Chapter 01 - Introduction to Penetration Testing
1. Which of the following terms describes a flaw in software, hardware, or procedures?
a. A vulnerability
b. An exploit
c. An attack
d. A mistake
ANSWER: a
RATIONALE: A vulnerability is a flaw in the software, hardware, or procedures that, if exploited,
can cause undesired operations or can be used to circumvent security controls.
POINTS: 1
REFERENCES: 1.1 The Ins and Outs of Penetration Testing
QUESTION TYPE: Multiple Choice
HAS VARIABLES: False
LEARNING OBJECTIVES: COMP.PGPT.2.1.1 - Describe the penetration testing process and its phases, activities, and
team members.
TOPICS: Chapter 1 Introduction to Penetration Testing
KEYWORDS: Bloom's: Remember | Understand
DATE CREATED: 4/27/2026 1:13 AM
DATE MODIFIED: 4/27/2026 1:13 AM
2. The National Institute of Standards and Technology (NIST) provides Special Publications to assist IT personnel and
companies in establishing procedures that govern information systems. Which Special Publication (SP) is the technical
guide to information systems testing and assessment?
a. SP 800-53
b. SP 800-100
c. SP 800-128
d. SP 800-115
ANSWER: d
RATIONALE: The SP 800-115 is the Technical Guide to Information Security Testing and
Assessment.
POINTS: 1
REFERENCES: 1.1 The Ins and Outs of Penetration Testing
QUESTION TYPE: Multiple Choice
HAS VARIABLES: False
LEARNING OBJECTIVES: COMP.PGPT.2.1.1 - Describe the penetration testing process and its phases, activities, and
team members.
TOPICS: Chapter 1 Introduction to Penetration Testing
KEYWORDS: Bloom's: Remember | Understand
DATE CREATED: 4/27/2026 1:13 AM
DATE MODIFIED: 4/27/2026 1:13 AM
3. How often should penetration tests be performed to maintain compliance with PCI DSS?
a. Quarterly
b. Monthly
Page 1
,Name: Class: Date:
Chapter 01 - Introduction to Penetration Testing
c. Annually
d. Semi-annually
ANSWER: c
RATIONALE: The Payment Card Industry Data Security Standard (PCI DSS) defines scheduled pen
testing as a requirement, so to achieve and maintain PCI DSS compliance, pen testing
must be a regular activity conducted at least once a year.
POINTS: 1
REFERENCES: 1.1 The Ins and Outs of Penetration Testing
QUESTION TYPE: Multiple Choice
HAS VARIABLES: False
LEARNING OBJECTIVES: COMP.PGPT.2.1.1 - Describe the penetration testing process and its phases, activities, and
team members.
TOPICS: Chapter 1 Introduction to Penetration Testing
KEYWORDS: Bloom's: Remember | Understand
DATE CREATED: 4/27/2026 1:13 AM
DATE MODIFIED: 4/27/2026 1:13 AM
4. Which of the following terms is not a part of the CIA triad?
a. Confidentiality
b. Availability
c. Intelligence
d. Integrity
ANSWER: c
RATIONALE: Confidentiality, integrity, and availability are the known concepts of the CIA triad.
POINTS: 1
REFERENCES: 1.2 CIA, DAD, and the Hacker Mindset
QUESTION TYPE: Multiple Choice
HAS VARIABLES: False
LEARNING OBJECTIVES: COMP.PGPT.2.1.2 - Describe the CIA and DAD triads.
TOPICS: Chapter 1 Introduction to Penetration Testing
KEYWORDS: Bloom's: Remember | Understand
DATE CREATED: 4/27/2026 1:13 AM
DATE MODIFIED: 4/27/2026 1:13 AM
5. The ROE will specify which of the following during the scoping process?
a. The targets that are in scope
b. The cost of the testing being performed
c. The tool that will be used against the network
d. The insurance policy and amounts of coverage
ANSWER: a
RATIONALE: The ROE will include what targets are in scope.
POINTS: 1
Page 2
,Name: Class: Date:
Chapter 01 - Introduction to Penetration Testing
REFERENCES: 1.4 The Pen-Test Process
QUESTION TYPE: Multiple Choice
HAS VARIABLES: False
LEARNING OBJECTIVES: COMP.PGPT.2.1.1 - Describe the penetration testing process and its phases, activities, and
team members.
TOPICS: Chapter 1 Introduction to Penetration Testing
KEYWORDS: Bloom's: Remember | Understand
DATE CREATED: 4/27/2026 1:13 AM
DATE MODIFIED: 4/27/2026 1:13 AM
6. At what stage of the pen-test process would a security tester use programs such as OpenVas?
a. Planning and scoping
b. Information gathering and vulnerability scanning
c. Attacking and exploitation
d. Reporting and communicating results
ANSWER: b
RATIONALE: OpenVAS is a scanning utility used to scan for and identify vulnerabilities of the
network and in the information gathering and vulnerability scanning phase of pen-
testing.
POINTS: 1
REFERENCES: 1.4 The Pen-Test Process
QUESTION TYPE: Multiple Choice
HAS VARIABLES: False
LEARNING OBJECTIVES: COMP.PGPT.2.1.4 - Describe some of the tools used in penetration testing.
TOPICS: Chapter 1 Introduction to Penetration Testing
KEYWORDS: Bloom's: Apply
DATE CREATED: 4/27/2026 1:13 AM
DATE MODIFIED: 4/27/2026 1:13 AM
7. Aurora has just used John the Ripper to crack passwords from the client's network. Tools like John the Ripper are used
at what stage of the penetration testing process?
a. Planning and scoping
b. Information gathering and vulnerability scanning
c. Attacking and exploitation
d. Reporting and communicating results
ANSWER: c
RATIONALE: Password cracking utilities are used during the attacking and exploiting phase of the
penetration test.
POINTS: 1
REFERENCES: 1.4 The Pen-Test Process
QUESTION TYPE: Multiple Choice
HAS VARIABLES: False
LEARNING OBJECTIVES: COMP.PGPT.2.1.4 - Describe some of the tools used in penetration testing.
Page 3
, Name: Class: Date:
Chapter 01 - Introduction to Penetration Testing
TOPICS: Chapter 1 Introduction to Penetration Testing
KEYWORDS: Bloom's: Apply
DATE CREATED: 4/27/2026 1:13 AM
DATE MODIFIED: 4/27/2026 1:13 AM
8. Disclosure of sensitive data and making it available to unauthorized entities can bring undesired publicity and liability
to a company. Disclosure attempts to destroy which property of the CIA triad?
a. Confidentiality
b. Integrity
c. Availability
d. Intelligence
ANSWER: a
RATIONALE: You can think of the DAD triad (disclosure, alteration, destruction) as the hacker's
ultimate goal of corrupting the CIA model by disclosing confidential information,
altering or corrupting the integrity of information, and destroying or denying the
availability of access to resources.
POINTS: 1
REFERENCES: 1.2 CIA, DAD, and the Hacker Mindset
QUESTION TYPE: Multiple Choice
HAS VARIABLES: False
LEARNING OBJECTIVES: COMP.PGPT.2.1.2 - Describe the CIA and DAD triads.
TOPICS: Chapter 1 Introduction to Penetration Testing
KEYWORDS: Bloom's: Remember | Understand
DATE CREATED: 4/27/2026 1:13 AM
DATE MODIFIED: 4/27/2026 1:13 AM
9. The cyber kill chain is a seven-step process describing the normal process of cyber attacks. Which step is described as
"Intruder transmits weapon to target"?
a. Weaponization
b. Delivery
c. Exploitation
d. Installation
ANSWER: b
RATIONALE: Transmitting the weapon to the target (via email, website, etc.) is the main goal of the
third step of the kill chain, delivery.
POINTS: 1
REFERENCES: 1.5 The Cyber Kill Chain
QUESTION TYPE: Multiple Choice
HAS VARIABLES: False
LEARNING OBJECTIVES: COMP.PGPT.2.1.3 - Describe the ethical hacking mindset.
TOPICS: Chapter 1 Introduction to Penetration Testing
KEYWORDS: Bloom's: Remember | Understand
DATE CREATED: 4/27/2026 1:13 AM
Page 4