Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 3Objective 4

Privilege Escalation CEH Practice Questions (Page 2)

Part of the System Hacking Phases and Attack Techniques domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 2–3 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
7concepts

Questions 6–10

  1. 6foundation · easy

    A penetration tester discovers that a Windows service runs with SYSTEM privileges and the service's executable file is writable by the Everyone group. Which privilege escalation vector is most directly indicated?

    Select an answer first
  2. 7foundation · easy

    A Linux system has a cron job that runs a script located in a world-writable directory. An attacker can replace the script with a malicious one. Which Linux privilege escalation vector does this exploit?

    Select an answer first
  3. 8foundation · easy

    After successfully escalating privileges on a Windows system, an attacker creates a new local user account and adds it to the Administrators group. What is the primary purpose of this action?

    Select an answer first
  4. 9application · medium

    A Linux system has a cron job that runs as root every minute and executes '/usr/local/bin/cleanup.sh'. The script is writable by all users. A low-privileged user wants to escalate to root. Which action would achieve this?

    Select an answer first
  5. 10expert · hard

    You are on a penetration test with a strict time limit. You have unprivileged access to a Windows Server 2016. You find a scheduled task 'Cleanup' that runs as SYSTEM and executes 'C:\Scripts\cleanup.bat'. The 'C:\Scripts' folder is writable by your user. However, the task is scheduled to run only once a week. You also find that the service 'VulnSvc' runs as SYSTEM and its binary path is 'C:\Program Files\VulnApp\vuln.exe', and the folder is writable. Which path is more appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.