Vulnerability Assessment Flashcards
7 cards from real EJPT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Vulnerability Assessment flashcards as text
Which of the following describes a 'zero-day' vulnerability?
Answer: A vulnerability unknown to the vendor with no available patch
A zero-day vulnerability is one that is unknown to the software vendor or has no official patch available, making it especially dangerous.
During a vulnerability assessment, you identify port 23 open on a network device. What is the primary security concern?
Answer: Telnet transmits data including credentials in plaintext
Telnet (port 23) sends all data, including usernames and passwords, in unencrypted plaintext, making it vulnerable to network sniffing attacks.
What is the role of the National Vulnerability Database (NVD) in vulnerability assessment?
Answer: It is the U.S. government repository of CVE vulnerability data with CVSS scores
The NVD is maintained by NIST and provides a comprehensive database of CVE entries enriched with CVSS scores, CWE identifiers, and remediation guidance.
Which technique involves sending specially crafted packets to determine if a host is filtering, closed, or open on specific ports?
Answer: Port scanning
Port scanning sends packets to target ports and analyzes responses to determine whether ports are open, closed, or filtered by a firewall.
You discover SMB signing is disabled on a Windows host. Which attack does this enable?
Answer: NTLM relay attacks
When SMB signing is disabled, an attacker can capture and relay NTLM authentication to authenticate to other services as the victim (NTLM relay attack).
What information does the 'searchsploit' tool help a penetration tester find?
Answer: Local copies of public exploits and shellcodes from Exploit-DB
Searchsploit is a command-line tool that searches a local copy of the Exploit-DB archive for public exploits and shellcodes matching a given service or software.
Which of the following is the correct order of steps in a typical vulnerability assessment workflow?
Answer: Scan → Enumerate → Identify vulnerabilities → Report findings
A standard vulnerability assessment follows: scan for open services, enumerate service details, identify vulnerabilities against findings, then document and report results.