eJPTv2 Certification Exam — Questions and Answers
Question 1: In social engineering reconnaissance, what information gathered from social media is MOST useful for crafting a convincing phishing pretext?
- The target's IP address
- The target's browser history
- The target's MAC address
- The target's recent work events, colleagues' names, and projects (Correct answer)
Correct answer: The target's recent work events, colleagues' names, and projects
Recent work events and colleague names allow attackers to craft believable, context-aware pretexts that bypass suspicion.
Question 2: In a network capture, you see repeated ICMP Type 3 Code 3 messages. What do these indicate?
- Port unreachable (Correct answer)
- Network unreachable
- Time to live exceeded
- Host unreachable
Correct answer: Port unreachable
ICMP Type 3 Code 3 means 'Destination Port Unreachable,' typically seen when a UDP packet hits a closed port.
Question 3: What is 'token impersonation' in Windows post-exploitation?
- Bypassing UAC by cloning an admin process
- Stealing saved browser credentials
- Forging Kerberos tickets to access services
- Using another user's access token to perform actions with their privileges (Correct answer)
Correct answer: Using another user's access token to perform actions with their privileges
Token impersonation uses the Windows access token of another logged-in user to execute commands with that user's privileges, enabling lateral movement or privilege escalation.
Question 4: What is the function of a VPN (Virtual Private Network)?
- To create a secure connection to a remote network. (Correct answer)
- To monitor online activity.
- To bypass firewalls and access restricted content.
- To increase internet speed.
Correct answer: To create a secure connection to a remote network.
A Virtual Private Network (VPN) establishes an encrypted connection, often called a 'tunnel,' over a public network like the internet. This secure tunnel allows users to send and receive data as if their computing device were directly connected to the private network. VPNs are primarily used to provide secure remote access to corporate resources or to enhance privacy by encrypting internet traffic.
Question 5: What is the purpose of input validation in preventing web application vulnerabilities?
- To speed up page load times.
- To monitor network traffic.
- To ensure that user inputs are properly sanitized. (Correct answer)
- To improve the web application's UI.
Correct answer: To ensure that user inputs are properly sanitized.
Input validation is a critical security measure that checks and sanitizes all data entered by users into a web application. Its purpose is to prevent malicious data, such as SQL injection commands or XSS scripts, from being processed by the application. By ensuring inputs conform to expected formats and content, it significantly reduces the risk of various web application vulnerabilities.
Question 6: Which tool is commonly used to perform Pass-the-Hash attacks on Windows networks?
- Hydra
- Netcat
- Mimikatz (Correct answer)
- Nmap
Correct answer: Mimikatz
Mimikatz can perform Pass-the-Hash by injecting NTLM hashes directly into authentication sessions without needing the plaintext password.
Question 7: In the context of penetration test reporting, what is 'risk rating' typically based on?
- The tester's personal opinion of the vulnerability's importance
- The number of tools required to exploit the vulnerability
- The age of the CVE associated with the vulnerability
- A combination of likelihood of exploitation and potential impact on the organization (Correct answer)
Correct answer: A combination of likelihood of exploitation and potential impact on the organization
Risk rating combines likelihood (how probable exploitation is) with impact (how severe the consequences would be) to produce a meaningful priority score.
Question 8: What does 'security misconfiguration' refer to in the OWASP Top 10 context, as relevant to web application testing?
- Storing passwords in plain text in the database
- Using outdated cryptographic algorithms in TLS
- Improperly configured permissions, defaults, or settings that expose the application to attack (Correct answer)
- Failing to validate user-uploaded file types
Correct answer: Improperly configured permissions, defaults, or settings that expose the application to attack
Security misconfiguration covers a broad category of issues including default credentials, open cloud storage, verbose error messages, unnecessary features enabled, and missing security headers.
Question 9: What is the primary purpose of encryption in eJPT security?
- To compress data
- To protect data confidentiality during storage and transmission (Correct answer)
- To organize data more efficiently
- To make data transfer slower
Correct answer: To protect data confidentiality during storage and transmission
Encryption protects data confidentiality by converting information into an unreadable format that can only be decoded with the proper key.
Question 10: What is the MOST important leadership quality for a eJPT certified professional managing a team?
- Demonstrating integrity, clear communication, and ability to develop team members (Correct answer)
- Achieving the highest personal performance metrics
- Maintaining strict control over all decisions
- Avoiding all forms of conflict within the team
Correct answer: Demonstrating integrity, clear communication, and ability to develop team members
Effective leadership in professional settings requires integrity to build trust, clear communication to align the team, and the ability to develop team members' skills and capabilities. These qualities create a productive and engaged team.
Question 11: What is the key to effective cross-functional communication in eJPT environments?
- Communicating only in writing
- Adapting language and context for different audiences (Correct answer)
- Using department-specific jargon
- Avoiding all technical details
Correct answer: Adapting language and context for different audiences
Adapting language and providing appropriate context for different audiences ensures effective communication across functional boundaries.
Question 12: Which reconnaissance technique involves examining website source code and headers?
- Privilege escalation
- Brute force attack
- Web application fingerprinting (Correct answer)
- Password spraying
Correct answer: Web application fingerprinting
Web application fingerprinting examines HTTP headers, source code, and responses to identify technologies and versions in use.
Question 13: What is the main goal of a web application penetration test?
- To fix coding errors.
- To enhance server-side performance.
- To find and exploit vulnerabilities in the web application. (Correct answer)
- To protect against DDoS attacks.
Correct answer: To find and exploit vulnerabilities in the web application.
The main goal of a web application penetration test is to proactively identify and exploit security weaknesses within a web application's code, configuration, and underlying infrastructure. Testers simulate real-world attacks to uncover vulnerabilities such as SQL injection, XSS, broken authentication, and insecure direct object references. This helps organizations understand their security posture and remediate flaws before malicious actors can exploit them.
Question 14: In the context of vulnerability scanning, what is 'network enumeration' typically performed before?
- Social engineering attacks
- Vulnerability scanning itself (Correct answer)
- Patch management
- Report generation
Correct answer: Vulnerability scanning itself
Network enumeration discovers live hosts, open ports, and services before the vulnerability scan, so the scanner knows exactly what targets to assess.
Question 15: Which Burp Suite feature is best suited for discovering hidden parameters and values through automated fuzzing?
- Burp Scanner
- Burp Decoder
- Burp Intruder (Correct answer)
- Burp Comparer
Correct answer: Burp Intruder
Burp Intruder automates customizable attack patterns against HTTP requests, making it ideal for fuzzing parameter values, discovering injection points, and brute-forcing inputs.
Question 16: What is the NTDS.dit file and why is it targeted in post-exploitation?
- A Windows firewall configuration file
- A file storing browser saved passwords
- The Windows event log database
- The Active Directory database containing all domain user hashes (Correct answer)
Correct answer: The Active Directory database containing all domain user hashes
NTDS.dit is the Active Directory database on a Domain Controller that contains password hashes for all domain accounts, making it a high-value target.
Question 17: What is a common method used to test for SQL injection vulnerabilities in web applications?
- Scanning for vulnerabilities in the source code.
- Performing a system reboot.
- Using brute force to break passwords.
- Inserting SQL commands like single quote (') in input fields. (Correct answer)
Correct answer: Inserting SQL commands like single quote (') in input fields.
A common and basic method to test for SQL injection vulnerabilities is to insert special SQL characters, such as a single quote ('), into input fields. If the application is vulnerable, this character can break the intended SQL query, causing a database error or unexpected behavior. This indicates that user input is not being properly sanitized before being passed to the database.
Question 18: Which Windows built-in tool can attackers use to exfiltrate files using HTTP/S without installing additional software?
- ipconfig
- certutil (Correct answer)
- netstat
- tasklist
Correct answer: certutil
Certutil can encode/decode files and download content over HTTP/S using its `-urlcache -split -f` flags, making it a living-off-the-land exfiltration tool.
Question 19: What does the term 'false positive' mean in the context of vulnerability scanning?
- A reported vulnerability that does not actually exist (Correct answer)
- A correctly identified critical vulnerability
- A scan that crashes the target service
- A vulnerability that was missed by the scanner
Correct answer: A reported vulnerability that does not actually exist
A false positive occurs when a scanner reports a vulnerability that is not actually present on the target system.
Question 20: What is the purpose of a vulnerability scan policy or template in tools like Nessus?
- To schedule report delivery to stakeholders
- To define the scope, plugins, and settings used during a scan (Correct answer)
- To store scan results in a database format
- To automatically patch discovered vulnerabilities
Correct answer: To define the scope, plugins, and settings used during a scan
Scan policies or templates configure which plugins run, scan speed, credentials, and port ranges, tailoring the scan to a specific use case.
Question 21: What does a 'bind shell' payload do differently from a reverse shell?
- It listens on a port on the target for the attacker to connect to (Correct answer)
- It encrypts traffic using TLS
- It embeds itself in a legitimate process
- It uses UDP instead of TCP
Correct answer: It listens on a port on the target for the attacker to connect to
A bind shell opens a listening port on the compromised target, and the attacker connects to that port to get a shell.
Question 22: Why should penetration testers maintain detailed notes and logs throughout the engagement?
- To comply with OWASP Top 10 requirements
- To share techniques publicly after the engagement
- To support accurate reporting, provide evidence for findings, and enable recreation of the testing timeline if disputed (Correct answer)
- To bill the client for more hours
Correct answer: To support accurate reporting, provide evidence for findings, and enable recreation of the testing timeline if disputed
Detailed logs and notes form the evidentiary basis for the final report and protect the tester legally if the engagement or its findings are ever questioned.
Question 23: In a pass-the-hash attack, what credential material is used to authenticate without knowing the plaintext password?
- SSL certificate
- NTLM hash (Correct answer)
- Kerberos ticket
- MD5 digest
Correct answer: NTLM hash
Pass-the-hash exploits Windows NTLM authentication by using the captured NTLM hash directly, bypassing the need for the plaintext password.
Question 24: What is the value of continuing education in post-exploitation techniques for eJPT professionals?
- It replaces workplace experience
- It is only needed for recertification
- It keeps professionals current with evolving standards and practices (Correct answer)
- It is primarily a social activity
Correct answer: It keeps professionals current with evolving standards and practices
Continuing education ensures professionals stay current with the latest developments, standards, and best practices in their field.
Question 25: Which documentation is essential when working with network attacks in eJPT?
- Only verbal notes
- General descriptions without specifics
- Detailed technical specifications and as-built diagrams (Correct answer)
- Marketing materials
Correct answer: Detailed technical specifications and as-built diagrams
Detailed technical specifications and as-built diagrams provide the accurate reference information needed for maintenance and troubleshooting.
Question 26: A client asks you to test their web application but explicitly excludes the database server from scope. During testing, you discover a SQL injection that likely affects the database. What should you do?
- Document the finding and immediately notify the client about the out-of-scope risk (Correct answer)
- Ignore it since the database is out of scope
- Pivot to the database server to gather evidence
- Exploit the SQL injection to demonstrate its severity
Correct answer: Document the finding and immediately notify the client about the out-of-scope risk
When you discover a vulnerability that affects out-of-scope systems, you must stop and notify the client so they can decide how to proceed.
Question 27: Which port and protocol does DNS primarily use for standard queries?
- UDP 53 (Correct answer)
- TCP 853
- UDP 443
- TCP 53
Correct answer: UDP 53
DNS uses UDP on port 53 for standard queries because it is faster; TCP 53 is used for zone transfers and responses exceeding 512 bytes.
Question 28: What type of attack involves an adversary tricking a user's authenticated browser into submitting an unwanted request to a web application?
- Cross-Site Request Forgery (CSRF) (Correct answer)
- Session Hijacking
- Cross-Site Scripting (XSS)
- Clickjacking
Correct answer: Cross-Site Request Forgery (CSRF)
CSRF exploits the trust a web application has in the user's browser, causing it to send authenticated state-changing requests without the user's knowledge.
Question 29: Which Metasploit post module can be used to gather comprehensive system information on a Windows target?
- post/windows/escalate/getsystem
- post/multi/recon/local_exploit_suggester
- post/multi/manage/shell_to_meterpreter
- post/windows/gather/enum_system (Correct answer)
Correct answer: post/windows/gather/enum_system
The `post/windows/gather/enum_system` module collects detailed information about the Windows target including OS version, installed patches, and running services.
Question 30: What is Cross-Site Request Forgery (CSRF)?
- Hacking a user's account by guessing passwords.
- Spamming a web application with requests.
- Tricking users into making unintended actions on a web application. (Correct answer)
- Forcing users to change their password.
Correct answer: Tricking users into making unintended actions on a web application.
Cross-Site Request Forgery (CSRF) is an attack that tricks a victim's web browser into sending an authenticated request to a vulnerable web application. The attacker crafts a malicious request (e.g., to change a password or transfer funds) and embeds it in a page the victim visits. If the victim is logged into the target application, their browser will automatically include their session cookies, making the request appear legitimate to the server.
Question 31: Why is a penetration test report marked 'CONFIDENTIAL' or 'RESTRICTED'?
- Because penetration testers are required to keep all client communications secret forever
- Because it contains a detailed roadmap of exploitable weaknesses that could be used by attackers if disclosed (Correct answer)
- To prevent the client from sharing it with their own IT staff
- To comply with CVSS scoring requirements
Correct answer: Because it contains a detailed roadmap of exploitable weaknesses that could be used by attackers if disclosed
A pentest report is a sensitive document because it details exactly how to compromise the client's systems; unauthorized disclosure could enable real attacks.
Question 32: Which Nmap scan type sends only SYN packets and never completes the TCP handshake, making it stealthier?
- -sU (UDP)
- -sS (SYN Stealth) (Correct answer)
- -sA (ACK)
- -sT (TCP Connect)
Correct answer: -sS (SYN Stealth)
The SYN scan (`-sS`) sends a SYN packet and, upon receiving SYN-ACK, sends RST without completing the 3-way handshake, leaving fewer logs.
Question 33: A tester's automated scanner reports 200 vulnerabilities. What is the professional approach before including these in the final report?
- Include all 200 automatically to maximize the report's value
- Manually validate each finding to eliminate false positives before reporting (Correct answer)
- Include only the top 10 most severe without validation
- Send the raw scanner output directly to the client as the final report
Correct answer: Manually validate each finding to eliminate false positives before reporting
Automated scanner output must be manually validated because scanners produce false positives; reporting unvalidated results wastes client remediation resources.
Question 34: Which tool can be used to perform port forwarding through a Meterpreter session to reach internal services?
- portfwd (Correct answer)
- route add
- socks4a
- autoroute
Correct answer: portfwd
The `portfwd` command in Meterpreter creates local TCP port forwarding rules, allowing the attacker to connect to internal services via the compromised host.
Question 35: What Nmap flag enables OS detection during a vulnerability assessment scan?
- -A
- -p-
- -sV
- -O (Correct answer)
Correct answer: -O
The -O flag instructs Nmap to attempt OS fingerprinting by analyzing TCP/IP stack responses from the target.
Question 36: An attacker intercepts an NTLMv2 hash using Responder. What is the immediate next step to leverage this credential?
- Pass the hash directly to SMB
- Use it to forge a Kerberos ticket
- Inject it into an LDAP query
- Crack it offline with Hashcat or attempt an NTLM relay (Correct answer)
Correct answer: Crack it offline with Hashcat or attempt an NTLM relay
NTLMv2 hashes cannot be passed directly; they must either be cracked offline or relayed in real time using a tool like ntlmrelayx.
eJPTv2 Certification Exam
The eJPTv2 certification validates foundational penetration testing skills, including reconnaissance, vulnerability assessment, exploitation, and post-exploitation techniques.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds