
EC-CouncilCertified Penetration Testing Professional
Domain 4Objective 2
Windows Exploitation and Privilege Escalation CPENT Practice Questions (Page 3)
Part of the Perimeter Evasion and Host Exploitation domain, which makes up ~13% of our current practice bank.
40questions here
8free pages
10concepts
Questions 11–15
- 11
You have SYSTEM access on a Windows 10 workstation that is not domain-joined. You need to obtain credentials for a local administrator account. Which approach is most effective?
Select an answer first - 12
You have a standard user account on a Windows 10 machine with UAC set to 'Always Notify'. You need to run an administrative command without triggering a UAC prompt. Which technique is most likely to succeed?
Select an answer first - 13
What is the primary vulnerability in an unquoted service path that allows privilege escalation?
Select an answer first - 14
You have a low-privileged shell on a Windows Server 2016 host. You find a scheduled task 'UpdateTask' that runs as SYSTEM. The task action is 'powershell.exe -File C:\Scripts\update.ps1'. You have write access to C:\Scripts\ but the task's security descriptor prevents modification. The task is scheduled to run every hour. What is the best way to escalate privileges?
Select an answer first - 15
You have administrative access to a Windows server but need to move laterally to a domain controller. You want to extract credentials from the local machine. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.