CompTIA Pentest+ (PT0-002) Exam Questions With Correct Answers
White-list {Access Control} - Answer allows specifically identified users {based on identification mechanisms including but not limited to username, IP address, and network range} with the required authorization access to access a given system or network. Risk Acceptance - Answer a term that indicates an understanding and willingness to bear the likelihood and impact of a specific threat to an organization's systems or networks reverse DNS lookup - Answer queries the PTR record for a named IP address and then returns the associated domain name Stumbling - Answer a surveillance technique used to discover SSIDs, router information, signal strength, MAC addresses, and other information pertinent to an 802.11 wireless network AAA - Answer Authentication, Authorization and Accounting; a framework for intelligently controlling access to computer resources, enforcing policies, auditing usage, and providing the information necessary to bill for services ACL - Answer Access Control List AES - Answer advanced encryption standard, a symmetric 128-bit block data encryption technique AP - Answer Access Point API - Answer Application Programming Interface is offered by a server for communication with a client app. A client computer program can send instructions to the server and get data from the server by sending requests to various URL endpoints that form the API. APT - Answer Advanced Persistent Threat ARP - Answer Address Resolution Protocol. An Internet protocol used to map an IP address to a MAC address. Defined in RFC 826. AS2 - Answer Applicability Statement 2; is a specification about how to transport structured business-to-business data securely and reliably over the Internet. Security is achieved by using digital certificates and encryption. BeEF - Answer Browser Exploitation Framework; a penetration testing tool that focuses on the web browser BLE - Answer Bluetooth Low Energy BSSID - Answer Basic Service Set Identifiers CA {Certificate Authority} - Answer An organization that manages, issues, and signs certificates and is part of a PKI. Certificates are an important part of asymmetric encryption. Certificates include public keys along with details on the owner of the certificate and on the CA that issued the certificate. CAPEC {Common Attack Pattern Enumeration and Classification} - Answer is a comprehensive dictionary and classification taxonomy of known attacks that can be used by analysts, developers, testers, and educators to advance community understanding and enhance defenses" CLI - Answer Command-line interface. An interface that enables the user to interact with the operating system by entering commands and optional arguments. CSRF {Cross-Site Request Forgery} - Answer an attack that forces an end user to execute unwanted actions on a web application in which they're currently authenticated; aka one-click attack or session riding CSV - Answer Comma-Separated Values CVE - Answer Common Vulnerabilities and Exposures (CVE). A dictionary of publicly known security vulnerabilities and exposures. CVSS {Common Vulnerability Scoring Systems} - Answer attempts to assign severity scores to vulnerabilities; In CVSS 3.1, the base metric is comprised of 8 factors: access vector {AV}, access complexity {AC}, privileges required {PR}, user interaction {UI}, scope {S}, confidentiality {C}, integrity {I}, and availability {A} C W E - Answer Common Weakness Enumeration; a community-developed list of software and hardware weakness types. It serves as a common language or measuring stick for security tools, and as a baseline for weakness identification, mitigation, and prevention efforts. DB - Answer Database DDoS - Answer Distributed Denial-of-Service DHCP - Answer Dynamic Host Configuration Protocol DLL - Answer Dynamic Link Library. A compiled set of code that can be called from other programs. DLP - Answer Data Loss Prevention DNS - Answer (Domain Name System)—The service that allows you to use a friendly name like instead of an IP address like 165.193.123.253 to contact a Web site. DNSSEC - Answer Domain Name System Security Extensions. A suite of extensions to DNS used to protect the integrity of DNS records and prevent some DNS attacks. EAP - Answer Extensible Authentication Protocol. An authentication framework that provides general guidance for authentication methods. Variations include LEAP and PEAP FOCA {Fingerprinting Organizations with Collected Archives} - Answer a tool used mainly to find metadata and hidden information in the documents its scans. These documents may be on web pages and can be downloaded and analyzed with FOCA FTP - Answer File Transfer Protocol FTPS - Answer File Transfer Protocol Secure. An extension of FTP that uses SSL or TLS to encrypt FTP traffic. Some implementations of FTPS use ports 989 and 990. GDB - Answer GNU debugger; a portable debugger that runs on many Unix-like systems and works for many programming languages, including Ada, C, C++, Objective-C, Free Pascal, Fortran, Go, and partially others GPU - Answer Graphics Processing Unit GDPR - Answer General Data Protection Regulation HTTP - Answer Hypertext Transfer Protocol HTTPS - Answer Hypertext Transfer Protocol Secure IaaS - Answer Infrastructure as a Service. IAM - Answer Identity and Access Management ICMP - Answer Internet Control Message Protocol ICS - Answer Industrial Control System IDA {Interactive Disassembler} - Answer a disassembler for computer software which generates assembly language source code from machine-executable code. It supports a variety of executable formats for different processors and operating systems. IDS - Answer Intrusion Detection System IIoT - Answer Industrial Internet of Things IMEI - Answer International Mobile Equipment Identity (IMEI) is a unique serial number which identifies a mobile phone. IoT - Answer Internet of Things IP - Answer Internet Protocol - A set of rules for communicating over the internet. IP can also stand for intellectual property. IPMI - Answer Intelligent Platform Management Interface (IPMI) is a set of computer interface specifications for an autonomous computer subsystem that provides management and monitoring capabilities independently of the host system's CPU, firmware (BIOS or UEFI) and operating system IPS - Answer Intrusion Prevention System ISO - Answer International Organization for Standardization ISP - Answer Internet Service Provider I.S.S.A.F. {Information Systems Security Assessment Framework} - Answer a methodology where the pen tester imitates hacking, Utilizes the following phases: Information gathering; Network mapping; Vulnerability identification; Penetration; Gaining access & privilege escalation; Enumerating further; Compromising remote users/sites; Maintaining access; Covering tracks; JSON - Answer JavaScript Object Notation (JSON) - a popular data interchange format, JSON is a technology standard often used to format data when being sent or received via APIs. LAN - Answer Local Area Network
Document information
- Uploaded on
- September 8, 2023
- Number of pages
- 21
- Written in
- 2023/2024
- Type
- Exam (elaborations)
- Contains
- Questions & answers