โ† All EJPT Flashcard Decks

Vulnerability Scanning Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Vulnerability Scanning flashcards as text
  1. In Nessus, what is a 'plugin' used for?

    Answer: A script that checks for a specific vulnerability or configuration issue

    Nessus plugins are individual test scripts, each targeting a specific vulnerability, misconfiguration, or information-gathering check.

  2. Which scanning technique sends packets and waits for responses to determine if a port is open, without completing the TCP handshake?

    Answer: SYN Scan (Half-open)

    A SYN scan (half-open scan) sends a SYN packet and analyzes the response without completing the three-way handshake, making it stealthier.

  3. What does CVSS stand for in vulnerability management?

    Answer: Common Vulnerability Scoring System

    CVSS stands for Common Vulnerability Scoring System, providing a standardized method to rate the severity of security vulnerabilities.

  4. Which of the following is a key risk of running an aggressive vulnerability scan against a production system?

    Answer: Scan probes may crash unstable services or cause denial of service

    Aggressive scans send many packets rapidly and some intrusive checks can destabilize vulnerable services, causing outages on production systems.

  5. What is the purpose of a vulnerability scan policy or template in tools like Nessus?

    Answer: To define the scope, plugins, and settings used during a scan

    Scan policies or templates configure which plugins run, scan speed, credentials, and port ranges, tailoring the scan to a specific use case.

  6. During a network vulnerability scan, which protocol is commonly used to scan for vulnerabilities in network devices like routers and switches?

    Answer: SNMP

    SNMP (Simple Network Management Protocol) is used to query and manage network devices, and misconfigurations in SNMP are commonly checked during vulnerability scans.

  7. What does the Nmap command 'nmap --script vuln ' do?

    Answer: Runs all scripts in the 'vuln' NSE category against the target

    Using '--script vuln' tells Nmap to execute all NSE scripts tagged with the 'vuln' category, checking for known vulnerabilities on open ports.