Courseiva

OffSec PEN-200 / OSCP Concepts (PEN-200) — Questions 151–225

285 questions total · 4pages · All types, answers revealed

Page 2

Page 3 of 4

Page 4
151
MCQeasy

Refer to the exhibit. Given the sudo privileges, which command will successfully spawn a root shell?

A.sudo /usr/bin/vim -c ':!/bin/sh'
B.sudo /usr/bin/vim /etc/shadow
C.sudo /usr/bin/vim --version
D.sudo /usr/bin/vim -u NONE
AnswerA

The -c command flag executes a command immediately upon vim startup. By invoking :!/bin/sh, the user forces vim to spawn a system shell. Because vim is running with sudo privileges, the spawned shell inherits root permissions, effectively escalating the user's access level to the highest possible on the system.

Why this answer

The exhibit shows that the user can run 'vim' as root without a password. Since vim has a built-in shell execution feature, an attacker can escape the editor to a root-privileged command prompt. This is a classic example of misconfigured sudo rights, where allowing full access to a versatile utility that supports command execution effectively grants the user complete control over the system.

Exam trap

Candidates often try to execute vim normally or forget the critical syntax required to pass commands via flags, failing to utilize the built-in escape sequences needed to spawn a root shell.

152
MCQmedium

During a PEN-200 lab engagement, you obtain a low-privileged shell on a Windows machine and discover an unquoted service path containing spaces in its directory name. The service runs as Local System, but the parent folder has overly permissive discretionary access control lists granting standard users Full Control. How should you exploit this misconfiguration to escalate your privileges?

A.Modify the Windows Registry ImagePath entry directly using standard user credentials to append your custom payload path.
B.Replace the existing service executable file directly inside the protected system folder to hijack execution upon the next reboot.
C.Upload your malicious executable to the vulnerable intermediate directory using the exact intermediate folder name expected by the path parser.
D.Send a malformed buffer overflow payload directly to the service network port to achieve remote code execution as Local System.
AnswerC

Overly permissive DACLs on the parent folder allow standard users to create a malicious executable that matches the first space-separated token of the path. When the service starts, Windows executes this malicious binary instead of the intended program because quotes are missing.

Why this answer

Placing a malicious executable with a name matching the fragmented path segment allows you to hijack the service binary resolution process when the service restarts. Windows searches for spaces sequentially from left to right, executing your payload with Local System privileges. This technique is a fundamental Windows privilege escalation vector taught in the PEN-200 curriculum.

Exam trap

Candidates often try to replace the original service executable. However, the exploit relies on creating a new, malicious executable that matches the fragmented path segment to hijack the resolution process.

153
Multi-Selecthard

A penetration tester needs to deliver a Meterpreter payload to a Windows target protected by an EDR that performs both static file scanning and behavioral monitoring of process creation. The tester wants to reduce the chance of detection during initial execution while still obtaining a session. Which two techniques most directly reduce detection in this combined scenario? (Choose two.)

Select 2 answers
A.Disable Windows Defender real-time protection by modifying the registry before executing the payload.
B.Rename the payload executable to svchost.exe and place it in the user's temp directory.
C.Spawn the payload by injecting into a legitimate, already-running process such as explorer.exe rather than starting a new process.
D.Compress the payload with UPX and deliver it as a self-extracting archive.
E.Use a custom loader that stores the shellcode encrypted and decrypts it into memory only at runtime.
AnswersC, E

EDR behavioral monitoring often flags the creation of a new, unsigned process that immediately performs suspicious actions. Injecting into an existing trusted process like explorer.exe avoids a new process creation event and places the malicious code inside a process the EDR considers benign. This directly addresses the behavioral monitoring component described in the scenario.

Why this answer

The scenario involves two distinct controls: static file scanning and behavioral process monitoring. A custom loader with encrypted shellcode removes recognizable bytes from disk, defeating static signatures. Injecting into an existing trusted process avoids the new-process creation event that behavioral engines monitor, placing execution inside a process already deemed legitimate.

Together these address both controls. Renaming, UPX packing, and registry tampering either leave the static bytes intact or generate their own high-signal events.

Exam trap

The trap here is treating static obfuscation and behavioral evasion as interchangeable, when the scenario explicitly includes both controls and requires a technique that addresses each one separately.

154
MCQmedium

You find that a binary relies on a relative path to execute a secondary script. If you cannot modify the PATH variable, what is the best alternative to exploit this configuration?

A.Modify the binary's ELF header to change the search path.
B.Create the expected directory structure in a location you control and execute the binary from there.
C.Use the 'ptrace' system call to attach to the binary and change its execution flow.
D.Inject environment variables like 'LD_LIBRARY_PATH' to overwrite the binary's functionality.
AnswerB

If the binary expects to find a script in a relative path like './scripts/run.sh', you can create a directory named 'scripts' in your current location and place a malicious 'run.sh' inside. When the binary runs, it will find and execute your script, inheriting the binary's SUID privileges.

Why this answer

If PATH modification is not possible, you can utilize symlinks or directory traversal to manipulate the binary's search logic. By creating a directory structure that mimics the expected relative path, you can place a malicious executable where the binary expects the legitimate one. This is effective because it exploits the binary's reliance on current working directory context, bypassing strict system-wide path settings entirely.

Exam trap

Test-takers frequently assume they can simply modify the system PATH variable even when they lack the necessary administrative write permissions, leading them down a dead end.

155
MCQmedium

Refer to the exhibit. What can you conclude about the security of this service binary?

A.The service is vulnerable to a DLL hijacking attack.
B.The binary can be replaced by any local user to achieve privilege escalation.
C.The service is secure because only SYSTEM and Administrators have full access.
D.The service cannot be stopped by a standard user.
AnswerB

The '(M)' permission granted to BUILTIN\Users allows any standard user to write to, modify, or delete the file. By replacing the service executable with a malicious payload, the user can ensure that the next time the service starts, the malicious code executes with SYSTEM privileges.

Why this answer

The icacls output shows that 'BUILTIN\Users' has '(M)' or Modify permissions on the binary. This means a low-privileged user can replace the legitimate service executable with a malicious one. Because services run as SYSTEM, replacing this file allows for immediate privilege escalation upon the next service restart.

This is a common misconfiguration where excessive folder or file permissions enable attackers to gain total control over the host.

Exam trap

Candidates mistakenly believe that Read permissions are sufficient to compromise a binary, overlooking the requirement for Modify or Write access to replace the file.

156
MCQmedium

Why is it important to use a local listener that matches the protocol expected by your exploit's payload?

A.It makes the exploit run significantly faster.
B.It prevents the firewall from blocking your connection.
C.It ensures the connection is successfully captured.
D.It automatically bypasses target authentication.
AnswerC

Matching the listener protocol to the payload is mandatory for a successful reverse shell. If the exploit expects to send data via TCP and your listener is configured differently, the handshake will fail. This is a common point of failure for beginners during their first few attempts.

Why this answer

If your exploit sends a reverse shell, the listener must be configured to accept the specific connection type (e.g., TCP or UDP) and handle the payload correctly. A mismatch—such as trying to catch a TCP reverse shell on a UDP listener—will result in the connection failing to establish. Proper alignment between the exploit's payload and your listener is the cornerstone of successful, stable remote command execution.

Exam trap

Candidates often forget to check the listener protocol. A common mistake is setting up a standard Netcat listener for a payload that requires a specific handler or different connection type.

157
Multi-Selecthard

You are testing a web application that uses a MySQL database. You suspect a UNION-based SQL injection in the 'id' parameter of a product page. The page displays product names and descriptions. Which two steps are necessary to successfully extract data using a UNION attack? (Choose two.)

Select 2 answers
A.Determine the number of columns in the original query using ORDER BY or UNION SELECT.
B.Ensure the database user has FILE privileges to read data from the filesystem.
C.Identify which columns are displayed on the page by injecting unique strings into each column.
D.Use a time-based injection to confirm the vulnerability before attempting UNION.
E.Encode the payload using base64 to bypass web application firewalls.
AnswersA, C

To perform a UNION attack, the number of columns in the injected query must match the original query. Using ORDER BY with increasing column numbers or injecting UNION SELECT with NULLs helps determine the column count. Without this, the database returns an error, and the injection fails. This step is fundamental to crafting a valid UNION statement that aligns with the original query's structure.

Why this answer

A successful UNION-based SQL injection requires matching the number of columns in the original query and identifying which columns are reflected in the response. These steps allow the attacker to craft a UNION SELECT that returns data in visible fields. Other techniques like time-based injection or file privileges are unrelated to UNION extraction and are not necessary for this scenario.

Exam trap

The trap here is thinking that time-based injection is always needed to confirm SQL injection, when UNION attacks rely on direct output and can be tested by observing changes in the page.

158
MCQmedium

Refer to the exhibit. [!] Error compiling payload: Function 'VirtualAlloc' not found in target assembly scope. An operator is writing a custom process injection loader in C# and encounters the compilation error shown above while attempting to allocate memory for shellcode. How should the operator properly resolve this issue to enable low-level memory allocation?

A.Replace VirtualAlloc with the standard .NET File.ReadAllBytes method to read the shellcode into a byte array.
B.Enable unsafe code blocks in the project settings and use raw C-style pointer arithmetic directly.
C.Import the unmanaged function from kernel32.dll using Platform Invoke (P/Invoke) declarations.
D.Compile the C# application as a 64-bit exclusive binary to match the target operating system architecture.
AnswerC

Importing VirtualAlloc from kernel32.dll via P/Invoke declarations supplies the missing unmanaged Win32 API that the .NET runtime cannot expose natively, resolving the compile error. This satisfies the stem's requirement for low-level memory allocation, since managed C# has no built-in equivalent for reserving executable pages.

Why this answer

Managed languages like C# do not natively expose low-level Windows API functions like VirtualAlloc without explicit interoperability declarations. Utilizing Platform Invoke allows developers to import unmanaged DLL functions from kernel32.dll, bridging the gap between managed code execution and low-level memory manipulation required for advanced payload execution.

Exam trap

Candidates often assume managed C# code can natively call native Win32 APIs like VirtualAlloc directly without realizing that low-level memory allocation requires explicit unmanaged interoperability declarations via P/Invoke.

159
MCQhard

You are reviewing a public exploit for a Linux-based web application. The exploit is a Python script that uses a hardcoded offset to overwrite a return address, and it includes a comment stating it was tested on a specific kernel version. Your target runs a different kernel but the same application version. After running the exploit, the service crashes but no shell is obtained. Which action is the MOST appropriate next step?

A.Recompile the target's kernel to match the version the exploit was tested on.
B.Modify the exploit's offset to match the target's kernel by debugging the crash and calculating the correct offset.
C.Search for a different public exploit that targets the same application version but is written in a different language.
D.Assume the exploit is unreliable and discard it, then attempt to exploit a different service on the target.
AnswerB

The crash indicates the exploit reached the vulnerable code but the return address was incorrect for this kernel. Debugging the crash (e.g., with a core dump or attaching a debugger) lets you determine the actual offset to the return address. Replacing the hardcoded offset with the correct one for the target kernel is the precise fix, rather than abandoning the exploit.

Why this answer

A crash with no shell typically means the offset to the return address is wrong for the target's memory layout. Debugging the crash to find the correct offset and updating the exploit is the precise, minimal fix. This preserves the working parts of the exploit and directly addresses the kernel-dependent difference.

Exam trap

The trap here is assuming a kernel mismatch makes the exploit unusable, when in fact it often just requires recalculating the offset after debugging the crash.

160
Multi-Selectmedium

Which TWO techniques are primarily used to bypass static signature-based detection by altering the file's binary appearance without changing its underlying functionality?

Select 2 answers
A.Binary Packing
B.Process Hollowing
C.Payload Encryption
D.Direct System Calls
E.Token Manipulation
AnswersA, C

Packing involves using a tool to compress and wrap the original executable within a new outer layer. When the file is scanned on disk, the antivirus only sees the packer's code rather than the malicious payload. At runtime, the packer decompress the original code into memory, effectively hiding the malware from static analysis.

Why this answer

Static evasion focuses on changing the 'look' of the file to bypass signature databases. Packing compresses the executable and adds a wrapper that unpacks it in memory, while encryption hides the payload entirely until runtime. Both techniques drastically change the file's hash and byte sequence, making it unrecognizable to scanners that rely on matching known malicious code patterns on disk.

Exam trap

Candidates often confuse static evasion with dynamic evasion, focusing on changing code behavior rather than altering the binary's appearance to bypass the signature-based detection databases used by antivirus software.

161
MCQmedium

You are conducting a password spraying attack against an Active Directory environment. You have a list of common passwords and a list of usernames. To avoid locking out accounts, which approach should you take?

A.Try all passwords against one username before moving to the next username.
B.Use a tool like Hydra to perform a dictionary attack with a high thread count to speed up the process.
C.Spray each password against a small subset of usernames, then rotate to another subset without waiting.
D.Spray one password against all usernames, then wait 30 minutes before trying the next password.
AnswerD

Password spraying involves trying a single password against many accounts to avoid lockouts. Waiting between attempts (e.g., 30 minutes) ensures that the account lockout threshold is not triggered, as most lockout policies count failed attempts within a time window. This approach balances efficiency and stealth, directly addressing the scenario's goal of avoiding lockouts while testing common passwords.

Why this answer

Password spraying avoids lockouts by trying a single password against many accounts, then waiting before the next password. This keeps the number of failed attempts per account below the lockout threshold within the observation window. Trying all passwords against one account or using high concurrency increases lockout risk.

Rotating subsets without waiting can also accumulate attempts. Thus, spraying one password at a time with a delay is the correct approach.

Exam trap

The trap here is confusing password spraying with brute-forcing, leading to techniques that concentrate attempts on few accounts and trigger lockouts.

162
MCQhard

You have a low-privileged shell on a Linux host. You discover a cron job that runs every minute as root and executes a script located at /opt/backup/backup.sh. The script is world-writable. However, you also notice that the directory /opt/backup is owned by root and has permissions 755. Which of the following is the MOST reliable way to escalate privileges?

A.Replace the backup.sh script with a symbolic link to a file you control.
B.Modify the script to add a new user with UID 0 to /etc/passwd.
C.Use the `crontab` command to edit the root user's crontab and add a new job.
D.Overwrite the backup.sh script with a reverse shell payload.
AnswerD

The script is world-writable, meaning any user can modify its contents. Since the cron job runs as root, overwriting the script with a payload that creates a SUID root shell or connects back to your listener will execute with root privileges. The directory permissions do not prevent modifying the file's contents because the file itself is world-writable. This is a direct and reliable escalation.

Why this answer

The script is world-writable, so you can modify its contents directly. Because the cron job executes it as root, any commands you insert will run with root privileges. A reverse shell payload is a common and effective method.

The directory permissions prevent replacing the file or creating symlinks, but do not prevent editing the file's contents. Therefore, overwriting the script is the most reliable approach.

Exam trap

The trap here is focusing on the directory permissions and assuming you cannot modify the script, when in fact the file itself is writable and that is sufficient to inject commands.

163
MCQhard

Refer to the exhibit. ```http HTTP/1.1 200 OK Server: nginx Content-Type: text/html; charset=UTF-8 Content-Security-Policy: default-src 'self'; script-src 'self' 'unsafe-inline' <html> <body> <h1>Welcome</h1> <script>var token = '12345';</script> </body> </html> ``` Based on the HTTP response headers and body shown in the exhibit, what significant security risk is present regarding client-side attacks?

A.The application is completely immune to Cross-Site Scripting because a Content Security Policy is strictly enforced
B.The 'unsafe-inline' directive permits the execution of inline scripts, undermining CSP protections against Cross-Site Scripting
C.The server is vulnerable to remote code execution because the nginx version header is explicitly exposed
D.The session token is vulnerable to interception because the response is transmitted over unencrypted HTTP
AnswerB

The script-src directive includes 'unsafe-inline', so the browser executes the inline <script> block defining the token. This nullifies CSP's core defence against injected inline scripts, allowing an attacker who achieves HTML injection to run arbitrary JavaScript despite the policy being present.

Why this answer

The inclusion of the 'unsafe-inline' directive in the Content Security Policy script-src allows the browser to execute inline script blocks present in the HTML. This configuration largely defeats the protective benefits of a CSP against Cross-Site Scripting, as attackers who can inject inline scripts will achieve execution.

Exam trap

Candidates often misinterpret CSP headers by assuming that any CSP policy is secure. They overlook the specific 'unsafe-inline' directive, which explicitly allows the very vulnerability the CSP is intended to prevent.

164
MCQhard

During a penetration test, you have gained access to a workstation and extracted a Kerberos TGT for a domain user. You want to use this ticket to access a file share on another server without knowing the user's password. Which technique should you employ?

A.Silver Ticket by forging a service ticket for the file share using the service account's hash.
B.Pass-the-Ticket by injecting the TGT into the current session using Mimikatz's kerberos::ptt command.
C.Golden Ticket by forging a TGT using the KRBTGT hash to impersonate any user.
D.Overpass-the-Hash by using the TGT's associated NTLM hash to request a new TGT.
AnswerB

Pass-the-Ticket with Mimikatz's kerberos::ptt injects the extracted TGT into the current logon session, allowing the attacker to impersonate the user for Kerberos authentication. This enables access to network resources like file shares without knowing the password. It is the standard method for leveraging stolen Kerberos tickets in Active Directory environments.

Why this answer

Pass-the-Ticket with Mimikatz's kerberos::ptt injects the stolen TGT into the current session, allowing Kerberos authentication as the user. This grants access to network resources such as file shares without needing the password. It is the appropriate technique when a TGT is already available and the goal is to use it for lateral movement.

Exam trap

The trap here is confusing Pass-the-Ticket with other Kerberos attacks like Overpass-the-Hash or Golden Ticket, which require different prerequisites such as hashes or elevated privileges.

165
MCQmedium

You are exploiting a 32-bit Windows FTP server that uses a fixed-size stack buffer and a vulnerable call to strcpy. After overwriting EIP with a JMP ESP address, you notice that your shellcode executes but the connection drops immediately without a shell. You suspect bad characters corrupted the payload. Which method is most effective for identifying all bad characters in this scenario?

A.Run a strings command on the vulnerable binary to list all characters that appear in the code.
B.Send a byte array from 0x00 to 0xFF and inspect the stack in a debugger to see which bytes are truncated or altered.
C.Encode your shellcode with shikata_ga_nai and assume any remaining corruption is due to the encoder.
D.Use a disassembler to check whether the binary contains any null bytes in its machine code.
AnswerB

Sending the full byte range and examining memory after the crash reveals exactly which bytes are removed, terminated, or transformed by the vulnerable function. For example, a null byte may truncate a string copy, and a newline may terminate input. This empirical approach is the standard method taught in PEN-200 for mapping bad characters before finalizing shellcode.

Why this answer

Sending the full 0x00-0xFF byte range and inspecting stack memory in a debugger is the definitive way to identify bad characters. It shows which bytes are truncated or transformed by the vulnerable function. Static analysis and encoding do not replace this dynamic test.

This step must precede shellcode generation to ensure payload integrity.

Exam trap

The trap here is assuming that encoding shellcode will fix corruption caused by bad characters, when the encoder itself may produce bytes that the vulnerable function rejects.

166
MCQmedium

You are performing a client-side phishing engagement and need to deliver a malicious payload using an ISO image file. Why is this delivery method often effective against modern Windows security warnings?

A.ISO files automatically disable Windows Defender Antivirus real-time protection upon mounting
B.Windows natively mounts ISO files without requiring external software, and extracted payloads can evade certain Mark of the Web propagation behaviors
C.ISO files encrypt all internal payload binaries, rendering static signature analysis completely impossible
D.Mark of the Web attributes are permanently stripped from all files stored within virtual disk containers
AnswerB

Operating system native support for mounting disk images allows users to open ISO files easily. Depending on how files are copied out of the ISO, the Mark of the Web security identifier may not propagate as reliably as it does with direct browser downloads.

Why this answer

ISO image files can be mounted natively by Windows without third-party software, and files contained within the ISO often inherit a lower severity of Mark of the Web restrictions when extracted or executed, helping bypass certain SmartScreen prompts compared to direct web downloads.

167
Multi-Selecthard

When evaluating antivirus evasion techniques for Windows targets in a penetration test, which TWO of the following approaches specifically target memory-based detection mechanisms rather than static disk signatures? (Choose TWO)

Select 2 answers
A.Direct system calls invoked via assembly instructions to bypass user-mode hooks placed by security software in ntdll.dll.
B.Applying a multi-layer XOR encoder to obfuscate the binary payload before writing the executable to the target hard drive.
C.Process injection into a legitimate native Windows process such as explorer.exe to mask malicious execution threads.
D.Modifying the compilation timestamp within the portable executable header to confuse static signature heuristics.
E.Compressing the compiled binary with UPX to scramble sections and alter the import address table layout.
AnswersA, C

Security solutions place inline hooks within user-mode DLLs like ntdll.dll to monitor API calls. Implementing direct system calls bypasses these hooked functions entirely, allowing the payload to interact directly with the kernel without triggering user-mode security monitoring alerts.

Why this answer

Memory-based evasion techniques focus on how payloads behave in RAM and interact with operating system APIs. Syscall manipulation avoids hooked functions in ntdll.dll, while process injection executes code within legitimate, trusted processes to blend in with normal system activity and avoid heuristic flags.

Exam trap

Students frequently select static packing or XOR encoding, forgetting that those techniques only apply to files stored on the filesystem and offer zero protection once the process starts running.

168
MCQmedium

You are developing an exploit for a Windows 32-bit application with a stack buffer overflow. You have identified a JMP ESP instruction at a static address. However, the application uses SafeSEH. Which statement is true regarding the use of JMP ESP in this scenario?

A.SafeSEH encrypts the JMP ESP instruction, making it unusable.
B.You must use a POP POP RET sequence instead of JMP ESP to bypass SafeSEH.
C.JMP ESP will not work because SafeSEH validates all addresses on the stack, including the return address.
D.JMP ESP can still be used if the address is in a module not compiled with SafeSEH.
AnswerD

This is correct because SafeSEH only protects exception handlers, not the return address overwrite. If you can overwrite the return address and redirect to a JMP ESP in a module without SafeSEH (or with SafeSEH disabled), you can still execute your shellcode. SafeSEH does not prevent stack overflow exploitation via return address overwrite.

Why this answer

SafeSEH is a mitigation for SEH overwrites, not for return address overwrites. If you are overwriting the saved return address, you can still use a JMP ESP gadget from a module that is not SafeSEH-protected. The presence of SafeSEH does not prevent this technique, as it only validates exception handlers when an exception occurs.

Exam trap

The trap here is conflating SafeSEH with return address protection; SafeSEH only affects exception handler exploitation, not standard stack overflows.

169
MCQmedium

During a stack-based buffer overflow exploit development exercise against a custom Windows application, an OSCP student successfully overwrites the instruction pointer (EIP) with the address of a JMP ESP instruction. However, upon triggering the vulnerability, the application immediately crashes with an access violation before executing the shellcode located directly after the return address. Which of the following is the most likely root cause of this execution failure?

A.The bad characters array contained null bytes that truncated the shellcode payload before it could reach the return address offset.
B.The stack pointer (ESP) was offset too far forward, causing the processor to execute NOP sled instructions instead of the first shellcode instruction.
C.Data Execution Prevention (DEP) is enabled on the target application, blocking CPU execution instructions from the non-executable stack memory region.
D.The chosen JMP ESP instruction address contained little-endian byte ordering that corrupted the stack frame alignment during the return operation.
AnswerC

Hardware-enforced Data Execution Prevention flags stack memory segments as non-executable data pages. When the CPU attempts to fetch and execute instructions located at the stack address pointed to by ESP, it triggers an access violation exception.

Why this answer

An access violation directly following an EIP overwrite usually indicates that the target memory address pointed to by ESP is non-executable due to Data Execution Prevention (DEP). Even though control flow successfully transfers via JMP ESP, modern operating systems enforce hardware-level NX/DEP protections, preventing shellcode execution on the stack unless bypassed through Return-Oriented Programming or valid OS API functions.

Exam trap

Students frequently assume that successfully redirecting EIP guarantees shellcode execution, completely forgetting that modern Windows systems enforce DEP by default, rendering stack memory non-executable unless explicitly bypassed.

170
MCQeasy

You are conducting a penetration test and need to identify the operating system of a target host without sending any packets to it. Which of the following methods is most appropriate?

A.Reviewing publicly available information such as job postings or technology stack details on the company's website.
B.Analyzing the Time-to-Live (TTL) values from a ping response.
C.Using Nmap's OS detection (-O) against the target IP address.
D.Performing a banner grab by connecting to open ports like 22 or 80.
AnswerA

Reviewing publicly available information is a passive reconnaissance technique that does not involve any direct interaction with the target. Job postings might mention specific operating systems or technologies, and the website's technology stack can be inferred from headers or public profiles. This meets the requirement of sending no packets to the target.

Why this answer

Passive reconnaissance involves gathering information without directly interacting with the target. Reviewing public sources like job postings and website technology stacks can reveal the operating system without sending any packets. Active methods such as TTL analysis, Nmap OS detection, and banner grabbing all require sending packets to the target, violating the constraint.

Exam trap

The trap here is assuming that analyzing TTL values is passive because it uses ping responses, but it still requires sending packets to the target.

171
MCQhard

During exploitation of a stack-based buffer overflow on a 32-bit Windows application, you overwrite EIP with the address of a JMP ESP instruction, but the shellcode does not execute. You verify the JMP ESP address is correct and that the shellcode is in memory. Which of the following is the most likely cause?

A.The JMP ESP instruction address contains a null byte, which prevents it from being written correctly to EIP.
B.The shellcode contains null bytes, which terminate the string copy and prevent the full shellcode from being placed on the stack.
C.The shellcode is encoded, and the decoder stub is missing, so it cannot execute.
D.The JMP ESP instruction is located in a memory region with the DEP (Data Execution Prevention) flag set.
AnswerB

If the vulnerable function uses a string copy function like strcpy, null bytes in the shellcode will terminate the copy, truncating the shellcode. Even if the JMP ESP is correct, the shellcode on the stack may be incomplete, leading to failed execution. This is a common issue in Windows exploits, as many shellcodes contain null bytes. The scenario notes that shellcode is in memory, but it might be truncated. Thus, null bytes are a likely culprit.

Why this answer

Null bytes in shellcode are a frequent problem when exploiting buffer overflows in string-based functions. Functions like strcpy or sprintf treat null bytes as string terminators, so any null byte in the shellcode will cause the copy to stop prematurely. As a result, the shellcode on the stack will be incomplete, and even with a correct JMP ESP, execution will fail.

Therefore, ensuring shellcode is free of null bytes or properly encoded is essential. This is a common pitfall in Windows exploit development.

Exam trap

The trap here is overlooking the impact of null bytes in shellcode when using string copy functions, assuming that if the shellcode is in memory it must be intact.

172
MCQeasy

You are using Proxychains to route your Nmap scan through a SOCKS proxy. Which configuration file must you modify to ensure that the proxy settings are correctly applied during your scan?

A./etc/nmap/nmap.conf
B./etc/proxychains.conf
C./etc/ssh/ssh_config
D./etc/network/interfaces
AnswerB

This is the default configuration file for Proxychains. It defines the proxy servers, the chain type, and other operational parameters. Editing this file to add your SOCKS proxy entry at the bottom is the standard procedure to enable Proxychains to successfully route traffic through your established pivot tunnel.

Why this answer

Proxychains relies on a configuration file to determine which proxy servers to use for traffic redirection. Misconfiguring this file is a common pitfall that leads to scans either failing or leaking traffic directly from your machine. Correctly setting the proxy type, IP address, and port ensures that all traffic generated by the tools you prefix with proxychains is routed through the specified tunnel, maintaining your stealth and reachability.

Exam trap

Candidates often waste time searching for dynamic command-line flags to set proxy details, forgetting that Proxychains relies entirely on editing a static local configuration file.

173
MCQeasy

While testing a web application, you find that the login form is vulnerable to SQL injection. You input the username 'admin'-- and a blank password. The application logs you in as admin without validating the password. Which type of SQL injection attack is this?

A.Authentication bypass via SQL injection
B.Error-based SQL injection
C.Blind SQL injection
D.Union-based SQL injection
AnswerA

The payload 'admin'-- comments out the rest of the SQL query, effectively removing the password check. This allows the attacker to log in as admin without knowing the password. This is a classic authentication bypass using SQL injection. It does not require data extraction or error messages, and the result is immediate access, making this the correct categorization.

Why this answer

The attack uses a comment sequence (--) to truncate the SQL query, eliminating the password validation. This directly bypasses authentication, granting access as the admin user. Union-based, error-based, and blind SQL injection are different techniques used for data extraction or inference, not for simple authentication bypass.

Thus, authentication bypass via SQL injection is the correct answer.

Exam trap

The trap here is overcomplicating the scenario and assuming that any SQL injection must involve data extraction, when in fact authentication bypass is a distinct and common goal.

174
MCQmedium

You have compromised a domain user account and want to escalate privileges by abusing a misconfigured Group Policy Object (GPO). You discover that the GPO is linked to an Organizational Unit (OU) containing privileged servers and that the domain user has write permissions on the GPO. Which action should you take to escalate privileges?

A.Use the compromised user to add themselves to the Domain Admins group directly via LDAP modification.
B.Configure a new GPO to deploy a startup script that disables antivirus on all servers in the OU.
C.Extract the KRBTGT hash using DCSync and forge a Golden Ticket to gain domain admin access.
D.Modify the GPO to add a new immediate scheduled task that runs a reverse shell as SYSTEM on all computers in the OU.
AnswerD

If a user has write permissions on a GPO linked to an OU with privileged servers, they can modify the GPO to include a malicious scheduled task or startup script. This task will execute with SYSTEM privileges on all affected computers when Group Policy refreshes. This is a direct and effective privilege escalation method, as it leverages the GPO's application to gain elevated code execution.

Why this answer

With write permissions on a GPO linked to an OU containing privileged servers, modifying the GPO to add an immediate scheduled task that runs as SYSTEM allows code execution with elevated privileges on those servers. This directly escalates privileges by leveraging the GPO's application to all computers in the OU, achieving SYSTEM-level access.

Exam trap

The trap here is assuming that write access to a GPO allows direct domain admin escalation, when in fact it enables code execution as SYSTEM on affected machines, which can then be used for further privilege escalation.

175
MCQmedium

During a penetration test, you want to exploit a client-side vulnerability by sending a link that will execute JavaScript in a victim’s browser when clicked. The target application uses a session cookie without the SameSite attribute. Which attack is most directly enabled by the missing SameSite attribute?

A.Clickjacking
B.Reflected Cross-Site Scripting (XSS)
C.DOM-based Cross-Site Scripting (XSS)
D.Cross-Site Request Forgery (CSRF)
AnswerD

When a session cookie lacks the SameSite attribute, browsers may send it with cross-site requests. This allows an attacker to craft a malicious page that submits a request to the target application, and the victim’s browser automatically includes the session cookie. The server then processes the request as the authenticated user, enabling CSRF. SameSite is a primary defense against this class of attack.

Why this answer

The SameSite cookie attribute controls whether cookies are sent with cross-site requests. Without it, a browser may include the session cookie when a victim’s browser makes a request to the target site from a different origin. An attacker can exploit this by crafting a page that automatically submits a state-changing request, such as a form POST, to the target application.

The server sees the authenticated cookie and processes the action, which is the essence of CSRF.

Exam trap

The trap here is confusing cookie transmission controls with script injection flaws, assuming that a missing SameSite attribute enables XSS rather than CSRF.

176
MCQmedium

You have found a Python exploit that uses the 'requests' library but your target machine only has standard Python installed. What is your best course of action?

A.Upload the library to the target machine.
B.Modify the script to use standard Python libraries instead.
C.Install the library on your own machine and hope it works.
D.Give up on this exploit and find a different one.
AnswerB

Rewriting the exploit to use native libraries is the most reliable method for ensuring execution in restrictive environments. It removes the dependency on external packages, making the script more robust and independent of the specific environment's pre-installed tools, which is crucial for successful exploitation in an exam.

Why this answer

When a public exploit has unmet dependencies, the most efficient approach is to rewrite the exploit to use standard libraries or ensure the dependency is met in a way that doesn't disrupt the target. In an exam, you often cannot install external packages on the target. Therefore, porting the functionality to native libraries like 'urllib' ensures your exploit remains portable and functional without requiring additional, potentially unavailable, software installations.

Exam trap

Candidates often waste time attempting to install missing Python packages using pip on an isolated target, which typically results in permission errors or network connectivity issues that prevent the exploit from running.

177
Multi-Selectmedium

Which TWO of the following are common reasons for a buffer overflow exploit to fail even after the return address is correctly overwritten?

Select 2 answers
A.The presence of undocumented bad characters in the payload.
B.The use of a static JMP ESP address.
C.The system has Data Execution Prevention (DEP) enabled.
D.The pattern generator failed to reach the buffer.
E.The shellcode is too short for the buffer.
AnswersA, C

If a character is not identified as 'bad' during the initial testing phase, it can cause the input function to terminate the copy operation. This results in the shellcode being truncated, so the buffer contains only a partial payload that cannot perform the intended task when the CPU jumps to it.

Why this answer

Exploits often fail due to environmental factors that were not accounted for during the development phase. Even with a perfect offset, the presence of hidden bad characters can truncate the shellcode before it reaches the stack. Additionally, security controls like DEP (Data Execution Prevention) or ASLR (Address Space Layout Randomization) can prevent the shellcode from executing if the environment is locked down, rendering a simple stack-based overflow ineffective.

Exam trap

Test-takers frequently assume that reaching EIP guarantees exploitation, overlooking environmental security mitigations like DEP or hidden bad characters that silently truncate payloads.

178
MCQeasy

Which resource is most reliable for verifying that a public exploit is legitimate and does not contain hidden backdoors?

A.The 'Download' link from an anonymous search result page.
B.A reputable source like Exploit-DB or a verified GitHub repository.
C.A public exploit video on social media showcasing the hack.
D.Running the script inside a browser-based online compiler.
AnswerB

Reputable sources like Exploit-DB maintain a degree of oversight and community scrutiny. Verified GitHub repositories often include commit history and issue trackers where users report concerns. Reviewing this metadata helps ensure the code's provenance and provides confidence that the exploit performs only the documented actions against the intended target.

Why this answer

Verifying exploit integrity is crucial to prevent self-compromise. Official repositories and reputable security platforms provide peer-reviewed code. By examining the source code manually and checking the history of the repository, you can identify suspicious commands like hardcoded reverse shells to unknown addresses.

Relying on reputable sources minimizes the risk of executing malicious code designed to target the researcher's own machine during an engagement.

Exam trap

Test-takers sometimes rely on random blog posts or unverified forums for exploits, ignoring trusted platforms that offer peer-reviewed and vetted security code.

179
MCQmedium

You have obtained a Windows domain user's NTLM hash and want to authenticate to a remote SMB service without cracking the hash or knowing the plaintext. Which tool and technique should you use to perform pass-the-hash against the target?

A.Use `crackmapexec smb <target> -u <user> -H <hash>` to authenticate with the NTLM hash.
B.Use `john --format=NT <hashfile>` to crack the hash and then log in with the recovered password.
C.Use `smbclient -U <user>%<hash> //<target>/share` to authenticate with the hash.
D.Use `hydra -l <user> -P <hashfile> smb://<target>` to replay the hash as a password.
AnswerA

CrackMapExec (now NetExec) supports pass-the-hash via the `-H` flag, allowing SMB authentication with an NTLM hash without cracking it. It sends the hash in the NTLM authentication exchange, which the server accepts because it only verifies the hash. This is the standard method for lateral movement when only the hash is available, and it works against SMB services that permit NTLM authentication.

Why this answer

Pass-the-hash allows an attacker to authenticate using the NTLM hash directly, bypassing the need to crack it. CrackMapExec (NetExec) is specifically designed for this and includes the `-H` flag to supply the hash. The other options either attempt to crack the hash, use tools that do not support hash authentication, or misconfigure the syntax.

The correct approach leverages the hash as a credential in the NTLM challenge-response protocol.

Exam trap

The trap here is confusing pass-the-hash with password cracking or assuming any tool that handles SMB can accept a hash directly.

180
MCQmedium

During an internal penetration test, you run a UDP scan against a Linux server and see the following result: `161/udp open snmp`. You want to extract as much host information as possible without triggering authentication failures. Which command should you run first?

A.`onesixtyone -c /usr/share/seclists/Discovery/SNMP/common-snmp-community-strings.txt 10.10.10.25`
B.`snmpwalk -v3 -l authPriv -u admin -a SHA -A password 10.10.10.25`
C.`snmpwalk -v2c -c public 10.10.10.25`
D.`nmap -sU -p161 --script snmp-brute 10.10.10.25`
AnswerC

SNMPv2c with the default community string `public` is commonly left enabled on Linux servers, and `snmpwalk` recursively walks the MIB tree to reveal system description, interfaces, routes, users, and installed software. It is a read operation that does not attempt authentication, so it gathers maximum information without locking accounts or generating failed-login events.

Why this answer

The most efficient first action is to query SNMP with the default read-only community string using `snmpwalk`. It both confirms the service is accessible and dumps a large amount of host data in one step. Brute-forcing or using SNMPv3 credentials is premature and risks detection or lockout without adding immediate value.

Exam trap

The trap here is assuming SNMP enumeration requires brute-forcing community strings, when the default `public` string is often still enabled and yields immediate results.

181
MCQmedium

During a PEN-200 lab engagement you locate a public exploit for a web application running on the target. The exploit's banner string is 'Mozilla/5.0' and the script appends the payload to a URL parameter. Before running it against the target, which action best reduces the risk of unintended side effects on the production web service?

A.Review the exploit's HTTP request construction and test it against a local instance of the same application version.
B.Increase the exploit's timeout value to ensure the request completes fully before you observe the result.
C.Change the target URL to a non-existent host so the exploit exits early, then redirect it to the real target.
D.Run the exploit with a --safe flag if the script supports it, then immediately run it against the target.
AnswerA

Auditing the request construction reveals exactly what parameters and payloads are sent, and reproducing the same application version locally lets you observe the exploit's real effect without touching the production service. This combination gives verifiable behavior before any live request, which is the core discipline of safe exploit validation in PEN-200.

Why this answer

Examining how the exploit builds its HTTP request and replaying it against a matching local instance is the only approach that both reveals the payload's behavior and prevents production impact. Local reproduction lets the tester observe success or failure and confirm the exploit is appropriate before touching the live service, which is the safe validation workflow emphasized in PEN-200.

Exam trap

The trap here is assuming that a script's built-in safety flag or a dry-run URL substitution proves the exploit is harmless when neither actually exercises the vulnerable code path.

182
MCQmedium

During a network assessment, you want to enumerate users on a domain controller. Which protocol and port combination is the most standard target for this type of enumeration?

A.HTTP on port 80
B.LDAP on port 389
C.FTP on port 21
D.SMTP on port 25
AnswerB

LDAP is the primary protocol for directory services in Windows domains. Connecting to port 389 allows for queries that can return lists of users, groups, and computers. This is a standard enumeration technique used to map the domain and prepare for further attacks like password spraying or credential harvesting.

Why this answer

LDAP, running on port 389, is the standard protocol for querying directory information in a Windows domain. By successfully connecting to the LDAP service, a tester can often dump user lists, group memberships, and other organizational data. Understanding this protocol is vital, as it provides the foundation for password spraying attacks and deeper reconnaissance within Active Directory, which is a common objective in enterprise penetration tests.

Exam trap

Candidates often confuse LDAP port 389 with Kerberos (88) or SMB (445) when specifically trying to query organizational domain user lists.

183
MCQhard

You have obtained a low-privileged shell on a Linux server. During enumeration, you discover a file named `backup.sh` in `/opt/scripts` that is owned by root and has permissions `-rwxr-xr-x`. A cron job runs this script every night as root. The directory `/opt/scripts` has permissions `drwxrwxr-x` and is owned by root:developers. Your user is a member of the `developers` group. What is the most reliable way to escalate privileges?

A.Use the `sudo` command to edit the script with `sudoedit`.
B.Replace `/opt/scripts/backup.sh` with a malicious script by deleting the original and creating a new file with the same name.
C.Add a new cron job that runs a reverse shell as your user.
D.Modify the contents of `/opt/scripts/backup.sh` to include a reverse shell payload.
AnswerB

Because the directory `/opt/scripts` is group-writable and you are a member of the `developers` group, you can delete the existing `backup.sh` file and create a new file with the same name. The new file will be owned by your user, but the cron job runs as root and will execute it. This is a classic privilege escalation via writable directory containing a root-executed script. The original file's permissions do not prevent deletion because deletion is controlled by the directory's permissions, not the file's.

Why this answer

The key vulnerability is that the directory `/opt/scripts` is writable by the `developers` group, of which your user is a member. Although the script file itself is not writable, you can delete it and create a new file with the same name because directory write permission allows file deletion and creation. The cron job will then execute your malicious script as root, granting privilege escalation.

This is a common misconfiguration in Linux environments.

Exam trap

The trap here is focusing on the file's permissions and overlooking the directory's write permission, which allows replacing the file entirely.

184
MCQhard

You have identified an AlwaysOn service running with SYSTEM privileges. The service binary is read-only, but you have write access to its directory. What is the most likely escalation vector?

A.Exploiting the unquoted service path.
B.DLL Hijacking.
C.Modify the service binary directly.
D.Overwriting the service configuration file.
AnswerB

When an application loads a DLL, it searches the application directory first. If you have write access to that directory, you can place a malicious DLL with a matching name. The application will load it instead of the system version, executing your code under the service's context.

Why this answer

If the binary is read-only but the directory is writable, you may be able to perform DLL hijacking. Windows applications often look for DLLs in the application directory before searching system folders. By placing a malicious DLL with the same name as a dependency into the application's folder, you can force the application to load your code when it starts, gaining SYSTEM privileges.

Exam trap

Candidates attempt to replace the read-only service executable directly, forgetting that directory-level write access enables alternative vectors like DLL hijacking.

185
MCQeasy

During an assessment, you identify a Cross-Site Scripting vulnerability that allows you to execute arbitrary JavaScript in the context of a victim user's browser session. What is the primary objective of leveraging this capability against an authenticated user?

A.Extracting plaintext password hashes directly from the remote web server operating system memory
B.Hijacking the user session by accessing session tokens or performing actions on their behalf within the application
C.Modifying the enterprise DNS records hosted on the primary domain controller via client-side DOM manipulation
D.Bypassing enterprise firewall packet inspection rules by encapsulating shellcode inside HTTPS headers
AnswerB

Executing JavaScript in the victim browser permits access to session identifiers stored in cookies or local storage, facilitating session hijacking. The attacker can also forge HTTP requests using the user's active session to perform unauthorized administrative actions.

Why this answer

XSS allows attackers to execute scripts in the victim browser session, giving them access to document.cookie, local storage, and the ability to perform actions on behalf of the user. This effectively hijacks their session without needing to crack their underlying password.

Exam trap

Students often believe XSS is solely useful for defacing web pages or executing simple alerts, failing to recognize its power in stealing session tokens for unauthorized access.

186
Multi-Selectmedium

Which TWO of the following actions are considered best practice during the initial host enumeration phase to avoid detection by security monitoring tools?

Select 2 answers
A.Perform a full port scan on all 65535 ports concurrently.
B.Prioritize passive reconnaissance using OSINT sources.
C.Implement scan rate-limiting to reduce traffic volume.
D.Use aggressive service detection flags in all scans.
E.Scan from the same IP address at all times.
AnswersB, C

Passive reconnaissance involves gathering information without directly interacting with the target, such as using search engines, public records, or WHOIS data. This is completely stealthy, as it leaves no trace on the target system or their network, making it an essential first step in any professional engagement.

Why this answer

To minimize detection, penetration testers should prioritize passive information gathering before engaging in active, noisy scanning. When active scanning is required, rate-limiting and targeting specific ports rather than performing a 'scan all' approach helps blend the traffic into normal network behavior. These practices are essential for maintaining the stealth required in professional engagements, ensuring that the tester remains undetected while collecting the necessary intelligence to identify high-value targets.

Exam trap

Candidates often include aggressive scanning techniques like 'full TCP connect scans'. The question asks for best practices to 'avoid detection', which mandates passive methods and rate-limited active traffic.

187
MCQmedium

You are performing a penetration test on a web application that uses a PHP session cookie. You notice the cookie lacks the HttpOnly flag. An attacker could exploit this by injecting a script that steals the cookie. Which attack technique is most directly enabled by the missing HttpOnly flag?

A.Cross-Site Scripting (XSS) cookie theft
B.Session fixation
C.Cross-Site Request Forgery (CSRF)
D.SQL injection
AnswerA

Without HttpOnly, JavaScript can access the session cookie via document.cookie. If an attacker can inject and execute JavaScript through an XSS vulnerability, they can read the cookie and send it to a remote server, hijacking the session. This is a direct consequence of missing HttpOnly, as the flag is designed to prevent exactly this type of theft.

Why this answer

The HttpOnly flag prevents client-side scripts from accessing the cookie, mitigating XSS-based session theft. Without it, an XSS vulnerability can be used to read the session cookie and hijack the user's session. CSRF, session fixation, and SQL injection are separate issues not directly enabled by the absence of HttpOnly.

Thus, XSS cookie theft is the most direct attack technique enabled by this misconfiguration.

Exam trap

The trap here is assuming that missing HttpOnly enables CSRF, when in fact CSRF does not require reading the cookie; it exploits automatic cookie inclusion.

188
MCQhard

You have compromised a Windows server and want to escalate privileges using the `AlwaysInstallElevated` setting. You check the registry and find that both `HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated` and `HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated` are set to 1. What is the most direct way to leverage this misconfiguration?

A.Leverage the setting to bypass UAC and run any executable as an administrator without an MSI package.
B.Create a malicious MSI package and execute it with `msiexec /quiet /qn /i malicious.msi` to run with SYSTEM privileges.
C.Use `reg add` to modify the service binary path of a running service to point to a malicious executable.
D.Extract the MSI to a writable directory and replace a DLL to achieve privilege escalation.
AnswerB

When AlwaysInstallElevated is enabled in both HKLM and HKCU, any MSI package installed by the user runs with elevated (SYSTEM) privileges. You can generate a malicious MSI that executes a command, for example adding a user to the Administrators group, and then install it using `msiexec` with quiet flags to avoid user interaction.

Why this answer

With AlwaysInstallElevated enabled in both registry hives, any MSI package installed by a user runs with SYSTEM privileges. The most direct exploitation is to create a malicious MSI that performs a privileged action, such as adding a user to the Administrators group, and then install it using `msiexec`. This leverages the misconfiguration exactly as designed.

Exam trap

The trap here is thinking that AlwaysInstallElevated allows arbitrary executables to run elevated, when it specifically applies to MSI packages.

189
MCQmedium

During an authorized internal penetration test, you discover that the corporate proxy does not perform SSL inspection and allows outbound HTTPS to any destination. You need to deliver a client-side payload over HTTPS while evading signature-based network detection. Which technique is most appropriate?

A.Send the payload as a base64-encoded attachment in a plain SMTP email to the target user.
B.Serve the payload from a valid TLS certificate on a domain categorized as business-related, using domain fronting through a CDN.
C.Host the payload on an unregistered domain with a self-signed certificate and rely on the user to click through the browser warning.
D.Embed the payload in an ICMP echo request and use a custom tunnel to the target workstation.
AnswerB

Domain fronting leverages a CDN's shared TLS endpoint to hide the true destination in the encrypted SNI, so network defenders only see a benign domain. Combined with a valid TLS certificate and business categorization, it blends with normal traffic and bypasses signature-based detection that relies on IP or domain reputation.

Why this answer

Domain fronting through a CDN with a valid certificate and a business-categorized domain conceals the true destination in the TLS SNI, allowing the payload to be delivered over HTTPS while blending with legitimate traffic. This evades signature-based network detection that relies on domain or IP reputation.

Exam trap

The trap here is assuming that any HTTPS delivery automatically evades detection, when in fact certificate validity, domain reputation, and traffic categorization are what determine whether the connection blends in.

190
Multi-Selecthard

When enumerating a web application, which THREE of the following items are most important to identify to increase the likelihood of finding a vulnerability?

Select 3 answers
A.Hidden directories and files.
B.The web server software and version.
C.User input fields and URL parameters.
D.The color scheme of the website.
E.The number of images hosted on the server.
AnswersA, B, C

Hidden directories often contain configuration files, backup scripts, or administrative interfaces that lack proper authentication. Identifying these paths provides a significant advantage, as they may contain sensitive information or serve as entry points that bypass the main application's security controls, providing easier access for a penetration tester.

Why this answer

Effective web enumeration requires looking beyond the main page. Identifying hidden directories, software versions, and input fields allows a tester to map the attack surface comprehensively. By finding these components, a tester can research known vulnerabilities associated with specific technologies or test for common web flaws like SQL injection or cross-site scripting, which are frequently found in custom application code and forgotten administrative paths.

Exam trap

Candidates often focus only on finding a single vulnerability on the homepage, neglecting input fields, parameters, and hidden administrative directories.

191
MCQeasy

You are analyzing a Windows 32-bit application that uses a fixed-size stack buffer and calls strcpy() without bounds checking. You want to determine the exact offset to overwrite the saved return address. Which tool or method is most appropriate for this task?

A.Use a disassembler to count the number of bytes between the buffer and the return address.
B.Use a hex editor to modify the binary and insert a breakpoint at the return instruction.
C.Use a debugger to send a unique cyclic pattern and inspect the value of EIP.
D.Use a fuzzer to send random data and monitor for a crash, then guess the offset.
AnswerC

This is correct because sending a unique cyclic pattern allows you to identify the exact offset by observing the overwritten EIP value. Tools like Mona.py in Immunity Debugger or pattern_create/pattern_offset in Metasploit can generate and locate the offset. This is a standard step in buffer overflow exploitation.

Why this answer

The most reliable way to find the exact offset is to send a unique cyclic pattern and observe which four bytes overwrite EIP. This directly maps input position to the return address. Tools like Mona.py automate this process.

Static counting or random fuzzing are less precise and can be misleading.

Exam trap

The trap here is thinking that static analysis or random fuzzing can pinpoint the offset, when dynamic pattern generation is needed to account for runtime stack layout.

192
MCQmedium

During a buffer overflow exploit development, you need to ensure that your shellcode does not contain any null bytes. You have generated shellcode that includes a null byte. Which of the following is the most appropriate action?

A.Manually replace the null byte with a NOP (0x90) instruction.
B.Use an encoder such as Shikata Ga Nai to encode the shellcode, which will remove null bytes and add a decoder stub.
C.Split the shellcode into two parts and execute them sequentially using a staged payload.
D.Use a different shellcode that does not contain null bytes, such as one generated with the 'alpha_mixed' encoder.
AnswerB

Encoders like Shikata Ga Nai are designed to transform shellcode to avoid bad characters such as null bytes. They prepend a decoder stub that reconstructs the original shellcode at runtime. This is a standard technique in exploit development when bad characters are present. The encoded shellcode is larger but functionally equivalent after decoding.

Why this answer

When shellcode contains bad characters like null bytes, encoding it with a tool like Shikata Ga Nai is the standard solution. The encoder transforms the shellcode into a null-free version and adds a decoder stub that reconstructs the original code in memory. This allows the exploit to deliver the payload without the bad characters causing premature termination.

It is a fundamental step in exploit development, especially for stack-based overflows.

Exam trap

The trap here is assuming that any null-free shellcode will work without considering that the encoder must also preserve the shellcode's functionality and be compatible with the available space.

193
MCQmedium

You are on a Windows 10 machine and discover that the folder 'C:\Temp' has permissions: BUILTIN\Users:(F). You also notice that a scheduled task runs every hour, executing 'C:\Temp\cleanup.exe' as SYSTEM. However, cleanup.exe does not exist in the folder. What is the most effective way to escalate privileges?

A.Use icacls to change permissions on the scheduled task file.
B.Create a new scheduled task that runs as SYSTEM.
C.Modify the scheduled task to run a different command using schtasks.
D.Place a malicious cleanup.exe in C:\Temp and wait for the scheduled task to run.
AnswerD

Since the scheduled task runs cleanup.exe as SYSTEM and the folder is writable by Users, you can create a malicious executable named cleanup.exe. When the task triggers, it will execute your payload with SYSTEM privileges. This is a straightforward privilege escalation via a missing binary in a writable directory.

Why this answer

The scheduled task runs a missing executable from a writable directory as SYSTEM. By placing a malicious cleanup.exe in C:\Temp, you ensure that the task executes your code with SYSTEM privileges. This is a classic privilege escalation via weak folder permissions and scheduled tasks.

Exam trap

The trap here is overlooking that the task runs a missing binary and focusing on modifying the task itself, which requires higher privileges.

194
MCQmedium

Which command is most useful for identifying processes that are running as root, which might be potential targets for privilege escalation?

A.ps aux | grep root
B.ls -l /proc
C.netstat -tulnp
D.cat /etc/passwd | grep root
AnswerA

The 'ps aux' command lists every process on the system, and 'grep root' filters that list to show only those owned by the root user. This is the fastest way to identify all high-privilege services, which are the most valuable targets for your privilege escalation attempts.

Why this answer

The 'ps' command is essential for process enumeration. By using specific flags like 'aux', you can display all processes running on the system, including their owner. Identifying services owned by root allows you to focus your efforts on finding vulnerabilities in those specific processes.

This is a fundamental enumeration step, as privilege escalation often involves finding a misconfigured or vulnerable service that is already running with the target privileges.

Exam trap

Candidates often forget specific filtering flags or confuse process enumeration commands, attempting to use tools that do not display the file owners or trying to inspect user-level processes instead of focusing on root-owned services.

195
MCQhard

Refer to the exhibit. You identify an Apache 2.4.49 vulnerability and locate the exploit. After reviewing the exploit code, you realize it requires a specific input format to trigger the path traversal. What is the most effective way to verify the vulnerability without crashing the server?

A.Execute the exploit immediately against the root directory.
B.Use a simple path traversal payload to request a harmless file.
C.Run the exploit as is and hope the server remains stable.
D.Modify the exploit to dump the entire password file immediately.
AnswerB

Requesting a harmless file like a public document is a safe way to confirm the path traversal vulnerability exists. If you receive the file content back successfully, you have proven the vulnerability without causing any disruption to the service or damaging the target system's stability.

Why this answer

Verification is a critical phase where you test for the vulnerability's presence using non-destructive inputs. By attempting a benign request, such as reading a safe, non-sensitive file like a public README, you confirm the exploit works without risking a Denial of Service. This professional approach demonstrates a cautious mindset, essential for performing assessments that prioritize target stability while successfully confirming the vulnerability exists.

Exam trap

Test-takers often rush to execute aggressive or destructive exploit payloads to prove a concept, risking accidental service crashes instead of using safe, non-destructive verification methods.

196
MCQmedium

You have obtained a low-privileged domain user account and are performing internal enumeration. You identify a computer object in the domain where the 'ms-MCS-AdmPwd' attribute is readable by your user account. Which attack path does this vulnerability facilitate?

A.Kerberoasting the computer account password hash
B.Exploiting the GPO to modify the Domain Admins group
C.Extracting the cleartext local administrator password
D.Performing an AS-REP Roasting attack on the machine
AnswerC

The LAPS solution stores the cleartext local administrator password in the ms-MCS-AdmPwd attribute of the computer object. If a domain user has read access to this attribute, they can retrieve the password, enabling them to authenticate as the local administrator on that specific computer, facilitating unauthorized access.

Why this answer

The ms-MCS-AdmPwd attribute stores the cleartext Local Administrator Password for a computer managed by LAPS. By reading this attribute, an attacker can extract the password for the local administrator account of the target machine. This is a critical discovery because it allows immediate lateral movement from a low-privileged domain context to local administrative privileges on that specific host, potentially leading to further credential harvesting or domain escalation.

Exam trap

Students often misidentify LAPS attribute names or confuse computer object permissions with standard user right assignments, missing the direct implications of readable administrative passwords.

197
MCQhard

Why does enabling 'SMB Signing' prevent NTLM relay attacks?

A.It encrypts the entire SMB session using TLS
B.It requires the client to prove they have the password
C.It validates the integrity of the authentication packets
D.It disables NTLM authentication globally
AnswerC

SMB signing forces the use of cryptographic signatures for every packet. Because the attacker cannot generate valid signatures for the relayed authentication without the session key, the target server rejects the relayed packets. This makes it impossible to relay authentication successfully between a client and a target server.

Why this answer

SMB Signing adds a cryptographic signature to each packet in an SMB communication. When a relay attack occurs, the attacker does not possess the session key required to generate these signatures for the relayed packets. Consequently, the target server detects the missing or invalid signature and rejects the authentication attempt, effectively neutering the relay attack at the protocol level.

Exam trap

Candidates often assume SMB signing encrypts the entire traffic flow. In reality, it only adds a cryptographic signature to each packet to verify its integrity and origin, preventing unauthorized relaying.

198
MCQmedium

During an internal assessment you compromise a workstation and recover a Kerberos TGS ticket from memory that belongs to a service account. Analysis shows the ticket was encrypted with the RC4-HMAC cipher using a key derived from the service account's password hash. You want to recover the plaintext password of that service account offline. Which action should you take?

A.Submit the ticket to the domain controller with GetUserSPNs.py and let the KDC decrypt it to disclose the service account's NT hash.
B.Convert the ticket to a .kirbi file and import it with Rubeus to request a service ticket that reveals the account password in the response.
C.Use Kerbrute to spray the recovered ticket against the domain controller and read the resulting authentication error codes.
D.Crack the ticket offline with Hashcat in mode 13100, since the ticket is encrypted with RC4-HMAC and its checksum can be attacked with a wordlist.
AnswerD

A TGS-REP ticket encrypted with RC4-HMAC can be brute-forced offline because the checksum is keyed by the service account's NT hash. Hashcat mode 13100 targets Kerberos 5 TGS-REP etype 23 hashes exactly, allowing a wordlist or rule-based attack to recover the plaintext, which is the standard Kerberoasting cracking path.

Why this answer

A service ticket encrypted with RC4-HMAC (etype 23) is protected by a key derived from the target service account's NT hash, so the ciphertext can be attacked entirely offline. Extracting the TGS-REP hash and running Hashcat mode 13100 against a wordlist recovers the plaintext password when it is weak, without generating additional authentication traffic against the domain.

Exam trap

The trap here is assuming a captured service ticket can be replayed to the KDC to reveal the password, when in fact Kerberoasting success depends on cracking the RC4-encrypted ticket offline.

199
MCQmedium

Refer to the exhibit. What is the primary purpose of the command provided?

A.Performing a brute-force attack on a SHA-256 encrypted archive.
B.Cracking NTLM hashes using a dictionary-based approach.
C.Attempting a mask attack to guess passwords based on a specific pattern.
D.Extracting domain user hashes from a SAM database file.
AnswerB

Mode 1000 identifies the hash type as NTLM, and -a 0 specifies the dictionary attack mode. This combination is the standard method for attempting to recover plaintext passwords from NTLM hashes using a predefined list of words, which is the most efficient starting point for offline password recovery in Windows environments.

Why this answer

This command initiates a dictionary attack against NTLM hashes. Mode 1000 is specifically designated for NTLM authentication hashes, while -a 0 denotes a straight dictionary attack using a wordlist. Knowing how to map hash formats to their corresponding Hashcat mode is a fundamental skill for password cracking.

Incorrectly identifying the mode or the attack type will result in an inability to recover the plaintext credentials during a penetration test.

Exam trap

Candidates frequently confuse Hashcat mode numbers, mistakenly applying modes meant for Kerberos or salted hashes when attempting to crack standard NTLM authentication hashes.

200
MCQmedium

An attacker places a malicious 'version.dll' file into the same directory as a legitimate, signed executable that is known to load that DLL. When the legitimate program starts, it loads the malicious DLL instead of the one in the System32 folder. What evasion technique is being demonstrated?

A.DLL Injection
B.DLL Sideloading
C.COM Hijacking
D.Reflective DLL Loading
AnswerB

Sideloading takes advantage of the Windows DLL search order, which prioritizes the application's directory over system directories. By naming the malicious file after a required dependency, the attacker tricks a trusted application into executing their code. This is a highly effective way to gain execution while appearing as a legitimate, signed process.

Why this answer

DLL Sideloading exploits the default search order that Windows uses to locate dynamic-link libraries. By placing a malicious DLL in the application's local directory, the attacker ensures it is loaded before the legitimate system DLL. This allows malicious code to run under the context of a trusted, signed process, which often bypasses security controls and behavioral alerts.

Exam trap

Candidates often confuse DLL Sideloading with DLL Hijacking or Search Order Hijacking. While related, Sideloading specifically refers to placing a malicious DLL alongside a legitimate executable to exploit the default search order.

201
Multi-Selecthard

Which THREE techniques are commonly implemented in malware to detect and evade dynamic analysis within an automated sandbox environment?

Select 3 answers
A.Checking for a low number of CPU cores or small RAM size
B.Executing a large number of NOP instructions to increase file size
C.Monitoring for specific mouse movements or keyboard input
D.Implementing long 'Sleep' delays or complex timing loops
E.Using direct syscalls to bypass the Windows API hooks
AnswersA, C, D

Automated sandboxes are often resource-constrained to save costs, frequently operating with only one or two CPU cores and minimal memory. Legitimate modern workstations typically have more resources. Malware can check these hardware specifications and terminate execution if they fall below a certain threshold, assuming the environment is a virtualized analysis lab.

Why this answer

Sandbox evasion relies on identifying traits that distinguish a virtualized, automated analysis environment from a real user workstation. Malware often checks for specific hardware configurations, waits for human-like interaction, or uses long delays to exceed the sandbox's limited analysis time. These methods ensure the malicious payload remains dormant while the environment is being monitored by security researchers.

Exam trap

Candidates frequently select 'checking for network connectivity' or 'checking for domain membership'. While relevant, these are not the most common core sandbox evasion techniques requested in standard exam scenarios.

202
MCQmedium

During an internal assessment, you compromise a workstation and recover a cached domain credential hash for a user who previously logged on. You want to use this hash to authenticate to a file server on the same network, but you do not know the plaintext password. Which of the following tools is specifically designed to perform Pass-the-Hash authentication from a Linux-based attack platform?

A.Hashcat with mode 1000
B.Responder with the -w flag
C.Mimikatz with the sekurlsa::logonpasswords module
D.Impacket's psexec.py
AnswerD

Impacket's psexec.py supports Pass-the-Hash via the -hashes argument, allowing an attacker to authenticate to SMB services using an NTLM hash without knowing the plaintext password. It constructs the SMB session using the provided LM:NT hash pair, which is precisely the objective in this scenario where only the hash was recovered from a compromised workstation.

Why this answer

Pass-the-Hash requires a tool that can supply an NTLM hash directly during authentication. Impacket's psexec.py is a Python implementation of PsExec that accepts -hashes, enabling authentication to SMB shares with a hash. The other tools either crack hashes offline, harvest credentials, or extract credentials locally, none of which achieve remote authentication with a hash.

Exam trap

The trap here is assuming that any credential extraction tool like Mimikatz or Hashcat can also perform Pass-the-Hash authentication, when in fact only specific modules or tools are designed for that purpose.

203
MCQeasy

Refer to the exhibit. Which ports are currently open on the target host 192.168.1.10?

A.All ports from 1 to 1000.
B.Only port 22.
C.Ports 22 and 80.
D.No ports are open.
AnswerC

The scan report explicitly shows that ports 22/tcp and 80/tcp are in the 'open' state. Correctly identifying these ports is fundamental to the reconnaissance phase, as it provides the necessary roadmap for deciding which service to analyze further for potential vulnerabilities or configuration weaknesses during the engagement.

Why this answer

The Nmap output clearly indicates the state of the scanned ports. In this exhibit, ports 22 and 80 are explicitly listed as 'open', while 998 others are closed. Identifying these specific ports is the first step in mapping the target's attack surface.

Understanding how to read scan output is a core competency that allows a tester to prioritize their focus towards the services that are most likely to be exploitable.

Exam trap

Candidates often misread Nmap output columns, confusing filtered or closed ports with open ones, or missing secondary ports running non-standard services due to rushing.

204
MCQeasy

A penetration tester is preparing a Windows payload for a client engagement where the target endpoint runs a traditional signature-based antivirus product that does not perform cloud lookups. The tester wants to reduce the chance that the raw output of msfvenom is flagged during initial delivery. Which action best addresses this goal?

A.Rename the payload file to a benign-looking name such as invoice.pdf.exe and set the archive attribute.
B.Compile a custom loader that embeds the shellcode in an encrypted form and decrypts it at runtime, rather than delivering the raw msfvenom executable.
C.Use msfvenom's -e encoder option with shikata_ga_nai and iterate the encoding multiple times.
D.Pipe the msfvenom output through gzip and deliver the compressed archive to the target.
AnswerB

A custom loader with encrypted embedded shellcode presents a different on-disk artifact than the original msfvenom executable, so the signature that matched the raw payload no longer applies. The executable's own code is unique to the tester, and the shellcode is not present in a recognizable form until runtime decryption. This directly addresses signature-based detection at delivery without relying on well-known encoders.

Why this answer

Signature-based antivirus matches known byte patterns in files. To avoid that match, the delivered artifact must not contain those known patterns. Building a custom loader that stores shellcode in encrypted form produces a file whose bytes differ entirely from the raw msfvenom output, so the original signature no longer applies.

Compression and renaming leave the executable bytes intact, and well-known encoders like shikata_ga_nai are themselves signatured.

Exam trap

The trap here is believing that compressing, renaming, or re-encoding a payload hides it from signature scanning, when the scanner reads the underlying executable bytes regardless of wrapper or filename.

205
MCQhard

A penetration tester uses process hollowing to hide their payload inside 'svchost.exe'. They start the process in a suspended state, unmap its memory, write their shellcode, and resume the thread. What is a specific indicator that an advanced EDR might use to detect this activity?

A.The 'svchost.exe' process will show a significantly higher CPU usage.
B.The entry point of the process in memory differs from the image on disk.
C.The process will be unable to communicate with the network.
D.The system will automatically restart the process due to a checksum error.
AnswerB

EDR tools can compare the executable's entry point and memory map against the original file on disk. When a process is hollowed, the memory contents and the entry point are modified to point to the malicious code. This mismatch is a clear sign that the process has been tampered with and is no longer legitimate.

Why this answer

Process hollowing is a powerful evasion technique, but it leaves behind traces in the system's memory and process metadata. Advanced EDR solutions monitor for discrepancies between the file on disk and the code in memory. They also track specific API call sequences, such as creating a process in a suspended state followed immediately by memory unmapping and cross-process writing.

Exam trap

Candidates often suggest 'the process is running as SYSTEM'. While true, EDRs look for specific memory-based indicators, not just process privileges.

206
MCQeasy

You are auditing a web application and notice it uses base64 encoding to store user credentials in a cookie. What is the most accurate assessment of this security practice?

A.The credentials are secure because base64 is difficult to reverse without the secret key.
B.The credentials are protected from casual inspection but vulnerable to automated tools.
C.The implementation is insecure because base64 is an encoding, not a cryptographic protection.
D.The implementation is acceptable if the connection is encrypted with TLS.
AnswerC

Base64 is designed to represent binary data in an ASCII string format. It offers no confidentiality or integrity. Using it to store credentials is a critical vulnerability because it exposes plaintext passwords to anyone who can view the cookie, allowing for trivial credential theft and subsequent unauthorized account access by an attacker.

Why this answer

Base64 is an encoding scheme, not an encryption or hashing algorithm. It is completely reversible and provides zero confidentiality for sensitive data. An attacker can easily decode these values to reveal plaintext credentials.

This is a common finding in penetration tests that highlights a lack of understanding of the difference between obfuscation and actual security controls, requiring immediate remediation to protect session integrity.

207
MCQhard

During an internal penetration test, you capture NTLMv2 challenge-response pairs from the network using Responder. The client is a Windows 10 workstation and the server is a Windows Server 2019 domain controller. You need to crack these NTLMv2 hashes offline. Which tool and mode correctly performs this attack?

A.Hashcat with mode 1000 (NTLM)
B.Hashcat with mode 5600 (NetNTLMv2)
C.Cain & Abel with the NTLMv2 sniffer
D.John the Ripper with the --format=NT option
AnswerB

Hashcat mode 5600 is specifically designed for NetNTLMv2 (NTLMv2 challenge-response) hashes. These are network captures that include the server challenge, username, and domain, and are cracked as a challenge-response pair. This mode correctly handles the format and cryptographic operations needed to test candidate passwords against the captured NTLMv2 response, making it the appropriate choice for this scenario.

Why this answer

NTLMv2 challenge-response captures from tools like Responder are network authentication attempts, not raw password hashes. They must be cracked using a tool that supports the NetNTLMv2 format, such as Hashcat mode 5600. Raw NTLM hashes require different modes (e.g., 1000).

Using the correct mode ensures the cracking process properly computes the HMAC-MD5 response for each candidate password.

Exam trap

The trap here is confusing NetNTLMv2 challenge-response hashes with raw NTLM password hashes, leading to the selection of an incorrect cracking mode.

208
MCQeasy

Which of the following describes a successful Path Traversal attack in a web application?

A.Injecting JavaScript into a form field to capture user session cookies.
B.Using dot-dot-slash sequences to read /etc/passwd on a Linux server.
C.Submitting a crafted SQL query to retrieve data from the database.
D.Overloading the server with requests to exhaust system memory.
AnswerB

This is the classic example of a Path Traversal attack. By moving up the directory tree using '..', the attacker can point the application to sensitive files like /etc/passwd that reside outside the intended document root, effectively bypassing access controls.

Why this answer

Path Traversal allows attackers to access files outside the intended web root directory by manipulating input parameters that contain file paths. By using dot-dot-slash sequences, an attacker escapes the restricted directory. This is a critical vulnerability that can lead to the exposure of configuration files, sensitive system data, or source code, which is why validating input is a fundamental security requirement.

Exam trap

Candidates often confuse Path Traversal with other vulnerabilities like Local File Inclusion (LFI), though they are related, the specific mechanism involves escaping directories using dot-dot-slash sequences.

209
MCQeasy

While mapping a subnet you want to discover live hosts quickly before running detailed service scans. Which approach best fits an initial host-discovery sweep?

A.Run an ICMP echo sweep combined with TCP SYN probes to common ports to identify responsive hosts.
B.Query the local ARP cache and enumerate only the entries already present.
C.Send UDP probes to port 53 on every address and treat any reply as proof of a live host.
D.Perform a full TCP connect scan of all ports against every address in the subnet range.
AnswerA

Combining ICMP echo with TCP SYN probes to frequently open ports catches hosts that block ping but still expose services, a common configuration. This layered discovery approach maximizes live-host detection quickly, providing a target list for later, more intensive service enumeration without wasting time scanning dead addresses.

Why this answer

Effective host discovery layers ICMP echo with TCP SYN probes to common ports, because many systems disable ping replies while still exposing services. This combination surfaces more live hosts faster than any single method, producing an accurate target list. Full port scans, single-port UDP probes, and ARP cache reads are either too slow, too unreliable, or too incomplete for an initial sweep.

Exam trap

The trap here is assuming ping alone identifies all live hosts, when many systems block ICMP yet still respond on TCP ports.

210
MCQmedium

You have identified a vulnerable service using an outdated version of a CMS. You successfully locate a public exploit script on GitHub. What is the most critical first step before running this script against your target?

A.Immediately run the exploit script with administrative privileges.
B.Change the target IP address in the script's configuration.
C.Read the source code to understand its mechanism and potential impact.
D.Install all dependencies listed in the script's requirements file.
AnswerC

Analyzing the source code allows you to confirm that the exploit performs exactly what you expect. It helps identify hardcoded credentials, malicious payloads, or potential stability issues that could crash the target service, which is essential for maintaining control and stability during your assessment.

Why this answer

Before executing any public exploit, you must analyze the source code to understand its functionality, dependencies, and potential impact. Public exploits are often poorly written or intentionally malicious, potentially causing service crashes or backdooring the attacker machine. Understanding the payload ensures you do not inadvertently trigger unwanted side effects or trigger defensive alarms that could disrupt your assessment during the penetration testing engagement.

Exam trap

Candidates frequently rush to execute downloaded exploits immediately to save time, ignoring the risk of malicious payload execution or system instability caused by poorly written, untested third-party code.

211
MCQeasy

During external reconnaissance you collect DNS records for a target organization and find an MX record pointing to mail.example.com. You want to identify the IP addresses of other hosts in the same mail infrastructure without sending any packets directly to the target's servers. Which action best fits this passive goal?

A.Query a public passive DNS database such as SecurityTrails or VirusTotal for historical A records of example.com.
B.Use nmap -sn 203.0.113.0/24 to discover which hosts in the mail subnet are alive.
C.Run dig axfr @ns1.example.com example.com to transfer the full zone.
D.Perform a reverse DNS lookup against each IP in the target's announced BGP prefixes.
AnswerA

Passive DNS databases store historical resolution data collected from recursive resolvers and other sensors, so querying them reveals IP addresses and subdomains without any packet ever reaching the target's infrastructure. That directly satisfies the requirement to identify hosts while remaining passive. Historical records can also expose decommissioned or origin hosts that current DNS no longer advertises, adding reconnaissance value.

Why this answer

Passive reconnaissance relies on data already collected by third parties, so no packets touch the target. Passive DNS services aggregate historical resolution records from many sensors, letting you map subdomains and IP addresses, including hosts no longer published. Zone transfers, ping sweeps, and reverse lookups all generate traffic toward the target or its authoritative infrastructure, which breaks the passive-only requirement stated in the scenario.

Exam trap

The trap here is assuming that any DNS query is passive, when queries sent to the target's own name servers or hosts are active and attributable.

212
MCQhard

You are assessing a web application that uses a strict Content Security Policy (CSP) with nonce-based script-src. You discover a reflected XSS vulnerability where your input is inserted into an existing <script> block that already has a valid nonce. Which action would most likely allow your JavaScript to execute despite the CSP?

A.Inject JavaScript code directly into the existing script block, leveraging the valid nonce.
B.Inject a new <script> tag with a guessed nonce value.
C.Use a data: URI in an iframe to execute JavaScript.
D.Break out of the existing script context and inject a new script element without a nonce.
AnswerA

Because the existing script block already has a valid nonce, any JavaScript injected inside it is considered trusted by the CSP. By breaking out of the current JavaScript context (e.g., closing a string or statement) and appending your code, you can execute arbitrary JavaScript without triggering CSP violations. This is a common bypass when user input is reflected into a nonce-protected script block.

Why this answer

The most effective action is to inject JavaScript directly into the existing script block that already carries a valid nonce. Since the CSP trusts scripts with that nonce, any code within that block executes without violation. This bypasses the need to create new script elements or guess nonces.

It exploits the fact that the application reflects user input into a trusted script context, allowing arbitrary code execution.

Exam trap

The trap here is focusing on creating new script tags or guessing nonces, while overlooking that the existing nonce-protected script block can be abused by injecting code directly into it.

213
MCQmedium

During an authorized penetration test of a PHP e-commerce site, you discover that the 'remember me' cookie is created with the following code: setcookie('auth', base64_encode($user_id . ':' . $role), time()+2592000); The cookie value is 'MTIzNDp1c2Vy'. You decode it to '123:user'. The application trusts this cookie for authentication on subsequent requests. What is the MOST direct way to escalate privileges to administrator?

A.Brute-force the base64-encoded cookie to discover the administrator's session identifier.
B.Use SQL injection on the login form to extract the administrator password hash.
C.Perform a cross-site request forgery (CSRF) attack to change the administrator's password.
D.Modify the cookie value to base64_encode('123:admin') and set it in your browser.
AnswerD

The cookie stores user ID and role in plaintext after base64 decoding. By changing the role to 'admin' and re-encoding, you forge a valid cookie. The server does not verify integrity, so it accepts the tampered value, granting administrative access. This is a classic insecure direct object reference combined with cookie tampering.

Why this answer

The cookie contains base64-encoded user ID and role with no signature or encryption. Decoding reveals the format, allowing an attacker to change the role to 'admin' and re-encode. The application trusts the cookie for authorization, so this directly escalates privileges.

Other methods like SQL injection or CSRF are not indicated by the scenario and would not be as straightforward.

Exam trap

The trap here is assuming that base64 encoding provides security or that the cookie is a random session token, when it is actually a predictable, reversible encoding of authorization data.

214
MCQhard

During an internal penetration test, you capture a NetNTLMv2 challenge-response hash from a Windows host. You want to crack it offline to recover the plaintext password. Which tool and mode should you use to maximize efficiency against this hash type?

A.Hashcat with mode 1000 and a mask attack targeting eight-character passwords.
B.John the Ripper with `--format=netntlmv2` and the `--incremental` mode.
C.Use `responder` to relay the hash to another host and gain access without cracking.
D.Hashcat with mode 5600 and a wordlist combined with rule-based mutations.
AnswerD

Hashcat mode 5600 is specifically for NetNTLMv2 hashes. Using a wordlist with rule-based mutations (e.g., best64.rule) increases the likelihood of cracking common password patterns. This approach is efficient because it leverages GPU acceleration and targets the exact hash format. The challenge-response nature of NetNTLMv2 means the hash cannot be used directly for pass-the-hash, so cracking is often necessary to obtain the plaintext for further access.

Why this answer

NetNTLMv2 hashes are challenge-response pairs that cannot be used directly for pass-the-hash. To recover the plaintext, offline cracking is required. Hashcat mode 5600 is designed for NetNTLMv2, and combining a wordlist with rules significantly improves success rates by mimicking common password transformations.

Other modes or tools may work but are less efficient or incorrect for this hash type.

Exam trap

The trap here is selecting the wrong Hashcat mode (e.g., 1000 for NTLM) or assuming that relaying the hash recovers the password.

215
MCQmedium

When exploiting a service via 'Modify' permissions on its binary, why is it necessary to restart the service?

A.To refresh the file system cache.
B.To trigger the execution of the new binary.
C.To bypass the Windows Service integrity check.
D.To allow the service to read the new configuration.
AnswerB

The Service Control Manager only executes the binary when the service is started. Replacing the file does not affect the currently running process. A restart is required to stop the original binary and initiate the new one, which allows the attacker's code to run as the service user.

Why this answer

Services run as long-lived processes. When the service starts, the binary is loaded into memory and executed. If you replace the binary while the service is running, the old process remains active.

Restarting the service forces the Service Control Manager to stop the original process and start the new, modified binary, thereby executing your malicious code in the process space of the service.

Exam trap

Candidates assume replacing a binary on disk immediately changes the running process behavior without realizing the old instance remains loaded in memory.

216
MCQmedium

During an internal assessment you run a TCP SYN scan and note that a host responds with an RST/ACK for every probed port. What does this behavior most reliably indicate about the target host?

A.The host is up and reachable, but no TCP listeners are present on the probed ports.
B.The target is running an IDS that spoofs resets to mislead the scanner.
C.The probed ports are open but the services are refusing the connection.
D.A stateful firewall is silently dropping the probe packets before they reach the host.
AnswerA

An RST/ACK reply to a SYN means the host's TCP stack is alive and actively rejecting the connection because no process is bound to that port. This is the canonical 'closed port' response and confirms host reachability, which is why filtered versus closed distinctions matter so much during enumeration.

Why this answer

A TCP RST/ACK in response to a SYN is the standard signal of a closed but reachable port, because the kernel answers on behalf of a port with no bound listener. It confirms the host is alive and the path is unfiltered, letting you distinguish closed ports from filtered ones and focus subsequent service enumeration on ports that actually return SYN/ACK.

Exam trap

The trap here is assuming any reply means the port is open, when a reset confirms the opposite: the host is alive but nothing is listening.

217
MCQmedium

Which of the following is the most effective way to prevent Cross-Site Scripting (XSS) in a web application?

A.Using a blacklist to filter out common JavaScript keywords.
B.Implementing context-aware output encoding for all user-supplied data.
C.Disabling all JavaScript in the user's browser settings.
D.Setting all cookies with the 'Secure' flag in the response header.
AnswerB

Context-aware encoding ensures that data is neutralized based on where it is displayed—HTML body, attribute, or JavaScript. By correctly encoding characters like '<', '>', and quotes, the browser is instructed to display the input literally rather than executing it, which is the standard defensive requirement.

Why this answer

The most effective defense against XSS is context-aware output encoding. By converting special characters into their HTML entity equivalents before rendering, you ensure the browser treats the input as data rather than executable code. This is a critical security practice because it handles the root cause of the vulnerability—the browser's inability to distinguish between intended content and injected malicious scripts, regardless of the user input provided.

Exam trap

Test-takers frequently select input validation or sanitization instead of context-aware output encoding, misunderstanding that prevention must occur when data is rendered in the browser.

218
MCQmedium

What is the most likely security risk associated with the configuration shown in the exhibit?

A.The server will allow remote code execution through the index file.
B.Attackers can browse the directory and discover sensitive files.
C.The configuration will prevent users from accessing any files.
D.The server will stop processing PHP files entirely.
AnswerB

Enabling directory indexes allows the server to generate a listing of all files in a directory. This often reveals sensitive files like config.php, database dumps, or backup files that the administrator forgot to remove, giving the attacker a roadmap for further exploitation of the application.

Why this answer

The 'Indexes' option enables directory listing, allowing attackers to browse the web server's file system if no index file is present. This is a significant information disclosure vulnerability because it exposes sensitive configuration files, backups, and source code that were never intended for public view. Disabling directory browsing is a fundamental hardening step for any web server to prevent accidental leakage of proprietary or sensitive infrastructure information.

Exam trap

Candidates sometimes confuse directory listing with Remote Code Execution or SQL injection, missing that exposed indexes primarily facilitate direct information disclosure of sensitive files.

219
MCQmedium

You have a low-privileged shell on a Windows 10 machine. While enumerating, you find that the folder C:\Program Files\CustomApp is writable by the Everyone group. Inside, there is an executable named updater.exe that is run as a service with SYSTEM privileges. However, the service is currently stopped. You want to escalate privileges by replacing updater.exe with a malicious binary. What is the most reliable way to ensure your malicious binary is executed with SYSTEM privileges?

A.Replace updater.exe and wait for the system to reboot, as services are automatically started on boot.
B.Replace updater.exe and then use `schtasks /run /tn <servicename>` to trigger the service.
C.Replace updater.exe with your malicious executable and then start the service using `sc start <servicename>`.
D.Replace updater.exe and then use `wmic service where name='<servicename>' call startservice`.
AnswerC

The service executable is run with SYSTEM privileges. By replacing the binary and starting the service, your malicious code executes as SYSTEM. Since the service is stopped, you can overwrite the file and then start it. This is a direct and reliable method.

Why this answer

When a service binary is in a writable directory, replacing it with a malicious executable and then starting the service will run the payload as SYSTEM. Because the service is stopped, you can overwrite the file without issues. Using `sc start` is the direct way to trigger execution.

Waiting for a reboot is uncertain, and schtasks is for scheduled tasks, not services.

Exam trap

The trap here is overcomplicating the service start method or assuming a reboot is necessary, when simply starting the service with `sc start` is sufficient and reliable.

220
MCQmedium

When performing a DCSync attack, what is the core mechanism being exploited?

A.The Kerberos ticket granting service process
B.The Active Directory Replication Service (DRS) protocol
C.The LDAP signing enforcement on the Domain Controller
D.The storage of passwords in the SYSVOL share
AnswerB

DCSync uses the DRS protocol to request that a domain controller send account data, including password hashes, as if it were performing a legitimate replication operation. This allows an attacker to dump credentials for any user in the domain without ever needing to log into the domain controller itself.

Why this answer

DCSync exploits the Active Directory replication protocol. By mimicking the behavior of a domain controller, an attacker can request that another domain controller replicate user credentials, including password hashes, to them. This requires the attacker to hold 'Replication-Get-Changes' and 'Replication-Get-Changes-All' permissions, which are typically only held by domain controllers or highly privileged administrators, making it a powerful tool for dumping the entire domain's secrets.

Exam trap

Candidates often confuse DCSync with standard credential dumping from memory. DCSync specifically targets the replication protocol to pull secrets directly from a Domain Controller, not from a local workstation's memory.

221
MCQeasy

What is the primary purpose of an exploit payload in a buffer overflow context?

A.To increase the size of the target buffer.
B.To crash the application for a denial-of-service attack.
C.To execute arbitrary commands on the target system.
D.To bypass the authentication mechanism of the application.
AnswerC

The shellcode within the payload is designed to perform a specific task, such as opening a network port or running an OS command. Once the CPU is redirected to the shellcode, it runs with the privileges of the application, effectively giving the attacker control over the system as intended by the exploit.

Why this answer

The exploit payload is the set of instructions (often shellcode) that you want the CPU to execute once you have successfully redirected the program's control flow. The goal is to perform an action, such as spawning a reverse shell or executing a command. The entire process of finding an offset and overwriting the return address is merely the delivery vehicle for this payload, which provides the desired post-exploitation access.

Exam trap

Many candidates confuse the exploit payload with the offset calculation or the return address overwrite mechanism, missing that the payload is the actual functional code executed post-hijack.

222
MCQhard

You are adapting a public exploit whose payload is a reverse shell. The exploit runs and the service reports success, but your netcat listener never receives a connection. Which cause is most likely?

A.Netcat is not capable of receiving reverse shells and a different listener is required.
B.The target's outbound firewall blocks the callback port, or the payload is calling back to an address the target cannot route to.
C.The exploit's buffer overflow offset is incorrect, so the payload never reaches the instruction pointer.
D.The exploit was run without administrative privileges on the attacker machine, preventing the listener from binding.
AnswerB

A successful exploit trigger with no callback almost always means the payload executed but its network path failed. Outbound filtering on the target or a payload pointing at an unreachable address prevents the reverse connection even though the vulnerability was exploited, which matches the observed success-without-shell behavior exactly.

Why this answer

When exploitation succeeds but no callback arrives, the network path from target to listener is the prime suspect. Outbound firewall rules or a payload addressed to an unroutable interface stop the reverse shell even though the vulnerability was triggered. Offset errors would crash the service, netcat is a valid listener, and high-port binding needs no elevated privileges.

Exam trap

The trap here is assuming the exploit failed at the memory-corruption stage when the service already reported success, pointing instead to the callback network path.

223
Multi-Selectmedium

You are performing a password spraying attack against an Active Directory environment. To avoid locking out accounts, which TWO of the following practices should you follow? (Choose two.)

Select 2 answers
A.Use a large list of common passwords for each account.
B.Attempt multiple passwords per account in quick succession.
C.Use a single password attempt per account per lockout window.
D.Target only accounts that have never logged in.
E.Monitor the domain's lockout policy and adjust attempts accordingly.
AnswersC, E

Password spraying aims to avoid lockouts by trying one password against many accounts, then waiting before trying another password. Using a single attempt per account per lockout window respects the lockout threshold, minimizing the risk of locking accounts. This is a core principle of password spraying.

Why this answer

Password spraying avoids lockouts by limiting attempts per account. Using a single attempt per lockout window and monitoring the lockout policy are both critical. Attempting multiple passwords per account or using large password lists increases lockout risk.

Targeting only never-logged-in accounts is irrelevant to lockout avoidance. Thus, the correct practices are to use one attempt per window and to monitor the policy.

Exam trap

The trap here is confusing password spraying with brute-forcing, leading to the selection of practices that actually increase lockout risk.

224
MCQmedium

During an engagement, you capture an AS-REP response from the domain controller. What is the specific prerequisite for this account to be vulnerable to AS-REP Roasting?

A.The account must have a Service Principal Name (SPN) set in the domain properties.
B.The account must have the 'Do not require Kerberos pre-authentication' option enabled.
C.The user must be a member of the Domain Admins or Enterprise Admins group.
D.The account must be configured with a password that has never been rotated.
AnswerB

This setting is the primary vulnerability that makes AS-REP Roasting possible. When disabled, the domain controller sends an encrypted TGT without verifying the user's password first. This encrypted ticket can then be captured and cracked offline, making it a highly effective method for gaining access to user accounts.

Why this answer

AS-REP Roasting is possible when a user account has the 'Do not require Kerberos pre-authentication' attribute enabled in Active Directory. This allows an attacker to request a ticket for the user without needing the correct password, which can then be cracked offline. Understanding this specific AD attribute is critical for identifying vulnerable accounts during internal reconnaissance, as it represents a significant misconfiguration that simplifies the path to credential recovery.

Exam trap

Students frequently confuse AS-REP Roasting with Kerberoasting, incorrectly looking for Service Principal Names (SPNs) instead of checking for the specific pre-authentication disabled attribute on user accounts.

225
MCQmedium

During an external penetration test, you discover a web application that uses a JSON Web Token (JWT) for authentication. The token header is {"alg":"HS256","typ":"JWT"}, and you have captured a valid token. You want to escalate privileges by modifying the "role" claim from "user" to "admin". Which action would most likely allow you to forge a valid token?

A.Change the "alg" value to "none" and remove the signature, then send the token.
B.Brute-force the HMAC secret used to sign the token, then re-sign the modified token.
C.Modify the "role" claim and recompute the signature using the original token's signature as the key.
D.Change the "alg" value to "RS256" and sign the token with the public key.
AnswerB

With HS256, the token is signed using a symmetric secret. If the secret is weak or guessable, an attacker can brute-force it offline using tools like hashcat or john. Once the secret is recovered, the attacker can modify the "role" claim and generate a valid signature, forging an admin token. This is a common and effective attack when the secret is not strong.

Why this answer

The JWT is signed with HS256, meaning a symmetric secret is used. If that secret is weak, an attacker can crack it offline and then sign arbitrary tokens. Changing the algorithm to "none" might work only if the server is misconfigured, but brute-forcing the secret is a direct and reliable method when the secret is guessable.

The other options either rely on server misconfigurations or incorrect cryptographic assumptions.

Exam trap

The trap here is assuming that changing the algorithm to "none" always works, when in fact most modern JWT libraries reject unsigned tokens by default.

Page 2

Page 3 of 4

Page 4

All pages