ExamDumpster

Free LPT (Master) sample questions

Real questions from the EC-Council Licensed Penetration Tester (Master) practice bank, with the correct answer and an explanation for each one. No junk, no filler.

Try them in the simulator Same questions, with study, timed and flashcard modes.

Showing 6 of 12 free sample questions.

Question 1Choose one

You are testing a web application that uses JSON Web Tokens (JWT) for authentication. You intercept a token and notice the header contains `{"alg": "RS256"}`. You attempt to modify the payload to escalate privileges to 'admin', change the header to `{"alg": "HS256"}`, and sign the token using the server's public key (which you retrieved from a publicly accessible JWKS endpoint). What specific vulnerability are you attempting to exploit?

Question 2Choose one

During a web application test, you encounter a GraphQL endpoint. You want to map out the entire schema including all available types, queries, and mutations. Which specific query should you send to the endpoint to perform introspection?

Question 3Choose one

You are testing a banking application that processes XML input for money transfers. The application parses the XML but does not validate external entity references. You successfully inject the following payload: ```xml <!DOCTYPE foo [ ]> &xxe; ``` However, the application response is generic and does NOT return the file content in the HTTP response body. To exfiltrate the data, which variation of this attack should you attempt next?

Question 4Choose 2

Select TWO methods that are effective for identifying a SQL Injection vulnerability when the application suppresses all error messages and does not return data in the response (Blind SQLi).

Question 5Choose one

You have gained access to a compromised Linux server in a DMZ and want to pivot to an internal network (10.10.10.x). The server has no netcat or SSH server running, but it has Python installed. You want to set up a dynamic SOCKS proxy to tunnel your attack traffic (e.g., Burp Suite, Nmap) through this server. Which tool combination and configuration would BEST achieve this?

Question 6Choose one

You are assessing a network where a strict firewall drops all TCP packets with the SYN flag set coming from the external network, except for established connections. You suspect a host is alive behind the firewall. Which Nmap scan type is most likely to elicit a response (RST packet) from a live host in this scenario?

6 more free samples are waiting

Create a free account to unlock the whole LPT (Master) sample bank, or get full access to all 150 practice questions in the simulator.

Create account