During repeated scans of the same subnet, results show inconsistent host availability and varying open ports. Network logs indicate intermittent packet loss during the scan window. How should the tester respond to this?
The latest changes and updates from the administration for this exam.
Latest Update: Jun 15 2026
All questions are working fine.
During repeated scans of the same subnet, results show inconsistent host availability and varying open ports. Network logs indicate intermittent packet loss during the scan window. How should the tester respond to this?
Frank, a penetration tester, has successfully compromised a workstation within a company's network. He uses Mimikatz to extract user credentials from the memory of the compromised machine. With these credentials, Frank aims to move laterally to other machines within the network to further assess the security posture further. Which of the following best describes the performance of this lateral movement?
For a penetration test, you need to hide malicious files within the filesystem to evade detection by antivirus software. You decide to utilize a method that leverages the existing filesystem structure, attaching the malicious file to an innocuous file without altering its size or content. Of the following options, which would be the best choice?
During a penetration test, an assessor identifies several exploitable weaknesses within a target environment and documents them in the final report. After the organization implements multiple remediation controls, the tester performs validation and determines that some residual risk still exists even though exploitation difficulty has significantly increased. Which of the following actions should the organization take NEXT regarding the remaining risk?
You are conducting a social engineering attack against an organization as part of an engagement. You run over to a busy employee and quickly push a USB drive in their face. "Quick, quick, I am running late for my presentation. Please, print out the PDF on this drive for me!" The employee looks unwilling to help, but you continue to explain how you are running out of time and need their assistance. What type of social engineering principle is being exploited here?
Consider the following data structure:

Which of the following best describes the data structure presented above?
Which of the following types of encryption would ensure the best security of a website?
You call up the CFO's assistant at an organization that is the target of your penetration test. You tell the assistant that you are an IRS agent and will be coming by this afternoon to meet with their boss. You ask the assistant for their email address so you can send them a PowerPoint to print out for the CFO to review before the meeting. When the assistant opens the PowerPoint, a warning pops up asking to enable Macros. You tell them to click accept and hurry because the CFO must get a copy of this before you arrive in 30 minutes. What type of social engineering principle are you using to exploit this organization?
Which of the following attacks would most likely be used to create an inadvertent disclosure of information from an organization's database?
During an internal penetration test, you are modifying a Bash script that parses Nmap scan results to count the number of exposed services on a target host. The script must trigger an alert when the number of open ports exceeds the maximum allowed threshold (20 Open TCP ports) defined in the Rules of Engagement (RoE) to highlight high-risk systems for prioritization. Which of the following operators would be BEST used to generate the alert?