Vulnerability Analysis
Comprehensive Objective Assessment (Qns &
Ans)
2025
Multiple Choice (MC)
Which tool is best suited for performing advanced buffer
overflow exploitation in a live environment?
A. Nessus
B. Wireshark
C. Immunity Debugger
D. Nikto
ANS: C
Rationale: Immunity Debugger is widely used for analyzing and
exploiting buffer overflows.
©2025
,What is the primary goal of pivoting in a post-exploitation
scenario?
A. Elevate privileges
B. Bypass firewalls
C. Move laterally within a network
D. Gather credentials
ANS: C
Rationale: Pivoting is used to access other machines in the
internal network through a compromised host.
When using SQLmap for SQL injection testing, which parameter
allows the user to specify the risk of payloads?
A. --level
B. --risk
C. --dbms
D. --os-shell
ANS: B
Rationale: The --risk parameter controls the risk level of payloads
sent by SQLmap.
©2025
, A penetration test report lists "CWE-79" for a vulnerability. What
does this refer to?
A. Insecure cryptographic storage
B. Cross-Site Scripting (XSS)
C. Broken authentication
D. Buffer overflow
ANS: B
Rationale: CWE-79 specifically refers to Cross-Site Scripting
vulnerabilities.
Which of the following is NOT typically considered a method to
evade Network Intrusion Detection Systems (NIDS)?
A. Packet fragmentation
B. Tunneling traffic over DNS
C. Using encrypted tunnels
D. Avoiding use of TCP/IP protocols
ANS: D
Rationale: All traffic uses TCP/IP protocols; the other options are
valid NIDS evasion techniques.
Which of the following frameworks is primarily used for
managing the lifecycle of penetration testing engagements?
©2025