C795 Chapter 15 Questions
1. Which one of the following tools is used primarily to perform network discovery
scans?
A. Nmap
B. OpenVAS
C. Metasploit Framework
D. lsof - answer A. Nmap
OpenVAS is a network vulnerability scanning tool.
Metasploit Framework is an exploitation framework used in penetration testing.
lsof is a Linux command used to list open files on a system.
2. Adam recently ran a network port scan of a web server running in his organization.
He ran the scan from an external network to get an attacker's perspective on the scan.
Which one of the following results is the greatest cause for alarm?
A. 80/open
B. 22/filtered
C. 443/open
D. 1433/open - answerD. 1433/open
3. Which one of the following factors should not be taken into consideration when
planning a security testing schedule for a particular system?
A. Sensitivity of the information stored on the system
B. Difficulty of performing the test
C. Desire to experiment with new testing tools
D. Desirability of the system to attackers - answerC. Desire to experiment with new
testing tools
4. Which one of the following is not normally included in a security assessment?
A. Vulnerability scan
B. Risk assessment
C. Mitigation of vulnerabilities
D. Threat assessment - answerC. Mitigation of vulnerabilities
5. Who is the intended audience for a security assessment report?
A. Management
B. Security auditor
C. Security professional
D. Customers - answerC. Security professional
6. Wendy is considering the use of a vulnerability scanner in her organization. What is
the proper role of a vulnerability scanner?
A. They actively scan for intrusion attempts.
1. Which one of the following tools is used primarily to perform network discovery
scans?
A. Nmap
B. OpenVAS
C. Metasploit Framework
D. lsof - answer A. Nmap
OpenVAS is a network vulnerability scanning tool.
Metasploit Framework is an exploitation framework used in penetration testing.
lsof is a Linux command used to list open files on a system.
2. Adam recently ran a network port scan of a web server running in his organization.
He ran the scan from an external network to get an attacker's perspective on the scan.
Which one of the following results is the greatest cause for alarm?
A. 80/open
B. 22/filtered
C. 443/open
D. 1433/open - answerD. 1433/open
3. Which one of the following factors should not be taken into consideration when
planning a security testing schedule for a particular system?
A. Sensitivity of the information stored on the system
B. Difficulty of performing the test
C. Desire to experiment with new testing tools
D. Desirability of the system to attackers - answerC. Desire to experiment with new
testing tools
4. Which one of the following is not normally included in a security assessment?
A. Vulnerability scan
B. Risk assessment
C. Mitigation of vulnerabilities
D. Threat assessment - answerC. Mitigation of vulnerabilities
5. Who is the intended audience for a security assessment report?
A. Management
B. Security auditor
C. Security professional
D. Customers - answerC. Security professional
6. Wendy is considering the use of a vulnerability scanner in her organization. What is
the proper role of a vulnerability scanner?
A. They actively scan for intrusion attempts.