Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 210 pages
Exam (elaborations)

CompTIA PenTest+ Guide to Penetration Testing, 2nd Edition Test Bank – Rob Wilson

Document preview thumbnail
Preview 4 out of 210 pages

Advance your cybersecurity and ethical hacking knowledge with the Test Bank for CompTIA PenTest+ Guide to Penetration Testing, 2e 2nd Edition by Rob Wilson (ISBN 9798214410111). Designed for the latest 2026/2027 edition, this instructor resource contains 420 carefully developed Multiple Choice Questions (MCQs) with complete answer keys, making it an excellent companion for classroom instruction, certification preparation, and independent study. Questions are organized according to the textbook structure and learning objectives, allowing students and instructors to evaluate understanding after every chapter. Whether preparing quizzes, homework, laboratory assessments, chapter reviews, midterm exams, or final examinations, this Test Bank provides practical practice aligned with current penetration testing methodologies and CompTIA PenTest+ objectives. Coverage extends across all 14 chapters, exploring penetration testing fundamentals, penetration-testing lab setup, engagement management, reporting and communication, reconnaissance, enumeration, vulnerability scanning, exploitation techniques, network attacks, wireless and specialized systems, application security testing, cloud technologies, host attacks, social engineering, physical security assessments, scripting and code analysis, and the complete penetration-testing project. A valuable resource for cybersecurity students, ethical hackers, penetration testers, instructors, and IT professionals seeking structured exam preparation and hands-on security knowledge.

Content preview

Test Bank - CompTIA PenTest+ Guide to Penetration Testing, 2nd Edition Rob Wilson

Chapter 01 - Introduction to Penetration Testing
1. Which of the following terms describes a flaw in software, hardware, or procedures?
a. A vulnerability
b. An exploit
c. An attack
d. A mistake
ANSWER: a
RATIONALE: A vulnerability is a flaw in the software, hardware, or procedures that, if exploited,
can cause undesired operations or can be used to circumvent security controls.
POINTS: 1
REFERENCES: 1.1 The Ins and Outs of Penetration Testing
QUESTION TYPE: Multiple Choice
HAS VARIABLES: False
LEARNING OBJECTIVES: COMP.PGPT.2.1.1 - Describe the penetration testing process and its phases, activities, and
team members.
TOPICS: Chapter 1 Introduction to Penetration Testing
KEYWORDS: Bloom's: Remember | Understand
DATE CREATED: 4/27/2026 1:13 AM
DATE MODIFIED: 4/27/2026 1:13 AM

2. The National Institute of Standards and Technology (NIST) provides Special Publications to assist IT personnel and
companies in establishing procedures that govern information systems. Which Special Publication (SP) is the technical
guide to information systems testing and assessment?
a. SP 800-53
b. SP 800-100
c. SP 800-128
d. SP 800-115
ANSWER: d
RATIONALE: The SP 800-115 is the Technical Guide to Information Security Testing and
Assessment.
POINTS: 1
REFERENCES: 1.1 The Ins and Outs of Penetration Testing
QUESTION TYPE: Multiple Choice
HAS VARIABLES: False
LEARNING OBJECTIVES: COMP.PGPT.2.1.1 - Describe the penetration testing process and its phases, activities, and
team members.
TOPICS: Chapter 1 Introduction to Penetration Testing
KEYWORDS: Bloom's: Remember | Understand
DATE CREATED: 4/27/2026 1:13 AM
DATE MODIFIED: 4/27/2026 1:13 AM

3. How often should penetration tests be performed to maintain compliance with PCI DSS?
a. Quarterly
b. Monthly

Page 1

,Name: Class: Date:

Chapter 01 - Introduction to Penetration Testing
c. Annually
d. Semi-annually
ANSWER: c
RATIONALE: The Payment Card Industry Data Security Standard (PCI DSS) defines scheduled pen
testing as a requirement, so to achieve and maintain PCI DSS compliance, pen testing
must be a regular activity conducted at least once a year.
POINTS: 1
REFERENCES: 1.1 The Ins and Outs of Penetration Testing
QUESTION TYPE: Multiple Choice
HAS VARIABLES: False
LEARNING OBJECTIVES: COMP.PGPT.2.1.1 - Describe the penetration testing process and its phases, activities, and
team members.
TOPICS: Chapter 1 Introduction to Penetration Testing
KEYWORDS: Bloom's: Remember | Understand
DATE CREATED: 4/27/2026 1:13 AM
DATE MODIFIED: 4/27/2026 1:13 AM

4. Which of the following terms is not a part of the CIA triad?
a. Confidentiality
b. Availability
c. Intelligence
d. Integrity
ANSWER: c
RATIONALE: Confidentiality, integrity, and availability are the known concepts of the CIA triad.
POINTS: 1
REFERENCES: 1.2 CIA, DAD, and the Hacker Mindset
QUESTION TYPE: Multiple Choice
HAS VARIABLES: False
LEARNING OBJECTIVES: COMP.PGPT.2.1.2 - Describe the CIA and DAD triads.
TOPICS: Chapter 1 Introduction to Penetration Testing
KEYWORDS: Bloom's: Remember | Understand
DATE CREATED: 4/27/2026 1:13 AM
DATE MODIFIED: 4/27/2026 1:13 AM

5. The ROE will specify which of the following during the scoping process?
a. The targets that are in scope
b. The cost of the testing being performed
c. The tool that will be used against the network
d. The insurance policy and amounts of coverage
ANSWER: a
RATIONALE: The ROE will include what targets are in scope.
POINTS: 1

Page 2

,Name: Class: Date:

Chapter 01 - Introduction to Penetration Testing
REFERENCES: 1.4 The Pen-Test Process
QUESTION TYPE: Multiple Choice
HAS VARIABLES: False
LEARNING OBJECTIVES: COMP.PGPT.2.1.1 - Describe the penetration testing process and its phases, activities, and
team members.
TOPICS: Chapter 1 Introduction to Penetration Testing
KEYWORDS: Bloom's: Remember | Understand
DATE CREATED: 4/27/2026 1:13 AM
DATE MODIFIED: 4/27/2026 1:13 AM

6. At what stage of the pen-test process would a security tester use programs such as OpenVas?
a. Planning and scoping
b. Information gathering and vulnerability scanning
c. Attacking and exploitation
d. Reporting and communicating results
ANSWER: b
RATIONALE: OpenVAS is a scanning utility used to scan for and identify vulnerabilities of the
network and in the information gathering and vulnerability scanning phase of pen-
testing.
POINTS: 1
REFERENCES: 1.4 The Pen-Test Process
QUESTION TYPE: Multiple Choice
HAS VARIABLES: False
LEARNING OBJECTIVES: COMP.PGPT.2.1.4 - Describe some of the tools used in penetration testing.
TOPICS: Chapter 1 Introduction to Penetration Testing
KEYWORDS: Bloom's: Apply
DATE CREATED: 4/27/2026 1:13 AM
DATE MODIFIED: 4/27/2026 1:13 AM

7. Aurora has just used John the Ripper to crack passwords from the client's network. Tools like John the Ripper are used
at what stage of the penetration testing process?
a. Planning and scoping
b. Information gathering and vulnerability scanning
c. Attacking and exploitation
d. Reporting and communicating results
ANSWER: c
RATIONALE: Password cracking utilities are used during the attacking and exploiting phase of the
penetration test.
POINTS: 1
REFERENCES: 1.4 The Pen-Test Process
QUESTION TYPE: Multiple Choice
HAS VARIABLES: False
LEARNING OBJECTIVES: COMP.PGPT.2.1.4 - Describe some of the tools used in penetration testing.
Page 3

, Name: Class: Date:

Chapter 01 - Introduction to Penetration Testing
TOPICS: Chapter 1 Introduction to Penetration Testing
KEYWORDS: Bloom's: Apply
DATE CREATED: 4/27/2026 1:13 AM
DATE MODIFIED: 4/27/2026 1:13 AM

8. Disclosure of sensitive data and making it available to unauthorized entities can bring undesired publicity and liability
to a company. Disclosure attempts to destroy which property of the CIA triad?
a. Confidentiality
b. Integrity
c. Availability
d. Intelligence
ANSWER: a
RATIONALE: You can think of the DAD triad (disclosure, alteration, destruction) as the hacker's
ultimate goal of corrupting the CIA model by disclosing confidential information,
altering or corrupting the integrity of information, and destroying or denying the
availability of access to resources.
POINTS: 1
REFERENCES: 1.2 CIA, DAD, and the Hacker Mindset
QUESTION TYPE: Multiple Choice
HAS VARIABLES: False
LEARNING OBJECTIVES: COMP.PGPT.2.1.2 - Describe the CIA and DAD triads.
TOPICS: Chapter 1 Introduction to Penetration Testing
KEYWORDS: Bloom's: Remember | Understand
DATE CREATED: 4/27/2026 1:13 AM
DATE MODIFIED: 4/27/2026 1:13 AM

9. The cyber kill chain is a seven-step process describing the normal process of cyber attacks. Which step is described as
"Intruder transmits weapon to target"?
a. Weaponization
b. Delivery
c. Exploitation
d. Installation
ANSWER: b
RATIONALE: Transmitting the weapon to the target (via email, website, etc.) is the main goal of the
third step of the kill chain, delivery.
POINTS: 1
REFERENCES: 1.5 The Cyber Kill Chain
QUESTION TYPE: Multiple Choice
HAS VARIABLES: False
LEARNING OBJECTIVES: COMP.PGPT.2.1.3 - Describe the ethical hacking mindset.
TOPICS: Chapter 1 Introduction to Penetration Testing
KEYWORDS: Bloom's: Remember | Understand
DATE CREATED: 4/27/2026 1:13 AM
Page 4

Document information

Uploaded on
July 25, 2026
Number of pages
210
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$29.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Tutor247
4.2
(849)
Sold
6800
Followers
3563
Items
1248
Last sold
7 hours ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions