Exploitation Fundamentals
CPTS · 35 questions
- On a county foothold host, common third-party file-copy utilities are blocked by policy, but built-in OS features remain available within scope. Which transfer approach is most appropriate at a concept level?
- A city Linux target allows outbound HTTP only; other egress is blocked. How should the tester choose a file-transfer approach?
- A municipal Windows host grants the tester only a standard user session; software installs that need admin rights are blocked. What staging concept fits?
- A transit engagement requires that any files transferred onto targets be removable after testing. What practice supports that requirement?
- A library server permits SMB from the tester's jump host, and HTTP and FTP are also reachable in scope. How should transfer protocol choice be framed?
- A water-utility jump box is Linux while many targets are Windows. What cross-platform transfer concern should the tester plan for conceptually?
- A city firewall allows outbound connections from a compromised host but blocks unsolicited inbound connections to that host. Which shell-direction concept fits that posture?
- A county RoE forbids leaving persistent listeners or implants after the test day. Which approach aligns with that constraint?
- A municipal tester mixes up staged and stageless payload delivery concepts during planning. Which statement captures the tradeoff at a high level—without providing a payload?
- A civic Windows host terminates unfamiliar binaries quickly under endpoint controls. At a concept level, what should guide the next remote-access choice within RoE?
- A city IT lead wants Metasploit used for every exploitation task on the engagement. What is the soundest way to position the framework?
- A county asks what Metasploit auxiliary, exploit, and post modules are each for. Which mapping is correct?
- A library engagement opens multiple Metasploit sessions across hosts. What session-management practice best protects scope?
- A transit tester treats a successful Metasploit check as enough proof of business impact. What should they do instead?
- Municipal policy bans certain automated exploitation frameworks on OT segments listed in the Rules of Engagement. What should the tester do?
- A city login portal has no lockout. The tester must choose a password-attack approach that still respects careful RoE. Which judgment is soundest?
- A county engagement obtains an NTLM-class hash within scope. Conceptually, which distinction should guide next steps?
- A library still uses vendor default credentials on a printer admin page. How should that be treated?
- A transit Wi-Fi captive portal uses one seasonal staff password shared across the team. What risk framing is most accurate?
- A city Active Directory policy allows short passwords. What impact should the assessment highlight?
- A municipal app stores unsalted legacy password hashes. Why does that matter for offline attacks?
- A county sponsor wants every password in a huge list tried against production OWA tonight. What is the correct response?
- A civic helpdesk resets passwords using predictable temporary patterns. What finding class does this represent?
- A city tester finds cleartext credentials inside scripts on an accessible file share. What technique class does this illustrate?
- A water plant asks whether cracked passwords should appear in cleartext in the main report. What handling is appropriate?
- A county exposes internet-facing SSH with password authentication and no MFA. How should this be framed?
- A city still transfers sensitive files with FTP that moves credentials in cleartext. What is the core risk?
- A library database listens on a wide network with weak privileged authentication. What finding class fits best?
- A municipal NFS export is world-readable and contains SSH private keys. What connection should the report emphasize?
- From the approved test segment, a transit mail server behaves as an open relay. How should this be classified?
- County printers expose management protocols on the same VLAN as user workstations. What should the assessment highlight?
- A city CI server's service account allows interactive logon and uses a weak password. Why is that risky?
- A civic cache or queue service binds on an internal host with no authentication. What does that represent?
- A municipal Windows host still runs a legacy file-sharing protocol required by one application. How should risk be framed?
- A county asks the tester to exploit Domain Admin as the first step without service enumeration. What should the tester do?