
EC-CouncilCertified Penetration Testing Professional
Domain 4Objective 3
Linux Exploitation and Privilege Escalation CPENT Practice Questions (Page 6)
Part of the Perimeter Evasion and Host Exploitation domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
10concepts
Questions 26–30
- 26
You discover a network service running as root on a Linux server. The service has a known remote code execution vulnerability. What is the most direct way to gain a root shell?
Select an answer first - 27
You find an NFS export /data that is configured with 'no_root_squash' and is writable by your user. You have root access on your own machine. What is the most effective way to escalate privileges on the NFS server?
Select an answer first - 28
You have a low-privilege shell on a Linux host. 'sudo -l' shows you can run '/usr/bin/passwd' as root without a password. However, the system has 'Defaults requiretty' enabled in sudoers. What is the most likely impact?
Select an answer first - 29
You have a low-privilege shell on a Linux host. 'sudo -l' shows you can run '/usr/bin/find' as root without a password. However, the system has 'sudo' configured with 'secure_path' that does not include your writable directory. What is the best way to escalate privileges?
Select an answer first - 30
What is the primary purpose of using a tool like John the Ripper or Hashcat in a Linux privilege escalation scenario?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.