Vulnerability Assessment Flashcards
6 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Vulnerability Assessment flashcards as text
A penetration tester is conducting a vulnerability assessment and wants to simulate the perspective of an external attacker with no prior knowledge of the internal network. Which type of scan would be MOST appropriate for this objective?
Answer: Unauthenticated scan
An unauthenticated scan is performed without any special credentials or privileges. It mimics how an external attacker would see the system, identifying vulnerabilities that are exposed to the public internet without any login access.
During a vulnerability assessment, a junior penetration tester uses a tool that actively sends specially crafted packets to target systems to elicit responses and identify potential weaknesses. This method, however, risks disrupting network operations. Which vulnerability scanning technique is being used?
Answer: Active scanning
Active scanning involves directly interacting with target systems by sending probes, packets, and queries to gather information and identify vulnerabilities. This direct interaction makes it more thorough but also carries a risk of impacting the performance or stability of the targeted network or services.
Which of the following is the PRIMARY purpose of the Common Vulnerability Scoring System (CVSS)?
Answer: To offer a standardized framework for rating the severity of vulnerabilities.
The primary purpose of CVSS is to provide a standardized, open framework for communicating the characteristics and severity of software vulnerabilities. It assigns a numerical score from 0-10 to help organizations prioritize their response and remediation efforts.
A penetration tester needs to perform a vulnerability scan that provides the most comprehensive and accurate view of a system's security posture by looking at its configuration, patch levels, and installed software from an 'insider' perspective. Which scanning method should be chosen?
Answer: Authenticated scan
An authenticated (or credentialed) scan uses valid user credentials to log into the target system. This allows the scanner to access the file system, configuration settings, and installed software list, providing a much more detailed and accurate report on vulnerabilities like missing patches and misconfigurations that are not visible externally.
While Nmap is primarily known as a network port scanner, its capabilities can be extended to perform vulnerability assessments using which of its features?
Answer: The Nmap Scripting Engine (NSE)
The Nmap Scripting Engine (NSE) allows users to write and use scripts to automate a wide variety of networking tasks. A specific category of these scripts, often invoked with '--script vuln', is designed to check for known vulnerabilities on the target services.
A security analyst is comparing vulnerability assessment tools. One tool, Nessus, is primarily known as a dedicated vulnerability scanner. Another tool, Nmap, is primarily a network discovery and port scanner. What is a key advantage of using a dedicated scanner like Nessus over Nmap for vulnerability assessment?
Answer: Nessus provides more comprehensive and detailed vulnerability reports with remediation suggestions.
While Nmap's NSE can find some vulnerabilities, dedicated scanners like Nessus are built specifically for this purpose. They have extensive, regularly updated vulnerability databases (plugins) and provide detailed reports that include risk scores, evidence of the vulnerability, and actionable remediation advice, which is a key differentiator from Nmap's primary function.