
EC-CouncilCertified Ethical Hacker
Domain 3Objective 4
Privilege Escalation CEH Practice Questions (Page 3)
Part of the System Hacking Phases and Attack Techniques domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 2–3 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
7concepts
Questions 11–15
- 11
An attacker finds that a Windows scheduled task runs as SYSTEM and its associated executable is stored in a folder where the attacker has write permissions. How can the attacker exploit this misconfiguration?
Select an answer first - 12
After escalating to root on a Linux server, a penetration tester wants to maintain access even if the server is rebooted. Which technique would best achieve persistence?
Select an answer first - 13
A Windows system has a service 'HelperSvc' that runs as SYSTEM. The service's executable path is 'C:\Program Files\Helper\helper.exe'. The 'C:\Program Files\Helper' directory is writable by the 'Users' group. A low-privileged user wants to escalate privileges. Which action would achieve this?
Select an answer first - 14
During a Windows privilege escalation assessment, a tester discovers that the 'C:\Program Files\ImportantApp' directory has the following ACL: 'Everyone:(OI)(CI)(F)'. The application runs as SYSTEM and is configured to start automatically. Which action would allow the tester to gain SYSTEM privileges?
Select an answer first - 15
In the context of system hacking, what is the primary difference between horizontal and vertical privilege escalation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.