
EC-CouncilCertified Penetration Testing Professional
Domain 5Objective 1
Active Directory Penetration Testing CPENT Practice Questions (Page 3)
Part of the Active Directory and Lateral Movement domain, which makes up ~8% of our current practice bank.
34questions here
7free pages
8concepts
Questions 11–15
- 11
You are enumerating Active Directory using LDAP queries. Which LDAP query would you use to find all user objects that are members of the 'Domain Admins' group?
Select an answer first - 12
You have compromised a domain user and need to execute a command on a remote Windows server without creating a new service or writing a binary to disk. You want to minimize the chance of detection by EDR. Which technique is most appropriate?
Select an answer first - 13
You are on a penetration test with a strict rule: do not modify any AD objects (no adding users, no changing group memberships, no ACL changes). You have low-privileged credentials and have found that a service account 'svc_app' has a weak password and is a member of 'Backup Operators'. You need to escalate to domain admin. Which approach is most aligned with the constraint?
Select an answer first - 14
Which Windows remote management protocol uses TCP port 5985 (or 5986 for HTTPS) and allows PowerShell remoting, making it a common lateral movement technique?
Select an answer first - 15
You are testing a multi-domain forest. You have compromised a domain admin in Domain A. Domain B has a bidirectional trust with Domain A. Which technique would allow you to compromise Domain B?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.