Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 4Objective 3

Linux Exploitation and Privilege Escalation CPENT Practice Questions (Page 8)

Part of the Perimeter Evasion and Host Exploitation domain, which makes up ~13% of our current practice bank.

48questions here
10free pages
10concepts

Questions 36–40

  1. 36application · medium

    You have read access to /etc/passwd and /etc/shadow on a Linux system. Which approach would most likely yield a plaintext password for the root account?

    Select an answer first
  2. 37application · medium

    You discover that the root-owned cron job /etc/cron.d/backup runs the script /opt/backup.sh every 5 minutes. The script is writable by your user. What is the most effective way to escalate privileges?

    Select an answer first
  3. 38expert · hard

    You have root access on a client that mounts an NFS share from a server. The share is exported with 'no_root_squash' but also with 'noexec'. You need to escalate privileges on the server. Which approach is most likely to succeed?

    Select an answer first
  4. 39foundation · easy

    Which of the following is an example of a Linux privilege escalation vector that relies on a flaw in the operating system's core component rather than a misconfiguration?

    Select an answer first
  5. 40expert · hard

    After gaining root on a Linux server, you want to establish persistence that is stealthy and survives reboots. The server has SELinux enforcing and a host-based intrusion detection system (HIDS) that monitors cron jobs and systemd services. Which persistence mechanism is most likely to evade detection?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.