Question 1 of 15 Engagement Management
Which document defines the systems, methods, and boundaries a penetration tester is authorized to test?
A A rules of engagement document B A vulnerability scan report C An incident response plan D A data retention policy
Question 2 of 15 Engagement Management
Why must a penetration tester obtain written authorization before testing begins?
A Because testing without authorization is illegal unauthorized access B To qualify for a discount on tools C To speed up the network scan D To avoid writing a final report
Question 3 of 15 Reconnaissance and Enumeration
A tester gathers employee names and email formats from a company website and LinkedIn without sending any packets to target systems. What is this called?
A Passive reconnaissance B Active exploitation C Privilege escalation D Lateral movement
Question 4 of 15 Reconnaissance and Enumeration
Which tool is most commonly used to discover live hosts and open ports during network enumeration?
A Nmap B Wireshark C John the Ripper D Burp Suite
Question 5 of 15 Attacks and Exploits
A tester finds a web input that returns database errors when a single quote is submitted. Which vulnerability should be investigated?
A Clickjacking B SQL injection C ARP spoofing D DNS amplification
Question 6 of 15 Attacks and Exploits
After gaining a low-privilege shell on a Linux host, a tester searches for misconfigured SUID binaries and weak sudo rules. What is the goal of this activity?
A Initial reconnaissance B Report writing C Scope definition D Privilege escalation
Question 7 of 15 Attacks and Exploits
Which attack captures and reuses a valid authentication hash to access a system without cracking the password?
A Phishing B SQL injection C Directory traversal D Pass-the-hash
Question 8 of 15 Attacks and Exploits
A social engineering test sends employees a crafted email hoping they click a malicious link. Which technique is this?
A Port scanning B Fuzzing C Phishing D War driving
Question 9 of 15 Post-exploitation and Reporting
Which section of a penetration test report is written for executives who need to understand business impact without technical detail?
A The raw tool output appendix B The methodology section C The executive summary D The exploit proof-of-concept code
Question 10 of 15 Post-exploitation and Reporting
After finishing an engagement, why should a tester remove any accounts, tools, and backdoors they created?
A To hide evidence of the test from the client B To reduce the size of the final report C To restore the environment to its original state and avoid leaving new risk D To free disk space on the tester laptop
Question 11 of 15 Post-exploitation and Reporting
Which finding should typically be prioritized first for remediation in a penetration test report?
A An informational note about a missing HTTP header on an internal test box B A low-severity banner disclosure on a printer C A critical vulnerability on an internet-facing server with a public exploit D A cosmetic typo on an intranet page
Question 12 of 15 Engagement Management
What is the main purpose of maintaining detailed notes and timestamps throughout an engagement?
A To bill the client for more hours B To support an accurate, reproducible report and evidence trail C To share exploits publicly afterward D To replace the rules of engagement
Question 13 of 15 Engagement Management
A client asks the tester to also assess a subsidiary domain that was not listed in the agreed scope. What is the correct action?
A Test it immediately since the client asked verbally B Ignore the request entirely C Test it but leave it out of the report D Pause and get the scope formally amended in writing before testing it
Question 14 of 15 Engagement Management
Which practice reduces the risk that an active exploit will disrupt production systems during a test?
A Running every exploit at maximum intensity during business hours B Coordinating testing windows and validating exploits in a safe manner per the rules of engagement C Skipping communication with the client D Testing only after systems have already crashed
Question 15 of 15 Reconnaissance and Enumeration
A penetration tester gathers information about a target using only publicly available sources such as search engines and social media. What is this technique called?
A Active exploitation B Open source intelligence gathering C Privilege escalation D Denial of service