Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 4Objective 3

Linux Exploitation and Privilege Escalation CPENT Practice Questions (Page 2)

Part of the Perimeter Evasion and Host Exploitation domain, which makes up ~13% of our current practice bank.

48questions here
10free pages
10concepts

Questions 6–10

  1. 6application · medium

    You find a script owned by root that is executed by a cron job. The script calls 'ls' without an absolute path. Your user has write access to one directory in the PATH. How can you exploit this to gain root?

    Select an answer first
  2. 7expert · hard

    You have extracted a root password hash from /etc/shadow, but it is a very strong password. You also have write access to a root cron job. Which approach is more efficient for gaining root?

    Select an answer first
  3. 8foundation · easy

    Which file on a Linux system defines the sudo permissions for users and groups?

    Select an answer first
  4. 9application · medium

    You have a low-privilege shell on a Linux host. Running 'sudo -l' shows the current user can run '/usr/bin/find' as root without a password. Which command would you use to spawn a root shell?

    Select an answer first
  5. 10foundation · easy

    What does the 'no_root_squash' option in an NFS export do?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.