Courseiva

OffSec PEN-200 / OSCP Concepts (PEN-200) — Questions 226–285

285 questions total · 4pages · All types, answers revealed

Page 3

Page 4 of 4

226
MCQmedium

You are exploiting a 32-bit Windows application that reads a line of input into a 256-byte stack buffer using a vulnerable function. After sending a payload of 300 'A' characters, the application crashes and the debugger shows EIP contains 0x41414141. You need to determine the exact number of bytes from the start of the buffer to the saved return address. Which approach is most appropriate?

A.Incrementally increase the number of 'A' characters until the application crashes, then subtract 4 from the total length.
B.Send a payload of 256 'A's followed by 4 'B's and check if EIP contains 0x42424242.
C.Use a debugger to inspect the stack and manually count the bytes between the start of the buffer and the saved return address.
D.Send a unique, non-repeating pattern of characters (e.g., generated by pattern_create) and calculate the offset from the value in EIP.
AnswerD

A non-repeating pattern allows you to correlate the overwritten EIP value with the exact offset in the buffer. Tools like pattern_create.rb from Metasploit generate such a pattern, and pattern_offset.rb reveals the distance. This is the standard method to find the precise offset to the return address in a stack-based buffer overflow.

Why this answer

The pattern-based approach is the de facto standard for determining the offset to the return address in a buffer overflow. By sending a unique cyclic pattern, the overwritten EIP value directly maps to a specific offset, which can be calculated with pattern_offset. This method is reliable because it does not rely on assumptions about stack layout and works even when the buffer size is not exactly known.

Exam trap

The trap here is assuming that the saved return address is always exactly 4 bytes after the buffer, ignoring possible saved registers or alignment padding that can shift the offset.

227
MCQmedium

You have compromised a Linux jump host and need to access an internal web application on 192.168.1.50:80 that is firewalled from your local machine. You have SSH access to the jump host. Which command should you execute on your local machine to securely access the application via your browser?

A.ssh -R 8080:192.168.1.50:80 user@jump-host
B.ssh -D 8080 user@jump-host
C.ssh -L 8080:192.168.1.50:80 user@jump-host
D.ssh -fN -L 192.168.1.50:80:8080 user@jump-host
AnswerC

Local port forwarding uses the -L flag to map a local port (8080) to the destination internal IP and port (192.168.1.50:80). This connection is tunneled through the SSH session, allowing you to access the web application by pointing your local web browser to http://127.0.0.1:8080, effectively bypassing the firewall limitations.

Why this answer

Local port forwarding allows you to tunnel traffic from a local port to a destination reachable by the SSH server. By mapping a local port to the internal web server's address, you bypass network restrictions imposed by firewalls. This technique is fundamental for pivoting through compromised hosts, enabling tools like Burp Suite or browsers to interact with internal services as if they were running locally, which is vital for further web application vulnerability assessment.

Exam trap

Candidates often mix up the local and remote port numbers in the -L command syntax, leading to connection failures because the local port is not bound to the intended target service.

228
MCQeasy

When fuzzing an application to identify a buffer overflow, what is the most common symptom indicating that the application's memory boundaries have been exceeded?

A.The application begins to consume high CPU resources
B.The application returns an 'Access Violation' or 'Segmentation Fault'
C.The application prints a stack dump to the console
D.The application generates a new network port listener
AnswerB

When an overwrite corrupts the saved return address, the CPU eventually attempts to return to an address that is not valid or mapped, resulting in an immediate crash. This exception is the standard indicator for a successful fuzzer trigger, confirming the boundary has been exceeded and control is potentially lost.

Why this answer

Fuzzing involves sending large amounts of data to an application to find stability issues. The most common indicator of a buffer overflow is the application crashing, specifically resulting in a segmentation fault or an access violation. This occurs because the injected data has overwritten critical stack memory, such as the return address, causing the CPU to attempt an execution from an invalid or unauthorized memory location.

229
MCQeasy

A tester is preparing a reverse shell executable for a Windows target protected by a signature-based antivirus product. To reduce the chance the file is flagged, the tester wants to modify the binary so it no longer matches known signatures while keeping its behavior. Which action best accomplishes this?

A.Run the executable with administrator privileges so it can bypass user-level scanning hooks.
B.Move the executable from the Downloads folder to a less commonly scanned directory such as C:\Temp.
C.Change the file's icon and version information resource to mimic a legitimate application.
D.Recompile the source after renaming functions and adding benign junk instructions, then rebuild the binary.
AnswerD

Static signatures often include byte sequences from compiled code, strings, and payload data. Renaming functions and inserting junk instructions alters the compiled output's byte layout and instruction sequence while preserving the program's logic. Rebuilding produces a new binary whose bytes no longer match the original signature, which directly addresses signature matching without changing behavior, matching the tester's stated goal.

Why this answer

Signature-based detection compares file bytes against known patterns derived from code, strings, and embedded payloads. Altering the source so the compiled binary's byte sequence changes, such as renaming functions and inserting junk instructions, breaks that match while preserving functionality. Metadata edits, directory changes, and privilege elevation leave the underlying bytes intact, so the original signature continues to identify the file.

Exam trap

The trap here is believing that cosmetic metadata like icons or version strings, or the file's location, affects content-based signature matching when scanners examine the executable's bytes.

230
MCQmedium

During a Linux privilege escalation assessment, you discover that the current user can run `/usr/bin/find` via sudo without a password. You execute `sudo find /home -exec /bin/bash \;`. What is the outcome?

A.A root shell is spawned because find's -exec runs the command as the invoking user, not root.
B.The command fails because find does not allow -exec to run shell commands.
C.A root shell is spawned only if the current user is a member of the sudo group.
D.A root shell is spawned because sudo runs find as root, and -exec executes /bin/bash with root privileges.
AnswerD

This is correct. When sudo executes find as root, the find process runs with an effective UID of 0. The -exec action forks and executes /bin/bash as a child of find, inheriting root privileges. Thus, an interactive root shell is obtained. This is a classic GTFOBins technique for privilege escalation.

Why this answer

When a user is allowed to run find with sudo, they can leverage the -exec action to execute arbitrary commands as root. Because the entire find process runs with root privileges, any command spawned by -exec inherits those privileges. This allows an attacker to spawn a root shell, achieving privilege escalation.

Exam trap

The trap here is assuming that -exec drops privileges or runs commands as the original user, when in fact it inherits the effective UID of the find process.

231
MCQhard

Which of the following describes the 'Open Redirect' vulnerability often used in phishing attacks?

A.The application reflects user input into the HTML body, allowing for XSS.
B.The application uses user-supplied parameters to control the destination of a redirect.
C.The application fails to set the Secure flag on cookies during redirection.
D.The application allows arbitrary file uploads to the server's redirect directory.
AnswerB

Open redirect occurs when an application uses an untrusted input parameter to define where to send the user next. Without validation, an attacker can supply a malicious URL. The application then performs the redirect, lending its own reputation to the attack and increasing the likelihood of success.

Why this answer

Open Redirect occurs when an application accepts user-supplied input to determine a destination URL without validating it against a whitelist. Attackers exploit this to redirect users to a malicious site. Because the URL starts with the trusted domain, victims are less likely to suspect a phishing attempt, making it a highly effective social engineering technique to steal credentials or deliver malware.

232
MCQmedium

You are analyzing a binary and identify a function that uses strcpy() to copy user input into a fixed-size stack buffer. Which register must be controlled to redirect the instruction pointer to your shellcode?

A.The ESP register
B.The EAX register
C.The saved Return Address on the stack
D.The EBP register
AnswerC

The saved Return Address sits just above the local variables on the stack. When the function epilogue executes, the CPU performs a RET instruction, which pops this specific stack value directly into the EIP register. Controlling this value is the direct way to hijack the program control flow.

Why this answer

To redirect the execution flow, you must overwrite the saved Return Address on the stack. When a function finishes, the CPU pops the value at the saved EIP/RIP location into the Instruction Pointer. By overflowing the buffer and reaching this specific memory location, you gain control over the program's subsequent execution path, which is the foundational concept for stack-based buffer overflow exploitation in the PEN-200 curriculum.

Exam trap

Candidates often confuse the EIP/RIP register with the stack pointer (ESP/RSP). They forget that the return address on the stack is what determines the next instruction pointer value.

233
MCQhard

Refer to the exhibit. You are running a public exploit, but it fails with a 'Connection refused' error. What should you investigate first?

A.The exploit's payload encoding settings.
B.The service availability and network path to the target.
C.The exploit's memory address offsets.
D.The target's operating system version.
AnswerB

Before troubleshooting the exploit, you must confirm the service is actually listening on the target port. A 'Connection refused' error suggests the port is closed or filtered. Verifying network connectivity ensures you are not wasting time on an exploit that has no chance of succeeding.

Why this answer

A 'Connection refused' error usually indicates that the target port is not open, the service is not running, or a firewall is blocking the connection. Investigating the network connectivity and service status using tools like Nmap or netcat is essential. This allows you to confirm the service is actually reachable and running on the expected port before assuming the exploit itself is flawed or the payload is failing.

Exam trap

Candidates often immediately assume their payload syntax or exploit code is broken when seeing a 'Connection refused' error, rather than checking if the port is even open or firewalled.

234
MCQmedium

You are assessing a Windows host and discover the Print Spooler service is running. You locate a public PoC for CVE-2021-1675 that requires an attacker-controlled SMB share hosting a malicious DLL. You want to execute the exploit from your Kali machine against the target. Which action must you take FIRST before running the PoC?

A.Upload the DLL to C:\Windows\Temp on the target using an existing low-privilege session.
B.Start a Metasploit handler on port 445 to catch the reverse shell from the Spooler service.
C.Configure a Samba share on your Kali machine with anonymous read access that hosts the malicious DLL.
D.Disable Windows Defender Real-Time Protection on the target through a registry remoting call.
AnswerC

The PrintNightmare PoC relies on the target loading a DLL from a UNC path over SMB. You must host the DLL on an accessible SMB share (e.g., via impacket-smbserver or Samba) with anonymous read so the target's Spooler service can fetch and load it. Without this share, the exploit has no payload delivery mechanism.

Why this answer

The PrintNightmare PoC abuses the Spooler's driver installation to load a DLL from a UNC path. The attacker must therefore host that DLL on an SMB share reachable by the target, typically with anonymous read access. The other options either target the wrong delivery mechanism or assume capabilities the attacker does not yet possess.

Exam trap

The trap here is assuming the DLL must be copied to the target's filesystem, when the exploit actually forces the Spooler to load it directly from an attacker-controlled SMB share.

235
MCQmedium

You have compromised a Linux host that sits on both your external network and an isolated internal network containing a Windows server with SMB exposed. From your Kali machine you need to interact with the SMB service as if it were local. Which single command creates the correct tunnel?

A.ssh -D 445 user@10.10.10.10
B.ssh -R 127.0.0.1:445:10.10.10.20:445 user@10.10.10.10
C.ssh -L 127.0.0.1:445:10.10.10.20:445 user@10.10.10.10
D.ssh -L 0.0.0.0:445:10.10.10.20:445 user@10.10.10.10
AnswerC

This local forward binds port 445 on your own loopback and tunnels traffic through the pivot at 10.10.10.10 to the internal SMB host 10.10.10.20 on port 445. Because the pivot can reach both networks, your SMB client can now connect to 127.0.0.1:445 and reach the internal server without exposing the port on your external interface.

Why this answer

A local port forward created with -L makes your attacking machine listen on a chosen local address and port, then relays that traffic through the SSH server to a destination reachable from the pivot. Binding to 127.0.0.1 keeps the forwarded port private to your host, which is appropriate when only your local tools need to reach the internal SMB service. Remote and dynamic forwards solve different problems and do not give a direct local-to-internal mapping here.

Exam trap

The trap here is confusing the direction of -L and -R, assuming a remote forward will somehow expose an internal service to your local machine.

236
Multi-Selecthard

You have compromised a service account that has the SeEnableDelegationPrivilege right on a domain controller. You want to abuse Kerberos delegation to gain access to a target server's file share. Which two steps are required to configure and exploit unconstrained delegation on a controlled computer object? (Choose two.)

Select 2 answers
A.Configure a Service Principal Name on the controlled computer object for the target file share service (cifs/target).
B.Set the TRUSTED_FOR_DELEGATION flag on the controlled computer object so the domain controller will forward TGTs to it.
C.Modify the msDS-AllowedToDelegateTo attribute on the controlled computer to include the target server's CIFS service.
D.Add the controlled computer to the Protected Users group to ensure delegation tokens are cached securely.
E.Coerce a privileged user to authenticate to the controlled computer so its TGT is captured in memory and can be extracted.
AnswersB, E

Unconstrained delegation requires the TRUSTED_FOR_DELEGATION userAccountControl flag on the computer object. With SeEnableDelegationPrivilege, you can set this flag on a machine you control. The domain controller then includes that computer in the list of services allowed to receive forwarded TGTs, which is the foundational configuration for this attack.

Why this answer

Unconstrained delegation abuse requires two things: enabling the TRUSTED_FOR_DELEGATION flag on a controlled computer so the DC forwards TGTs to it, and coercing a privileged user to authenticate to that computer so a TGT is cached in memory. Extracting the TGT then allows impersonation. The other options describe constrained delegation, an unrelated SPN configuration, or a security control that blocks the attack.

Exam trap

The trap here is confusing unconstrained delegation, which relies on the TRUSTED_FOR_DELEGATION flag and TGT capture, with constrained delegation, which uses msDS-AllowedToDelegateTo and SPNs.

237
MCQeasy

You have obtained a plaintext password for a domain user and want to quickly identify which domain-joined systems the account can access with local administrative rights, without triggering account lockout. Which approach is most appropriate?

A.Use CrackMapExec with the -u and -p options against a list of hosts and the smb module to check for administrative access.
B.Execute BloodHound with SharpHound using the -c Session collection method to enumerate where the user has administrative rights.
C.Use Hydra to brute-force the password against SMB on each host to confirm administrative access.
D.Run Responder on the network to poison LLMNR and capture administrative credentials from other hosts.
AnswerA

CrackMapExec's smb module with valid credentials performs a single authentication attempt per host, checking for administrative access without repeated failed logons. This avoids lockout because it uses the correct password and does not spray. It efficiently identifies which systems grant local admin rights to the compromised account.

Why this answer

CrackMapExec with valid credentials is the standard tool for quickly checking administrative access across many hosts. It performs a single authentication per host using the known password, avoiding lockout, and reports whether the account has local admin rights. Alternatives either risk lockout, capture unrelated credentials, or collect session data that does not directly answer the access question.

Exam trap

The trap here is assuming that brute-forcing or password spraying is needed to test access, when valid credentials should be used directly to avoid lockout and unnecessary noise.

238
MCQmedium

Why are static memory addresses for 'JMP ESP' preferred over dynamic stack addresses?

A.Static addresses are faster to access by the CPU.
B.Static addresses are less likely to contain bad characters.
C.Static addresses remain constant across different executions.
D.Static addresses are protected by DEP and ASLR.
AnswerC

Static addresses in the code segment or imported DLLs do not change between program runs. This consistency makes them ideal for redirecting control flow. Because they are always in the same place, you can be confident that the jump instruction will exist at that location every time the exploit is launched.

Why this answer

Stack addresses change during every execution of a program due to factors like system environment variables and memory allocation. If you use a hardcoded stack address in your exploit, it will likely be invalid the next time the program runs. A static JMP ESP address, found in a loaded DLL or the binary itself, remains constant, providing a reliable and stable redirect for your shellcode execution every time.

Exam trap

Test-takers frequently hardcode dynamic stack memory addresses into their exploits, leading to immediate crashes because stack locations shift across different program executions.

239
MCQmedium

Refer to the exhibit. An analyst observes this response header after a successful login. What is the security implication of the 'HttpOnly' and 'Secure' flags set on the 'session_id' cookie?

A.The flags guarantee protection against all SQL injection.
B.The cookie will be accessible to JavaScript, but not via HTTP.
C.The session is protected against XSS theft and cleartext interception.
D.The cookie will be automatically deleted when the browser closes.
AnswerC

The 'HttpOnly' attribute blocks access to the cookie from JavaScript, preventing XSS-based theft. The 'Secure' attribute ensures the browser only sends the cookie over encrypted HTTPS, preventing it from being intercepted in transit. These controls are standard security practices for mitigating session hijacking and credential exposure in web applications.

Why this answer

These security flags are critical for session hardening. 'HttpOnly' prevents client-side scripts from accessing the cookie via document.cookie, mitigating XSS-based session theft. 'Secure' ensures the cookie is only transmitted over encrypted HTTPS connections, preventing interception via man-in-the-middle attacks. Together, they provide a defense-in-depth layer protecting user session integrity, which is essential for maintaining secure authentication sessions against common web-based attacks during the post-authentication phase of an engagement.

Exam trap

Candidates often mix up the roles of 'HttpOnly' and 'Secure' flags, mistakenly thinking 'Secure' prevents XSS script access rather than mitigating cleartext network interception.

240
MCQeasy

During a penetration test, you discover that a web application uses an outdated version of a JavaScript library that contains a known DOM-based XSS vulnerability. The vulnerability is triggered when a specific URL parameter is processed by the library. Which action would best allow you to demonstrate the impact of this vulnerability to the client?

A.Perform a brute-force attack to guess the victim's credentials and log in as them.
B.Use a web proxy to intercept and modify the library's JavaScript file to include a malicious payload.
C.Craft a URL with a malicious payload in the vulnerable parameter and send it to a victim user.
D.Exploit a SQL injection vulnerability to extract the library's source code and identify the flaw.
AnswerC

Since the vulnerability is DOM-based and triggered by a URL parameter, crafting a URL with a malicious payload and delivering it to a victim will execute the script in the victim's browser when they visit the link. This demonstrates the impact by showing how an attacker could steal data or perform actions. It is a direct proof of concept for reflected DOM-based XSS.

Why this answer

The best action is to craft a URL with a malicious payload in the vulnerable parameter and send it to a victim. Because the vulnerability is DOM-based and triggered by URL parameters, visiting the link executes the payload in the victim's browser. This directly demonstrates the impact, such as session hijacking or data theft, and is a standard proof of concept for DOM-based XSS.

Exam trap

The trap here is overcomplicating the exploitation by using proxies or SQL injection, when the DOM-based XSS can be triggered simply by delivering a crafted URL to a victim.

241
MCQmedium

During a PEN-200 lab, a penetration tester develops a custom C# loader that allocates memory, writes shellcode, and executes it. Windows Defender's AMSI flags the process when the shellcode buffer is passed to a scanning routine. The tester wants to prevent AMSI from inspecting the buffer at runtime without disabling Defender. Which technique should the tester apply?

A.Use the AmsiScanBuffer function's memory patching to force it to return a clean result.
B.Run the loader under a different user account with limited privileges.
C.Base64-encode the shellcode and decode it at runtime before execution.
D.Compile the loader with the /guard:cf flag to enable Control Flow Guard.
AnswerA

Patching AmsiScanBuffer in memory (e.g., by overwriting its first bytes with a return value of S_OK or a benign HRESULT) prevents AMSI from scanning the buffer, effectively bypassing detection without disabling Defender. This is a common in-memory evasion technique taught in PEN-200 for evading AMSI.

Why this answer

AMSI scans buffers passed to functions like AmsiScanBuffer; to evade it without disabling Defender, the tester can patch AmsiScanBuffer in memory to return a benign result. This prevents the shellcode from being flagged. Encoding, CFG, or user privileges do not stop AMSI from scanning the buffer at runtime.

Exam trap

The trap here is assuming that encoding or obfuscating shellcode prevents AMSI from scanning it, when AMSI actually inspects the decoded buffer in memory.

242
MCQmedium

An attacker gains a low-privilege shell on a Windows 10 machine and discovers a third-party service named 'DataSync'. The attacker notes that the service runs as SYSTEM and they have 'FILE_WRITE_DATA' permissions on the service executable 'C:\Program Files\DataSync\sync.exe'. Which action is the most direct method to escalate privileges to SYSTEM?

A.Place a malicious DLL named 'sync.dll' in the 'C:\Windows\System32' directory to intercept calls.
B.Stop the service, replace 'sync.exe' with a malicious payload, and restart the service.
C.Modify the service configuration using 'sc config' to point to a different malicious executable.
D.Create a new service with the same name in the 'HKCU' registry hive to override the system service.
AnswerB

This is the most direct path to escalation when 'FILE_WRITE_DATA' is available. By replacing the service binary, the attacker ensures their code runs with the service's privileges. If the attacker has the rights to stop and start the service, they can trigger the payload execution immediately without needing a full system reboot.

Why this answer

Service binary hijacking is a powerful technique where an attacker replaces a legitimate executable with a malicious one. Since the service runs as SYSTEM, the replaced binary will execute with those high privileges upon the next service start. This method is often more reliable than DLL hijacking because it directly controls the primary execution flow of the service, provided the attacker can restart the service or wait for a system reboot.

Exam trap

Candidates often confuse binary hijacking with DLL hijacking or unquoted service paths. They might look for missing quotes or library search orders instead of checking direct file permissions on the primary executable itself.

243
MCQeasy

Which command-line tool is primarily used during the reconnaissance phase to identify open ports and service versions on a remote target?

A.netcat
B.Nmap
C.Wireshark
D.grep
AnswerB

Nmap is the primary utility for network discovery and security auditing. It offers advanced features like service version detection, operating system fingerprinting, and scriptable automation, making it the most reliable and comprehensive tool available for identifying the services running on a target during the reconnaissance phase of testing.

Why this answer

Nmap is the industry-standard tool for port scanning and service enumeration. By identifying open ports and the software versions running on them, a tester can pinpoint specific vulnerabilities to research. This step is the foundation of the reconnaissance phase, as it maps the target's attack surface and guides the subsequent selection of exploits, ensuring a focused and efficient penetration testing process.

Exam trap

Candidates often confuse Nmap with vulnerability scanners like Nessus or OpenVAS. While Nmap can run scripts, its primary role is port scanning, service detection, and reconnaissance.

244
MCQmedium

A penetration tester has a working PowerShell-based stager that is being blocked by AMSI on a Windows 11 target. The tester wants to keep using PowerShell for convenience but needs the stager to run without AMSI inspecting the script content. Which technique most directly targets AMSI's inspection of the script?

A.Set the PowerShell execution policy to Bypass using the -ExecutionPolicy Bypass parameter.
B.Sign the PowerShell script with a trusted code-signing certificate before execution.
C.Obfuscate the stager and split it across multiple string concatenations and variable substitutions so the script text does not contain recognizable AMSI signatures.
D.Run the stager through a PowerShell downgrade to version 2 using the -Version 2 parameter.
AnswerC

AMSI scans the script content as it is submitted for execution, matching known malicious patterns. If the script is rewritten so that no contiguous string matches an AMSI signature, the scan passes and the script executes. Techniques such as string splitting, character substitution, and dynamic construction change the textual representation while preserving behavior. This directly targets AMSI's pattern-matching inspection of the script.

Why this answer

AMSI inspects PowerShell script content by matching patterns against known malicious code. If the script text no longer contains those patterns, the inspection passes. Obfuscation through string splitting, concatenation, and dynamic construction changes the textual form while preserving the executed logic, so the stager runs.

Execution policy and code signing are separate controls, and version downgrade is unreliable on patched Windows 11 systems where AMSI enforcement is not tied to the PowerShell version.

Exam trap

The trap here is assuming that bypassing execution policy or using an older PowerShell version will also bypass AMSI, when AMSI inspects script content independently of those controls.

245
MCQeasy

You identify a cron job running as root that executes a script located in a writable directory. What is the most reliable way to escalate privileges in this scenario?

A.Modify the /etc/shadow file directly.
B.Append a reverse shell command to the writable script.
C.Restart the crond service to force execution.
D.Change the ownership of the script using chmod.
AnswerB

Appending a reverse shell payload to a script executed by a root cron job ensures the shell executes with root authority. This is a standard privilege escalation technique because cron jobs typically run with the permissions of the user who owns them, which is root in this specific scenario.

Why this answer

When a cron job runs as root, any script it executes also runs with root privileges. If the script is writeable by a low-privileged user, it can be modified to include a reverse shell. This is a common misconfiguration that highlights the importance of checking file permissions and cron job schedules during the post-exploitation phase of a penetration test or a professional security assessment.

Exam trap

Candidates often attempt to replace the entire script file, which may trigger file integrity monitors. Appending the command is often stealthier and sufficient to gain the reverse shell.

246
MCQeasy

When reviewing 'sudo -l' output, what does the 'NOPASSWD' tag signify for the listed command?

A.The user is automatically added to the root group.
B.The command can be run as root without entering a password.
C.The command is not logged by the system administrator.
D.The command will run in a sandbox for security.
AnswerB

NOPASSWD specifically bypasses the sudo password prompt for the defined command. This allows the user to execute the command with the elevated privileges defined in the sudoers file instantly. This is a primary target during privilege escalation, as it simplifies the path to root significantly.

Why this answer

The 'NOPASSWD' tag indicates that the user can execute the specified command with sudo privileges without being prompted for their own password. This is a critical misconfiguration, as it removes the authentication barrier for privilege escalation. In an attack scenario, it allows for immediate, automated execution of commands as root, which is significantly more dangerous than configurations that still require a user to authenticate via their password.

Exam trap

Candidates often confuse NOPASSWD with a general sudo privilege. The trap is failing to realize that this specific tag bypasses the password prompt entirely, allowing for immediate execution of commands.

247
MCQeasy

During a penetration test, you need to enumerate DNS records for the domain `example.com` to find subdomains and mail servers. Which command should you use to perform a zone transfer attempt?

A.`nslookup -type=any example.com`
B.`host -l example.com ns1.example.com`
C.`dnsenum --enum example.com`
D.`dig axfr @ns1.example.com example.com`
AnswerD

The `axfr` option in `dig` requests a full zone transfer from the specified name server. If the server is misconfigured to allow transfers from any host, it will return all DNS records for the domain, revealing subdomains, mail servers, and other hosts. This is the standard command for attempting a zone transfer.

Why this answer

The `dig axfr` command is the direct way to request a zone transfer from a name server. It targets the specific DNS server and domain, and if the server allows transfers, it returns the full zone file. Other commands may perform DNS queries but do not explicitly request a zone transfer.

Exam trap

The trap here is confusing general DNS enumeration tools with the specific AXFR query needed for a zone transfer attempt.

248
MCQmedium

You are performing a network scan on a target network and notice that ICMP echo requests are blocked, but you need to determine if the target host is alive. Which technique should you utilize to identify active hosts without relying on standard ICMP ping?

A.Send a UDP packet to port 53 and wait for a DNS response.
B.Perform a TCP SYN scan on common ports such as 80, 443, and 22.
C.Use ARP scanning regardless of the network topography.
D.Send a broadcast ping to the entire subnet range.
AnswerB

TCP SYN scanning to common ports reliably confirms host activity by triggering a response from the TCP/IP stack. Since most servers run these services, the receipt of a SYN/ACK or RST packet acts as a definitive indicator that the host is reachable, bypassing the need for ICMP connectivity.

Why this answer

When ICMP is filtered by firewalls, TCP SYN scanning on common ports like 80 or 443 is an effective alternative for host discovery. This technique works because the target system responds to a SYN packet with a SYN/ACK if the port is open, or an RST if closed, confirming the host's presence. Mastering non-ICMP discovery is critical for bypass techniques in hardened network environments where security policies block traditional discovery methods.

Exam trap

Candidates often assume that if ICMP ping fails, the target host is completely dead and abandon further testing, forgetting that firewalls frequently block ICMP echo requests.

249
MCQmedium

Why might a public exploit for a specific service fail to execute even when the service version matches the vulnerability description exactly?

A.The exploit code is always written in an incompatible shell format.
B.The target environment has different memory protections or patch levels.
C.Public exploits are intentionally corrupted to prevent usage.
D.You forgot to increase the network timeout settings.
AnswerB

Memory protections like ASLR and DEP are common on modern systems and can prevent standard exploit payloads from executing. Even with the same service version, different patch levels or underlying OS configurations significantly alter the target environment, causing the original exploit code to fail consistently on your target.

Why this answer

Public exploits are typically written against a specific environment, which may differ from your target's configuration. Variations in operating systems, patch levels, installed libraries, or memory protection mechanisms like ASLR and DEP can prevent the exploit from succeeding. Understanding these environmental dependencies is key to troubleshooting failed exploits, as it often requires you to manually port or adjust the exploit to fit the target's unique security posture.

Exam trap

Candidates frequently assume that if a service version matches a public exploit exactly, it will work out-of-the-box without verifying memory protections, OS architecture, or specific patch levels.

250
MCQmedium

During an authorized penetration test, you deliver a malicious script to a victim's browser by exploiting a reflected XSS vulnerability. The script executes in the context of the vulnerable application and silently sends a crafted HTTP request to the application's password-change endpoint. The victim is currently authenticated. Which client-side attack technique are you performing?

A.Cross-Site Scripting (XSS)-based request forgery
B.DOM-based XSS
C.Cross-Site Request Forgery (CSRF)
D.Clickjacking
AnswerA

By leveraging XSS to execute JavaScript in the victim's browser, you can read anti-CSRF tokens and craft a legitimate-looking request to the password-change endpoint. This technique, often called XSS-based CSRF or script-driven request forgery, bypasses token protections because the script can extract the token from the page. It is a client-side attack that combines XSS with request forgery.

Why this answer

The correct technique is XSS-based request forgery, where JavaScript executed via XSS in the victim's browser is used to send authenticated requests to the application. Because the script runs in the origin of the vulnerable site, it can read anti-CSRF tokens and include them in the forged request, defeating typical CSRF protections. This is a client-side attack that combines script execution with request forgery.

Exam trap

The trap here is assuming that any request forgery involving a victim's browser is pure CSRF, ignoring that the presence of script execution via XSS changes the attack class and bypasses token defenses.

251
MCQeasy

A penetration tester has compromised a Linux host and wants to use it as a pivot to reach an internal network. The tester decides to use SSH local port forwarding to access an internal web server at 10.0.0.5:80 from their attacking machine. Which command should the tester run on the attacking machine?

A.ssh -D 8080 user@pivot
B.ssh -R 8080:10.0.0.5:80 user@pivot
C.ssh -L 8080:10.0.0.5:80 user@pivot
D.ssh -L 10.0.0.5:80:8080 user@pivot
AnswerC

This command creates a local port forward: the attacking machine listens on port 8080 and forwards any connections through the SSH tunnel to the pivot host, which then connects to 10.0.0.5:80. This allows the tester to access the internal web server by browsing to localhost:8080 on their machine.

Why this answer

Local port forwarding with SSH uses the -L local_port:remote_host:remote_port syntax. The attacking machine listens on the local port and forwards connections through the SSH tunnel to the pivot, which then connects to the specified remote host and port. This is the standard way to access an internal service from an external machine.

Exam trap

The trap here is mixing up local and remote port forwarding, or misordering the parameters in the -L option, which can lead to a non-functional tunnel or an error.

252
MCQhard

During an internal assessment, you find a public exploit for a Jenkins script console vulnerability. The exploit sends a Groovy script to /script via a POST request. When you run it, the server returns HTTP 403. The Jenkins version matches the vulnerable range, and the endpoint is reachable. Which is the MOST likely reason the exploit fails?

A.The exploit requires an authenticated session, and the request is being rejected due to missing or invalid credentials.
B.The target uses HTTPS and the exploit is sending plaintext HTTP requests to port 8080.
C.The Groovy script contains syntax errors that Jenkins rejects at parse time.
D.The Groovy payload is blocked by a Web Application Firewall rule matching common reverse-shell strings.
AnswerA

The Jenkins script console at /script requires authentication and administrative privileges. An unauthenticated POST returns 403. The exploit likely expects a valid session cookie or API token. Without it, Jenkins denies access before evaluating the Groovy code, regardless of version. Supplying valid credentials or a token is the necessary fix.

Why this answer

Jenkins protects the script console with authentication and authorization. Even on a vulnerable version, an unauthenticated request to /script is rejected with 403 before any Groovy executes. The exploit must include a valid session or API token belonging to a user with administrative rights.

Version matching alone does not bypass access controls.

Exam trap

The trap here is assuming that a version match guarantees exploitability, when access controls can block the request before the vulnerable code is ever reached.

253
MCQmedium

You have identified an open port 445 on a Windows machine. Which tool is most effective for checking if the machine is vulnerable to common SMB-based exploits like EternalBlue?

A.Use ping to verify the host is reachable.
B.Use Nmap with the --script smb-vuln-ms17-010 argument.
C.Run a full Nessus scan against the IP.
D.Use telnet to manually send an exploit string.
AnswerB

The Nmap NSE script smb-vuln-ms17-010 is specifically written to detect the EternalBlue vulnerability. It performs a safe check by interacting with the SMB service to see if it responds in a way that indicates the vulnerability, providing a fast and accurate assessment during the reconnaissance phase of the test.

Why this answer

Nmap's scripting engine (NSE) is the most effective way to check for specific vulnerabilities like EternalBlue without requiring a full-scale vulnerability scanner. The 'smb-vuln-ms17-010' script is specifically designed to detect this vulnerability. Using such targeted scripts allows for accurate assessment with minimal footprint, which is a hallmark of professional penetration testing practices, ensuring the system's security posture is evaluated safely and effectively during the reconnaissance phase.

Exam trap

Candidates often suggest using Nessus or OpenVAS, which are full-scale scanners. The question specifically asks for a tool to check for a single exploit, making targeted Nmap scripts the preferred answer.

254
Multi-Selectmedium

You need to fingerprint the web server technology behind an HTTP service without sending malformed or intrusive requests. Which two actions best accomplish passive-leaning banner and behavior fingerprinting during enumeration? (Choose two.)

Select 2 answers
A.Send a buffer of several thousand bytes in the request line to provoke a crash signature.
B.Inspect the Server and X-Powered-By response headers returned in the HTTP reply.
C.Request a deliberately nonexistent path and analyze the structure of the resulting error page.
D.Run a full TCP port scan of all 65535 ports on the host to infer the web stack.
E.Attempt default administrative credentials against the web login form.
AnswersB, C

Response headers often disclose the web server software, version, and backend language runtime. Reading them requires only a normal request, so it is low-risk and directly identifies the technology stack. This makes header inspection a foundational, non-intrusive fingerprinting step that frequently narrows the target's platform before deeper probing.

Why this answer

Header inspection and error-page analysis both identify server technology using ordinary, non-destructive requests. Headers may name the server and runtime directly, while distinctive 404 templates expose the stack when banners are hidden. Together they fingerprint the web service safely, whereas crash attempts, full port sweeps, and credential guessing are intrusive or simply unrelated to identifying the technology.

Exam trap

The trap here is equating aggressive probing such as crash attempts or credential guessing with fingerprinting, when simple headers and error pages already reveal the stack.

255
MCQmedium

You are attempting to escalate privileges on a Windows target and decide to exploit unquoted service paths. You find a service with the binary path `C:\Program Files\My App\service.exe` and the service is running as LocalSystem. Which condition must be true for this unquoted path to be exploitable?

A.The service must be configured to run as a domain user with a weak password that can be cracked.
B.A directory like `C:\Program.exe` or `C:\Program Files\My.exe` must be writable by your user, and the service must restart.
C.The service must have the `SeImpersonatePrivilege` enabled for the LocalSystem account.
D.The directory `C:\Program Files\My App` must have Modify permissions for the Everyone group.
AnswerB

Unquoted service paths are exploited by placing a malicious executable in a directory that Windows will search before reaching the intended binary. For the path `C:\Program Files\My App\service.exe`, Windows will try `C:\Program.exe`, then `C:\Program Files\My.exe`, and so on. If any of those locations are writable and the service restarts, your executable runs as LocalSystem.

Why this answer

For an unquoted service path to be exploitable, a writable directory must exist in the search order before the intended executable, such as `C:\Program.exe` or `C:\Program Files\My.exe`. When the service starts, Windows will execute the first found executable from that path. If you can place a malicious binary in a writable location and the service restarts, you gain code execution as the service account.

Exam trap

The trap here is assuming that write access to the service's own directory is required, when actually the vulnerability lies in writable parent directories due to missing quotes.

256
MCQmedium

During a PEN-200 lab exercise, you find a public exploit for a Windows service. The exploit source contains a hardcoded return address of 0x41414141 and a comment that it was tested against a different Windows build with ASLR disabled. What should you do before running it against your target?

A.Run the exploit as-is and observe the target's behavior to determine whether ASLR is enabled.
B.Replace the hardcoded return address with a NOP sled of equivalent length and rerun the exploit.
C.Recompile the exploit with a debugger, identify the correct return address for this target, and update the payload accordingly.
D.Disable ASLR on the target by editing the system registry, then run the exploit unchanged.
AnswerC

The hardcoded address and the note about ASLR being disabled on a different build indicate the exploit must be retargeted. By attaching a debugger such as Immunity Debugger or WinDbg, determining the actual return address and offset for your specific Windows build, and updating the payload, you adapt the exploit to the target's memory layout. This is the standard PEN-200 approach for porting public exploits.

Why this answer

A public exploit with a hardcoded return address and a note about ASLR being disabled on a different build is not portable as-is. The reliable path is to debug the target process, calculate the correct offset and return address for the specific Windows build, and update the exploit's payload. Blindly running it risks a crash, and altering the target's ASLR configuration is neither appropriate nor feasible without prior access.

Exam trap

The trap here is assuming a public exploit will work unchanged against any Windows build, ignoring the fact that return addresses and ASLR settings are build-specific.

257
MCQeasy

You have a Windows host with outbound internet access but want to avoid installing a full agent. You decide to use Chisel to pivot. Which statement accurately describes how Chisel establishes the tunnel in this scenario?

A.Chisel encrypts traffic only when the --tls flag is used, and otherwise sends plaintext over the wire.
B.The Chisel server must run on the compromised host so the client on your attacking machine can pull traffic from the internal network.
C.The Chisel client on the compromised host connects outbound to the Chisel server on your attacking machine, and the server can expose a SOCKS proxy on your side.
D.Chisel requires a kernel TUN interface on both endpoints to carry the tunneled traffic.
AnswerC

Chisel uses a client-server model where the client dials the server. Running the server with reverse tunneling and SOCKS options lets the server-side listener present a SOCKS proxy on your attacking machine, while the client on the victim maintains the outbound connection. This fits hosts that cannot accept inbound connections.

Why this answer

Chisel's client dials the server, so a compromised host with only outbound access can still establish a tunnel. When the server is started with reverse tunneling and SOCKS support, the operator gets a SOCKS proxy locally that routes through the client into the internal network. This makes Chisel a practical choice when a full agent is undesirable.

Exam trap

The trap here is reversing the client and server roles and assuming the tool requires a routed interface like a TUN device.

258
MCQmedium

During an exploit development exercise on a 32-bit Windows application, you have identified that a JMP ESP instruction resides at 0x625011AF inside a module that is not protected by ASLR or SafeSEH. You need to place your shellcode after the overwritten return address. What is the primary reason for using this JMP ESP address rather than jumping directly to a stack address where your shellcode resides?

A.The JMP ESP instruction provides a stable, predictable target because the module's base address is fixed, while direct stack addresses vary between runs and debugger sessions.
B.JMP ESP increases the size of the stack buffer so that larger shellcode can be placed.
C.JMP ESP automatically encodes the shellcode to bypass antivirus signature detection.
D.JMP ESP ensures that the shellcode executes with SYSTEM privileges.
AnswerA

Stack addresses change due to environment variables, debugger overhead, and ASLR on the stack, making hardcoded stack jumps unreliable. A non-ASLR module's JMP ESP address remains constant across executions, so overwriting EIP with that address reliably transfers control to ESP, which points to your shellcode. This stability is why PEN-200 teaches JMP ESP as a dependable pivot.

Why this answer

JMP ESP is preferred because its address in a non-ASLR module is constant, whereas stack addresses fluctuate, making direct jumps unreliable. It provides a deterministic pivot to shellcode placed after the return address. It does not encode payloads, resize buffers, or change privileges; those are separate concerns in exploit development.

Exam trap

The trap here is believing that JMP ESP itself provides reliability benefits beyond address stability, such as encoding or privilege escalation, when it only redirects execution to the stack.

259
MCQhard

During an authorized penetration test, a tester needs to deliver a Meterpreter payload to a Windows Server 2019 target that runs a next-generation antivirus with behavioral monitoring. The tester decides to use a process injection technique to run the payload inside a legitimate process. Which injection method is LEAST likely to be flagged by behavioral monitoring because it avoids allocating new executable memory in the target process?

A.Process hollowing by creating a suspended process and replacing its image.
B.Thread execution hijacking by suspending a thread and modifying its context to point to shellcode.
C.Classic CreateRemoteThread with VirtualAllocEx and WriteProcessMemory.
D.Module stomping by overwriting the .text section of a loaded DLL with shellcode.
AnswerD

Module stomping writes shellcode into the existing executable .text section of a legitimately loaded DLL, so no new executable memory is allocated. Because the memory is already marked executable and belongs to a signed module, behavioral monitors that focus on new executable allocations or thread creation may not flag it. This technique is stealthier against memory-permission-based detection, though integrity checks on the DLL could still reveal tampering.

Why this answer

Module stomping avoids allocating new executable memory by reusing the existing .text section of a loaded DLL. Since the memory is already executable and associated with a legitimate module, it bypasses detection logic that looks for new PAGE_EXECUTE_READWRITE allocations or suspicious thread creation. Other injection methods require allocating or modifying executable memory in ways that behavioral monitoring commonly correlates with malicious activity, making them more likely to be flagged.

Exam trap

The trap here is assuming that any injection method that avoids CreateRemoteThread is automatically stealthy, when most still allocate new executable memory that behavioral monitoring watches for.

260
MCQhard

Why must you carefully identify 'bad characters' before finalizing an exploit payload?

A.To prevent the shellcode from triggering an antivirus alert.
B.To ensure the shellcode is correctly copied into memory in its entirety.
C.To allow the CPU to perform faster instruction decoding.
D.To bypass DEP (Data Execution Prevention) controls.
AnswerB

Certain characters like null bytes or line feeds are interpreted by copy functions as termination signals. If such a character appears in the middle of your shellcode, the program stops processing the rest of the buffer, leaving the shellcode incomplete and making it impossible for the CPU to execute it.

Why this answer

Bad characters are bytes that cause a function or protocol to stop processing input prematurely. If these characters exist in your shellcode, the application will truncate the payload. Identifying these characters ensures that the full exploit string is correctly placed into memory, allowing the overflow to reach the return address and execute the shellcode as intended without corruption or partial injection.

Exam trap

Candidates often think bad characters only affect visual output, failing to realize they cause payload truncation and break shellcode execution entirely.

261
MCQeasy

You are performing a penetration test against a Linux server and have obtained a copy of the /etc/shadow file. The file contains a hash for user 'admin' that starts with '$6$'. You want to crack this hash offline. Which hashcat mode should you use?

A.Mode 7400 (sha256crypt)
B.Mode 1800 (sha512crypt)
C.Mode 3200 (bcrypt)
D.Mode 500 (md5crypt)
AnswerB

Mode 1800 in hashcat is specifically for sha512crypt, which corresponds to the '$6$' prefix in /etc/shadow. This is the correct mode to crack the hash. It supports the SHA-512 based crypt(3) algorithm used by most modern Linux systems. Using this mode ensures the hash is processed correctly and efficiently.

Why this answer

The '$6$' prefix in /etc/shadow denotes SHA-512 crypt, which is handled by hashcat mode 1800 (sha512crypt). The other modes correspond to different algorithms: mode 500 for md5crypt ('$1$'), mode 3200 for bcrypt ('$2a$'), and mode 7400 for sha256crypt ('$5$'). Using the correct mode is essential for successful cracking.

Therefore, mode 1800 is the right choice.

Exam trap

The trap here is confusing the various '$id$' prefixes in crypt(3) hashes, leading to selection of the wrong hashcat mode.

262
MCQeasy

A web application uses JSON Web Tokens for authentication. You capture a token whose header is `{"alg":"HS256","typ":"JWT"}` and payload is `{"user":"guest","role":"user"}`. The server verifies the signature with a symmetric secret. Which attack is most likely to let you forge a token with `"role":"admin"` if the application is misconfigured?

A.Crack the HS256 secret offline with a wordlist using a tool like hashcat or john, then re-sign a modified payload.
B.Replay the captured token after changing only the payload `role` field to `admin`, keeping the original signature.
C.Switch the header `alg` to `RS256` and sign the token with the server's public key as an HMAC secret.
D.Change the header `alg` to `none` and remove the signature segment, then submit the token.
AnswerA

HS256 uses a shared secret, and if the application chose a weak or default secret, an attacker who possesses a valid token can perform an offline dictionary attack against the HMAC. Once the secret is recovered, the attacker can sign any payload, including one with `"role":"admin"`. This is the most realistic path when signature verification is enforced but the key is guessable.

Why this answer

When HS256 is enforced but the secret is weak, the practical attack is an offline dictionary or brute-force attack against the HMAC using a captured token. Recovering the secret allows the attacker to mint arbitrary tokens, including one with elevated privileges. Algorithm-confusion and `alg:none` attacks require different misconfigurations that are not present in this scenario.

Exam trap

The trap here is jumping to `alg:none` or algorithm confusion, when the scenario specifies symmetric verification, pointing instead to secret cracking.

263
MCQhard

You are testing an e-commerce application that uses a cookie named 'sessionid' to maintain authenticated sessions. The application sets this cookie without the HttpOnly attribute, and you have identified a reflected XSS vulnerability in the product search feature. Which of the following attack methods would allow you to steal the session cookie and hijack an authenticated user's session?

A.Inject a script that reads document.cookie and sends it to an attacker-controlled server.
B.Inject a script that calls window.location = 'https://attacker.com' to redirect the user.
C.Inject a script that triggers a CSRF request to change the user's password.
D.Inject a script that modifies the DOM to display a fake login form.
AnswerA

Because the sessionid cookie lacks the HttpOnly flag, JavaScript running in the page context can access it via document.cookie. By injecting a script through the reflected XSS vulnerability, the attacker can read the cookie value and exfiltrate it to a server they control. The stolen sessionid can then be used to impersonate the victim and hijack the authenticated session. This directly exploits the missing HttpOnly attribute combined with XSS.

Why this answer

When a session cookie lacks the HttpOnly attribute, client-side JavaScript can access it through document.cookie. A reflected XSS vulnerability allows an attacker to inject and execute arbitrary script in the victim's browser, which can then read the cookie and exfiltrate it. The stolen session identifier can be used to impersonate the authenticated user.

Other attacks like redirects, fake forms, or CSRF do not directly steal the cookie.

Exam trap

The trap here is confusing session hijacking via cookie theft with other client-side attacks like CSRF or phishing, which do not require reading the cookie value.

264
MCQhard

You are testing a web application that sets a session cookie with the HttpOnly flag. You find a reflected XSS vulnerability on a page that does not require authentication. What is the primary impact of exploiting this XSS given the HttpOnly flag?

A.You can read the session cookie using document.cookie because HttpOnly only applies to cookies set over HTTPS.
B.You can bypass HttpOnly by using XMLHttpRequest to fetch the cookie from the server’s response headers.
C.You cannot execute JavaScript at all because HttpOnly blocks all script execution on the page.
D.You can execute arbitrary JavaScript in the victim’s browser to perform actions as the victim, but you cannot directly read the session cookie via document.cookie.
AnswerD

HttpOnly prevents JavaScript from accessing the cookie through document.cookie, but it does not stop script execution. The attacker can still issue authenticated requests from the victim’s browser, read page content, log keystrokes, or manipulate the DOM. The session remains usable by the browser automatically, so actions can be performed on behalf of the victim even though the cookie value cannot be stolen directly.

Why this answer

HttpOnly is designed to prevent client-side scripts from reading cookie values, but it does not prevent script execution or stop the browser from sending the cookie with requests. An attacker who achieves XSS can still act as the victim by issuing requests, reading page content, or capturing keystrokes. The session cookie may be inaccessible to document.cookie, but the authenticated session remains exploitable.

Exam trap

The trap here is equating HttpOnly with complete protection against XSS, when it only blocks direct cookie theft via document.cookie.

265
MCQeasy

Which of the following best describes the function of the EIP register in the context of a stack-based buffer overflow?

A.It stores the current stack frame's base address.
B.It points to the memory address of the next instruction to be executed.
C.It keeps track of the number of active threads.
D.It holds the results of arithmetic operations.
AnswerB

EIP is the instruction pointer, which governs the flow of the program. By controlling this register, an attacker can redirect the CPU from its normal path of execution to any chosen memory address. This is the core mechanism that makes buffer overflow exploitation possible and effective for arbitrary code execution.

Why this answer

The EIP (Extended Instruction Pointer) register holds the memory address of the next instruction the CPU should execute. In an exploit, the goal is to overwrite this register by corrupting the saved return address on the stack. When the function finishes, the CPU pops this controlled value into EIP, forcing the processor to jump to the attacker's shellcode, thus hijacking the control flow of the entire application.

Exam trap

Test-takers frequently confuse the EIP register with the ESP or the input buffer itself, failing to recognize that EIP specifically tracks the next instruction to be executed by the CPU.

266
MCQhard

Refer to the exhibit. If you attempt an SSH remote port forward (-R) to bind a port to all network interfaces on the server, what will happen?

A.The request will be rejected and the connection will close.
B.The port will be bound to 127.0.0.1 instead of 0.0.0.0.
C.The server will allow the binding because it is a superuser request.
D.The connection will hang indefinitely.
AnswerB

Because GatewayPorts is set to 'no', the SSH daemon forces all forwarded ports to bind to the loopback interface, regardless of the user's request. This effectively enforces a security policy where only local processes on the jump host can interact with the forwarded port, preventing external access.

Why this answer

The 'GatewayPorts no' setting in the sshd_config specifically prevents forwarded ports from binding to any interface other than the loopback (localhost). Even if the user specifies 0.0.0.0 or a public IP in their SSH command, the server will ignore this request and bind the port only to 127.0.0.1. This is a common security hardening measure to prevent unauthorized access to forwarded ports from external networks.

Exam trap

Candidates assume that specifying 0.0.0.0 in an SSH command overrides server-side configurations, forgetting that 'GatewayPorts no' strictly enforces loopback-only bindings on the remote host.

267
MCQhard

A penetration tester has a working unmanaged PowerShell runner in C# that executes a script block on a Windows 10 host with AMSI enabled. The runner currently fails because AMSI scans the script content. The tester wants to disable AMSI scanning for the current process without touching files on disk and without requiring administrative privileges. Which technique best fits these constraints?

A.Set the registry value HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableAMSI to 1.
B.Run the PowerShell runner from a session launched with the -NoProfile and -ExecutionPolicy Bypass switches.
C.Patch the AmsiScanBuffer function in memory by overwriting its first bytes with a return value that indicates a clean scan.
D.Delete the amsi.dll file from C:\Windows\System32 and reboot the target host.
AnswerC

AMSI resolves AmsiScanBuffer from amsi.dll inside each process. Overwriting the function's prologue in the current process's memory so it returns a benign result causes subsequent scans to report no detection, and this works within the user's own process without admin rights or disk changes. It matches the requirement to disable scanning for the current process only and leaves files untouched.

Why this answer

AMSI performs in-process scanning through functions resolved from amsi.dll, most notably AmsiScanBuffer. Because the DLL is loaded into the calling process, a user-mode patch of that function in memory changes scan results for that process only, needs no administrative rights, and writes nothing to disk. Deleting system files, inventing registry policies, or adjusting execution policy do not alter the in-memory scanning path AMSI uses.

Exam trap

The trap here is confusing PowerShell's execution policy, which governs script running, with AMSI, which performs content scanning independent of that policy.

268
Multi-Selectmedium

When analyzing a public exploit, which TWO elements should you specifically look for to understand its networking behavior? (Choose TWO)

Select 2 answers
A.The target port the exploit connects to.
B.The author's name and email address.
C.The type of connection (e.g., reverse, bind).
D.The date the exploit was uploaded.
E.The color scheme used in the code.
AnswersA, C

Identifying the target port is critical for ensuring your exploit is reaching the correct service. If you are not targeting the right port, the exploit will simply fail. This is the first thing you should check when you are analyzing the network logic of any public exploit.

Why this answer

Understanding how an exploit communicates is vital for both success and stealth. By identifying the hardcoded target port and the type of callback payload (e.g., reverse shell vs. bind shell), you can align your listener and firewall configuration to ensure the exploit functions correctly. This level of technical oversight is essential to avoid common pitfalls where the exploit succeeds, but the attacker fails to receive the connection due to network-level misconfigurations.

Exam trap

Candidates often focus only on the exploit's payload code while ignoring the networking configuration, causing them to set up the wrong listener type or use the wrong port for the callback.

269
MCQmedium

You are fuzzing a Linux x86-64 network service and cause a segmentation fault. You run the binary under GDB and see that the instruction pointer is 0x41414141. However, the crash address is in a non-executable stack region. Which technique should you use to redirect execution to your shellcode?

A.Use a heap spray to place shellcode in a predictable location and jump to it.
B.Overwrite the return address with a pointer to the stack and rely on the NX bit being disabled.
C.Use a ret2libc attack to call system() with a pointer to "/bin/sh".
D.Increase the size of the buffer to overwrite the saved return address with a stack address.
AnswerC

This is correct because the stack is non-executable, so you cannot execute shellcode directly on the stack. ret2libc leverages existing executable code in libc, such as system(), to spawn a shell. By controlling the return address and arguments, you can call system("/bin/sh") without needing executable stack permissions.

Why this answer

When the stack is non-executable, direct shellcode execution fails. The ret2libc technique bypasses this by reusing existing executable code, typically calling functions like system() with controlled arguments. This is a standard method taught in PEN-200 for defeating NX, provided you can locate the necessary addresses and gadgets.

Exam trap

The trap here is assuming that a larger buffer or a stack address can overcome NX, when in fact NX specifically prevents code execution from writable memory regions like the stack.

270
MCQhard

You have compromised a dual-homed Linux host that can reach an internal network. You want to use it as a SOCKS proxy so that tools like Nmap and Metasploit can route traffic into that internal network. You decide to use SSH dynamic port forwarding. Which command should you run from your attacking machine to create a SOCKS proxy on local port 1080 that tunnels through the compromised host?

A.ssh -D 1080 -L 1080:127.0.0.1:1080 user@compromised-host
B.ssh -L 1080:compromised-host:1080 user@compromised-host
C.ssh -D 1080 user@compromised-host
D.ssh -R 1080 user@compromised-host
AnswerC

The -D option enables dynamic port forwarding, turning the SSH client into a SOCKS proxy listening on local port 1080. Applications configured to use that SOCKS proxy will send traffic through the SSH tunnel to the compromised host, which then makes the outbound connections. This matches the requirement to route tools into the internal network without specifying individual static forwards.

Why this answer

Dynamic port forwarding with ssh -D creates a local SOCKS proxy that forwards connections through the SSH server. Applications configured to use that SOCKS proxy can reach any host the SSH server can reach, making it ideal for pivoting into internal networks with tools like Nmap and Metasploit.

Exam trap

The trap here is assuming that a static local forward (-L) can act as a SOCKS proxy, when only dynamic forwarding (-D) provides that capability.

271
MCQeasy

You download a public exploit for a known vulnerability from an untrusted source. Before running it against a client's production system, what is the most important action to take?

A.Check the exploit's file hash against online databases to confirm it is known.
B.Run the exploit in a sandboxed virtual machine first to see if it works.
C.Review the exploit's source code to understand its actions and check for malicious payloads.
D.Ask the client for permission to run the exploit on their production system.
AnswerC

Auditing the source code is critical because public exploits from untrusted sources may contain backdoors, additional malicious payloads, or destructive commands. Understanding what the exploit does before execution protects both the client's environment and your own testing platform.

Why this answer

Reviewing the exploit's source code is the most important step because it reveals exactly what the code will execute. Permission and sandboxing are valuable but secondary to understanding the code, which protects both the client and the tester from unintended consequences.

Exam trap

The trap here is assuming that sandbox testing or hash verification is sufficient, when neither guarantees the exploit is free of malicious behavior.

272
MCQmedium

You are enumerating an Apache web server and discover the '.git' directory is accessible. What is the most significant risk this poses for your reconnaissance?

A.It indicates the server is using an outdated version of Apache.
B.The entire source code repository can be downloaded.
C.It means the server is vulnerable to SQL injection.
D.It suggests that the server is running on a Windows OS.
AnswerB

Exposed .git directories allow an attacker to reconstruct the entire project repository, including code, database schema, and configuration files. This provides deep insight into the application's internal structure and security logic, exposing credentials or secrets that are frequently hardcoded by developers during the initial phases of coding.

Why this answer

An exposed '.git' directory allows an attacker to download the entire project repository, including source code, configuration files, and commit history. This is a critical discovery because the source code may contain hardcoded credentials, API keys, or sensitive business logic that would otherwise be hidden. Analyzing this data often provides the most direct path to exploitation, as it reveals the application's internal workings and potential flaws that are not apparent from the outside.

Exam trap

Candidates often assume the risk is just file disclosure or directory listing. The most significant risk is the full repository download, which provides the entire codebase and sensitive history.

273
Multi-Selecthard

During an Active Directory penetration test, you have obtained Domain Admin privileges. To maintain persistent access, you decide to create a Golden Ticket. Which two of the following pieces of information are required to forge a valid Golden Ticket? (Choose two.)

Select 2 answers
A.The target user's password.
B.The KRBTGT account's NTLM hash.
C.A valid Kerberos TGT for a Domain Admin.
D.The Domain Controller's machine account hash.
E.The domain's SID.
AnswersB, E

The KRBTGT account's NTLM hash is used to encrypt and sign the Golden Ticket. Without it, the ticket cannot be forged because the KDC uses this hash to validate TGTs. This is a core requirement for creating a Golden Ticket, as it allows the attacker to mint TGTs for any user, including Domain Admins.

Why this answer

To forge a Golden Ticket, you need the KRBTGT account's NTLM hash to encrypt the ticket and the domain SID to populate the PAC correctly. These two elements allow you to create a TGT for any user, granting persistent domain-wide access. Other items like a valid TGT or user passwords are not required, as the ticket is self-signed with the KRBTGT hash.

Exam trap

The trap here is thinking that a Golden Ticket requires a legitimate TGT or user password, when in fact it is forged using the KRBTGT hash and domain SID.

274
MCQeasy

When analyzing a stack buffer, what is the significance of the 'saved EBP' value?

A.It is the primary register for shellcode execution.
B.It helps the program restore the previous stack frame.
C.It is a security mechanism to prevent overflows.
D.It stores the base address of the shellcode.
AnswerB

The saved EBP is used by the function epilogue (specifically the LEAVE or POP EBP instructions) to restore the stack pointer to the state of the calling function. Overwriting this value is necessary to reach the return address, but it often leads to a crash if the stack cannot be properly unwound.

Why this answer

The saved EBP is part of the standard function epilogue, which helps the program restore the stack frame of the calling function. In a buffer overflow, this value is overwritten immediately before the return address. While usually not the primary target for flow hijacking, it is a critical piece of the stack frame that, if corrupted, will likely cause the program to crash when it attempts to restore the stack frame after the function finishes.

Exam trap

Many candidates confuse the saved EBP with the instruction pointer, mistakenly believing that overwriting EBP directly alters the execution flow rather than crashing during the function epilogue.

275
MCQhard

You are enumerating a Windows host and have obtained valid low-privilege domain credentials. You want to identify which systems in the domain the account can access administratively, so you can plan lateral movement. Which approach most efficiently maps that access?

A.Use CrackMapExec or NetExec with the credentials to test administrative access across the domain.
B.Query the domain controller with ldapsearch for all computer objects and their operating systems.
C.Capture network traffic on the domain controller to observe authentication events.
D.Run a full TCP port scan of every host in the domain to find open port 445.
AnswerA

Tools like CrackMapExec and NetExec authenticate to each host using the supplied credentials and report whether the account has administrative rights, often by attempting a privileged operation such as reading the SAM database or listing shares with admin access. That directly answers which systems the account can control. Running it against the domain inventory is far more efficient and informative than scanning for open ports, because it tests actual authorization rather than mere reachability.

Why this answer

Mapping administrative access requires testing authorization, not just reachability or inventory. Credentialed tools such as CrackMapExec and NetExec authenticate to each host and report whether the supplied account holds administrative rights, typically by performing a privileged action. Port scans only show that SMB is listening, directory queries only list computers, and packet capture observes rather than tests, so none of those alternatives directly answers where the low-privilege account can move laterally.

Exam trap

The trap here is equating an open SMB port with administrative access, when authorization must be tested with the actual credentials.

276
Multi-Selecthard

When evaluating a web application for Cross-Site Scripting vulnerabilities during a penetration test, which TWO input contexts should you examine because they frequently lead to executable script injection?

Select 2 answers
A.Input reflected directly between opening and closing HTML tags, such as <div>USER_INPUT</div>
B.Input processed by a backend database stored procedure for primary key generation
C.Input placed inside HTML event handler attributes, such as <img src='x' onerror='USER_INPUT'>
D.Input stored as an encrypted binary blob inside the browser local session storage
E.Input utilized as a parameter value inside a server-side JSON response header without content-type sniffing
AnswersA, C

Reflecting user input between standard HTML tags allows an attacker to supply arbitrary HTML and script tags. When the browser parses the document, it interprets the injected <script> tags as executable code rather than plain text.

Why this answer

XSS occurs when untrusted user input is rendered in an unsafe context within the HTML document. Examining input reflected directly inside HTML body tags or inside event handler attributes (like onload or onerror) are primary areas where browsers will evaluate injected strings as executable JavaScript.

Exam trap

Candidates often focus only on standard input fields, missing that HTML attributes like 'onerror' or 'onload' are frequently overlooked injection vectors that browsers process as executable JavaScript.

277
Multi-Selectmedium

You are assessing a login form and suspect a blind SQL injection vulnerability. The application does not return database errors, but the response time varies significantly based on the input. Which TWO of the following techniques would be most effective to confirm this vulnerability?

Select 2 answers
A.Injecting 'SLEEP(5)' or equivalent wait commands.
B.Reviewing the server's source code files.
C.Injecting payloads that alter Boolean response conditions.
D.Forcing the application to display verbose error messages.
E.Attempting to perform a Cross-Site Request Forgery.
AnswersA, C

Time-based payloads force the database to execute a delay before responding. If the server response is delayed by exactly the specified duration, it confirms that the injected command was successfully executed by the backend engine, providing a reliable indicator for confirming blind SQL injection vulnerabilities during testing.

Why this answer

Blind SQL injection relies on inferring data through side channels like time delays or Boolean logic. Time-based payloads force the database to pause, while Boolean-based payloads cause the page content to change based on true/false conditions. These methods are essential when direct data output is suppressed, allowing an attacker to reconstruct the database contents systematically through repeated, measured queries to the back-end server.

Exam trap

Test-takers often look only for error-based payloads, forgetting that blind SQL injection requires alternative side-channel techniques like time delays or boolean conditions.

278
MCQmedium

During enumeration, you discover that the registry keys 'HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated' and 'HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated' are both set to 1. Which of the following is the most efficient way to exploit this configuration?

A.Use 'certutil' to download and execute a portable executable (EXE) directly.
B.Generate a malicious MSI file and execute it using 'msiexec /quiet /qn /i payload.msi'.
C.Modify the 'AlwaysInstallElevated' key in HKCU to point to a malicious script instead of '1'.
D.Inject a malicious DLL into the 'msiexec.exe' process while it is running.
AnswerB

This is the standard method for exploiting AlwaysInstallElevated. The 'msiexec' utility processes the MSI file, and because the policy is enabled, the Windows Installer service executes the internal scripts or binaries of the MSI as SYSTEM. The flags '/quiet' and '/qn' ensure the installation happens in the background without user interaction.

Why this answer

The AlwaysInstallElevated policy is a specific Windows feature that allows non-privileged users to run Windows Installer (MSI) packages with SYSTEM privileges. For this to work, the policy must be enabled in both the machine (HKLM) and user (HKCU) registry hives. Attackers can exploit this by crafting a malicious MSI file that executes a command, such as adding a user or opening a reverse shell.

Exam trap

Candidates often forget that BOTH registry keys must be set to 1. If only one is set, the installation will not run with elevated privileges, and the exploit will fail silently or return an error.

279
MCQmedium

During an internal penetration test, you gain shell access to a Linux machine. You want to pivot deeper into a segmented internal network that is completely unreachable directly from your attack host. Which tunneling approach establishes a true layer 2 network tunnel by creating a virtual network interface, allowing you to route raw Ethernet frames and perform ARP scanning?

A.Local port forwarding using SSH (-L flag)
B.Remote port forwarding using SSH (-R flag)
C.Setting up a TAP network interface tunnel
D.Dynamic port forwarding using an SSH SOCKS proxy (-D flag)
AnswerC

A TAP interface operates at the Data Link Layer (Layer 2) of the OSI model, capturing and tunneling raw Ethernet frames. This enables protocols like ARP and allows attackers to perform comprehensive ping sweeps and layer 2 scanning through the pivot host.

Why this answer

Creating a TUN or TAP device using tools like sshuttle or OpenVPN establishes a Layer 3 or Layer 2 tunnel respectively. A TAP interface operates at Layer 2, allowing raw Ethernet frames to cross the boundary. This capability is essential when standard TCP/UDP port forwarding fails because you need to execute broadcast-dependent reconnaissance or vulnerability scanning against hidden internal subnets.

Exam trap

Many candidates confuse Layer 2 TAP interfaces with Layer 3 TUN interfaces or simple SSH port forwarding. Remember that port forwarding only handles TCP or UDP streams, whereas Layer 2 tunneling allows raw framing and ARP scanning across boundaries.

280
MCQmedium

Which property of a URL is most commonly used as a source for DOM-based XSS because it is not sent to the server?

A.The query string (everything after the ? character).
B.The URL fragment (everything after the # character).
C.The HTTP Referer header.
D.The user-agent string.
AnswerB

The fragment identifier is never sent to the server, making it invisible to server-side security controls. This allows attackers to manipulate the client-side state without triggering backend alerts, making it the most common source for DOM XSS where the payload is handled entirely within the browser.

Why this answer

The URL fragment (the part after the # character) is strictly handled by the browser and is never included in the HTTP request sent to the server. Because developers often assume this data is 'safe' or ignored by the backend, they frequently fail to sanitize it before using it in client-side operations, creating an ideal vector for DOM-based XSS attacks that bypass traditional WAFs.

Exam trap

Test-takers frequently guess standard query parameters or HTTP headers, forgetting that URL fragments are client-side only and never transmitted to servers.

281
Multi-Selectmedium

A penetration tester is preparing to bypass antivirus on a Windows target during a PEN-200 lab. The tester wants to use packing and encryption to alter the payload's signature and avoid static detection. Which TWO techniques are effective for evading static signature-based detection by changing the file's binary appearance without altering its functionality? (Choose two.)

Select 2 answers
A.Modifying the PE header to change the compile timestamp and checksum.
B.Renaming the executable file to a system process name such as svchost.exe.
C.Encrypting the payload with a unique key and including the decryption routine in a custom loader.
D.Using a packer that compresses and encrypts the original executable, with a stub that decrypts it in memory at runtime.
E.Appending random bytes to the end of the executable to change its file hash.
AnswersC, D

Encrypting the payload with a unique key ensures that the on-disk bytes are different for each build, defeating static signatures that rely on fixed byte patterns. The custom loader decrypts the payload in memory before execution, so functionality is preserved. This is a strong method for evading static detection because the encrypted payload does not match known signatures. It requires the loader to handle decryption and execution, often leading to in-memory execution.

Why this answer

Effective static evasion requires changing the bytes that signatures match. Packers encrypt and compress the original code, so the on-disk file no longer contains the recognizable pattern. Encrypting the payload with a unique key and a custom loader achieves the same by making each build's bytes unique.

Both preserve functionality while altering the binary appearance. Appending random bytes, renaming, or modifying PE metadata do not change the core code sections that signatures target, so they are ineffective for evading static detection.

Exam trap

The trap here is thinking that any change to the file, such as appending bytes or renaming, will evade signature detection, when only changes that alter the actual code or data patterns are effective.

282
MCQmedium

You have gained a low-privileged shell on a Linux system and discovered a binary with the SUID bit set. The binary executes a system call to 'cat' without specifying an absolute path. How can you leverage this to escalate privileges?

A.Overwrite the SUID binary's source code in /usr/src to include a reverse shell.
B.Use 'chmod' to grant everyone execute permissions on the SUID binary to trigger a buffer overflow.
C.Prepend a directory containing a malicious 'cat' script to the PATH variable and run the binary.
D.Modify the /etc/ld.so.preload file to inject a malicious library into the SUID binary's execution flow.
AnswerC

By creating a script named 'cat' in a directory like /tmp and setting the PATH variable to start with that directory, the system executes your script instead of the legitimate binary. Because the parent program is SUID root, your malicious script runs with root privileges, granting a shell.

Why this answer

By manipulating the PATH environment variable, you can point the system to a malicious 'cat' executable created in a writable directory. When the SUID binary runs, it executes your script with the permissions of the file owner rather than yours. This technique exploits the insecure execution of external commands, a common vulnerability in improperly coded SUID binaries that allows for arbitrary command execution under an elevated security context.

Exam trap

Candidates often assume the binary is vulnerable because it is SUID, forgetting that they must actually manipulate the environment to redirect the binary's execution to their own malicious code.

283
MCQmedium

Refer to the exhibit. What is the most likely goal of this command execution in a privilege escalation context?

A.To install a persistent backdoor on the system.
B.To perform automated enumeration for privilege escalation.
C.To escalate privileges to SYSTEM directly.
D.To exfiltrate sensitive files from the system.
AnswerB

Scripts like PowerUp are designed to search for common misconfigurations that lead to privilege escalation. Executing such scripts from a remote server is a standard technique to quickly identify escalation paths without leaving traces on the local file system, which helps maintain operational security during an engagement.

Why this answer

This command downloads and executes a PowerShell script directly into memory from a remote server. This is a common technique for running automated enumeration scripts like PowerUp or WinPEAS without writing them to the disk. By executing in memory, the attacker minimizes their footprint on the host system, avoiding detection by file-based signature scanning while gathering information about potential escalation vectors.

Exam trap

Candidates often assume this command is for persistence or data exfiltration. They miss that the primary goal in privilege escalation is automated enumeration to identify misconfigurations before manual exploitation begins.

284
MCQeasy

What is the primary objective of a 'Clickjacking' attack?

A.To steal the user's session cookies through hidden JavaScript execution.
B.To bypass the Same-Origin Policy by forcing cross-domain requests.
C.To trick users into clicking on a hidden element, often to perform unauthorized actions.
D.To inject malicious scripts into the page to capture keystrokes.
AnswerC

Clickjacking involves overlaying a transparent or hidden iframe over a legitimate web page. The user thinks they are clicking a button on the visible page, but they are actually interacting with an element in the hidden iframe, leading to unintended and potentially harmful actions being executed.

Why this answer

Clickjacking tricks users into clicking something different from what they perceive, often by overlaying a hidden, malicious iframe over a legitimate page element. The objective is to force the user to perform unintended actions, like changing account settings or transferring funds, while they believe they are interacting with the benign UI. This leverages the user's existing session to execute authorized requests without their informed consent.

Exam trap

Candidates often confuse clickjacking with credential harvesting or phishing, missing the core mechanism of transparently overlaying UI elements to hijack clicks.

285
MCQmedium

During a web assessment, you find that an application uses an insecure random number generator for token creation. What is the main security implication of this flaw?

A.It allows attackers to perform Cross-Site Request Forgery (CSRF).
B.It leads to session hijacking through token prediction.
C.It triggers a stack overflow in the web server process.
D.It makes the application vulnerable to SQL Injection.
AnswerB

If the random number generator is predictable, an attacker can generate a sequence of valid tokens and potentially hijack active user sessions. This allows unauthorized access to user accounts without needing to know a password, representing a severe flaw in authentication and session integrity.

Why this answer

Predictable tokens compromise the integrity of session management and password reset mechanisms. If an attacker can determine the algorithm and seed used by the generator, they can forge valid session tokens or reset codes for other users. This vulnerability highlights the necessity of using cryptographically secure pseudorandom number generators (CSPRNGs) to ensure that sensitive authentication tokens cannot be guessed or recreated by adversaries.

Exam trap

Candidates often confuse random number generation flaws with encryption key length issues, failing to realize that predictability directly allows attackers to forge tokens and hijack active user sessions effortlessly.

Page 3

Page 4 of 4

All pages