
EC-CouncilCertified Penetration Testing Professional
Domain 4Objective 1
Perimeter Defense Evasion Techniques CPENT Practice Questions (Page 5)
Part of the Perimeter Evasion and Host Exploitation domain, which makes up ~13% of our current practice bank.
25questions here
5free pages
7concepts
Questions 21–25
- 21
You are delivering a web shell to a target behind a WAF that blocks requests containing 'cmd' or 'exec' in the query string. The web application allows file upload. Which technique is most likely to bypass the WAF while still allowing command execution?
Select an answer first - 22
During an internal penetration test, you need to reach a management interface on a server inside a DMZ. The perimeter firewall only permits inbound TCP 443 to the DMZ web server. You have valid credentials for an SSH service on the DMZ web server, but the management interface is not directly reachable. Which technique should you use to access the management interface while staying within the allowed port?
Select an answer first - 23
What should a penetration tester document after validating an evasion technique in a controlled environment?
Select an answer first - 24
Which firewall evasion technique involves splitting a packet into smaller pieces so that the firewall's inspection engine cannot reassemble them in the correct order?
Select an answer first - 25
A stateful firewall is configured to allow outbound TCP connections but blocks inbound connections. You need to establish a reverse shell from a compromised host inside the network to your external server. Which technique is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CPENT
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.