
EC-CouncilCertified Penetration Testing Professional
Domain 4Objective 2
Windows Exploitation and Privilege Escalation CPENT Practice Questions (Page 2)
Part of the Perimeter Evasion and Host Exploitation domain, which makes up ~13% of our current practice bank.
40questions here
8free pages
10concepts
Questions 6–10
- 6
You find a Windows service named 'SupportSvc' with the following configuration: the service binary path is C:\Program Files\Support\svc.exe, and the service's registry key HKLM\SYSTEM\CurrentControlSet\Services\SupportSvc has weak permissions allowing the Users group to modify the ImagePath value. The service runs as SYSTEM. What is the most direct escalation technique?
Select an answer first - 7
You have a shell as a service account that has the SeAssignPrimaryTokenPrivilege and SeImpersonatePrivilege. You need to escalate to SYSTEM. Which tool is specifically designed to exploit these privileges?
Select an answer first - 8
You have write access to the registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\notepad.exe. You want to escalate privileges when an administrator runs notepad.exe. Which registry value should you set?
Select an answer first - 9
What is the primary purpose of exploiting weak registry permissions for privilege escalation?
Select an answer first - 10
Which of the following is a common technique to exploit a scheduled task for privilege escalation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.