
EC-CouncilCertified Ethical Hacker
Domain 3Objective 4
Privilege Escalation CEH Practice Questions (Page 4)
Part of the System Hacking Phases and Attack Techniques domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 2–3 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
7concepts
Questions 16–20
- 16
You have unprivileged access to a Linux server. You find a cron job that runs as root and executes the script '/opt/scripts/backup.sh'. The script is writable by your user. What is the most effective way to escalate privileges?
Select an answer first - 17
Which of the following is a common source from which an attacker can harvest credentials to reuse for privilege escalation?
Select an answer first - 18
Which of the following is an example of a persistence mechanism that an attacker might use after privilege escalation on a Linux system?
Select an answer first - 19
You have unprivileged access to a Windows server. You find that the 'C:\Program Files\VulnApp' directory is writable by Everyone, and the application 'VulnApp.exe' runs as SYSTEM. The application is not currently running. What is the most reliable way to escalate privileges?
Select an answer first - 20
A penetration tester has a low-privileged shell on a Windows server. The tester wants to automate the enumeration of privilege escalation vectors. Which tool is specifically designed for this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.