WGU D484 (Latest Update )
Penetration Testing Questions & Answers
{Grade A} 100% Correct
Administrative controls - Correct answer security measures implemented to monitor
the adherence to organizational policies and procedures. Those include activities such
as hiring and termination policies, employee training along with creating business
continuity and incident response plans.
Physical controls - Correct answer restrict, detect and monitor access to specific
physical areas or assets. Methods include barriers, tokens, biometrics or other
controls such as ensuring the server room doors are properly locked, along with using
surveillance cameras and access cards.
Technical or logical controls - Correct answer automate protection to prevent
unauthorized access or misuse, and include Access Control Lists (ACL), and Intrusion
Detection System (IDS)/ Intrusion Prevention System (IPS) signatures and
antimalware protection that are implemented as a system hardware, software, or
firmware solution.
,What is the primary goal of PenTesting? - Correct answer Reduce overall risk by taking
proactive steps to reduce vulnerabilities.
Principle of Least Privilege - Correct answer Basic principle of security stating that
something should be allocated the minimum necessary rights, privileges, or
information to perform its role.
Risk - Correct answer Likelihood and impact (or consequence) of a threat actor
exercising a vulnerability.
Threat - Correct answer represents something such as malware or a natural disaster,
that can accidentally or intentionally exploit a vulnerability and cause undesirable
results.
Vulnerability - Correct answer is a weakness or flaw, such as a software bug, system
flaw, or human error. A vulnerability can be exploited by a threat
,Risk Analysis - Correct answer is a security process used to assess risk damages that
can affect an organization.
Unified Threat Management (UTM) - Correct answer All-in-one security appliances and
agents that combine the functions of a firewall, malware scanner, intrusion detection,
vulnerability scanner, data loss prevention, content filtering, and so on.
Main steps of the structured PenTesting Process: - Correct answer Planning and
scoping, Reconnaissance, Scanning, Gaining Access, Maintaining Access, Covering
Tracks, Analysis, Reporting
Unauthorized Hacker - Correct answer A hacker operating with malicious intent.
Payment Card Industry Data Security Standard (PCI DSS) - Correct answer Information
security standard for organizations that process credit or bank card payments.
An organization must do the following in order to protect cardholder data: - Correct
answer Maintain secure infrastructure using dedicated appliances and software to
, monitor and prevent attacks. Implement best practices like changing default
passwords, educating users on email safety, and continuously monitoring for
vulnerabilities with updated anti-malware protection. Enforce strict access controls
through the principle of least privilege and regularly test and monitor networks.
PCI DSS Level 1 - Correct answer Large merchant with over six million transactions a
year and external auditor by a Qualified Security Assessor (QSA), must complete a
RoC.
PCI DSS Level 2 - Correct answer merchant with one to six million transactions a year,
must complete a RoC.
PCI DSS Level 3 - Correct answer merchant with 20000 to one million transactions a
year
PCI DSS Level 4 - Correct answer small merchant with under 20000 transactions a
year
Penetration Testing Questions & Answers
{Grade A} 100% Correct
Administrative controls - Correct answer security measures implemented to monitor
the adherence to organizational policies and procedures. Those include activities such
as hiring and termination policies, employee training along with creating business
continuity and incident response plans.
Physical controls - Correct answer restrict, detect and monitor access to specific
physical areas or assets. Methods include barriers, tokens, biometrics or other
controls such as ensuring the server room doors are properly locked, along with using
surveillance cameras and access cards.
Technical or logical controls - Correct answer automate protection to prevent
unauthorized access or misuse, and include Access Control Lists (ACL), and Intrusion
Detection System (IDS)/ Intrusion Prevention System (IPS) signatures and
antimalware protection that are implemented as a system hardware, software, or
firmware solution.
,What is the primary goal of PenTesting? - Correct answer Reduce overall risk by taking
proactive steps to reduce vulnerabilities.
Principle of Least Privilege - Correct answer Basic principle of security stating that
something should be allocated the minimum necessary rights, privileges, or
information to perform its role.
Risk - Correct answer Likelihood and impact (or consequence) of a threat actor
exercising a vulnerability.
Threat - Correct answer represents something such as malware or a natural disaster,
that can accidentally or intentionally exploit a vulnerability and cause undesirable
results.
Vulnerability - Correct answer is a weakness or flaw, such as a software bug, system
flaw, or human error. A vulnerability can be exploited by a threat
,Risk Analysis - Correct answer is a security process used to assess risk damages that
can affect an organization.
Unified Threat Management (UTM) - Correct answer All-in-one security appliances and
agents that combine the functions of a firewall, malware scanner, intrusion detection,
vulnerability scanner, data loss prevention, content filtering, and so on.
Main steps of the structured PenTesting Process: - Correct answer Planning and
scoping, Reconnaissance, Scanning, Gaining Access, Maintaining Access, Covering
Tracks, Analysis, Reporting
Unauthorized Hacker - Correct answer A hacker operating with malicious intent.
Payment Card Industry Data Security Standard (PCI DSS) - Correct answer Information
security standard for organizations that process credit or bank card payments.
An organization must do the following in order to protect cardholder data: - Correct
answer Maintain secure infrastructure using dedicated appliances and software to
, monitor and prevent attacks. Implement best practices like changing default
passwords, educating users on email safety, and continuously monitoring for
vulnerabilities with updated anti-malware protection. Enforce strict access controls
through the principle of least privilege and regularly test and monitor networks.
PCI DSS Level 1 - Correct answer Large merchant with over six million transactions a
year and external auditor by a Qualified Security Assessor (QSA), must complete a
RoC.
PCI DSS Level 2 - Correct answer merchant with one to six million transactions a year,
must complete a RoC.
PCI DSS Level 3 - Correct answer merchant with 20000 to one million transactions a
year
PCI DSS Level 4 - Correct answer small merchant with under 20000 transactions a
year