NEW
Font size
WorksheetsFirst Part
Total questions: 10
Worksheet time: 4mins
Which of the following is NOT a primary objective of penetration testing?
Identifying weaknesses in systems and applications.
Providing actionable recommendations to improve security posture.
Ensuring compliance with industry standards and regulations.
Maximizing system performance through hardware upgrades.
A financial institution conducts a penetration test to verify adherence to PCI-DSS requirements. This aligns with which penetration testing objective?
Identify Weaknesses
Compliance Assurance
Improve Security Posture
Assess Risks
A penetration tester is given user account credentials and a network diagram before starting the test. Which type of penetration test is this?
White Box Testing
Black Box Testing
Gray Box Testing
External Testing
Which type of penetration test involves evaluating internal vulnerabilities by conducting the test within the organization’s network?
Internal Testing
External Testing
Black Box Testing
Gray Box Testing
In the OWASP Testing Framework, which phase involves actively attempting to exploit identified vulnerabilities to determine their real-world impact?
Information Gathering
Threat Modeling
Vulnerability Scanning
Penetration Testing
In the NIST SP 800-115 process, which phase focuses on setting clear objectives and defining the boundaries of the test?
Information Gathering and Analysis
Planning and Scoping
Vulnerability Assessment
Reporting and Remediation
A testing team has finished identifying vulnerabilities and now needs to summarize their findings, provide recommendations, and track remediation efforts. Which NIST SP 800-115 phase is this?
Penetration Testing
Vulnerability Assessment
Reporting and Remediation
Planning and Scoping
Which activity would be considered active reconnaissance?
Reviewing job postings for IT staff on a company’s careers page
Collecting email addresses from social media profiles
Running an Nmap scan to identify open ports on a target server
Searching for past data breaches in public leak databases
Which phase of the Cyber Kill Chain involves developing malicious tools or exploits to take advantage of identified vulnerabilities?
Reconnaissance
Weaponization
Exploitation
Installation
Which Cyber Kill Chain phase comes immediately after exploitation and typically involves establishing persistence on the target system?
Weaponization
Actions on Objectives
Reconnaissance
Installation
