Penetration Testing &
Vulnerability Analysis
LATEST FA REVIEW
Q&S
©2024/2025
,1. Which of the following tools is typically used to exploit
vulnerabilities during a penetration test?
a) Wireshark
b) Metasploit
c) Nessus
d) Nmap
ANS: b) Metasploit
2. What is the primary purpose of a buffer overflow attack?
a) To execute arbitrary code
b) To encrypt data
c) To perform denial-of-service attack
d) To steal data in transit
ANS: a) To execute arbitrary code
3. Which framework is commonly used for conducting a
structured vulnerability assessment?
a) OWASP
b) ISO/IEC 27001
©2024/2025
, c) CVSS
d) OSSTMM
ANS: d) OSSTMM
4. During the enumeration phase of a penetration test, what is the
key activity performed?
a) Identifying open ports
b) Scanning for vulnerabilities
c) Gathering usernames and passwords
d) Installing spyware
ANS: c) Gathering usernames and passwords
5. Which of the following methods is primarily used to test the
security of web applications?
a) Port Scanning
b) Sniffing
c) Fuzz Testing
d) Code Review
ANS: c) Fuzz Testing
### Fill-in-the-Blank
©2024/2025