Kahoot - EH-07-P1 Windows Privilege Escalation Flashcards

1
Q

Which windows privilege type is associated with a domain account

a. ) Delegated Admin
b. ) Guest User
c. ) Admin
d. ) NTAuthority

A

a.) Delegated Admin

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What tool in windows lets you edit the computer’s registry?

a. ) regedit
b. ) system
c. ) gpedit.msc
d. ) msconfig

A

a.) regedit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which command based utility is associated with creating user accounts?

a. ) cmd.exe
b. ) AddUser
c. ) UserAdd
d. ) net.exe

A

d.) net.exe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

The WinLogon process is launched with _____ privileges

a. ) Root
b. ) Admin
c. ) NT Authority
d. ) Kernel

A

c.) NT Authority

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Privilege Escalation is the process of going from a computer to a domain controller T or F

A

F

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Mitigations for windows privilege escalation include all the following EXCEPT:

a. ) Limit Physical address
b. ) Add a BIOS Password
c. ) Password protect GRUB
d. ) Encrypt the drive

A

c.) Password protect GRUB

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

You hide an account from the Net utility by appending a $ to the end of the user name T or F

A

T

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What tool would you use to review when or if a user account is created?

a. ) Event Viewer
b. ) System Viewer
c. ) UserLog Viewer
d. ) regedit Viewer

A

a.) Event Viewer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the name of the shell executable in windows?

a. ) sethc.exe
b. ) cmd.exe
c. ) shell.exe
d. ) Bash

A

b.) cmd.exe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Implementing whole disk encryption helps mitigate live disk boot attacks T or F

A

T

How well did you know this?
1
Not at all
2
3
4
5
Perfectly