
EC-CouncilCertified Penetration Testing Professional
Domain 4Objective 1
Perimeter Defense Evasion Techniques CPENT Practice Questions (Page 1)
Part of the Perimeter Evasion and Host Exploitation domain, which makes up ~13% of our current practice bank.
25questions here
5free pages
7concepts
Questions 1–5
- 1
What is the primary function of a proxy in the context of perimeter evasion?
Select an answer first - 2
A firewall is configured to allow only outbound HTTPS traffic. Which application-layer evasion technique could be used to send non-HTTP data through this allowed channel?
Select an answer first - 3
Your client's perimeter firewall blocks all inbound traffic except TCP 80 and 443 to a web server. You need to perform a vulnerability scan against an internal host that is not directly accessible. You have compromised the web server and have administrative access. Which technique is most efficient to scan the internal host?
Select an answer first - 4
What is the primary purpose of evasion encoding in the context of IDS/IPS evasion?
Select an answer first - 5
A client wants to test their perimeter defenses. They have a firewall that blocks all inbound traffic except TCP/80 and TCP/443, and an IPS that inspects HTTP traffic. You need to demonstrate a realistic attack that bypasses these controls. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.