Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 4Objective 2

Windows Exploitation and Privilege Escalation CPENT Practice Questions (Page 8)

Part of the Perimeter Evasion and Host Exploitation domain, which makes up ~13% of our current practice bank.

40questions here
8free pages
10concepts

Questions 36–40

  1. 36foundation · easy

    Which Windows process is commonly targeted to extract credentials from memory?

    Select an answer first
  2. 37application · medium

    You are on a Windows Server 2016 host with a low-privileged shell. You enumerate scheduled tasks and find a task named 'CleanupTask' that runs as SYSTEM. The task's action is to execute C:\Scripts\cleanup.bat. You have write access to the C:\Scripts folder but not to the task definition itself. What is the most effective way to escalate privileges?

    Select an answer first
  3. 38foundation · easy

    What is the primary purpose of the Windows Exploit Suggester tool?

    Select an answer first
  4. 39application · hard

    You have a standard user account that is a member of the Administrators group on a Windows 10 machine. UAC is set to default (notify me only when apps try to make changes). You need to run an elevated command silently. Which UAC bypass technique is most likely to work?

    Select an answer first
  5. 40application · medium

    You have a standard user account on a Windows server. You enumerate scheduled tasks and find a task that runs as SYSTEM with the following action: 'Run program: C:\Tools\backup.exe'. You have write access to C:\Tools. What is the most effective way to escalate privileges?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CPENT

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.