โ† All CCP Flashcard Decks

Vulnerability Assessment & Penetration Testing Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Vulnerability Assessment & Penetration Testing flashcards as text
  1. What is a 'false positive' in vulnerability scanning?

    Answer: A scan result that reports a vulnerability that does not actually exist on the target

    A false positive occurs when a vulnerability scanner incorrectly reports a vulnerability that does not actually exist on the scanned system, requiring manual validation to filter out inaccurate findings.

  2. Which phase of penetration testing involves using tools like Shodan, WHOIS, and LinkedIn to collect target information before active scanning?

    Answer: Reconnaissance

    Reconnaissance (also called information gathering) is the first phase of penetration testing, where testers collect as much information as possible about the target using both passive and active techniques before launching attacks.

  3. A SQL injection attack works by:

    Answer: Injecting malicious SQL queries into user-supplied input fields to manipulate a backend database

    SQL injection inserts or 'injects' malicious SQL code into input fields that are passed to a backend database, potentially allowing attackers to read, modify, or delete data and bypass authentication.

  4. What is the purpose of the CVE (Common Vulnerabilities and Exposures) system?

    Answer: To provide a publicly available catalog of known cybersecurity vulnerabilities with unique identifiers

    CVE provides a standardized list of publicly disclosed cybersecurity vulnerabilities, each assigned a unique identifier (e.g., CVE-2021-44228), enabling consistent communication across tools, vendors, and security teams.

  5. What does 'privilege escalation' mean in the context of penetration testing?

    Answer: Gaining higher-level permissions on a system than those initially obtained during exploitation

    Privilege escalation is the process of exploiting a vulnerability or misconfiguration to gain elevated permissions (e.g., moving from a standard user to Administrator or root) on a system already accessed.

  6. Which web application penetration testing tool acts as an intercepting proxy, allowing testers to inspect and modify HTTP/HTTPS traffic between a browser and a web server?

    Answer: Burp Suite

    Burp Suite is a comprehensive web application testing platform that includes an intercepting proxy to capture, inspect, and modify HTTP/HTTPS requests and responses in real time.

  7. A buffer overflow vulnerability occurs when:

    Answer: A program writes more data to a buffer than it was allocated, potentially overwriting adjacent memory and allowing code execution

    A buffer overflow happens when a program writes data beyond the allocated memory buffer boundary, overwriting adjacent memory regions, which can enable an attacker to overwrite return addresses and execute arbitrary code.