You need to collect data that maps relationships between users, groups, computers, and sessions, and you want to visualize shortest paths to Domain Admin. Which tool and collection method best fits this requirement?

A.Run SharpHound with the -c All collection method and import the resulting JSON files into BloodHound for path analysis.
B.Execute CrackMapExec with the --shares and --sessions modules to enumerate shares and active sessions across the domain.
C.Run ldapsearch against the domain controller with a filter for objectClass=user and parse the output for group membership attributes.
D.Use PowerView's Invoke-ShareFinder to list accessible shares and infer privilege escalation paths from share permissions.
AnswerA

SharpHound is the official BloodHound collector, and the -c All method gathers group memberships, ACLs, sessions, and trusts. The resulting JSON data imports directly into BloodHound, which computes shortest paths to high-value targets like Domain Admin. This combination directly satisfies the requirement to map relationships and visualize escalation paths.

Why this answer

BloodHound with SharpHound is purpose-built for Active Directory attack path analysis. The -c All collection method gathers the full set of relationships, including ACLs and sessions, that BloodHound needs to compute shortest paths. Alternative enumeration tools may gather partial data but lack the graph-based analysis and visualization that makes escalation paths immediately actionable.

Exam trap

The trap here is equating general AD enumeration tools with attack path analysis, when only a graph-based collector and analyzer can compute shortest paths to high-value targets.

51
Multi-Selecthard

Which THREE of the following are considered 'active' reconnaissance techniques, as opposed to passive techniques?

Select 3 answers
A.Port scanning with Nmap.
B.Service version detection.
C.Directory brute-forcing.
D.WHOIS lookup.
E.Searching Google for public documents.
AnswersA, B, C

Port scanning requires sending packets directly to the target system to determine if specific ports are open. This interaction is recorded in logs and constitutes a clear 'active' action, as the target system must process and reply to the probes, making it a highly visible reconnaissance technique.

Why this answer

Active reconnaissance involves direct interaction with the target system, which creates a visible footprint in server logs. Techniques like port scanning, service version detection, and directory brute-forcing are all active because they involve sending packets that the target must respond to. In contrast, passive reconnaissance uses third-party services to gather information without touching the target.

Understanding this distinction is vital for maintaining the desired level of stealth throughout the reconnaissance and exploitation process.

Exam trap

Candidates often misidentify banner grabbing or simple DNS lookups as active. Active reconnaissance requires direct interaction that generates logs on the target system, unlike passive OSINT gathering.

52
MCQmedium

During an authorized web application assessment, you discover a search page that reflects the query parameter directly into the HTML response body without encoding. You want to confirm the presence of a reflected cross-site scripting vulnerability using a minimal, non-destructive payload. Which of the following payloads is most likely to execute JavaScript in a victim's browser when injected into the vulnerable parameter?

A.1' OR '1'='1
B.../../../../etc/passwd
C.<script>alert(document.domain)</script>
D.'; DROP TABLE users; --
AnswerC

This payload injects a script tag that executes in the context of the victim's browser when the reflected response is rendered, directly confirming reflected cross-site scripting. Because the parameter is reflected unencoded into the HTML body, the browser parses the script element and runs the JavaScript, causing an alert that displays the current domain. This is a standard, minimal proof-of-concept for reflected XSS in an authorized penetration test.

Why this answer

Reflected cross-site scripting occurs when user input is immediately returned by the web server without proper output encoding, allowing an attacker to inject client-side script. A script tag containing a simple alert is a reliable proof of concept because it executes in the victim's browser context when the crafted URL is visited. The other payloads target SQL injection or path traversal and do not demonstrate JavaScript execution.

Exam trap

The trap here is assuming that any special characters reflected in the response confirm XSS, when only payloads that are parsed as executable script in the browser context actually demonstrate the vulnerability.

53
Multi-Selectmedium

Which TWO methods are effective for obfuscating a PowerShell script to bypass AMSI without modifying the underlying system DLLs?

Select 2 answers
A.String Concatenation
B.Memory Patching
C.Variable Randomization
D.Registry Modification
E.Kernel Driver Loading
AnswersA, C

By breaking a keyword like 'amsiInitFailed' into smaller pieces (e.g., 'am' + 'si' + 'Init') and joining them at runtime, the static scanner cannot see the full word. Since AMSI often relies on keyword-based signatures, this simple technique can effectively prevent the script from being flagged during the pre-execution scan.

Why this answer

PowerShell obfuscation for AMSI bypass focuses on making the script content unrecognizable to the scanner. String concatenation breaks up known malicious keywords, while variable randomization ensures that simple signature matches fail. These techniques are applied directly to the script code and do not require administrative privileges to patch memory or modify protected system files like amsi.dll.

Exam trap

Candidates often guess 'patching amsi.dll in memory'. The question specifically asks for methods to obfuscate the script content itself, not methods that modify the system's memory-resident AMSI engine.

54
Multi-Selectmedium

Which TWO of the following techniques are most effective for enumerating SMB shares on a Windows host during a penetration test?

Select 2 answers
A.Use smbclient -L //target_ip -N to list available shares.
B.Run nmap with the --script smb-enum-shares scan argument.
C.Perform a brute-force attack on the C$ share.
D.Attempt to ping the host using ICMP to check SMB connectivity.
E.Use the telnet command to connect to port 445.
AnswersA, B

The smbclient tool is the standard Linux utility for interacting with SMB shares. The -L flag queries the target for a list of shares, and the -N flag specifies no password, which is essential when testing for null sessions or guest access that might be improperly enabled on the target.

Why this answer

Enumerating SMB shares is crucial for identifying sensitive data, configuration files, or scripts that can lead to privilege escalation. Tools like smbclient and specialized scripts allow testers to interact with the SMB protocol to list shares and check for null sessions. Understanding these methods is fundamental for gathering intelligence in Windows environments, as misconfigured SMB permissions often provide an easy path to sensitive information and potential system compromise.

Exam trap

Candidates often forget specific syntax parameters or use tools that require active domain credentials when attempting unauthenticated SMB enumeration like null sessions.

55
MCQeasy

A junior penetration tester is preparing a payload for a Windows 10 target and wants to avoid signature-based detection by changing the binary's appearance without altering its functionality. Which technique is specifically designed to achieve this?

A.Splitting the payload into multiple chunks and reassembling at runtime.
B.Running the payload from a remote SMB share instead of the local disk.
C.Encoding the payload with msfvenom's shikata_ga_nai encoder multiple times.
D.Compressing the payload with UPX to reduce its size.
AnswerC

Shikata_ga_nai is an encoder that transforms the payload's bytes using a polymorphic XOR additive feedback loop, changing the binary appearance while preserving functionality. Applying it multiple times further mutates the signature, which can help evade static signature-based detection. This is a classic PEN-200 technique for altering the file's binary appearance without changing what the payload does.

Why this answer

Shikata_ga_nai is a polymorphic encoder that mutates the payload's bytes while preserving its functionality, directly targeting signature-based detection by changing the binary appearance. The other options either do not alter the binary signature, are easily unpacked, or change only the delivery mechanism rather than the payload's bytes.

Exam trap

The trap here is assuming that packing or splitting a payload changes its signature, when those methods either get unpacked by AV or leave the original bytes intact.

56
MCQmedium

While auditing a web application, you identify an endpoint that retrieves profile images via a URL parameter: 'image.php?file=profile.jpg'. Changing the parameter to 'image.php?file=/etc/passwd' returns the contents of the system password file. Which vulnerability is present, and what is the primary risk?

A.Remote Code Execution via file inclusion.
B.SQL Injection, allowing database schema enumeration.
C.Path Traversal, allowing arbitrary file disclosure.
D.Cross-Site Scripting, allowing session hijacking.
AnswerC

The ability to traverse directories using sequences like '../' or absolute paths allows the application to serve files outside the intended directory. This occurs when user-supplied input is passed directly to file system APIs without sanitization, leading to unauthorized disclosure of sensitive data residing on the underlying server.

Why this answer

This scenario demonstrates Path Traversal, where improper input validation allows access to unauthorized files outside the web root. Exploiting this flaw can lead to sensitive information disclosure, such as configuration files, credentials, or system binaries. It is a critical finding because it grants an attacker arbitrary file read access, which is often the precursor to full system compromise if sensitive keys or database credentials are exposed.

Exam trap

Test-takers frequently misidentify path traversal vulnerabilities as Local File Inclusion execution vulnerabilities, confusing arbitrary file reading with executing server-side code scripts.

57
MCQmedium

An operator is analyzing why a compiled C# stager payload was flagged immediately by Windows Defender despite having a completely unique cryptographic hash. Which AV detection mechanism is most likely responsible for flagging the binary based on internal structure rather than known file signatures?

A.Cloud-based cryptographic hash lookup databases containing global blacklists of known malware samples.
B.Static signature matching using rigid byte sequences extracted from older malware variants.
C.Heuristic analysis evaluating suspicious API imports, section characteristics, and code patterns indicative of stagers.
D.Network signature inspection monitoring incoming HTTP traffic headers for default command and control strings.
AnswerC

Heuristic analysis analyzes the structural makeup of an executable, including imported DLLs like VirtualAlloc and CreateThread. When these suspicious API combinations appear together in an unknown binary, the engine flags it as a potential threat based on risk scoring.

Why this answer

Heuristic and behavioral engines examine internal characteristics, structural layouts, and API import patterns rather than relying strictly on known file hashes. If a binary imports suspicious combinations of memory allocation and execution APIs, heuristics flag it as malicious even if the file has never been seen before.

Exam trap

Many beginners believe that changing a file hash via padding guarantees evasion, ignoring that structural heuristics and API imports are heavily analyzed.

58
MCQmedium

During an internal penetration test, you obtain an NTDS.dit file and the associated SYSTEM registry hive. You need to crack the NTLM password hashes extracted from these files using Hashcat. Which command-line argument correctly specifies the hash type for standard Windows NTLM hashes?

A.hashcat -m 0 -a 0 hashes.txt wordlist.txt
B.hashcat -m 5600 -a 0 hashes.txt wordlist.txt
C.hashcat -m 1000 -a 0 hashes.txt wordlist.txt
D.hashcat -m 3000 -a 0 hashes.txt wordlist.txt
AnswerC

Mode 1000 directs Hashcat to target NTLM hashes, which matches the format of password hashes dumped directly from the Windows NTDS.dit database. Combining this mode with attack mode 0 enables a standard dictionary attack using your specified wordlist against the collected credentials.

Why this answer

Hashcat mode 1000 specifically targets Windows NTLM password hashes extracted from Active Directory or SAM databases. Specifying the correct hash mode is essential because Hashcat uses specialized algorithms and optimization routines tailored to the exact cryptographic structure of each supported hash format during the attack.

Exam trap

Candidates frequently confuse NTLM mode 1000 with NetNTLMv2 challenge-response mode 5600, wasting valuable attack time by supplying the wrong hash algorithm flag to Hashcat.

59
MCQmedium

When using SSH tunneling, what is the primary security risk of using the '-R' flag in a multi-user environment?

A.It exposes the tunnel to all users on the remote server.
B.It forces the remote server to enable password-less login.
C.It requires the remote server to have a GUI installed.
D.It automatically disables logs on the jump host.
AnswerA

By default, ports forwarded with -R bind to the loopback interface on the remote server. However, if the server configuration allows it or if you bind to all interfaces, any user on that server can access the forwarded port, effectively hijacking your pivot for their own network activities or malicious use.

Why this answer

The -R flag binds a port on the remote (attacker/server) machine. If that machine has other users logged in, they can potentially connect to the forwarded port and gain access to the internal network through the tunnel you established. This exposes your pivot to unintended access by other users on the same machine, which is a significant risk in shared lab or production environments.

Exam trap

Students frequently focus only on the functionality of the tunnel, missing the multi-user environment context where bound ports on shared servers expose sensitive entry points to unauthorized local users.

60
MCQhard

Refer to the exhibit. The 'find' binary has the SUID bit set. How can you leverage this to gain a root shell?

A.find . -exec /bin/sh -p \;
B.find . -name "*" -delete
C.find . -exec chmod 777 /etc/shadow \;
D.find / -user web -exec ls -l {}
AnswerA

Using the -exec flag with /bin/sh allows you to spawn a shell. The -p flag is essential for 'sh' to maintain the SUID privilege level instead of dropping it to the user's real UID. This command effectively drops you into a root shell because 'find' is executing as root.

Why this answer

The 'find' command includes an '-exec' flag that allows executing arbitrary commands on the files it locates. When an SUID-bit 'find' binary is used with the '-exec' flag, the command spawned by '-exec' will also run with the SUID owner's privileges. This is a well-documented technique for privilege escalation, demonstrating why SUID binaries must be audited to ensure they do not offer functionality that can be abused for command execution.

Exam trap

Candidates frequently omit the critical '-p' flag when spawning a shell via SUID binaries, causing the shell to drop privileges and preventing root access.

61
MCQmedium

During a PEN-200 lab engagement, a tester delivers a custom C# implant compiled with csc.exe. Windows Defender's real-time protection immediately quarantines the executable at rest on disk, before any process is created. The tester wants to keep the same implant logic but reduce static file-based detection. Which approach best addresses this specific detection stage?

A.Rename the executable to a trusted Windows binary name such as svchost.exe and place it in C:\Windows\System32.
B.Pack the executable with a custom crypter that XOR-encrypts the payload bytes and decrypts them only in memory at runtime.
C.Compress the executable into a password-protected ZIP archive and deliver the archive to the target host.
D.Sign the executable with a self-signed code-signing certificate generated with makecert.exe.
AnswerB

Static on-disk scanning matches byte signatures and PE characteristics before execution. A crypter that XOR-encrypts the original payload bytes and only reconstructs them in memory changes the stored file's byte pattern, so the signature that flagged the plaintext implant no longer matches the file on disk. The implant logic still runs after decryption, satisfying the requirement to preserve behavior while reducing file-based detection.

Why this answer

Detection at rest is driven by static signatures over the file's bytes and PE structure. Changing the stored representation so the original signature no longer matches, while reconstructing the functional payload only in memory, directly defeats that stage. Renaming, self-signing, and archiving leave the underlying executable bytes unchanged, so the same on-disk signature continues to match once the file is written or extracted.

Exam trap

The trap here is assuming that renaming or signing a binary changes what static scanners inspect, when they actually match the file's byte content and PE structure.

62
MCQeasy

When evaluating an antivirus solution's effectiveness, what is the primary difference between signature-based detection and behavioral-based detection?

A.Signatures look for file hashes, while behavior looks for network traffic.
B.Signatures identify known files, while behavior identifies suspicious actions.
C.Signatures are only used for disk scans, while behavior is for memory scans.
D.Behavioral detection is always more accurate and faster than signature-based.
AnswerB

Signature detection compares a file's content against a list of known malware 'fingerprints.' Behavioral detection, on the other hand, monitors the actual operations a program performs while running, such as attempting to inject code into another process or modifying sensitive registry keys, allowing it to catch zero-day threats.

Why this answer

Signature-based detection is a reactive approach that relies on a database of known threats, while behavioral-based detection is a proactive approach that monitors for suspicious actions. Understanding this distinction is crucial for evasion, as bypassing one often requires different techniques than bypassing the other, such as obfuscating file content versus using legitimate system tools for malicious purposes.

Exam trap

Candidates often equate 'behavioral' with 'heuristic'. While related, the core distinction is between static file-based signatures versus runtime activity monitoring of legitimate processes.

63
MCQhard

During an external penetration test, you discover a web server hosting multiple virtual hosts. You want to enumerate additional hostnames that resolve to the same IP address without triggering intrusion detection systems. Which technique is most appropriate?

A.Query public Certificate Transparency logs for certificates issued for the target domain.
B.Send HTTP requests with different Host headers to the web server and analyze responses.
C.Perform a DNS zone transfer (AXFR) against the authoritative name server.
D.Use a reverse DNS sweep of the IP address range to identify PTR records.
AnswerA

Certificate Transparency (CT) logs are public, passive sources that record every SSL/TLS certificate issued by participating CAs. Searching CT logs for the target domain can reveal subdomains and virtual hostnames without sending any traffic to the target. This is a passive reconnaissance technique that does not trigger IDS because you are querying third-party logs, not the target.

Why this answer

Certificate Transparency logs are a passive reconnaissance resource that aggregates certificates issued for domains. By querying these logs, you can discover subdomains and virtual hostnames without interacting with the target. This avoids IDS alerts and is a standard OSINT technique.

The other options involve active scanning or noisy DNS queries that are more likely to be detected.

Exam trap

The trap here is assuming that any enumeration method that does not directly connect to the target is passive, when in fact reverse DNS sweeps and zone transfer attempts still generate traffic that can be logged and flagged.

64
MCQmedium

During an internal penetration test, you have captured network traffic and identified a host that responds on TCP port 445. You want to gather detailed information about the SMB service, including the operating system version, NetBIOS name, and domain, without authenticating. Which Nmap NSE script is most appropriate for this task?

A.smb-vuln-ms17-010
B.smb-brute
C.smb-os-discovery
D.smb-enum-shares
AnswerC

This script attempts to connect to the SMB service and extract the OS version, NetBIOS name, domain, and other details without requiring credentials. It is specifically designed for unauthenticated enumeration of SMB hosts and is part of the default Nmap Scripting Engine library. It is the correct choice for the scenario.

Why this answer

The smb-os-discovery script is designed to query SMB services for host details such as operating system, NetBIOS name, and domain without requiring credentials. Other SMB scripts focus on shares, brute-forcing, or vulnerability checks, which do not provide the required enumeration data. Therefore, smb-os-discovery is the correct tool for this task.

Exam trap

The trap here is confusing SMB enumeration scripts that require authentication with those that can extract host information anonymously.

65
MCQmedium

You have successfully found the exact offset to overwrite the EIP register and identified a reliable JMP ESP instruction inside an unProtected DLL. However, when your shellcode executes, the program immediately crashes with an access violation before launching the payload. Inspection reveals that the stack pointer (ESP) points directly to the beginning of your shellcode, but the memory page housing the stack lacks execution permissions. Which modern defense mechanism is preventing your exploit from succeeding?

A.Data Execution Prevention (DEP) configured as OptOut or OptIn across the operating system environment.
B.Control Flow Guard (CFG) validating indirect call targets against a pre-compiled bitmap of valid function entries.
C.Address Space Randomization relocating the base addresses of operating system libraries dynamically on every reboot.
D.Structured Exception Handling Overwrite Protection guarding exception handler chains from malicious pointer manipulation.
AnswerA

Data Execution Prevention utilizes processor features to enforce non-executable memory pages, stopping shellcode placed directly on the stack from running. Bypassing this defense requires employing Return-Oriented Programming chains to alter memory protections or execute existing code blocks.

Why this answer

Data Execution Prevention marks memory regions such as the stack and heap as non-executable to prevent malicious code from running directly from those locations. When an exploit attempts to jump into shellcode residing on the stack, the CPU generates an access violation because execution permissions are explicitly denied on that memory page.

Exam trap

Candidates often blame bad shellcode or incorrect offsets when an exploit crashes on the stack, missing the fact that DEP prevents execution directly from stack memory.

66
MCQmedium

What is the primary security risk of an application that fails to properly validate the 'Content-Type' header during a file upload process?

A.It allows attackers to perform SQL Injection attacks.
B.It enables an attacker to bypass file type restrictions to upload executable scripts.
C.It prevents the server from storing large files, leading to denial of service.
D.It exposes the server to Cross-Site Request Forgery (CSRF) attacks.
AnswerB

The Content-Type header is easily modified in an intercepting proxy. If the server trusts this header, an attacker can send a PHP script while labeling it as 'image/jpeg'. The server accepts it, potentially allowing the attacker to execute malicious code on the system.

Why this answer

Relying on the 'Content-Type' header is dangerous because it is sent by the client and easily spoofed. If an application uses this header to determine file safety, an attacker can upload malicious scripts disguised as images. This leads to Remote Code Execution (RCE) if the web server executes the uploaded file, making secure file upload handling a critical defense-in-depth practice.

Exam trap

Candidates often believe that checking the Content-Type header is a valid security measure, not realizing it is user-controlled data that can be easily spoofed to bypass upload filters.

67
Multi-Selectmedium

You are performing web enumeration against a target application and want to discover hidden directories, backup files, and administrative interfaces that are not linked from the visible pages. Which two approaches are most appropriate for this goal? (Choose two.)

Select 2 answers
A.Use the search engine operator site:target.com to enumerate internal directories.
B.Inspect the robots.txt and sitemap.xml files for disallowed or listed paths.
C.Run a content discovery tool such as Gobuster or Feroxbuster with a curated wordlist against the web root.
D.Send a single HTTP GET request to the web root and review the returned status code.
E.Perform a full TCP port scan of the web server to reveal application directories.
AnswersB, C

robots.txt frequently lists directories that administrators want excluded from crawlers, which often correlates with sensitive or administrative areas. Sitemap.xml enumerates pages the site owner considers important. Both are publicly accessible and cost almost nothing to retrieve, and they routinely surface paths that are not linked in navigation menus. That makes them a high-value, low-noise source for discovering hidden or restricted areas during enumeration.

Why this answer

Discovering unlinked web content requires either actively probing candidate paths with a wordlist-driven tool or harvesting the metadata files administrators use to guide crawlers. Content discovery tools test many paths and interpret responses, while robots.txt and sitemap.xml often expose restricted or sensitive directories directly. Passive search operators, port scans, and a single root request all fail to reveal paths that are not linked or already indexed.

Exam trap

The trap here is assuming that search engine indexing or a single root request counts as web enumeration, when unlinked content only appears through active path brute forcing or metadata file inspection.

68
MCQmedium

Refer to the exhibit. As an attacker attempting to brute-force a web login, why is receiving this specific error message beneficial to your engagement?

A.It indicates that the account is currently locked and will not accept further attempts.
B.It confirms that the application uses a weak hashing algorithm that ignores complexity.
C.It reveals information that allows you to prune your wordlist to only relevant password candidates.
D.It implies that the application is vulnerable to SQL injection because of poor error handling.
AnswerC

Knowing the exact password policy allows you to filter your wordlists to exclude passwords that would be rejected by the application's validation logic. This optimization significantly speeds up the brute-forcing process by ensuring that every password tested is at least theoretically compliant with the target organization's security policy.

Why this answer

This error message provides actionable intelligence regarding the target's password policy. By confirming the complexity requirements, you can refine your wordlists or mask attacks to target only valid password formats, drastically reducing the search space. This minimizes the time spent on invalid attempts and increases the probability of finding a match.

Understanding how to leverage application feedback is a hallmark of efficient password-based exploitation.

Exam trap

Candidates often ignore verbose web application error messages during brute-force attacks, missing valuable clues regarding password complexity rules that can optimize wordlists.

69
MCQmedium

Refer to the exhibit. The command failed to crack the NTLM hash despite using a comprehensive wordlist. What is the most likely reason for this result?

A.The hash type was incorrectly specified for NTLM.
B.The password is not present in the provided wordlist.
C.The GPU memory limit was exceeded during processing.
D.The hash format is corrupted or invalid.
AnswerB

The 'Exhausted' status explicitly confirms that every entry in wordlist.txt was processed against the loaded hash. Since no match was found, the password is simply not included in the dictionary, necessitating a shift to other techniques like brute-forcing or rule-based mangling to find the cleartext.

Why this answer

The 'Exhausted' status in Hashcat indicates that all candidates in the provided wordlist were tested against the hash, but none resulted in a match. In a penetration test, this suggests that the password complexity exceeds the provided dictionary content. The attacker must now pivot to alternative strategies such as rule-based attacks, mask attacks, or using a more extensive, custom-generated wordlist tailored to the target organization's password policies.

Exam trap

Students mistakenly assume that an exhausted hashcat session means the hash is entirely uncrackable, rather than recognizing the wordlist was simply insufficient.

70
Multi-Selectmedium

You are performing a client-side attack against a target web application that uses a Content Security Policy (CSP) with the directive `script-src 'self'`. Which TWO techniques are most likely to bypass this CSP and execute JavaScript in a victim’s browser? (Choose two.)

Select 2 answers
A.Exploiting a JSONP endpoint on the target domain that reflects a callback parameter into executable JavaScript.
B.Using an open redirect on the target domain to load a script from an external domain.
C.Using a data: URI in a script tag to embed the JavaScript payload.
D.Hosting a malicious JavaScript file on the target’s own domain via an upload feature, then loading it with a script tag.
E.Injecting an inline script tag with the payload directly into the HTML.
AnswersA, D

A JSONP endpoint on the same origin returns JavaScript that calls a user-supplied callback. Because the script is served from the target origin, script-src 'self' permits it. The attacker can craft a callback that executes arbitrary code, effectively using the trusted origin to bypass the CSP. This is a classic same-origin script gadget.

Why this answer

A CSP with script-src 'self' trusts scripts loaded from the target’s own origin. Therefore, an attacker who can host or reflect JavaScript on that origin bypasses the policy. Uploading a JavaScript file and loading it via a script tag, or abusing a same-origin JSONP endpoint, both result in script execution from a trusted origin.

External scripts, inline scripts, and data URIs are blocked because they do not match 'self'.

Exam trap

The trap here is assuming that any script delivery technique bypasses CSP, when only those that result in a same-origin script source are permitted by script-src 'self'.

71
MCQeasy

Which file is essential for auditing to determine which users have been granted sudo privileges?

A./etc/passwd
B./etc/sudoers
C./etc/shadow
D./etc/group
AnswerB

The /etc/sudoers file is the definitive source for sudo permissions. It lists all users and groups that have been granted sudo rights and specifies the exact scope of those rights. This file is the primary target for auditing privilege assignments on any Linux system.

Why this answer

The /etc/sudoers file is the configuration file that controls sudo access. It defines exactly which users or groups can execute commands with elevated privileges and under what conditions. Auditing this file is the standard way to identify misconfigurations that could allow a low-privileged user to gain root access.

Understanding its syntax is vital for any security professional to accurately identify and remediate potential privilege escalation paths in a Linux environment.

Exam trap

Candidates often waste time looking into generic system logs or password files instead of targeting the definitive configuration file that dictates sudo access policies.

72
MCQhard

During an internal assessment you receive a scope that lists a /24 subnet but explicitly forbids any traffic that could cause service disruption. You need to identify live hosts and open TCP ports while keeping the scan as quiet and non-intrusive as possible. Which single Nmap invocation best matches these constraints?

A.nmap -sS -T2 --top-ports 100 10.10.10.0/24
B.nmap -sS -T4 -p- 10.10.10.0/24
C.nmap -sn 10.10.10.0/24
D.nmap -sU -T4 --min-rate 5000 10.10.10.0/24
AnswerA

A half-open SYN scan with -T2 timing and only the most common 100 ports balances coverage and stealth. SYN scanning never completes the TCP handshake, reducing load on target services, while -T2 slows packet delivery to avoid overwhelming hosts or triggering rate-based alarms. Limiting to top ports keeps the footprint small, which directly satisfies the non-disruptive requirement while still identifying live hosts and their common open TCP ports.

Why this answer

Balancing reconnaissance depth against a no-disruption clause requires a scan that avoids full TCP connections, throttles its own packet rate, and limits the port set. A half-open SYN scan with conservative timing and a small top-ports list achieves host discovery plus meaningful TCP port enumeration without stressing services. Full-range or high-rate scans and UDP sweeps either overload targets or answer a different question than the one asked.

Exam trap

The trap here is assuming that any SYN scan is automatically stealthy, when timing templates and port range determine how disruptive the scan actually is.

73
MCQhard

You are testing a Java web application that stores user-supplied SVG avatars. The application sanitizes SVG files by stripping `<script>` tags, then serves them from the same origin with `Content-Type: image/svg+xml`. When a victim views another user's profile, the browser renders the SVG inline. Which technique most reliably achieves script execution in the victim's session despite the sanitizer?

A.Use the SVG `<animate>` element with an `onbegin` event handler that calls `alert(document.domain)` when the animation starts.
B.Encode `<script>` as `<scr&#x69;pt>` so the sanitizer's regex fails to match the tag but the browser still parses it as script.
C.Embed a JavaScript URL in an SVG `<a xlink:href="javascript:alert(document.domain)">` element that the victim must click.
D.Insert an external `<image href="https://attacker.example/evil.svg">` reference that loads a second SVG containing the payload.
AnswerA

SVG supports SMIL animation elements such as `<animate>` and `<set>`, which fire `onbegin` and `onend` events as soon as the document renders. Because the sanitizer only strips `<script>` tags, this event-handler vector survives and executes automatically when the victim views the profile, achieving same-origin script execution without interaction. This is a well-known SVG XSS bypass.

Why this answer

SVG is an XML format that supports SMIL animation and event attributes, so stripping only `<script>` leaves a large attack surface. Event handlers like `onbegin` on `<animate>` or `<set>` fire during rendering, executing attacker JavaScript in the victim's session on the same origin. This bypasses naive blacklist sanitizers that focus solely on script tags.

Exam trap

The trap here is believing that removing `<script>` tags neutralizes SVG, when SMIL animation event handlers execute JavaScript without any script element.

74
MCQhard

When performing reconnaissance on an unknown network, you discover a service running on port 161. What is the most appropriate action to take to determine if this service can be abused?

A.Attempt a brute-force attack on the SSH service.
B.Use snmpwalk to attempt to retrieve data using default community strings.
C.Run a full Nmap script scan for all protocols.
D.Ignore the port as it is rarely used for anything critical.
AnswerB

Snmpwalk is the standard tool for querying SNMP agents. Testing common default community strings is the industry-standard initial step for enumerating SNMP. If the agent responds, it reveals a wealth of information about the target's configuration, which is essential for informed decision-making during the subsequent stages of testing.

Why this answer

Port 161 is the default port for SNMP (Simple Network Management Protocol). Often, SNMP is misconfigured with default community strings like 'public' or 'private'. By testing these strings, a tester can potentially retrieve sensitive system information such as running processes, network interfaces, and even user accounts.

This is a classic, high-value enumeration target that frequently yields significant information for further lateral movement or privilege escalation within the network environment.

Exam trap

Candidates often suggest port scanning or full vulnerability scans. The most effective first step for SNMP is using specific enumeration tools like snmpwalk to test default community strings for information.

75
MCQmedium

An ethical hacker wants to evade signature-based detection while developing a custom reverse shell loader for a PEN-200 lab assignment. Which technique fundamentally alters the binary's byte signatures without modifying its core execution logic or breaking the payload?

A.Stripping all debugging symbols and symbol tables from the executable using strip.
B.Modifying the file extension from .exe to .scr to trick the operating system shell.
C.Applying XOR encoding to the payload buffer and implementing a custom runtime stub to decrypt it in memory.
D.Compressing the final executable binary using standard ZIP archiving utilities without a password.
AnswerC

XOR encoding modifies every byte of the payload based on a key, entirely changing the static file hashes and byte signatures. A custom runtime stub allocates memory, decrypts the payload on the fly, and executes it without ever writing the cleartext binary back to disk.

Why this answer

Encoding or encrypting the payload alters static byte signatures that antivirus engines use to flag known malicious files. By decoding the payload dynamically in memory at runtime, the payload remains obfuscated on disk, preventing signature detection while preserving the exact execution logic required for the reverse shell to successfully connect back to the attacking machine.

Exam trap

Candidates often confuse static encryption with process injection, assuming that hiding the payload on disk automatically bypasses behavioral monitoring during runtime execution.

Page 1 of 4

Page 2

All pages