Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Ethical Hacker

Domain 3Objective 4

Privilege Escalation CEH Practice Questions (Page 7)

Part of the System Hacking Phases and Attack Techniques domain, which makes up ~16% of our current practice bank. EC-Council does not publish an official question count, but from its 240-minute exam (~95–160 total, ~15–26 in this domain), expect 2–3 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
7concepts

Questions 31–35

  1. 31foundation · easy

    Which of the following tools can be used to automate both enumeration and exploitation of privilege escalation vulnerabilities?

    Select an answer first
  2. 32application · medium

    A penetration tester has gained access to a Windows workstation as a standard user. The tester wants to escalate privileges to a local administrator. During enumeration, the tester finds that the local administrator's password is stored in plaintext in a configuration file. Which technique would most directly achieve privilege escalation?

    Select an answer first
  3. 33application · medium

    You have unprivileged access to a Windows 10 machine. WinPEAS shows that the service 'VulnSvc' runs as SYSTEM and its binary path is 'C:\Program Files\VulnApp\vulnservice.exe'. The registry key 'HKLM\SYSTEM\CurrentControlSet\Services\VulnSvc' has weak permissions that allow your user to modify the 'ImagePath' value. What is the most reliable way to escalate privileges?

    Select an answer first
  4. 34foundation · easy

    Which of the following is a common Windows privilege escalation vector that involves a service executable path not enclosed in quotes and containing spaces?

    Select an answer first
  5. 35application · medium

    You have unprivileged access to a Linux server. LinPEAS reports that the file '/usr/local/bin/backup' has the SUID bit set and is owned by root. When you run it, it executes 'cp /etc/passwd /tmp/backup' using the system() function. Which action would allow you to gain a root shell?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CEH” is a trademark of its owner, used for identification only.