A tester runs an Nmap scan against a Windows server and receives the following results:
Which of the following TCP ports should be prioritized for using hash-based relays?
A. 53
B. 161
C. 445
D. 3389
Show Answer
Correct Answer: C
Explanation: TCP port 445 is SMB (Microsoft-DS), the primary Windows service that commonly uses NTLM authentication and is the standard target for pass-the-hash and NTLM relay attacks. Port 53 (DNS) and 161 (SNMP) are not used for hash relays, and while RDP (3389) can use Network Level Authentication, it is not the primary service prioritized for hash-based relay attacks.
Question 172
A penetration tester conducts reconnaissance for a client's network and identifies the following system of interest:
The tester notices numerous open ports on the system of interest. Which of the following best describes this system?
A. A honeypot
B. A Windows endpoint
C. A Linux server
D. An already-compromised system
Show Answer
Correct Answer: A
Explanation: The best answer is a honeypot. A host exposing an unusually large and diverse set of services across many ports, including combinations that are atypical for a single production system (e.g., both Windows-oriented and Linux-oriented services), is characteristic of a honeypot designed to attract and observe attackers. Numerous open ports alone do not demonstrate compromise, and the observed mix does not fit a typical Windows endpoint or Linux server.
Question 173
In a cloud environment, a security team discovers that an attacker accessed confidential information that was used to configure virtual machines during their initialization. Through which of the following features could this information have been accessed?
A. IAM
B. Block storage
C. Virtual private cloud
D. Metadata services
Show Answer
Correct Answer: D
Explanation: Cloud instance metadata services provide instance metadata and user data used during VM initialization, including startup scripts, temporary credentials, and configuration information. If an attacker can access the instance or exploit SSRF/local access, they may retrieve this initialization data. IAM manages identities and permissions, block storage provides persistent disks, and a virtual private cloud provides network isolation, none of which are the feature specifically used to expose VM initialization metadata.
Question 174
A penetration tester obtains the following output during an Nmap scan:
Which of the following should be the next step for the tester?
A. Search for vulnerabilities on msrpc.
B. Enumerate shares and search for vulnerabilities on the SMB service.
C. Execute a brute-force attack against the Remote Desktop Services.
D. Execute a new Nmap command to search for another port.
Show Answer
Correct Answer: B
Explanation: After identifying exposed services with Nmap, the appropriate next step is targeted enumeration of the most promising service. SMB on port 445 is a high-value target for share enumeration, misconfiguration discovery, and known vulnerability assessment. Searching only MSRPC is less productive initially, brute-forcing RDP is premature and noisy, and rescanning for more ports is not the best next step when actionable services have already been identified.
Question 175
A penetration tester obtains password dumps associated with the target and identifies strict lockout policies. The tester does not want to lock out accounts when attempting access. Which of the following techniques should the tester use?
A. Credential stuffing
B. MFA fatigue
C. Dictionary attack
D. Brute-force attack
Show Answer
Correct Answer: A
Explanation: Credential stuffing uses previously obtained username/password pairs and typically attempts one or a small number of logins per account, reducing the chance of triggering account lockout policies. Dictionary and brute-force attacks involve many password guesses against an account and are more likely to cause lockouts. MFA fatigue targets users with repeated MFA prompts and is unrelated to password dump usage.
Question 176
A penetration tester aims to exploit a vulnerability in a wireless network that lacks proper encryption. The lack of proper encryption allows malicious content to infiltrate the network. Which of the following techniques would most likely achieve the goal?
A. Packet injection
B. Bluejacking
C. Beacon flooding
D. Signal jamming
Show Answer
Correct Answer: A
Explanation: Packet injection is the technique used to inject crafted wireless frames or packets into a Wi-Fi network, which is facilitated when protections are absent or weak. Bluejacking targets Bluetooth, beacon flooding creates fake access point beacons rather than injecting malicious network content, and signal jamming disrupts communications instead of inserting traffic.
Question 177
Given the following statements:
Implement a web application firewall.
Upgrade end-of-life operating systems.
Implement a secure software development life cycle.
In which of the following sections of a penetration test report would the above statements be found?
A. Executive summary
B. Attack narrative
C. Detailed findings
D. Recommendations
Show Answer
Correct Answer: D
Explanation: The statements are remediation and mitigation actions, which belong in the Recommendations section of a penetration test report. The executive summary provides a high-level overview, the attack narrative describes testing activities and attack paths, and detailed findings document vulnerabilities, evidence, and impact.
Question 178
As part of an engagement, a penetration tester wants to maintain access to a compromised system after rebooting. Which of the following techniques would be best for the tester to use?
A. Establishing a reverse shell
B. Executing a process injection attack
C. Creating a scheduled task
D. Performing a credential-dumping attack
Show Answer
Correct Answer: C
Explanation: Creating a scheduled task is a persistence mechanism that can automatically execute a payload or backdoor at system startup, user logon, or on a schedule, allowing access to be re-established after a reboot. A reverse shell and process injection typically do not survive a reboot on their own, and credential dumping is used to obtain credentials rather than maintain persistence.
Question 179
During a routine penetration test, the client's security team observes logging alerts that indicate several ID badges were reprinted after working hours without the appropriate authorization. Which of the following is the penetration tester most likely trying to do?
A. Obtain long-term, valid access to the facility.
B. Disrupt the availabilty of facility access systems.
C. Change access to the facility for valid users.
D. Revoke access to the facility for valid users.
Show Answer
Correct Answer: A
Explanation: Reprinting ID badges after hours without authorization is most consistent with creating duplicate or replacement credentials to gain or maintain physical access while appearing legitimate. This supports persistent, valid-looking facility access rather than disrupting systems, changing existing users' permissions, or revoking their access.
Question 180
A penetration tester is researching a path to escalate privileges. While enumerating current user privileges, the tester observes the following output:
Which of the following privileges should the tester use to achieve the goal?
A. SeImpersonatePrivilege
B. SeCreateGlobalPrivilege
C. SeChangeNotifyPrivilege
D. SeManageVolumePrivilege
Show Answer
Correct Answer: A
Explanation: SeImpersonatePrivilege is the Windows privilege most commonly abused for local privilege escalation. It allows a process to impersonate authenticated clients and is the basis for well-known techniques such as Potato variants and PrintSpoofer to obtain NT AUTHORITY\SYSTEM under the right conditions. The other listed privileges do not generally provide a direct privilege-escalation path.
$19
Get all 342 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.