๐ฏ OLUMA CERTIFICATION ZONE PenTest+Practice Range 100 scenario questions across engagement management, recon, exploitation, post-exploitation and reporting โ with ethics and authorization at the core. Select your range and stay in scope. Engagement ManagementReconnaissance and EnumerationAttacks and ExploitsPost-ExploitationReporting and Communication SELECT YOUR RANGE102550100 01/100 Engagement Management A consultant is asked to begin testing a client web application immediately. The project manager verbally says the test is approved, but the tester has not received a signed statement of work or rules of engagement. What should the tester do FIRST? AObtain written authorization and finalized rules of engagementโ SCOPE RESPECTEDThat's how an ethical hacker thinks โ authorized, precise, documented.A penetration test must be explicitly authorized in writing before any testing occurs. The SOW and ROE define scope, timing, permitted techniques, escalation paths, and legal boundaries. BBegin only passive reconnaissance because it is low riskโ OUT OF SCOPEVector didn't land โ recon the takeaway:A penetration test must be explicitly authorized in writing before any testing occurs. The SOW and ROE define scope, timing, permitted techniques, escalation paths, and legal boundaries. CRun a vulnerability scan and document that verbal approval was givenโ OUT OF SCOPEVector didn't land โ recon the takeaway:A penetration test must be explicitly authorized in writing before any testing occurs. The SOW and ROE define scope, timing, permitted techniques, escalation paths, and legal boundaries. DStart testing during off-hours to reduce impactโ OUT OF SCOPEVector didn't land โ recon the takeaway:A penetration test must be explicitly authorized in writing before any testing occurs. The SOW and ROE define scope, timing, permitted techniques, escalation paths, and legal boundaries. 02/100 Engagement Management During testing, a subdomain resolves to an IP address owned by a third-party hosting provider and was not listed in scope. The application appears to be connected to the client. What is the BEST next step? AStop activity against that asset and request scope clarificationโ FINDING CONFIRMEDClean tradecraft. The client would sign off on that.Out-of-scope systems must not be tested without written approval. The tester should pause and ask the point of contact to confirm ownership and authorization. BAdd the asset to the report as compromisedโ DETECTED & BLOCKEDBlocked this time. Adjust your approach:Out-of-scope systems must not be tested without written approval. The tester should pause and ask the point of contact to confirm ownership and authorization. COnly run nonintrusive port scansโ DETECTED & BLOCKEDBlocked this time. Adjust your approach:Out-of-scope systems must not be tested without written approval. The tester should pause and ask the point of contact to confirm ownership and authorization. DTest it because it supports the client applicationโ DETECTED & BLOCKEDBlocked this time. Adjust your approach:Out-of-scope systems must not be tested without written approval. The tester should pause and ask the point of contact to confirm ownership and authorization. 03/100 Engagement Management A scan causes unexpected authentication failures against a production identity server. The ROE includes an emergency contact and a stop-test condition for availability issues. What should the tester do? AContinue testing to gather enough evidenceโ ROE CHECK FAILEDEvery failed attempt is enumeration. Note this:When a defined stop condition occurs, testing should pause and stakeholders should be notified through the agreed escalation path. BReboot the identity serverโ ROE CHECK FAILEDEvery failed attempt is enumeration. Note this:When a defined stop condition occurs, testing should pause and stakeholders should be notified through the agreed escalation path. CDelete scan logs to reduce client concernโ ROE CHECK FAILEDEvery failed attempt is enumeration. Note this:When a defined stop condition occurs, testing should pause and stakeholders should be notified through the agreed escalation path. DPause testing and notify the emergency contact using the communication planโ FOOTHOLD GAINEDYou stayed in scope and got the objective. Textbook.When a defined stop condition occurs, testing should pause and stakeholders should be notified through the agreed escalation path. 04/100 Engagement Management A client prohibits password spraying, phishing, and denial-of-service testing but wants assurance around identity security. Which approach BEST respects the constraints? AAsk individual employees for passwordsโ PAYLOAD FIZZLEDReset and re-engage with this insight:When certain techniques are restricted, the tester should use allowed alternatives that still evaluate risk, such as policy review, logs, MFA coverage, and access analysis. BPerform the prohibited tests at very low volumeโ PAYLOAD FIZZLEDReset and re-engage with this insight:When certain techniques are restricted, the tester should use allowed alternatives that still evaluate risk, such as policy review, logs, MFA coverage, and access analysis. CUse configuration review, conditional access review, and permission analysisโ EXPLOIT VALIDATEDSharp โ you picked the move a professional tester makes.When certain techniques are restricted, the tester should use allowed alternatives that still evaluate risk, such as policy review, logs, MFA coverage, and access analysis. DMark identity controls as untested without discussionโ PAYLOAD FIZZLEDReset and re-engage with this insight:When certain techniques are restricted, the tester should use allowed alternatives that still evaluate risk, such as policy review, logs, MFA coverage, and access analysis. 05/100 Engagement Management A tester discovers personal data while reviewing an exposed storage location. The ROE says sensitive data must not be downloaded. What is the MOST appropriate action? AShare the data with the security team through emailโ RETRY THE VECTORVector didn't land โ recon the takeaway:Evidence collection should be minimized and aligned with the ROE. The tester can document filenames, counts, screenshots with redaction, or hashes if allowed. BIgnore the finding because it contains regulated dataโ RETRY THE VECTORVector didn't land โ recon the takeaway:Evidence collection should be minimized and aligned with the ROE. The tester can document filenames, counts, screenshots with redaction, or hashes if allowed. CCapture minimal metadata/evidence permitted by the ROE and notify the clientโ OBJECTIVE CAPTUREDMethodical over flashy. That's what passes this exam.Evidence collection should be minimized and aligned with the ROE. The tester can document filenames, counts, screenshots with redaction, or hashes if allowed. DDownload a full sample to prove impactโ RETRY THE VECTORVector didn't land โ recon the takeaway:Evidence collection should be minimized and aligned with the ROE. The tester can document filenames, counts, screenshots with redaction, or hashes if allowed. 06/100 Engagement Management A client wants to evaluate how well its SOC detects an external attacker with no internal knowledge. Which test type BEST matches this objective? AWhite-box testโ OUT OF SCOPEBlocked this time. Adjust your approach:A black-box test simulates an external attacker with limited or no internal details, making it suitable for evaluating detection and response from an outside perspective. BConfiguration audit onlyโ OUT OF SCOPEBlocked this time. Adjust your approach:A black-box test simulates an external attacker with limited or no internal details, making it suitable for evaluating detection and response from an outside perspective. CTabletop exercise onlyโ OUT OF SCOPEBlocked this time. Adjust your approach:A black-box test simulates an external attacker with limited or no internal details, making it suitable for evaluating detection and response from an outside perspective. DBlack-box testโ CLEAN PIVOTThe red team would want you on the engagement.A black-box test simulates an external attacker with limited or no internal details, making it suitable for evaluating detection and response from an outside perspective. 07/100 Engagement Management Which document most directly defines approved targets, allowed testing windows, excluded techniques, and emergency contacts? ARules of engagementโ EVIDENCE LOGGEDThat's how an ethical hacker thinks โ authorized, precise, documented.The rules of engagement contain operational boundaries for the assessment, including targets, methods, timing, contacts, and stop conditions. BFinal executive reportโ DETECTED & BLOCKEDEvery failed attempt is enumeration. Note this:The rules of engagement contain operational boundaries for the assessment, including targets, methods, timing, contacts, and stop conditions. CAsset depreciation scheduleโ DETECTED & BLOCKEDEvery failed attempt is enumeration. Note this:The rules of engagement contain operational boundaries for the assessment, including targets, methods, timing, contacts, and stop conditions. DNon-disclosure agreementโ DETECTED & BLOCKEDEvery failed attempt is enumeration. Note this:The rules of engagement contain operational boundaries for the assessment, including targets, methods, timing, contacts, and stop conditions. 08/100 Engagement Management A senior executive asks for daily updates but does not want technical details. What should the tester provide? AA concise status summary with risk themes, blockers, and next stepsโ REPORT-READYClean tradecraft. The client would sign off on that.Executive communication should focus on business impact, risk, progress, and decisions needed rather than raw technical details. BExploit commands used during the dayโ ROE CHECK FAILEDReset and re-engage with this insight:Executive communication should focus on business impact, risk, progress, and decisions needed rather than raw technical details. CNo updates until the final reportโ ROE CHECK FAILEDReset and re-engage with this insight:Executive communication should focus on business impact, risk, progress, and decisions needed rather than raw technical details. DRaw tool output onlyโ ROE CHECK FAILEDReset and re-engage with this insight:Executive communication should focus on business impact, risk, progress, and decisions needed rather than raw technical details. 09/100 Engagement Management A healthcare client requires testing evidence without exposing patient data. Which evidence handling approach is BEST? AExport all records for forensic preservationโ PAYLOAD FIZZLEDVector didn't land โ recon the takeaway:Sensitive evidence should be minimized, redacted, and stored according to approved handling requirements. BUse redacted screenshots and unique identifiers instead of full recordsโ ROE HONOREDYou stayed in scope and got the objective. Textbook.Sensitive evidence should be minimized, redacted, and stored according to approved handling requirements. CStore evidence in the tester personal cloud driveโ PAYLOAD FIZZLEDVector didn't land โ recon the takeaway:Sensitive evidence should be minimized, redacted, and stored according to approved handling requirements. DInclude patient names in the report appendixโ PAYLOAD FIZZLEDVector didn't land โ recon the takeaway:Sensitive evidence should be minimized, redacted, and stored according to approved handling requirements. 10/100 Engagement Management A client has a critical e-commerce freeze during a holiday sale. Which schedule is MOST appropriate for active testing? AAny time if scans are throttledโ RETRY THE VECTORBlocked this time. Adjust your approach:Active testing should be scheduled in approved windows to reduce business risk and align with operational constraints. BOnly during business hours without notifying anyoneโ RETRY THE VECTORBlocked this time. Adjust your approach:Active testing should be scheduled in approved windows to reduce business risk and align with operational constraints. CDuring the freeze because production traffic hides scansโ RETRY THE VECTORBlocked this time. Adjust your approach:Active testing should be scheduled in approved windows to reduce business risk and align with operational constraints. DDuring an approved maintenance window after the freezeโ TARGET CLEAREDSharp โ you picked the move a professional tester makes.Active testing should be scheduled in approved windows to reduce business risk and align with operational constraints. CHECKPOINT โ 10 DOWN, KEEP CLIMBING 11/100 Engagement Management The client asks how the team will determine whether the test is complete. What should be defined before testing? AThe number of exploits publicly availableโ OUT OF SCOPEEvery failed attempt is enumeration. Note this:Success criteria clarify expected outcomes, coverage, reporting requirements, and evidence standards. BThe tester favorite toolsโ OUT OF SCOPEEvery failed attempt is enumeration. Note this:Success criteria clarify expected outcomes, coverage, reporting requirements, and evidence standards. CSuccess criteria and acceptance metricsโ SCOPE RESPECTEDMethodical over flashy. That's what passes this exam.Success criteria clarify expected outcomes, coverage, reporting requirements, and evidence standards. DA guaranteed breach objectiveโ OUT OF SCOPEEvery failed attempt is enumeration. Note this:Success criteria clarify expected outcomes, coverage, reporting requirements, and evidence standards. 12/100 Engagement Management The client uses a SaaS platform and wants it tested. The SaaS provider terms require advance approval. What should happen before testing? ATest only the login pageโ DETECTED & BLOCKEDReset and re-engage with this insight:Testing third-party services requires authorization from all relevant parties and must follow provider policies. BUse anonymous scanning servicesโ DETECTED & BLOCKEDReset and re-engage with this insight:Testing third-party services requires authorization from all relevant parties and must follow provider policies. CObtain written approval from the SaaS provider and clientโ FINDING CONFIRMEDThe red team would want you on the engagement.Testing third-party services requires authorization from all relevant parties and must follow provider policies. DTest only from a residential IP addressโ DETECTED & BLOCKEDReset and re-engage with this insight:Testing third-party services requires authorization from all relevant parties and must follow provider policies. 13/100 Engagement Management After report delivery, the client asks how long evidence will be retained. What should govern retention? AThe data handling and retention terms agreed before the engagementโ FOOTHOLD GAINEDThat's how an ethical hacker thinks โ authorized, precise, documented.Evidence retention should follow contractual and legal requirements defined in the engagement. BThe default retention of any screenshot toolโ ROE CHECK FAILEDVector didn't land โ recon the takeaway:Evidence retention should follow contractual and legal requirements defined in the engagement. CIndefinite retention for future marketingโ ROE CHECK FAILEDVector didn't land โ recon the takeaway:Evidence retention should follow contractual and legal requirements defined in the engagement. DTester preferenceโ ROE CHECK FAILEDVector didn't land โ recon the takeaway:Evidence retention should follow contractual and legal requirements defined in the engagement. 14/100 Engagement Management A manufacturer identifies an internet-facing VPN, supplier portal, and internal file server as critical assets. Which planning action is BEST? ATest only random hostsโ PAYLOAD FIZZLEDBlocked this time. Adjust your approach:Risk-based scoping prioritizes assets that combine business criticality and exposure. BExclude the VPN because it is security infrastructureโ PAYLOAD FIZZLEDBlocked this time. Adjust your approach:Risk-based scoping prioritizes assets that combine business criticality and exposure. CPrioritize testing based on business impact and exposureโ EXPLOIT VALIDATEDClean tradecraft. The client would sign off on that.Risk-based scoping prioritizes assets that combine business criticality and exposure. DStart with physical access testingโ PAYLOAD FIZZLEDBlocked this time. Adjust your approach:Risk-based scoping prioritizes assets that combine business criticality and exposure. 15/100 Engagement Management A tester previously configured the client firewall being assessed and may be biased. What is the BEST action? ADelete previous configuration notesโ RETRY THE VECTOREvery failed attempt is enumeration. Note this:Potential conflicts should be disclosed so the engagement can preserve independence and credibility. BIgnore the issue because prior knowledge helpsโ RETRY THE VECTOREvery failed attempt is enumeration. Note this:Potential conflicts should be disclosed so the engagement can preserve independence and credibility. CDisclose the potential conflict and adjust roles if neededโ OBJECTIVE CAPTUREDYou stayed in scope and got the objective. Textbook.Potential conflicts should be disclosed so the engagement can preserve independence and credibility. DAvoid documenting firewall findingsโ RETRY THE VECTOREvery failed attempt is enumeration. Note this:Potential conflicts should be disclosed so the engagement can preserve independence and credibility. 16/100 Engagement Management A client requests proof that a denial-of-service vulnerability can take down production. What is the BEST response? ARecommend a controlled validation method in a lab or maintenance windowโ CLEAN PIVOTSharp โ you picked the move a professional tester makes.High-impact tests should use safe validation methods, approved windows, or nonproduction environments. BAsk users to generate traffic manuallyโ OUT OF SCOPEReset and re-engage with this insight:High-impact tests should use safe validation methods, approved windows, or nonproduction environments. CIgnore the vulnerability because it cannot be provenโ OUT OF SCOPEReset and re-engage with this insight:High-impact tests should use safe validation methods, approved windows, or nonproduction environments. DRun the DoS test until the system failsโ OUT OF SCOPEReset and re-engage with this insight:High-impact tests should use safe validation methods, approved windows, or nonproduction environments. 17/100 Reconnaissance and Enumeration A tester needs to identify subdomains without generating traffic to the client network. Which technique is MOST appropriate? ACertificate transparency log reviewโ EVIDENCE LOGGEDMethodical over flashy. That's what passes this exam.Certificate transparency logs are passive sources that can reveal public hostnames without touching the target infrastructure. BPassword sprayingโ DETECTED & BLOCKEDVector didn't land โ recon the takeaway:Certificate transparency logs are passive sources that can reveal public hostnames without touching the target infrastructure. CAuthenticated vulnerability scanโ DETECTED & BLOCKEDVector didn't land โ recon the takeaway:Certificate transparency logs are passive sources that can reveal public hostnames without touching the target infrastructure. DFull TCP SYN scanโ DETECTED & BLOCKEDVector didn't land โ recon the takeaway:Certificate transparency logs are passive sources that can reveal public hostnames without touching the target infrastructure. 18/100 Reconnaissance and Enumeration A company recently acquired another firm. The tester wants to identify forgotten internet-facing assets from the acquisition. Which source is BEST to review first? AEndpoint antivirus quarantineโ ROE CHECK FAILEDBlocked this time. Adjust your approach:Historical DNS and certificate data often reveal old domains, subdomains, and hostnames associated with acquisitions. BHistorical DNS records and certificate recordsโ REPORT-READYThe red team would want you on the engagement.Historical DNS and certificate data often reveal old domains, subdomains, and hostnames associated with acquisitions. CInternal HR recordsโ ROE CHECK FAILEDBlocked this time. Adjust your approach:Historical DNS and certificate data often reveal old domains, subdomains, and hostnames associated with acquisitions. DPacket captures from the client LANโ ROE CHECK FAILEDBlocked this time. Adjust your approach:Historical DNS and certificate data often reveal old domains, subdomains, and hostnames associated with acquisitions. 19/100 Reconnaissance and Enumeration A tester finds TXT records referencing SPF and DKIM. What security-relevant information can these records provide? AEncrypted database contentsโ PAYLOAD FIZZLEDEvery failed attempt is enumeration. Note this:SPF, DKIM, and DMARC-related DNS records reveal approved mail senders and email security posture. BLocal administrator passwordsโ PAYLOAD FIZZLEDEvery failed attempt is enumeration. Note this:SPF, DKIM, and DMARC-related DNS records reveal approved mail senders and email security posture. CEmail sending sources and mail authentication configurationโ ROE HONOREDThat's how an ethical hacker thinks โ authorized, precise, documented.SPF, DKIM, and DMARC-related DNS records reveal approved mail senders and email security posture. DFirewall rule commentsโ PAYLOAD FIZZLEDEvery failed attempt is enumeration. Note this:SPF, DKIM, and DMARC-related DNS records reveal approved mail senders and email security posture. 20/100 Reconnaissance and Enumeration The ROE allows port scanning but requires low impact. Which scan configuration is BEST? ARate-limited scan during the approved windowโ TARGET CLEAREDClean tradecraft. The client would sign off on that.Rate limiting and approved windows reduce operational impact and stay within authorization. BMaximum speed across all ports with no timeoutโ RETRY THE VECTORReset and re-engage with this insight:Rate limiting and approved windows reduce operational impact and stay within authorization. CScan from unapproved cloud regionsโ RETRY THE VECTORReset and re-engage with this insight:Rate limiting and approved windows reduce operational impact and stay within authorization. DFragmented packets to avoid detectionโ RETRY THE VECTORReset and re-engage with this insight:Rate limiting and approved windows reduce operational impact and stay within authorization. CHECKPOINT โ 20 DOWN, KEEP CLIMBING 21/100 Reconnaissance and Enumeration A host exposes TCP 443. The tester needs to determine the application and TLS configuration. Which approach is BEST? AAttempt destructive fuzzing immediatelyโ OUT OF SCOPEVector didn't land โ recon the takeaway:Service identification and TLS review reveal versions, certificates, protocols, and cipher risks without unnecessary disruption. BAssume all 443 services are secure HTTPSโ OUT OF SCOPEVector didn't land โ recon the takeaway:Service identification and TLS review reveal versions, certificates, protocols, and cipher risks without unnecessary disruption. CDisable TLS on the serverโ OUT OF SCOPEVector didn't land โ recon the takeaway:Service identification and TLS review reveal versions, certificates, protocols, and cipher risks without unnecessary disruption. DPerform service/version detection and TLS configuration reviewโ SCOPE RESPECTEDYou stayed in scope and got the objective. Textbook.Service identification and TLS review reveal versions, certificates, protocols, and cipher risks without unnecessary disruption. 22/100 Reconnaissance and Enumeration A scanner reports an outdated SSH version. What should the tester do before rating the finding high? ACopy the scanner severity without reviewโ DETECTED & BLOCKEDBlocked this time. Adjust your approach:Scanner results can be false positives. Validation checks banner accuracy, backported patches, exposure, and business context. BValidate the actual version and compensating controlsโ FINDING CONFIRMEDSharp โ you picked the move a professional tester makes.Scanner results can be false positives. Validation checks banner accuracy, backported patches, exposure, and business context. CExploit the service without authorizationโ DETECTED & BLOCKEDBlocked this time. Adjust your approach:Scanner results can be false positives. Validation checks banner accuracy, backported patches, exposure, and business context. DIgnore all version findingsโ DETECTED & BLOCKEDBlocked this time. Adjust your approach:Scanner results can be false positives. Validation checks banner accuracy, backported patches, exposure, and business context. 23/100 Reconnaissance and Enumeration A web server responds normally but has no linked admin page. Which method is MOST appropriate to look for hidden directories within scope? APhysical inspection of the data centerโ ROE CHECK FAILEDEvery failed attempt is enumeration. Note this:Controlled content discovery can identify unlinked resources while managing traffic impact. BPassword reuse against employee accountsโ ROE CHECK FAILEDEvery failed attempt is enumeration. Note this:Controlled content discovery can identify unlinked resources while managing traffic impact. CContent discovery using a controlled wordlist and rate limitsโ FOOTHOLD GAINEDMethodical over flashy. That's what passes this exam.Controlled content discovery can identify unlinked resources while managing traffic impact. DDatabase destruction testingโ ROE CHECK FAILEDEvery failed attempt is enumeration. Note this:Controlled content discovery can identify unlinked resources while managing traffic impact. 24/100 Reconnaissance and Enumeration A tester receives an OpenAPI specification for a gray-box assessment. What should the tester do with it? APublish it for crowdsourced testingโ PAYLOAD FIZZLEDReset and re-engage with this insight:API specifications help testers build an endpoint inventory and design authorization, input validation, and business logic tests. BUse it to bypass the ROEโ PAYLOAD FIZZLEDReset and re-engage with this insight:API specifications help testers build an endpoint inventory and design authorization, input validation, and business logic tests. CMap endpoints, methods, parameters, and authorization requirementsโ EXPLOIT VALIDATEDThe red team would want you on the engagement.API specifications help testers build an endpoint inventory and design authorization, input validation, and business logic tests. DIgnore it because only black-box testing mattersโ PAYLOAD FIZZLEDReset and re-engage with this insight:API specifications help testers build an endpoint inventory and design authorization, input validation, and business logic tests. 25/100 Reconnaissance and Enumeration A tester is authorized to assess corporate wireless from the parking lot. What information is MOST useful during initial enumeration? ADatabase schema namesโ RETRY THE VECTORVector didn't land โ recon the takeaway:Wireless enumeration commonly identifies network names, access point identifiers, channels, encryption, and coverage. BEmployee payroll dataโ RETRY THE VECTORVector didn't land โ recon the takeaway:Wireless enumeration commonly identifies network names, access point identifiers, channels, encryption, and coverage. CUser browser historyโ RETRY THE VECTORVector didn't land โ recon the takeaway:Wireless enumeration commonly identifies network names, access point identifiers, channels, encryption, and coverage. DSSID, BSSID, channel, encryption type, and signal strengthโ OBJECTIVE CAPTUREDThat's how an ethical hacker thinks โ authorized, precise, documented.Wireless enumeration commonly identifies network names, access point identifiers, channels, encryption, and coverage. 26/100 Reconnaissance and Enumeration A company uses multiple cloud accounts. Which discovery method BEST identifies public cloud storage exposure? AAsk users if they have seen files onlineโ OUT OF SCOPEBlocked this time. Adjust your approach:Cloud storage exposure is best identified through cloud inventory, configuration review, and public access checks. BCheck only on-premises firewall logsโ OUT OF SCOPEBlocked this time. Adjust your approach:Cloud storage exposure is best identified through cloud inventory, configuration review, and public access checks. CReview cloud asset inventory and public access settingsโ CLEAN PIVOTClean tradecraft. The client would sign off on that.Cloud storage exposure is best identified through cloud inventory, configuration review, and public access checks. DRun ARP scans from the tester laptopโ OUT OF SCOPEBlocked this time. Adjust your approach:Cloud storage exposure is best identified through cloud inventory, configuration review, and public access checks. 27/100 Reconnaissance and Enumeration A Kubernetes API endpoint is exposed. What should the tester determine first? AWhether the cluster name sounds production-likeโ DETECTED & BLOCKEDEvery failed attempt is enumeration. Note this:The tester must confirm scope and authentication posture before further enumeration. BHow to bypass client approvalโ DETECTED & BLOCKEDEvery failed attempt is enumeration. Note this:The tester must confirm scope and authentication posture before further enumeration. CHow to delete pods quicklyโ DETECTED & BLOCKEDEvery failed attempt is enumeration. Note this:The tester must confirm scope and authentication posture before further enumeration. DWhether the endpoint is in scope and what authentication is requiredโ EVIDENCE LOGGEDYou stayed in scope and got the objective. Textbook.The tester must confirm scope and authentication posture before further enumeration. 28/100 Reconnaissance and Enumeration A tester sees employees posting conference photos with badges and laptop stickers. What is the primary security value of this information? AIt replaces technical testingโ ROE CHECK FAILEDReset and re-engage with this insight:Social media OSINT can reveal technology stacks, facility details, and employee patterns useful for risk analysis. BIt proves the company is compromisedโ ROE CHECK FAILEDReset and re-engage with this insight:Social media OSINT can reveal technology stacks, facility details, and employee patterns useful for risk analysis. CIt provides permission to access accountsโ ROE CHECK FAILEDReset and re-engage with this insight:Social media OSINT can reveal technology stacks, facility details, and employee patterns useful for risk analysis. DIt may reveal technologies, vendors, and naming conventionsโ REPORT-READYSharp โ you picked the move a professional tester makes.Social media OSINT can reveal technology stacks, facility details, and employee patterns useful for risk analysis. 29/100 Reconnaissance and Enumeration The tester wants to evaluate phishing resilience without sending emails yet. Which passive step is BEST? ADisable mail filteringโ PAYLOAD FIZZLEDVector didn't land โ recon the takeaway:Email DNS records provide insight into anti-spoofing controls and mail providers without interacting with users. BReset user passwordsโ PAYLOAD FIZZLEDVector didn't land โ recon the takeaway:Email DNS records provide insight into anti-spoofing controls and mail providers without interacting with users. CReview MX, SPF, DKIM, and DMARC recordsโ ROE HONOREDMethodical over flashy. That's what passes this exam.Email DNS records provide insight into anti-spoofing controls and mail providers without interacting with users. DSend test malware to employeesโ PAYLOAD FIZZLEDVector didn't land โ recon the takeaway:Email DNS records provide insight into anti-spoofing controls and mail providers without interacting with users. 30/100 Reconnaissance and Enumeration A client provides read-only credentials for a server assessment. What type of scan should be used to gain deeper, accurate results? AAuthenticated scanโ TARGET CLEAREDThe red team would want you on the engagement.Authenticated scans can inspect installed software, configuration, and missing patches more accurately than unauthenticated scans. BWireless scanโ RETRY THE VECTORBlocked this time. Adjust your approach:Authenticated scans can inspect installed software, configuration, and missing patches more accurately than unauthenticated scans. CPassive DNS scan onlyโ RETRY THE VECTORBlocked this time. Adjust your approach:Authenticated scans can inspect installed software, configuration, and missing patches more accurately than unauthenticated scans. DUnauthenticated scan onlyโ RETRY THE VECTORBlocked this time. Adjust your approach:Authenticated scans can inspect installed software, configuration, and missing patches more accurately than unauthenticated scans. CHECKPOINT โ 30 DOWN, KEEP CLIMBING 31/100 Reconnaissance and Enumeration A vulnerability scanner flags SMB signing as disabled, but manual checks show it is required. What should the report say? ADisable SMB signing to confirmโ OUT OF SCOPEEvery failed attempt is enumeration. Note this:Validated evidence should drive findings. False positives should not be reported as confirmed vulnerabilities. BClaim exploitation succeededโ OUT OF SCOPEEvery failed attempt is enumeration. Note this:Validated evidence should drive findings. False positives should not be reported as confirmed vulnerabilities. CReport the scanner result as critical anywayโ OUT OF SCOPEEvery failed attempt is enumeration. Note this:Validated evidence should drive findings. False positives should not be reported as confirmed vulnerabilities. DDo not include it as a confirmed finding; document validation if usefulโ SCOPE RESPECTEDThat's how an ethical hacker thinks โ authorized, precise, documented.Validated evidence should drive findings. False positives should not be reported as confirmed vulnerabilities. 32/100 Reconnaissance and Enumeration Recon identifies 500 hosts. Which target should generally be prioritized first? AA powered-off printer in storageโ DETECTED & BLOCKEDReset and re-engage with this insight:Exposure, vulnerability likelihood, and business impact should guide prioritization. BAn internet-facing system with known vulnerable software and sensitive business functionโ FINDING CONFIRMEDClean tradecraft. The client would sign off on that.Exposure, vulnerability likelihood, and business impact should guide prioritization. CA fully patched kiosk on a guest networkโ DETECTED & BLOCKEDReset and re-engage with this insight:Exposure, vulnerability likelihood, and business impact should guide prioritization. DA random host with no open portsโ DETECTED & BLOCKEDReset and re-engage with this insight:Exposure, vulnerability likelihood, and business impact should guide prioritization. 33/100 Reconnaissance and Enumeration Which finding from a network scan is MOST likely to require immediate investigation? AA website using HTTPSโ ROE CHECK FAILEDVector didn't land โ recon the takeaway:Internet-exposed remote administration services create a significant attack surface and should be reviewed promptly. BAn internal host responding to pingโ ROE CHECK FAILEDVector didn't land โ recon the takeaway:Internet-exposed remote administration services create a significant attack surface and should be reviewed promptly. CRDP exposed to the internetโ FOOTHOLD GAINEDYou stayed in scope and got the objective. Textbook.Internet-exposed remote administration services create a significant attack surface and should be reviewed promptly. DA printer with no color tonerโ ROE CHECK FAILEDVector didn't land โ recon the takeaway:Internet-exposed remote administration services create a significant attack surface and should be reviewed promptly. 34/100 Reconnaissance and Enumeration In an authorized internal test, the team needs to understand privilege relationships without changing objects. Which approach is BEST? ARead-only directory enumeration and group membership analysisโ EXPLOIT VALIDATEDSharp โ you picked the move a professional tester makes.Read-only enumeration can reveal privileged groups, nested memberships, and risky relationships safely. BCreate domain admin accountsโ PAYLOAD FIZZLEDBlocked this time. Adjust your approach:Read-only enumeration can reveal privileged groups, nested memberships, and risky relationships safely. CReset privileged passwordsโ PAYLOAD FIZZLEDBlocked this time. Adjust your approach:Read-only enumeration can reveal privileged groups, nested memberships, and risky relationships safely. DDelete inactive accountsโ PAYLOAD FIZZLEDBlocked this time. Adjust your approach:Read-only enumeration can reveal privileged groups, nested memberships, and risky relationships safely. 35/100 Reconnaissance and Enumeration A response header reveals an outdated framework. What is the BEST follow-up? AImmediately exploit every known issueโ RETRY THE VECTOREvery failed attempt is enumeration. Note this:Headers can be misleading. The tester should validate version, exposure, exploitability, and compensating controls. BPublish the finding onlineโ RETRY THE VECTOREvery failed attempt is enumeration. Note this:Headers can be misleading. The tester should validate version, exposure, exploitability, and compensating controls. CAssume full compromiseโ RETRY THE VECTOREvery failed attempt is enumeration. Note this:Headers can be misleading. The tester should validate version, exposure, exploitability, and compensating controls. DVerify whether the version is accurate and whether the vulnerable component is reachableโ OBJECTIVE CAPTUREDMethodical over flashy. That's what passes this exam.Headers can be misleading. The tester should validate version, exposure, exploitability, and compensating controls. 36/100 Reconnaissance and Enumeration A breach database shows employee emails and old password hashes. What should the tester recommend first within an authorized assessment? AAttempt logins against all company portals immediatelyโ OUT OF SCOPEReset and re-engage with this insight:Credential exposure should be handled carefully with client coordination, data minimization, and approved validation. BPost the list in the report unredactedโ OUT OF SCOPEReset and re-engage with this insight:Credential exposure should be handled carefully with client coordination, data minimization, and approved validation. CCoordinate with the client to validate exposure safely and check password reuse controlsโ CLEAN PIVOTThe red team would want you on the engagement.Credential exposure should be handled carefully with client coordination, data minimization, and approved validation. DEmail users their exposed passwordsโ OUT OF SCOPEReset and re-engage with this insight:Credential exposure should be handled carefully with client coordination, data minimization, and approved validation. 37/100 Reconnaissance and Enumeration A fragile legacy system is in scope but has caused outages during scans before. What is the BEST strategy? ACoordinate a cautious test plan with backups, monitoring, and throttled checksโ EVIDENCE LOGGEDThat's how an ethical hacker thinks โ authorized, precise, documented.Fragile systems require careful planning, monitoring, and conservative testing to reduce availability risk. BScan only from multiple sources to distribute loadโ DETECTED & BLOCKEDVector didn't land โ recon the takeaway:Fragile systems require careful planning, monitoring, and conservative testing to reduce availability risk. CExclude it without telling the clientโ DETECTED & BLOCKEDVector didn't land โ recon the takeaway:Fragile systems require careful planning, monitoring, and conservative testing to reduce availability risk. DRun the most aggressive scan to finish quicklyโ DETECTED & BLOCKEDVector didn't land โ recon the takeaway:Fragile systems require careful planning, monitoring, and conservative testing to reduce availability risk. 38/100 Reconnaissance and Enumeration Why should a tester document recon sources and timestamps? ATo make the report longerโ ROE CHECK FAILEDBlocked this time. Adjust your approach:Good documentation helps stakeholders verify findings, reproduce observations, and distinguish current from historical data. BTo avoid explaining findingsโ ROE CHECK FAILEDBlocked this time. Adjust your approach:Good documentation helps stakeholders verify findings, reproduce observations, and distinguish current from historical data. CTo support repeatability, evidence quality, and client validationโ REPORT-READYClean tradecraft. The client would sign off on that.Good documentation helps stakeholders verify findings, reproduce observations, and distinguish current from historical data. DTo hide the source of informationโ ROE CHECK FAILEDBlocked this time. Adjust your approach:Good documentation helps stakeholders verify findings, reproduce observations, and distinguish current from historical data. 39/100 Attacks and Exploits A web app locks accounts after five failures but allows unlimited password reset attempts without rate limiting. What vulnerability class is MOST relevant? ASecure cookie configurationโ PAYLOAD FIZZLEDEvery failed attempt is enumeration. Note this:Authentication workflows must protect all paths, including password reset, from abuse such as brute force and enumeration. BNetwork segmentationโ PAYLOAD FIZZLEDEvery failed attempt is enumeration. Note this:Authentication workflows must protect all paths, including password reset, from abuse such as brute force and enumeration. CWeak authentication workflow controlโ ROE HONOREDYou stayed in scope and got the objective. Textbook.Authentication workflows must protect all paths, including password reset, from abuse such as brute force and enumeration. DStrong encryption at restโ PAYLOAD FIZZLEDEvery failed attempt is enumeration. Note this:Authentication workflows must protect all paths, including password reset, from abuse such as brute force and enumeration. 40/100 Attacks and Exploits A user can change the account ID in a request and view another customer invoice. What is the BEST classification? ADNS cache poisoningโ RETRY THE VECTORReset and re-engage with this insight:Changing an object identifier to access another user data indicates broken authorization/IDOR. BWeak TLS cipherโ RETRY THE VECTORReset and re-engage with this insight:Changing an object identifier to access another user data indicates broken authorization/IDOR. CInsecure direct object reference / broken object level authorizationโ TARGET CLEAREDSharp โ you picked the move a professional tester makes.Changing an object identifier to access another user data indicates broken authorization/IDOR. DClickjacking onlyโ RETRY THE VECTORReset and re-engage with this insight:Changing an object identifier to access another user data indicates broken authorization/IDOR. CHECKPOINT โ 40 DOWN, KEEP CLIMBING 41/100 Attacks and Exploits A search field returns database error messages when special characters are submitted. What should the tester do next? APerform safe validation for injection within scope and document impactโ SCOPE RESPECTEDMethodical over flashy. That's what passes this exam.Detailed errors can indicate injection risk. The tester should validate safely under the ROE and document impact and remediation. BDelete the databaseโ OUT OF SCOPEVector didn't land โ recon the takeaway:Detailed errors can indicate injection risk. The tester should validate safely under the ROE and document impact and remediation. CIgnore it because errors are normalโ OUT OF SCOPEVector didn't land โ recon the takeaway:Detailed errors can indicate injection risk. The tester should validate safely under the ROE and document impact and remediation. DPost the error message publiclyโ OUT OF SCOPEVector didn't land โ recon the takeaway:Detailed errors can indicate injection risk. The tester should validate safely under the ROE and document impact and remediation. 42/100 Attacks and Exploits A comment field stores user input that executes script when another user views the page. What type of issue is this? AARP spoofingโ DETECTED & BLOCKEDBlocked this time. Adjust your approach:Stored XSS occurs when malicious script is saved by the application and later executed in another user browser. BStored cross-site scriptingโ FINDING CONFIRMEDThe red team would want you on the engagement.Stored XSS occurs when malicious script is saved by the application and later executed in another user browser. CReflected DNS amplificationโ DETECTED & BLOCKEDBlocked this time. Adjust your approach:Stored XSS occurs when malicious script is saved by the application and later executed in another user browser. DPassword sprayingโ DETECTED & BLOCKEDBlocked this time. Adjust your approach:Stored XSS occurs when malicious script is saved by the application and later executed in another user browser. 43/100 Attacks and Exploits A portal allows users to upload profile images. Which control BEST reduces risk of malicious file upload? AValidate file type and content, restrict extensions, scan files, and store outside executable pathsโ FOOTHOLD GAINEDThat's how an ethical hacker thinks โ authorized, precise, documented.Secure upload handling uses layered controls, including content validation, scanning, storage isolation, and execution prevention. BTrust the file extension onlyโ ROE CHECK FAILEDEvery failed attempt is enumeration. Note this:Secure upload handling uses layered controls, including content validation, scanning, storage isolation, and execution prevention. CAllow uploads only at nightโ ROE CHECK FAILEDEvery failed attempt is enumeration. Note this:Secure upload handling uses layered controls, including content validation, scanning, storage isolation, and execution prevention. DDisable loggingโ ROE CHECK FAILEDEvery failed attempt is enumeration. Note this:Secure upload handling uses layered controls, including content validation, scanning, storage isolation, and execution prevention. 44/100 Attacks and Exploits A cloud role grants wildcard administrative permissions to a workload that only reads one storage bucket. Which principle is violated? APhysical securityโ PAYLOAD FIZZLEDReset and re-engage with this insight:The role grants far more access than required. Least privilege limits permissions to the minimum necessary for the workload. BNonrepudiationโ PAYLOAD FIZZLEDReset and re-engage with this insight:The role grants far more access than required. Least privilege limits permissions to the minimum necessary for the workload. CData deduplicationโ PAYLOAD FIZZLEDReset and re-engage with this insight:The role grants far more access than required. Least privilege limits permissions to the minimum necessary for the workload. DLeast privilegeโ EXPLOIT VALIDATEDClean tradecraft. The client would sign off on that.The role grants far more access than required. Least privilege limits permissions to the minimum necessary for the workload. 45/100 Attacks and Exploits An API allows unlimited requests to a one-time passcode verification endpoint. What is the BEST remediation recommendation? AImplement rate limits, lockouts, monitoring, and abuse detectionโ OBJECTIVE CAPTUREDYou stayed in scope and got the objective. Textbook.Rate limiting and abuse monitoring reduce brute-force and automation risk. BMake passcodes shorterโ RETRY THE VECTORVector didn't land โ recon the takeaway:Rate limiting and abuse monitoring reduce brute-force and automation risk. CDisable TLSโ RETRY THE VECTORVector didn't land โ recon the takeaway:Rate limiting and abuse monitoring reduce brute-force and automation risk. DMove the endpoint to a different URL onlyโ RETRY THE VECTORVector didn't land โ recon the takeaway:Rate limiting and abuse monitoring reduce brute-force and automation risk. 46/100 Attacks and Exploits A company guest Wi-Fi uses an old shared password that has not changed in years. What is the MAIN risk? ADatabase normalization errorsโ OUT OF SCOPEBlocked this time. Adjust your approach:Long-lived shared keys are difficult to control and may remain known to unauthorized users. BAutomatic patching failureโ OUT OF SCOPEBlocked this time. Adjust your approach:Long-lived shared keys are difficult to control and may remain known to unauthorized users. CUnauthorized access by former guests or outsiders who know the keyโ CLEAN PIVOTSharp โ you picked the move a professional tester makes.Long-lived shared keys are difficult to control and may remain known to unauthorized users. DImproved network performanceโ OUT OF SCOPEBlocked this time. Adjust your approach:Long-lived shared keys are difficult to control and may remain known to unauthorized users. 47/100 Attacks and Exploits An authorized vishing test finds employees disclose internal ticket numbers and manager names. What is the BEST recommendation? ADisable all phone systemsโ DETECTED & BLOCKEDEvery failed attempt is enumeration. Note this:Social engineering findings are best addressed with clear verification procedures, training, and reporting channels. BPunish all employees publiclyโ DETECTED & BLOCKEDEvery failed attempt is enumeration. Note this:Social engineering findings are best addressed with clear verification procedures, training, and reporting channels. CRemove incident response processesโ DETECTED & BLOCKEDEvery failed attempt is enumeration. Note this:Social engineering findings are best addressed with clear verification procedures, training, and reporting channels. DImprove verification procedures and security awareness trainingโ EVIDENCE LOGGEDMethodical over flashy. That's what passes this exam.Social engineering findings are best addressed with clear verification procedures, training, and reporting channels. 48/100 Attacks and Exploits A compromised workstation can connect directly to database administration ports. What control would BEST reduce blast radius? AA larger monitor for administratorsโ ROE CHECK FAILEDReset and re-engage with this insight:Segmentation restricts lateral movement and limits access to sensitive services from user networks. BPublic DNS recordsโ ROE CHECK FAILEDReset and re-engage with this insight:Segmentation restricts lateral movement and limits access to sensitive services from user networks. CMore user desktop shortcutsโ ROE CHECK FAILEDReset and re-engage with this insight:Segmentation restricts lateral movement and limits access to sensitive services from user networks. DNetwork segmentation and access control between user and database zonesโ REPORT-READYThe red team would want you on the engagement.Segmentation restricts lateral movement and limits access to sensitive services from user networks. 49/100 Attacks and Exploits A password spraying test is authorized but must avoid account lockouts. Which control should be reviewed as a safer alternative validation? ATesting against personal accountsโ PAYLOAD FIZZLEDVector didn't land โ recon the takeaway:Reviewing identity controls and logs can evaluate resilience while reducing operational risk. BHigh-volume login attemptsโ PAYLOAD FIZZLEDVector didn't land โ recon the takeaway:Reviewing identity controls and logs can evaluate resilience while reducing operational risk. CDisabling MFA temporarilyโ PAYLOAD FIZZLEDVector didn't land โ recon the takeaway:Reviewing identity controls and logs can evaluate resilience while reducing operational risk. DPassword policy, MFA coverage, sign-in risk logs, and lockout thresholdsโ ROE HONOREDThat's how an ethical hacker thinks โ authorized, precise, documented.Reviewing identity controls and logs can evaluate resilience while reducing operational risk. 50/100 Attacks and Exploits A session token remains valid after logout and password change. What is the BEST finding title? AImproper session invalidationโ TARGET CLEAREDClean tradecraft. The client would sign off on that.Sessions should be invalidated on logout and significant account events such as password changes. BDNS zone transferโ RETRY THE VECTORBlocked this time. Adjust your approach:Sessions should be invalidated on logout and significant account events such as password changes. CInsecure wireless roamingโ RETRY THE VECTORBlocked this time. Adjust your approach:Sessions should be invalidated on logout and significant account events such as password changes. DWeak physical access controlโ RETRY THE VECTORBlocked this time. Adjust your approach:Sessions should be invalidated on logout and significant account events such as password changes. CHECKPOINT โ 50 DOWN, KEEP CLIMBING 51/100 Attacks and Exploits A public site supports deprecated TLS protocols. What is the BEST remediation? AUse self-signed certificates everywhereโ OUT OF SCOPEEvery failed attempt is enumeration. Note this:Modern TLS configuration should remove deprecated protocols and weak cipher suites while considering business compatibility. BDisable HTTPS entirelyโ OUT OF SCOPEEvery failed attempt is enumeration. Note this:Modern TLS configuration should remove deprecated protocols and weak cipher suites while considering business compatibility. CDisable deprecated protocols and weak ciphers after compatibility reviewโ SCOPE RESPECTEDYou stayed in scope and got the objective. Textbook.Modern TLS configuration should remove deprecated protocols and weak cipher suites while considering business compatibility. DMove the server behind a monitorโ OUT OF SCOPEEvery failed attempt is enumeration. Note this:Modern TLS configuration should remove deprecated protocols and weak cipher suites while considering business compatibility. 52/100 Attacks and Exploits A maintenance form passes user input to a backend system command. The application returns OS-level error output. What should the tester suspect? AShoulder surfingโ DETECTED & BLOCKEDReset and re-engage with this insight:OS-level errors from user-controlled input can indicate command injection risk that requires safe validation. BScreen burn-inโ DETECTED & BLOCKEDReset and re-engage with this insight:OS-level errors from user-controlled input can indicate command injection risk that requires safe validation. CCommand injection riskโ FINDING CONFIRMEDSharp โ you picked the move a professional tester makes.OS-level errors from user-controlled input can indicate command injection risk that requires safe validation. DNormal database indexingโ DETECTED & BLOCKEDReset and re-engage with this insight:OS-level errors from user-controlled input can indicate command injection risk that requires safe validation. 53/100 Attacks and Exploits A web application fetches images from user-supplied URLs. Which additional risk should be assessed? AServer-side request forgery to internal resourcesโ FOOTHOLD GAINEDMethodical over flashy. That's what passes this exam.URL-fetching features can be abused to make server-side requests to internal systems if not restricted. BPrinter toner exhaustionโ ROE CHECK FAILEDVector didn't land โ recon the takeaway:URL-fetching features can be abused to make server-side requests to internal systems if not restricted. CKeyboard layout mismatchโ ROE CHECK FAILEDVector didn't land โ recon the takeaway:URL-fetching features can be abused to make server-side requests to internal systems if not restricted. DBluetooth pairing weaknessโ ROE CHECK FAILEDVector didn't land โ recon the takeaway:URL-fetching features can be abused to make server-side requests to internal systems if not restricted. 54/100 Attacks and Exploits An application accepts serialized objects from clients and throws class loading errors. What is the BEST security concern? AWeak badge accessโ PAYLOAD FIZZLEDBlocked this time. Adjust your approach:Client-supplied serialized objects can create insecure deserialization risks if not validated and safely handled. BDNSSEC misconfiguration onlyโ PAYLOAD FIZZLEDBlocked this time. Adjust your approach:Client-supplied serialized objects can create insecure deserialization risks if not validated and safely handled. CExcessive monitor brightnessโ PAYLOAD FIZZLEDBlocked this time. Adjust your approach:Client-supplied serialized objects can create insecure deserialization risks if not validated and safely handled. DInsecure deserializationโ EXPLOIT VALIDATEDThe red team would want you on the engagement.Client-supplied serialized objects can create insecure deserialization risks if not validated and safely handled. 55/100 Attacks and Exploits A container image includes old packages, secrets in environment variables, and runs as root. Which recommendation is BEST? ADisable image scanningโ RETRY THE VECTOREvery failed attempt is enumeration. Note this:Container hardening includes patching, secret management, minimal images, and non-root execution. BPublish the image publicly for reviewโ RETRY THE VECTOREvery failed attempt is enumeration. Note this:Container hardening includes patching, secret management, minimal images, and non-root execution. CIncrease container CPU limits onlyโ RETRY THE VECTOREvery failed attempt is enumeration. Note this:Container hardening includes patching, secret management, minimal images, and non-root execution. DUse minimal patched images, remove secrets, and run with least privilegeโ OBJECTIVE CAPTUREDThat's how an ethical hacker thinks โ authorized, precise, documented.Container hardening includes patching, secret management, minimal images, and non-root execution. 56/100 Attacks and Exploits During an internal test, a standard user can install a service that runs with elevated privileges due to misconfigured permissions. What is the impact? ASafe default configurationโ OUT OF SCOPEReset and re-engage with this insight:Misconfigured service permissions can allow a lower-privileged user to gain higher local privileges. BData compression failureโ OUT OF SCOPEReset and re-engage with this insight:Misconfigured service permissions can allow a lower-privileged user to gain higher local privileges. CLocal privilege escalationโ CLEAN PIVOTClean tradecraft. The client would sign off on that.Misconfigured service permissions can allow a lower-privileged user to gain higher local privileges. DEmail spoofing onlyโ OUT OF SCOPEReset and re-engage with this insight:Misconfigured service permissions can allow a lower-privileged user to gain higher local privileges. 57/100 Attacks and Exploits A critical vulnerability is reported on a server, but the vendor backported the fix without changing the displayed version. What should the tester do? AExploit the server to prove itโ DETECTED & BLOCKEDVector didn't land โ recon the takeaway:Backported patches can make banner versions misleading. Verification should use reliable package or vendor data. BAssume vulnerable based only on banner versionโ DETECTED & BLOCKEDVector didn't land โ recon the takeaway:Backported patches can make banner versions misleading. Verification should use reliable package or vendor data. CRemove the server from scopeโ DETECTED & BLOCKEDVector didn't land โ recon the takeaway:Backported patches can make banner versions misleading. Verification should use reliable package or vendor data. DVerify patch status through package metadata or vendor advisory detailsโ EVIDENCE LOGGEDYou stayed in scope and got the objective. Textbook.Backported patches can make banner versions misleading. Verification should use reliable package or vendor data. 58/100 Attacks and Exploits A developer repository contains hard-coded API keys. What is the BEST immediate remediation sequence? ARename the repository onlyโ ROE CHECK FAILEDBlocked this time. Adjust your approach:Exposed secrets should be considered compromised; rotation, cleanup, and preventive controls are required. BRevoke/rotate exposed keys, remove secrets from code history where feasible, and implement secret scanningโ REPORT-READYSharp โ you picked the move a professional tester makes.Exposed secrets should be considered compromised; rotation, cleanup, and preventive controls are required. CAdd more comments explaining the keyโ ROE CHECK FAILEDBlocked this time. Adjust your approach:Exposed secrets should be considered compromised; rotation, cleanup, and preventive controls are required. DMove the key to another public branchโ ROE CHECK FAILEDBlocked this time. Adjust your approach:Exposed secrets should be considered compromised; rotation, cleanup, and preventive controls are required. 59/100 Attacks and Exploits A web application database account has schema owner permissions but only needs read/write to specific tables. What is the finding? AExcessive database privilegesโ ROE HONOREDMethodical over flashy. That's what passes this exam.Overprivileged database accounts increase impact if the application is compromised. BStrong access governanceโ PAYLOAD FIZZLEDEvery failed attempt is enumeration. Note this:Overprivileged database accounts increase impact if the application is compromised. CSecure password hashingโ PAYLOAD FIZZLEDEvery failed attempt is enumeration. Note this:Overprivileged database accounts increase impact if the application is compromised. DProper network isolationโ PAYLOAD FIZZLEDEvery failed attempt is enumeration. Note this:Overprivileged database accounts increase impact if the application is compromised. 60/100 Attacks and Exploits A download endpoint accepts a filename parameter and may access files outside the intended directory. What control BEST mitigates the issue? AMake filenames longerโ RETRY THE VECTORReset and re-engage with this insight:Path traversal is mitigated by safe path handling, canonicalization, allowlists, and access controls. BCanonicalize paths and enforce an allowlist of permitted files/locationsโ TARGET CLEAREDThe red team would want you on the engagement.Path traversal is mitigated by safe path handling, canonicalization, allowlists, and access controls. CDisable user trainingโ RETRY THE VECTORReset and re-engage with this insight:Path traversal is mitigated by safe path handling, canonicalization, allowlists, and access controls. DUse a slower diskโ RETRY THE VECTORReset and re-engage with this insight:Path traversal is mitigated by safe path handling, canonicalization, allowlists, and access controls. CHECKPOINT โ 60 DOWN, KEEP CLIMBING 61/100 Attacks and Exploits A shopping cart quantity can be changed to a negative number, reducing the total price. What type of issue is this? ABusiness logic flawโ SCOPE RESPECTEDThat's how an ethical hacker thinks โ authorized, precise, documented.Business logic flaws occur when application workflows allow unintended actions not caught by technical controls. BOpen Wi-Fi encryptionโ OUT OF SCOPEVector didn't land โ recon the takeaway:Business logic flaws occur when application workflows allow unintended actions not caught by technical controls. CPatch management successโ OUT OF SCOPEVector didn't land โ recon the takeaway:Business logic flaws occur when application workflows allow unintended actions not caught by technical controls. DDNS recursionโ OUT OF SCOPEVector didn't land โ recon the takeaway:Business logic flaws occur when application workflows allow unintended actions not caught by technical controls. 62/100 Attacks and Exploits A tester finds that users with legacy mail protocols can access mail without MFA. What is the BEST recommendation? AIgnore because mail is not sensitiveโ DETECTED & BLOCKEDBlocked this time. Adjust your approach:Legacy protocols may bypass modern MFA controls. Disabling legacy authentication and enforcing modern auth reduces risk. BRemove all email accountsโ DETECTED & BLOCKEDBlocked this time. Adjust your approach:Legacy protocols may bypass modern MFA controls. Disabling legacy authentication and enforcing modern auth reduces risk. CAllow MFA only for administratorsโ DETECTED & BLOCKEDBlocked this time. Adjust your approach:Legacy protocols may bypass modern MFA controls. Disabling legacy authentication and enforcing modern auth reduces risk. DDisable legacy authentication and require modern authentication with MFAโ FINDING CONFIRMEDClean tradecraft. The client would sign off on that.Legacy protocols may bypass modern MFA controls. Disabling legacy authentication and enforcing modern auth reduces risk. 63/100 Attacks and Exploits An internal chatbot can be prompted to reveal confidential policy content from restricted documents. What is the BEST classification? ANormal chatbot behaviorโ ROE CHECK FAILEDEvery failed attempt is enumeration. Note this:AI systems must enforce authorization boundaries and prevent disclosure of restricted content. BWireless deauthenticationโ ROE CHECK FAILEDEvery failed attempt is enumeration. Note this:AI systems must enforce authorization boundaries and prevent disclosure of restricted content. CAI access control/data leakage weaknessโ FOOTHOLD GAINEDYou stayed in scope and got the objective. Textbook.AI systems must enforce authorization boundaries and prevent disclosure of restricted content. DPhysical tailgatingโ ROE CHECK FAILEDEvery failed attempt is enumeration. Note this:AI systems must enforce authorization boundaries and prevent disclosure of restricted content. 64/100 Attacks and Exploits While validating a web vulnerability, the tester notices no server-side logs are generated for failed authorization attempts. What additional finding may be appropriate? AInsufficient security logging and monitoringโ EXPLOIT VALIDATEDSharp โ you picked the move a professional tester makes.Security-relevant events such as authorization failures should be logged and monitored to support detection and response. BStrong incident readinessโ PAYLOAD FIZZLEDReset and re-engage with this insight:Security-relevant events such as authorization failures should be logged and monitored to support detection and response. COverly strict access controlโ PAYLOAD FIZZLEDReset and re-engage with this insight:Security-relevant events such as authorization failures should be logged and monitored to support detection and response. DExcessive encryptionโ PAYLOAD FIZZLEDReset and re-engage with this insight:Security-relevant events such as authorization failures should be logged and monitored to support detection and response. 65/100 Attacks and Exploits A tester is authorized for external network testing only but notices an unlocked side door. What should the tester do? AEnter and search for network portsโ RETRY THE VECTORVector didn't land โ recon the takeaway:Testing must stay within scope. Physical access attempts require explicit authorization. BProp the door open for the clientโ RETRY THE VECTORVector didn't land โ recon the takeaway:Testing must stay within scope. Physical access attempts require explicit authorization. CTake equipment to prove accessโ RETRY THE VECTORVector didn't land โ recon the takeaway:Testing must stay within scope. Physical access attempts require explicit authorization. DDocument the observation if permitted and avoid entering because physical testing is out of scopeโ OBJECTIVE CAPTUREDMethodical over flashy. That's what passes this exam.Testing must stay within scope. Physical access attempts require explicit authorization. 66/100 Attacks and Exploits Two vulnerabilities are found: one unauthenticated remote code execution on an internet-facing server and one low-severity missing header. Which should be prioritized for validation? AThe one with the shortest descriptionโ OUT OF SCOPEBlocked this time. Adjust your approach:Prioritization should consider exploitability, exposure, and business impact. BThe missing header because it is easierโ OUT OF SCOPEBlocked this time. Adjust your approach:Prioritization should consider exploitability, exposure, and business impact. CThe unauthenticated internet-facing RCE due to likelihood and impactโ CLEAN PIVOTThe red team would want you on the engagement.Prioritization should consider exploitability, exposure, and business impact. DNeither because all vulnerabilities are equalโ OUT OF SCOPEBlocked this time. Adjust your approach:Prioritization should consider exploitability, exposure, and business impact. 67/100 Post-Exploitation After gaining approved low-privilege access to a test host, the tester finds a possible privilege escalation path. What should happen before attempting it? AAttempt it on all hosts immediatelyโ DETECTED & BLOCKEDEvery failed attempt is enumeration. Note this:Post-exploitation actions can increase risk and must be explicitly permitted and controlled. BChange production passwordsโ DETECTED & BLOCKEDEvery failed attempt is enumeration. Note this:Post-exploitation actions can increase risk and must be explicitly permitted and controlled. CConfirm the ROE permits privilege escalation and that safeguards are in placeโ EVIDENCE LOGGEDThat's how an ethical hacker thinks โ authorized, precise, documented.Post-exploitation actions can increase risk and must be explicitly permitted and controlled. DDisable endpoint protectionโ DETECTED & BLOCKEDEvery failed attempt is enumeration. Note this:Post-exploitation actions can increase risk and must be explicitly permitted and controlled. 68/100 Post-Exploitation A standard workstation has stored administrative credentials that can access many servers. What is the PRIMARY risk? ACredential reuse enabling lateral movementโ REPORT-READYClean tradecraft. The client would sign off on that.Stored privileged credentials on endpoints can enable lateral movement if the workstation is compromised. BBetter password complexityโ ROE CHECK FAILEDReset and re-engage with this insight:Stored privileged credentials on endpoints can enable lateral movement if the workstation is compromised. CImproved user productivityโ ROE CHECK FAILEDReset and re-engage with this insight:Stored privileged credentials on endpoints can enable lateral movement if the workstation is compromised. DReduced need for backupsโ ROE CHECK FAILEDReset and re-engage with this insight:Stored privileged credentials on endpoints can enable lateral movement if the workstation is compromised. 69/100 Post-Exploitation A client asks whether persistence can be established on production servers to test detection. What is the BEST response? AUse only approved, controlled, reversible methods with clear cleanup stepsโ ROE HONOREDYou stayed in scope and got the objective. Textbook.Persistence testing must be explicitly approved, reversible, and documented with cleanup procedures. BLeave persistence for future testsโ PAYLOAD FIZZLEDVector didn't land โ recon the takeaway:Persistence testing must be explicitly approved, reversible, and documented with cleanup procedures. CDisable all logs before testingโ PAYLOAD FIZZLEDVector didn't land โ recon the takeaway:Persistence testing must be explicitly approved, reversible, and documented with cleanup procedures. DInstall hidden backdoors without telling anyoneโ PAYLOAD FIZZLEDVector didn't land โ recon the takeaway:Persistence testing must be explicitly approved, reversible, and documented with cleanup procedures. 70/100 Post-Exploitation The ROE prohibits real data exfiltration but allows simulation. Which method is BEST? AUse benign test files with agreed labels and sizesโ TARGET CLEAREDSharp โ you picked the move a professional tester makes.Simulated exfiltration with benign files demonstrates control gaps without exposing sensitive data. BEmail sensitive files to personal emailโ RETRY THE VECTORBlocked this time. Adjust your approach:Simulated exfiltration with benign files demonstrates control gaps without exposing sensitive data. CCopy customer records to prove impactโ RETRY THE VECTORBlocked this time. Adjust your approach:Simulated exfiltration with benign files demonstrates control gaps without exposing sensitive data. DCompress the finance share and transfer it externallyโ RETRY THE VECTORBlocked this time. Adjust your approach:Simulated exfiltration with benign files demonstrates control gaps without exposing sensitive data. CHECKPOINT โ 70 DOWN, KEEP CLIMBING 71/100 Post-Exploitation A tester establishes access to a jump host and wants to test reachability to an internal subnet. What must be verified first? AThat pivoting and the target subnet are authorized in the ROEโ SCOPE RESPECTEDMethodical over flashy. That's what passes this exam.Pivoting changes the test path and can affect additional systems. It must be within scope. BThat testing avoids all client contactsโ OUT OF SCOPEEvery failed attempt is enumeration. Note this:Pivoting changes the test path and can affect additional systems. It must be within scope. CThat no notes are takenโ OUT OF SCOPEEvery failed attempt is enumeration. Note this:Pivoting changes the test path and can affect additional systems. It must be within scope. DThat the jump host has a fast CPUโ OUT OF SCOPEEvery failed attempt is enumeration. Note this:Pivoting changes the test path and can affect additional systems. It must be within scope. 72/100 Post-Exploitation After completing a test, what should the tester do with test accounts, temporary files, and artifacts? AHide them to test future detectionโ DETECTED & BLOCKEDReset and re-engage with this insight:Cleanup is a required post-exploitation activity to restore the environment and reduce residual risk. BLeave them for future convenienceโ DETECTED & BLOCKEDReset and re-engage with this insight:Cleanup is a required post-exploitation activity to restore the environment and reduce residual risk. CShare them with another clientโ DETECTED & BLOCKEDReset and re-engage with this insight:Cleanup is a required post-exploitation activity to restore the environment and reduce residual risk. DRemove or help the client remove artifacts according to the cleanup planโ FINDING CONFIRMEDThe red team would want you on the engagement.Cleanup is a required post-exploitation activity to restore the environment and reduce residual risk. 73/100 Post-Exploitation A tester gains access to a file share containing sensitive HR records. What evidence approach is BEST? ACapture minimal proof such as redacted filenames/metadata allowed by ROEโ FOOTHOLD GAINEDThat's how an ethical hacker thinks โ authorized, precise, documented.Minimize access to sensitive data and collect only approved evidence necessary to prove risk. BDownload all HR recordsโ ROE CHECK FAILEDVector didn't land โ recon the takeaway:Minimize access to sensitive data and collect only approved evidence necessary to prove risk. CUpload the data to a public scannerโ ROE CHECK FAILEDVector didn't land โ recon the takeaway:Minimize access to sensitive data and collect only approved evidence necessary to prove risk. DOpen every file to assess sensitivityโ ROE CHECK FAILEDVector didn't land โ recon the takeaway:Minimize access to sensitive data and collect only approved evidence necessary to prove risk. 74/100 Post-Exploitation A web server contains cloud access tokens in a configuration file. What is the BEST immediate recommendation? APrint tokens in the final reportโ PAYLOAD FIZZLEDBlocked this time. Adjust your approach:Exposed tokens should be rotated, protected, and managed using secure secret storage. BLeave tokens because the server needs themโ PAYLOAD FIZZLEDBlocked this time. Adjust your approach:Exposed tokens should be rotated, protected, and managed using secure secret storage. CDisable the application permanentlyโ PAYLOAD FIZZLEDBlocked this time. Adjust your approach:Exposed tokens should be rotated, protected, and managed using secure secret storage. DRotate tokens and move secrets to a managed secret storeโ EXPLOIT VALIDATEDClean tradecraft. The client would sign off on that.Exposed tokens should be rotated, protected, and managed using secure secret storage. 75/100 Post-Exploitation During an assumed-breach test, lateral movement simulation is not detected. What should the tester include in the report? ADetection gap, telemetry sources reviewed, and recommended monitoring improvementsโ OBJECTIVE CAPTUREDYou stayed in scope and got the objective. Textbook.Detection findings should be objective, evidence-based, and include actionable monitoring recommendations. BOnly that the SOC failedโ RETRY THE VECTOREvery failed attempt is enumeration. Note this:Detection findings should be objective, evidence-based, and include actionable monitoring recommendations. CNo mention because detection is not technicalโ RETRY THE VECTOREvery failed attempt is enumeration. Note this:Detection findings should be objective, evidence-based, and include actionable monitoring recommendations. DNames of analysts to blameโ RETRY THE VECTOREvery failed attempt is enumeration. Note this:Detection findings should be objective, evidence-based, and include actionable monitoring recommendations. 76/100 Post-Exploitation A tester needs to show how a low-privilege user could reach a privileged role through group nesting. What is the BEST evidence? AA deleted group policy objectโ OUT OF SCOPEReset and re-engage with this insight:Privilege path evidence helps stakeholders understand escalation risk and remediation steps. BA screenshot of unrelated antivirus statusโ OUT OF SCOPEReset and re-engage with this insight:Privilege path evidence helps stakeholders understand escalation risk and remediation steps. CA clear privilege path diagram or description based on directory relationshipsโ CLEAN PIVOTSharp โ you picked the move a professional tester makes.Privilege path evidence helps stakeholders understand escalation risk and remediation steps. DA list of all employee salariesโ OUT OF SCOPEReset and re-engage with this insight:Privilege path evidence helps stakeholders understand escalation risk and remediation steps. 77/100 Post-Exploitation An internal assessment permits collecting password hashes for offline strength analysis. What is the BEST handling practice? AStore them in a personal folder indefinitelyโ DETECTED & BLOCKEDVector didn't land โ recon the takeaway:Password hashes are sensitive authentication material and must be tightly controlled. BUse them against third-party servicesโ DETECTED & BLOCKEDVector didn't land โ recon the takeaway:Password hashes are sensitive authentication material and must be tightly controlled. CProtect hashes as sensitive data and follow agreed storage/retention rulesโ EVIDENCE LOGGEDMethodical over flashy. That's what passes this exam.Password hashes are sensitive authentication material and must be tightly controlled. DEmail them to the full companyโ DETECTED & BLOCKEDVector didn't land โ recon the takeaway:Password hashes are sensitive authentication material and must be tightly controlled. 78/100 Post-Exploitation The tester can access a sensitive database using an overprivileged service account. What is the safest way to demonstrate impact? AModify production recordsโ ROE CHECK FAILEDBlocked this time. Adjust your approach:Impact should be demonstrated with minimal, approved evidence that avoids data exposure or system damage. BRun a limited, approved query that proves access without exposing sensitive recordsโ REPORT-READYThe red team would want you on the engagement.Impact should be demonstrated with minimal, approved evidence that avoids data exposure or system damage. CExport the entire databaseโ ROE CHECK FAILEDBlocked this time. Adjust your approach:Impact should be demonstrated with minimal, approved evidence that avoids data exposure or system damage. DDelete one table as proofโ ROE CHECK FAILEDBlocked this time. Adjust your approach:Impact should be demonstrated with minimal, approved evidence that avoids data exposure or system damage. 79/100 Post-Exploitation A client asks the tester to disable EDR on production systems to make testing easier. What should the tester recommend? ADisable EDR everywhereโ PAYLOAD FIZZLEDEvery failed attempt is enumeration. Note this:Security monitoring should generally remain in place; exceptions must be approved, limited, and documented. BUninstall EDR secretlyโ PAYLOAD FIZZLEDEvery failed attempt is enumeration. Note this:Security monitoring should generally remain in place; exceptions must be approved, limited, and documented. CAvoid documenting the requestโ PAYLOAD FIZZLEDEvery failed attempt is enumeration. Note this:Security monitoring should generally remain in place; exceptions must be approved, limited, and documented. DUse an approved test plan that preserves monitoring or uses a lab exception if necessaryโ ROE HONOREDThat's how an ethical hacker thinks โ authorized, precise, documented.Security monitoring should generally remain in place; exceptions must be approved, limited, and documented. 80/100 Post-Exploitation A tester identifies that session cookies lack secure attributes. What is the BEST post-exploitation demonstration? AShow risk using a controlled test account and approved evidenceโ TARGET CLEAREDClean tradecraft. The client would sign off on that.Use controlled accounts and minimize sensitive exposure when demonstrating session risks. BDisable the websiteโ RETRY THE VECTORReset and re-engage with this insight:Use controlled accounts and minimize sensitive exposure when demonstrating session risks. CPublish cookies in the reportโ RETRY THE VECTORReset and re-engage with this insight:Use controlled accounts and minimize sensitive exposure when demonstrating session risks. DHijack a real executive sessionโ RETRY THE VECTORReset and re-engage with this insight:Use controlled accounts and minimize sensitive exposure when demonstrating session risks. CHECKPOINT โ 80 DOWN, KEEP CLIMBING 81/100 Post-Exploitation After gaining access to a workstation, the tester can reach cardholder data systems despite segmentation claims. What should the report emphasize? AThat all firewalls should be removedโ OUT OF SCOPEVector didn't land โ recon the takeaway:Segmentation bypass can carry significant business and compliance impact and should be clearly documented. BOnly the workstation hostnameโ OUT OF SCOPEVector didn't land โ recon the takeaway:Segmentation bypass can carry significant business and compliance impact and should be clearly documented. CSegmentation control failure and business/compliance impactโ SCOPE RESPECTEDYou stayed in scope and got the objective. Textbook.Segmentation bypass can carry significant business and compliance impact and should be clearly documented. DThat segmentation is unnecessaryโ OUT OF SCOPEVector didn't land โ recon the takeaway:Segmentation bypass can carry significant business and compliance impact and should be clearly documented. 82/100 Post-Exploitation The ROE states all remote access must be removed within 24 hours of test completion. What should the tester do? AWait until the next annual testโ DETECTED & BLOCKEDBlocked this time. Adjust your approach:Access lifecycle management and cleanup must follow the ROE. BTrack access methods and confirm removal within the required timeframeโ FINDING CONFIRMEDSharp โ you picked the move a professional tester makes.Access lifecycle management and cleanup must follow the ROE. CTransfer access to another tester outside the projectโ DETECTED & BLOCKEDBlocked this time. Adjust your approach:Access lifecycle management and cleanup must follow the ROE. DKeep one account as a backupโ DETECTED & BLOCKEDBlocked this time. Adjust your approach:Access lifecycle management and cleanup must follow the ROE. 83/100 Post-Exploitation A test path reaches an engineering design repository. Which additional context improves the finding? AAn unrelated list of open portsโ ROE CHECK FAILEDEvery failed attempt is enumeration. Note this:Post-exploitation findings should translate technical access into business impact. BA copy of all designsโ ROE CHECK FAILEDEvery failed attempt is enumeration. Note this:Post-exploitation findings should translate technical access into business impact. CThe tester personal opinion on design qualityโ ROE CHECK FAILEDEvery failed attempt is enumeration. Note this:Post-exploitation findings should translate technical access into business impact. DBusiness impact such as intellectual property exposure and competitive harmโ FOOTHOLD GAINEDMethodical over flashy. That's what passes this exam.Post-exploitation findings should translate technical access into business impact. 84/100 Post-Exploitation Which statement is BEST for documenting a successful privilege escalation? AEveryone should be firedโ PAYLOAD FIZZLEDReset and re-engage with this insight:Good reporting is specific, evidence-based, scoped, and professional. BWe used cool techniquesโ PAYLOAD FIZZLEDReset and re-engage with this insight:Good reporting is specific, evidence-based, scoped, and professional. CA standard user could gain local administrator privileges due to misconfigured service permissions; evidence was validated on one approved hostโ EXPLOIT VALIDATEDThe red team would want you on the engagement.Good reporting is specific, evidence-based, scoped, and professional. DThe network is completely insecureโ PAYLOAD FIZZLEDReset and re-engage with this insight:Good reporting is specific, evidence-based, scoped, and professional. 85/100 Reporting and Communication Which statement is BEST suited for an executive summary? ARun this exact exploit string to reproduce compromiseโ RETRY THE VECTORVector didn't land โ recon the takeaway:Executives need business-focused risk, impact, and prioritization. BTesting identified three high-risk paths that could expose customer data; remediation should prioritize identity controls and internet-facing systemsโ OBJECTIVE CAPTUREDThat's how an ethical hacker thinks โ authorized, precise, documented.Executives need business-focused risk, impact, and prioritization. CThe tester used five toolsโ RETRY THE VECTORVector didn't land โ recon the takeaway:Executives need business-focused risk, impact, and prioritization. DThe /admin endpoint returned HTTP 403 with header X-Frame-Options missingโ RETRY THE VECTORVector didn't land โ recon the takeaway:Executives need business-focused risk, impact, and prioritization. 86/100 Reporting and Communication What elements should a strong technical finding include? AOnly a screenshotโ OUT OF SCOPEBlocked this time. Adjust your approach:Complete findings allow technical teams to understand, validate, prioritize, and remediate issues. BOnly the tester nameโ OUT OF SCOPEBlocked this time. Adjust your approach:Complete findings allow technical teams to understand, validate, prioritize, and remediate issues. COnly the scanner plugin IDโ OUT OF SCOPEBlocked this time. Adjust your approach:Complete findings allow technical teams to understand, validate, prioritize, and remediate issues. DTitle, description, evidence, impact, likelihood, affected assets, and remediationโ CLEAN PIVOTClean tradecraft. The client would sign off on that.Complete findings allow technical teams to understand, validate, prioritize, and remediate issues. 87/100 Reporting and Communication A vulnerability is easy to exploit remotely and affects a system storing regulated data. How should risk generally be rated? ALow because exploitation has not happened yetโ DETECTED & BLOCKEDEvery failed attempt is enumeration. Note this:Risk should consider likelihood, impact, exposure, data sensitivity, and compensating controls. BNo risk because the system is onlineโ DETECTED & BLOCKEDEvery failed attempt is enumeration. Note this:Risk should consider likelihood, impact, exposure, data sensitivity, and compensating controls. CInformational because it is commonโ DETECTED & BLOCKEDEvery failed attempt is enumeration. Note this:Risk should consider likelihood, impact, exposure, data sensitivity, and compensating controls. DHigh or critical depending on compensating controls and business contextโ EVIDENCE LOGGEDYou stayed in scope and got the objective. Textbook.Risk should consider likelihood, impact, exposure, data sensitivity, and compensating controls. 88/100 Reporting and Communication A report identifies excessive cloud permissions. Which recommendation is BEST? AGive all users admin to simplify troubleshootingโ ROE CHECK FAILEDReset and re-engage with this insight:Actionable recommendations should target root cause and include preventive and detective controls. BDelete all cloud accountsโ ROE CHECK FAILEDReset and re-engage with this insight:Actionable recommendations should target root cause and include preventive and detective controls. CIgnore because cloud providers are responsible for everythingโ ROE CHECK FAILEDReset and re-engage with this insight:Actionable recommendations should target root cause and include preventive and detective controls. DImplement least-privilege roles, remove wildcard permissions, and monitor privileged actionsโ REPORT-READYSharp โ you picked the move a professional tester makes.Actionable recommendations should target root cause and include preventive and detective controls. 89/100 Reporting and Communication Which evidence practice is BEST for sensitive findings? AAvoid evidence entirelyโ PAYLOAD FIZZLEDVector didn't land โ recon the takeaway:Reports should protect sensitive data while providing sufficient evidence. BAttach full databasesโ PAYLOAD FIZZLEDVector didn't land โ recon the takeaway:Reports should protect sensitive data while providing sufficient evidence. CRedact secrets and sensitive data while preserving enough proof for validationโ ROE HONOREDMethodical over flashy. That's what passes this exam.Reports should protect sensitive data while providing sufficient evidence. DInclude full passwords so teams can test themโ PAYLOAD FIZZLEDVector didn't land โ recon the takeaway:Reports should protect sensitive data while providing sufficient evidence. 90/100 Reporting and Communication After remediation, what is the purpose of a retest? APunish teams for original findingsโ RETRY THE VECTORBlocked this time. Adjust your approach:Retesting verifies remediation and supports closure decisions. BAvoid documenting closureโ RETRY THE VECTORBlocked this time. Adjust your approach:Retesting verifies remediation and supports closure decisions. CValidate that fixes are effective and did not introduce obvious regressionsโ TARGET CLEAREDThe red team would want you on the engagement.Retesting verifies remediation and supports closure decisions. DGenerate a brand-new unrelated reportโ RETRY THE VECTORBlocked this time. Adjust your approach:Retesting verifies remediation and supports closure decisions. CHECKPOINT โ 90 DOWN, KEEP CLIMBING 91/100 Reporting and Communication Developers request guidance for an injection finding. What should the tester provide? AOnly a severity numberโ OUT OF SCOPEEvery failed attempt is enumeration. Note this:Developers need actionable technical detail to fix the issue safely. BOnly business impactโ OUT OF SCOPEEvery failed attempt is enumeration. Note this:Developers need actionable technical detail to fix the issue safely. CA vague statement to improve securityโ OUT OF SCOPEEvery failed attempt is enumeration. Note this:Developers need actionable technical detail to fix the issue safely. DTechnical root cause, safe reproduction summary, and secure coding remediation guidanceโ SCOPE RESPECTEDThat's how an ethical hacker thinks โ authorized, precise, documented.Developers need actionable technical detail to fix the issue safely. 92/100 Reporting and Communication How should automated scanner output be used in a final report? ACopied directly without reviewโ DETECTED & BLOCKEDReset and re-engage with this insight:Scanner output is useful but must be validated and interpreted in context. BAs the only report contentโ DETECTED & BLOCKEDReset and re-engage with this insight:Scanner output is useful but must be validated and interpreted in context. CDeleted even when usefulโ DETECTED & BLOCKEDReset and re-engage with this insight:Scanner output is useful but must be validated and interpreted in context. DAs supporting evidence after validation and contextual analysisโ FINDING CONFIRMEDClean tradecraft. The client would sign off on that.Scanner output is useful but must be validated and interpreted in context. 93/100 Reporting and Communication Multiple findings trace back to lack of MFA for privileged access. What should the report include? AA recommendation to remove all adminsโ ROE CHECK FAILEDVector didn't land โ recon the takeaway:A root-cause theme helps clients address systemic weaknesses rather than isolated symptoms. BA thematic/root-cause observation recommending MFA enforcement and privileged access governanceโ FOOTHOLD GAINEDYou stayed in scope and got the objective. Textbook.A root-cause theme helps clients address systemic weaknesses rather than isolated symptoms. COnly separate low-level findings with no connectionโ ROE CHECK FAILEDVector didn't land โ recon the takeaway:A root-cause theme helps clients address systemic weaknesses rather than isolated symptoms. DNo mention because MFA is inconvenientโ ROE CHECK FAILEDVector didn't land โ recon the takeaway:A root-cause theme helps clients address systemic weaknesses rather than isolated symptoms. 94/100 Reporting and Communication A vulnerable service cannot be patched immediately due to vendor support limits. What should the report recommend? AExpose it to the internet to monitor attacksโ PAYLOAD FIZZLEDBlocked this time. Adjust your approach:When immediate patching is not possible, compensating controls reduce risk while a long-term fix is planned. BTurn off backupsโ PAYLOAD FIZZLEDBlocked this time. Adjust your approach:When immediate patching is not possible, compensating controls reduce risk while a long-term fix is planned. CCompensating controls such as isolation, access restrictions, monitoring, and a patch/upgrade planโ EXPLOIT VALIDATEDSharp โ you picked the move a professional tester makes.When immediate patching is not possible, compensating controls reduce risk while a long-term fix is planned. DIgnore the issue permanentlyโ PAYLOAD FIZZLEDBlocked this time. Adjust your approach:When immediate patching is not possible, compensating controls reduce risk while a long-term fix is planned. 95/100 Reporting and Communication A tester confirms a critical internet-facing vulnerability during week one of a month-long test. What should happen? AWait until final deliveryโ RETRY THE VECTOREvery failed attempt is enumeration. Note this:Critical findings should be communicated promptly according to the ROE so the client can reduce risk quickly. BNotify the client through the agreed escalation process before the final reportโ OBJECTIVE CAPTUREDMethodical over flashy. That's what passes this exam.Critical findings should be communicated promptly according to the ROE so the client can reduce risk quickly. CTell only unrelated employeesโ RETRY THE VECTOREvery failed attempt is enumeration. Note this:Critical findings should be communicated promptly according to the ROE so the client can reduce risk quickly. DPost it on social mediaโ RETRY THE VECTOREvery failed attempt is enumeration. Note this:Critical findings should be communicated promptly according to the ROE so the client can reduce risk quickly. 96/100 Reporting and Communication Which metric combination BEST supports remediation prioritization? ASeverity, exploitability, asset criticality, exposure, and remediation effortโ CLEAN PIVOTThe red team would want you on the engagement.Prioritization should combine risk and practical remediation factors. BLength of finding titleโ OUT OF SCOPEReset and re-engage with this insight:Prioritization should combine risk and practical remediation factors. CTool logo colorโ OUT OF SCOPEReset and re-engage with this insight:Prioritization should combine risk and practical remediation factors. DAlphabetical order of hostnamesโ OUT OF SCOPEReset and re-engage with this insight:Prioritization should combine risk and practical remediation factors. 97/100 Reporting and Communication Which report language is MOST professional? AEverything is brokenโ DETECTED & BLOCKEDVector didn't land โ recon the takeaway:Professional reporting is objective, specific, and evidence-based. BThis was easy to hackโ DETECTED & BLOCKEDVector didn't land โ recon the takeaway:Professional reporting is objective, specific, and evidence-based. CThe application allowed unauthorized access to invoice records due to missing object-level authorization checksโ EVIDENCE LOGGEDThat's how an ethical hacker thinks โ authorized, precise, documented.Professional reporting is objective, specific, and evidence-based. DThe developers made a terrible mistakeโ DETECTED & BLOCKEDVector didn't land โ recon the takeaway:Professional reporting is objective, specific, and evidence-based. 98/100 Reporting and Communication A finding requires changes by identity, network, and application teams. What should the report include? AA statement that no one can fix itโ ROE CHECK FAILEDBlocked this time. Adjust your approach:Multi-team findings benefit from clear ownership mapping and coordinated action. BClear remediation steps and suggested ownership by control areaโ REPORT-READYClean tradecraft. The client would sign off on that.Multi-team findings benefit from clear ownership mapping and coordinated action. COnly the tester phone numberโ ROE CHECK FAILEDBlocked this time. Adjust your approach:Multi-team findings benefit from clear ownership mapping and coordinated action. DA recommendation to outsource everythingโ ROE CHECK FAILEDBlocked this time. Adjust your approach:Multi-team findings benefit from clear ownership mapping and coordinated action. 99/100 Reporting and Communication After remediation, the client accepts a remaining low-risk issue due to business need. What should be documented? AResidual risk, business justification, owner, and review dateโ ROE HONOREDYou stayed in scope and got the objective. Textbook.Accepted residual risks should be formally documented with ownership and review timelines. BOnly the tester disagreementโ PAYLOAD FIZZLEDEvery failed attempt is enumeration. Note this:Accepted residual risks should be formally documented with ownership and review timelines. CNothing because accepted risks do not matterโ PAYLOAD FIZZLEDEvery failed attempt is enumeration. Note this:Accepted residual risks should be formally documented with ownership and review timelines. DA public announcementโ PAYLOAD FIZZLEDEvery failed attempt is enumeration. Note this:Accepted residual risks should be formally documented with ownership and review timelines. 100/100 Reporting and Communication What is the BEST agenda for a final penetration test readout? AObjectives and scope, key risk themes, critical findings, business impact, remediation roadmap, and Q&Aโ TARGET CLEAREDSharp โ you picked the move a professional tester makes.A final readout should summarize scope, impact, priorities, and actionable next steps for stakeholders. BA list of every packet sentโ RETRY THE VECTORReset and re-engage with this insight:A final readout should summarize scope, impact, priorities, and actionable next steps for stakeholders. COnly jokes and screenshotsโ RETRY THE VECTORReset and re-engage with this insight:A final readout should summarize scope, impact, priorities, and actionable next steps for stakeholders. DOnly raw scan outputโ RETRY THE VECTORReset and re-engage with this insight:A final readout should summarize scope, impact, priorities, and actionable next steps for stakeholders. ENGAGEMENT COMPLETE โ REPORT DELIVEREDA real test ends with a report that makes the client stronger. You just sharpened yours. Oluma respects the reps. TARGETS CLEARED ENGAGED These are original practice scenarios written for the Oluma community with an ethical, authorized-testing focus. CompTIAยฎ and PenTest+ยฎ are registered trademarks of CompTIA, Inc. Oluma is not affiliated with or endorsed by CompTIA. No official exam content is reproduced here โ learn the craft, never the dumps.