
EC-CouncilCertified Penetration Testing Professional
Domain 5Objective 2
Lateral Movement and Pivoting CPENT Practice Questions (Page 7)
Part of the Active Directory and Lateral Movement domain, which makes up ~8% of our current practice bank.
38questions here
8free pages
8concepts
Questions 31–35
- 31
Which of the following is a common detection mechanism for lateral movement in Windows environments?
Select an answer first - 32
Which routing technique is commonly used to redirect traffic through a compromised host to access an internal network?
Select an answer first - 33
You have compromised a Windows server and need to execute a command on another server in the same domain. The target server has WinRM enabled and you have valid credentials for a domain user who is in the remote management users group. Which tool would be the most appropriate to execute the command?
Select an answer first - 34
You have compromised a Linux jump host in a DMZ that has connectivity to an internal Windows network. Your workstation cannot reach the internal network directly. You need to use RDP to access a Windows server on the internal network. Which command would you run on your workstation to establish a secure tunnel through the jump host?
Select an answer first - 35
You have compromised a web server that has outbound internet access but no inbound access from your workstation. You need to access an internal database server that is only reachable from the web server. You want to use a tool that can create a reverse tunnel to your workstation, allowing you to route traffic to the internal database. Which tool would be most suitable for this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.