
EC-CouncilCertified Penetration Testing Professional
Domain 5Objective 2
Lateral Movement and Pivoting CPENT Practice Questions (Page 3)
Part of the Active Directory and Lateral Movement domain, which makes up ~8% of our current practice bank.
38questions here
8free pages
8concepts
Questions 11–15
- 11
What is the primary purpose of using SSH tunneling in a penetration test?
Select an answer first - 12
Why is it important to use separate credentials for different lateral movement steps?
Select an answer first - 13
You have compromised a Windows host that is domain-joined and has access to an internal network. You need to pivot to a Linux server on that network, but the Windows host does not have an SSH client installed. Which technique is most appropriate for pivoting from the Windows host?
Select an answer first - 14
You have compromised a Windows workstation and extracted a Kerberos ticket-granting ticket (TGT) for a domain user. You need to access a file server that the user is authorized to access. The file server is in the same domain. Which technique would allow you to use the TGT to access the file server?
Select an answer first - 15
You have valid credentials for a domain user and need to execute a command on a remote Windows server that has WinRM enabled. Which tool or protocol is specifically designed for remote command execution over WinRM?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.