← All EJPT Flashcard Decks

Vulnerability Scanning Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Vulnerability Scanning flashcards as text
  1. Which Nmap script category is most useful for identifying known vulnerabilities during a scan?

    Answer: vuln

    The 'vuln' script category in Nmap runs scripts specifically designed to check for known vulnerabilities on target services.

  2. What does the term 'false positive' mean in the context of vulnerability scanning?

    Answer: A reported vulnerability that does not actually exist

    A false positive occurs when a scanner reports a vulnerability that is not actually present on the target system.

  3. Which OpenVAS component is responsible for executing the actual vulnerability tests against targets?

    Answer: OpenVAS Scanner

    The OpenVAS Scanner daemon (ospd-openvas) executes the Network Vulnerability Tests (NVTs) against target hosts.

  4. When scanning for vulnerabilities on a web application, which tool is specifically designed for this purpose?

    Answer: Nikto

    Nikto is a web server scanner that checks for dangerous files, outdated software, and common web vulnerabilities.

  5. What is the primary difference between a credentialed and a non-credentialed vulnerability scan?

    Answer: Credentialed scans use valid login credentials to access the system internally, finding more vulnerabilities

    Credentialed scans authenticate to the target system, enabling deeper inspection of installed software, configurations, and patches that external scans cannot see.

  6. Which CVSSv3 score range is classified as 'Critical' severity?

    Answer: 9.0 – 10.0

    CVSSv3 defines Critical severity as scores from 9.0 to 10.0, representing the highest risk vulnerabilities.

  7. What Nmap flag enables OS detection during a vulnerability assessment scan?

    Answer: -O

    The -O flag instructs Nmap to attempt OS fingerprinting by analyzing TCP/IP stack responses from the target.