โ† All EJPT Flashcard Decks

Vulnerability Assessment Flashcards

7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Vulnerability Assessment flashcards as text
  1. When using OpenVAS (Greenbone), what is the first step before running a vulnerability scan?

    Answer: Create a target and select a scan configuration

    In OpenVAS/Greenbone, you must first define a target (IP/host) and choose a scan configuration before initiating any vulnerability scan.

  2. Which vulnerability is associated with the CVE-2014-0160 identifier?

    Answer: Heartbleed

    CVE-2014-0160, known as Heartbleed, is a critical OpenSSL vulnerability that allows attackers to read memory from affected servers.

  3. A scan reveals a service banner showing 'Apache/2.2.8'. What is the most significant security concern?

    Answer: This is an outdated version with known vulnerabilities

    Apache 2.2.8 is a very old version with numerous known CVEs; the version disclosure allows attackers to identify and target specific vulnerabilities.

  4. During vulnerability assessment, which port is associated with the default Microsoft RDP service?

    Answer: 3389

    Remote Desktop Protocol (RDP) runs on TCP port 3389 by default, making it a common target for vulnerability assessment on Windows systems.

  5. What is the significance of identifying end-of-life (EOL) software during a vulnerability assessment?

    Answer: EOL software no longer receives security updates, leaving vulnerabilities permanently unpatched

    End-of-life software no longer receives vendor patches, meaning any discovered vulnerabilities will remain permanently exploitable.

  6. Which Nmap flag enables OS detection during a host scan?

    Answer: -O

    The -O flag enables Nmap's OS detection feature, which uses TCP/IP stack fingerprinting to identify the target's operating system.

  7. What is a vulnerability's 'attack vector' metric in CVSS v3?

    Answer: The context in which the vulnerability can be exploited (e.g., Network, Adjacent, Local, Physical)

    The Attack Vector (AV) metric in CVSS v3 describes the context required to exploit the vulnerability, ranging from Network (remotely exploitable) to Physical (requires physical access).