CPENT Practice Questions
Prepare for CPENT with more than an answer.
- Exam fee
- $1000 USD
- Level
- Advanced Professional
- Valid for
- 3 years
Domains covered on the exam 14
- Introduction to Penetration Testing and Methodologies7%
- Penetration Testing Scoping and Engagement7%
- Open-Source Intelligence (OSINT)7%
- Social Engineering Penetration Testing7%
- Network Penetration Testing - External7%
- Network Penetration Testing - Internal7%
- Network Penetration Testing - Perimeter Devices7%
- Web Application Penetration Testing14%
- Wireless Penetration Testing7%
- IoT Penetration Testing7%
- OT/SCADA Penetration Testing7%
- Cloud Penetration Testing7%
- Binary Analysis and Exploitation7%
- Report Writing and Post Testing Actions7%
- 1
A penetration tester is analyzing a Kerberos environment and wants to perform a Kerberoasting attack. They need to identify service accounts that have a Service Principal Name (SPN) set. Which PowerShell command (using PowerView or native AD module) achieves this?
Show answer details
Correct answer: B
Using PowerView,
Get-NetUser -SPNreturns all user accounts that have a Service Principal Name set. These accounts are targets for Kerberoasting because their TGS tickets can be requested and then cracked offline. - 2
You are assessing a firewall configuration and suspect it is filtering traffic based on the source port. You want to force your Nmap scan to send packets with a source port of 53 (DNS) to attempt to bypass the firewall rules. Which Nmap flag should you use?
Show answer details
Correct answer: D
The
-gor--source-portoption in Nmap allows the user to specify the source port for the scan packets. Firewalls often allow traffic from port 53 (DNS) or 88 (Kerberos) to accommodate responses, making this a common evasion technique. - 3
A penetration tester is facing a Web Application Firewall (WAF) that is blocking SQL injection attempts containing spaces. Which of the following is a common technique to bypass this filter in a MySQL environment?
Show answer details
Correct answer: A
In MySQL, inline comments
/**/can be used to replace spaces. For example,SELECT/**/username/**/FROM/**/usersis treated as valid SQL but may bypass WAF regex rules that look for spaces. - 4
You have identified a potential UNION-based SQL injection vulnerability in a web application. You are trying to determine the number of columns in the current query. Which of the following payloads is the correct way to test this?
Show answer details
Correct answer: B
The
ORDER BYclause is used to determine the number of columns. You increment the number (ORDER BY 1,ORDER BY 2, etc.) until the application throws an error, indicating you have exceeded the number of columns in the SELECT statement. - 5
A penetration tester is testing a web application and notices that user input is reflected in the web page without proper sanitization. The tester inputs
alert(document.cookie)and a popup box appears with the session ID. What type of vulnerability has been discovered?Show answer details
Correct answer: D
Reflected XSS occurs when an application receives data in an HTTP request (like a search query) and includes that data within the immediate response in an unsafe way. The script executes immediately in the browser.
- 6
A penetration tester is engaged to perform a black-box assessment of a corporate network. The tester decides to follow the Penetration Testing Execution Standard (PTES) to ensure a structured approach. During the Intelligence Gathering phase, the tester is attempting to map the organization's business relationships and employee hierarchy without touching the target's infrastructure. Which phase of the PTES does this activity strictly fall under, and which tool is MOST appropriate for visualizing these relationships?
Show answer details
Correct answer: A
The Intelligence Gathering phase in PTES involves collecting as much information as possible about the target. Maltego is a premier tool for open-source intelligence (OSINT) and forensics that excels at visualizing relationships (links) between people, companies, domains, and internet infrastructure. BloodHound is for Active Directory trust mapping (internal), and Threat Modeling comes after intelligence gathering.
- 7
During a strategic planning meeting for a new penetration test, the client requests that the assessment team specifically focus on simulating the tactics, techniques, and procedures (TTPs) of a specific Advanced Persistent Threat (APT) group known to target their industry. Which framework should the lead penetration tester reference to accurately design this emulation plan?
Show answer details
Correct answer: A
The MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework is the industry standard for describing the actions an adversary might take during an intrusion. It provides detailed information on APT groups and their specific TTPs, making it the correct choice for adversary emulation.
- 8
A penetration tester has discovered a critical vulnerability in a production database server that allows for remote code execution. The Rules of Engagement (RoE) explicitly state that no exploitation causing potential denial of service or data corruption is permitted on production systems. The tester believes they can exploit this to gain domain admin access. What is the correct course of action?
Show answer details
Correct answer: C
The Rules of Engagement are a binding agreement. If the RoE prohibits risky exploitation on production systems, the tester must adhere to it strictly. The correct action is to document the finding (proof of vulnerability) without executing the dangerous payload, and report it.
- 9
You are preparing the scoping document for a penetration test of a financial institution. The client requires that the test be conducted from the perspective of a malicious insider with standard user access. This type of test is BEST described as:
Show answer details
Correct answer: C
Grey Box testing simulates an attacker with some knowledge or access to the system, such as a compromised employee account or an insider. This aligns with the client's request for a 'malicious insider with standard user access'. Black box implies no prior knowledge; White box implies full knowledge/admin access.
- 10
While conducting OSINT on a target organization, you wish to identify all subdomains associated with 'example.com' that might be hosting development or staging environments. You decide to use a tool that queries multiple search engines (Google, Bing, etc.) and Shodan without actively scanning the target's network. Which tool is MOST suitable for this passive reconnaissance task?
Show answer details
Correct answer: B
TheHarvester is a tool specifically designed for gathering emails, subdomains, hosts, employee names, open ports, and banners from different public sources like search engines, PGP key servers, and SHODAN. It is a passive reconnaissance tool (unless active options are enabled), fitting the requirement perfectly.
