eJPT Exam Fundamentals and Penetration Testing Methodology Flashcards
6 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 eJPT Exam Fundamentals and Penetration Testing Methodology flashcards as text
What is the purpose of the CVSS score in penetration testing reports?
Answer: To standardize the severity rating of vulnerabilities on a numeric scale
CVSS (Common Vulnerability Scoring System) provides a standardized 0–10 numeric score reflecting the severity of a vulnerability.
Which environment is the eJPT exam conducted in?
Answer: A fully hands-on virtual lab with real target machines
The eJPT exam is a fully practical, hands-on assessment conducted in a virtual lab environment with real targets to attack.
In penetration testing methodology, what does 'scope creep' refer to?
Answer: Testing systems or assets outside the agreed-upon scope
Scope creep occurs when a tester interacts with systems outside the authorized target list, which is unauthorized and potentially illegal.
What is the significance of the /etc/hosts file in eJPT lab exercises?
Answer: It maps hostnames to IP addresses locally, enabling domain-based lab navigation
The /etc/hosts file provides local hostname-to-IP resolution, which eJPT labs use so testers can reach targets by hostname.
Which statement best describes the concept of 'least privilege' in the context of penetration testing findings?
Answer: Ensuring users and services have only the minimum permissions needed to perform their function
Least privilege limits access rights to the minimum necessary, reducing the attack surface and limiting damage from compromised accounts.
When writing up eJPT exam findings, what must be included to prove a vulnerability was successfully exploited?
Answer: Proof of concept (PoC) screenshots or command output showing successful exploitation
Proof of concept evidence such as screenshots or command output showing successful exploitation is required to validate findings in any pentest report.