Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 67 pages
Exam (elaborations)

8 - Vulnerability Management Exam Questions 100- Verified Complete Answers New Update.docx

Document preview thumbnail
Preview 4 out of 67 pages

8 - Vulnerability Management Exam Questions 100- Verified Complete Answers New U

Content preview

8 - Vulnerability Management Exam
Questions 100% Verified Complete
Answers New Update
Enumeration Tools -
correct answer ✅Used to identify and scan network ranges and
hosts belonging to the target and map out an attack surface.


This is performed to gather intelligence that can be turned into an
attack strategy, or conversely, when used as a defensive tool, to
reduce the attack surface and mitigate potential attack vectors.


Involve at least some sort of active connection to the target.


An active connection is one where the attacker transmits data to
the target.


The attacker machine may make obvious TCP connections to a
firewall, send repetitive DNS and reverse DNS queries, or transmit
phishing emails to targets within the network.


Active techniques are those that will be discovered if the victim is
logging or otherwise monitoring network and host connections.

,8 - Vulnerability Management Exam
Questions 100% Verified Complete
Answers New Update
Enumeration Tools: Open-source Intelligence (OSINT) -
correct answer ✅These tools query publicly available information,
mostly using web and social media search tools.


This can be considered a fully passive approach.


Enumeration Tools: Footprinting -
correct answer ✅These tools map out the layout of a network,
typically in terms of IP address usage, routing topology, and DNS
namespace (subdomains and hostnames).


Can be performed in active, nonstealthy modes to obtain quick
results at the risk of detection or by using slow semi-passive and
passive techniques.


Enumeration Tools: Fingerprinting -
correct answer ✅These tools perform host system detection to
map out open ports, OS type and version, file shares, running
services and applications, system uptime, and other useful
metadata.

,8 - Vulnerability Management Exam
Questions 100% Verified Complete
Answers New Update
Can be performed by active, semi-passive, and passive tools.


Nmap Security Scanner -
correct answer ✅Uses diverse methods of host discovery and
fingerprinting.


The tool is open-source software with packages for most versions of
Windows, Linux, and macOS.


It can be run from the command line or via a GUI.


Nmap: List scan (-sL) -
correct answer ✅This lists the IP addresses from the supplied
target range(s) and performs a reverse-DNS query to discover any
host names associated with those IPs.


This can be used to check that you have specified appropriate
targets. No probes are directed at the actual hosts.

, 8 - Vulnerability Management Exam
Questions 100% Verified Complete
Answers New Update
Nmap: TCP SYN ping (-PS <PortList>) -
correct answer ✅To defeat a firewall, the attacker might want to
probe ports other than the default HTTP/HTTPS ones.


There are numerous other host detection techniques, including TCP
ACK, UDP, SCTP INIT, and IP protocol ping.


Nmap: Sparse scanning (--scan-delay <Time>) -
correct answer ✅One of the principal means of making a scan
stealthy is to collect results over an extended period.


You can set Nmap to issue probes with significant delays between
each probe to try to defeat intrusion detection systems.


Of course, this makes host discovery a lengthy process. You can also
configure delays using a timing template (-Tn, where n is a number
from 0 to 5, with 0 being slowest).


Another IDS evasion technique is to scan the scope in a random
order (--randomize-hosts).

Document information

Uploaded on
January 15, 2026
Number of pages
67
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$15.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Cindellera
3.9
(31)
Sold
183
Followers
3
Items
15346
Last sold
3 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions