PenTest+ Lateral Movement and Pivoting Concepts Quiz

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 8865 | Total Attempts: 106,055
| Questions: 20 | Updated: Aug 13, 2026
Please wait...
Question 1 / 21
🏆 Rank #--
0 %
0/100
Score 0/100

1. Kerberoasting targets which Kerberos component to extract crackable hashes?

Submit
Please wait...
About This Quiz
PenTest+ Lateral Movement and Pivoting Concepts Quiz - Quiz

This quiz evaluates your understanding of post-exploitation techniques and lateral movement strategies used in penetration testing. You will be tested on pivoting methods, credential harvesting, network reconnaissance from a compromised host, and techniques for moving between systems while avoiding detection. Ideal for security professionals preparing for advanced penetration testing certifications.

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. BloodHound is used post-exploitation to map ____ relationships and identify privilege escalation paths.

Submit

3. Which Windows registry hive contains cached domain credentials that can be extracted post-exploitation?

Submit

4. True or False: Token impersonation requires the attacker to have SYSTEM-level privileges on the compromised host.

Submit

5. What is the primary purpose of using a SOCKS proxy during lateral movement?

Submit

6. A ____ is a user account with administrative privileges created for persistence after exploitation.

Submit

7. Which of the following are effective methods for network reconnaissance from a compromised host? (Select all that apply)

Submit

8. True or False: Constrained delegation allows a service to impersonate users for specific services only.

Submit

9. Which tool is used to create a golden ticket after compromising the krbtgt hash?

Submit

10. In Active Directory, the ____ attribute can be modified to enable privileged delegation.

Submit

11. What is the primary goal of lateral movement in a post-exploitation phase?

Submit

12. What is the primary advantage of using a reverse proxy for lateral movement?

Submit

13. True or False: A compromised domain controller provides immediate access to all domain user credentials.

Submit

14. Which Windows service is often exploited for privilege escalation through service modification?

Submit

15. Mimikatz is commonly used post-exploitation to extract ____ from Windows systems.

Submit

16. What does the term 'living off the land' refer to in post-exploitation?

Submit

17. Which of the following is a valid method for credential harvesting post-exploitation? (Select all that apply)

Submit

18. True or False: Kerberos golden tickets can be used to impersonate any user on a domain after compromising the krbtgt account.

Submit

19. Pass-the-hash attacks are effective because they allow attackers to authenticate without knowing the user's ____.

Submit

20. Which technique allows an attacker to use a compromised host as a gateway to access other network segments?

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (20)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
Kerberoasting targets which Kerberos component to extract crackable...
BloodHound is used post-exploitation to map ____ relationships and...
Which Windows registry hive contains cached domain credentials that...
True or False: Token impersonation requires the attacker to have...
What is the primary purpose of using a SOCKS proxy during lateral...
A ____ is a user account with administrative privileges created for...
Which of the following are effective methods for network...
True or False: Constrained delegation allows a service to impersonate...
Which tool is used to create a golden ticket after compromising the...
In Active Directory, the ____ attribute can be modified to enable...
What is the primary goal of lateral movement in a post-exploitation...
What is the primary advantage of using a reverse proxy for lateral...
True or False: A compromised domain controller provides immediate...
Which Windows service is often exploited for privilege escalation...
Mimikatz is commonly used post-exploitation to extract ____ from...
What does the term 'living off the land' refer to in...
Which of the following is a valid method for credential harvesting...
True or False: Kerberos golden tickets can be used to impersonate any...
Pass-the-hash attacks are effective because they allow attackers to...
Which technique allows an attacker to use a compromised host as a...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!