- In the context of penetration testing, what is the primary purpose of defining a Rules of Engagement (RoE) document?
- To record the consent and approval of the owner
- To weigh the impact and urgency of the exposure
- To settle the bounds and limits of the exercise
- To agree the budget and manpower of the project
Correct answer: To settle the bounds and limits of the exercise
Correct answer: To settle the bounds and limits of the exercise. Explanation: Rules of Engagement fix what the team may touch and how far it may go - which targets and address ranges are in play, which techniques are barred, which windows testing may run in, and what must never be attempted. Consent and approval are carried by the signed authorisation letter, not the RoE. Weighing impact and urgency is scoring work that only becomes possible once findings exist, and it belongs in the report. Budget and manpower are commercial terms that sit in the statement of work.
- Which element is crucial to include in a penetration testing report for it to be most effective for the client?
- A short summary of the risks for the owners
- A full account of the flags for the scanner
- A brief profile of the staff for the vendor
- A plain export of the logs for the archives
Correct answer: A short summary of the risks for the owners
Correct answer: A short summary of the risks for the owners. Explanation: A report only changes anything if the people who fund remediation can read it, so a non-technical summary of business risk and recommended action is the element that makes the deliverable effective. An account of the flags handed to a scanner is appendix material that proves method but drives no decision. A profile of the assigned staff is contract paperwork, not a finding. A raw log export pushes the analysis back onto the reader and buries the risk.
- What is the most important reason for defining a clear scope in a penetration testing engagement?
- To hold the final invoice under the agreed rate
- To pick the scanning tools the client team runs
- To time each testing hour around the office day
- To stop the probing of hosts left outside scope
Correct answer: To stop the probing of hosts left outside scope
Correct answer: To stop the probing of hosts left outside scope. Explanation: Scope is the line between authorised and unauthorised activity, so its most important job is keeping the team off systems nobody agreed to expose - shared hosting neighbours, partner networks and third-party services included. Capping the bill is a commercial control set in the contract. Tool choice follows the environment and is a technical decision, not the reason scope exists. Scheduling around the working day is a matter for the engagement calendar.
- Which of the following best describes a Black Box penetration test?
- The tester begins with a complete network document.
- The tester begins with nothing beyond public facts.
- The tester begins with schematics but no passwords.
- The tester begins with a working internal identity.
Correct answer: The tester begins with nothing beyond public facts.
Correct answer: The tester begins with nothing beyond public facts. Explanation: A black box engagement models an outside attacker: the team is handed no internal detail and has to build its own picture from open sources and from what the target exposes. Starting from complete internal documentation describes a white box test. Starting from partial diagrams describes a grey box test. Starting from a working internal account describes an assumed-breach or insider scenario, which begins where a black box test would have to finish.
- What factor is most critical when determining the timeline for a penetration test?
- The count of the spare laptops kept for testers
- The scale of the entire network placed in scope
- The depth of the earlier reviews given to staff
- The style of the final report picked by clients
Correct answer: The scale of the entire network placed in scope
Correct answer: The scale of the entire network placed in scope. Explanation: Duration tracks how much ground has to be covered and how tangled it is - host and application counts, segmentation, business logic and the number of distinct technologies all add hours that cannot be compressed. Spare hardware is procurement, not coverage. Earlier reviews are already-spent work and do not reduce the number of systems that must now be examined. Report styling is a formatting decision taken after the technical work is finished.
- In penetration testing, why is it important to establish a communication plan with the client?
- To agree the dates of each invoice sent out
- To agree the brand of scanner the team runs
- To agree the rooms used by the client staff
- To agree the way an urgent flaw is reported
Correct answer: To agree the way an urgent flaw is reported
Correct answer: To agree the way an urgent flaw is reported. Explanation: A communication plan exists so that a critical finding, a system outage or evidence of a prior compromise reaches a named contact by an agreed route within an agreed time, while the client can still act on it. Invoicing terms are commercial and sit in the contract. Scanner choice is a technical decision for the test team. Workspace arrangements are logistics that have no bearing on how findings travel to the client.
- Which of the following is a key consideration when scoping a penetration test for an e-commerce website?
- The systems that handle the saved payment data
- The pages that show the current product prices
- The scripts that draw the animated home banner
- The letters that thank the loyal repeat buyers
Correct answer: The systems that handle the saved payment data
Correct answer: The systems that handle the saved payment data. Explanation: Payment handling is where an e-commerce breach turns into cardholder loss and regulatory exposure, so the payment path, the stores behind it and the segmentation around them drive the scope. Price display pages carry no sensitive data and fail harmlessly. Banner scripts are presentation code with no route into the payment path. Marketing mail to returning customers is a business process, not part of the tested attack surface.
- What is the primary reason for conducting a risk assessment before a penetration test?
- To learn which vendor sells the fastest tools
- To learn which tester holds the newest badges
- To learn which systems carry the largest loss
- To learn which weekday brings the lowest load
Correct answer: To learn which systems carry the largest loss
Correct answer: To learn which systems carry the largest loss. Explanation: A pre-test risk assessment ranks assets by what their compromise would cost the business, so the engagement can be aimed at the systems where a flaw matters most rather than spread evenly. Scanner speed is a purchasing question. Tester certifications are a staffing question settled before the engagement starts. Quiet periods matter for scheduling disruptive checks but say nothing about which assets deserve the deepest attention.
- In the planning phase of a penetration test, why is it important to consider regulatory compliance?
- To check that the fee sits under the agreed budget
- To check that the tools carry a valid support deal
- To check that the staff hold a current cyber badge
- To check that the work stays inside the local laws
Correct answer: To check that the work stays inside the local laws
Correct answer: To check that the work stays inside the local laws. Explanation: Testing activity can breach computer misuse statutes, data protection rules and sector regulation, so planning has to confirm that every planned technique is lawful and permitted for the data and jurisdictions involved. Budget checks are commercial. Tool support contracts are a vendor matter with no legal bearing on the test. Team certifications may satisfy a client requirement, but holding one does not make an otherwise unlawful action lawful.
- What is the significance of defining a "Stop Point" in a penetration testing engagement?
- It sets the payment date of the client bill
- It sets the strict grounds of an early halt
- It sets the top level of the granted access
- It sets the fixed order of the report parts
Correct answer: It sets the strict grounds of an early halt
Correct answer: It sets the strict grounds of an early halt. Explanation: A stop point names the conditions that suspend testing - a system becoming unstable, evidence of an existing intrusion, or a finding severe enough that continuing would add risk - and tells the team who to call when one is met. Billing dates are contractual. The level of access reached is a result of the test, not a condition for stopping it. Report ordering is a documentation convention agreed at delivery.
- In penetration testing, what is the main purpose of defining the scope in relation to the client's objectives?
- To tie the daily rate to the agreed payment date
- To tie the tool list to the vendor support deals
- To tie the work plan to the stated security aims
- To tie the shift roster to the local office week
Correct answer: To tie the work plan to the stated security aims
Correct answer: To tie the work plan to the stated security aims. Explanation: Scope written against the objectives keeps effort on the questions the organisation actually asked - whether the payment path holds, whether segmentation works, whether an insider could pivot - so the findings answer those questions. Rates and payment dates are commercial terms. Tool lists follow the technology in the environment. Shift rosters are scheduling detail and change nothing about which risks get examined.
- Why is it important to understand the client's infrastructure before starting a penetration test?
- To match the toolset to the running services
- To draft the invoice for the agreed staffing
- To satisfy the law covering the whole sector
- To book the classroom for the team refresher
Correct answer: To match the toolset to the running services
Correct answer: To match the toolset to the running services. Explanation: Knowing what the environment runs - cloud or on-premises, which operating systems, which application stacks, how it is segmented - decides which techniques and tooling can produce results at all, so that understanding is gathered before testing begins. Invoicing is commercial. Regulatory duties are established during legal review, not from an inventory of hosts. Training is arranged around staff development and has nothing to do with this client's architecture.
- What is a critical factor to consider when determining the legal implications of a penetration test?
- The laws of the land hosting the tested systems
- The scale of the budget agreed for the customer
- The brand of the tools running the daily checks
- The count of the servers listed in the contract
Correct answer: The laws of the land hosting the tested systems
Correct answer: The laws of the land hosting the tested systems. Explanation: Testing is lawful or unlawful according to the jurisdiction the systems and their data sit in, so the governing statutes and any cross-border data rules decide what the team may do and what evidence it may keep. Budget size is a commercial figure with no legal weight. Tool branding changes nothing about legality. Host counts describe the size of the job, not the rules that govern it.
- In the planning phase, what is the importance of identifying the critical assets of the organization?
- To spread the same hours across the whole site
- To shorten the total time spent on the network
- To aim the deepest work at the richest targets
- To lower the daily rate charged for the labour
Correct answer: To aim the deepest work at the richest targets
Correct answer: To aim the deepest work at the richest targets. Explanation: Naming the assets that carry the most sensitive data or the most business dependency lets a fixed number of testing hours be spent where a finding would matter most, which is the point of the exercise. Spreading identical effort everywhere treats a domain controller like a print server. Shortening the engagement is a scheduling goal, not a targeting one. Day rates are commercial and are agreed before any asset is examined.
- What role does a threat model play in the planning phase of a penetration test?
- It shows the amount that the client would pay
- It shows the damage that a breach would cause
- It shows the vendor that the staff would pick
- It shows the shift that one tester would work
Correct answer: It shows the damage that a breach would cause
Correct answer: It shows the damage that a breach would cause. Explanation: A threat model pairs likely attackers and their routes in with the assets they would reach, so the planning team can judge what a successful attack would cost and aim testing at those paths. Pricing is a commercial calculation. Vendor selection follows the technology found in the environment. Shift allocation is staffing administration and has no bearing on which threats deserve attention.
- Why is it necessary to establish data handling procedures before conducting a penetration test?
- To speed the files passed between the two testers
- To satisfy the terms listed in the vendor licence
- To settle the format chosen for the client report
- To guard the evidence held until the agreed purge
Correct answer: To guard the evidence held until the agreed purge
Correct answer: To guard the evidence held until the agreed purge. Explanation: Testing produces credentials, screenshots and extracted records that are as sensitive as the client's live data, so handling rules set encrypted storage, restricted access, a retention period and a destruction step before any of it is collected. Faster file sharing between testers is convenience and often the opposite of what the rules require. Licence terms govern the software, not the client's data. Report formatting is a delivery choice made at the end.
- In a penetration testing engagement, why is it important to have a clear understanding of the client's business operations?
- So the checks avoid the busiest retail periods
- So the report copies the usual industry layout
- So the findings match the actual business risk
- So the invoice reflects the agreed hourly rate
Correct answer: So the findings match the actual business risk
Correct answer: So the findings match the actual business risk. Explanation: Knowing how the organisation earns money and which processes cannot stop lets the team rate a finding by what it would do to that business rather than by a generic severity score, which is what makes the report actionable. Avoiding busy retail periods is a scheduling courtesy. Copying an industry layout changes presentation, not relevance. Invoice accuracy is a billing concern with no effect on the value of the findings.
- What is the primary purpose of obtaining written permission before conducting a penetration test?
- It records the precise calendar dates for the visit
- It settles the fee charged for the whole engagement
- It fixes the scope drawn around the listed services
- It proves the owner allowed the intrusive test work
Correct answer: It proves the owner allowed the intrusive test work
Correct answer: It proves the owner allowed the intrusive test work. Explanation: Techniques that are routine on an engagement are criminal offences without permission, so a signed authorisation from someone able to grant it is the document that separates a test from an attack and protects both sides. Recording calendar dates is scheduling detail. Settling a fee is commercial. Fixing the scope defines where the work happens, but a boundary with no signature behind it authorises nothing.
- How does defining the scope of a penetration test benefit the client organization?
- It keeps the paid effort on the agreed targets
- It lowers the price the client pays each month
- It shortens the hours the whole test now takes
- It settles the shape of the final report pages
Correct answer: It keeps the paid effort on the agreed targets
Correct answer: It keeps the paid effort on the agreed targets. Explanation: A defined scope means every hour the organisation buys is spent on systems it chose to have examined, and nothing is wasted on hosts, partners or services that were never meant to be touched. A narrower scope does not by itself reduce the agreed price. It does not shorten the calendar either, since the remaining systems are simply examined more thoroughly. Report formatting is settled separately at delivery.
- In penetration testing, what is the significance of understanding the client's risk tolerance?
- It sets the number of testers booked each month
- It sets the amount of outage the client accepts
- It sets the price the insurer charges each year
- It sets the details of the final written report
Correct answer: It sets the amount of outage the client accepts
Correct answer: It sets the amount of outage the client accepts. Explanation: Risk tolerance tells the team how far it may push - whether denial-of-service checks, exploitation of production systems or credential reuse are permitted - so the strategy can be matched to the disruption the organisation is willing to absorb. Team size follows the scope and the schedule. Insurance pricing is an underwriting matter. Report detail is a documentation decision taken once testing is complete.
- Which tool is primarily used for automated vulnerability scanning in a network penetration testing scenario?
Correct answer: Nessus
Correct answer: Nessus. Explanation: Nessus drives automated network vulnerability assessment: it enumerates hosts and services, runs a maintained plugin feed against them, and reports missing patches, weak configurations and exposed services with severity ratings. Medusa is a parallel login brute-forcer and tests credentials rather than assessing systems for known weaknesses. Kismet passively detects and records wireless networks and clients. Netcat opens raw connections for reading a service or moving data and performs no assessment of its own.
- In the context of penetration testing, what is the primary purpose of using a tool like Burp Suite?
- Editing web requests inside an intercepting proxy
- Cracking wireless keys from captured radio frames
- Mapping reachable hosts across a segmented subnet
- Recovering plain passwords from stolen hash files
Correct answer: Editing web requests inside an intercepting proxy
Correct answer: Editing web requests inside an intercepting proxy. Explanation: Burp Suite sits between the browser and the application so requests and responses can be paused, altered and replayed, which is how authorisation, input handling and session logic in a web application are examined. Wireless key recovery belongs to Wi-Fi auditing suites. Host discovery across a subnet belongs to network mappers. Offline hash cracking belongs to dedicated password crackers, none of which touch application traffic.
- Which technique is most effective for identifying live hosts on a network during a penetration test?
- Reading the HTTP banner from a live service
- Asking the DNS server for the zone transfer
- Trying the SMB share with a stolen password
- Sending an ICMP echo to each target address
Correct answer: Sending an ICMP echo to each target address
Correct answer: Sending an ICMP echo to each target address. Explanation: A sweep of echo requests across the address range is the standard first pass for host discovery, because a reply proves an address is answering before any deeper work is aimed at it. Reading a service banner identifies software on a host already known to exist. A zone transfer returns records held by a name server, which may list hosts that are long gone. Trying a credential against a share tests access, not whether the address is alive.
- What is the primary purpose of using the whois command in the information gathering phase of a penetration test?
- To list the mail exchangers named in the record
- To trace the router hops crossed by the traffic
- To read the contact details filed by the holder
- To show the cipher suites offered by the server
Correct answer: To read the contact details filed by the holder
Correct answer: To read the contact details filed by the holder. Explanation: A whois query returns registration data - the registrant and registrar, contact addresses, creation and expiry dates and the authoritative name servers - which seeds later reconnaissance with names, addresses and infrastructure hints. Mail exchanger records come from a DNS query. Router hops come from a path trace. Cipher suites come from a TLS handshake against the service itself, none of which whois performs.
- Which tool or technique is used for discovering subdomains of a target domain during a penetration test?
- DirBuster
- Bettercap
- Responder
- Subfinder
Correct answer: Subfinder
Correct answer: Subfinder. Explanation: Subfinder exists to enumerate subdomains, querying certificate transparency logs, passive DNS sources and search data to assemble the hostnames that belong to a domain and widen the attack surface under test; Sublist3r and Amass fill the same role. DirBuster brute-forces directories and files on a host that is already known. Bettercap runs on-path network attacks against traffic in a segment. Responder answers broadcast name-resolution requests to capture authentication, and none of the three enumerate hostnames.
- What is the primary goal of fingerprinting a server during a penetration test?
- Listing the local users and group names
- Drawing the router hops and link speeds
- Naming the host system and patch levels
- Timing the answer delay and packet loss
Correct answer: Naming the host system and patch levels
Correct answer: Naming the host system and patch levels. Explanation: Fingerprinting reads how a host answers - stack behaviour, service banners, headers and response quirks - to establish the operating system and the versions of the software it runs, which is what makes a vulnerability relevant or irrelevant to that host. Account enumeration lists principals, not versions. Hop discovery describes the path to the host. Latency and loss measurements describe the link, and none of them identify what the host is running.
- In penetration testing, what is the primary use of a tool like SQLmap?
- Automating the capture of frames from wireless clients
- Automating the injection of code into database queries
- Automating the mapping of ports across remote networks
- Automating the delivery of messages to staff mailboxes
Correct answer: Automating the injection of code into database queries
Correct answer: Automating the injection of code into database queries. Explanation: SQLmap detects where user input reaches a database query unsafely and then works that flaw automatically - fingerprinting the engine, enumerating databases and extracting data - which is why it is the standard tool for demonstrating injection findings. Frame capture on wireless links belongs to Wi-Fi tooling. Port mapping belongs to network scanners. Bulk mail delivery belongs to phishing frameworks, and none of them reach the database layer.
- Which of the following is an active information gathering technique?
- Probing the open ports on the tested company server
- Querying a public breach store for leaked user mail
- Searching a code sharing site for saved access keys
- Reading the cached pages a search index still holds
Correct answer: Probing the open ports on the tested company server
Correct answer: Probing the open ports on the tested company server. Explanation: Active gathering is defined by contact with the target: packets are sent to the client's own systems and the answers are recorded, which produces fresh detail and also leaves entries in the client's logs. Querying a breach store interrogates a third-party dataset. Searching a public code host reads what someone else published. Reading a cached page retrieves a copy held elsewhere, so all three gather intelligence without touching the target at all.
- During a penetration test, which tool is most effective for automated password cracking of hashed passwords?
- Hashcat
- Maltego
- Gophish
- OpenVAS
Correct answer: Hashcat
Correct answer: Hashcat. Explanation: Hashcat is built for offline recovery of passwords from captured hashes, driving dictionary, rule-based, mask and brute-force attacks across many hash types with GPU acceleration; John the Ripper fills the same role. Maltego maps relationships between people, domains and infrastructure for open-source intelligence. Gophish builds and tracks phishing campaigns against staff. OpenVAS scans hosts for known vulnerabilities, and none of the three recover a plaintext from a hash.
- Which method is commonly used to discover the technology stack (like CMS, web server version) of a target web application?
- Timing the page load from several world regions
- Reading the banner text each open service sends
- Counting the links the site offers each visitor
- Checking the owner names listed in the registry
Correct answer: Reading the banner text each open service sends
Correct answer: Reading the banner text each open service sends. Explanation: Connecting to a service and reading what it announces - server headers, framework tokens, generator tags and version strings - is the direct way to establish the platform behind a web application, and it needs nothing more than a normal request. Load timing measures performance. Counting outbound links describes site structure. Registry records name the domain holder, and none of those disclose the software stack in use.
- In penetration testing, what is the primary purpose of a tool like Nikto?
- Capturing the traffic on a shared local segment
- Recovering the password from a stolen hash file
- Checking a web server for known dangerous files
- Auditing the encryption keys on a wireless link
Correct answer: Checking a web server for known dangerous files
Correct answer: Checking a web server for known dangerous files. Explanation: Nikto tests a web server against a large catalogue of risky files and scripts, default content, outdated server versions and unsafe configuration items, and reports what it finds. Traffic capture on a segment is the work of a protocol analyser. Recovering plaintext from hashes is the work of a cracker. Auditing wireless keys is the work of a Wi-Fi suite, and none of them examine a web server's exposed content.
- Which technique is effective for identifying if a web application is vulnerable to cross-site scripting (XSS)?
- Timing the database replies to an altered value
- Listing the open ports a firewall still permits
- Requesting a zone transfer from the name server
- Placing a script marker inside a returned field
Correct answer: Placing a script marker inside a returned field
Correct answer: Placing a script marker inside a returned field. Explanation: Cross-site scripting is confirmed by submitting harmless script markup where user input is echoed back, then checking whether the browser treats the returned text as code rather than as data; the marker shows both the reflection and the missing output encoding. Timing database replies points at injection in a query, a different flaw. Listing permitted ports describes network exposure. A zone transfer returns DNS records, and neither says anything about how input is rendered.
- What is the main goal of utilizing a tool like Wapiti in penetration testing?
- Flooding a wireless channel with forged beacons
- Calling staff members to obtain their passwords
- Crawling a website for hidden injectable inputs
- Replaying captured frames against a router port
Correct answer: Crawling a website for hidden injectable inputs
Correct answer: Crawling a website for hidden injectable inputs. Explanation: Wapiti works purely from the outside: it walks the application to build a list of reachable pages, forms and parameters, then probes those entry points and judges the responses, which is what a black-box web scan means. Forged wireless beacons belong to Wi-Fi attacks. Calling staff for credentials is social engineering. Replaying captured frames targets the network layer, and none of them examine an application's own inputs.
- During a penetration test, which tool is used for sniffing and analyzing network packets?
- Subfinder
- Wireshark
- DirBuster
- Setoolkit
Correct answer: Wireshark
Correct answer: Wireshark. Explanation: Wireshark captures frames from an interface and decodes them protocol by protocol, so a tester can follow a conversation, extract transferred content and prove that a service is sending data without protection. Subfinder enumerates hostnames from passive sources and never reads traffic. DirBuster requests candidate paths from a web server. Setoolkit builds social-engineering campaigns aimed at people, and none of the three decode captured packets.
- In the context of penetration testing, which tool is specifically designed for testing SQL injection vulnerabilities?
Correct answer: SQLmap
Correct answer: SQLmap. Explanation: SQLmap is written for one flaw class: it fingerprints where input reaches a database query unsafely, confirms the weakness through several detection techniques and then enumerates the database behind it. Fierce performs DNS reconnaissance to locate hosts belonging to a domain. Reaver attacks the wireless setup feature on access points to recover the network key. Ncrack brute-forces logins across network services, and none of them examine how an application builds its queries.
- What is the primary use of a tool like OpenVAS in penetration testing?
- Encrypted handshake capture
- Offline passphrase cracking
- Corporate phishing exercise
- Unpatched service discovery
Correct answer: Unpatched service discovery
Correct answer: Unpatched service discovery. Explanation: OpenVAS is a vulnerability management framework: it fingerprints hosts and services, tests them against a maintained feed of network vulnerability tests, and reports the weaknesses found with severity ratings so remediation can be prioritised. Handshake capture belongs to wireless auditing. Passphrase cracking belongs to offline password tools. Phishing exercises target staff behaviour, and none of the three assess hosts for known flaws.
- Which penetration testing technique is most effective for discovering outdated software versions on a target system?
- Sweeping address ranges to find responsive hosts
- Capturing wireless frames to recover shared keys
- Reading service banners to identify release data
- Querying registrar records to list site contacts
Correct answer: Reading service banners to identify release data
A network service announces itself when a connection opens, and that announcement normally carries the product name and release level of the software answering, which is what identifies an unpatched build. Sweeping an address range only establishes which hosts respond at all and returns nothing about the software they run. Capturing wireless frames works at the radio link layer and yields key material, not server software levels. Querying registrar records returns ownership and contact details held outside the target entirely, so it cannot reveal what is installed on the host.
- During a penetration test, what is the primary purpose of using tools like Maltego?
- Charting the relationships between a target's public records
- Recovering the passphrase from a client's wireless handshake
- Exhausting a service until legitimate requests go unanswered
- Guessing credentials against an exposed remote login gateway
Correct answer: Charting the relationships between a target's public records
This tool belongs to the reconnaissance phase: it pulls entities such as people, domains and hosts out of public sources and draws the links between them, so a tester can see how the target organisation is put together before sending it a single packet. Recovering a passphrase from a client's captured handshake is offline wireless cracking, a much later and entirely separate activity. Exhausting a service is an availability attack, which a mapping tool neither performs nor needs. Guessing credentials against a login gateway is an active brute-force attempt, the opposite of assembling data that is already published.
- What is the primary objective of using the 'dig' command in penetration testing?
- Listing private folders exposed by a public web server
- Sorting the captured packets by the protocol they hold
- Finding the live hosts inside one agreed address range
- Pulling the name records published for a chosen domain
Correct answer: Pulling the name records published for a chosen domain
The command queries name servers directly and returns the records published for a domain, which is why testers use it to map hosts, mail routing and delegation during footprinting. Listing folders on a web server is content discovery, driven by a wordlist aimed at the site itself rather than at a name server. Sorting captured packets by protocol is traffic analysis performed on a capture file that already exists. Finding which addresses are live inside a range is host discovery, which works by probing each address rather than by asking a name server anything.
- In penetration testing, what is the primary purpose of tools like theHarvester?
- Recovering account secrets from a captured hash archive
- Collecting staff mailboxes out of openly shared sources
- Enumerating service ports answering on a target machine
- Guessing common passwords against a public login portal
Correct answer: Collecting staff mailboxes out of openly shared sources
This is an open-source intelligence collector: it queries search engines, public listings and key servers to assemble mailboxes, subdomains, host names and staff names for a target, giving the tester a starting picture without touching the target's own systems. Recovering secrets from a captured hash archive is offline cracking, which needs material already stolen from a host. Enumerating which service ports answer is an active scan aimed straight at the target. Guessing passwords against a login portal is an online brute-force attempt, not the collection of data that is already public.
- Which tool is essential for a penetration tester to perform a man-in-the-middle attack for analyzing and intercepting traffic between a web application and its users?
- Cain & Abel, which corrupts address mappings to relay traffic
- Nmap, which examines ranges to chart the services hosts offer
- Aircrack-ng, which digs keys out of the captured radio frames
- Metasploit, which throws a prepared module at one chosen host
Correct answer: Cain & Abel, which corrupts address mappings to relay traffic
To sit between a client and the application it is talking to, a tester has to make both sides send their traffic through the tester's machine, and corrupting the local address-resolution mappings is the classic way to achieve that on a switched segment. The tool that performs that corruption and then relays the redirected traffic is the on-path choice here. A port and service sweeper only inventories what is reachable and never enters the conversation. A wireless key recovery suite works on captured radio frames, not on a wired session with a web application. An exploit delivery framework launches prepared code at a host once a flaw is known, which places nothing between two parties.
- In penetration testing, what is the primary purpose of using the arp-scan tool?
- Recovering account secrets from a stolen credential store
- Decoding one protected session without the negotiated key
- Delivering prepared exploit modules at a chosen appliance
- Listing devices answering address requests on the segment
Correct answer: Listing devices answering address requests on the segment
Address resolution is confined to one broadcast domain, so sending resolution requests to every address on the local segment and recording which ones reply produces a fast and reliable inventory of the hosts physically present, including hosts that ignore other probes. Recovering secrets from a stolen credential store is offline cracking and involves no traffic on the segment. Decoding a protected session without its key is a cryptographic attack. Delivering exploit modules at a chosen appliance is exploitation, which happens long after the tester knows what is on the wire.
- In penetration testing, which attack method involves intercepting and modifying communication between two parties without their knowledge?
- Tricking a person into surrendering secrets with fake warnings
- Relaying one exchange between endpoints while also altering it
- Exhausting a host's capacity until real requests go unanswered
- Smuggling database instructions into a parameter a site trusts
Correct answer: Relaying one exchange between endpoints while also altering it
The defining property is position: the attacker sits in the path, forwards the conversation so both sides believe they are talking directly, and can read or change whatever passes through. Tricking a person with fake warnings works on the human rather than on the traffic, and no exchange is relayed at all. Exhausting a host's capacity denies service instead of intercepting it, and the victims notice immediately. Smuggling instructions into a parameter attacks the data handling at one endpoint; the conversation between two parties is never entered.
- Which type of attack primarily targets web applications by injecting unauthorized SQL commands?
- Planting a script for later execution in a visitor's browser
- Writing beyond a fixed buffer to redirect a program's course
- Slipping a crafted statement into the query a site assembles
- Riding a live signed-in session to issue an unwanted request
Correct answer: Slipping a crafted statement into the query a site assembles
When user input is concatenated into a query instead of being bound as a parameter, an attacker can close the intended statement and append their own, so the database executes commands the developer never wrote. Planting a script that runs later in a visitor's browser attacks other users of the site, not its data store. Writing beyond a fixed buffer corrupts memory in a compiled program and has nothing to do with how a query is assembled. Riding a signed-in session forges a request that the server treats as the victim's own; no statement is injected into any query.
- In the context of penetration testing, what is a 'zero-day' exploit?
- An attack that starts on the day a public patch appears
- An attack that wipes its own traces once a host reboots
- An attack that strikes a server the moment it goes live
- An attack that exploits a bug unknown to its own vendor
Correct answer: An attack that exploits a bug unknown to its own vendor
The term describes the window in which no patch can exist, because the vendor has not yet learned the flaw is there and defenders have had zero days to react. An attack timed to the appearance of a public patch works against a flaw that is already known and fixed, which is an ordinary race against patching. Wiping traces after a reboot is anti-forensics and says nothing about who knows about the flaw. Striking a server the moment it goes live describes when the target was deployed, which is unrelated to whether the underlying weakness has been reported.
- Which technique is used in penetration testing to bypass security mechanisms by corrupting the memory of a program?
- Injecting database queries into a form field left unchecked
- Writing past an allocated region to steer program execution
- Tricking people into handing over their daily login details
- Storing an unwanted script for replay inside other browsers
Correct answer: Writing past an allocated region to steer program execution
When a program copies more data into a fixed region than that region can hold, the surplus lands on adjacent memory such as saved control data, and an attacker who controls the surplus can direct where execution goes next. Injecting queries into an unchecked form field abuses how a statement is built and leaves process memory untouched. Tricking people into handing over login details targets the person, not the program. Storing an unwanted script for replay runs code in someone else's browser and corrupts nothing in the server process.
- What is the primary goal of a Cross-Site Request Forgery (CSRF) attack in web applications?
- To steal personal data a browser holds for another site
- To run a hostile script inside pages other visitors see
- To have a trusted session submit an action nobody chose
- To swamp a server beneath more requests than it answers
Correct answer: To have a trusted session submit an action nobody chose
This attack borrows the victim's authority: the browser already holds a valid session, so a request forged by the attacker arrives with that session attached and the application performs a state change the victim never asked for, such as a transfer or a settings edit. Stealing personal data a browser holds for another site is a same-origin problem, not an action taken in the victim's name. Running a hostile script inside pages other visitors see is a scripting attack against those viewers. Swamping a server with requests removes availability and gains no authority whatsoever.
- In penetration testing, what is the primary purpose of using a 'fuzzer'?
- To feed malformed input in quantity until a target fails
- To turn stolen hash values back into their readable form
- To relay a stream between two endpoints with quiet edits
- To catalogue the accounts held on a public mail platform
Correct answer: To feed malformed input in quantity until a target fails
The tool generates unexpected, malformed and boundary input in bulk, throws it at an interface and watches for crashes, hangs or error states that mark a handling flaw worth investigating; the value is that it explores input space far faster than a human can. Turning stolen hash values back into readable form is offline cracking. Relaying a stream between endpoints with quiet edits is an on-path attack. Cataloguing the accounts held on a mail platform is enumeration. None of the three generate input or watch a target for failure.
- Which attack vector is most commonly used to exploit vulnerabilities in software without user interaction?
- A cloned sign-in form that takes the details a target types
- A hostile web page that fires while a target simply browses
- A rogue access point that logs the sessions a target starts
- A crafted attachment that runs when a target opens the file
Correct answer: A hostile web page that fires while a target simply browses
The distinguishing feature is that no decision by the victim is needed beyond ordinary browsing: content served to the browser exploits a flaw in the browser or one of its components and runs on its own, with no click, no credential entry and no connection choice. The other three vectors all wait on a deliberate act by the target: typing details into a cloned form, choosing to associate with a rogue access point, or opening an attached file. That dependence on user action is exactly what the stem rules out.
- What is the main objective of a Distributed Denial of Service (DDoS) attack?
- To steal the confidential files held on a target server
- To corrupt the saved records a target server hands over
- To exhaust a target server until real users get refused
- To hide hostile code in target server pages people load
Correct answer: To exhaust a target server until real users get refused
The objective is availability rather than secrecy or accuracy: traffic arrives from many sources at once so that bandwidth, connection tables or processing capacity run out and legitimate users are refused. Stealing confidential files is a confidentiality attack that depends on staying quiet, which flooding makes impossible. Corrupting the records a server hands back attacks integrity, and the service keeps answering. Hiding hostile code in pages people load attacks the visitors rather than the server's capacity to respond.
- In the context of penetration testing, what is 'privilege escalation'?
- Raising an account's rights beyond the level first granted
- Reaching hosts on segments outside the limits once settled
- Reading protected files without ever holding the right key
- Lifting credentials from traffic captured on a host's line
Correct answer: Raising an account's rights beyond the level first granted
The term names a change in authority level on a host where the tester already has some foothold: an ordinary account acquires administrative or system rights it was never issued, usually by abusing a misconfiguration, a weak service permission or a flawed component. Reaching hosts on segments outside the agreed limits is a change of location, not of rights, and it is a scoping problem rather than this technique. Reading protected files without the key is a cryptographic problem. Lifting credentials from captured traffic is collection, and on its own it confers no higher authority on the machine.
- What is the primary goal of 'pass-the-hash' attacks?
- Cracking a saved digest offline to recover its clear text
- Replaying stored packets at a service a short while later
- Reading one plain credential as it traverses an open line
- Authenticating using a stolen hash in place of a password
Correct answer: Authenticating using a stolen hash in place of a password
Some authentication schemes accept the stored hash itself as proof of identity, so an attacker who lifts that value from memory or a credential store can present it directly and be logged in; the plaintext password is never needed and never recovered. Cracking a saved digest offline is the slow alternative this technique exists to avoid. Replaying stored packets resends whole messages instead of presenting a credential to an authentication service. Reading a plain credential as it crosses an open line is sniffing, and it works only when the password travels unprotected in the first place.
- In penetration testing, which technique is used to identify and exploit vulnerabilities in web applications by automatically sending a large number of requests with varying payloads?
- Fuzzing, which fills inputs with malformed sample values
- Pivoting, which enters hosts through one compromised box
- Sniffing, which records frames crossing a shared segment
- Phishing, which lures staff into revealing their secrets
Correct answer: Fuzzing, which fills inputs with malformed sample values
Sending a very large number of requests whose values are systematically varied, then watching for errors, stack traces or crashes, is the automated input-generation technique named here; against a web application it exposes mishandled parameters and unexpected states. Entering further hosts through an already compromised machine is lateral movement and generates no input at all. Recording frames that cross a shared segment is passive capture. Luring staff into revealing secrets targets people rather than parameters. None of the three vary application input at volume.
- What type of attack involves manipulating a user into executing unauthorized actions on a website they are currently authenticated to?
- Cookie stealing, which harvests a stored token from browsers
- Open-redirect abuse, which sends a visitor onto another host
- Cross-site request forgery, which rides a user's own session
- Directory traversal, which steps outside a server's web root
Correct answer: Cross-site request forgery, which rides a user's own session
The victim's browser attaches its existing session to any request aimed at that site, so an attacker who can make the browser issue a crafted request has the application act under the victim's identity and perform a change the victim never intended. Harvesting a stored token steals the credential outright instead of borrowing a session in place. Sending a visitor onto another host through an open redirect moves them somewhere else but performs no action in their name. Stepping outside a server's web root reads files from the file system and never involves the victim's session at all.
- In penetration testing, what does a 'payload' refer to?
- The hole in a service that lets an outsider send data
- The reply a server gives that says why a query failed
- The path a tester keeps open that aids a quiet return
- The code that runs on a host once an exploit succeeds
Correct answer: The code that runs on a host once an exploit succeeds
The term names the part that does the attacker's work after entry has been gained: a reverse shell, a command stager or a beacon, delivered by the exploit and executed on the target. Exploit and payload are separate pieces, which is why a framework lets a tester pair one with the other. The hole in a service is the vulnerability, the condition the exploit abuses. A reply explaining why a query failed is ordinary protocol output. A path kept open for a quiet return is persistence, which a payload may establish but is not what the word itself means. NOTE: v1 keyed 'the code used to exploit a vulnerability', which defines the exploit, not the payload; the key has been corrected.
- Which attack exploits the trust that a user has for a particular certificate authority (CA)?
- Replay attack, where captured messages are resent much later
- Rogue CA attack, where a fraudulent issuer blesses impostors
- Downgrade attack, where a weakened TLS suite gets negotiated
- Phishing attack, where a lookalike page gathers user secrets
Correct answer: Rogue CA attack, where a fraudulent issuer blesses impostors
Client software trusts a set of issuers and will accept any identity vouched for by one of them, so an attacker who controls or fraudulently obtains an issuing position can produce credentials for a site they do not own and the client validates them without complaint. That is an abuse of the trust placed in the issuer, exactly as the stem describes. Resending captured messages abuses freshness rather than issuer trust. Negotiating a weakened suite attacks the strength of the agreed protection. A lookalike page deceives the person and never touches the chain of trust.
- In penetration testing, what is the primary goal of a 'side-channel attack'?
- To pull secrets from stolen backups, dumps, or archives
- To pull secrets from crafted queries, forms, or headers
- To pull secrets from captured frames, sessions, or logs
- To pull secrets from measured time, power, or emissions
Correct answer: To pull secrets from measured time, power, or emissions
This class of attack ignores the algorithm and reads the machine running it: how long an operation takes, how much current it draws and what it radiates all vary with the data being processed, and those physical measurements leak key material even when the mathematics is sound. Stolen backups, dumps and archives are data recovered at rest. Crafted queries, forms and headers are application-layer input. Captured frames, sessions and logs are recorded traffic and stored output. Only measurements taken from the physical implementation match the stem.
- Which penetration testing technique involves injecting malicious scripts into a web page viewed by other users?
- Cross-site scripting, which runs code in a visitor's browser
- SQL injection, which inserts statements into a running query
- Buffer overflow, which swamps a small program's memory space
- Server-side forgery, which makes a host fetch internal links
Correct answer: Cross-site scripting, which runs code in a visitor's browser
Input that an application reflects or stores without escaping is returned inside a page, so the browser of anyone viewing that page executes the attacker's code with the site's own origin, exposing session data and letting the attacker act inside the page. Inserting statements into a running query attacks the database rather than the viewer. Swamping a program's memory space corrupts a compiled process and never reaches the page. Making a host fetch internal links abuses the server's own outbound requests, so nothing at all is injected into what other users see.
- What kind of penetration testing attack is conducted against the hardware of a device, such as routers, switches, or servers?
- Passive attack, where traffic is read as it crosses wires
- Physical attack, where the case itself is opened right up
- Protocol attack, where a stage in the exchange is twisted
- Remote attack, where a defect in loaded code is triggered
Correct answer: Physical attack, where the case itself is opened right up
Testing aimed at the equipment itself means reaching the device: console and debug ports, removable storage, factory reset behaviour and chassis access, which is why this work is scoped alongside facility access rather than under network testing. Reading traffic as it crosses wires is interception and needs no access to the case. Twisting one stage of an exchange attacks a protocol, not the metal. Triggering a defect in loaded code is software exploitation delivered over the network, and it never requires the tester to be present.
- Which attack involves an unauthorized person gaining access to a network by using a legitimate user's credentials?
- Address spoofing, where a sender's identifier is quietly forged
- Traffic eavesdropping, where a silent listener logs an exchange
- Credential reuse, where an outsider arrives using valid secrets
- Session hijacking, where an existing token is silently captured
Correct answer: Credential reuse, where an outsider arrives using valid secrets
Here the attacker presents credentials that genuinely belong to a real account, obtained from a breach dump, a phishing capture or a password reused across services, so authentication succeeds and the access looks ordinary in the logs. Forging a sender's identifier misrepresents where traffic comes from and proves nothing about identity to an application. A silent listener that logs an exchange is passive and gains no access by itself. Capturing an existing token bypasses authentication rather than completing it with the user's own secrets.
- Which attack aims to make a network resource unavailable to its intended users by disrupting the services of a host connected to the Internet?
- Phishing attack, which tempts a user into surrendering secrets
- On-path attack, which forwards each exchange while altering it
- Denial of service attack, which overwhelms a responding server
- Injection attack, which smuggles commands into a running query
Correct answer: Denial of service attack, which overwhelms a responding server
The aim is to consume something finite on the target, whether bandwidth, connection state or processing time, until requests from real users can no longer be served; the resource is made unavailable rather than read or altered. Tempting a user into surrendering secrets targets the person and leaves the service running normally. Forwarding each exchange while altering it actually depends on the service staying reachable. Smuggling commands into a running query attacks the data the application handles, not its capacity to answer.
- What type of penetration testing technique involves the exploitation of vulnerabilities in communication protocols?
- Poisoning the exchanges machines rely on to locate each other
- Bending an application's own logic through a typed user input
- Breaking a cipher by attacking the mathematics under its hood
- Walking a directory tree to retrieve records outside its root
Correct answer: Poisoning the exchanges machines rely on to locate each other
Attacks in this family abuse the rules of the conversation itself: machines that broadcast to locate one another accept whichever answer arrives first, so an attacker who answers falsely is believed and traffic is redirected without any software defect being exploited. Bending an application's logic through typed input operates at the application layer, above the protocol. Attacking the mathematics beneath a cipher is a cryptographic attack. Walking a directory tree to retrieve records outside the root abuses path handling inside one web application.
- In penetration testing, what is the primary objective of 'war driving'?
- To measure how strong a system's deployed encryption really is
- To find the wireless networks broadcasting across a whole area
- To eavesdrop on the calls crossing a mobile operator's network
- To rate the guard coverage protecting the entire main building
Correct answer: To find the wireless networks broadcasting across a whole area
The activity is survey work: moving through an area with a receiver and recording the access points detected, together with their names, channels and protection settings, to build a picture of the wireless footprint in and around a target. Measuring how strong the deployed encryption is comes later, once a specific network has been chosen and traffic captured. Eavesdropping on calls crossing a mobile operator's network is a different medium entirely. Rating the guard coverage around a building is a physical assessment that involves no radio survey.
- What is the primary purpose of ARP spoofing in a network?
- To scramble packets so one machine's client alone reads these
- To maintain a concealed channel for returning to this address
- To overload a network with more incoming frames than expected
- To pull a whole segment's traffic through the testing station
Correct answer: To pull a whole segment's traffic through the testing station
By answering address-resolution requests with its own hardware address, the attacking host convinces its neighbours that it is the gateway or peer they were looking for, so their frames are delivered to it first and can be read, changed or passed on. Scrambling packets so only the intended receiver can read them describes encryption, which protects traffic instead of diverting it. Maintaining a concealed channel for later return is persistence. Overloading a network with incoming frames denies service and destroys the quiet position that interception depends on.
- In the context of penetration testing, what is a 'rainbow table' used for?
- To unwrap the traffic protected by a negotiated session key
- To match stolen hashes against a precomputed list of values
- To assemble a picture of how one network's segments connect
- To prioritize the flaws found by an automated scan platform
Correct answer: To match stolen hashes against a precomputed list of values
The structure is a stored, precomputed mapping between candidate passwords and their digests, built once and reused, so recovering a password becomes a lookup rather than a fresh computation for every guess; the trade is disk space for time, and a per-account random value defeats it. Unwrapping traffic protected by a negotiated session key is a transport problem. Assembling a picture of how segments connect is topology mapping. Prioritizing flaws found by a scanner is triage of scan output, and none of the three involve stored digests.
- Which tool is primarily used for automated vulnerability scanning in web applications?
- Wireshark, which builds whole streams from a session's frames
- Nmap, which discovers which listening ports a machine exposes
- Metasploit, which delivers prepared exploit modules to a host
- Burp Suite, which intercepts then audits a website's requests
Correct answer: Burp Suite, which intercepts then audits a website's requests
An intercepting proxy sits between the browser and the application, captures every request, and can then replay and mutate those requests automatically to test each parameter for injection, access-control and logic flaws, which is what automated web application scanning means in practice. A packet analyser rebuilds streams from frames that already exist and issues no requests of its own. A port scanner reports which services are exposed, not how an application handles input. An exploit framework delivers prepared modules for flaws that are already known.
- What is the main purpose of the tool 'Sqlmap' in penetration testing?
- Reads frames off a host's interface to rebuild conversations
- Recovers passwords from captured hashes with a prepared list
- Examines each parameter for weaknesses in a target's queries
- Surveys the wireless channels for access points within range
Correct answer: Examines each parameter for weaknesses in a target's queries
The tool automates the whole database-injection workflow: it varies each parameter in turn, compares the responses for evidence that input is reaching the query, then fingerprints the back end and extracts data once a weakness is confirmed. Reading frames off an interface to rebuild conversations is packet analysis. Recovering passwords from captured hashes with a prepared list is offline cracking. Surveying wireless channels for access points is a radio survey. None of those three look at how a site assembles its queries.
- Which tool is best suited for performing a password cracking attack on a WPA2 wireless network?
- Aircrack-ng, which pulls keys from a captured radio handshake
- Nessus, which reports known flaws found by credentialed scans
- John the Ripper, which attacks hashes retrieved from archives
- Cain & Abel, which gathers credentials from poisoned segments
Correct answer: Aircrack-ng, which pulls keys from a captured radio handshake
Recovering the passphrase for this kind of protected wireless network is an offline job against a captured association exchange: the suite named here captures that exchange, deauthenticating a client if necessary to force one, then tests candidate passphrases against it. A vulnerability scanner reports known flaws and cracks nothing. A general password cracker works on digests already retrieved from storage and cannot capture the wireless exchange in the first place. A segment-poisoning credential collector gathers what crosses a wired network, not what is carried over radio.
- In penetration testing, which tool is used for comprehensive network discovery and security auditing?
- Nmap, which sweeps address ranges to chart listening systems
- Hydra, which guesses credentials against a web login service
- Tcpdump, which captures raw frames arriving on one interface
- OWASP ZAP, which examines running websites through its proxy
Correct answer: Nmap, which sweeps address ranges to chart listening systems
The scanner named here is the general-purpose discovery tool: it sweeps address ranges, establishes which hosts are up, enumerates the services listening on them and fingerprints operating systems and versions, producing the inventory every later phase is built on. A credential guesser attacks one authentication service and discovers nothing about the network. A packet capture tool records what arrives on an interface but sends no probes of its own. A web proxy scanner examines one site's application layer rather than the hosts and services across a network.
- What is the primary use of the tool 'Nikto' in penetration testing?
- Guesses login credentials against a remote service quickly
- Examines one web server for outdated vulnerable components
- Strips transport protection from a captured session record
- Rebuilds packet capture into legible protocol data streams
Correct answer: Examines one web server for outdated vulnerable components
This scanner works from a large signature list of server-side items, requesting each in turn and reporting what it finds: leftover scripts, default content, revealing headers and server software carrying known problems. It is deliberately loud and fast, and it targets the server rather than the application's own logic. Guessing login credentials quickly is an online brute-force attack. Stripping transport protection from a captured record is a cryptographic attack. Rebuilding a capture into legible streams is packet analysis, which sends no requests at all.
- Which tool is primarily used for fuzzing in software testing to discover coding errors and security loopholes?
- Wireshark, which turns captured frames into a full protocol view
- Metasploit, which fires a prepared exploit payload at the target
- GDB, which crawls through live code to investigate its registers
- Peach, which drives malformed inputs into one program under test
Correct answer: Peach, which drives malformed inputs into one program under test
The framework named here is built for input generation: a model of the expected format is defined, the framework mutates it into large numbers of malformed cases, feeds them to the target and records the inputs that produce a crash or a hang. A packet decoder turns frames that already exist into a readable view. An exploit framework fires prepared code at flaws that are already known. A debugger crawls through live code and is used alongside a fuzzer to explain why a case crashed, but it generates no test input itself.
- In the context of penetration testing, what is the main function of the 'BeEF' framework?
- Recovering the keys protecting a locked archive kept offline
- Firing service exploits at hosts reachable over the internet
- Hooking browsers to run commands against a visitor's session
- Organizing those pretexts used in a client's social campaign
Correct answer: Hooking browsers to run commands against a visitor's session
The framework works on the client side: a small script loaded by a page hooks the visiting browser, and from then on the tester issues commands that run inside it, fingerprinting the browser, reaching internal resources it can see and abusing whatever the visitor is signed in to. Recovering the keys protecting an offline archive is cryptographic cracking. Firing service exploits at internet-reachable hosts is server-side exploitation. Organizing pretexts for a social campaign prepares the human approach rather than driving a browser that is already hooked.
- Which tool is used for automated exploitation and payload delivery in penetration testing?
- Metasploit
- BloodHound
- Volatility
- Enum4linux
Correct answer: Metasploit
Metasploit is built around a module library of exploits paired with a payload builder and a listener, so a tester selects a target weakness, attaches a staged or stageless payload and lets the framework handle delivery and session setup. BloodHound ingests directory data and graphs the relationships inside it to reveal attack paths; it maps a route but launches nothing. Volatility parses a captured memory image offline, which is analysis of a system that has already been compromised. Enum4linux queries SMB and NetBIOS services for users, shares and password policy, which is enumeration that precedes exploitation rather than exploitation itself.
- What is the primary purpose of the tool 'Yersinia' in network protocol penetration testing?
- Capturing traffic in the mirrored network trunk
- Cracking keys taken from the wireless handshake
- Attacking weaknesses in the layer two protocols
- Mapping reachable hosts across a routed segment
Correct answer: Attacking weaknesses in the layer two protocols
Yersinia is a layer two attack tool: it crafts traffic for spanning tree, dynamic trunking, CDP, VLAN tagging, HSRP and DHCP so a tester can force a root bridge election, negotiate a trunk or drain an address pool. Taking a copy of traffic from a mirrored trunk is passive collection, not an attack on the protocols that move the frames. Recovering a wireless key from a captured handshake is offline cracking of a pre-shared secret and belongs to a different tool class. Sweeping a subnet for reachable addresses is layer three discovery and reveals nothing about how the switching fabric itself behaves.
- Which tool is used for testing and exploiting web application Cross-Site Scripting (XSS) vulnerabilities?
Correct answer: XSSer
XSSer automates the detection and exploitation of cross-site scripting by injecting encoded vectors into each parameter, following the response and reporting which vectors actually execute in the page. Nikto fingerprints a web server and flags dangerous files, stale software and weak configuration entries, but it never confirms script injection. Hydra performs online password guessing against network login services. Scapy assembles and sends arbitrary packets so a tester can probe how a stack handles malformed traffic, which is protocol work far below the application layer where this class of flaw lives.
- Which tool is best suited for conducting a Man-in-the-Middle (MitM) attack in a penetration testing scenario?
- Kerbrute
- Dnsrecon
- Skipfish
- Ettercap
Correct answer: Ettercap
Ettercap is purpose-built for on-path work: it poisons the ARP caches of two hosts on the same segment so their traffic is relayed through the tester, then applies filters, forces protocol downgrades and records the intercepted sessions. Kerbrute checks Kerberos account names and sprays candidate passwords at a domain controller, which never moves anyone's traffic. Dnsrecon queries name servers for records and attempts zone transfers. Skipfish crawls an application and reports issues in the responses it receives. None of those three ever places the tester between two communicating parties.
- What is the primary function of the tool 'Gobuster' in penetration testing?
- Recovering account passwords from a captured hash store
- Charting nearby access points from their beacon signals
- Rebuilding user sessions inside a stored packet capture
- Discovering unlinked directories on a target web server
Correct answer: Discovering unlinked directories on a target web server
Gobuster works from a wordlist against a live web service, requesting candidate names and reading the status codes that come back, so it surfaces directories, files, virtual hosts and DNS names that no link on the site points to. Turning a captured hash store back into passwords is offline cracking and needs no web service at all. Charting access points from their beacons is wireless survey work performed with a radio in monitor mode. Reassembling sessions inside a saved capture is protocol analysis of traffic already recorded, which discovers nothing new on the server.
- Which tool is primarily used for sniffing and analyzing HTTP/HTTPS traffic in a penetration testing exercise?
- Dirbuster
- Wireshark
- Sublist3r
- Slowloris
Correct answer: Wireshark
Wireshark captures live traffic from an interface and decodes it protocol by protocol, so a tester can follow an HTTP conversation, read headers and bodies, and inspect the TLS handshake that precedes an HTTPS session. Dirbuster guesses directory and file names against a web server. Sublist3r collects subdomain names for a target from public sources. Slowloris holds many half-finished requests open to exhaust a web server's connection pool. Each of those three generates or gathers something for its own purpose, but none of them decodes what is on the wire.
- In penetration testing, which tool is used for exploiting vulnerabilities in VoIP (Voice over IP) systems?
- Enum4linux
- Metagoofil
- SIPVicious
- EyeWitness
Correct answer: SIPVicious
SIPVicious is the standard audit suite for SIP telephony: it sweeps a range for devices that answer SIP, enumerates the valid extensions and then guesses credentials on the extensions it finds, which is exactly the assessment path for a voice deployment. Enum4linux pulls users, shares and policy from SMB and NetBIOS services on Windows hosts. Metagoofil harvests documents published by a domain and strips their metadata for names and paths. EyeWitness visits a list of web services and stores a screenshot of each one. None of those three speaks the signalling protocol that carries a call.
- What is the main use of the 'Hashcat' tool in penetration testing?
- Recovering account passwords by attacking a captured hash
- Discovering host names advertised beneath a target domain
- Auditing wireless encryption using a monitor mode capture
- Reviewing shipped binaries for unsafe function call sites
Correct answer: Recovering account passwords by attacking a captured hash
Hashcat is a cracking engine: it takes hashes already obtained from a target, throws dictionary, rule, mask or brute force candidates at them on the GPU and reports the plaintext for every hash it solves. It queries no name servers, so building out the subdomains beneath a target is the job of a reconnaissance tool. It does not drive a radio or handle a live wireless capture, which needs an adapter in monitor mode and a suite built for 802.11. It never parses program code either, so hunting unsafe calls in a shipped binary is static analysis rather than password recovery.
- Which tool is used for automated SSL/TLS security testing and identifying vulnerabilities like Heartbleed and POODLE in a target system?
Correct answer: SSLyze
SSLyze connects to a service and interrogates its TLS stack directly, listing the protocol versions and cipher suites on offer, checking certificate validity and testing for the specific defects that carry names such as Heartbleed and POODLE. Wapiti crawls a web application and injects test values to find flaws in application code, not in the transport underneath it. Rubeus requests, forges and renews Kerberos tickets inside a Windows domain. Kismet listens passively on radio channels to map wireless networks and their clients. Neither of those last two touches a TLS negotiation at all.
- In penetration testing, what is the primary function of the tool 'Mimikatz'?
- Charting attack paths between accounts in a domain
- Carving deleted documents from a raw storage image
- Replaying recorded frames to test a network switch
- Reading credential material out of a local process
Correct answer: Reading credential material out of a local process
Mimikatz runs on a compromised Windows host with elevated rights and reads secrets straight out of the memory of the local security subsystem, returning plaintext passwords, NTLM hashes, PINs and Kerberos tickets that can then be reused elsewhere. Charting a route between accounts to reach a privileged group is graph analysis performed over collected directory data. Carving deleted documents out of a storage image is disk forensics and touches no running process. Replaying recorded frames at a switch probes network configuration rather than the credential store held on a host.
- Which tool is specifically designed for testing the security of wireless networks?
- Airgeddon
- Airmon-ng
- PowerView
- GoWitness
Correct answer: Airgeddon
Airgeddon wraps a whole wireless assessment into one workflow: it scans for networks, captures handshakes, sends deauthentication, drives offline cracking and stands up rogue access point attacks, so it is the entry built to assess wireless security from end to end. Airmon-ng only places an adapter into monitor mode and clears interfering processes; it performs no assessment of its own. PowerView enumerates users, groups and trusts inside a Windows domain from a shell. GoWitness fetches a list of web services and saves a screenshot of each response.
- What is the primary use of the 'sqlninja' tool in penetration testing?
- Recovering Oracle credential hashes from a backup
- Fingerprinting the MySQL instance behind a portal
- Attacking injection flaws in Microsoft SQL Server
- Reading Postgres traffic for credentials in clear
Correct answer: Attacking injection flaws in Microsoft SQL Server
Sqlninja is written specifically for Microsoft SQL Server sitting behind a vulnerable web application: it confirms the injection point, fingerprints the backend, escalates the database account and works toward command execution on the host. Cracking credential hashes pulled from an Oracle backup is an offline password task that needs no injection point at all. Fingerprinting the engine behind a portal is reconnaissance that stops before any flaw is used. Reading credentials out of database traffic on the wire is passive interception, which again involves no injection.
- In penetration testing, which tool is best suited for capturing and analyzing Bluetooth communication?
- EAPHammer
- Airtun-ng
- Ubertooth
- Smbclient
Correct answer: Ubertooth
Ubertooth One is dedicated Bluetooth hardware with an open firmware stack: it follows a piconet across its hopping pattern, captures baseband packets and hands them to analysis tools, which is what assessing a Bluetooth link requires. EAPHammer stands up rogue access points that attack enterprise Wi-Fi authentication over 802.11. Airtun-ng creates a virtual tunnel interface for injecting into and decrypting an 802.11 network already captured. Smbclient is a command line client for Windows file shares. Only one of the four listens on the Bluetooth radio at all.
- In penetration testing reports, what is the primary purpose of an executive summary?
- To give leadership a short account of the business risk
- To record each request the tester issued against a host
- To capture raw tool output for a later technical review
- To restate the scope limits set before the work started
Correct answer: To give leadership a short account of the business risk
An executive summary is written for the readers who set budgets, not for the people who apply fixes: it states what a hostile party could achieve, what that would cost the business and how urgent the response is, in a page of plain language. A log of the requests issued during the engagement belongs in the attack narrative, where a reader follows the steps in order. Raw tool output belongs in an appendix as supporting evidence. A restatement of the boundaries belongs in the scope section. All three are genuine parts of the document, just not this part.
- When communicating penetration testing results, which factor is most important for ensuring that the findings are actionable?
- A tally of the flaws found on each live host
- A record of the tools run in each test phase
- A copy of the raw text output from each scan
- A note of the fix steps on each named defect
Correct answer: A note of the fix steps on each named defect
A finding becomes actionable when the reader is told what to change and in what order, so a concrete remediation instruction per issue is the element that turns a report into work a team can schedule. A count of issues per host sizes the problem but tells nobody what to do about it. A record of which tools ran supports repeatability and belongs with the methodology. Raw output is evidence that a finding is real, and the reader still has to decide what to do next after reading it. Only one entry names the change itself.
- Which element is essential to include in a penetration testing report to aid in prioritizing remediation efforts?
- The count of hosts probed at each test stage
- The severity score put on each of the faults
- The list of tools aimed at each named target
- The clock time when each check was first run
Correct answer: The severity score put on each of the faults
Remediation capacity is finite, so the report has to rank the work: a severity or risk score per issue, derived from impact and from how easily the issue can be reached, is what lets a team fix the dangerous items first. The number of hosts touched at each stage measures coverage of the engagement, not the danger of any single issue. A list of tools aimed at each target supports repeatability and says nothing about consequence. Timestamps let a defender line findings up against their own logs. None of those three orders the work by how much harm an issue can do.
- In the context of penetration testing, what is the primary purpose of a post-engagement cleanup report?
- To verify the tester cleared out the files left behind
- To detail the hours the tester spent within each phase
- To record the sign-off the client gave the lead tester
- To list the exploits the tester used against each host
Correct answer: To verify the tester cleared out the files left behind
Cleanup and restoration is the last technical obligation of an engagement: shells, scheduled tasks, uploaded binaries, added accounts and altered settings all have to come off the estate, and the cleanup record is the document that states each one was removed and the host returned to its prior state. Hours per phase is billing and project data. A countersigned acceptance closes the commercial side of the work. A list of the exploits used belongs to the attack narrative, which explains how access was gained rather than proving that nothing was left behind.
- What is the most appropriate action when a penetration tester discovers sensitive data, such as personally identifiable information (PII), during a test?
- Copy the data into the evidence pack for the report
- Widen the sweep to measure how much data is present
- Destroy the data in place so the exposure is closed
- Warn the client contact at once of the exposed data
Correct answer: Warn the client contact at once of the exposed data
Personal data found in scope is a live exposure, and the rules of engagement almost always make it a stop-and-notify event: the tester alerts the named point of contact straight away, records only what is needed to prove the exposure exists and handles nothing further without direction. Pulling copies into an evidence pack multiplies the exposure and moves regulated records onto tester-controlled storage. Probing further to size the store is unauthorised collection dressed up as diligence. Deleting or overwriting the records in place is destructive action on production data, which the tester has no authority to take and which wrecks the client's own evidence.
- Which of the following best describes the purpose of including threat modeling in a penetration testing report?
- To time-box the hours spent on each phase of the audit
- To capture the entire output of a scanner in the sweep
- To map the route of a real attacker in the environment
- To log the version number for each tool the tester ran
Correct answer: To map the route of a real attacker in the environment
Threat modelling turns a list of separate weaknesses into a picture of what an adversary would actually do with them: which actor would care, which entry point they would take, and how individual issues combine into a route to something valuable. Time-boxing each phase is planning and effort control agreed before the work begins. Raw scanner output is appendix evidence. Tool versions support repeatability, so another tester can reproduce the result later. None of those three says anything about the attacker on the other side of the findings.
- What is the primary reason for including both false positives and false negatives in a penetration testing report?
- To give the client a count of issues per severity
- To mark the full reach of the chosen probe method
- To prove the scan engine was current at test time
- To trace each finding back to its source tool run
Correct answer: To mark the full reach of the chosen probe method
Naming the results that proved unfounded, and the coverage gaps where an issue could have been missed, tells the reader how far the assessment actually reached: automated checks over-report and under-report, and a report that hides both invites a false sense of assurance. A severity breakdown quantifies what was found and says nothing about what was not. Showing that the engine was up to date supports quality, but a current engine still misses logic flaws. Traceability links a result to the run that produced it, which is provenance rather than the limit of the method.
- Why is it important to include a methodology section in a penetration testing report?
- To give the board a short summary of the business impact
- To lay out in order each separate action the tester took
- To keep the raw console output of each finished scan run
- To state the fixes the client should apply as a priority
Correct answer: To lay out in order each separate action the tester took
The methodology section exists so the work can be judged and repeated: it records the standard followed, the phases worked through, the techniques applied at each phase and the order in which they ran, which is what lets a second tester or an auditor reproduce the same result. A short statement of business impact is the executive summary's job. Raw console output belongs in an appendix as evidence. Prioritised fixes belong with the findings, where each issue carries its own remediation guidance. Only one of the four describes how the engagement was actually conducted.
- When a penetration tester finds a previously unknown vulnerability, what is the best practice for reporting it?
- Open a joint disclosure path with the named vendor
- Publish the complete detail on a public feed today
- Include the finding in the client report as before
- Forward the matter to a general support desk queue
Correct answer: Open a joint disclosure path with the named vendor
A previously unknown flaw affects everyone running that software, so the accepted route is coordinated disclosure: the tester informs the client, works with them to reach the vendor, and gives the vendor a defined window to produce a fix before any detail becomes public. Releasing the detail immediately leaves every other user exposed while no patch exists. Writing it up for one client alone leaves the vendor unaware and the flaw unfixed everywhere else. Dropping it into a general support queue neither reaches the people who maintain the code nor keeps the detail restricted.
- What is a key element to include in a penetration testing report to facilitate effective communication with non-technical stakeholders?
- A summary of the open services found on each host
- A list of the exploit modules run against the app
- A copy of the scanner output for each test window
- A chart of the risk drawn in plain business terms
Correct answer: A chart of the risk drawn in plain business terms
Executives, legal staff and business owners read a report to decide where money and attention go, and a well-built visual carries relative risk, trend and concentration in one glance where paragraphs of technical prose would not. A service summary is raw inventory data with no risk framing at all. A list of the modules used is technical provenance that means nothing to a non-technical reader. Scanner output per window is evidence for the appendix. All three belong in the report, but none of them communicates severity to a lay audience.
- What is the primary purpose of including risk impact assessments in a penetration testing report?
- To name the tools run on each in-scope client host
- To give the client a bill for the whole engagement
- To show the client the damage from each open fault
- To record the date the client first saw each issue
Correct answer: To show the client the damage from each open fault
Risk impact analysis answers the question the client actually cares about: if this weakness were used against us, what breaks, what data moves, what stops trading and what regulatory exposure follows. That business consequence, paired with likelihood, is what drives sequencing and spending. A list of the tools pointed at each host is methodology detail. A cost figure for the engagement is commercial reporting. A record of when each issue was first shown to the client is a disclosure timeline. None of those three describes the damage a weakness could cause.
- In penetration testing, why is it important to communicate interim findings to the client?
- To inform the client the engagement is a third done
- To hand the client raw scanner output as it appears
- To let the client fix a critical flaw straight away
- To show the client the tester kept inside set scope
Correct answer: To let the client fix a critical flaw straight away
Some findings are too dangerous to sit in a draft for a fortnight: an exposed administrative interface, a live credential leak or a system already showing signs of compromise is raised the moment it is confirmed, so the client can shut the exposure while the engagement continues. Progress updates are project management and can wait for the weekly call. Handing over raw output as it appears buries the client in unvalidated noise, including results that later prove unfounded. Confirming the work stayed inside the agreed boundary is a closing statement, not an urgent one.
- What is the most effective way to present complex technical vulnerabilities to a non-technical audience in a penetration test report?
- Quoting the raw console output beside each entry
- Recasting the finding as a simple business story
- Ranking the results by the port numbers involved
- Grouping the issues around their source scan run
Correct answer: Recasting the finding as a simple business story
A non-technical reader needs the consequence, not the mechanism, so the effective move is to restate each issue as what an attacker gains and what the business loses, using a familiar comparison in place of protocol detail while the technical body carries the evidence. Quoting raw output next to each entry adds exactly the material that reader cannot parse. Ordering by port number is an arbitrary technical sort that hides severity. Grouping by the scan that produced a result serves the tester's own workflow rather than the audience being addressed.
- Why is it important to include mitigation strategies for each vulnerability in a penetration test report?
- To give the client a procedure to close each flaw
- To show the client where the weak spots are found
- To flag for the client the hosts beyond set scope
- To record for the client the times of each action
Correct answer: To give the client a procedure to close each flaw
A finding without a fix leaves the client holding a problem and no route out of it, so each issue carries remediation guidance: the specific change, any compensating control that buys time and enough detail for an engineer to act without a second call. Naming where a weakness sits locates the problem but stops short of the cure. Flagging the hosts left outside the boundary is a coverage caveat. A timeline of tester actions helps a defender correlate their own logs. None of those three tells the client what to change.
- In a penetration testing report, what is the significance of categorizing vulnerabilities by exploitability?
- To show the site owner the issues already put right
- To note the tool chain used against each named host
- To group the findings by the business unit they hit
- To order the faults by the effort each attack takes
Correct answer: To order the faults by the effort each attack takes
Exploitability describes how much an attacker needs in order to use a weakness: network reach, privileges already held, user interaction, and whether working code is public. Ordering on that axis puts the issues that need no credentials and no user action at the top of the queue, which is where limited remediation effort belongs. A record of what has already been fixed measures progress after the fact. A record of the tool chain supports repeatability. Grouping by business unit routes the work to owners. None of those three ranks anything by ease of attack.
- How should a penetration tester handle the discovery of illegal content during a test?
- Log the item then finish the whole job as planned
- Copy the item into a secure store for later study
- Wipe the item from the host to limit the exposure
- Halt the test then flag the item to legal counsel
Correct answer: Halt the test then flag the item to legal counsel
Material of this kind moves the situation out of the engagement and into a legal process, so the tester stops work on that system, preserves the state as found, touches nothing further and escalates through the route the rules of engagement define, which normally reaches counsel and law enforcement rather than the day-to-day technical contact. Carrying on and writing it up at the end delays a mandatory notification. Copying it to tester-controlled storage risks possession of the material itself. Deleting it from the host destroys evidence in a matter the client does not control.
- What is a key reason for including both qualitative and quantitative data in a penetration testing report?
- To prove the scan tool licenses were still valid
- To assign each server into its own risk category
- To pair hard numbers with a reasoned expert view
- To commit the client to a strict repair deadline
Correct answer: To pair hard numbers with a reasoned expert view
Counts, scores and coverage figures show scale and support comparison over time, while written judgement explains what the figures mean in this environment, which controls already blunt them and which of them the tester considers genuinely dangerous. Presenting both keeps a reader from treating a raw score as the whole story. Evidence that tooling was licensed and current is a quality note. Sorting servers into risk categories is one use of the numbers, not a reason to add narrative. Committing the client to a repair deadline is a remediation undertaking settled after the report lands.
- In the context of penetration testing, what is the primary purpose of a root cause analysis?
- To show the host with the highest flaw count seen
- To trace each flaw back to the practice behind it
- To rank each flaw by the repair effort it demands
- To note the exact time each flaw was first logged
Correct answer: To trace each flaw back to the practice behind it
Root cause analysis looks past the individual finding to the thing that produced it: an unpatched build image, a default configuration shipped estate-wide, an absent code review step or a broken joiner process. Fixing that source removes the whole family of issues instead of the instances this test happened to reach. Naming the host with the most findings ranks symptoms by concentration. Ranking by remediation effort schedules work. Recording when each issue was first observed builds a timeline. None of those three explains why the weakness existed in the first place.
- When a penetration test uncovers a vulnerability in third-party software, what is the best practice for reporting this finding?
- Give the vendor the flaw with a private fix window
- Publish the flaw across a public list the same day
- Keep the flaw in a client report with nothing else
- Classify the flaw as out of scope with no write-up
Correct answer: Give the vendor the flaw with a private fix window
A weakness in someone else's product cannot be fixed by the client, so the finding is routed to the party that maintains the code: the tester tells the client, then coordinates disclosure to the vendor so a patch exists before the detail circulates. Publishing the same day exposes every other organisation running that product while no fix is available. Leaving it in one client report means the vendor never hears of it and the flaw persists everywhere. Calling it out of scope and dropping it abandons a real risk the client is carrying today.
- What is the importance of including a revision history in a penetration testing report?
- To show the text changes for each report draft issued
- To record the people cleared to read the report early
- To set the storage period of the finished report file
- To store the raw evidence for each report claim filed
Correct answer: To show the text changes for each report draft issued
A test report is a controlled document that usually goes through a draft, a client review and a final release, sometimes with a retest addendum, so the revision table records version, date, author and what changed, which lets any reader tell whether the copy in front of them is the current one. A distribution list controls who may hold the document. A retention period governs how long it is kept before disposal. Supporting evidence sits in the appendices. Only the revision table tracks the document's own history.
- After gaining a foothold, a penetration tester creates a Windows scheduled task that launches a payload at logon. What post-exploitation objective does this support?
- Network discovery
- Persistent access
- Defensive evasion
- Credential replay
Correct answer: Persistent access
A scheduled task that fires a payload at logon re-establishes the tester's channel every time the host boots or a user signs in, which is the definition of persistence: keeping access without having to exploit the original weakness again. Discovery maps hosts, services and shares once access exists and adds nothing to survivability. Evasion is about avoiding detection by defensive tooling, which a task entry does not achieve. Reusing captured credentials moves the tester sideways to other systems. Any of the four may follow a foothold, but only one keeps it alive.
- Which of the following is a Linux persistence mechanism analogous to a Windows scheduled task?
- A live tcpdump run
- A name server zone
- A cron table entry
- A single sudo rule
Correct answer: A cron table entry
Cron is the Unix scheduler, so an entry in a crontab runs a chosen command at a fixed interval or at boot, which gives a tester the same automatic re-launch that a Windows scheduled task provides and makes it the direct analogue. A packet capture only records traffic while it is running and survives nothing. A zone on a name server publishes records for a domain and executes no code. A sudo rule grants elevated rights to an account that already exists, which is privilege escalation; it starts nothing on its own.
- A tester adds a new local administrator account on a compromised server to maintain future access. This is BEST categorized as which post-exploitation activity?
- Traffic inspection
- Firewall traversal
- Physical intrusion
- Access persistence
Correct answer: Access persistence
Creating an extra local administrator account gives the tester a credential that survives reboots and the loss of the original shell, so it is a persistence mechanism in the same family as a scheduled task or a start-up service, and it must be recorded for removal during cleanup. Watching traffic is collection. Getting a session out through a filtering device is tunnelling work that carries traffic rather than preserving access. Entering a building targets physical controls. None of those three leaves a way back into the compromised host.
- On a Linux host, a tester finds a binary owned by root with the SUID bit set that can be abused to run commands as root. Which post-exploitation goal does exploiting it achieve?
- Relaying harvested archives off the network
- Wiping forensic artifacts from the logfiles
- Gaining superuser authority over the system
- Charting exposed services across the subnet
Correct answer: Gaining superuser authority over the system
A binary that carries the set-user-ID bit runs with the rights of its owner rather than the rights of the account that launched it, so a root-owned example that can be coerced into running arbitrary instructions hands a low-privileged foothold the ability to act as root. Gaining superuser authority over the system is precisely the post-exploitation objective known as privilege escalation, and permissive sudo rules produce the same outcome by a different route. Moving harvested archives outward is exfiltration, a separate objective concerned with removing data rather than raising rights. Erasing forensic artifacts is anti-forensic cleanup performed after an objective is already met and it grants no new permission. Charting exposed services belongs to reconnaissance, which happens before any access exists and never changes an account's privilege level.
- On Windows, which tool is most commonly used to dump credentials and extract NTLM hashes or plaintext passwords from the LSASS process?
- Mimikatz, extracting secrets from resident memory
- Responder, seizing digests from broadcast queries
- Hashcat, recovering cleartext from offline values
- Hydra, guessing logins against reachable services
Correct answer: Mimikatz, extracting secrets from resident memory
Mimikatz reads the Local Security Authority Subsystem Service while that process is resident in memory, extracting secrets that the operating system caches there: NTLM hashes, Kerberos tickets and, on legacy configurations, plaintext credentials. Those recovered secrets are what make pass-the-hash and pass-the-ticket movement possible afterwards. Responder is a poisoner that answers broadcast name-resolution queries and seizes authentication digests off the wire, so it never inspects a running process. Hashcat is an offline recovery engine that turns already-captured values back into cleartext and has no collection capability of its own. Hydra performs online guessing against reachable network services, producing a valid login rather than a memory dump.
- A tester uses a captured NTLM hash to authenticate to other systems without ever cracking the plaintext password. What technique is this?
- Kerberoasting, cracking tickets from service accounts
- Password spraying, attempting one secret network-wide
- Credential stuffing, reusing breached account details
- Pass-the-hash, authenticating with an uncracked value
Correct answer: Pass-the-hash, authenticating with an uncracked value
Windows NTLM authentication treats the stored hash itself as the proof of identity, so a tester holding that hash can present it directly. Pass-the-hash is exactly this: authenticating with an uncracked value, never recovering the underlying password, which makes it a fast route to lateral movement wherever the same local or domain credential is reused. Kerberoasting requests service tickets tied to service principal names and then cracks them offline, so it depends on the very cracking step the scenario rules out. Password spraying attempts one likely secret against many accounts and is an online guessing attack against the plaintext space. Credential stuffing reuses details harvested from an unrelated breach, which requires knowing the password rather than only its digest.
- Which tool lets a tester execute commands on a remote Windows host over SMB using legitimate administrative protocols, making it a popular lateral-movement utility?
- BloodHound, graphing trust paths across domains
- PsExec, spawning services through hidden shares
- Rubeus, requesting tickets from Kerberos realms
- Mimikatz, harvesting secrets from cached logons
Correct answer: PsExec, spawning services through hidden shares
PsExec works by copying a helper binary to an administrative share and then spawning services through those hidden shares over Server Message Block, using functionality Windows ships for legitimate remote administration. That is why it, and the Impacket equivalents, became a standard lateral-movement utility once valid credentials or a usable hash are in hand. BloodHound is a collector and analysis tool that graphs trust and permission paths inside Active Directory, but it executes nothing on a target. Rubeus manipulates Kerberos material, requesting and abusing tickets, which yields authentication artifacts rather than remote command execution. Mimikatz harvests secrets from cached logon sessions in memory and likewise stops at credential recovery.
- A tester wants to run commands on a remote Windows machine using WMI rather than dropping a service binary, for a stealthier approach. Which protocol/mechanism is being leveraged?
- Server Message Block privileged administrative shares
- Windows Management Instrumentation object class calls
- Remote Desktop Protocol interactive terminal sessions
- Background Intelligent Transfer Service download jobs
Correct answer: Windows Management Instrumentation object class calls
Windows Management Instrumentation exposes a management layer whose object class calls can create a process on a remote machine without first writing and registering a service binary, which is why wmiexec-style tooling is treated as quieter than the service-creation route. The same layer also answers inventory queries, so it doubles as an enumeration surface. Server Message Block privileged administrative shares are the path a service-dropping utility uses, and that is the noisier technique the scenario is deliberately avoiding. Remote Desktop Protocol grants an interactive graphical logon, which is highly visible and does not run a single command unattended. The Background Intelligent Transfer Service moves files as scheduled jobs and is a persistence or download mechanism, not a command execution interface.
- A tester compromises a dual-homed host and uses it to reach an internal subnet that is not directly accessible from the attacker's machine. This technique is called:
- Banner grabbing, reading advertised service labels
- Packet sniffing, recording cleartext subnet frames
- Protocol fuzzing, sending mutated input repeatedly
- Network pivoting, rerouting sessions via footholds
Correct answer: Network pivoting, rerouting sessions via footholds
Network pivoting means rerouting sessions via footholds already held, so a machine that sits on two segments becomes the relay that carries a tester's traffic into address space the attacking workstation cannot route to directly. A multihomed victim is the classic candidate because it already has an interface in each segment. Banner grabbing only reads the labels a listening service advertises about itself, which identifies software versions and opens no new path. Packet sniffing records frames that cross a segment the tester can already observe, so it never extends reach beyond that segment. Protocol fuzzing repeatedly submits mutated input to provoke a crash, a vulnerability-discovery activity that has nothing to do with routing into an unreachable range.
- Which tool is commonly used to route a tester's traffic through a chain of proxies or a compromised host to reach otherwise unreachable internal hosts?
- Proxychains, forcing connections along relay hops
- Ettercap, poisoning bindings on adjacent segments
- Nessus, auditing systems for unpatched components
- Nikto, probing webservers for weak configurations
Correct answer: Proxychains, forcing connections along relay hops
Proxychains sits in front of an ordinary client and forces its outbound connections along relay hops, normally a SOCKS listener opened by a tunnel or by a command-and-control session on a machine the tester already owns. Because the redirection happens below the application, unmodified scanners and clients suddenly reach address space that is only routable from that machine. Ettercap poisons bindings on a segment the tester can already reach, which intercepts traffic rather than extending reach. Nessus audits reachable systems for unpatched components and reports findings, offering no traffic redirection at all. Nikto examines web servers for weak or dangerous configuration, again limited to targets that are already routable.
- A tester sets up 'ssh -D 1080 user@pivot' to create a SOCKS proxy through a compromised jump host. What is the purpose of this command?
- Forwarding a graphical display to the workstation
- Reusing credential agents on the downstream hosts
- Providing a dynamic conduit for internal pivoting
- Copying files through the encrypted shell channel
Correct answer: Providing a dynamic conduit for internal pivoting
Dynamic port forwarding turns the client into a SOCKS listener, providing a dynamic conduit for internal pivoting: any tool pointed at that listener has its traffic carried across the existing session and emitted from the jump host, so targets that are only routable from that host become reachable without dropping an implant. Graphical display forwarding is a separate feature that carries an X session back to the tester and moves no arbitrary traffic. Agent forwarding lets keys held locally be reused onward, which is a credential convenience rather than a route into a network. File copying over the same encrypted transport moves data between two endpoints that can already speak to each other.
- Which of the following is a command-and-control (C2) framework a tester might use to manage compromised hosts during post-exploitation?
- Nessus, ranking discovered weaknesses by criticality
- Wireshark, decoding captured bytes for investigators
- Impacket, scripting logon exchanges against services
- Metasploit, tasking implants across breached servers
Correct answer: Metasploit, tasking implants across breached servers
Metasploit is the framework in this list built for tasking implants across breached servers: it holds sessions open, issues follow-up jobs to them, and carries post-exploitation modules for harvesting, migration and onward movement, which is what a command-and-control framework must do. Cobalt Strike, Sliver, Covenant and Empire occupy the same role. Nessus is a vulnerability management platform that ranks findings by criticality and never holds an interactive session. Wireshark decodes traffic that has already been captured and issues nothing to a target. Impacket is a protocol library whose scripts drive individual authentication and remote-execution exchanges, but it maintains no persistent tasking channel over a fleet of hosts.
- A tester encodes stolen data inside DNS queries to slip it past egress filtering. This is an example of:
- A staging step compressing archives locally
- A covert channel smuggling secrets outbound
- A persistence method outlasting each reboot
- A pivot relay reaching isolated subnetworks
Correct answer: A covert channel smuggling secrets outbound
Hiding information inside name-resolution requests is a covert channel smuggling secrets outbound: the traffic is shaped like an ordinary, universally permitted service, so a control that inspects destination and protocol sees nothing unusual while data leaves the estate. The same idea drives tunnels built over ICMP or over ordinary web traffic. A staging step assembles or compresses material on the host and stops before anything leaves it. A persistence method exists to regain access after a restart and moves no data at all. A pivot relay extends routing into address space that the tester cannot otherwise reach, which is a movement technique rather than a way out through an egress control.
- Which technique hides data within another file (such as embedding it in an image) to avoid detection during exfiltration?
- Compression, reducing a dataset's transfer volume
- Encoding, altering byte patterns against scanners
- Steganography, concealing a payload inside images
- Tunneling, transporting a stream within protocols
Correct answer: Steganography, concealing a payload inside images
Steganography is the practice of concealing a payload inside images, audio or document carriers so that the carrier still opens normally and nothing about it advertises the hidden content. That is why it appears in the staging and covert-channel material: inspection sees an ordinary picture. Compression only reduces how much has to move and leaves the content perfectly recoverable by anyone who unpacks it. Encoding rewrites byte patterns to slip past signature matching, but the result is still an obvious blob rather than an innocuous carrier file. Tunneling carries a stream inside a permitted protocol, which conceals traffic in transit rather than hiding one file inside another.
- Before exfiltrating a large dataset, a tester compresses and encrypts it. What is the primary benefit of this staging step?
- It compacts the payload into protected ciphertext
- It scatters the bundle across separate transports
- It overwrites the modification timestamps on disk
- It preserves the deliverable evidence for reports
Correct answer: It compacts the payload into protected ciphertext
Compressing and then encrypting a collection before it moves compacts the payload into protected ciphertext, which delivers both staging benefits at once: fewer bytes have to cross the wire, so the transfer is quicker and less conspicuous in flow records, and the bytes that do cross are opaque to data-loss-prevention inspection and to anyone reading the capture later. Splitting a bundle across separate transports is a different evasion tactic and is not what compressing or encrypting does. Overwriting modification timestamps is anti-forensic cleanup applied to the file system, unrelated to how much data moves. Preserving evidence for the report is an engagement obligation, not a property produced by packing and encrypting a dataset.
- At the end of an engagement, which cleanup and restoration activity should the penetration tester perform?
- Removing the artifacts introduced across the systems
- Delivering the findings required for the remediation
- Retesting the defects corrected since the assessment
- Rotating the credentials uncovered inside the report
Correct answer: Removing the artifacts introduced across the systems
Cleanup and restoration means removing the artifacts introduced across the systems that were touched: persistence mechanisms, accounts the team created, uploaded tooling, and any configuration that was altered to make an attack path work. Anything left behind is a genuine exposure that the client did not consent to carry, which is why the task belongs to the tester rather than to the customer. Delivering the written findings is the reporting obligation and happens whether or not the environment was ever modified. Retesting corrected defects is a separate, usually separately scoped engagement that validates the customer's repairs. Rotating exposed credentials is remediation work the customer performs on its own systems, and it does not undo the changes the tester made.
- During an authorized internal engagement, a tester wants to capture NTLMv2 hashes by answering broadcast name-resolution requests that Windows hosts send when DNS lookups fail. Which protocol weakness does this technique abuse?
- DNS resolvers accepting unauthenticated answer records
- NTP servers supplying unauthenticated timestamp values
- LLMNR fallback answering unauthenticated local queries
- SNMP agents exposing unauthenticated community strings
Correct answer: LLMNR fallback answering unauthenticated local queries
When a Windows host cannot resolve a name through its configured server it falls back to link-local resolution, and that LLMNR fallback answering unauthenticated local queries is the weakness in play: NBT-NS behaves the same way, neither mechanism authenticates the responder, and whichever station replies first is believed. An attacker who replies claiming to own the requested name receives an authentication attempt and with it NTLMv2 material that can be cracked offline or relayed. A resolver that accepts unsolicited answer records is the classic cache-poisoning problem, a different protocol and a different attack. Unauthenticated time distribution allows clock manipulation, not credential capture. Readable community strings expose device inventory over a management protocol and disclose no user authentication at all.
- A penetration tester runs Responder on an authorized internal network and immediately begins receiving NTLMv2 hashes from workstations. What is the primary function of the Responder tool in this scenario?
- It attacks digests by trying dictionary candidates
- It answers broadcasts by returning rogue responses
- It enumerates shares by probing anonymous sessions
- It intercepts traffic by rewriting cached mappings
Correct answer: It answers broadcasts by returning rogue responses
Responder is a poisoner: it answers broadcasts by returning rogue responses to LLMNR, NBT-NS and mDNS name lookups, claiming to be whatever host the victim was searching for. The victim then opens an authentication exchange with the attacker and discloses NTLMv2 material, which is why hashes start arriving within moments of starting it on a busy segment. That material is cracked offline or relayed onward. Guessing candidates from a dictionary against captured digests is the job of a separate offline cracking tool. Probing anonymous sessions to list shares is share enumeration, which reads exposed resources rather than collecting credentials. Rewriting cached layer-two mappings describes an on-path poisoner that redirects traffic, a distinct family of attack that does not depend on name resolution failing.
- After capturing NTLMv2 hashes that resist cracking, a tester wants to forward the authentication to another host to gain access without ever recovering the plaintext password. Which technique accomplishes this?
- Fabricating a privileged ticket from krbtgt material
- Requesting secrets bound to visible service accounts
- Substituting the digest into an impersonated session
- Relaying the handshake onto one unsigned destination
Correct answer: Relaying the handshake onto one unsigned destination
A relay attack works by relaying the handshake onto one unsigned destination while the exchange is still live, so that target completes the negotiation believing the attacker is the victim and the tester never needs the plaintext at all. It only succeeds where message signing is not enforced, which is exactly why enabling signing is the standard remediation. Fabricating a privileged ticket depends on already holding the domain key-distribution secret, a far deeper compromise than a captured workstation response. Requesting secrets tied to service accounts describes an offline cracking route that still ends in recovering a password. Substituting a captured response into a logon session cannot work, because a challenge-response value is bound to that one challenge and is not reusable the way a stored hash would be.
- A tester needs to generate a standalone Windows executable that, when run, connects back to the tester's listener. Which Metasploit Framework utility is purpose-built to create such payloads in various output formats?
- Msfconsole, driving exploit choice from an interactive shell
- Msfdb, preparing the shared workspace storage behind modules
- Msfvenom, building runnable artifacts in many chosen formats
- Multi-handler, receiving the incoming sessions at a listener
Correct answer: Msfvenom, building runnable artifacts in many chosen formats
Msfvenom is the generator: building runnable artifacts in many chosen formats is its whole purpose, combining payload selection with encoding so the result can be emitted as an executable, a script, a library or raw shellcode for embedding elsewhere. That is what produces a file which, once run, calls back to a waiting handler. Msfconsole is the interactive driver where a module is selected and configured, and it does not by itself write a distributable file. Msfdb prepares the backing workspace storage so results persist between sessions, which is bookkeeping rather than payload creation. The multi-handler module is the receiving end that accepts the callback once the generated file executes, so it consumes the product instead of producing it.
- In Metasploit, what does the term payload most accurately describe?
- The auxiliary module profiling hosts during discovery scans
- The encoder rewriting opcodes to dodge signature inspection
- The listener waiting for an unsolicited incoming connection
- The instructions running on a target following exploitation
Correct answer: The instructions running on a target following exploitation
A payload is the instructions running on a target following exploitation. The exploit's job ends once it has hijacked execution; what happens next, whether that is opening a shell, staging Meterpreter or executing a single command, is the payload's job, and the two are configured separately precisely because either can be swapped without touching the other. An auxiliary module performs scanning and profiling work and never gains code execution to hand off. An encoder only reshapes the bytes of an existing payload so they survive signature inspection, which changes its appearance and not its function. The listener is the attacker-side component that accepts a callback, and it runs on the tester's machine rather than on the compromised target.
- A tester generates a payload that opens a listening port on the compromised host and waits for the tester to connect inbound. What type of shell is this?
- A bind shell awaiting one external connection attempt
- A reverse shell dialing the operator outbound instead
- A web shell responding within the application service
- A restricted shell lacking any full terminal handling
Correct answer: A bind shell awaiting one external connection attempt
A bind shell awaiting one external connection attempt is exactly the described behaviour: the payload binds a port on the victim, listens there, and does nothing until the tester dials in. Its practical weakness is that an ingress rule or a network address translation boundary in front of the victim will usually drop that inbound attempt, which is why the pattern is mostly useful on flat internal segments. The reverse pattern inverts the roles: the victim dials out to the operator, so nothing listens on the victim at all. A web shell is a script left inside a running application and reached over ordinary requests to that application, not a payload holding its own socket. A restricted shell describes a session with no proper terminal handling, a comfort problem rather than a direction of connection.
- Why do penetration testers frequently prefer a reverse shell over a bind shell when targeting a host behind a restrictive firewall?
- Reverse channels apply encryption to the forwarded bytes
- Reverse channels dial outward past ordinary egress rules
- Reverse channels avoid reliance on any attacker listener
- Reverse channels reacquire access despite a host restart
Correct answer: Reverse channels dial outward past ordinary egress rules
Because reverse channels dial outward past ordinary egress rules, the connection is started by the compromised machine rather than by the tester, and most perimeters are asymmetric: unsolicited traffic arriving from outside is denied, while traffic leaving on common service ports is allowed so that ordinary work can continue. A bind pattern needs precisely the inbound permission the perimeter withholds. Nothing about the reverse direction adds encryption; a plain reverse connection is cleartext unless the payload or a wrapper provides transport security. The tester still runs a listener to catch the callback, so the requirement moves to the attacking side rather than disappearing. Regaining access after a restart is what a persistence mechanism provides, and it is unrelated to which end opens the socket.
- A tester is choosing between a staged and a stageless Metasploit payload for a low-bandwidth, signature-restricted environment. Which statement about staged payloads is correct?
- A staged payload ships one artifact holding each component
- A staged payload transmits a stub retrieving the remainder
- A staged payload avoids the handler awaiting its callbacks
- A staged payload hides its traffic using native encryption
Correct answer: A staged payload transmits a stub retrieving the remainder
A staged payload transmits a stub retrieving the remainder from the attacking machine once execution begins, which is why it suits the situation described: the first-stage code is tiny, so it fits where only a few hundred bytes of space are available and it presents very little for a signature to match. Shipping one self-contained artifact that already holds every component describes the stageless alternative, the opposite arrangement. A handler is still mandatory, and in fact the staged form depends on it more heavily because the handler serves the second stage. Encryption is a property of the specific payload chosen rather than of staging, so nothing about splitting delivery into two steps conceals the traffic on its own.
- A tester poisons the ARP cache of a target host and the gateway so that traffic between them flows through the tester's machine. What category of attack is this, and what is its immediate effect?
- An on-path position, permitting silent packet alteration
- A saturation condition, exhausting the connection tables
- An amplification abuse, multiplying the reflected volume
- A segmentation escape, reaching another switched network
Correct answer: An on-path position, permitting silent packet alteration
Forging address-resolution replies so that both the victim and its gateway map each other's addresses to the tester's interface places the tester in an on-path position, permitting silent packet alteration as well as plain observation, because every frame between the two now transits the tester's machine before being forwarded on. This is the technique formerly labelled man-in-the-middle. A saturation attack exhausts connection state to deny service and never yields visibility into a conversation. An amplification abuse uses a third-party service to multiply reflected traffic toward a victim, which is a volumetric attack rather than an interception. A segmentation escape crosses from one switched network into another by abusing tagging or trunking, and it changes reachability without inserting the tester between two parties.
- On a Layer 2 segment, a tester sends crafted replies that associate the tester's MAC address with the default gateway's IP so victim hosts forward their traffic to the tester. Which attack is being performed?
- MAC flooding, overwhelming the switch address table
- DHCP starvation, draining the available lease space
- STP manipulation, claiming the root bridge election
- ARP poisoning, overwriting the victim cache entries
Correct answer: ARP poisoning, overwriting the victim cache entries
ARP poisoning works by overwriting the victim cache entries with forged replies, because address resolution carries no authentication and a host will accept an unsolicited reply that maps the gateway's address to the tester's hardware address. Traffic destined for the gateway is then handed to the tester instead. MAC flooding attacks the switch rather than the host, filling its forwarding table until it floods frames out every port. DHCP starvation drains the lease space so that legitimate clients cannot obtain an address, a denial of service rather than a redirection. Spanning-tree manipulation claims the root bridge role to bend the logical topology, which reroutes at the switching layer without touching any host's resolution cache.
- A tester wants to redirect victims to an attacker-controlled server by supplying forged name-to-IP mappings during resolution. Which attack describes this manipulation of name resolution?
- BGP hijacking, announcing the false prefix ownership
- ICMP redirects, altering the local routing decisions
- DNS spoofing, returning the attacker address mapping
- TLS stripping, removing the secured channel silently
Correct answer: DNS spoofing, returning the attacker address mapping
DNS spoofing, also called cache poisoning, works by returning the attacker address mapping in place of the legitimate one, so a victim that looks up a hostname is handed an address the tester controls and connects there believing it reached the real service. It can be achieved by seeding a resolver's cache or by answering queries from an on-path position. Route hijacking announces prefix ownership that is not the announcer's, which redirects at the routing layer and never changes a name lookup. Router redirect messages alter a host's next-hop choice for a destination it has already resolved. Transport-security stripping removes protection from a session that is already established to the correct address, so it degrades confidentiality rather than misdirecting resolution.
- What term does the current PenTest+ objectives use to describe attacks where the tester positions themselves between two communicating systems to intercept or alter traffic?
- Off-path attack, guessing values from outside completely
- Pass-back attack, harvesting saved device secrets onsite
- Out-of-band attack, retrieving output via separate media
- On-path attack, intruding inside an ongoing conversation
Correct answer: On-path attack, intruding inside an ongoing conversation
The current objectives use on-path attack, intruding inside an ongoing conversation, as the label for the family that used to be called man-in-the-middle: the tester occupies a place through which both parties' traffic must pass, so it can be read and altered in flight. Address-resolution poisoning and rogue wireless access points are the usual ways of getting there. An off-path attacker cannot see the exchange at all and must guess predictable values such as sequence or transaction identifiers to inject anything. A pass-back attack reconfigures a networked device so that stored credentials are sent to the tester instead of to the intended destination. Out-of-band techniques carry results back over a completely different medium, which is a way of retrieving output rather than a position between two parties.
- A web application passes a user-supplied filename directly into a shell command. By appending a semicolon and an additional OS command, the tester causes the server to run their command. Which vulnerability class is this?
- SQL injection, reshaping the relational query expression
- LDAP injection, distorting the directory search criteria
- Command injection, chaining another operating system job
- XPath injection, redirecting the document node selection
Correct answer: Command injection, chaining another operating system job
When unsanitised input is concatenated into a string that the server hands to a shell, a separator character ends the intended work and everything after it is treated as command injection, chaining another operating system job that runs with the privileges of the web process. The defence is to avoid shell interpretation entirely and pass arguments as a list. The relational form manipulates a query sent to a database engine, so the damage stays inside the data layer rather than reaching the host. The directory form distorts a search filter evaluated by a directory service. The XPath form redirects node selection inside an XML document. All three abuse a parser, but none of them hands the attacker execution on the underlying operating system.
- A tester manipulates a file parameter using sequences such as ../../ to read files outside the web root, retrieving /etc/passwd. Which vulnerability is being exploited?
- Open redirect, bouncing visitors onto hostile destinations
- Path traversal, escaping the configured directory boundary
- Server-side forgery, coercing an unintended internal fetch
- Object reference exposure, revealing another user's record
Correct answer: Path traversal, escaping the configured directory boundary
Manipulating a file reference with relative sequences is path traversal, escaping the configured directory boundary so that a reference intended to stay inside one folder resolves somewhere else on the file system and returns an unrelated file. Canonicalising the resolved path and rejecting anything outside the permitted root is the fix. An open redirect abuses a destination parameter to bounce a visitor to a site the operator did not intend, which costs the user rather than the file system. Server-side forgery makes the application itself issue a request the tester chooses, reaching internal services rather than reading local files. Object reference exposure returns another account's record because an identifier is trusted without an authorisation check, and no path is manipulated at all.
- During testing of a login form, the tester submits a value that closes the intended SQL string and appends OR 1=1, returning all rows. What is the most reliable code-level defense the tester should recommend?
- Prepared statements binding submitted values as parameters
- Perimeter filtering blocking known attack strings outright
- Output encoding escaping content during template rendering
- Restricted accounts limiting harm from successful exploits
Correct answer: Prepared statements binding submitted values as parameters
Prepared statements binding submitted values as parameters is the reliable code-level fix, because the statement is compiled with its structure fixed before any input is supplied. Whatever the user sends is then delivered as a value, so a quotation mark or a trailing clause is stored and compared as literal text and can never become part of the logic. Perimeter filtering matches known patterns and is routinely evaded by encoding or by an unusual dialect, so it buys time rather than correctness. Output encoding protects the browser from injected markup and does nothing on the path into the database. Restricted database accounts reduce how much a successful exploit can reach, which is defence in depth and leaves the flaw itself in place.
- A tester injects a script payload into a comment field; when other users view the page, the script runs in their browsers and steals session cookies. Which attack is demonstrated?
- Stored scripting, running inside each later visitor's browser
- Request forgery, riding an already authenticated user session
- Interface overlay, capturing clicks meant for another control
- Script inclusion, reading private data across origin barriers
Correct answer: Stored scripting, running inside each later visitor's browser
Because the submitted markup is saved by the application and served again to everyone who opens the page, this is stored scripting, running inside each later visitor's browser with the origin's own privileges, which is why the session cookie of every reader can be read and sent away. No lure is needed and one submission reaches many victims. Request forgery causes a browser that already holds a valid session to perform an action chosen by the attacker, but it injects no code into the page. An interface overlay hides the real control beneath a decoy so a click lands somewhere unintended, again without executing attacker script. Script inclusion pulls data from one origin into a document controlled by another and depends on how a response is parsed, not on markup persisted by the target.
- A tester wants to capture and manipulate HTTP requests between a browser and a web application, then resend modified requests to probe for flaws. Which tool is designed for this web application proxy workflow?
- Wireshark, dissecting the payloads captured across a segment
- Burp Suite, rewriting exchanges inside an intercepting proxy
- Gobuster, finding the hidden paths through wordlist guessing
- Hydra, submitting the credential guesses against login forms
Correct answer: Burp Suite, rewriting exchanges inside an intercepting proxy
Burp Suite, rewriting exchanges inside an intercepting proxy, is built for this loop: the browser is pointed at it, every message can be paused and edited before it continues, and any captured message can be resent repeatedly with altered parameters or automated through its fuzzing component. That edit-and-resend cycle is the core of manual web testing. Wireshark dissects traffic that has already been captured and cannot hold a message open or change it in flight. Gobuster discovers unlinked paths by trying candidate names from a list, which finds attack surface but does not manipulate a single exchange. Hydra submits credential guesses to a login form and is a brute-force engine rather than an editing proxy.
- Which description best captures what the Metasploit Framework is primarily used for during an engagement?
- A discovery utility enumerating the unlinked web directories
- A wireless suite recovering keys from intercepted handshakes
- A modular platform matching payloads with candidate exploits
- A protocol analyser rebuilding sessions from stored captures
Correct answer: A modular platform matching payloads with candidate exploits
Metasploit is a modular platform matching payloads with candidate exploits: a module is selected for the flaw in question, options and a payload are configured against it, and the whole thing is fired at the target while a handler waits for whatever comes back. The same framework then supplies post-exploitation modules for the session it opens. Enumerating unlinked directories on a web server is content discovery, handled by dedicated tools that never deliver code. Recovering wireless keys from intercepted handshakes belongs to a wireless cracking suite and is limited to that one protocol family. Rebuilding sessions from stored captures is protocol analysis, which explains traffic that already happened and takes no action against a host.
- A tester captured a set of password hashes and wants to recover plaintext passwords using GPU-accelerated cracking with multiple attack modes. Which tool is built for this?
- Responder, collecting the material from poisoned service lookups
- Hydra, hammering live services with repeated credential attempts
- CeWL, building specialised wordlists from crawled site documents
- Hashcat, recovering the plaintext through rapid offline guessing
Correct answer: Hashcat, recovering the plaintext through rapid offline guessing
Hashcat, recovering the plaintext through rapid offline guessing, is the tool described: it drives graphics hardware to compute enormous numbers of candidate hashes per second, supports a long list of hash types, and offers dictionary, rule, mask, combinator and hybrid modes so the search can be shaped rather than merely brute-forced. Responder collects authentication material by poisoning name lookups, which produces the very captures that need cracking but performs none of it. Hydra hammers a live service with credential attempts, an online attack that is slow, noisy and constrained by lockout policy. CeWL builds a targeted wordlist by crawling a site for vocabulary, so it feeds a cracker rather than being one.
- In a dictionary-based password cracking attack, what role does a wordlist play?
- It records the resolved results for scheduled delivery
- It defines the acceptable characters a mask enumerates
- It supplies the candidate guesses hashed then compared
- It stores the precomputed answers for recorded digests
Correct answer: It supplies the candidate guesses hashed then compared
In a dictionary attack the wordlist supplies the candidate guesses hashed then compared against the target value: each entry is run through the same algorithm the application used, and a match reveals the password behind the stored value. Its quality is what decides the outcome, which is why testers tailor lists to the target. Recording resolved results for later delivery describes the file a cracker keeps so it does not repeat work, an output rather than an input. Defining the acceptable characters a template enumerates describes a mask or pure brute-force search, which walks a space instead of reading prepared words. Storing precomputed answers for recorded digests describes a lookup table built in advance, where the hashing has already been done and nothing is computed at attack time.
- A tester uses a precomputed table that maps hash values directly to their corresponding plaintext passwords to crack unsalted hashes quickly. What is this resource called, and what defeats it?
- A rainbow table; a per-password salt defeats it
- A checksum collision; a wider digest defeats it
- A keyspace estimate; a faster laptop defeats it
- A dictionary list; a strict throttle defeats it
Correct answer: A rainbow table; a per-password salt defeats it
A precomputed structure that maps stored values straight back to the passwords behind them is a rainbow table; a per-password salt defeats it, because a distinct random value mixed into each password means the stored result no longer matches anything in a table built for unsalted input, and the attacker has to compute the chains again for every account. That is why salting, not secrecy, is the standard countermeasure. A checksum collision is two inputs sharing one output, a property of the algorithm rather than a stored resource. A keyspace estimate merely counts how large a search would be. A dictionary list holds candidate words that still have to be hashed at attack time, and throttling only slows guessing that happens online.
- Which choice best defines social engineering in the context of a penetration test?
- Overrunning a memory buffer to hijack execution control
- Sweeping an address block to locate responsive services
- Recovering secrets offline from a captured digest store
- Persuading a person into weakening their usual defences
Correct answer: Persuading a person into weakening their usual defences
Social engineering means persuading a person into weakening their usual defences, whether that is disclosing something they should protect, opening an attachment, or letting an unknown visitor through a controlled door. The target is human judgement and trust, which is why no patch closes it and why awareness training and verification procedures are the countermeasures. Overrunning a memory buffer manipulates how a program stores data so that execution can be hijacked, a purely technical flaw in software. Sweeping an address block to find responsive services is reconnaissance carried out against machines. Recovering secrets offline from a captured store is a computational attack on stored values, and none of the three requires a person to be convinced of anything.
- During an authorized engagement, the tester sends targeted emails impersonating the IT help desk to lure employees into entering credentials on a cloned login page. What is this technique, and what is the tester measuring?
- Vishing; gauging how completely an unknown caller persuades
- Phishing; gauging how many staff surrender live credentials
- Smishing; gauging how messaged links are routinely followed
- Tailgating; gauging how doors are physically watched onsite
Correct answer: Phishing; gauging how many staff surrender live credentials
Sending crafted mail that imitates an internal service and drives the reader to a cloned sign-in page is phishing; gauging how many staff surrender live credentials is the measurement, tracked through who opened the message, who clicked, and who actually typed a password into the copy. Those three figures are the deliverable the client uses to judge exposure and to target awareness work. Vishing runs the same deception over a telephone call and measures whether an unfamiliar caller is believed. Smishing delivers the lure by text message and measures how such links are treated on a handset. Tailgating tests whether a controlled door is watched closely enough to stop an unauthorised follower, which is a physical control rather than an email exercise.
- A tester deauthenticates a client from a WPA2-Personal wireless network to capture the four-way handshake, then attempts to recover the passphrase offline. Which captured element is necessary for the offline crack to succeed?
- The beacon broadcast naming the network and its channel layout
- The ARP replay flooding the airtime and gathering more traffic
- The EAPOL exchange carrying the random nonces and check values
- The DHCP negotiation granting the station its lease and router
Correct answer: The EAPOL exchange carrying the random nonces and check values
Offline recovery of a WPA2-Personal passphrase works by hashing each candidate into a pairwise master key, deriving a pairwise transient key from the captured nonces and the hardware addresses, then testing the resulting message integrity check against the value seen in the capture. Those EAPOL frames are the only captured material that can confirm or reject a guess. A beacon advertises the network and its channel but carries no per-session key material. Replayed ARP traffic only generates volume, which mattered for legacy WEP keystream work and adds nothing to a WPA2 dictionary run. DHCP addressing is handed out after association and contains no value a cracker can test against.
- A tester sets up a rogue access point that broadcasts the same SSID as the corporate wireless network to lure clients into connecting. What is this attack commonly called?
- Evil twin, often paired with a matching captive credential page
- Deauth flooding, often paired with a forced client rejoin phase
- War driving, often paired with a detailed street corner mapping
- Passphrase cracking, often paired with a raw saved capture file
Correct answer: Evil twin, often paired with a matching captive credential page
A rogue access point that answers to a legitimate network name is an evil twin: clients that trust the name associate with the tester instead of the real infrastructure, which is why the technique is usually finished with a portal or credential prompt. Deauthentication flooding only knocks clients off an existing network; it can push victims toward a twin but is not itself the impersonation. War driving is a survey that records networks from a moving vehicle and attacks nothing. Passphrase cracking is an offline computation against captured material and never involves standing up an access point.
- A web application reflects an unsanitized id parameter into the response, and the tester confirms a script entered in the URL executes only for the user who follows the crafted link. Which XSS variant is this?
- Stored XSS, held by the application and fed to new viewers
- DOM based XSS, driven by a browser script after page loads
- Blind XSS, parked in a back office console and fired later
- Reflected XSS, echoed by the server and gone after it runs
Correct answer: Reflected XSS, echoed by the server and gone after it runs
Reflected cross-site scripting is delivered inside the request itself: the server echoes the unsanitised parameter straight back into the immediate response, so the script runs only for the person who submitted that request and nothing is retained afterwards. The stored variant requires the payload to be written into the application's data and served to everyone who later views the page, which is not what happened here. A DOM-based payload needs no echo from the server at all, because it reaches a client-side sink while the page assembles itself in the browser. A blind payload fires somewhere the tester cannot watch, so it could not have been confirmed simply by following the link.
- A tester finds that a cloud storage bucket is publicly readable and lists sensitive objects. Within the Attacks and Exploits domain, which cloud attack class does exploiting this misconfiguration represent?
- Cloud image abuse of a publicly readable machine template
- Cloud storage abuse of an overly permissive object policy
- Cloud identity abuse of a secret left inside repositories
- Cloud tenancy abuse of a shared hypervisor timing channel
Correct answer: Cloud storage abuse of an overly permissive object policy
A bucket readable by anyone is a resource policy problem: the storage service is doing exactly what it was told, and the tester simply reads objects the owner never meant to publish, with no software vulnerability involved. A poisoned or openly shared machine image is a supply-chain problem in how compute gets built, not an access decision on stored data. A leaked long-lived credential is an identity problem and yields authenticated access rather than anonymous reads. A timing side channel between tenants is a hardware isolation problem in shared compute, unrelated to how the object store was configured.
- A tester escapes a container by abusing an overly privileged container that was run with host namespace access, gaining code execution on the underlying node. Which class of attack is this?
- Container breakout reaching the platform beneath the sandbox
- Container image poisoning inside the shared registry mirrors
- Container traffic sniffing among the adjacent peer workloads
- Container resource exhaustion starving a common worker queue
Correct answer: Container breakout reaching the platform beneath the sandbox
Running a container with host namespaces and extra privileges removes the isolation that separates it from the machine underneath, so code inside the container reaches the node itself; crossing that isolation boundary is what defines a breakout. Poisoning an image is a supply-chain attack that changes what gets deployed, not an escape from something already running. Sniffing traffic between co-located workloads stays inside the network plane and yields no execution on the machine. Exhausting processor or memory quota pressures the scheduler and denies service, but it never places the tester outside the sandbox.
- A tester intercepts an API request and changes the account identifier in the request body to access another user's records, with the server returning the data. Which web flaw is being exploited?
- Session riding forcing an unintended state change from elsewhere
- Mass assignment binding unexpected fields onto the stored record
- Excessive data exposure returning far more values than requested
- Broken object level checks trusting a client supplied identifier
Correct answer: Broken object level checks trusting a client supplied identifier
Changing an identifier and receiving another account's data means the application resolves whatever object the caller names without checking that the caller owns it, so the authorization decision is missing at the object level. Session riding, better known as cross-site request forgery, makes a victim's browser perform an action inside their own session; it does not let the tester read someone else's record on demand. Mass assignment lets unexpected fields be written during an update, which is a write problem rather than a broken read check. Excessive data exposure returns too many fields of the caller's own object, which is not the same as returning an object belonging to somebody else.
- A tester crafts a request that makes a vulnerable server fetch a URL of the tester's choosing, reaching an internal metadata endpoint not exposed externally. Which vulnerability is this?
- Open redirect abuse, forwarding a browser to outside addresses
- Server side forgery, pointing towards an unlisted host address
- Local file inclusion, loading a stylesheet from the filesystem
- Cached response splitting, injecting a header into the traffic
Correct answer: Server side forgery, pointing towards an unlisted host address
Making the vulnerable server issue a request to a destination the tester chooses is server-side request forgery, and it matters precisely because the server can reach addresses the tester cannot, such as an instance metadata service. An open redirect only changes where a victim's browser lands and never causes the server to fetch anything on the tester's behalf. File inclusion loads content already present on the host rather than sending outbound traffic. Response splitting forges a header boundary so a second reply can be planted in a cache, which manipulates what comes back to clients rather than making the server call outward.
- A tester abuses a vulnerable web parameter to include and execute a server-side file, ultimately gaining remote code execution through a log-poisoning chain. Which initial flaw enabled this?
- Command injection, folding the web parameter inside a shell command
- Careless upload, folding an unchecked script inside a public folder
- File inclusion, folding the crafted path inside the include handler
- Object deserialization, folding saved state inside a live data tree
Correct answer: File inclusion, folding the crafted path inside the include handler
The chain starts with local file inclusion: user input decides which server-side file gets included, and once an attacker-controlled string has been written into a log, including that log turns its contents into executable code. Command injection would already reach a shell without needing anything to be included. An unrestricted upload achieves execution by placing a file the server will run, which needs a writable reachable directory rather than a parameter that chooses an include target. Insecure deserialization abuses reconstruction of saved objects and needs a gadget chain rather than a path parameter, so it does not describe the flaw that opened this chain.
- While testing a SOAP/XML endpoint, the tester submits XML defining an external entity that reads a local file and returns its contents in the response. Which attack is this?
- Schema poisoning, abusing a validation document traded mid transit
- Signature wrapping, abusing a moved element inside signed messages
- Action spoofing, abusing a header choosing the requested operation
- Entity injection, abusing a parser resolving the outer declaration
Correct answer: Entity injection, abusing a parser resolving the outer declaration
Submitting a document that declares an external entity and having the parser resolve it is XML external entity injection: the parser follows the declaration, retrieves the referenced resource and places its content into the result the application returns. Schema poisoning swaps the validation document a parser trusts, which changes what is accepted rather than what is read off disk. Signature wrapping moves a signed element so the validator checks one part of a message while the service acts on another, defeating integrity rather than reading a file. Action spoofing changes which operation a message is routed to, an authorization and routing problem rather than entity resolution.
- A tester sends a request with a deliberately oversized input to a network service and observes a crash, then refines the input to control the instruction pointer. Which vulnerability class is being exploited?
- Format string flaw, where attacker text feeds the logging call
- Buffer overflow, where long input runs past its own allocation
- Type confusion, where a cast reads memory as another structure
- Use after free, where a stale pointer reaches released storage
Correct answer: Buffer overflow, where long input runs past its own allocation
Sending more data than the destination buffer can hold overwrites whatever memory sits after it, and refining that input until the saved instruction pointer holds a chosen value is the classic exploitation path for a buffer overflow. A format string flaw needs attacker text to reach a formatting function, which reads and writes memory through specifiers rather than by overrunning anything. Type confusion mishandles a cast so memory is interpreted as the wrong structure, with no oversized write required. A use-after-free depends on a pointer outliving its allocation, which is a lifetime error rather than a length error.
- A tester crafts a malicious serialized object that, when parsed by a vulnerable Java application, instantiates a gadget chain and executes attacker code. Which vulnerability is being exploited?
- Class loader hijacking, where a planted archive shadows the libraries
- Reflection abuse, where the lookup value selects an unexpected method
- Insecure deserialization, where saved bytes rebuild a live object set
- Path traversal, where the submitted name escapes the protected folder
Correct answer: Insecure deserialization, where saved bytes rebuild a live object set
Handing an application attacker-controlled serialized data makes it rebuild objects it was never meant to build, and a chain of methods already present in its own classes turns that reconstruction into execution. Class loader hijacking requires the tester to place an archive where it will be loaded ahead of the genuine one, which needs prior write access to the host. Reflection abuse depends on the application choosing a method name from untrusted input rather than rebuilding an object graph. Path traversal manipulates a filename to escape a directory, which discloses or overwrites files but instantiates nothing.
- A tester tampers with a JWT used for authentication by changing the alg header to none and removing the signature, and the application accepts the modified token. Which attack class does this represent?
- Signature bypass, where a server trusts entirely unverified claims
- Session fixation, where a prepared identifier survives the handoff
- Credential stuffing, where leaked password pairs are replayed fast
- Ticket replay, where a lifted Kerberos ticket authenticates anyway
Correct answer: Signature bypass, where a server trusts entirely unverified claims
Accepting a token whose algorithm was set to none and whose signature was stripped means the server never verified integrity, so the tester can assert any claims and be believed: the failure is in signature validation and the result is an authentication bypass. Session fixation needs the victim to authenticate under an identifier the tester planted in advance. Credential stuffing replays real username and password pairs harvested from other breaches and never touches token verification. Kerberos ticket replay uses a genuine stolen ticket, which still carries valid cryptographic material rather than none at all.
- During an authorized engagement, a tester wants to map open TCP ports quickly while avoiding completing the three-way handshake, and is running with root privileges. Which Nmap scan type best fits this requirement?
- UDP scan (-sU), probing datagram ports where silence says little
- SYN scan (-sS), resetting the connection once the answer appears
- Connect scan (-sT), finishing the call an operating system opens
- ACK scan (-sA), charting the rules a filtering firewall enforces
Correct answer: SYN scan (-sS), resetting the connection once the answer appears
A SYN scan sends a SYN, reads whichever reply comes back to decide the port state, and then tears the exchange down with a reset rather than completing it, which keeps it fast and leaves less behind in application logs. It builds its own packets, so it needs the raw-socket privilege this tester already has. A connect scan hands the work to the operating system and therefore completes every connection it opens. An ACK scan is built to map how a firewall treats traffic and does not report ports as open. A UDP scan probes datagram services, which is slow and answers nothing about TCP.
- A penetration tester is operating from a low-privilege account on a Linux jump host and cannot obtain root. They need to enumerate open TCP ports on a target. Which behavior should they expect from the scan they are forced to use?
- The SYN scan needs no raw privileges, so the tester stays undetected
- The UDP scan skips the root requirement, so each closed port answers
- The connect scan finishes each handshake, so the service keeps a log
- The idle scan hides behind a borrowed zombie, so nothing gets traced
Correct answer: The connect scan finishes each handshake, so the service keeps a log
Without raw-socket privilege Nmap cannot craft its own half-open probes, so it falls back on the operating system's connect call: every open port receives a completed three-way handshake, and the listening application is in a position to record it. That makes the technique slower and noisier than half-open scanning, which is the behaviour to expect here. Half-open SYN probing is exactly what the privilege limit rules out, so it cannot be the quieter fallback. UDP scanning also builds raw packets and needs the same privilege. Idle scanning depends on crafted packets with a spoofed source address, which is unavailable for the same reason.
- A tester adds -sV to an Nmap command against discovered open ports. What does this flag instruct Nmap to do?
- It probes an open port and reports its software release
- It pings the subnet for answers and skips deep scanning
- It compares the stack replies and guesses a host family
- It widens the range and adds the highest numbered ports
Correct answer: It probes an open port and reports its software release
Version detection interrogates ports already known to be open: Nmap sends protocol-specific probes, matches the replies against its service fingerprint database, and prints the application name and version rather than just the port number, which is what lets a tester line running software up against known issues. Sweeping a subnet for live hosts while skipping ports is host discovery. Estimating the platform from TCP/IP stack behaviour is operating system detection. Extending coverage past the default port selection is a port-range option. None of those three report what software answers on a port.
- A tester queries public records, social media, code repositories, and breach databases to build a profile of a target organization without sending packets to its systems. Which activity best describes this work?
- Service enumeration drawn from replies of a listening interface
- Vulnerability validation drawn from probes against a known flaw
- Traffic capture drawn from packets crossing a monitored segment
- Open source intelligence drawn from freely published news feeds
Correct answer: Open source intelligence drawn from freely published news feeds
Building a profile from registrant records, social profiles, public code and breach dumps is open-source intelligence: everything comes from third parties who already publish it, which is why no packet reaches the organisation and nothing appears in its logs. Service enumeration means connecting to a listening service and pulling detail out of it. Vulnerability validation means firing a check at a live host to see whether a reported weakness is real. Traffic capture requires the tester to sit where the target's packets actually pass. Each of those three touches infrastructure, which this tester deliberately avoided.
- Which statement most accurately distinguishes passive reconnaissance from active reconnaissance during an engagement?
- Passive work needs a written approval; active work needs nothing
- Passive work runs after the exploitation; active work runs first
- Passive work leaves the target untouched; active work queries it
- Passive work crafts packets at hosts; active work reads archives
Correct answer: Passive work leaves the target untouched; active work queries it
The dividing line is contact with the target. Passive reconnaissance reads what other parties hold — registrar data, resolvers run by someone else, search indexes, published documents — so the organisation's own systems see nothing. Active reconnaissance sends traffic to those systems, which is why port scanning and banner grabbing can be detected and logged. Crafting packets is the active side, so an option that assigns it to passive work reverses the two. Written authorisation covers the entire engagement rather than one half of it. And neither is fixed to a point before or after exploitation; both can recur throughout a test.
- A tester is explaining the workflow to a client. Which description correctly captures how reconnaissance differs from enumeration?
- Recon opens after the exploitation; enumeration closes before scoping
- Recon sketches the whole surface; enumeration extracts named accounts
- Recon needs written approval; enumeration proceeds under stated rules
- Recon fingerprints exact builds; enumeration counts the known domains
Correct answer: Recon sketches the whole surface; enumeration extracts named accounts
Reconnaissance is the wide pass that establishes what exists — domains, address ranges, technologies, people — while enumeration is the narrow one that interacts with services already found and pulls out concrete items such as usernames, group memberships, shares and exact software versions. Reconnaissance comes before exploitation, not after it, and enumeration does not precede scoping. Both phases sit inside the same written authorisation, so approval does not separate them. And the split is not about builds versus domains: cataloguing domains is the broad early work, while pinning down an exact build is an enumeration result.
- In the context of a penetration test, what does the term footprinting most precisely refer to?
- Removing testing artifacts once the final report has shipped
- Recovering captured hashes with a large offline wordlist run
- Turning a discovered service into a new interactive foothold
- Profiling the complete attack surface early in an engagement
Correct answer: Profiling the complete attack surface early in an engagement
Footprinting is the systematic build-up of a target's profile at the start of a test: domain names, address blocks, technologies in use, providers and organisational detail, gathered until the tester can see what could be attacked. It may be passive or active, and it precedes detailed enumeration and scanning. Clearing artifacts belongs to cleanup once the work is finished. Recovering hashes offline is a credential attack that happens after material has been captured. Turning a service into a foothold is exploitation, which consumes the profile footprinting produced rather than creating it.
- A tester connects to TCP port 25 on an in-scope mail server and reads the SMTP response line returned by the service to learn its software and version. What technique is being used?
- Banner grabbing, an early step tapping the listening service directly
- Credential stuffing, an online pass replaying many leaked login pairs
- Protocol fuzzing, an aggressive probe flooding a parser with nonsense
- Zone transfer, a single request copying an entire published namespace
Correct answer: Banner grabbing, an early step tapping the listening service directly
Reading the text a service volunteers when a connection opens is banner grabbing: an SMTP greeting, an HTTP server header or an SSH version string names the product and often the exact build, which the tester then matches against known issues. It counts as active because it requires connecting to the port. Credential stuffing replays known username and password pairs against a login and attacks authentication rather than identifying software. Fuzzing sends malformed input to provoke crashes and odd handling. A zone transfer copies records from a name server and says nothing about what is listening on a mail port.
- A tester wants to discover hostnames, mail servers, and other records associated with a target domain by interrogating its name servers. Which activity is this?
- DNS tunneling, moving encoded payloads inside query and reply fields
- DNS cache poisoning, seeding a resolver with a manufactured response
- DNS reverse sweeping, converting a numbered address block into names
- DNS enumeration, collecting the record set a public domain publishes
Correct answer: DNS enumeration, collecting the record set a public domain publishes
Asking a domain's name servers for the records they publish — address, mail exchanger, name server, text and canonical name entries, together with subdomains found along the way — is DNS enumeration, and it maps the hosts and services attached to the organisation. Tunneling hides payload data inside queries and replies as a covert channel, which moves data rather than discovering it. Cache poisoning plants a forged answer in a resolver so victims are misdirected. A reverse sweep starts from addresses and works back to names across a block, which is the opposite direction and never enumerates a domain's record set.
- During DNS enumeration, a tester attempts to retrieve every record in a zone from a misconfigured name server using a single AXFR request. What is this specific technique called?
- A cache poison, a spoofed answer meant for the caching resolver
- A reverse lookup, a pointer query meant for a specified address
- A zone transfer, a copy feature meant for the secondary servers
- A DNS tunnel, a covert channel meant for private data transfers
Correct answer: A zone transfer, a copy feature meant for the secondary servers
A zone transfer is the replication mechanism authoritative name servers use to hand a full copy of a zone to a secondary, so a server that accepts the request from any client returns every record at once. That is why one AXFR against a misconfigured server is such a high-value finding: the internal host map arrives in a single answer. Cache poisoning inserts a false record into a resolver instead of reading the authoritative zone. A reverse lookup resolves one address at a time and cannot enumerate a zone. A covert tunnel encodes data inside queries for transport and retrieves no records at all.
- What is the primary purpose of running Gobuster against an authorized web target?
- Guessing hidden paths and virtual hosts from a predefined wordlist
- Recovering account passwords and phrases from a captured hash dump
- Replaying stolen hashes and tickets onto many exposed file servers
- Editing live requests and replies inside an intercepting web proxy
Correct answer: Guessing hidden paths and virtual hosts from a predefined wordlist
Gobuster works from a wordlist: it requests candidate directories, filenames, subdomains and virtual host names, then reports which ones the server treats as real, exposing admin panels, backups and development endpoints that nothing links to. That content discovery widens the web attack surface before any exploitation. Recovering passwords from captured hashes is offline cracking, a separate tool class. Replaying stolen hashes or tickets against reachable systems is credential relay and lateral movement, which needs credentials this stage has not obtained. Editing traffic inside an intercepting proxy manipulates what the tester already reaches instead of finding unlinked content.
- A tester captures live traffic on an authorized network segment to inspect packets, follow TCP streams, and identify plaintext protocols. Which tool is purpose-built for this analysis?
- Hydra, an online guessing tool attacking multiple login protocols
- Wireshark, a protocol analyser unpacking the captured wire frames
- Hashcat, an offline password cracker using the graphics processor
- Responder, a spoofing service faking stray broadcast name replies
Correct answer: Wireshark, a protocol analyser unpacking the captured wire frames
Wireshark is a protocol analyser: it decodes captured frames field by field, applies display filters, reassembles TCP and HTTP conversations and shows exactly what crossed the segment, including cleartext protocols and any credentials carried in them. Hydra drives online password guessing against login services and captures no traffic. Hashcat cracks captured hashes offline, usually on a graphics card, and never touches the network. Responder answers stray name-resolution broadcasts to collect authentication material, which poisons a segment rather than analysing what is on it.
- In penetration testing, what does enumeration specifically accomplish that general reconnaissance does not?
- It queries a listening service for account lists and share paths
- It maps the address blocks and domain names a customer published
- It measures whether a reported defect genuinely runs on a server
- It removes the scanning artifacts a tester left on every machine
Correct answer: It queries a listening service for account lists and share paths
Enumeration is the phase that connects to services already identified and extracts specifics from them: valid usernames, group memberships, share names, SNMP data and exact software versions, all of which decide which exploit or credential attack is worth attempting next. Mapping published address blocks and domains is reconnaissance, the broad pass that comes first and never touches a service. Confirming that a reported weakness genuinely exists on a host is vulnerability validation, which tests one finding rather than harvesting detail. Removing artifacts is cleanup at the end of the engagement and produces nothing for the tester to act on.
- How is reconnaissance best defined within the penetration testing process?
- The stage that reproduces a finding inside a laboratory rebuild
- The stage that keeps a captured foothold alive after compromise
- The stage that turns the findings into rated remediation advice
- The stage that profiles likely targets before any attack starts
Correct answer: The stage that profiles likely targets before any attack starts
Reconnaissance is the information-gathering phase: before anything is attacked, the tester identifies and profiles candidate targets — domains, address ranges, technologies, personnel — so later effort lands where it is most likely to succeed. Reproducing a finding in a lab is validation work that can only follow discovery. Keeping a foothold alive after a host has fallen is persistence, which belongs much later in the engagement. Turning findings into ranked remediation advice is reporting, the final deliverable. All three consume what reconnaissance produced rather than producing it.
- A tester uses Nmap's -O flag against an in-scope host and reviews the output. What information is this option designed to provide?
- A list of the service names drawn from greeting matching
- A guess of the platform drawn from stack response traits
- A set of active hosts drawn from discovery probe replies
- A breakdown of open ports drawn from an exhaustive sweep
Correct answer: A guess of the platform drawn from stack response traits
Operating system detection sends a series of probes and compares response characteristics — initial sequence numbers, window sizes, and which TCP options appear and in what order — against a fingerprint database, then prints a best guess at the platform, which helps the tester pick compatible tooling. Naming the software behind a port is version detection, a different option. Producing a list of hosts that answered is host discovery. Recording which ports are open across the full range is ordinary port scanning. None of those characterise the operating system from stack behaviour.
- A tester runs Nmap with -p- against an authorized host. What is the effect of this option on the scan?
- It adds the datagram ports beside the customary stream ports
- It restricts the whole scan to a preliminary discovery phase
- It covers the entire numbered port range beyond the defaults
- It applies a version probe against each service already seen
Correct answer: It covers the entire numbered port range beyond the defaults
The option removes the default port selection and scans the whole TCP port range, all 65,535 of them, instead of the top 1,000 Nmap checks by default. It costs considerably more time but finds listeners deliberately moved to unusual high ports, such as an administrative service parked far above the common range. Adding datagram ports is what a UDP scan does. Limiting the run to discovery and skipping the port stage is host discovery. Applying version probes to ports already found open is version detection. None of those change which port numbers get covered.
- A tester is determining whether a target subnet has live hosts before committing to full port scans. Using Nmap, which option performs host discovery only, without scanning ports?
Correct answer: -sn
Host discovery on its own is what -sn does: Nmap sends its discovery probes, lists the addresses that answer, and skips the port-scanning phase entirely, which is why it is the standard way to inventory a subnet before committing to slower scans. -sS is a half-open port scan and needs raw packet privileges. -sV probes ports already known to be open in order to identify the service and its version. -sA maps how a firewall treats traffic and reports filtered or unfiltered rather than telling the tester which hosts are alive.
- A tester runs theHarvester against a target domain during early reconnaissance. Which category of data is this tool primarily designed to collect?
- Mailbox addresses and subdomain names pulled from public indexes
- Cracked password hashes and salts pulled from captured databases
- Runnable exploit packages and shellcode pulled from a repository
- Kernel version strings and patch levels pulled from fingerprints
Correct answer: Mailbox addresses and subdomain names pulled from public indexes
theHarvester aggregates public sources — search engines, certificate transparency data and similar open datasets — and returns email addresses, subdomains and host names belonging to the organisation, which is why it appears at the very start of an engagement and counts as passive collection. It performs no cracking, so recovered password material is outside what it produces. It ships no exploit code, which is a framework's role. And it does not fingerprint kernels or patch levels, because that requires probing a live host rather than reading published records.
- A tester needs to enumerate shares, users, and policies from a Windows host exposing SMB on TCP 445. Which tool is most appropriate for this enumeration?
- volatility 3, a memory framework driven from the command line
- eyewitness, a python3 web client driven from the command line
- enum4linux, a perl based utility driven from the command line
- macchanger, a small local binary driven from the command line
Correct answer: enum4linux, a perl based utility driven from the command line
enum4linux wraps the Samba client utilities and queries a Windows or Samba host over SMB, returning share names, user and group lists, password policy and system details — precisely the concrete inventory this stage calls for. macchanger only rewrites the hardware address of a local interface and never speaks to the target at all. volatility analyses memory images already collected from a host, an offline forensic task. eyewitness collects screenshots of web interfaces so a tester can triage them visually. None of the three speak the protocol the target is exposing.
- A tester queries certificate transparency logs for a target's primary domain. What reconnaissance value does this provide?
- Certificate pinning blocks an intercepting proxy from reading traffic
- Certificate revocation notices show which signing keys were withdrawn
- Certificate chain inspection exposes weak signature algorithms in use
- Certificate records uncover the host names an organization registered
Correct answer: Certificate records uncover the host names an organization registered
Every publicly trusted certificate is written into transparency logs, and each entry lists the names that certificate covers, so searching the logs surfaces subdomains and internal-sounding hosts that ordinary browsing would never reveal — all without sending a packet to the organisation. Pinning is a client-side defence that limits which certificate a client will accept and yields no names. Revocation data records which keys an issuer withdrew, which says nothing about hosts that exist. Inspecting a presented chain examines one host's configuration at a time and discovers no new ones.
- A tester sends a UDP scan (-sU) against a host and several ports return no response at all. How should an open-or-filtered UDP result be interpreted?
- The state is left ambiguous, since a quiet service answers nothing
- The state is certainly shut, since a loaded port disregards probes
- The state is offline, since the host stopped replying much earlier
- The state is confirmed, since the initial handshake has now closed
Correct answer: The state is left ambiguous, since a quiet service answers nothing
UDP is connectionless, so an open datagram port frequently has nothing to say to an empty probe and simply stays quiet, while a closed port is expected to answer with an ICMP port-unreachable message. Silence therefore cannot separate open from filtered, which is why the two are reported together and why UDP scanning is slow and usually needs service-specific probes or version detection to resolve. Treating silence as proof of a closed port inverts the real behaviour. It is not evidence that the host has gone away either, since other ports on the same host replied. And UDP has no handshake that could have completed.
- A tester reviews Nmap output showing a port in the filtered state. What does the filtered result most likely indicate?
- The machine returned a reset, so Nmap declares it fully closed
- The service answered the query, so Nmap reports a version line
- The device dropped the probes, so Nmap marks the state unknown
- The host remained silent, so Nmap omits the whole port listing
Correct answer: The device dropped the probes, so Nmap marks the state unknown
Filtered means probes were sent and nothing usable came back, because something along the path dropped or rejected them, leaving the true state undetermined. That is different from closed, where the target actively returns a reset, and from open, where a service replies and version probes can name the product. It is also not the same as a host that answers nothing at all, which is treated as down during discovery and never reaches the port stage. The practical reading is that packet filtering sits between the tester and the target.
- During authorized OSINT, a tester uses Google search operators such as site:, filetype:, and inurl: to surface exposed documents and pages indexed for a target. What is this technique commonly called?
- Wayback review, which reads what an archive stored from retired pages
- Shodan lookup, which reads what a device scanner banner once recorded
- GitHub mining, which reads what a developer published to shared repos
- Google dorking, which reads what a public web crawler already indexed
Correct answer: Google dorking, which reads what a public web crawler already indexed
Narrowing a search engine's index with advanced operators is called Google dorking, and it surfaces spreadsheets, configuration files, login portals and other material that was indexed but never meant to be found. Because everything comes out of a public index, nothing belonging to the organisation is touched. Archive review pulls historical copies of pages rather than current index entries. A device search engine returns banners its own scanners collected, which is a separate corpus gathered by someone else's probes. Mining public repositories examines code and commit history that developers published, not search operator results.
- A tester wants to query WHOIS and DNS records and enumerate subdomains in an automated, modular way during reconnaissance. Among the following, which is a recon and OSINT framework rather than an exploitation tool?
- Mimikatz
- Recon-ng
- Ettercap
- Evilginx
Correct answer: Recon-ng
Recon-ng is a modular reconnaissance and OSINT framework: it runs collection modules against public sources such as registrant data and DNS records, harvests hosts, contacts and subdomains, and stores everything in a workspace database ready for the next stage. Mimikatz extracts credential material from Windows memory once access has already been achieved. Ettercap runs on-path attacks against a local segment. Evilginx proxies real login flows to capture sessions during phishing. All three act against a target rather than gathering published information about one.
- A tester discovers a network device responding on UDP 161 and supplies the default community string public to query it. What enumeration data can this commonly yield from a misconfigured device?
- Host descriptions, interface counters, and routing entries
- Wireless passphrases, handshake captures, and roaming keys
- Private certificates, session tickets, and secret material
- Zone records, delegation entries, and nameserver addresses
Correct answer: Host descriptions, interface counters, and routing entries
A device that still answers on its default read community string exposes its management information base, so a walk of that tree returns host descriptions, interface tables and routing entries, plus process and software inventory on many platforms. That is exactly the inventory and topology data enumeration is after. Wireless passphrases come out of a captured handshake and an offline cracking run, not from a management query. Certificates and session tickets are key material held by cryptographic subsystems that never publish private keys over a management protocol. Zone records and delegation entries come from a name server that permits a zone transfer, a different service and a different misconfiguration.
- During an authorized internal engagement, a tester is given a valid domain account before running a vulnerability scan. The client wants to understand what advantage this provides over a scan run without any login. Which statement best describes an authenticated (credentialed) scan compared to an unauthenticated scan?
- It probes each host across the network for banners, missing local detail
- It reads the rendered page of each web application, skipping other hosts
- It signs into each server for local patch state, cutting false positives
- It reads a central asset database for its software, avoiding live probes
Correct answer: It signs into each server for local patch state, cutting false positives
A credentialed scan authenticates to the target and reads what only a logged-in session can see: installed packages, applied patches and the actual configuration files. Because it verifies rather than infers, it reports far fewer false positives than a scan that can only guess from the outside. Probing from the network and reading banners is the unauthenticated behaviour the client is comparing against, not the advantage credentials add. Credentialed scanning is not limited to web applications; it is used mostly against operating systems and installed software. Reading a central asset database is inventory reconciliation, and it still tells you nothing about the live state of the host.
- A tester scans a Linux web server with credentials and the report lists every missing OS patch and an outdated OpenSSL package, while a prior uncredentialed scan of the same host only flagged an exposed service banner. Why did the credentialed scan surface so much more detail?
- It ran an exploit against each flagged service to confirm exact versions
- It read the local package and config databases to confirm exact versions
- It replayed one captured request and its reply to confirm exact versions
- It queried an external source by hostname and domain to confirm versions
Correct answer: It read the local package and config databases to confirm exact versions
With a valid login the scanner queries the host's own package manager and configuration files, so it can compare installed build strings against the vendor's patch data and enumerate every missing update, including a library such as OpenSSL that exposes nothing on the wire. Without credentials the scanner is limited to what the host volunteers over the network, which is why the earlier run produced only a service banner. Nothing was exploited: a credentialed scan authenticates and reads, it does not launch attacks to prove findings. No traffic was replayed through a proxy; that is a web-application testing technique and it cannot enumerate installed packages. A public feed keyed on hostname knows nothing about what is actually installed on that machine.
- A client reading a penetration test report asks what a CVSS base score actually represents. Which explanation is correct under CVSS v4.0?
- Exploit activity, drawn from threat and vendor intelligence bulletins
- Deployment-specific risk, drawn from asset value and local safeguards
- Remediation progress, drawn from patch and rescan coverage statistics
- Intrinsic base severity, drawn from exploitability and impact metrics
Correct answer: Intrinsic base severity, drawn from exploitability and impact metrics
The base metric group describes the qualities a vulnerability has on its own: how it is reached, how hard it is to reach, what privileges and interaction it needs, and what it costs the vulnerable and any downstream system. Those qualities do not change over time and do not depend on where the flaw is deployed, which is why the base score is published once and reused everywhere. Current exploit activity belongs to the threat metric group, which is layered on top of the base score rather than folded into it. Asset value and local compensating controls belong to the environmental group, supplied by the organisation. Patch and rescan coverage is remediation reporting; it never feeds a CVSS score at all.
- A tester is producing a CVSS v4.0 vector for a flaw that an unauthenticated attacker can trigger over the internet with no special conditions and no user interaction. Which combination of base metric values most accurately captures this?
- AV:A / AC:H / PR:L / UI:P
- AV:L / AC:L / PR:H / UI:A
- AV:P / AC:H / PR:N / UI:P
- AV:N / AC:L / PR:N / UI:N
Correct answer: AV:N / AC:L / PR:N / UI:N
An attacker who reaches the flaw across the internet scores Attack Vector Network. No special preparation or unusual conditions means Attack Complexity Low. Unauthenticated means Privileges Required None, and a flaw that fires without a victim doing anything means User Interaction None. Adjacent restricts the attacker to the same logical network segment, which the stem rules out, and High complexity would demand conditions the stem says are absent. Local requires a shell or console session on the target and High privileges would require an administrative account, neither of which an unauthenticated internet attacker has. Physical requires the attacker to touch the device, and the Passive and Active user-interaction values both assume a victim contributes to the attack.
- When using the FIRST CVSS v4.0 calculator to derive a numeric score, which set of inputs determines the base score?
- Threat metrics such as exploit maturity levels
- Base metrics such as exploitability and impact
- Environmental metrics such as base risk levels
- Supplemental metrics such as safety and effort
Correct answer: Base metrics such as exploitability and impact
The calculator derives the base score purely from the base metric group: attack vector, attack complexity, attack requirements, privileges required and user interaction on the exploitability side, and the confidentiality, integrity and availability impact on both the vulnerable system and any subsequent system. Nothing else moves that number. Exploit maturity sits in the threat group, which adjusts a score that has already been calculated. Security requirements and asset value sit in the environmental group, supplied by the consuming organisation rather than the publisher. Automatable and recovery effort sit in the supplemental group, which carries context for decision-making and is explicitly not scored.
- A developer asks the tester to clarify the difference between SAST and DAST during a secure-coding discussion. Which statement is accurate?
- SAST examines source code offline, while DAST probes the live site
- SAST replays saved traffic offline, while DAST reads the code repo
- SAST needs a compiled binary first, while DAST needs source access
- SAST reads production log data, while DAST reviews the build files
Correct answer: SAST examines source code offline, while DAST probes the live site
Static application security testing works on the artifact at rest, reading source or compiled code and reasoning about paths the program could take without ever executing it. Dynamic application security testing works on the artifact in motion, sending requests to a running instance and judging the responses, so it needs a deployed target but no code. Replaying captured traffic is a proxy technique and is not how static analysis operates, and reading the source tree is exactly what dynamic testing cannot do. The description that has static testing needing a binary while dynamic testing needs source reverses the two disciplines. Watching production logs is monitoring, and reviewing build output is a pipeline task; neither defines either method.
- A tester must assess a third-party web application during an engagement but has no access to its source code and cannot install agents on the server. Which testing approach fits these constraints?
- Static testing, which parses the raw application source code trees
- Interactive testing, which needs an agent inside the app's runtime
- Dynamic testing, which exercises the deployed app from the outside
- Composition testing, which reads the list of core dependency files
Correct answer: Dynamic testing, which exercises the deployed app from the outside
With no source and no ability to instrument the server, the only surface left is the running application itself, and dynamic testing is defined by exercising that surface from the outside over its own protocols. It needs nothing but a reachable, running instance, which is exactly what the tester has. Static testing consumes source or binaries, so the first constraint rules it out. Interactive testing runs an instrumentation agent inside the application runtime, which the second constraint rules out. Software composition analysis needs the dependency manifests or lock files that ship with the source, so it fails the first constraint as well.
- A vulnerability scanner reports that a Windows IIS server is vulnerable to a flaw that only affects a specific Linux Apache module, even though that module is not present on the host. How should the tester classify this result?
- False negative: the scanner overlooked a genuine live flaw
- True positive: the flagged flaw is present and exploitable
- False positive: the reported condition is not present here
- Risk acceptance: the client accepts a known unpatched flaw
Correct answer: False positive: the reported condition is not present here
The host is a Windows web server and the flaw belongs to a module that only exists on a different platform and is not installed, so the precondition the finding depends on does not hold. A report of a vulnerability that does not exist on the target is a false positive, and the tester validates it manually and marks it as such rather than passing it to the client. A false negative is the opposite failure, a real flaw the scanner never reported, and here the scanner reported something rather than nothing. It cannot be a true positive because the affected component is absent from the host. Risk acceptance is a business decision about a confirmed weakness, not a way to classify a scanner's accuracy.
- In vulnerability scanning, what is a false positive and why does it matter to a penetration tester?
- A reported flaw that is not real, so testers verify it manually
- A real flaw that the scan missed, so testers widen the coverage
- A repeat entry that doubles one host, so testers merge the rows
- A proven flaw that has a known identifier, so testers record it
Correct answer: A reported flaw that is not real, so testers verify it manually
A false positive is a finding the tool presents as a vulnerability when the underlying condition is not actually present on the target. It matters because a report built on unvalidated output wastes the client's remediation budget and damages the tester's credibility, which is why manual verification of scanner output is a required step rather than an optional one. A genuine flaw the scanner failed to report is a false negative, the opposite error. A duplicated record from scanning the same host twice is a reporting artifact, not a judgement about whether the flaw exists. A finding that has been confirmed and carries an identifier is a true positive, which is what validation is meant to produce.
- A non-technical client asks the tester, in plain terms, what a vulnerability scan does. Which description is most accurate?
- It watches live traffic and alerts on attacks aimed at these systems
- It patches each system and confirms the clearance of the known flaws
- It exploits each system and proves the impact of the confirmed flaws
- It probes systems and matches them against a database of known flaws
Correct answer: It probes systems and matches them against a database of known flaws
A vulnerability scan is an automated discovery and comparison exercise. The tool probes the target, records the software, versions and configuration it can observe, then checks that inventory against a maintained database of known weaknesses and returns a list of potential issues for a human to validate. Watching live traffic and alerting on attacks describes an intrusion detection system, which is a monitoring control rather than an assessment tool. Applying patches is remediation, done by the client after findings are agreed, and no scanner does it as part of scanning. Exploiting each system to prove impact is penetration testing, the manual work that follows the scan and is deliberately not automated by the scanner.
- A penetration tester needs a widely used commercial vulnerability scanner to perform automated network and host assessment, including credentialed checks across thousands of plugins. Which tool is purpose-built for this?
- Hydra, an automated multi-protocol network login brute-forcer
- Nessus, an automated credentialed asset vulnerability scanner
- Mimikatz, an automated in-memory Windows credential harvester
- Wireshark, an automated network host packet-capture inspector
Correct answer: Nessus, an automated credentialed asset vulnerability scanner
Nessus is the commercial vulnerability scanner the objectives name for exactly this task: automated network and host assessment driven by a very large, frequently updated plugin feed, with credentialed checks that log into targets to verify patch level and configuration. Hydra guesses credentials against live network services and reports weak logins; it performs no vulnerability assessment. Mimikatz extracts credential material from memory on a host the tester already controls, so it is a post-exploitation tool rather than a scanner. Wireshark captures and decodes traffic for analysis and never probes a target or compares it to a vulnerability database.
- During web application analysis, a tester sends large volumes of malformed, unexpected, and random input to a target to trigger crashes or anomalous behavior that may reveal exploitable flaws. What is this technique called?
- Grabbing the target application's service banners
- Fuzzing the target application's request handlers
- Pivoting through the compromised internal gateway
- Escalating the local machine account's privileges
Correct answer: Fuzzing the target application's request handlers
Feeding a target large volumes of malformed, unexpected or randomly generated input and watching for crashes, hangs or other anomalous behaviour is fuzzing. The crashes it produces are the signal, because a handler that fails on malformed input is often the handler that can be pushed into an exploitable state. Banner grabbing reads the version string a service volunteers and involves no malformed input at all. Pivoting routes traffic through a compromised host to reach a network the tester cannot address directly, which is a movement technique and not an input test. Privilege escalation raises the rights of an account the tester already holds and likewise has nothing to do with malformed input.
- A scanner reports four findings on a client's host: a Critical remote code execution flaw, a High privilege-escalation issue, and two Low informational items. With limited remediation time, how should the tester advise the client to prioritize?
- Remediate the two lowest findings first, then the critical issue
- Remediate by the identifier order first, then by discovery dates
- Remediate the oldest finding first, then the newest logged issue
- Remediate the critical execution flaw first, then the high issue
Correct answer: Remediate the critical execution flaw first, then the high issue
Remediation order follows severity and exploitability. A critical remote code execution flaw gives an unauthenticated attacker control of the host and is the single largest reduction in risk available, so it goes first, followed by the high-severity privilege escalation issue; the two low informational items can wait for a normal maintenance window. Fixing the low items first spends the limited window on the smallest risk reduction available. Working through findings by identifier is an arbitrary ordering that ignores impact entirely. Age-based ordering is a service-level convention for routine patching and would leave the critical flaw exposed if it happened to be the newest finding.
- A tester wants a fully open-source vulnerability scanner to assess a client's external network without paying for a commercial license. Which tool fits this requirement?
- Aircrack-ng, an open-source wireless network capture scanner
- Cobalt Strike, a licensed network post-exploitation platform
- OpenVAS, an open-source network vulnerability scanner engine
- Wireshark, an open-source network protocol capture inspector
Correct answer: OpenVAS, an open-source network vulnerability scanner engine
OpenVAS, maintained as part of the Greenbone stack, is the open-source network vulnerability scanner used where a commercial licence is not available. It runs a community feed of network vulnerability tests against the external range and produces the same class of output a commercial scanner would. Aircrack-ng is open source but audits wireless encryption and recovers keys from captured frames, so it does not assess a wired external network. Cobalt Strike is a paid commercial product for adversary emulation and command and control, which fails the licensing requirement outright. Wireshark is open source but only captures and decodes traffic; it never probes hosts or matches them against a vulnerability feed.
- While analyzing scan results, a tester sees a web server self-reporting version 2.4.49 of a well-known HTTP daemon associated with a path-traversal and remote code execution issue. What is the most appropriate next analysis step within the engagement scope?
- Map the banner version to published CVEs, then verify it manually
- Treat the banner version as proof of compromise, then move onward
- Dismiss the banner version as invalid, then rescan the host again
- Send the banner version to the vendor, then await their statement
Correct answer: Map the banner version to published CVEs, then verify it manually
A self-reported version is a lead, not a finding. The correct analysis step is to map that version to the CVEs published against it, then confirm by hand that the host is genuinely affected, because the module may be absent, the build may be back-ported, or the banner may simply be inaccurate. Only after that does the issue belong in the report as exploitable. Treating the banner as proof and jumping to post-exploitation records an unvalidated finding and risks acting outside what the evidence supports. Rescanning the whole subnet repeats work already done and answers nothing about this host. Banners are frequently unreliable but are not worthless, and vendor notification is the client's decision, not a step in the tester's analysis.
- A tester writes a short script to parse Nmap XML output and automatically cross-reference each discovered service version against a local vulnerability list. Within the Vulnerability Discovery and Analysis domain, what does this scripting primarily accomplish?
- It automates the correlation of scan data with known vulnerability tables
- It automates the exploitation of each service found without manual review
- It automates the production of the engagement invoice from scanner output
- It automates the removal of the affected software packages across servers
Correct answer: It automates the correlation of scan data with known vulnerability tables
Parsing structured scan output and joining each discovered service and version to a vulnerability list is correlation, and scripting it means the analysis stage runs at machine speed with none of the transcription mistakes a manual lookup introduces. That is the value the objectives attach to automation in vulnerability discovery and analysis. It does not exploit anything; the script only reads and compares data that has already been collected. Generating an invoice is a business activity with no relationship to the vulnerability analysis domain. Removing packages is remediation performed by the client, and a tester who altered production software would be acting outside the agreed scope.
- A vulnerability scanner runs against a bespoke web application and reports no issues, yet the tester later confirms a custom authentication bypass exists. How is the scanner's original result classified, and what does it illustrate?
- False positive, showing that scanners tend to over-report custom code
- True negative, showing that the application had no exploitable defect
- True positive, showing that the scanner matched a published signature
- False negative, showing that signatures do miss custom business flaws
Correct answer: False negative, showing that signatures do miss custom business flaws
The flaw was genuinely present and the scanner reported nothing, which is a false negative. It illustrates the structural limit of signature and pattern driven scanning: the tool recognises known software and known weaknesses, but a custom authentication bypass is business logic unique to that application, so no signature exists for it and only manual testing finds it. A false positive would be the scanner reporting something that is not there, the opposite of what happened. A true negative would require the application to be genuinely clean, which the tester disproved. A true positive would require the scanner to have reported the bypass, which it never did.
- A tester wants to discover hidden input-handling crashes in a custom compiled binary by feeding it mutated and generated inputs and monitoring for failures. Which category of tool is most appropriate?
- Mimikatz, a Windows process credential dumper
- AFL++, a coverage-guided binary memory fuzzer
- Burp, a client-side traffic interception tool
- Nmap, a networked service discovery inspector
Correct answer: AFL++, a coverage-guided binary memory fuzzer
Feeding a compiled binary mutated and generated inputs while watching for crashes is what a fuzzer does, and a coverage-guided fuzzer such as AFL++ instruments the target so that inputs which reach new code paths are kept and mutated further, which is why it finds input-handling crashes that random data alone would miss. A credential dumper harvests secrets from memory on a host the tester already controls and performs no input testing. A web proxy intercepts and manipulates HTTP traffic against a running web application, not a local compiled binary. A port mapper discovers hosts and open services and has no view of how a binary handles its input.
- After running two different scanners against the same web application, a tester finds one tool reports a SQL injection on a parameter while the other does not. What is the most defensible way to resolve the discrepancy during analysis?
- Accept the sole scanner result and report the injection as confirmed
- Discard both scanner findings and omit the parameter from the report
- Manually retest the parameter and observe the response to resolve it
- Average both severity ratings and report the midpoint as the finding
Correct answer: Manually retest the parameter and observe the response to resolve it
When two tools disagree, neither result is evidence on its own, so the tester resolves it by testing the parameter directly within scope and reading how the application behaves. That produces first-hand evidence that either confirms the injection or refutes it, and the report then rests on the tester's own verification rather than on a vote between scanners. Accepting the single detection ships an unvalidated finding and is how false positives reach a client. Discarding both results throws away a lead without answering the question. Averaging severity scores invents a number that describes neither tool's finding and still leaves the existence of the flaw undetermined.
- A client has a flat asset inventory and asks the tester to help decide which scan-discovered vulnerabilities deserve attention first. Beyond raw CVSS base score, what additional factor most improves this prioritization?
- The plugin category and complete check count behind each reported flaw
- The probe duration and network packet volume counted per reported flaw
- The exploit maturity and active attacks seen behind each reported flaw
- The scan schedule and rescan frequency recorded for each reported flaw
Correct answer: The exploit maturity and active attacks seen behind each reported flaw
A base score describes a flaw in the abstract, and two findings can share a score while posing very different real risk. Exploit maturity, whether working exploit code is public and whether the flaw is being used in live attacks, is the factor that separates them, so a moderately scored vulnerability under active exploitation should be fixed before a higher-scored one nobody has ever weaponised. The plugin family and check count describe how the scanner is built, not how dangerous a finding is. Probe duration and packet volume are performance measurements of the scan itself. The scan window and rescan cadence describe the assessment schedule and say nothing about the severity or exploitability of any finding.
- A tester needs to scan a web application specifically for common server-side problems such as outdated server software, dangerous default files, and known insecure CGI scripts. Which lightweight scanner is designed for this purpose?
- Hashcat, an accelerated password and hash retrieval workbench
- Nikto, a web server default-file and misconfiguration scanner
- Metasploit, an exploit scripts and payload delivery framework
- Nmap, a network-scale host and server enumeration environment
Correct answer: Nikto, a web server default-file and misconfiguration scanner
Nikto is the lightweight web server scanner built for precisely this checklist: outdated server and module versions, dangerous or forgotten default files, and known insecure CGI scripts, tested against thousands of well-known paths. It is fast, noisy and aimed at the server rather than the application's own logic. Hashcat recovers passwords from captured hashes offline and never touches a web server. Metasploit develops and delivers exploits against a target already known to be vulnerable, so it is an exploitation framework rather than a web content scanner. Nmap discovers hosts and open services and can identify a web server, but it does not carry the default-file and CGI checks the stem describes.
- During an authorized engagement, a penetration tester has compromised one workstation and now uses its access to authenticate to additional hosts in the same Active Directory domain, gradually expanding control across the network. Which post-exploitation activity does this describe?
- Privilege escalation on the local machine
- Persistence through a scheduled boot task
- Active reconnaissance of the network edge
- Lateral movement across peer domain hosts
Correct answer: Lateral movement across peer domain hosts
Using access gained on one machine to authenticate to further machines at a similar level of trust, and repeating that to widen the tester's reach across the domain, is lateral movement. The defining feature is sideways expansion between peers rather than upward expansion of rights. Privilege escalation raises the tester's rights on a system already reached, which is vertical rather than lateral and is not what the stem describes. Persistence keeps access alive across reboots and lost sessions; it maintains a foothold rather than adding new ones. Active reconnaissance interacts with targets to gather information and belongs before exploitation, not after a workstation has already been compromised.
- A tester has a foothold on a dual-homed host that can reach an isolated internal subnet the tester's own machine cannot. The tester configures the compromised host to relay traffic so that tools launched from the attack box can scan and attack systems in that hidden subnet. What is this technique called?
- Pivoting through the compromised relay point
- Sniffing across the compromised host segment
- Phishing against the internal helpdesk users
- Spoofing inside the isolated internal subnet
Correct answer: Pivoting through the compromised relay point
Turning a compromised dual-homed machine into a relay so that tools on the attack box can reach a network the attack box cannot address directly is pivoting. The foothold becomes the route into the isolated subnet, and everything the tester runs afterwards travels through it. Sniffing passively reads traffic that already reaches the listening interface and creates no route to an unreachable network. Phishing is a social engineering technique used to obtain an initial foothold, which the tester already has. Spoofing forges identity on a segment the attacker can already reach, which again does not solve the routing problem the stem describes.
- A penetration tester deploys an implant on a compromised host that periodically beacons out to an external server the tester controls, retrieving commands and returning their output. What does the external server in this arrangement function as?
- A jump box and bastion that reaches internal subnets
- A local resolver and cache that answers name lookups
- A file server and repository that holds the payloads
- A command and control server that tasks the implants
Correct answer: A command and control server that tasks the implants
An implant that beacons outward on a schedule, collects instructions and returns their output is speaking to a command and control server. That server is the operator's side of the channel: it queues tasking, receives results and holds the sessions the tester works through. A jump box is an administrative host inside the client network used for authorised access between segments, not an external node the tester controls. A recursive resolver answers name lookups and would only be involved if the channel happened to be tunnelled over DNS, which is transport rather than function. A file server that hosts payloads is a staging resource and does not receive beacons or issue commands.
- After gaining administrative access to several hosts, a tester collects passwords, password hashes, and Kerberos tickets from memory and configuration files to reuse them against other systems in the domain. What is this post-exploitation activity called?
- Harvesting credentials from memory and saved configuration data
- Fuzzing parameters against malformed uploaded files and headers
- Enumerating subdomains from public registries and domain tables
- Poisoning local name responses across several broadcast subnets
Correct answer: Harvesting credentials from memory and saved configuration data
Collecting passwords, password hashes and Kerberos tickets from process memory, registry hives and configuration files so that they can be replayed or cracked and reused elsewhere is credential harvesting, and it is what turns a single administrative foothold into domain-wide reach. Fuzzing sends malformed input to find crashes in an application and produces no credentials. Subdomain enumeration is passive or active reconnaissance against the client's public namespace and happens long before any host is compromised. Poisoning name resolution responses coerces authentication toward the tester, which is a way to obtain credential material on the wire rather than the act of collecting it from systems already under control.
- A tester with a valid but unprivileged domain account requests Kerberos service tickets for accounts that have a registered Service Principal Name, then exports those tickets to crack them offline and recover the service accounts' passwords. Which attack is being performed?
- Spraying credentials against the unprivileged domain user accounts
- Poisoning cached name resolution answers across corporate segments
- Kerberoasting the accounts with registered service principal names
- Relaying captured authentication onto adjacent domain member hosts
Correct answer: Kerberoasting the accounts with registered service principal names
Any authenticated domain user may request a service ticket for an account that has a Service Principal Name registered, and part of that ticket is encrypted with a key derived from the service account's password. Exporting those tickets and attacking them offline recovers the passwords of service accounts, which are often weak and over-privileged. That is Kerberoasting. Password spraying tries a small number of common passwords against many accounts and needs no ticket at all. Poisoning multicast name lookups coerces a victim into authenticating to the tester and yields hashes from a different protocol path. Relaying forwards captured authentication to another service in real time rather than cracking it offline.
- A penetration tester installs a scheduled task that re-launches an implant after every reboot so that access to a compromised host survives if the system is restarted or the original session drops. Which post-exploitation goal does this technique serve?
- Establishing a quiet implant exfiltration route
- Establishing persistence beyond a system reboot
- Establishing the agreed engagement access rules
- Establishing a direct privilege escalation path
Correct answer: Establishing persistence beyond a system reboot
A scheduled task that re-launches the implant whenever the machine starts exists so that access survives a reboot, a crash or a dropped session, which is the definition of persistence. Testers document these mechanisms carefully and remove them during cleanup so the client is not left with an unmanaged backdoor. A covert channel is about moving data out without detection, which is exfiltration rather than survival of access. Rules of engagement are agreed in the pre-engagement phase and constrain what the tester may do; they are paperwork, not a technique. A denial of service condition degrades availability and is normally excluded from scope, and it would draw attention rather than quietly preserve access.
- On a compromised Linux host, a tester runs the command that lists files with the SUID bit set and finds a root-owned binary that GTFOBins documents as exploitable. How does abusing this binary help the tester?
- The binary encrypts the local drives, so the tester evades review
- The binary executes with owner rights, so the tester reaches root
- The binary opens additional ports, so the tester maps the segment
- The binary tunnels outbound data, so the tester keeps its channel
Correct answer: The binary executes with owner rights, so the tester reaches root
A file carrying the set-user-ID bit executes with the privileges of its owner rather than the user who launched it, so a root-owned SUID binary runs as root for anyone allowed to start it. When that binary offers a documented way to run arbitrary commands or read arbitrary files, those actions inherit root, and the tester escalates from a limited account to full control of the host. Encrypting disks is destructive and does nothing for privilege. Opening ports would help enumeration of neighbouring hosts but grants no additional rights on this one. Tunnelling data out maintains a channel to infrastructure the tester controls, which is persistence and exfiltration rather than escalation.
- A tester has limited-user access on a Windows server and wants to find a path to SYSTEM. Which finding represents a classic Windows privilege-escalation opportunity?
- A self-signed certificate used by an internal web host
- An outdated browser plugin on a local user workstation
- An unquoted service path with a writable parent folder
- A published file share with an unrestricted guest user
Correct answer: An unquoted service path with a writable parent folder
A Windows service whose executable path contains spaces and is not enclosed in quotation marks makes the service control manager try each truncated path in turn when it starts. If a limited user can write to one of the directories along that path, they can place a file the service will load, and the service starts under a system account, so the tester's code inherits those rights at the next start or reboot. A self-signed certificate is a trust and transport finding and grants no local rights. An outdated browser plugin is a client-side issue that would need a user to browse to attacker content and would still yield only that user's context. An anonymous read-only share may leak information but confers no ability to execute anything.
- After collecting sensitive files on a compromised internal host, a tester encodes the data into the subdomain labels of DNS queries sent to a domain whose authoritative name server the tester controls, reassembling the data on that server. Why is this exfiltration method effective at evading network controls?
- DNS queries are widely permitted and seldom inspected in any depth
- DNS queries are exempt from capture and absent from perimeter logs
- DNS queries are encrypted by default and opaque to network proxies
- DNS queries are carried by one transport and ignored by inspectors
Correct answer: DNS queries are widely permitted and seldom inspected in any depth
Almost every network has to let name resolution out for anything else to work, so DNS is one of the few protocols that reliably crosses the perimeter, and the volume of ordinary lookups means the content of individual queries is rarely examined in depth. Encoding data into query labels therefore hides it inside traffic that is both allowed and unread, which is why the technique defeats controls that would stop an ordinary outbound connection. Queries are logged by resolvers and by network monitoring, so the traffic is recorded even when nobody reads it. Standard resolution is plaintext unless encrypted transport has been deliberately deployed. Lookups use UDP by default and fall back to TCP for large responses, and neither transport is immune to filtering.