Font size
S
M
L
XL
Worksheetspentest
Total questions: 119
Worksheet time: 20mins
Name
Class
Date
1.
What is the main purpose of penetration testing?
a)
To identify and exploit vulnerabilities before attackers do
b)
To create malware
c)
To replace vulnerability scanning
d)
To cause disruption to networks
2.
Which analogy best describes pentesting?
a)
A burglar testing the locks of a house with permission
b)
A pilot landing a plane
c)
A firefighter putting out a fire
d)
A doctor curing a patient
3.
What historical group is seen as early pentesters?
a)
Cyber Warriors
b)
Tiger Teams
c)
Cyber Guardians
d)
Black Hats
4.
Which of the following is NOT a purpose of pentesting?
a)
Risk reduction
b)
Compliance requirements
c)
Business assurance
d)
Creating new vulnerabilities
5.
Which breach is often cited as an example where pentesting could have helped?
a)
Yahoo breach
b)
Equifax breach
c)
Twitter hack
d)
Colonial Pipeline attack
6.
Which type of pentest involves no knowledge of the system?
a)
White-box
b)
Black-box
c)
Grey-box
d)
Internal
7.
Which type of pentest provides full knowledge to the tester?
a)
Black-box
b)
External
c)
White-box
d)
Grey-box
8.
Grey-box testing is best described as:
a)
Insider knowledge
b)
No knowledge
c)
Partial knowledge
d)
Full knowledge
9.
Which of the following is NOT a pentest type?
a)
Mobile application
b)
Green-box
c)
Web application
d)
External
10.
Vulnerability scans differ from pentests because they:
a)
Need full access to the system
b)
Require manual creativity
c)
Only report vulnerabilities without proving impact
d)
Always include exploitation
11.
Which of the following is broader than pentesting?
a)
Risk assessment
b)
Vulnerability scanning
c)
Auditing
d)
Red Teaming
12.
Which principle should pentests always follow?
a)
Cause maximum disruption
b)
Avoid harming business operations
c)
Focus only on external systems
d)
Never provide reports
13.
Which principle ensures pentests provide value?
a)
Actionable guidance
b)
Quick scans without details
c)
Stealth operations only
d)
Exploits without remediation
14.
Why is methodology important in pentesting?
a)
To provide consistency and credibility
b)
To skip reporting
c)
To avoid compliance
d)
To make tests random
15.
Which framework is NOT a pentest methodology?
a)
PTES
b)
OWASP
c)
OSSTMM
d)
COBIT
16.
Which is usually the first phase of a pentest?
a)
Pre-Engagement
b)
Reporting
c)
Exploitation
d)
Post-Exploitation
17.
Which pentest phase includes reconnaissance and scanning?
a)
Reporting
b)
Exploitation
c)
Information Gathering
d)
Legal work
18.
What happens during the exploitation phase?
a)
Testing proposals are written
b)
Legal contracts signed
c)
Proof-of-concept of vulnerabilities
d)
Scoping confirmed
19.
Post-exploitation primarily involves:
a)
Creating proposals
b)
Drafting contracts
c)
Impact analysis and lateral movement
d)
Only scanning vulnerabilities
20.
Which phase is often considered the most important?
a)
Exploitation
b)
Reconnaissance
c)
Reporting
d)
Post-Exploitation
21.
Which example shows poor pre-engagement practices?
a)
Testing without client permission
b)
Obtaining authorization
c)
Setting rules of engagement
d)
Defining scope clearly
22.
Which legal case highlighted the importance of pre-engagement?
a)
Marriott breach
b)
Sony hack
c)
Colonial Pipeline attack
d)
Coalfire pentesters arrested in Iowa
23.
What does scoping define?
a)
Compliance documents
b)
Time zones only
c)
Systems in and out of testing
d)
Risk appetite of regulators
24.
Which is NOT a pentest limitation?
a)
Legacy systems
b)
Data confidentiality
c)
Bandwidth restrictions
d)
Time constraints
25.
What law in the US makes unauthorized testing illegal?
a)
HIPAA
b)
DMCA
c)
CFAA
d)
GDPR
26.
Which law in the UK criminalizes unauthorized pentesting?
a)
SOX
b)
PCI DSS
c)
GDPR
d)
CMA
27.
What is the main purpose of Rules of Engagement (RoE)?
a)
Define allowed and disallowed testing actions
b)
Define reporting format
c)
Define budget
d)
Define scope of vulnerabilities
28.
Which activity is usually NOT allowed in RoE?
a)
Password testing
b)
SQL injection PoC
c)
Vulnerability scanning
d)
DoS attacks
29.
What does an incident handling procedure cover?
a)
How to conduct reports
b)
Steps to follow if something goes wrong during pentest
c)
Exploit development methods
d)
Client contracts
30.
Why is it important to have an emergency contact during testing?
a)
To increase network bandwidth
b)
To write reports
c)
To define scope
d)
To coordinate incident handling quickly
31.
What could happen without proper authorization?
a)
Faster testing
b)
Extended engagement
c)
Bonus payment
d)
Arrest, prosecution, lawsuit
32.
What document aligns client goals with methodology?
a)
Proposal
b)
NDA
c)
RoE
d)
Insurance
33.
Which detail is NOT included in a pentest proposal?
a)
Methodology used
b)
Client needs and goals
c)
Exploit code samples
d)
Time estimate
34.
Which document protects sensitive client data discovered during a pentest?
a)
NDA
b)
SLA
c)
MOU
d)
RoE
35.
What type of insurance may clients require before testing?
a)
Auto insurance
b)
Health insurance
c)
Travel insurance
d)
Liability insurance
36.
Why is reporting critical in pentests?
a)
It’s where proof-of-concept stops
b)
It reduces time
c)
It shows impact and provides remediation steps
d)
It removes need for scoping
37.
Which phrase best describes the pentesting lifecycle?
a)
Structured phases from planning to reporting
b)
Random steps taken by testers
c)
Purely legal paperwork
d)
Purely automated scanning
38.
Which of the following is an open-source methodology?
a)
COBIT
b)
ISO 9001
c)
ITIL
d)
OSSTMM
39.
Which is an example of a legal risk in pentesting?
a)
Short timeframe
b)
Too many vulnerabilities
c)
Lack of bandwidth
d)
No clear authorization
40.
What is the final step in a professional pentest engagement?
a)
Reconnaissance
b)
Legal approval
c)
Exploitation
d)
Reporting
41.
According to Sun Tzu, what ensures victory in battle?
a)
Having the best weapons
b)
Knowing the enemy and yourself
c)
Knowing the terrain
d)
Moving quickly
42.
In penetration testing, reconnaissance is also known as:
a)
Escalation
b)
Reporting
c)
Footprinting
d)
Exploitation
43.
Which ancient army is mentioned as an example of reconnaissance?
a)
Egyptian
b)
Greek
c)
Persian
d)
Roman
44.
Reconnaissance in pentesting helps identify:
a)
Operating systems
b)
Attack points with least resistance
c)
Reports
d)
Exploit code
45.
What is the main goal of reconnaissance in a pentest?
a)
Run reports
b)
Patch vulnerabilities
c)
Destroy data
d)
Find the most efficient way to access targets
46.
What can happen if reconnaissance creates too much noise?
a)
Report will be inaccurate
b)
Pentester will lose connection
c)
Network will fail
d)
Target will be alerted
47.
Why is reconnaissance considered the most important stage of hacking?
a)
It increases chances of success
b)
It ends the test
c)
It uses exploits
d)
It is fun
48.
What is passive reconnaissance?
a)
Exploiting servers
b)
Gathering publicly available information
c)
Running brute-force scans
d)
Engaging directly with the target
49.
What is active reconnaissance?
a)
Reading logs from IDS
b)
Gathering public information only
c)
Engaging directly with target systems
d)
Collecting from OSINT databases only
50.
Which example best describes passive collection?
a)
Using brute force to enter a system
b)
Walking into the foreman’s office
c)
Exploiting an SQL database
d)
Going to the library to research information
51.
Which example best describes active collection?
a)
Collecting logs from DNS
b)
Passive OSINT scanning
c)
Entering the loading dock of a building
d)
Reading books in a library
52.
Which type of information is gathered during passive reconnaissance?
a)
Encrypted files
b)
Internal network passwords
c)
Private databases
d)
Data available from public resources
53.
Which framework helps in data mining during recon?
a)
OSINT Framework
b)
PTES
c)
OSSTMM
d)
ISO 27001
54.
Which tool helps visualize relationships during OSINT?
a)
theHarvester
b)
Maltego
c)
Censys
d)
Shodan
55.
Which specialized search engine indexes Internet-connected devices?
a)
Bing
b)
Google
c)
Yahoo
d)
Shodan
56.
Which search engine is similar to Shodan and created at the University of Michigan?
a)
Maltego
b)
Recon-ng
c)
ZoomEye
d)
Censys
57.
Which Shodan feature helps refine results?
a)
Country filters
b)
Boolean filters
c)
Explore button
d)
All of the above
58.
Which of the following is a passive information source?
a)
SQLMap
b)
Shodan
c)
Hydra
d)
Nmap
59.
What is theHarvester mainly used for?
a)
Exploiting SQL databases
b)
Collecting emails and hosts
c)
Detecting firewalls
d)
Cracking passwords
60.
Which protocol does WHOIS use?
a)
TCP port 43
b)
DNS
c)
HTTP
d)
UDP port 161
61.
What does WHOIS primarily provide?
a)
Encrypted traffic details
b)
Domain registration information
c)
SQL logs
d)
Social media accounts
62.
Which command can perform DNS lookups?
a)
nslookup
b)
ping
c)
traceroute
d)
ipconfig
63.
What is a forward DNS lookup?
a)
Resolving an IP to a domain
b)
Resolving a domain to an IP
c)
Running a port scan
d)
Running OS fingerprinting
64.
What is a reverse DNS lookup?
a)
Service enumeration
b)
IP to domain resolution
c)
Port filtering
d)
Domain to IP resolution
65.
Which record type maps a domain to an IPv4 address?
a)
AAAA
b)
A
c)
CNAME
d)
MX
66.
Which record type is used for IPv6 addresses?
a)
SOA
b)
AAAA
c)
TXT
d)
CNAME
67.
Which DNS record type maps an alias name to a domain?
a)
MX
b)
TXT
c)
CNAME
d)
A
68.
Which DNS record specifies mail servers?
a)
MX
b)
TXT
c)
SOA
d)
A
69.
Which DNS record provides administrative domain details?
a)
MX
b)
SOA
c)
CNAME
d)
TXT
70.
Which command tests if a host is alive?
a)
traceroute
b)
whois
c)
ping
d)
nmap -sV
71.
What is the purpose of a ping sweep?
a)
To test OS versions
b)
To find open ports
c)
To discover live hosts in a network
d)
To scan SQL databases
72.
Which improved ping tool is default in Kali Linux?
a)
massping
b)
xping
c)
nping
d)
fping
73.
Which tool performs host discovery at high speed?
a)
Hydra
b)
Maltego
c)
masscan
d)
Shodan
74.
Which tool is widely used for network scanning and port enumeration?
a)
SQLMap
b)
Nikto
c)
Nmap
d)
Hydra
75.
Which Nmap option lists command help?
a)
-O
b)
-V
c)
-sP
d)
-h
76.
Which Nmap scan determines if a host is alive?
a)
SYN scan
b)
Ping scan (-sn)
c)
Version scan
d)
UDP scan
77.
What is the purpose of port scanning?
a)
To run vulnerability reports
b)
To generate OSINT graphs
c)
To evaluate state of ports and services
d)
To collect domain WHOIS info
78.
Which scan type is considered stealthy?
a)
Ping scan
b)
SYN scan
c)
UDP scan
d)
TCP connect scan
79.
Which Nmap feature allows custom detection scripts?
a)
NXS
b)
NSE (Nmap Scripting Engine)
c)
NPT
d)
NSR
80.
Why should targets be defined properly before scanning?
a)
To ensure traceroute works
b)
To avoid firewall bypass
c)
To improve DNS results
d)
To avoid wasting time and noise
81.
Vulnerability assessment is part of which process?
a)
Pentesting lifecycle
b)
Risk appetite analysis
c)
Exploitation phase
d)
Reporting only
82.
What can an attacker do with vulnerabilities?
a)
Patch them
b)
Report them automatically
c)
Exploit them for unauthorized access
d)
Ignore them
83.
Which is an example of a configuration-based vulnerability?
a)
Weak encryption keys
b)
SQL injection
c)
Phishing email
d)
Root directory mounted on NFS
84.
Which is an example of weak/default credentials?
a)
Multi-factor authentication
b)
Biometric password
c)
Username=admin, Password=admin
d)
Encrypted password hash
85.
Which is an example of application logic vulnerability?
a)
SQL injection
b)
Poor authentication mechanism
c)
Malware
d)
Weak firewall rules
86.
Phishing emails are an example of vulnerabilities related to:
a)
Misconfigured routers
b)
Cloud services
c)
Human factor
d)
Operating systems
87.
Privilege escalation vulnerabilities usually exploit:
a)
Email servers
b)
VPN tunnels
c)
Operating systems
d)
Hardware drivers
88.
Which is the current version of CVSS?
a)
3.0
b)
2.0
c)
4.0
d)
3.1
89.
What does CVSS stand for?
a)
Cyber Vulnerability Scoring Scale
b)
Comprehensive Vulnerability Security Scan
c)
Common Vulnerability Scoring System
d)
Central Vulnerability Scan System
90.
What is the main advantage of CVSS for management?
a)
Encrypts all reports
b)
Avoids the need for compliance
c)
Provides numbers and metrics to justify budgets
d)
Automatically patches vulnerabilities
91.
What does CVE stand for?
a)
Common Vulnerabilities and Exposures
b)
Cybersecurity Vulnerability Evaluation
c)
Central Vulnerability Engine
d)
Common Vulnerability Errors
92.
Who maintains the CVE Dictionary?
a)
Microsoft
b)
CVE Numbering Authority (CNA)
c)
Google Security Team
d)
ISO Standards Board
93.
Which organization maintains the National Vulnerability Database (NVD)?
a)
OWASP
b)
NSA
c)
NIST
d)
MITRE
94.
What system does NVD use to score vulnerabilities?
a)
CVE
b)
CWE
c)
CVSS
d)
PCI DSS
95.
CWE is mainly used to classify:
a)
Firewall rules
b)
Antivirus signatures
c)
Security patches
d)
Software weaknesses
96.
How many weaknesses does CWE approximately have?
a)
7,000
b)
70
c)
700+
d)
70,000
97.
Which type of CWE concept is aimed at academics?
a)
Architectural concepts
b)
Design concepts
c)
Development concepts
d)
Research concepts
98.
Which scanner is widely used and has both credentialed and noncredentialed scans?
a)
Hydra
b)
Nmap
c)
Nessus
d)
Wireshark
99.
Which scanner was forked from Nessus and is open source?
a)
SQLMap
b)
Qualys
c)
OpenVAS
d)
Nikto
100.
What does OpenVAS use to run tests?
a)
SQL queries
b)
NASL plugins
c)
LUA scripts
d)
Python scripts
101.
Which OpenVAS component performs scanning?
a)
CVE repository
b)
OSP and back-end engine
c)
Targets module
d)
GSA (web interface)
102.
Nikto is mainly used to scan:
a)
Mobile apps
b)
Networks
c)
Web servers
d)
Databases
103.
Nikto scans for:
a)
Wireless traffic
b)
Passwords in memory
c)
Rootkits
d)
Dangerous files and outdated server software
104.
What is a limitation of Nikto?
a)
It cannot scan web servers
b)
It is stealthy and hard to detect
c)
It is obvious in log files and not stealthy
d)
It is too expensive
105.
Which command displays Nikto’s options?
a)
nikto -config
b)
nikto -options
c)
nikto -Help
d)
nikto -list
106.
SQL injection mainly targets:
a)
VPNs
b)
Firewalls
c)
SQL databases
d)
Operating systems
107.
What is the impact of SQL injection?
a)
Website defacement only
b)
Slower website loading
c)
Control over backend database (credentials, credit cards, data)
d)
Disabling anti-virus
108.
Which tool automates SQL injection testing?
a)
OpenVAS
b)
Hydra
c)
Nessus
d)
SQLMap
109.
What does SQLMap need to test a parameter?
a)
Administrator password
b)
Source code
c)
A VPN tunnel
d)
Vulnerable URL and parameter
110.
Which SQL injection technique does SQLMap often use?
a)
UNION-based
b)
Boolean-based
c)
Error-based
d)
Time-based
111.
Which scanner is part of Greenbone’s GVM framework?
a)
SQLMap
b)
OpenVAS
c)
Nikto
d)
Nessus
112.
Which part of the GVM framework provides user interaction?
a)
Target engine
b)
GSA (Greenbone Security Assistant)
c)
NVT feed
d)
OSP
113.
Which feed provides OpenVAS with updated vulnerability tests?
a)
MITRE feed
b)
Greenbone Community Feed
c)
CWE updates
d)
CVE repository
114.
What is a common problem with vulnerability scanners?
a)
False positives
b)
Too stealthy
c)
Lack of plugins
d)
Always accurate results
115.
Which step comes first in vulnerability scanning?
a)
Exploitation
b)
SQL injection
c)
Determining live hosts and open ports
d)
Reporting
116.
What increases accuracy of vulnerability scanning?
a)
More phishing emails
b)
Accurate port scans
c)
Exploits
d)
A slow internet
117.
What can be customized in scanner configuration?
a)
Firewall rules
b)
Ignore OS vulnerabilities, scan web servers only
c)
User passwords
d)
Antivirus database
118.
What does a vulnerability assessment provide instead of a full pentest?
a)
Proof of exploit impact
b)
Guaranteed security
c)
New malware
d)
Weakness list without exploitation
119.
Which organization defines vulnerability as weaknesses in IT systems?
a)
NCSC
b)
OWASP
c)
MITRE
d)
NIST
Reset
