โ† All EJPT Flashcard Decks

Vulnerability Scanning Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Vulnerability Scanning flashcards as text
  1. What information does the '-sV' flag in Nmap provide during a vulnerability assessment?

    Answer: Service name and version running on open ports

    The -sV flag enables version detection, causing Nmap to probe open ports to identify the software name and version running on each service.

  2. Which vulnerability database is most commonly referenced by tools like Nessus and OpenVAS when reporting findings?

    Answer: CVE (Common Vulnerabilities and Exposures)

    CVE is the industry-standard dictionary of publicly known vulnerabilities, and scanners use CVE identifiers to reference specific vulnerabilities in their reports.

  3. In the context of vulnerability scanning, what is 'network enumeration' typically performed before?

    Answer: Vulnerability scanning itself

    Network enumeration discovers live hosts, open ports, and services before the vulnerability scan, so the scanner knows exactly what targets to assess.

  4. Which eJPT-relevant tool is used to perform automated web application vulnerability scanning and can detect issues like SQL injection and XSS?

    Answer: Nikto

    Nikto scans web servers for dangerous files, outdated software versions, and common vulnerabilities including some injection and XSS vectors.

  5. What does a vulnerability scan report typically include that helps prioritize remediation efforts?

    Answer: Severity ratings and CVSS scores for each finding

    Vulnerability scan reports assign severity ratings and CVSS scores to each finding, enabling security teams to prioritize patching the highest-risk issues first.

  6. When running Nmap with the '-A' flag, which combination of features is enabled?

    Answer: OS detection, version detection, script scanning, and traceroute

    The -A flag enables aggressive mode, combining OS detection (-O), version detection (-sV), script scanning (-sC), and traceroute in one command.

  7. What is the significance of the NVT (Network Vulnerability Test) database in OpenVAS?

    Answer: It contains the collection of vulnerability test scripts used to check targets

    The NVT database is OpenVAS's library of vulnerability test scripts, equivalent to Nessus plugins, and must be kept updated for accurate scanning.

Vulnerability Scanning Flashcards โ€” EJPT Study Cards with Answers