Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 3Objective 4

Privilege Escalation CEH Practice Questions (Page 6)

Part of the System Hacking Phases and Attack Techniques domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 2–3 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
7concepts

Questions 26–30

  1. 26application · medium

    A Linux administrator suspects a local user can escalate privileges. The user 'alice' can run the command '/usr/bin/find' via sudo without a password. The sudoers entry is: 'alice ALL=(ALL) NOPASSWD: /usr/bin/find'. Which technique would allow alice to gain a root shell?

    Select an answer first
  2. 27application · medium

    A penetration tester has a low-privileged shell on a Windows machine. The tester wants to harvest credentials from memory to escalate privileges. Which tool is specifically designed for this?

    Select an answer first
  3. 28expert · hard

    You have unprivileged access to a Windows 10 machine. WinPEAS shows two potential escalation paths: (1) a service 'VulnSvc' runs as SYSTEM with an unquoted path 'C:\Program Files\VulnApp\vuln service.exe', and the 'C:\Program Files\VulnApp' folder is writable; (2) the 'HKLM\SYSTEM\CurrentControlSet\Services\VulnSvc' registry key is writable by your user. The service is currently running. Which path is more reliable?

    Select an answer first
  4. 29application · medium

    A penetration tester has a low-privileged shell on a Linux server as user 'bob'. The tester discovers that the user 'alice' has access to a sensitive file that bob needs. Bob finds that he can read alice's home directory and copy the file. Which type of privilege escalation is this?

    Select an answer first
  5. 30application · medium

    A Linux system has a SUID binary at '/usr/bin/status' that runs a script located at '/opt/status/check.sh'. The script is writable by all users. A low-privileged user wants to escalate to root. What is the most effective way to exploit this?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.