LPT (Master) EC-Council Licensed Penetration Tester (Master) Practice Questions
Prepare for LPT (Master) with more than an answer.
- Exam fee
- $999 USD
- Level
- Master / Expert
- Valid for
- CPENT: 3 years (with 120 ECE credits within 3-year period). LPT (Master): 1 year (renewable annually).
Domains covered on the exam 8
- Penetration Testing Methodologies, Scoping, and Engagement13%
- Information Gathering and Attack Surface Mapping13%
- Web Application and API Penetration Testing14%
- Perimeter Defense Evasion Techniques12%
- Endpoint Exploitation, Privilege Escalation, and Lateral Movement13%
- Reverse Engineering and Binary Exploitation11%
- IoT Penetration Testing11%
- Reporting and Post-Testing Actions13%
- 1
Select TWO methods that are effective for identifying a SQL Injection vulnerability when the application suppresses all error messages and does not return data in the response (Blind SQLi).
Show answer details
Correct answer: A, C
Time-based injection relies on pausing the database execution. If the application takes 10 seconds to respond, the injection is successful.
Boolean-based blind SQLi involves sending true/false conditions. Even without data output, the application might respond differently (e.g., different HTTP content length, missing image, or 'Welcome' message) for a True condition versus a False one.
- 2
You have gained access to a compromised Linux server in a DMZ and want to pivot to an internal network (10.10.10.x). The server has no netcat or SSH server running, but it has Python installed. You want to set up a dynamic SOCKS proxy to tunnel your attack traffic (e.g., Burp Suite, Nmap) through this server. Which tool combination and configuration would BEST achieve this?
Show answer details
Correct answer: C
Chisel is a fast TCP/UDP tunnel over HTTP. Since the target is in a DMZ (likely behind a firewall blocking inbound), a reverse connection is preferred. Running the server on the attacker machine and the client on the compromised host to initiate a reverse SOCKS proxy is the most robust method. It encapsulates traffic over HTTP/WebSockets, often bypassing firewall rules.
- 3
You are assessing a network where a strict firewall drops all TCP packets with the SYN flag set coming from the external network, except for established connections. You suspect a host is alive behind the firewall. Which Nmap scan type is most likely to elicit a response (RST packet) from a live host in this scenario?
Show answer details
Correct answer: C
A TCP ACK scan sends a packet with only the ACK flag set. Stateless firewalls or simple packet filters that block SYN packets (to prevent connection initiation) might allow ACK packets through if they assume they belong to an established connection. If the packet reaches the target host, the host will respond with an RST packet because there is no actual connection context, thus revealing the host is alive.
- 4
You are the lead penetration tester for a multinational financial institution. During the scoping phase, the client requests a 'Black Box' assessment of their European subsidiary's payment gateway. However, the Rules of Engagement (ROE) explicitly state that no testing should be performed against systems hosting GDPR-protected data without specific written consent from the Data Protection Officer (DPO). While mapping the attack surface, you identify a load balancer (192.0.2.15) that routes traffic to both the payment gateway and a legacy HR portal hosting sensitive PII. The load balancer itself is within scope.
Based on the flowchart below and the scenario, what is the legally and ethically correct course of action?
Show answer details
Correct answer: C
The correct action is to pause and seek authorization. Even if the load balancer is in scope, the risk of inadvertently affecting the GDPR-protected HR portal (shared infrastructure) violates the specific constraint regarding the DPO's consent. Proceeding without this clarification risks severe legal penalties under GDPR and breach of contract.
- 5
A penetration tester is drafting a Statement of Work (SOW) for a client requiring PCI-DSS compliance testing. The client uses a cloud-native architecture with microservices. Which specific scoping requirement must be included to ensure the test satisfies PCI-DSS Requirement 11.3?
Show answer details
Correct answer: C
PCI-DSS Requirement 11.3 specifically mandates that penetration testing must include validation of any segmentation controls used to isolate the CDE from other networks. Testing only the CDE is insufficient if the segmentation is relied upon for scope reduction.
- 6
While utilizing AI-driven penetration testing tools during an engagement, you notice the tool is generating traffic that mimics a known ransomware propagation pattern (SMB scanning followed by encryption attempts on dummy files). The ROE strictly prohibits 'destructive testing' or 'simulation of malware that alters file integrity.' What is the immediate best practice response?
Show answer details
Correct answer: B
Even if the files are 'dummy' files, the behavior alters file integrity and mimics malware, which violates the strict ROE prohibition against destructive testing/malware simulation. The tool must be stopped, and the incident analyzed to ensure no actual damage occurred before proceeding.
