Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 5Objective 2

Lateral Movement and Pivoting CPENT Practice Questions (Page 3)

Part of the Active Directory and Lateral Movement domain, which makes up ~8% of our current practice bank.

38questions here
8free pages
8concepts

Questions 11–15

  1. 11foundation · easy

    What is the primary purpose of using SSH tunneling in a penetration test?

    Select an answer first
  2. 12foundation · easy

    Why is it important to use separate credentials for different lateral movement steps?

    Select an answer first
  3. 13expert · hard

    You have compromised a Windows host that is domain-joined and has access to an internal network. You need to pivot to a Linux server on that network, but the Windows host does not have an SSH client installed. Which technique is most appropriate for pivoting from the Windows host?

    Select an answer first
  4. 14application · medium

    You have compromised a Windows workstation and extracted a Kerberos ticket-granting ticket (TGT) for a domain user. You need to access a file server that the user is authorized to access. The file server is in the same domain. Which technique would allow you to use the TGT to access the file server?

    Select an answer first
  5. 15application · medium

    You have valid credentials for a domain user and need to execute a command on a remote Windows server that has WinRM enabled. Which tool or protocol is specifically designed for remote command execution over WinRM?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.