
EC-CouncilCertified Penetration Testing Professional
Domain 5Objective 1
Active Directory Penetration Testing CPENT Practice Questions (Page 6)
Part of the Active Directory and Lateral Movement domain, which makes up ~8% of our current practice bank.
34questions here
7free pages
8concepts
Questions 26–30
- 26
You have local admin on a server and need to move laterally to another server. The target server has Windows Defender Firewall enabled and blocks SMB (port 445) from your current server, but allows WinRM (port 5985). You have credentials for a local admin on the target. Which technique is most appropriate?
Select an answer first - 27
You are testing a forest with a one-way trust: Domain A trusts Domain B. You have compromised Domain A's domain admin. You want to compromise Domain B. Which technique is most likely to succeed?
Select an answer first - 28
You have captured an NTLMv2 hash of a domain admin from a compromised workstation. The target server has SMB signing disabled. You want to move laterally to that server without cracking the hash. Which technique is most appropriate?
Select an answer first - 29
You are on an internal penetration test. You have domain user credentials and need to find a path to Domain Admin. The client has a strict policy: no tools that write to disk, and you must minimize the number of LDAP queries to avoid detection. Which approach best balances stealth and effectiveness?
Select an answer first - 30
What is the primary goal of an NTLM relay attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.