Free LPT (Master) sample questions
Real questions from the EC-Council Licensed Penetration Tester (Master) practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 6 of 12 free sample questions.
A penetration tester is drafting a Statement of Work (SOW) for a client requiring PCI-DSS compliance testing. The client uses a cloud-native architecture with microservices. Which specific scoping requirement must be included to ensure the test satisfies PCI-DSS Requirement 11.3?
While utilizing AI-driven penetration testing tools during an engagement, you notice the tool is generating traffic that mimics a known ransomware propagation pattern (SMB scanning followed by encryption attempts on dummy files). The ROE strictly prohibits 'destructive testing' or 'simulation of malware that alters file integrity.' What is the immediate best practice response?
You are performing OSINT on a target organization 'Globex Corp'. You have identified their primary domain is `globex.com`. You suspect they are using a specific naming convention for their internal development servers which might be exposed. Using `massdns` or a similar tool, which wordlist strategy would yield the highest probability of discovering these hidden subdomains with minimal noise?
True or False: When performing a physical social engineering engagement, utilizing a ' pre-texting' call to the target facility's security desk to verify the arrival of a 'vendor' (yourself) constitutes a passive information gathering technique.
Which of the following Shodan search filters would be MOST effective for identifying a target organization's exposed Industrial Control Systems (ICS) specifically running the Modbus protocol, restricted to their specific IP range?
6 more free samples are waiting
Create a free account to unlock the whole LPT (Master) sample bank, or get full access to all 150 practice questions in the simulator.