eJPT Exam Fundamentals and Penetration Testing Methodology Flashcards
6 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 eJPT Exam Fundamentals and Penetration Testing Methodology flashcards as text
Which tool is most commonly used in eJPT labs to test connectivity and basic network reachability?
Answer: ping
The ping command sends ICMP echo requests to verify that a target host is reachable over the network.
What does the term 'attack surface' refer to in penetration testing?
Answer: All possible entry points an attacker could use to compromise a system
The attack surface encompasses all exposed points — open ports, services, interfaces, and input vectors — that an attacker could exploit.
During an eJPT exam, which notation is used to describe an IP address with its subnet mask in CIDR format?
Answer: 192.168.1.1/24
CIDR (Classless Inter-Domain Routing) notation combines the IP address and prefix length with a slash, e.g., 192.168.1.1/24.
What is the recommended first step when you gain access to a new network segment during an eJPT lab?
Answer: Enumerate the new segment by scanning for live hosts and services
When pivoting to a new network segment, enumeration of live hosts and services helps build a complete picture before exploitation.
What is a 'false positive' in the context of vulnerability scanning?
Answer: A result that incorrectly identifies a vulnerability that does not actually exist
A false positive is when a scanner reports a vulnerability that does not actually exist, requiring manual verification to confirm findings.
Which type of report section documents the specific vulnerabilities found, their severity, and remediation steps?
Answer: Technical Findings
The Technical Findings section of a pentest report details each vulnerability, its CVSS score, proof of exploitation, and recommended fixes.