wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

First Part

Total questions: 10

Worksheet time: 4mins

Name
Class
Date
1.

Which of the following is NOT a primary objective of penetration testing?

a)

Identifying weaknesses in systems and applications.

b)

Providing actionable recommendations to improve security posture.

c)

Ensuring compliance with industry standards and regulations.

d)

Maximizing system performance through hardware upgrades.

2.

A financial institution conducts a penetration test to verify adherence to PCI-DSS requirements. This aligns with which penetration testing objective?

a)

Identify Weaknesses

b)

Compliance Assurance

c)

Improve Security Posture

d)

Assess Risks

3.

A penetration tester is given user account credentials and a network diagram before starting the test. Which type of penetration test is this?

a)

White Box Testing

b)

Black Box Testing

c)

Gray Box Testing

d)

External Testing

4.

Which type of penetration test involves evaluating internal vulnerabilities by conducting the test within the organization’s network?

a)

Internal Testing

b)

External Testing

c)

Black Box Testing

d)

Gray Box Testing

5.

In the OWASP Testing Framework, which phase involves actively attempting to exploit identified vulnerabilities to determine their real-world impact?

a)

Information Gathering

b)

Threat Modeling

c)

Vulnerability Scanning

d)

Penetration Testing

6.

In the NIST SP 800-115 process, which phase focuses on setting clear objectives and defining the boundaries of the test?

a)

Information Gathering and Analysis

b)

Planning and Scoping

c)

Vulnerability Assessment

d)

Reporting and Remediation

7.

A testing team has finished identifying vulnerabilities and now needs to summarize their findings, provide recommendations, and track remediation efforts. Which NIST SP 800-115 phase is this?

a)

Penetration Testing

b)

Vulnerability Assessment

c)

Reporting and Remediation

d)

Planning and Scoping

8.

Which activity would be considered active reconnaissance?

a)

Reviewing job postings for IT staff on a company’s careers page

b)

Collecting email addresses from social media profiles

c)

Running an Nmap scan to identify open ports on a target server

d)

Searching for past data breaches in public leak databases

9.

Which phase of the Cyber Kill Chain involves developing malicious tools or exploits to take advantage of identified vulnerabilities?

a)

Reconnaissance

b)

Weaponization

c)

Exploitation

d)

Installation

10.

Which Cyber Kill Chain phase comes immediately after exploitation and typically involves establishing persistence on the target system?

a)

Weaponization

b)

Actions on Objectives

c)

Reconnaissance

d)

Installation