
EC-CouncilCertified Penetration Testing Professional
Domain 4Objective 3
Linux Exploitation and Privilege Escalation CPENT Practice Questions (Page 9)
Part of the Perimeter Evasion and Host Exploitation domain, which makes up ~13% of our current practice bank.
48questions here
10free pages
10concepts
Questions 41–45
- 41
You have a low-privilege shell on a Linux system with kernel version 4.4.0-21-generic. You recall that this kernel is vulnerable to a known local privilege escalation exploit. What is the most appropriate first step?
Select an answer first - 42
You have a shell on a Linux server running kernel 4.4.0-21-generic. The server is unpatched and vulnerable to CVE-2016-5195 (Dirty COW). Which action would most reliably escalate to root?
Select an answer first - 43
You find a SUID binary /usr/bin/backup that runs 'cp' without an absolute path. You have write access to /usr/local/bin. What is the most direct way to escalate privileges?
Select an answer first - 44
You have access to a Linux system and have extracted the root password hash from /etc/shadow. The hash is a SHA-512 crypt hash. You have a wordlist and a GPU-accelerated cracking tool. Which strategy is most likely to crack the password quickly?
Select an answer first - 45
Which file on an NFS server defines the filesystems that are exported and their permissions?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.