WGU D484 DKN1 PENETRATION ANALYSIS
FINAL TEST 2026 QUESTIONS WITH
CORRECT ANSWERS GRADED A+
◍ Airodump-ng.
Answer: Used to capture network traffic and save it to a PCAP file
◍ Metasploit store results.
Answer: hostsservicesvulns
◍ A PenTesting team has undergone a debrief and is discovering things that
will help them improve their tools and processes. Which follow-up phase
does this fall under?.
Answer: This falls under the lessons learned phase where the primary goal
of a lessons learned report (LLR) or after-action report (AAR) is to improve
the PenTest processes and tools.
◍ Metasploit system info commands.
Answer: sysinfogetuidipconfig
◍ Postman.
Answer: Tests, manipulates, and fuzzes API
◍ (DOM)-based attack.
Answer: When attackers send malicious scripts to a web app's client-side
implementation of JavaScript to execute their attack solely on the client.
◍ You are conducting a penetration test against an organization. You created
an evil twin of their wireless network. Many of the organization's laptops
are now connected to your evil twin access point. You want to capture all of
the victim's web browsing traffic in an unencrypted format during your
attack. Which of the following exploits should you utilize to meet this goal?.
, Answer: Perform an SSL stripping attack
◍ DAST.
Answer: Observes behavior, responses, and security flaws like: token
leakage, authentication failures, and parameter tampering.
◍ Metasploit show options to config.
Answer: show optionsshow advancedshow payloadsshow targets
◍ A security tester wants to launch an attack on a WPA2-Enterprise 802.11a
or 802.11n network in a free, easy-to-use platform. Which of the following
should they use?.
Answer: EAPHammer is another Python-based toolkit with a wide range of
features. It provides options that the team can use to launch an attack on a
WPA2-Enterprise 802.11a or 802.11n network in an easy-to-use platform.
◍ A new penetration tester is creating a summary of their first upcoming
process and wants to follow the standard process. What step takes place
after planning?.
Answer: Reconnaissance is next and focuses on gathering as much
information about the target as possible. This process includes searching
information on the Internet, using Open-Source Information Gathering
Tools (OSINT), and websites.
◍ An organization is reviewing the contents of a report and has questions
about the framework that the PenTesters used to conduct the penetration
test. What section of the report is the organization referring to?.
Answer: The organization is referring to the methodology section of the
report which is a high-level description of the standards or framework the
PenTesters followed to conduct the penetration test.
◍ Nmap TCP ACK flag.
Answer: -sADetermine if firewall is stateful or not
◍ A PenTester is creating variants and combinations of word lists in an
attempt to crack a user's password. What type of attack is this?.
Answer: The PenTester is using a rule attack which can make use of word
, lists to create variants and combinations and can then try trimming or
expanding words or substituting numbers or special characters for letters.
◍ Nmap -PS flag.
Answer: TCP SYN ping scan: three-way handshake ending with RST to
close connection instead of full connect, port 80 is default.
◍ Dima is reading reports from vulnerability scans run by different parts of her
organization using different products. She is responsible for assigning
remediation resources and is having difficulty prioritizing issues from
different sources. What SCAP component can help Dima with this task?.
Answer: CVSS
◍ Tools for Session Hijacking.
Answer: Burp Suite & ZAP
◍ NVD.
Answer: National Vulnerability Database, a superset of the CVE database,
maintained by NIST.
◍ Gordon is tasked with assessing the security posture of a client's network
using automated breach and attack simulation tools. He decides to use a tool
that provides a modular, open-source platform for automating adversary
emulation using predefined scripts. Gordon wants to simulate attacks that
closely resemble those of known APT groups. Which tool should Gordon
choose to effectively script these attacks?.
Answer: Caldera is an open-source platform developed by MITRE that
automates adversary emulation through scripting, allowing the simulation of
known APT attacks
◍ TXT record.
Answer: Text allows the admin to store notes about resource
◍ Nmap UDP scan.
Answer: -sUUse with DNS, SMNP, DHCP
◍ theHarvester.
, Answer: Collects emails, subdomains, IPs, and employee names from public
data sources.
◍ A penetration tester has landed a shell on a Linux box and wants to find out
more about the users' login and idle time. Which built-in bash command
should they use?.
Answer: The finger command views a user's home directory along with
login and idle time. You can also use nmap -O or -sV scans to fingerprint
the operating system and interrogate its services.
◍ Pacu.
Answer: AWS exploit framework
◍ Seatbelt Full Scan.
Answer: Seatbelt.exe -group=allScan for: credentials, processes,
network/user info
◍ Nmap modbus-discover.
Answer: Discover devices using modbus communication protocol
◍ What are some ways in which a malicious actor can compromise cloud
storage containers? (Select all that apply.).
Answer: Improperly managed secrets such as API keys, tokens, and
passwords, can cause container security risks and vulnerabilities that a
malicious actor can take advantage of to compromise cloud storage
containers.
◍ A security tester wants to disable monitor mode on a wireless interface.
Which tool should they use?.
Answer: Airmon-ng will enable and disable monitor mode on a wireless
interface. Airmon-ng can also switch an interface from managed mode to
monitor mode.
◍ Sami wants to conduct a DLL hijacking attack. Which directory will
Windows search first for a DLL if it does not have a specific known location
for it?.
Answer: The directory the application is in
FINAL TEST 2026 QUESTIONS WITH
CORRECT ANSWERS GRADED A+
◍ Airodump-ng.
Answer: Used to capture network traffic and save it to a PCAP file
◍ Metasploit store results.
Answer: hostsservicesvulns
◍ A PenTesting team has undergone a debrief and is discovering things that
will help them improve their tools and processes. Which follow-up phase
does this fall under?.
Answer: This falls under the lessons learned phase where the primary goal
of a lessons learned report (LLR) or after-action report (AAR) is to improve
the PenTest processes and tools.
◍ Metasploit system info commands.
Answer: sysinfogetuidipconfig
◍ Postman.
Answer: Tests, manipulates, and fuzzes API
◍ (DOM)-based attack.
Answer: When attackers send malicious scripts to a web app's client-side
implementation of JavaScript to execute their attack solely on the client.
◍ You are conducting a penetration test against an organization. You created
an evil twin of their wireless network. Many of the organization's laptops
are now connected to your evil twin access point. You want to capture all of
the victim's web browsing traffic in an unencrypted format during your
attack. Which of the following exploits should you utilize to meet this goal?.
, Answer: Perform an SSL stripping attack
◍ DAST.
Answer: Observes behavior, responses, and security flaws like: token
leakage, authentication failures, and parameter tampering.
◍ Metasploit show options to config.
Answer: show optionsshow advancedshow payloadsshow targets
◍ A security tester wants to launch an attack on a WPA2-Enterprise 802.11a
or 802.11n network in a free, easy-to-use platform. Which of the following
should they use?.
Answer: EAPHammer is another Python-based toolkit with a wide range of
features. It provides options that the team can use to launch an attack on a
WPA2-Enterprise 802.11a or 802.11n network in an easy-to-use platform.
◍ A new penetration tester is creating a summary of their first upcoming
process and wants to follow the standard process. What step takes place
after planning?.
Answer: Reconnaissance is next and focuses on gathering as much
information about the target as possible. This process includes searching
information on the Internet, using Open-Source Information Gathering
Tools (OSINT), and websites.
◍ An organization is reviewing the contents of a report and has questions
about the framework that the PenTesters used to conduct the penetration
test. What section of the report is the organization referring to?.
Answer: The organization is referring to the methodology section of the
report which is a high-level description of the standards or framework the
PenTesters followed to conduct the penetration test.
◍ Nmap TCP ACK flag.
Answer: -sADetermine if firewall is stateful or not
◍ A PenTester is creating variants and combinations of word lists in an
attempt to crack a user's password. What type of attack is this?.
Answer: The PenTester is using a rule attack which can make use of word
, lists to create variants and combinations and can then try trimming or
expanding words or substituting numbers or special characters for letters.
◍ Nmap -PS flag.
Answer: TCP SYN ping scan: three-way handshake ending with RST to
close connection instead of full connect, port 80 is default.
◍ Dima is reading reports from vulnerability scans run by different parts of her
organization using different products. She is responsible for assigning
remediation resources and is having difficulty prioritizing issues from
different sources. What SCAP component can help Dima with this task?.
Answer: CVSS
◍ Tools for Session Hijacking.
Answer: Burp Suite & ZAP
◍ NVD.
Answer: National Vulnerability Database, a superset of the CVE database,
maintained by NIST.
◍ Gordon is tasked with assessing the security posture of a client's network
using automated breach and attack simulation tools. He decides to use a tool
that provides a modular, open-source platform for automating adversary
emulation using predefined scripts. Gordon wants to simulate attacks that
closely resemble those of known APT groups. Which tool should Gordon
choose to effectively script these attacks?.
Answer: Caldera is an open-source platform developed by MITRE that
automates adversary emulation through scripting, allowing the simulation of
known APT attacks
◍ TXT record.
Answer: Text allows the admin to store notes about resource
◍ Nmap UDP scan.
Answer: -sUUse with DNS, SMNP, DHCP
◍ theHarvester.
, Answer: Collects emails, subdomains, IPs, and employee names from public
data sources.
◍ A penetration tester has landed a shell on a Linux box and wants to find out
more about the users' login and idle time. Which built-in bash command
should they use?.
Answer: The finger command views a user's home directory along with
login and idle time. You can also use nmap -O or -sV scans to fingerprint
the operating system and interrogate its services.
◍ Pacu.
Answer: AWS exploit framework
◍ Seatbelt Full Scan.
Answer: Seatbelt.exe -group=allScan for: credentials, processes,
network/user info
◍ Nmap modbus-discover.
Answer: Discover devices using modbus communication protocol
◍ What are some ways in which a malicious actor can compromise cloud
storage containers? (Select all that apply.).
Answer: Improperly managed secrets such as API keys, tokens, and
passwords, can cause container security risks and vulnerabilities that a
malicious actor can take advantage of to compromise cloud storage
containers.
◍ A security tester wants to disable monitor mode on a wireless interface.
Which tool should they use?.
Answer: Airmon-ng will enable and disable monitor mode on a wireless
interface. Airmon-ng can also switch an interface from managed mode to
monitor mode.
◍ Sami wants to conduct a DLL hijacking attack. Which directory will
Windows search first for a DLL if it does not have a specific known location
for it?.
Answer: The directory the application is in