
EC-CouncilCertified Penetration Testing Professional
Domain 5Objective 1
Active Directory Penetration Testing CPENT Practice Questions (Page 2)
Part of the Active Directory and Lateral Movement domain, which makes up ~8% of our current practice bank.
34questions here
7free pages
8concepts
Questions 6–10
- 6
You have Domain Admin privileges and want to establish persistence that survives a krbtgt password reset (performed twice) and is not easily detected by security teams. Which method is most appropriate?
Select an answer first - 7
You have compromised a server that has 'Unconstrained Delegation' enabled. You are a standard domain user. Which attack would allow you to capture a domain admin's TGT and escalate privileges?
Select an answer first - 8
Which Active Directory misconfiguration allows a user to authenticate to a service that then impersonates the user on behalf of the service, potentially allowing the attacker to access other resources as the user?
Select an answer first - 9
What is a 'living-off-the-land' (LOL) binary in the context of Active Directory penetration testing?
Select an answer first - 10
You have obtained a low-privileged domain user account and need to move laterally to a file server. You discover that a service account 'svc_backup' has a Service Principal Name (SPN) and is a local administrator on the file server. Which attack would allow you to obtain a password hash for 'svc_backup' without sending any traffic to the file server?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.