Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 4Objective 3

Linux Exploitation and Privilege Escalation CPENT Practice Questions (Page 6)

Part of the Perimeter Evasion and Host Exploitation domain, which makes up ~13% of our current practice bank.

48questions here
10free pages
10concepts

Questions 26–30

  1. 26application · medium

    You discover a network service running as root on a Linux server. The service has a known remote code execution vulnerability. What is the most direct way to gain a root shell?

    Select an answer first
  2. 27application · medium

    You find an NFS export /data that is configured with 'no_root_squash' and is writable by your user. You have root access on your own machine. What is the most effective way to escalate privileges on the NFS server?

    Select an answer first
  3. 28expert · hard

    You have a low-privilege shell on a Linux host. 'sudo -l' shows you can run '/usr/bin/passwd' as root without a password. However, the system has 'Defaults requiretty' enabled in sudoers. What is the most likely impact?

    Select an answer first
  4. 29expert · hard

    You have a low-privilege shell on a Linux host. 'sudo -l' shows you can run '/usr/bin/find' as root without a password. However, the system has 'sudo' configured with 'secure_path' that does not include your writable directory. What is the best way to escalate privileges?

    Select an answer first
  5. 30foundation · easy

    What is the primary purpose of using a tool like John the Ripper or Hashcat in a Linux privilege escalation scenario?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.