โ† All EJPT Flashcard Decks

Pivoting and Lateral Movement Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Pivoting and Lateral Movement flashcards as text
  1. A pentester has a shell on a Windows pivot host and wants to enumerate all network interfaces to identify additional subnets. Which command shows this information?

    Answer: ipconfig /all

    ipconfig /all displays all network adapter configurations including IP addresses, subnets, and gateways, revealing additional network segments.

  2. In a pivoting scenario, a pentester has routed through a compromised host to reach 172.16.0.0/24. Running nmap via proxychains returns only TCP results and misses ICMP-based host discovery. Why?

    Answer: SOCKS proxies only support TCP, not ICMP

    SOCKS proxies are TCP-only protocols and cannot tunnel ICMP packets, so nmap host discovery using ping (-PE) will not work through proxychains.

  3. After pivoting into a network via Metasploit routes, which nmap flag should be used to disable ICMP ping discovery so host scanning works through the SOCKS proxy?

    Answer: -Pn

    The -Pn flag tells nmap to skip host discovery (no ping) and treat all hosts as up, which is necessary when scanning through a SOCKS proxy that can't forward ICMP.

  4. A pentester uses SSH local port forwarding: 'ssh -L 8080:192.168.1.10:80 user@pivot'. After this, how does the pentester access the internal web service at 192.168.1.10?

    Answer: Browse to http://127.0.0.1:8080 on the attacker machine

    Local port forwarding binds the specified port on the local (attacker) machine, so connections to 127.0.0.1:8080 are forwarded through the SSH tunnel to the target.

  5. Which Windows command can a pentester run on a pivot host to discover other machines with open SMB shares in the local subnet (Windows built-in)?

    Answer: net view

    The `net view` command enumerates computers and shared resources visible on the Windows network, helping identify lateral movement targets.

  6. During an eJPT lab, a pentester needs to upgrade a basic netcat shell on a pivot host to a Meterpreter session for better pivoting capabilities. Which Metasploit post module accomplishes this?

    Answer: post/multi/manage/shell_to_meterpreter

    The shell_to_meterpreter post module injects a Meterpreter payload into an existing basic shell session, upgrading it to a full Meterpreter session.

  7. What is the primary security risk that makes pivoting possible in a segmented network during a penetration test?

    Answer: A compromised dual-homed host that bridges network segments

    Pivoting exploits a compromised host that has connectivity to multiple network segments, using it as a relay to reach otherwise isolated internal resources.