
EC-CouncilCertified Penetration Testing Professional
Domain 4Objective 3
Linux Exploitation and Privilege Escalation CPENT Practice Questions (Page 8)
Part of the Perimeter Evasion and Host Exploitation domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
10concepts
Questions 36–40
- 36
You have read access to /etc/passwd and /etc/shadow on a Linux system. Which approach would most likely yield a plaintext password for the root account?
Select an answer first - 37
You discover that the root-owned cron job /etc/cron.d/backup runs the script /opt/backup.sh every 5 minutes. The script is writable by your user. What is the most effective way to escalate privileges?
Select an answer first - 38
You have root access on a client that mounts an NFS share from a server. The share is exported with 'no_root_squash' but also with 'noexec'. You need to escalate privileges on the server. Which approach is most likely to succeed?
Select an answer first - 39
Which of the following is an example of a Linux privilege escalation vector that relies on a flaw in the operating system's core component rather than a misconfiguration?
Select an answer first - 40
After gaining root on a Linux server, you want to establish persistence that is stealthy and survives reboots. The server has SELinux enforcing and a host-based intrusion detection system (HIDS) that monitors cron jobs and systemd services. Which persistence mechanism is most likely to evade detection?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.