Free LPT (Master) sample questions
Real questions from the EC-Council Licensed Penetration Tester (Master) practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 6 of 12 free sample questions.
During a web application test, you encounter a GraphQL endpoint. You want to map out the entire schema including all available types, queries, and mutations. Which specific query should you send to the endpoint to perform introspection?
You are testing a banking application that processes XML input for money transfers. The application parses the XML but does not validate external entity references. You successfully inject the following payload: ```xml <!DOCTYPE foo [ ]> &xxe; ``` However, the application response is generic and does NOT return the file content in the HTTP response body. To exfiltrate the data, which variation of this attack should you attempt next?
Select TWO methods that are effective for identifying a SQL Injection vulnerability when the application suppresses all error messages and does not return data in the response (Blind SQLi).
You have gained access to a compromised Linux server in a DMZ and want to pivot to an internal network (10.10.10.x). The server has no netcat or SSH server running, but it has Python installed. You want to set up a dynamic SOCKS proxy to tunnel your attack traffic (e.g., Burp Suite, Nmap) through this server. Which tool combination and configuration would BEST achieve this?
You are assessing a network where a strict firewall drops all TCP packets with the SYN flag set coming from the external network, except for established connections. You suspect a host is alive behind the firewall. Which Nmap scan type is most likely to elicit a response (RST packet) from a live host in this scenario?
6 more free samples are waiting
Create a free account to unlock the whole LPT (Master) sample bank, or get full access to all 150 practice questions in the simulator.