← All CCP Flashcard Decks

Vulnerability Assessment & Penetration Testing Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Vulnerability Assessment & Penetration Testing flashcards as text
  1. What is the primary difference between a vulnerability assessment and a penetration test?

    Answer: A vulnerability assessment identifies and prioritizes weaknesses without exploiting them, while a penetration test attempts to actively exploit them

    A vulnerability assessment identifies, classifies, and prioritizes vulnerabilities without exploiting them, while a penetration test goes further by actively attempting to exploit weaknesses to determine real-world impact.

  2. Which CVSS v3.1 score range is classified as 'Critical' severity?

    Answer: 9.0 – 10.0

    CVSS v3.1 defines Critical severity as scores from 9.0 to 10.0, representing vulnerabilities that are most severe and typically easily exploitable with devastating impact.

  3. During a penetration test, what does 'pivoting' refer to?

    Answer: Using a compromised host as a launching point to attack other systems within the network

    Pivoting uses a compromised system as a relay or jump point to reach and attack other systems on the internal network that are not directly accessible from the attacker's position.

  4. What type of penetration test provides the tester with full knowledge of the target environment, including network diagrams, source code, and credentials?

    Answer: White-box test

    A white-box (or crystal/glass-box) penetration test gives the tester complete knowledge of the target environment, enabling thorough and efficient testing of the entire attack surface.

  5. Which tool is most commonly used for automated network vulnerability scanning in enterprise environments?

    Answer: Nessus

    Nessus (by Tenable) is the industry-standard automated vulnerability scanner used to detect misconfigurations, missing patches, and known CVEs across network hosts.

  6. What does the OWASP Top 10 primarily focus on?

    Answer: The ten most critical security risks for web applications

    The OWASP Top 10 is a standard awareness document listing the ten most critical security risks specifically affecting web applications, updated periodically based on industry data.

  7. In the context of penetration testing, what is 'passive reconnaissance'?

    Answer: Gathering information about a target using publicly available sources without directly interacting with the target's systems

    Passive reconnaissance collects information about a target through open-source intelligence (OSINT), DNS lookups, and public records without sending any traffic directly to the target, leaving no trace on their systems.