LPT (Master) Sample Questions & Answers
Free EC-Council Licensed Penetration Tester (Master) practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.
Launch the full LPT (Master) simulator →Showing 6 of 12 free samples.
- Question 1Intermediate
Information Gathering and Attack Surface Mapping · Collecting Open-source Intelligence (OSINT) on Target's Domain Name
You are performing OSINT on a target organization 'Globex Corp'. You have identified their primary domain is
globex.com. You suspect they are using a specific naming convention for their internal development servers which might be exposed. Usingmassdnsor a similar tool, which wordlist strategy would yield the highest probability of discovering these hidden subdomains with minimal noise?Show answer & explanation
Correct answer: D
Permutation scanning (or alteration scanning) is highly effective for discovering hidden assets that follow naming conventions (like
dev-,stg-,test-) derived from already known subdomains. This is more targeted and efficient than generic brute forcing. - Question 2Beginner
Information Gathering and Attack Surface Mapping · Social Engineering Penetration Testing Concepts
True or False: When performing a physical social engineering engagement, utilizing a ' pre-texting' call to the target facility's security desk to verify the arrival of a 'vendor' (yourself) constitutes a passive information gathering technique.
Show answer & explanation
Correct answer: B
This is False. Calling the target (vishing) involves direct interaction with the target organization's personnel. Passive information gathering (OSINT) strictly involves gathering information without directly engaging or alerting the target. Pre-texting calls are Active Reconnaissance/Social Engineering.
- Question 3Advanced
Information Gathering and Attack Surface Mapping · Collecting OSINT about Target Organization on the Web
Which of the following Shodan search filters would be MOST effective for identifying a target organization's exposed Industrial Control Systems (ICS) specifically running the Modbus protocol, restricted to their specific IP range?
Show answer & explanation
Correct answer: A
Port 502 is the standard TCP port for Modbus. The
net:filter restricts the search to the specific CIDR notation of the target organization. This combination precisely targets Modbus services within the client's infrastructure. - Question 4Advanced
Web Application and API Penetration Testing · Evaluate the Security of JSON Web Tokens (JWT)
You are testing a web application that uses JSON Web Tokens (JWT) for authentication. You intercept a token and notice the header contains
{"alg": "RS256"}. You attempt to modify the payload to escalate privileges to 'admin', change the header to{"alg": "HS256"}, and sign the token using the server's public key (which you retrieved from a publicly accessible JWKS endpoint). What specific vulnerability are you attempting to exploit?Show answer & explanation
Correct answer: B
This is a classic Algorithm Confusion attack. The attacker changes the algorithm from RS256 (Asymmetric) to HS256 (Symmetric) and signs the token with the public key. If the server is vulnerable, it will use its public key (which it treats as the secret key for HS256) to verify the signature, allowing the attacker to forge valid tokens.
- Question 5Intermediate
Web Application and API Penetration Testing · Test APIs for Security of GraphQL Implementations
During a web application test, you encounter a GraphQL endpoint. You want to map out the entire schema including all available types, queries, and mutations. Which specific query should you send to the endpoint to perform introspection?
Show answer & explanation
Correct answer: C
This is a standard GraphQL introspection query. It requests the
__schemameta-field, which exposes the entire schema definition, including types, fields, queries, and mutations, allowing the tester to map the API surface. - Question 6Advanced
Web Application and API Penetration Testing · Techniques for Identifying and Testing Injection Vulnerabilities
You are testing a banking application that processes XML input for money transfers. The application parses the XML but does not validate external entity references. You successfully inject the following payload:
<!DOCTYPE foo [ ]> &xxe;However, the application response is generic and does NOT return the file content in the HTTP response body. To exfiltrate the data, which variation of this attack should you attempt next?
Show answer & explanation
Correct answer: A
Since the application does not reflect the entity in the response (Blind XXE), the attacker must use an Out-of-Band (OOB) technique. This involves defining a parameter entity that references an external DTD on an attacker-controlled server. This external DTD then triggers a request back to the attacker's server, appending the content of the target file (e.g., /etc/passwd) to the URL query string.
Ready for the real thing?
The full LPT (Master) simulator has every exam-style question, timed mode, and instant scoring.