TechNuggets Academy

Attacks and Exploits

Free CompTIA PenTest+ practice — 6 questions on Attacks and Exploits, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Attacks and Exploits
During an authorized internal penetration test, a tester has obtained valid low-privileged domain user credentials. The tester wants to obtain a service account's plaintext password by requesting a Kerberos service ticket for an account with a registered SPN and cracking the ticket offline. Which technique BEST accomplishes this goal?
Kerberoasting exploits the fact that any authenticated domain user can request a TGS ticket for any SPN-registered service account; the ticket is encrypted with the service account's NTLM hash, which can be brute-forced offline with tools like Rubeus or Impacket's GetUserSPNs.py, without triggering account lockouts.
Question 2 of 6 · Attacks and Exploits
A web application penetration tester finds an in-scope application that fetches a user-supplied URL to render a preview image. The tester submits http://169.254.169.254/latest/meta-data/iam/security-credentials/ as the URL and the response contains temporary cloud IAM access keys. Which vulnerability class was exploited to obtain these credentials?
SSRF occurs when an application can be coerced into making requests to arbitrary destinations on the server's behalf; here the server itself queries the cloud instance metadata service (169.254.169.254), leaking IAM role credentials — a classic cloud SSRF-to-credential-theft chain.
Question 3 of 6 · Attacks and Exploits
A tester captures NTLMv2 authentication attempts on a segment using an LLMNR/NBT-NS poisoning tool, then forwards the captured authentication session in real time to a separate target server that has SMB signing disabled, gaining an authenticated session without ever cracking the password hash. Which attack does this describe?
An NTLM relay attack forwards a captured authentication attempt to a different server in real time (rather than cracking it), succeeding when the target does not enforce SMB signing — commonly executed with tools like ntlmrelayx.
Question 4 of 6 · Attacks and Exploits
A tester identifies a Java-based web application that deserializes user-supplied serialized objects without validation, exposing it to insecure deserialization. Which tool is purpose-built for generating malicious serialized payloads targeting known Java gadget chains to achieve remote code execution?
ysoserial generates malicious serialized Java objects using known gadget chains (e.g., CommonsCollections, Jdk7u21) to exploit insecure deserialization vulnerabilities and achieve RCE — it is the standard tool for this exact attack class.
Question 5 of 6 · Attacks and Exploits
A tester wants to capture the PMKID from a WPA2-PSK access point using hcxdumptool without needing to deauthenticate a connected client. Which hashcat attack mode should be used to attempt to crack the resulting capture file?
Hashcat mode 22000 is the current unified mode for cracking both PMKID-based captures and full 4-way handshakes converted to the .hc22000 format, having consolidated and deprecated the older 2500/16800 modes; PMKID capture requires no client interaction since it is broadcast by the AP itself in the first EAPOL frame.
Question 6 of 6 · Attacks and Exploits
During an authorized assessment of an operational technology (OT) environment, a tester observes that Modbus TCP traffic used to communicate with PLCs has no built-in authentication or encryption mechanism. Which statement BEST describes the resulting risk the tester should report?
Modbus TCP was designed for industrial reliability, not security, and includes no native authentication or encryption; any host with network reachability to the PLC can send legitimate-looking function codes to read or write coil/register values, enabling unauthorized control actions.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →