← All EJPT Flashcard Decks

Vulnerability Assessment Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Vulnerability Assessment flashcards as text
  1. Which Nmap script category is most useful for detecting known vulnerabilities during a vulnerability assessment?

    Answer: vuln

    The 'vuln' script category contains NSE scripts specifically designed to check for known vulnerabilities in services.

  2. What does a CVSS score of 9.8 indicate about a vulnerability?

    Answer: Critical severity requiring immediate attention

    A CVSS score of 9.8 falls in the Critical range (9.0–10.0), indicating the vulnerability poses an extreme risk and requires immediate remediation.

  3. During a vulnerability scan, you find an open port 445 on a Windows host. Which vulnerability should you prioritize checking for?

    Answer: EternalBlue (MS17-010)

    Port 445 is used by SMB, and EternalBlue (MS17-010) is a critical SMB vulnerability that enables remote code execution on unpatched Windows systems.

  4. What is the primary purpose of credentialed scanning versus uncredentialed scanning?

    Answer: Credentialed scans provide deeper visibility into installed software and local configurations

    Credentialed scans authenticate to the target, allowing inspection of installed patches, software versions, and local settings that are invisible from the network.

  5. Which tool is commonly used for web application vulnerability scanning during an eJPT-level assessment?

    Answer: Nikto

    Nikto is a web server scanner that checks for dangerous files, outdated software, and common misconfigurations in web applications.

  6. What does the term 'false positive' mean in the context of vulnerability scanning?

    Answer: A vulnerability reported by the scanner that does not actually exist

    A false positive is when a vulnerability scanner reports a vulnerability that does not actually exist on the target system.

  7. Which of the following best describes passive vulnerability assessment?

    Answer: Analyzing network traffic and banners without actively probing the target

    Passive vulnerability assessment involves observing and analyzing existing traffic, banners, and data without sending additional probes to the target.