
EC-CouncilCertified Penetration Testing Professional
Domain 4Objective 2
Windows Exploitation and Privilege Escalation CPENT Practice Questions (Page 6)
Part of the Perimeter Evasion and Host Exploitation domain, which makes up ~13% of our current practice bank.
40questions here
8free pages
10concepts
Questions 26–30
- 26
What is the primary condition that makes an application vulnerable to DLL hijacking?
Select an answer first - 27
You have a standard user shell on a Windows 10 machine. An application installed in C:\Program Files\LegacyApp runs as SYSTEM and loads a DLL named helper.dll. You discover that helper.dll is not present in the application's directory, and the directory C:\Program Files\LegacyApp is writable by Users. Which technique would allow you to execute code as SYSTEM?
Select an answer first - 28
You have obtained a low-privileged shell on a Windows domain-joined workstation. You need to find credentials that could grant access to other systems. Which approach is most likely to yield usable credentials without requiring immediate SYSTEM privileges?
Select an answer first - 29
You are on a Windows 7 SP1 host with a standard user shell. The host is not fully patched. You need SYSTEM access. Which approach is most appropriate?
Select an answer first - 30
You are on a fully patched Windows 10 22H2 host with a standard user shell. You want to escalate to SYSTEM. Which approach is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.