
EC-CouncilCertified Penetration Testing Professional
Domain 5Objective 1
Active Directory Penetration Testing CPENT Practice Questions (Page 5)
Part of the Active Directory and Lateral Movement domain, which makes up ~8% of our current practice bank.
34questions here
7free pages
8concepts
Questions 21–25
- 21
You have achieved domain admin privileges during a penetration test. The client wants to ensure that even if the current domain admin password is changed, you can still regain domain admin access later. Which persistence mechanism is most resilient to password changes?
Select an answer first - 22
During an internal penetration test, you have domain user credentials and are asked to identify the fastest path to Domain Admin without running any tools that write to disk. You have network access to the domain controller and can execute PowerShell in memory. Which approach best meets the objective?
Select an answer first - 23
What does a DCSync attack allow an attacker to do?
Select an answer first - 24
What is the primary difference between a domain trust and a forest trust in Active Directory?
Select an answer first - 25
You have discovered a user account 'svc_web' that has 'Do not require Kerberos pre-authentication' enabled. You have low-privileged credentials. What is the most efficient way to obtain a password hash for this account?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.