Test Bank Midterm Exam 2026-2027 ||Newest
Exam With Complete Questions & Accurate
Detailed Answers (Rationales) Latest Update!!
Best for Midterm Exam prep
1. Which two tools could be used to gather DNS information passively?
(Choose two.)
- Recon-ng
- Dig
2. When performing passive reconnaissance, which Linux command can
be used to identify the technical and administrative contacts of a given
domain?
whois
3. Which specification defines the format used by image and sound files
to capture metadata?
Exchangeable Image File Format (Exif)
,4. Why would a penetration tester perform a passive reconnaissance
scan instead of an active one?
to collect information about a network without being detected
5. What type of server is a penetration tester enumerating when they
enter the nmap -sU command?
DNS, SNMP, or DHCP server
6. What is the disadvantage of conducting an unauthenticated scan of a
target when performing a penetration test?
Vulnerability of services running inside the target may not be detected.
7. What is required for a penetration tester to conduct a comprehensive
authenticated scan against a Linux host?
user credentials with root-level access to the target system
8. In which circumstance would a penetration tester perform an
unauthenticated scan of a target?
when user credentials were not provided
,9. Why would a penetration tester use the nmap -sF command?
when a TCP SYN scan is detected by a network filter or firewall
10. What is the purpose of host enumeration when beginning a
penetration test?
to identify all active IP addresses within the scope of the test
11. What can be deduced when a tester enters the nmap -sF command
to perform a TCP FIN scan and the target host port does not respond?
that the port is open
12. What is the disadvantage of running a TCP Connect scan compared
to running a TCP SYN scan during a penetration test?
The extra packets required may trigger an IDS alarm.
13. When a penetration test identifies a vulnerability, how should the
vulnerability be further verified?
determine if the vulnerability is exploitable
, 14. Why is the Common Vulnerabilities and Exposures (CVE) resource
useful when investigating vulnerabilities detected by a penetration test?
It is an international consolidation of cybersecurity tools and databases.
15. What is the purpose of applying the Common Vulnerability Scoring
System (CVSS) to a vulnerability detected by a penetration test?
to calculate the severity of the vulnerability
16. A threat actor is looking at the IT and technical job postings of a
target organization. What would be the most beneficial information to
capture from these postings?
the type of hardware and software used
17. How is open-source intelligence (OSINT) gathering typically
implemented during a penetration test?
by using public internet searches
18. What initial information can be obtained when performing user
enumeration in a penetration test?
a valid list of users