← All EJPT Flashcard Decks

eJPT Exam Fundamentals and Penetration Testing Methodology Flashcards

6 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 eJPT Exam Fundamentals and Penetration Testing Methodology flashcards as text
  1. What is the correct order of phases in a standard penetration testing methodology?

    Answer: Reconnaissance → Scanning → Exploitation → Post-Exploitation → Reporting

    The standard pentest flow is Reconnaissance → Scanning → Exploitation → Post-Exploitation → Reporting to ensure structured, thorough testing.

  2. What is the eJPT certification primarily designed to validate?

    Answer: Junior-level practical penetration testing skills

    The eJPT (eLearnSecurity Junior Penetration Tester) validates foundational, practical hands-on penetration testing skills at the junior level.

  3. What type of engagement is a penetration test where the tester has full knowledge of the target environment, including source code and architecture?

    Answer: White-box testing

    White-box testing provides the tester with full knowledge of the system, including network diagrams, credentials, and source code.

  4. Which document formally authorizes a penetration tester to conduct testing against a client's systems?

    Answer: Rules of Engagement (RoE) / Scope of Work

    The Rules of Engagement or Scope of Work document defines authorized targets, methods, and timing, legally permitting the pentest.

  5. In a black-box penetration test, what information is provided to the tester at the start?

    Answer: Only the target IP range or domain

    In black-box testing, the tester receives minimal information (typically just the target scope) to simulate an external attacker.

  6. What is the main goal of a penetration test compared to a vulnerability assessment?

    Answer: Actively exploit vulnerabilities to demonstrate real-world impact

    A penetration test goes beyond listing vulnerabilities by actively exploiting them to demonstrate actual risk and business impact.