Pen Test Final Exam with all Correct & 100% Verified
Answers |Actual Complete Exam |Already Graded A+
What Unix command can you use to listed for input on a network port? ✔Correct Answer-nc
Examine the code snippet below. In what language is this code written?
begin
system 'nmap' + ip
rescue
puts "An error occurred.'
end ✔Correct Answer-Ruby
Alexa carefully pays attention to an employee as they type in their security code to her target
organization's high security area and writes down the code that she observes. What type of
attack has she conducted? ✔Correct Answer-Shoulder Surfing
Which one of the following is not a common category of remediation activity? ✔Correct
Answer-Testing
Adam is conducting a penetration test of an organization and is reviewing source code of an
application for vulnerabilities. What type of code testing is Adam conducting? ✔Correct
Answer-Static Code Analysis
Lisa wants to enumerate possible user accounts and has discovered an accessible SMTP server.
What SMTP commands are most useful for this? ✔Correct Answer-EXPN and VRFY
Which of the following operating systems support Powershell interpreters? ✔Correct Answer-
Windows, Mac, Linux (All of the Above)
Matt wants to pivot from a Linux host to other hosts in the network but is unable to install
additional tools beyond those found on a typical Linux server. How can he leverage the system
he is on to allow vulnerability scans of those remote hots if they are !rewalled against inbound
connections and protected from direct access from his penetration testing workstation?
✔Correct Answer-SSH Tunneling
Which type of organization is the most likely to face a regulatory requirement to conduct
vulnerability scans? ✔Correct Answer-Government Agency
Which one of the following commands will allow the owner to execute a Bash script?
✔Correct Answer-chmod u+x script.sh
, Which one of the following activities assumes that an organization has already been
compromised? ✔Correct Answer-Threat hunting
What is required for Jason to conduct a cold-boot attack against a system? ✔Correct Answer-
Remote Access
What is the default read-only community string for many SNMP devices? ✔Correct Answer-
Public
Selah wants to use a brute-force attack against the SSH service provided by one of her targets.
Which of the following tools is not designed to brute-force services like this? ✔Correct
Answer-Minotaur
Chris is conducting an onsite penetration test. The test is a gray box test, and he is permitted
onsite but has not been given access to the wired or wireless networks. He knows he needs to
gain access to both to make further progress.
If Chris wants to set up a false AP, which tool is best sutied to his needs? ✔Correct Answer-
Aircrack-ng
Chris is conducting an onsite penetration test. The test is a gray box test, and he is permitted
onsite but has not been given access to the wired or wireless networks. He knows he needs to
gain access to both to make further progress.
Once Chris has gained access to the network, what technique can he use to gather additional
credentials? ✔Correct Answer-ARP Spoofing to become a man in the middle
Where is the list of Linux users who can use elevated privileges via sudo typically found?
✔Correct Answer-/etc/sudoers
Which of the following Nmap output formats is unlikely to be useful for a penetration tester?
✔Correct Answer--oS
Biometric authentication technology !ts into what multifactor authentication category?
✔Correct Answer-Something you are
Tonya is con!guring vulnerability scans for a system that is subject to the PCI DSS compliance
standard. What is the minimum frequency with which she must conduct scans? ✔Correct
Answer-Quarterly
Which one of the following is not an example of a vulnerability scanning tool? ✔Correct
Answer-Snort
In what type of attack does the attacker seek to gain access to resources assigned to a di#erent
virtual machine? ✔Correct Answer-VM escape
Answers |Actual Complete Exam |Already Graded A+
What Unix command can you use to listed for input on a network port? ✔Correct Answer-nc
Examine the code snippet below. In what language is this code written?
begin
system 'nmap' + ip
rescue
puts "An error occurred.'
end ✔Correct Answer-Ruby
Alexa carefully pays attention to an employee as they type in their security code to her target
organization's high security area and writes down the code that she observes. What type of
attack has she conducted? ✔Correct Answer-Shoulder Surfing
Which one of the following is not a common category of remediation activity? ✔Correct
Answer-Testing
Adam is conducting a penetration test of an organization and is reviewing source code of an
application for vulnerabilities. What type of code testing is Adam conducting? ✔Correct
Answer-Static Code Analysis
Lisa wants to enumerate possible user accounts and has discovered an accessible SMTP server.
What SMTP commands are most useful for this? ✔Correct Answer-EXPN and VRFY
Which of the following operating systems support Powershell interpreters? ✔Correct Answer-
Windows, Mac, Linux (All of the Above)
Matt wants to pivot from a Linux host to other hosts in the network but is unable to install
additional tools beyond those found on a typical Linux server. How can he leverage the system
he is on to allow vulnerability scans of those remote hots if they are !rewalled against inbound
connections and protected from direct access from his penetration testing workstation?
✔Correct Answer-SSH Tunneling
Which type of organization is the most likely to face a regulatory requirement to conduct
vulnerability scans? ✔Correct Answer-Government Agency
Which one of the following commands will allow the owner to execute a Bash script?
✔Correct Answer-chmod u+x script.sh
, Which one of the following activities assumes that an organization has already been
compromised? ✔Correct Answer-Threat hunting
What is required for Jason to conduct a cold-boot attack against a system? ✔Correct Answer-
Remote Access
What is the default read-only community string for many SNMP devices? ✔Correct Answer-
Public
Selah wants to use a brute-force attack against the SSH service provided by one of her targets.
Which of the following tools is not designed to brute-force services like this? ✔Correct
Answer-Minotaur
Chris is conducting an onsite penetration test. The test is a gray box test, and he is permitted
onsite but has not been given access to the wired or wireless networks. He knows he needs to
gain access to both to make further progress.
If Chris wants to set up a false AP, which tool is best sutied to his needs? ✔Correct Answer-
Aircrack-ng
Chris is conducting an onsite penetration test. The test is a gray box test, and he is permitted
onsite but has not been given access to the wired or wireless networks. He knows he needs to
gain access to both to make further progress.
Once Chris has gained access to the network, what technique can he use to gather additional
credentials? ✔Correct Answer-ARP Spoofing to become a man in the middle
Where is the list of Linux users who can use elevated privileges via sudo typically found?
✔Correct Answer-/etc/sudoers
Which of the following Nmap output formats is unlikely to be useful for a penetration tester?
✔Correct Answer--oS
Biometric authentication technology !ts into what multifactor authentication category?
✔Correct Answer-Something you are
Tonya is con!guring vulnerability scans for a system that is subject to the PCI DSS compliance
standard. What is the minimum frequency with which she must conduct scans? ✔Correct
Answer-Quarterly
Which one of the following is not an example of a vulnerability scanning tool? ✔Correct
Answer-Snort
In what type of attack does the attacker seek to gain access to resources assigned to a di#erent
virtual machine? ✔Correct Answer-VM escape