Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 4Objective 3

Linux Exploitation and Privilege Escalation CPENT Practice Questions (Page 9)

Part of the Perimeter Evasion and Host Exploitation domain, which makes up ~13% of our current practice bank.

48questions here
10free pages
10concepts

Questions 41–45

  1. 41application · medium

    You have a low-privilege shell on a Linux system with kernel version 4.4.0-21-generic. You recall that this kernel is vulnerable to a known local privilege escalation exploit. What is the most appropriate first step?

    Select an answer first
  2. 42application · medium

    You have a shell on a Linux server running kernel 4.4.0-21-generic. The server is unpatched and vulnerable to CVE-2016-5195 (Dirty COW). Which action would most reliably escalate to root?

    Select an answer first
  3. 43application · medium

    You find a SUID binary /usr/bin/backup that runs 'cp' without an absolute path. You have write access to /usr/local/bin. What is the most direct way to escalate privileges?

    Select an answer first
  4. 44expert · hard

    You have access to a Linux system and have extracted the root password hash from /etc/shadow. The hash is a SHA-512 crypt hash. You have a wordlist and a GPU-accelerated cracking tool. Which strategy is most likely to crack the password quickly?

    Select an answer first
  5. 45foundation · easy

    Which file on an NFS server defines the filesystems that are exported and their permissions?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.