CPTS practice questions
Hack The Box · CPTS · 300 questions
Original practice questions for the Hack The Box HTB Certified Penetration Testing Specialist (CPTS) exam, covering penetration testing methodology, information gathering, exploitation fundamentals, pivoting and lateral movement, Active Directory attacks, web application penetration testing, privilege escalation, and documentation and reporting.
This course contains the use of artificial intelligence.
About the CPTS exam
The real exam is hands-on rather than multiple choice. The questions here drill the underlying knowledge; they do not reproduce the exam's format.
- Exam fee
- $210 USD
- Time allowed
- 10 days
- Passing score
- 12 of 14 flags within a 10-day window, plus a graded professional pentest report
- Format
- Hands-on practical exam, no multiple choice: a dedicated 10-day penetration-testing lab against a real-world Active Directory network, flags submitted on the lab page, plus a commercial-grade written report from a supplied template
Schedule this exam The certification this earns
Exam details published by the vendor, checked 28 August 2026. Vendors change fees and formats without notice — confirm on the vendor's own page before you book.
Practice Quizzes
Test your knowledge with standard 20-question practice sets.
Quiz 1
Quiz 2
Quiz 3
Quiz 4
Quiz 5
Quiz 6
Quiz 7
Quiz 8
Quiz 9
Quiz 10
Quiz 11
Quiz 12
Quiz 13
Quiz 14
Quiz 15
Browse by Domain
Study specific topics at your own pace.
Penetration Testing Process & Methodology · 25 questions
- A county CIO asks what a letter of engagement is supposed to lock in before any scanning starts. What should the tester treat as the primary purpose of that letter?
- A city attorney objects to a municipal pentest scoped as 'test everything on the network.' Why is that scope statement a professional risk?
- A water-utility board treats a vulnerability assessment and a full penetration test as the same deliverable. What distinction should the tester emphasize?
- A library consortium assumes staff LinkedIn OSINT is automatically in scope for a municipal web engagement. What is the sound professional stance?
- A transit IT lead requires that all active testing occur only after hours. How should that requirement be handled?
- A school district's rules of engagement forbid intentional denial-of-service during the assessment. A tester finds a path that would likely crash a critical student portal. What is the correct action?
- A mayor's office asks who can authorize a penetration test against city systems. Which answer is professionally correct?
- A parks department requests 'black box' external testing but provides full network diagrams on day one. What should the tester recognize?
- A municipal SOC asks for the high-level stages of a professional penetration test in sound order. Which sequence best reflects standard methodology flow?
- A county assessor asks why enumeration is not the same as exploitation during a CPTS-style engagement. What is the clearest distinction?
- A civic open-data portal engagement is scoped as web-application testing only, but a tester begins port-scanning the entire municipal /16. What problem does that create?
- A city grants VPN access for an Active Directory-focused internal assessment. How should the tester characterize the starting posture?
- A utility CISO asks what threat-landscape-driven testing means compared with only hunting famous CVEs. Which statement best captures the CPTS-style emphasis?
- A township requires immediate notification if critical findings appear during testing. How should the tester treat that expectation?
- A court IT manager frames success as 'get in and root everything,' while the engagement objective is protecting case data. What should the tester reinforce?
- A new hire wonders why careful note-taking matters before any exploit attempt on a municipal engagement. What is the best reason?
- A municipal team asks the tester to change production firewall rules mid-engagement 'to help secure them.' What is the appropriate response?
- A city procurement officer asks why a letter of engagement and report expectations appear at kickoff. What is the best explanation?
- A county asks whether skipping fundamentals on a training path is fine before a client engagement. What readiness stance should guide the answer?
- A library IT lead asks how lab reset habits differ from caution on a production municipal network. Which contrast is accurate?
- A public-health agency asks who owns residual risk after the penetration test findings are delivered. Who owns that decision?
- A city wants one commercial tool that will 'do the whole pentest' without further methodology. What should the tester explain?
- A transit security manager asks why legal and ethical boundaries still apply after a contract is signed. What is the right framing?
- A municipal PMO asks when reporting work should start during a multi-week penetration test. What timing is preferred?
- A county board asks what a commercial-grade penetration test report implies beyond a list of CVE IDs. Which answer best fits?
Information Gathering & Enumeration · 40 questions
- A city network team wants host discovery on an approved /24 before deep port scans. Which approach best fits rules of engagement while reducing unnecessary noise?
- A county SOC reports that a full TCP connect scan across all ports saturated a fragile SCADA historian VLAN that was mistakenly treated as fair game. What is the soundest lesson for scan aggressiveness?
- A municipal admin asks why service version detection matters after open ports are already listed. What is the primary reason to collect versions?
- A library IT lead treats a quick top-ports scan as the complete enumeration plan for an engagement. How should the tester correct that view?
- A transit blue team sees NSE-class scripts run during a test and asks what those scripts are for. Which answer best describes their role?
- A water utility asks whether UDP services can be ignored because TCP scans looked quiet. What should the tester explain?
- City firewall logs show a tester scanning out-of-scope partner ranges discovered via traceroute. What is the correct response to that discovery?
- A county wants stealthy scan timing but also has a short engagement window. How should the tester judge the tradeoff?
- A municipal DMZ review finds many filtered ports. What is the most accurate interpretation for next enumeration steps?
- A civic Wi-Fi guest VLAN is in scope for discovery only, but a tester proposes starting credential attacks immediately. What should happen?
- A school district asks why repeating scans after mid-engagement changes matters. What is the best answer?
- A city asks whether banner grabbing is hacking or enumeration. How should the tester classify it?
- A county mail gateway exposes rich SMTP behaviors and user-enumeration traits during approved probing. What should the tester emphasize about that footprinting?
- A municipal file share answers detailed SMB dialect and OS clues to unauthenticated probes. Why does that matter during footprinting?
- A library's internal DNS allows zone data leakage to the tester's approved network. How should that finding be framed?
- A city still uses well-known default SNMP communities on printers reachable in scope. What should the tester recognize?
- A transit database listener responds with version strings to simple approved probes. What is the best use of that footprinting result?
- A county VPN concentrator's management path is reachable from the test VLAN during footprinting. What should the tester flag?
- A civic application's FTP service allows anonymous listing during approved testing. How should the tester handle that result?
- A municipal AD-integrated web portal leaks internal naming via remote desktop gateway banners. What should the tester do with those multi-protocol clues?
- A city marketing site is in scope, and the tester starts with passive archive and certificate transparency review before active crawling. Why is that judgment sound?
- A county portal's HTTP headers reveal framework and server versions. How should the tester use that fingerprinting?
- A library site hides admin paths, so content discovery is planned. What is the proper purpose of that activity?
- A transit booking app's DNS reveals staging and admin subdomains. Why is subdomain enumeration core web recon?
- A city API gateway exposes verbose error messages with stack traces during recon. How should that be framed?
- A municipal public website starts returning 429 and gateway errors after the tester launches aggressive automated crawls. Rules of engagement cap request rates and protect availability. What should the tester do next?
- A county security lead asks whether searching public indexes for exposed PDFs, backups, and forgotten endpoints is still useful during a scoped external assessment. What is the best guidance?
- A civic identity portal returns "account not found" for some usernames and "invalid password" for others during login attempts the RoE permits. What finding class should the tester report?
- A city application sits behind a CDN that hides origin addresses, and the RoE allows origin discovery if it stays non-disruptive. Which recon approach best matches that goal?
- While reviewing a school district web app, the tester finds HTML comments pointing to forgotten VCS directories and backup archive paths still reachable in scope. How should those artifacts be treated?
- A county IT manager points at a green vulnerability-scanner dashboard and says the annual penetration test is finished. What clarification should the assessor give?
- A city VA report lists hundreds of low-severity findings and buries one critical default credential on an internet-facing admin portal. How should prioritization work?
- A municipal scanner flags a TLS configuration issue on an internal tool that manual review shows is a false positive. What should the tester do before delivering the finding as confirmed?
- A public library asks how approved credentialed scanning differs from unauthenticated scanning on the same subnet. What is the accurate distinction?
- A transit authority VA must serve both executives and system owners. Which reporting quality best drives remediation?
- A city wants to treat continuous vulnerability scanning as continuous penetration testing and cancel periodic adversarial assessments. What should the tester advise?
- A county risk register wants to import scanner base scores unchanged for every civic asset. What caution should guide severity mapping?
- A water-utility SCADA vendor appliance is fragile; scanning policy and RoE require it to be excluded. What is the professional handling?
- A municipal team asks the tester to run the vulnerability scanner and leave without analysis. What professional stance fits a complete VA?
- A city compares last year's vulnerability assessment to this year's penetration-test scope and wants to skip fresh enumeration because "the VA already listed everything." What should the tester do?
Exploitation Fundamentals · 35 questions
- On a county foothold host, common third-party file-copy utilities are blocked by policy, but built-in OS features remain available within scope. Which transfer approach is most appropriate at a concept level?
- A city Linux target allows outbound HTTP only; other egress is blocked. How should the tester choose a file-transfer approach?
- A municipal Windows host grants the tester only a standard user session; software installs that need admin rights are blocked. What staging concept fits?
- A transit engagement requires that any files transferred onto targets be removable after testing. What practice supports that requirement?
- A library server permits SMB from the tester's jump host, and HTTP and FTP are also reachable in scope. How should transfer protocol choice be framed?
- A water-utility jump box is Linux while many targets are Windows. What cross-platform transfer concern should the tester plan for conceptually?
- A city firewall allows outbound connections from a compromised host but blocks unsolicited inbound connections to that host. Which shell-direction concept fits that posture?
- A county RoE forbids leaving persistent listeners or implants after the test day. Which approach aligns with that constraint?
- A municipal tester mixes up staged and stageless payload delivery concepts during planning. Which statement captures the tradeoff at a high level—without providing a payload?
- A civic Windows host terminates unfamiliar binaries quickly under endpoint controls. At a concept level, what should guide the next remote-access choice within RoE?
- A city IT lead wants Metasploit used for every exploitation task on the engagement. What is the soundest way to position the framework?
- A county asks what Metasploit auxiliary, exploit, and post modules are each for. Which mapping is correct?
- A library engagement opens multiple Metasploit sessions across hosts. What session-management practice best protects scope?
- A transit tester treats a successful Metasploit check as enough proof of business impact. What should they do instead?
- Municipal policy bans certain automated exploitation frameworks on OT segments listed in the Rules of Engagement. What should the tester do?
- A city login portal has no lockout. The tester must choose a password-attack approach that still respects careful RoE. Which judgment is soundest?
- A county engagement obtains an NTLM-class hash within scope. Conceptually, which distinction should guide next steps?
- A library still uses vendor default credentials on a printer admin page. How should that be treated?
- A transit Wi-Fi captive portal uses one seasonal staff password shared across the team. What risk framing is most accurate?
- A city Active Directory policy allows short passwords. What impact should the assessment highlight?
- A municipal app stores unsalted legacy password hashes. Why does that matter for offline attacks?
- A county sponsor wants every password in a huge list tried against production OWA tonight. What is the correct response?
- A civic helpdesk resets passwords using predictable temporary patterns. What finding class does this represent?
- A city tester finds cleartext credentials inside scripts on an accessible file share. What technique class does this illustrate?
- A water plant asks whether cracked passwords should appear in cleartext in the main report. What handling is appropriate?
- A county exposes internet-facing SSH with password authentication and no MFA. How should this be framed?
- A city still transfers sensitive files with FTP that moves credentials in cleartext. What is the core risk?
- A library database listens on a wide network with weak privileged authentication. What finding class fits best?
- A municipal NFS export is world-readable and contains SSH private keys. What connection should the report emphasize?
- From the approved test segment, a transit mail server behaves as an open relay. How should this be classified?
- County printers expose management protocols on the same VLAN as user workstations. What should the assessment highlight?
- A city CI server's service account allows interactive logon and uses a weak password. Why is that risky?
- A civic cache or queue service binds on an internal host with no authentication. What does that represent?
- A municipal Windows host still runs a legacy file-sharing protocol required by one application. How should risk be framed?
- A county asks the tester to exploit Domain Admin as the first step without service enumeration. What should the tester do?
Pivoting, Tunneling & Lateral Movement · 30 questions
- A city web foothold can reach hosts on a payroll VLAN that the tester laptop cannot route to. What is the appropriate next judgment?
- A county tester gains a low-privilege shell and wants to reach a different subnet. Why is pivoting the wrong label for simply becoming local Administrator on that same host?
- A municipal RoE lists exact CIDR blocks allowed for lateral movement. The tester’s tunnel can technically reach an unlisted research segment. What should they do?
- A transit engagement needs RDP to an internal workstation that is reachable only from a jump host the tester already controls. Which approach best matches that goal at a concept level?
- A library IT lead asks how local and remote port forwards differ at a high level. What distinction should the tester emphasize?
- A city needs several protocols into an isolated subnet through one foothold, not just a single mapped port. What class of approach is generally more suitable than one-off forwards alone?
- A county firewall permits only HTTPS egress from a foothold. Which tunneling judgment fits that constraint without writing a configuration recipe?
- A municipal SOC notices unexpected reverse connections from a workstation used as a pivot. Beyond stopping the noise, what should the tester ensure for the engagement record?
- A water utility’s OT network sits adjacent to an in-scope IT foothold but is explicitly out of scope. The path is technically reachable. What is the correct action?
- A civic Windows foothold can speak SMB to a file server that the tester’s laptop cannot reach. What conceptual use of the foothold is appropriate?
- A city wants the tester to exercise browser-based admin apps that are only reachable through an internal path after foothold. Which pivoting pattern fits that use-case?
- A county path requires DMZ web → internal app → AD subnet hops. What planning posture should the tester take?
- A transit tester’s overlapping local forwards collide and break their own access mid-assessment. What hygiene lesson applies?
- A library Linux foothold is non-root. The tester still wants a user-level forward. What privilege constraint should they remember conceptually?
- A municipal RoE bans reverse shells but allows SSH-based forwards when valid credentials exist. How should the tester choose a pivot channel?
- A city asks whether ARP spoofing on a production VLAN is an acceptable default pivot method. What is the sound judgment?
- A county foothold drops intermittently. The team wants to race into deep lateral movement immediately. What should come first?
- A civic app tier is compromised; the database tier is segmented. What should the tester assume about DB access?
- A city tester pastes cleartext passwords used for pivots into a shared team chat. What is wrong with that practice?
- A municipal Windows host can open admin shares on peer systems using stolen user credentials. How should that pattern be framed in findings?
- A transit team debates dropping many binaries on a pivot host versus running tools remotely over an established tunnel. What footprint advantage can the tunnel approach offer?
- A county IPv6 path reaches internal hosts that IPv4 filtering blocked. What dual-stack lesson belongs in pivot planning?
- A city jump host requires interactive MFA, which breaks unattended tunnel automation. What planning adjustment is appropriate?
- A library engagement ends today, but tester tunnels and forwards are still active. What closeout action is required?
- A municipal tester discovers a trust route into a partner extranet. What must happen before testing across that trust?
- A water utility SCADA historian is reachable through an approved pivot path but the rules of engagement mark the system as fragile. What is the sound next move?
- A city security lead asks how adding layer-3 routes on a compromised foothold differs from using application-layer tunnels for reachability. What conceptual contrast should the tester emphasize?
- A county blue team requests an IOC-style list of all pivot ports and protocols used during the engagement. What should already be true of the tester's working notes?
- From a civic Kubernetes worker-node foothold, the tester notices pod networks that look flatter than the surrounding datacenter VLANs. What awareness should guide further pivoting?
- A municipal sponsor starts treating 'number of pivots completed' as the engagement success metric instead of risk to crown-jewel systems. How should the tester recenter the work?
Active Directory Enumeration & Attacks · 55 questions
- After gaining a foothold on a city domain-joined laptop, what should the tester prioritize first for Active Directory situational awareness?
- A county asks why Active Directory remains a large attack surface even when OS patch levels look solid. What explanation best fits?
- A municipal tester proposes running every Active Directory attack tool simultaneously on day one. What is the better professional approach?
- A library engagement needs a foundation for later AD attack-path planning. Which enumeration class best builds that map?
- A transit engineer finds unconstrained delegation configured on a server account. How should this be treated in the assessment narrative?
- A city service account has SPNs registered and is exempt from the strong password policy. Which risk class should the tester highlight?
- During a county AD review, several users are found with Kerberos pre-authentication disabled. What does that configuration class represent?
- A municipal IT group places Domain Admin rights on many day-to-day admin accounts. What finding theme should the tester raise?
- A civic GPO grants local administrator rights on workstations to a broad user group. Why is this a significant AD-related finding?
- A water utility still allows legacy LM or NTLMv1 preference in parts of the environment. What risk awareness should the tester communicate?
- A city assessment finds printers and servers that accept NTLM authentication without required signing. How should this configuration class be framed?
- A county OU ACL grants a helpdesk group Full Control over user objects. What should the tester conclude?
- A library domain allows excessive machine-account creation or join rights for ordinary users. Why does that matter conceptually?
- A transit authority's AD CS deployment includes overly permissive certificate templates. How should the tester characterize the issue?
- A city CISO asks what BloodHound-class AD graphing tools are for. Which explanation is accurate?
- A municipal forest maintains an external trust to a vendor domain. What should the tester do conceptually regarding that trust?
- A county assessment finds plaintext passwords in AD descriptions or scripts stored in SYSVOL. What finding class does this represent?
- A civic application service runs as Domain Admin without a strong justification. What recommendation aligns with AD least privilege?
- A city GPO legacy setting disables SMB signing domain-wide. What conceptual link should the tester make in the report?
- A library's LDAP configuration allows anonymous or overly broad read of sensitive directory attributes. What should the tester flag?
- A transit administrator uses the same password on a personal Domain Admin account and a daily workstation login. What hygiene lesson should the report emphasize?
- A municipal Windows estate has no LAPS-class local administrator password solution, so many workstations share the same local admin password. What risk should the tester highlight?
- A county discovers constrained Kerberos delegation configured on several service accounts. How should the assessment treat that finding?
- From the approved test VLAN, a city domain controller still permits null-session enumeration of users and shares. What should the tester report?
- A civic tiered-administration model exists on paper, yet operators routinely use Domain Admin credentials inside ordinary email and browsing sessions. What concept should the finding stress?
- A water utility domain still runs unsupported domain controllers. How should the tester prioritize that observation?
- A county places a read-only domain controller at a lightly secured branch with a weak password-caching policy. What AD design risk is most relevant?
- After cracking one standard user hash, a municipal stakeholder asks whether that automatically equals Domain Admin. What is the correct response?
- A city finds Print Spooler-related remote capabilities still enabled on domain controllers contrary to hardening guidance. How should that be framed?
- A library Active Directory ACL lets a helpdesk-related group modify membership of an Administrators-tier group. What control question does this raise?
- A transit domain configures extremely long Kerberos ticket lifetimes. What conceptual risk should the report call out?
- During business hours, a municipal tester begins a very large, noisy Active Directory data pull that conflicts with the agreed RoE timing. What should the tester do?
- A county asks how local administrator rights on a workstation differ from domain user rights when planning Active Directory attack paths. What distinction matters most?
- A city still has legacy Windows hosts domain-joined with weak local controls. How should the tester treat them in an AD path assessment?
- A civic forest shows poor handling of inter-domain trust secrets and related trust passwords. What concept should the finding emphasize?
- A municipal GPO broadly disables Defender-class endpoint protections across domain-joined hosts. What should the assessment report?
- A county finds many computer accounts with machine passwords that have not rotated for an unusually long time. What hygiene theme applies?
- A transit Active Directory site topology is broken, producing odd authentication routing during the assessment. Why does that matter?
- A city helpdesk group can reset passwords on privileged user accounts. What risk should be highlighted?
- A library stores backup Domain Admin credentials in a ticketing system readable by many staff. How should identity risk be framed?
- A municipal engagement objective is proving a path to a crown-jewel file server via Active Directory. The tester already has a viable path but considers dumping NTDS "for completeness." What methodology stance is correct?
- A county asks whether Azure AD / Entra hybrid identity topics are automatically core to a CPTS-style on-prem Active Directory engagement. What is the right scope stance?
- A city finds unconstrained Kerberos authentication delegation enabled on a web server account. Why is that significant?
- A water plant vendor account remains in Domain Admins "temporarily" for years. What should the finding stress?
- After a domain migration, a civic directory still shows SID History and related leftover privilege artifacts granting unexpected access. How should the tester treat that?
- A county AD review finds DCSync-class replication rights granted to a normal user account that is not a domain controller. What should the tester treat as the core risk?
- During a municipal AD engagement, an anxious stakeholder asks the tester to “disable the entire domain to stop the test.” What is the professional next step?
- A transit AD assessment discovers a Group Policy Object that is writable by a low-privilege group and linked to OUs holding high-value servers. How should the tester frame the finding?
- A city IT lead asks why clock skew between workstations and domain controllers matters for Kerberos. What awareness-level answer is most accurate?
- A library’s compromise-recovery plan for Active Directory never mentions the krbtgt account password. What recovery-hygiene point should the tester emphasize?
- A county gold image used for fleet builds embeds a domain-join credential in the template. What AD-adjacent risk should the assessment highlight?
- A municipal AD security review finds that privileged group membership and ACL changes are not monitored. What operational gap does that primarily create?
- A city engagement asks how Active Directory enumeration differs when the tester has a valid domain user versus working from a non-domain foothold. What is the key visibility contrast?
- A civic AD assessment identifies an enterprise certificate authority as a crown-jewel asset. How should the tester prioritize ADCS/CA review when it is in scope?
- A municipal tester proposes spraying AD passwords during the city’s lunch peak without checking lockout policy. What constraint should shape that decision first?
Web Application Penetration Testing · 60 questions
- A city web engagement begins by placing an intercepting proxy in the browser path. What is the primary reason that step matters?
- A county thick-client application speaks HTTP to backend APIs. How should proxy skills apply?
- A municipal web app uses certificate pinning that breaks the tester’s TLS interception. What is the sound methodological response?
- A library tester needs to vary a single request parameter while keeping the rest of a captured HTTP call intact. Which approach best matches controlled testing judgment?
- A transit content-discovery pass will use Ffuf-class tooling against a civic CMS. What discovery practice should guide the run?
- A city API exposes predictable paths such as /v1/user/{id}. Beyond listing HTML pages, what should discovery planning emphasize?
- A county web login form will be tested with carefully limited credential attempts under the rules of engagement. What constraint remains non-negotiable?
- A municipal app reflects user input into HTML responses without encoding. How should the tester classify the primary risk theme?
- A library comment field stores script that later runs in an administrator’s browser. Which XSS class best describes that pattern?
- A transit portal builds page behavior from untrusted URL fragments that flow into DOM sinks. What XSS theme does that illustrate?
- A city session cookie is missing the HttpOnly flag. In an XSS discussion, why does that matter?
- A county search box returns database-flavored errors that suggest SQL injection. What should the tester do before any broad automated dumping?
- A municipal app shows no verbose SQL errors, yet responses consistently change between true-looking and false-looking conditions for crafted inputs. How should that theme be classified?
- A library stakeholder wants SQLMap run against production with full crawl and unrestricted dump options. What automation judgment should the tester apply?
- A transit UNION-based SQL injection could return citizen PII. How should the tester demonstrate impact responsibly?
- A city portal stores a citizen nickname that is later reused in a different admin report query. Injection fails on the registration request but succeeds when staff generate that report. What injection class best fits this pattern?
- A county download endpoint accepts a file path parameter and returns document contents with little sanitization. What vulnerability class should the tester prioritize investigating?
- A municipal template engine includes remote URLs supplied by users when rendering pages. What risk class should the tester flag?
- A library upload form rejects filenames ending in .php but accepts the same script contents when renamed with an image extension and a matching Content-Type. What validation weakness does this demonstrate?
- A transit portal stores user uploads under a web-accessible directory where the server will execute matching scripts. Why is this combination a critical finding class?
- A city blocks a short list of dangerous extensions but does not normalize case, double extensions, or alternate handlers. What is the sound assessment takeaway?
- A county ticket system passes unsanitized user fields into a shell command that generates PDFs. Which vulnerability class does this describe?
- A municipal filter strips semicolon characters from PDF-job inputs but still shells out to build the command. What is the correct conceptual judgment?
- A library PDF feature never echoes command output, but carefully timed requests show consistent delays that track injected sleep-style behavior under RoE. What detection concept applies?
- A transit admin delete action is blocked on POST but succeeds when the same URL is requested with PUT or DELETE. What attack class does this illustrate?
- A city citizen portal shows another resident's case details when only the case ID in the URL is changed. What vulnerability class is this?
- A county intake form accepts XML uploads and the parser resolves external entities. What risk class should the tester report?
- A municipal API accepts a hidden role field from the client JSON body and grants admin features when it is set. What flaw theme should the tester call out?
- A library account settings page changes email via session-cookie authenticated POST with no anti-CSRF token or equivalent defense. What vulnerability class fits?
- A transit operations admin console uses HTTP Basic authentication over plain HTTP on an internal VLAN. How should the tester treat this?
- A city public CMS is years behind on patches and still serves the default administrator path. What hygiene finding theme is most accurate?
- A county continuous-integration portal similar to Jenkins is reachable from the internet with weak password-only auth. How should the tester prioritize it?
- A municipal database administration UI similar to phpMyAdmin is reachable without MFA and with broad network access. What is the correct finding emphasis?
- A library multi-tenant SSO setup lets a user from one tenant open another tenant's account context after a misconfigured identity mapping. What theme should the tester frame?
- A transit password-reset endpoint accepts unlimited attempts and returns distinct messages for valid versus invalid accounts. What abuse class should the tester highlight?
- A city GraphQL API leaves introspection enabled in production, revealing the full schema to unauthenticated clients. What is the tester's best framing?
- A county API verifies JWTs poorly, including accepting tokens that declare insecure algorithm handling. What vulnerability class theme applies?
- A municipal API reflects arbitrary Origin values in Access-Control-Allow-Origin while also allowing credentials. Why is this dangerous?
- A library feature fetches a user-supplied URL from the application server to generate link previews. What vulnerability class should the tester investigate first?
- A transit download response places an unsanitized user-controlled filename into Content-Disposition and related headers. What issue class should the tester emphasize?
- A city portal caches authenticated resident pages on a shared CDN edge. During a web assessment, what risk should the tester prioritize documenting?
- A county RoE excludes the HR admin panel, but an abandoned CNAME for a decommissioned ticket portal remains in scope. What should the tester do?
- A municipal chat feature uses WebSockets for permit-status actions. What authorization concern should the tester apply?
- A library voucher system is meant to redeem each code once, but simultaneous requests appear to redeem the same voucher twice. What finding class does this illustrate?
- A transit multi-step checkout accepts the price totals submitted from the browser on step 3. What should the tester emphasize?
- A city WAF blocks several obvious SQLi probe strings during testing. What is the most appropriate next methodology choice?
- A county security lead wants only automated DAST and no manual web testing for a civic portal. What should the tester explain?
- A municipal API returns stack traces that include resident email addresses in error bodies. How should the tester classify this?
- A library application behaves differently when the same parameter name appears twice in a request and authorization checks flip unexpectedly. What technique class is the tester observing?
- A transit portal redirects users to any URL supplied in a next= parameter without allowlisting. Why is this still a meaningful finding for civic staff phishing risk?
- A city payroll approval page can be framed by a third-party origin and overlays the Approve button. What defensive gap does this primarily indicate?
- A county GraphQL endpoint applies a per-HTTP-request rate limit, yet a single request can batch many aliased operations. What control gap should the tester highlight?
- A municipal upload feature re-encodes images but still stores files under a web-accessible path with predictable names. What defense-in-depth guidance fits best?
- A library XSS finding only triggers in an obsolete browser feature few patrons still use. How should the tester frame impact?
- A transit application accepts serialized objects from untrusted clients and reconstructs them server-side. What class of risk should the tester emphasize without providing exploit recipes?
- A city admin portal keeps the same session identifier after a user elevates from read-only staff to full administrator. What session hygiene issue should the tester flag?
- A county account settings page lets an already authenticated user change the password without re-entering the current password or completing step-up MFA. Why is this a problem if a session was stolen?
- A municipal web app has no Content-Security-Policy, or leaves CSP in report-only mode indefinitely. How should the tester describe CSP's role?
- A library admin UI ships a years-outdated JavaScript library known for client-side vulnerability classes. What should the tester emphasize?
- A transit engagement identifies server-side request forgery that can reach cloud instance metadata endpoints. How should impact be framed without exploit steps?
Privilege Escalation · 40 questions
- A city engagement yields a low-privilege Linux shell on an internal host. What should the tester do first for privilege-escalation situational awareness?
- A county Linux sudoers entry lets a standard user run a text editor as root. How should the tester interpret this class of finding?
- A municipal host has a custom script wrapper marked SUID root that is not a standard system binary. What should the tester conclude?
- A library server runs a root cron job that executes a script writable by unprivileged users. What misconfiguration class is this?
- A transit Linux host has a root-run maintenance job that invokes a command by relative name while PATH can be influenced insecurely. What risk class should the tester document?
- A water utility Linux host mounts an NFS share exported with norootsquash. During privilege-escalation enumeration, how should the tester interpret that export option?
- A city internet-facing Linux box is still running a years-old kernel. How should the tester treat that kernel age during privilege-escalation planning?
- A county Linux host shows file capability bits granting a binary powerful privileges without a traditional SUID bit. What should the tester include in enumeration thinking?
- A municipal low-privilege account is a member of the Docker group on a Linux host. Conceptually, how should the tester frame that membership?
- A library Linux system shows world-writable permissions on /etc/passwd or /etc/shadow-class files. What is the correct severity framing for that finding?
- A transit agency service runs as root and loads its configuration from a directory writable by a low-privilege user. What privilege-escalation theme does that represent?
- A city Linux foothold reveals a cleartext password in a world-readable shell history file. How should the tester treat that discovery during privilege escalation?
- A county Windows foothold is new. Before choosing a privilege-escalation path, what situational awareness should come first?
- A municipal Windows image shows AlwaysInstallElevated-class policy themes enabled. How should the tester classify that finding?
- A library Windows service uses an unquoted binary path containing spaces, and an intermediate folder is writable by the foothold user. What misconfiguration class is this?
- A transit Windows service runs as SYSTEM and its service binary is writable by a standard user. Conceptually, what does that enable?
- A city scheduled task runs elevated and points at a script the low-privilege user can modify. What should the tester conclude?
- A county Windows token shows SeImpersonatePrivilege on an older patch level. How should the tester frame that privilege without diving into exploit steps?
- A municipal elevated application loads DLLs from a path writable by a standard user. What privilege-escalation class should the tester investigate carefully?
- A library IT team uses one shared local administrator password across the entire workstation fleet. After compromising that password on one host, what privilege impact should the tester highlight?
- A water utility Windows host stores autologon credentials in the registry. Why does privilege-escalation enumeration care about that?
- A city workstation fleet has extremely permissive UAC settings. How should the tester include that posture in Windows risk framing?
- A county domain still shows leftover Group Policy Preferences cpassword-class artifacts. What should the Windows privilege-escalation mindset treat them as?
- A municipal high-value server has antivirus disabled and no EDR present. How should the tester report that condition in a privilege-escalation / post-exploitation context?
- A library workstation exposes an unnecessary elevated local service related to printer spooler-class functionality. Without providing exploit steps, what is the sound assessment takeaway?
- A transit engagement includes Linux container breakout in scope. Conceptually, which container traits should the tester enumerate first?
- A city sudo package is old with known public issues, but the rules of engagement ban using public exploits without approval. What is the correct next judgment?
- A county tester has proven a reliable path to local SYSTEM on one Windows host and the next objective involves Active Directory. What distinction must remain clear?
- A municipal low-privilege Linux user can read another user's private SSH keys due to weak home-directory permissions. What is the primary risk?
- A library Windows host runs an outdated third-party kernel driver. Why should privilege-escalation enumeration include that class of software?
- A transit agency has a Samba share that allows guest write next to a Linux cron job that ingests that share as a privileged user. Which class of privilege-escalation risk does this multi-service layout best illustrate?
- A city asks the tester to spend remaining time only on a CTF-style kernel exploit that depends on rare race conditions, while common local misconfigs remain unreviewed. What should the tester prefer for CPTS-style value?
- A county Windows host shows PowerShell history and transcription logs that appear to capture prior admin commands. What is the best privilege-escalation enumeration takeaway?
- A municipal Linux backup script runs as root and embeds database credentials in clear text. How should the tester frame this during privilege-escalation review?
- A library Windows service account can RDP interactively and is also a local administrator on additional hosts. Which risk class should the finding emphasize?
- A water utility marks a SCADA Windows host as forbidden for any privilege-escalation testing. What is the correct professional response?
- A city Linux host grants broad capabilities to a Python interpreter used by operators. How should the tester treat this finding class?
- A county engagement confirms local privilege escalation. Which evidence approach best matches least-impact professional proof?
- A municipal Windows estate shows long WSUS or update offline periods leaving hosts unpatched. How does that relate to privilege-escalation likelihood?
- A transit engagement finds both Linux and Windows local privilege escalations. How should reporting best help different system owners?
Documentation, Reporting & Engagement Delivery · 15 questions
- A city engagement is halfway complete and the tester has only sparse notes. What documentation practice should they adopt immediately?
- A county executive summary is being drafted. What content approach best fits a leadership audience?
- A municipal client asks for remediation guidance beyond a single urgent patch list. What framing should the report include?
- A library assessment finds the same vulnerability class on a jury PII system and on a public brochure site. How should severity be handled?
- A transit internal compromise needs to be explained in the report. What should the attack-path section emphasize?
- A city requests appendices covering what changed during testing. What operational content belongs there?
- A county stakeholder wants CVSS numbers only and no written impact narrative. What should the tester advocate?
- A municipal critical finding is fixed mid-engagement and the tester is asked to verify. How should the report treat that work?
- A library stakeholder meeting requires communicating serious findings. What tone is most appropriate?
- A water utility engagement is ending and tester-introduced shells or forwards may still exist. What closeout obligation applies?
- A city agreed at kickoff on a report template with executive summary, findings, remediations, and appendices. What should the tester do at delivery time?
- A county contact asks the tester to omit a material finding that would embarrass a vendor. What is the ethical response?
- A municipal enterprise-style assessment produced a lucky path to Domain Admin early. What else should the engagement still demonstrate?
- A transit client requests raw password lists be sent over ordinary email. How should the tester handle sensitive evidence delivery?
- A city proposes measuring engagement success solely by how many critical findings were produced. How should the tester reframe success?
These questions are original practice material and are NOT actual exam questions or brain-dump content. All vendor marks are trademarks of their respective owners. This site is not affiliated with, endorsed by, or sponsored by Hack The Box.