Exam Questions and CORRECT Answers
A penetration tester configured a Metasploit module with the settings shown below.
What type of attack is this?
Name
Required
RHOST
RPORT
SHARE
Current Setting
192.168.4.24
445
ADMIN$
yes
yes
no
SMBDomain WORKGROUP
SMBPass
CBC67974B2A219DIAAD3B414B51404EE:363DD639AD34B6C5153COF5T165AB74E
no
SMBUser
Administrator
no - CORRECT ANSWER - pass the hash
A penetration tester is performing a vulnerability scan on a Linux host and sees that
the scanner reports an application as a vulnerable version. What is the next step the
, tester should take to verify the vulnerability is a true positive? - CORRECT ANSWER -
Review the application's patch list to see if the vulnerability is addressed
What is required to create a Kerberos Golden Ticket using Mimikatz? - CORRECT
ANSWER - NT hash of the krbtgt account
A penetration tester has a list of URLs that they would like to evaluate for the use of
default credentials. What tool can use the list of URLs and provide the tester with
information on where default credentials are in use? - CORRECT ANSWER - EyeWitness
What defense against Kerberos attacks can only be enabled in versions of Windows
Enterprise since Windows 10? - CORRECT ANSWER - Deploy CredentialGuard throughout
the environment
Based on the image below, what is the pen tester configuring as part of an MSF
pivot? - CORRECT ANSWER - SSH local port forward
You've been contracted by the owner of a secure facility to try and break into their
office in the middle Of the night. Your client requested photographs Of any sensitive
information found as proof of your accomplishments. The job you've been hired to
perform is an example Of What practice? - CORRECT ANSWER - Penetration Testing
When account lockout functionality is in use, which of the following can result in a
denial-of-service attack? - CORRECT ANSWER - Password guessing
What is an advantage of a pass-the-hash attack over other types of password
attacks? - CORRECT ANSWER - Pass-the-hash takes
less time after hashes are obtained