A tester runs an Nmap scan against a Windows server and receives the following results:
Which of the following TCP ports should be prioritized for using hash-based relays?
A. 53
B. 161
C. 445
D. 3389
Show Answer
Correct Answer: C
Explanation: Port 445 (SMB/Microsoft-DS) is the primary service targeted for hash-based relay and pass-the-hash attacks in Windows environments. SMB commonly uses NTLM authentication, which can be captured and relayed for lateral movement. The other ports (DNS 53, SNMP 161, and RDP 3389) do not typically expose or relay authentication hashes in a way suitable for hash-based relay attacks.
Question 52
A penetration tester conducts reconnaissance for a client's network and identifies the following system of interest:
The tester notices numerous open ports on the system of interest. Which of the following best describes this system?
A. A honeypot
B. A Windows endpoint
C. A Linux server
D. An already-compromised system
Show Answer
Correct Answer: A
Explanation: A system exposing an unusually large number of open ports spanning disparate operating system services (e.g., both Windows-specific ports like 135/139/445 and Linux/Unix services like SSH, rsync, and multiple web/admin interfaces) is atypical for a normal endpoint or server. Such broad, intentionally diverse service exposure is characteristic of a honeypot designed to attract and observe attackers rather than a legitimately configured production system.
Question 53
A penetration tester obtains the following output during an Nmap scan:
Which of the following should be the next step for the tester?
A. Search for vulnerabilities on msrpc.
B. Enumerate shares and search for vulnerabilities on the SMB service.
C. Execute a brute-force attack against the Remote Desktop Services.
D. Execute a new Nmap command to search for another port.
Show Answer
Correct Answer: B
Explanation: The scan results indicate SMB is available on port 445, which is a high‑value service for post‑scan enumeration. The appropriate next step is to enumerate SMB shares and assess the service for misconfigurations or known vulnerabilities, as this often yields credentials, sensitive data, or further attack paths. Brute‑forcing RDP is premature and noisy, rescanning ports is unnecessary, and MSRPC is typically less immediately fruitful than SMB.
Question 54
A penetration tester obtains password dumps associated with the target and identifies strict lockout policies. The tester does not want to lock out accounts when attempting access. Which of the following techniques should the tester use?
A. Credential stuffing
B. MFA fatigue
C. Dictionary attack
D. Brute-force attack
Show Answer
Correct Answer: A
Explanation: With strict account lockout policies, the tester must minimize failed login attempts per account. Credential stuffing uses previously obtained username/password pairs and typically attempts only one or a very small number of logins per account, spreading attempts across many accounts and avoiding lockouts. Dictionary and brute-force attacks generate many failures per account, and MFA fatigue targets users with push requests rather than avoiding lockouts.
Question 55
A penetration tester aims to exploit a vulnerability in a wireless network that lacks proper encryption. The lack of proper encryption allows malicious content to infiltrate the network. Which of the following techniques would most likely achieve the goal?
A. Packet injection
B. Bluejacking
C. Beacon flooding
D. Signal jamming
Show Answer
Correct Answer: A
Explanation: Packet injection is the most appropriate technique because a wireless network lacking proper encryption allows an attacker to craft and inject malicious packets directly into the traffic stream. This can be used to manipulate communications or deliver malicious content. The other options involve Bluetooth messaging (bluejacking) or denial-of-service style disruptions (beacon flooding, signal jamming), not content infiltration.
Question 56
Given the following statements:
Implement a web application firewall.
Upgrade end-of-life operating systems.
Implement a secure software development life cycle.
In which of the following sections of a penetration test report would the above statements be found?
A. Executive summary
B. Attack narrative
C. Detailed findings
D. Recommendations
Show Answer
Correct Answer: D
Explanation: The statements describe mitigation and remediation actions (e.g., implementing controls, upgrading systems, adopting secure SDLC). These are typically presented in the Recommendations section of a penetration test report, not in the executive summary, attack narrative, or detailed findings.
Question 57
As part of an engagement, a penetration tester wants to maintain access to a compromised system after rebooting. Which of the following techniques would be best for the tester to use?
A. Establishing a reverse shell
B. Executing a process injection attack
C. Creating a scheduled task
D. Performing a credential-dumping attack
Show Answer
Correct Answer: C
Explanation: Maintaining access after a reboot requires a persistence mechanism. Creating a scheduled task allows a payload or backdoor to execute automatically at startup or on a schedule, surviving reboots. Reverse shells and process injection are typically transient and end when the system restarts, while credential dumping aids further compromise but does not provide persistence.
Question 58
During a routine penetration test, the client's security team observes logging alerts that indicate several ID badges were reprinted after working hours without the appropriate authorization. Which of the following is the penetration tester most likely trying to do?
A. Obtain long-term, valid access to the facility.
B. Disrupt the availabilty of facility access systems.
C. Change access to the facility for valid users.
D. Revoke access to the facility for valid users.
Show Answer
Correct Answer: A
Explanation: Reprinting ID badges after hours without authorization indicates cloning or issuing duplicate credentials to create persistent, legitimate-looking physical access. This aligns with a penetration tester’s goal of obtaining long-term, valid access rather than disrupting systems or modifying/revoking legitimate users’ access.
Question 59
A penetration tester is researching a path to escalate privileges. While enumerating current user privileges, the tester observes the following output:
Which of the following privileges should the tester use to achieve the goal?
A. SeImpersonatePrivilege
B. SeCreateGlobalPrivilege
C. SeChangeNotifyPrivilege
D. SeManageVolumePrivilege
Show Answer
Correct Answer: A
Explanation: SeImpersonatePrivilege allows a process to impersonate another authenticated security context. In Windows privilege escalation, this is the most commonly abused privilege because it enables well-known token impersonation attacks (e.g., Juicy Potato, Rotten Potato, PrintSpoofer) that can reliably escalate a low-privileged user to SYSTEM. The other listed privileges are generally not sufficient on their own for direct privilege escalation.
Question 60
During an engagement, a penetration tester needs to break the key for the Wi-Fi network that uses WPA2 encryption. Which of the following attacks would accomplish this objective?
A. ChopChop
B. Replay
C. Initialization vector
D. KRACK
Show Answer
Correct Answer: D
Explanation: WPA2 is vulnerable to the KRACK (Key Reinstallation Attack), which exploits flaws in the WPA2 4‑way handshake to force key reinstallation and enable decryption of traffic. The other options (ChopChop, replay, IV attacks) target WEP-era weaknesses and do not break WPA2 encryption.
$19
Get all 220 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.