Vulnerability Scanning Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Vulnerability Scanning flashcards as text
Which of the following best describes a 'zero-day' vulnerability in the context of vulnerability scanning?
Answer: A vulnerability unknown to the vendor with no available patch
A zero-day vulnerability is one that is unknown to the software vendor or has no patch available, making it particularly dangerous.
What is the main advantage of using Masscan over Nmap for initial reconnaissance in a large network assessment?
Answer: Masscan is capable of scanning the entire internet in minutes due to its asynchronous design
Masscan uses an asynchronous, stateless design that allows it to send millions of packets per second, making it significantly faster than Nmap for large-scale port scanning.
During a vulnerability scan, you discover an SMB service running on port 445. Which well-known vulnerability should you specifically check for on unpatched Windows systems?
Answer: EternalBlue (MS17-010)
EternalBlue (MS17-010) is a critical SMB vulnerability exploited by WannaCry and NotPetya, and is a standard check when SMB is discovered on unpatched Windows hosts.
What does the term 'attack surface' mean in the context of vulnerability scanning?
Answer: All the possible points where an attacker could try to enter or extract data from a system
The attack surface encompasses all entry points and exposed interfaces — open ports, services, APIs, and user inputs — that an attacker could potentially exploit.
Which scan type in Nmap is used specifically to scan UDP ports?
Answer: -sU
The -sU flag tells Nmap to perform a UDP scan, which is important for discovering services like DNS, SNMP, and DHCP that run over UDP.
What is the purpose of performing a vulnerability scan after applying patches to a system?
Answer: Both B and C are correct reasons
Post-patch scanning both verifies that target vulnerabilities are remediated and checks whether patches introduced new issues or changed the system's security posture.
In Nessus scan results, what does a 'High' severity finding typically indicate?
Answer: A vulnerability that is easily exploitable and could lead to significant compromise
High severity findings represent vulnerabilities with significant exploitability or impact, often with known exploits, requiring prompt remediation.