Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 5Objective 2

Lateral Movement and Pivoting CPENT Practice Questions (Page 8)

Part of the Active Directory and Lateral Movement domain, which makes up ~8% of our current practice bank.

38questions here
8free pages
8concepts

Questions 36–38

  1. 36application · medium

    You are performing lateral movement in a Windows domain. You have obtained a set of credentials for a service account that has local admin rights on several servers. You need to move to a target server without raising suspicion. The security team monitors for anomalous logon behavior, including logons outside of business hours and from unusual workstations. Which action would best minimize your detection risk?

    Select an answer first
  2. 37application · medium

    During a red team exercise, you are moving laterally between Windows hosts. The SOC is actively monitoring for suspicious service creations and event ID 4624 (logon) anomalies. Which technique is most likely to avoid triggering these specific detections?

    Select an answer first
  3. 38application · medium

    Your lateral movement attempts are being detected because the SOC is monitoring for new services created on endpoints. You need to execute commands on remote Windows hosts without creating a service. Which technique should you use?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CPENT

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.