Courseiva

CCNA Reconnaissance and Enumeration Questions

75 of 99 questions · Page 1/2 · Reconnaissance and Enumeration · Answers revealed

1
MCQeasy

A penetration tester wants to query Certificate Transparency logs to find all SSL/TLS certificates issued for a target domain, which may reveal subdomains. Which tool or website is specifically designed for this purpose?

A.crt.sh
B.Censys
C.Let's Encrypt
D.Shodan
AnswerA

crt.sh is a dedicated Certificate Transparency (CT) log search engine that aggregates and indexes certificates from multiple CT logs, allowing rapid lookups by domain, issuer, or serial number. It directly queries the CT framework's public, append-only logs via a web interface and API, making it the precise tool for checking which certificates have been issued for a domain, including your own. This is why it is the correct answer.

Why this answer

crt.sh is a website that queries Certificate Transparency logs and returns certificates for a domain, often revealing subdomains. Shodan and Censys also provide certificate data but crt.sh is focused on CT logs. Let's Encrypt is a CA, not a log query tool.

2
MCQeasy

Which tool is specifically designed for scanning WordPress websites to detect vulnerabilities, such as outdated plugins, themes, and weak passwords?

A.OpenVAS
B.Nikto
C.WPScan
D.Nessus
AnswerC

WPScan is a dedicated WordPress vulnerability scanner that enumerates installed plugins, themes and users, then checks them against known vulnerability databases and tests for weak credentials. Generic web scanners lack this WordPress-specific enumeration and detection logic.

Why this answer

WPScan is a dedicated WordPress security scanner that enumerates WordPress-specific vulnerabilities, including outdated plugins, themes, and weak passwords via XML-RPC brute-force testing. It uses the WordPress vulnerability database (wpvulndb.com) to match installed versions against known CVEs, making it the correct tool for this targeted task.

Exam trap

The trap here is that candidates often confuse general web vulnerability scanners (like Nikto or OpenVAS) with a CMS-specific tool, assuming any scanner can perform WordPress vulnerability detection, but only WPScan is purpose-built for WordPress enumeration and exploitation.

How to eliminate wrong answers

Option A is wrong because OpenVAS is a general-purpose vulnerability scanner that covers a wide range of systems and services, but it lacks WordPress-specific enumeration capabilities like theme/plugin version detection and password brute-forcing via XML-RPC. Option B is wrong because Nikto is a web server scanner that checks for common misconfigurations and outdated server software, but it does not perform WordPress-specific scans such as plugin vulnerability checks or user enumeration. Option D is wrong because Nessus is a comprehensive vulnerability scanner for networks and operating systems, but it is not designed for WordPress-specific scanning and does not include dedicated checks for WordPress plugin/theme versions or weak password attacks.

3
MCQmedium

A tester is scanning a target network using Nmap. The client wants minimal disruption and asks to avoid completing TCP three-way handshakes. Which scan type should the tester use?

A.TCP connect scan (-sT)
B.UDP scan (-sU)
C.SYN scan (-sS)
D.Ping sweep (-sn)
AnswerC

SYN scan (-sS) sends a bare SYN packet to each port, and if a SYN/ACK is returned, the port is considered open; the scan then immediately replies with an RST to tear down the half-open connection before the handshake completes. This avoids creating a full TCP session, so the target application never sees a completed connection, making it far less likely to appear in application-level logs. Because it sends raw packets, it requires root or CAP_NET_RAW privileges, but it is the default and fastest scan type in Nmap. It is not completely invisible—stateful firewalls can still detect the unprompted SYN/ACK followed by RST—but it is significantly more stealthy than a full connect scan.

Why this answer

A SYN scan (nmap -sS) sends SYN packets and analyzes responses without completing the handshake, making it stealthier than a full connect scan.

4
Multi-Selecthard

A penetration tester is analyzing a web application's JavaScript files for hardcoded secrets and API endpoints. Which THREE techniques or tools are MOST effective for this purpose? (Select THREE.)

Select 3 answers
A.Using LinkFinder to extract endpoints from JavaScript
B.Using Wappalyzer to identify frameworks
C.Using SecretFinder to search for API keys and secrets
D.Using Gobuster to bruteforce directories
E.Manually examining JavaScript source files
AnswersA, C, E

LinkFinder parses JavaScript files with regular expressions to extract URL paths, relative endpoints and API routes embedded in client-side code, directly satisfying the requirement to enumerate endpoints. Unlike generic secret scanners, it targets endpoint discovery specifically, making it effective when reviewing minified or bundled JavaScript for hidden API surfaces.

Why this answer

LinkFinder (A) is correct because it parses JavaScript files with regex patterns to extract URL paths, endpoints, and parameters that are otherwise buried in minified or bundled code, directly serving the goal of discovering API endpoints. SecretFinder (C) is correct because it is built specifically to scan JavaScript for high-entropy strings and regex signatures matching API keys, tokens, and other hardcoded secrets. Manually examining JavaScript source files (E) is correct because human review catches context-dependent secrets, obfuscated logic, and endpoint patterns that automated regex tools may miss or misclassify.

Wappalyzer (B) is not appropriate here because it only fingerprints technologies and frameworks from headers and page artifacts, not secrets or endpoints inside JS. Gobuster (D) is not appropriate because it performs directory and file brute-forcing against the web server, which does not analyze JavaScript content for secrets or embedded endpoints.

Exam trap

The exam often tests the distinction between tools that passively extract information from existing files (LinkFinder, SecretFinder) versus tools that actively bruteforce or fingerprint server-side resources (Gobuster, Wappalyzer), leading candidates to select tools that serve different phases of the penetration test.

5
MCQeasy

A penetration tester is conducting passive reconnaissance on a target organization. Which of the following tools is specifically designed for gathering OSINT by extracting email addresses, subdomains, and employee names from public sources?

A.Nikto
B.WPScan
C.Nmap
D.theHarvester
AnswerD

theHarvester is a passive OSINT tool that aggregates emails, subdomains, hostnames, and employee names from public data sources such as search engines, PGP key servers, and certificate transparency logs. It performs this collection without directly contacting the target servers, thus qualifying as passive reconnaissance. The gathered data helps penetration testers map an organization's external attack surface and identify potential entry points for social engineering or credential attacks.

Why this answer

theHarvester is a popular OSINT tool used to gather emails, subdomains, IPs, and employee names from public sources like search engines, PGP key servers, and social networks.

6
MCQmedium

During a penetration test, you are asked to discover all live hosts on a subnet without generating excessive traffic or being too intrusive. Which Nmap command best achieves this goal?

A.nmap -O 192.168.1.0/24
B.nmap -sn 192.168.1.0/24
C.nmap -A 192.168.1.0/24
D.nmap -sS 192.168.1.0/24
AnswerB

-sn performs host discovery only (ping sweep) without port scanning, meeting the requirement.

Why this answer

The `-sn` flag (ping scan) sends ICMP echo requests, TCP SYN to port 443, TCP ACK to port 80, and ICMP timestamp requests to discover live hosts without performing port scans or service detection, minimizing traffic and intrusiveness. This meets the requirement of discovering all live hosts on a subnet efficiently.

Exam trap

The trap here is that candidates often confuse `-sn` (ping scan) with `-sS` (SYN scan), assuming that a stealth scan is less intrusive, but `-sS` actually probes ports and generates more traffic, while `-sn` only checks for host liveness without port scanning.

How to eliminate wrong answers

Option A is wrong because `-O` performs OS detection, which requires active port scanning and generates more traffic, making it intrusive and not suitable for a low-traffic discovery goal. Option C is wrong because `-A` enables aggressive scanning (OS detection, version detection, script scanning, traceroute), which generates excessive traffic and is highly intrusive. Option D is wrong because `-sS` performs a SYN stealth scan that probes open ports on each host, generating significant traffic and being more intrusive than a simple ping sweep.

7
MCQmedium

A penetration tester is performing passive reconnaissance on a target organization. Which of the following tools would be BEST suited to gather information about the organization's domain names, email addresses, and subdomains from publicly available sources without directly interacting with the target's systems?

A.Nmap
B.theHarvester
C.Nessus
D.Metasploit
AnswerB

theHarvester queries public sources such as search engines, PGP key servers and certificate transparency logs to harvest domain names, email addresses and subdomains. This satisfies the passive constraint because it never sends traffic directly to the target's own systems.

Why this answer

theHarvester is specifically designed for passive reconnaissance, gathering domain names, email addresses, subdomains, and other publicly available information from search engines and public sources without directly interacting with the target's systems. It queries sources like Google, Bing, and LinkedIn, making it ideal for this task.

Exam trap

PT0-003 often tests the confusion between passive and active reconnaissance tools, where candidates might pick Nmap or Nessus thinking they are passive when they actually generate network traffic.

How to eliminate wrong answers

Option A is wrong because Nmap is an active scanning tool that sends packets to target systems to discover open ports and services, which is not passive. Option C is wrong because Nessus is a vulnerability scanner that actively probes systems for vulnerabilities, which is intrusive and not passive. Option D is wrong because Metasploit is an exploitation framework used for active attacks, not passive information gathering.

8
MCQeasy

During a penetration test, the tester wants to identify live hosts on a network without performing a full port scan. Which Nmap command is most appropriate for this task?

A.nmap -A 192.168.1.0/24
B.nmap -O 192.168.1.0/24
C.nmap -sS 192.168.1.0/24
D.nmap -sn 192.168.1.0/24
AnswerD

The -sn switch, previously called -sP, disables port scanning and instructs Nmap to perform only host discovery, commonly known as a ping sweep. Nmap sends a mix of ICMP echo requests, TCP SYN to port 443, TCP ACK to port 80, and ICMP timestamp requests, and any positive response marks the host as alive. This is the fastest and quietest way to enumerate responsive systems on 192.168.1.0/24 without revealing which services are open.

Why this answer

The -sn flag in Nmap performs a ping sweep (host discovery) without port scanning, sending ICMP echo requests, TCP SYN to port 443, TCP ACK to port 80, and ICMP timestamp requests by default.

9
MCQeasy

During a penetration test, the tester wants to gather information about the target organization's domain registration and contact details without sending any traffic to the target. Which OSINT source should the tester use first?

A.Shodan
B.crt.sh
C.WHOIS
D.Censys
AnswerC

WHOIS is a standard query/response protocol, usually over TCP port 43, that retrieves the authoritative registration record for a domain from the registry and registrar databases, including registrant and administrative contacts, creation/expiration timestamps, nameservers, and registrar identity. For a penetration tester, performing a passive WHOIS lookup during the information-gathering phase is the direct way to obtain domain registration details and can yield nameservers for later DNS enumeration or contact references for social engineering. Therefore, WHOIS is the correct answer because it specifically returns the registration information requested.

Why this answer

WHOIS lookups provide registration details for domains, including administrative contacts, name servers, and expiration dates, without sending traffic to the target. Shodan searches for internet-connected devices, Censys provides certificates and host information, and crt.sh shows certificate transparency logs.

10
MCQhard

During a penetration test, the tester runs a DNS zone transfer attempt against a target domain. The zone transfer fails. What is the most likely reason?

A.The DNS server is configured to deny zone transfers from unauthorized hosts
B.The DNS server is offline
C.The tester used the wrong tool
D.The domain does not exist
AnswerA

Zone transfers use the AXFR query type to replicate an entire DNS zone. The server's allow-transfer ACL determines which IP addresses may request a full zone copy; when the tester's source IP is not in that list, the server typically responds with a REFUSED or 'Transfer failed' error while still answering normal recursive/authoritative queries, so the attempt appears blocked.

Why this answer

DNS zone transfers are typically restricted by default to authorized secondary DNS servers only. Misconfigured DNS servers might allow zone transfers from any host, but it's uncommon. The failure is likely due to security restrictions.

The authoritative server is not necessarily offline, and the domain might not exist otherwise.

11
MCQmedium

During a penetration test, you want to perform a stealthy port scan that minimizes the chance of being logged by the target. Which Nmap option should you use?

A.-sU
B.-sV
C.-sT
D.-sS
AnswerD

The -sS TCP SYN half-open scan sends a SYN, reads the SYN-ACK, then tears down with RST before the connection completes. Because no session is established, most application and host logging never records it, satisfying the stem's stealth requirement.

Why this answer

The -sS option performs a TCP SYN scan (half-open scan), which sends SYN packets and never completes the TCP handshake. Because the connection is never fully established, the target's application layer never logs the connection, making it the stealthiest common scan type. It requires raw socket privileges (root/admin) but is the default scan type when Nmap is run with elevated privileges.

Exam trap

PT0-003 often tests the misconception that any scan without a full handshake is undetectable; candidates may pick -sT thinking it is stealthy because it is the default for unprivileged users, but it is actually the most logged scan type.

How to eliminate wrong answers

Option A is wrong because -sU performs UDP scanning, which is slow, often unreliable due to ICMP rate limiting, and not inherently stealthy — it can trigger ICMP port-unreachable responses that are logged. Option B is wrong because -sV enables version detection, which actively probes services with additional packets and increases the scan's footprint, making it less stealthy. Option C is wrong because -sT performs a full TCP connect scan using the OS's connect() system call, which completes the three-way handshake and is easily logged by the target application and IDS.

12
MCQmedium

During a penetration test, you need to gather information about a target's email addresses and employee names without directly interacting with the target's systems. Which tool is most appropriate for this passive reconnaissance task?

A.Shodan
B.Censys
C.Maltego
D.theHarvester
AnswerD

theHarvester is the correct answer because it is a dedicated OSINT tool engineered to passively gather emails, subdomains, hostnames, and employee names from public sources. It queries search engines like Bing and Google, PGP key servers, and other open data repositories, making it ideal for the early reconnaissance phase of a penetration test. Its specific focus on email harvesting and subdomain enumeration aligns precisely with the task of gathering information about an organization's digital footprint, unlike general-purpose scanners or link-analysis platforms.

Why this answer

theHarvester is an OSINT tool designed to gather emails, subdomains, IPs, and employee names from public sources like search engines and social media. Maltego is more for relationship mapping, Shodan for internet-facing devices, and Censys for certificate and network data.

13
MCQeasy

During an external penetration test, a tester needs to enumerate DNS records for a target domain to identify mail servers and potential subdomains. The tester has no credentials and wants to use a tool that queries DNS servers directly. Which tool is most appropriate for this task?

A.sqlmap
B.dnsrecon
C.Wireshark
D.John the Ripper
AnswerB

dnsrecon is a dedicated DNS enumeration tool that can query name servers for records such as MX, NS, and A, and can attempt zone transfers and brute-force subdomains. It works without credentials and is designed for the exact task of DNS reconnaissance, making it the most appropriate choice for identifying mail servers and subdomains.

Why this answer

dnsrecon is purpose-built for DNS enumeration, supporting queries for MX, NS, and other record types as well as zone transfer attempts and subdomain brute-forcing. It operates without credentials and directly queries DNS servers. The other tools serve unrelated functions such as packet capture, password cracking, or SQL injection exploitation and cannot perform the required DNS record discovery.

Exam trap

The trap here is confusing general-purpose network or exploitation tools with specialized DNS enumeration utilities that can actively query name servers for records.

14
MCQhard

During a penetration test, you want to discover API endpoints and hidden parameters in a web application. Which tool combination is most effective for this task?

A.Wappalyzer and curl
B.WhatWeb and theHarvester
C.Gobuster and Nikto
D.Arjun and ffuf
AnswerD

Arjun discovers hidden API parameters and endpoints through its extensive wordlists and passive/active scanning, while ffuf fuzzes directories, parameters and virtual hosts at high speed. Together they satisfy the stem's need to uncover endpoints and hidden parameters in a web application.

Why this answer

Arjun is a specialized tool for discovering hidden HTTP parameters by fuzzing with a wordlist and analyzing responses, while ffuf is a fast web fuzzer used for directory, file, and parameter discovery. Together, they efficiently uncover API endpoints and hidden parameters that are not linked in the application's visible interface. This combination is specifically designed for the reconnaissance phase of API testing.

Exam trap

PT0-003 often tests tool specialization; candidates may pick Gobuster and Nikto because they are well-known web tools, but they are not optimized for hidden parameter discovery, which is the specific task in the question.

How to eliminate wrong answers

Option A is wrong because Wappalyzer identifies technologies used by a website (e.g., frameworks, CMS) and curl is a manual HTTP client; neither is designed for automated endpoint or parameter discovery. Option B is wrong because WhatWeb is a fingerprinting tool and theHarvester gathers OSINT (emails, subdomains) from public sources, not hidden API endpoints or parameters. Option C is wrong because Gobuster is for brute-forcing directories and DNS subdomains, and Nikto is a web server scanner for known vulnerabilities; neither specializes in hidden parameter discovery.

15
MCQeasy

A penetration tester is performing passive reconnaissance on a target organization. Which of the following tools would be BEST for discovering subdomains and email addresses associated with the target domain without sending any packets to the target?

A.WPScan
B.Nmap
C.snmpwalk
D.theHarvester
AnswerD

theHarvester is a passive OSINT tool that aggregates publicly accessible information from third-party sources such as search engines, PGP key servers, and certificate transparency logs to collect email addresses, subdomains, hosts, and employee names for a given domain. It never sends packets directly to the target's own infrastructure, so it does not trigger target-side monitoring or violate the passive reconnaissance constraint. Its value lies in building a pre-attack picture of the attack surface from information already available on the internet, making it ideal for the passive phase.

Why this answer

theHarvester is an OSINT tool that collects emails, subdomains, IPs, and URLs from public sources like search engines and PGP key servers without interacting with the target network.

16
MCQmedium

While performing vulnerability scanning, a penetration tester runs a Nessus scan against a web server. The report shows a 'critical' finding, but after manual verification, the tester determines the service is not actually vulnerable. This scenario best describes:

A.A false negative
B.A configuration error
C.A false positive
D.A true positive
AnswerC

A false positive is an alert that a vulnerability scanner generates for a condition that, upon manual verification, does not actually exist. This is precisely what happened here: the scanner flagged a weakness, but penetration testing proved it was not present. Such alerts require triage to filter noise and avoid wasting remediation effort.

Why this answer

A false positive is when a scanner reports a vulnerability that does not actually exist. Penetration testers must verify scanner findings to avoid reporting false positives.

17
Multi-Selecthard

A penetration tester is conducting active reconnaissance on a target network and wants to enumerate SNMP information. Which TWO of the following tools or commands can be used to query SNMP data from network devices? (Select TWO.)

Select 2 answers
A.WPScan
B.snmpwalk
C.nmap with snmp scripts
D.dig
E.tcpdump
AnswersB, C

snmpwalk is the canonical command-line utility for actively enumerating SNMP-enabled devices, sending a sequence of GETNEXT requests to traverse the entire Management Information Base (MIB) tree. By default, it uses the community string 'public' via SNMPv2c, and a successful walk quickly reveals system name, interfaces, contacts, and even process tables—data that is extremely valuable during active reconnaissance. Unlike generic scanners, snmpwalk specifically implements the SNMP protocol and is designed to extract the full OID hierarchy in one pass.

Why this answer

snmpwalk is a standard SNMP tool to retrieve a subtree of MIB data, and nmap can be used with SNMP scripts to enumerate information.

18
MCQhard

During a penetration test, the tester runs an Nmap scan with the -sV option and gets a result showing 'Apache httpd 2.4.49'. This version is known to be vulnerable to a path traversal attack. Which of the following best describes the next step the tester should take?

A.Ignore it because Nmap version detection is unreliable.
B.Attempt to exploit the vulnerability using a known exploit.
C.Report the vulnerability immediately.
D.Move on to other targets since the vulnerability is well-known.
AnswerB

Attempting to exploit the identified vulnerability using a known, publicly available exploit (e.g., a Metasploit module or a PoC from Exploit-DB) is the definitive validation step in penetration testing. It transforms a potential false positive into demonstrated proof by showing that the service is actually vulnerable and the exploit path yields a controlled outcome. This must be executed with explicit authorization and caution, as a failed or unstable exploit could crash the target service, and the tester should gain approval for any exploit that may have a destructive impact. The successful execution provides concrete evidence, including command output and system access, that is far more persuasive to the client than a simple version-match.

Why this answer

After identifying a potentially vulnerable service, the tester should verify the vulnerability by attempting exploitation in a controlled manner to avoid false positives.

19
MCQhard

You are performing a vulnerability scan on a web application and notice that the scanner reports a high-severity SQL injection vulnerability. However, manual testing confirms that the input is properly sanitized. Which term best describes this situation?

A.False negative
B.True positive
C.Inconclusive
D.False positive
AnswerD

A false positive is an incorrect alert in which the scanner reports a vulnerability that does not actually exist in the web application, such as flagging a sanitized input parameter as SQL injectable. This often occurs due to heuristic detection misfires, outdated signature databases, or responses that imitate vulnerability patterns without the underlying weakness. It consumes security team time and resources on investigating and remediating non-existent issues, highlighting why every automated finding should be validated before being acted upon.

Why this answer

A false positive occurs when a scanner incorrectly identifies a vulnerability that does not exist. This is common in automated vulnerability scanning and requires manual verification.

20
MCQhard

A penetration tester is tasked with performing an authenticated vulnerability scan of a Windows network. The tester has domain admin credentials. Which tool is most appropriate for this task?

A.Nikto
B.Nmap
C.theHarvester
D.Nessus
AnswerD

Nessus is a commercial vulnerability scanner that supports credentialed scans via protocols like SSH, WinRM, or SMB, enabling deep assessment of Windows patch levels, service configurations, and custom software. It uses a comprehensive plugin database (e.g., via Nessus or the free Nessus Essentials) to map system state to known vulnerabilities, including missing patches, weak permissions, and policy violations. For authenticated Windows scanning, it connects with provided credentials (local or domain) to query WMI and the registry, making it the correct tool for this task.

Why this answer

Nessus supports authenticated scanning using credentials (e.g., domain admin) to perform deep vulnerability assessment of Windows systems, including missing patches and insecure configurations.

21
Multi-Selecteasy

A penetration tester wants to perform passive reconnaissance on a target organization. Which two activities are considered passive reconnaissance? (Choose TWO.)

Select 2 answers
A.Searching Pastebin for leaked credentials
B.Sending SNMP queries to a network device
C.Scanning ports with Nmap
D.Performing a DNS zone transfer attempt
E.Using crt.sh to view SSL certificates
AnswersA, E

Searching Pastebin for leaked credentials involves querying a third-party data-sharing site rather than touching the target's infrastructure, so no packets reach the organisation's systems. This satisfies the stem's passive reconnaissance constraint, since the tester gathers intelligence without directly interacting with the target's hosts, domains, or network ranges.

Why this answer

Option A is correct because searching Pastebin for leaked credentials involves only reviewing publicly available third-party data without ever touching the target's systems, which is the definition of passive reconnaissance. Option E is correct because crt.sh queries public Certificate Transparency logs to enumerate SSL/TLS certificates and associated subdomains, again relying on externally published data rather than interacting with the target. Option B is not passive because sending SNMP queries directly contacts the target device and can be logged.

Option C is not passive because Nmap port scanning actively probes the target's hosts and services. Option D is not passive because attempting a DNS zone transfer sends a direct AXFR request to the target's name server.

Exam trap

The trap here is that candidates often confuse 'publicly available information' with 'active probing'—for example, assuming that querying crt.sh or Pastebin is active because it involves a web request, when in fact it is passive because the request goes to a third-party service, not the target's own systems.

22
Multi-Selectmedium

A penetration tester is conducting a web application reconnaissance and wants to discover API endpoints and hidden parameters. Which three tools are most appropriate for this task? (Choose THREE.)

Select 3 answers
A.ffuf
B.Wappalyzer
C.Arjun
D.Gobuster
E.Whatweb
AnswersA, C, D

ffuf brute-forces web paths and parameter names using wordlists, directly satisfying the requirement to discover hidden API endpoints and parameters during reconnaissance. Its fuzzing engine substitutes payloads into URL paths or query strings, revealing resources that normal browsing misses, making it appropriate alongside other content-discovery tools.

Why this answer

ffuf (A) is correct because it is a fast web fuzzer that can brute-force directories, files, and API endpoint paths using wordlists, making it ideal for discovering hidden API routes. Arjun (C) is correct because it is specifically designed to discover hidden HTTP parameters by sending requests with common parameter names and analyzing response differences, which directly addresses the hidden-parameter discovery goal. Gobuster (D) is correct because its dir and vhost modes perform dictionary-based brute-forcing of web paths and subdomains, effectively enumerating API endpoints and hidden directories.

Wappalyzer (B) is not appropriate because it only fingerprints technologies (CMS, frameworks, libraries) from page content and headers, not endpoints or parameters. Whatweb (E) is also a fingerprinting tool that identifies web technologies and server banners, so it does not enumerate endpoints or hidden parameters.

Exam trap

The trap here is that candidates may confuse technology fingerprinting tools (Wappalyzer, Whatweb) with active discovery tools, or forget that Gobuster's directory brute-force mode is valid for API endpoint discovery, not just web directories.

23
MCQmedium

You are performing a network scan and need to identify live hosts on a subnet without triggering firewalls that block ICMP. Which technique should you use?

A.ARP scan with arp-scan
B.Ping sweep with nmap -sn
C.TCP SYN ping with nmap -PS
D.UDP scan with nmap -sU
AnswerA

ARP scan with arp-scan is the correct choice because ARP requests operate at Layer 2, directly querying each host on the local broadcast domain. Since ARP traffic is encapsulated in Ethernet frames, IP-based firewalls and host-based packet filters cannot intercept or block these probes, making ARP the most reliable method for discovering live hosts on the same subnet. Additionally, arp-scan sends gratuitous ARP requests and parses replies, efficiently mapping all active MAC and IP addresses without relying on higher-layer protocols.

Why this answer

Using ARP scan (arp-scan) works on local networks and does not rely on ICMP, making it effective even when ICMP is blocked. It sends ARP requests and listens for replies.

24
MCQmedium

You are conducting a penetration test and need to identify subdomains of a target domain using a passive approach that does not generate traffic to the target's servers. Which technique should you use?

A.Certificate transparency logs
B.DNS cache snooping
C.Subdomain bruteforce with gobuster
D.DNS zone transfer
AnswerA

Certificate transparency logs are a passive discovery resource because they are publicly available, append-only ledgers maintained by independent log operators, and querying them does not involve sending any packets to the target organization's own servers or infrastructure. Services like crt.sh or Censys provide APIs that return certificates issued for a domain, often revealing subdomains, wildcard entries, and even expired certificates that were previously in use. This method leaves no trace on the target's DNS logs, web servers, or intrusion detection systems, making it a classic OSINT/ passive-recon technique. For a penetration tester, it provides a high-yield, low-risk baseline for expanding the attack surface before active testing begins.

Why this answer

Certificate transparency logs (e.g., crt.sh) are public logs of SSL/TLS certificates, often containing subdomain names. Querying them is passive and does not interact with the target.

25
MCQhard

During a penetration test, a tester uses the Wayback Machine to review historical versions of the target's website. What is the primary benefit of this activity?

A.It reveals old web pages that may contain sensitive information or forgotten endpoints
B.It bypasses the target's WAF
C.It provides real-time vulnerability data
D.It performs a live vulnerability scan
AnswerA

Historical snapshots stored by the Internet Archive capture the target's web pages at various points in time. Penetration testers can mine these archives to locate old URLs, deprecated backup files, configuration snippets, or even credentials that were inadvertently posted before being removed from the live site. This passive intelligence gathering expands the attack surface by exposing forgotten endpoints that no longer appear in current site maps.

Why this answer

The Wayback Machine archives historical snapshots of web pages, which can reveal old files, endpoints, or sensitive information that may have been removed but are still accessible on the live site.

26
Multi-Selectmedium

A penetration tester is conducting passive reconnaissance and wants to gather information about a target organization's employees, email addresses, and internal structure. Which TWO tools are best suited for this purpose? (Select TWO.)

Select 2 answers
A.Maltego
B.Gobuster
C.Nmap
D.theHarvester
E.Nikto
AnswersA, D

Maltego is a passive OSINT and data-mining tool that aggregates information from public sources such as social media, DNS records, and certificate transparency logs. It uses transforms to pivot between entities — for example, from a domain to an employee email, then to a linked social profile — revealing organizational relationships without ever touching the target's infrastructure. This relationship graphing makes it ideal for passively mapping an organization's attack surface and employee information.

Why this answer

Maltego is a data mining tool that visualizes relationships and can collect info from social media, DNS, and other sources. theHarvester gathers emails, subdomains, and names from public sources. LinkedIn is also used for organizational chart mapping, but the question asks for tools specifically.

27
Multi-Selecthard

You are performing reconnaissance on a target's web application. Which of the following techniques can be used to discover hidden directories and files? (Select THREE.)

Select 3 answers
A.Using feroxbuster
B.Using dirsearch with a common wordlist
C.Running Nikto with default options
D.Using gobuster in dir mode
E.Querying theHarvester
AnswersA, B, D

feroxbuster is a high-performance, Rust-based directory and file bruteforcer built for web content discovery. It uses asynchronous I/O and parallel HTTP requests to rapidly enumerate hidden paths, and its automatic recursion (with the -r flag) lets it descend into discovered directories without manual rescanning. Features like extensions, filters on status codes/sizes, and the --extract-links option to mine further paths from response bodies make it a precise and efficient choice for this phase of recon.

Why this answer

Directory bruteforce tools like dirsearch, gobuster, and feroxbuster are designed to discover hidden directories and files by using wordlists. Nikto is a vulnerability scanner, not primarily for directory discovery. theHarvester is for email/subdomain harvesting.

28
MCQmedium

While performing vulnerability scanning with Nessus, a penetration tester notices that several high-severity vulnerabilities are reported for a web server, but manual verification shows the server is not vulnerable. What is the MOST likely cause of this discrepancy?

A.The scanner used unauthenticated scans, missing the actual vulnerabilities
B.The scanner configuration excluded necessary plugins for accurate testing
C.The target server is behind a load balancer that modifies responses
D.The scanner is reporting false positives due to inaccurate version detection
AnswerD

Version-based detection is a heuristic where the scanner matches a service's banner or fingerprint against a vulnerability database; if the version string is parsed incorrectly or the banner is outdated, false positives occur. For example, a web server with a backported security patch may still display an old version number, leading the scanner to flag a vulnerability that is not actually present. This is a well-known limitation of unauthenticated scanning and a common cause of erroneous positive reports.

Why this answer

Nessus performs version-based detection by analyzing server banners and HTTP response headers. If the web server's software version string is outdated or misconfigured, the scanner may flag vulnerabilities that do not actually exist in the patched or custom-compiled version. This is a classic false positive scenario where the scanner relies on version matching rather than actual exploit verification.

Exam trap

The trap here is that candidates often assume high-severity findings must be real, or they confuse false positives with missed vulnerabilities due to authentication or plugin issues.

How to eliminate wrong answers

Option A is wrong because unauthenticated scans typically reduce visibility and may miss vulnerabilities, but they do not cause false positives; in fact, they more often lead to false negatives. Option B is wrong because excluding necessary plugins would reduce the number of findings, not generate high-severity false positives. Option C is wrong because a load balancer modifies traffic distribution and may affect response headers, but it does not cause Nessus to report vulnerabilities that are not present; the scanner still sees the actual server response.

29
MCQeasy

During the information gathering phase, a penetration tester uses Google dorks to find exposed documents on a target's website. Which Google dork would be most appropriate to find PDF files containing sensitive information?

A.filetype:pdf
B.inurl:admin
C.site:target.com password
D.intitle:index.of
AnswerA

filetype:pdf restricts Google's index to files with the PDF extension, which is ideal for information gathering because PDFs published on a target domain—such as user guides, annual reports, or internal memos—frequently contain metadata, employee names, and technology stack details that are not visible in ordinary HTML pages. During passive reconnaissance, this operator narrows results to a discrete document format that often escapes normal web crawling and may reveal sensitive or forgotten disclosures.

Why this answer

The filetype:pdf dork restricts results to PDF files. Other dorks target different file types or content.

30
MCQeasy

A penetration tester is performing a vulnerability scan on a web server using Nikto. After the scan, the tester notices several findings related to outdated software versions and missing security headers. What should the tester do to validate the findings and reduce false positives?

A.Ignore findings related to missing headers as low priority
B.Manually verify a subset of the findings
C.Increase the scan intensity to get more details
D.Accept all findings as true since Nikto is a reliable tool
AnswerB

Manually verifying a subset of the findings is the correct next step after an automated scan, because tools like Nikto rely on signature matching and often produce false positives that don't reflect the actual application behavior. By using techniques such as inspecting raw HTTP responses, confirming server headers, or re-checking vulnerable files with curl, the tester can confirm whether a finding represents a genuine vulnerability, gauge the scanner's accuracy, and prioritize remediation based on validated evidence.

Why this answer

Manually verifying findings is the best practice to confirm if they are real vulnerabilities or false positives. Relying on scanner output alone is insufficient.

31
MCQhard

A penetration tester is analyzing a web application and wants to discover hidden API endpoints by brute-forcing common paths. Which tool is best suited for this task?

A.WPScan
B.Feroxbuster
C.theHarvester
D.Nikto
AnswerB

Feroxbuster is a Rust-based recursive content discovery tool designed specifically for brute-forcing web directories and files, including API endpoints. It uses dictionary-based wordlists, supports status-code and size filtering, and can recurse into discovered directories, making it effective for mapping undocumented API routes. Its speed and flexibility with custom headers, request methods, and extension fuzzing make it the correct tool for this task.

Why this answer

Feroxbuster is a fast, recursive content discovery tool that supports wordlist-based brute-forcing of directories, files, and API endpoints, with automatic recursion.

32
MCQmedium

A penetration tester is using Shodan to identify internet-facing devices associated with a target organization. Which of the following is Shodan's primary function in the context of passive reconnaissance?

A.Analyzing malware samples
B.Exploiting vulnerabilities in IoT devices
C.Searching for devices and services exposed to the internet
D.Performing live port scans on target IPs
AnswerC

Shodan continuously probes public IP ranges and collects response banners, including HTTP headers, SSH keys, and SNMP strings, which it indexes for instant querying. This enables a pen tester to identify specific device types, software versions, and open ports on a global scale, making it an invaluable reconnaissance tool prior to close-in testing. It allows searching by filter such as 'port:22', 'product:Apache', or 'country:US'.

Why this answer

Shodan is a search engine for internet-connected devices, providing information about services and banners. It does not perform active scans itself; it indexes data from active scanning.

33
MCQeasy

Which Nmap scan type sends SYN packets to determine open ports without completing the TCP three-way handshake?

A.-sU
B.-sS
C.-sT
D.-sN
AnswerB

The -sS option, Nmap's default SYN scan, transmits a raw TCP packet with only the SYN flag set to each port; an open port replies with a SYN/ACK, a closed port with an RST, and a filtered port drops the packet or returns an ICMP unreachable. Because Nmap aborts the handshake immediately upon receiving SYN/ACK, it determines TCP port state without ever completing a full connection, making it fast and relatively unobtrusive.

Why this answer

The SYN scan (-sS) sends a SYN packet and if a SYN/ACK is received, the port is considered open; it does not complete the handshake, making it stealthier than a full connect scan.

34
Multi-Selecteasy

You are conducting passive reconnaissance on a target organization. Which of the following are examples of passive reconnaissance techniques? (Select TWO.)

Select 2 answers
A.Querying certificate transparency logs
B.DNS zone transfer
C.Scanning ports with Nmap
D.Sending phishing emails
E.Performing a WHOIS lookup
AnswersA, E

Querying certificate transparency logs is passive because these logs are publicly auditable ledgers of all issued TLS/SSL certificates, maintained by independent log operators like Google and Cloudflare. An attacker can query them via services such as crt.sh or the ct.googleapis.com API to discover subdomains and certificate details without ever sending a packet to the target's own infrastructure, thereby leaving no trace in the target's logs.

Why this answer

Passive reconnaissance involves collecting information without directly interacting with the target's systems. WHOIS lookups and certificate transparency logs are passive. DNS zone transfer and port scanning are active.

Social engineering is active.

35
MCQmedium

A penetration tester is performing reconnaissance against a target organization and must passively collect email addresses, employee names, and document metadata without directly interacting with the target's servers. Which tool or technique is best suited for this requirement?

A.Nmap with the default script set against the target's mail server
B.theHarvester querying public search engines and data sources
C.Metasploit auxiliary scanner modules against the target's domain controller
D.Nikto scanning the target's public web server
AnswerB

theHarvester is built for OSINT gathering and can query search engines, certificate transparency logs, and other public sources without sending traffic to the target. It returns emails, hostnames, and employee names, matching the passive requirement. It does not need credentials or direct target access, so it avoids alerting the target while still producing actionable reconnaissance data.

Why this answer

theHarvester is designed for passive OSINT collection and can query search engines, certificate transparency logs, and public data sources without sending traffic to the target. It aggregates emails, hostnames, and employee names. The other tools listed are active scanners that interact directly with target systems and do not focus on gathering personnel or email data from public sources.

Exam trap

The trap here is assuming any reconnaissance tool satisfies a passive requirement, when tools like Nmap, Nikto, and Metasploit modules actively touch the target and may be logged.

36
MCQhard

A penetration tester is conducting active reconnaissance and wants to perform a SYN scan on a target network. During the scan, the tester notices that some ports are reported as filtered. What does a filtered port status typically indicate in Nmap?

A.The port is closed and the target responded with a RST packet.
B.The port is open but no service is listening.
C.The target is not responding to any probes.
D.A firewall is blocking the probe packets.
AnswerD

When Nmap receives no response (or an ICMP unreachable message, such as type 3 code 13, administratively prohibited) to a SYN probe to a specific port, it labels that port 'filtered'. This indicates that a firewall or packet-filtering device is interfering with the probe, either by dropping the packet silently or by sending back a rejection message. Consequently, Nmap cannot definitively determine whether the port is open or closed because it lacks a TCP-level response like SYN/ACK or RST. This is a common result when stateful firewalls inspect and block unsolicited inbound packets during active reconnaissance.

Why this answer

Filtered ports in Nmap indicate that a firewall, packet filter, or other network obstacle is blocking the probe packets, preventing Nmap from determining whether the port is open or closed.

37
MCQhard

A penetration tester is performing internal network scanning and wants to identify live hosts on a local subnet without sending IP packets. Which method is most effective in a switched Ethernet environment?

A.TCP SYN scan to common ports
B.Nmap ping sweep with -sn
C.arp-scan
D.SNMP walk
AnswerC

arp-scan sends ARP requests, which operate at layer 2, so it discovers live hosts on the local subnet without transmitting IP packets. In a switched Ethernet environment this bypasses router boundaries and reliably maps active devices by MAC address.

Why this answer

In a switched Ethernet environment, ARP (Address Resolution Protocol) operates at Layer 2 and does not require IP packets to discover hosts. The `arp-scan` tool sends ARP requests to the local broadcast MAC address, and live hosts respond with their MAC addresses, making it the most effective method for identifying live hosts without sending IP packets.

Exam trap

The trap here is that candidates often assume Nmap's `-sn` ping sweep is the standard for host discovery, overlooking that it relies on IP-layer packets, whereas ARP operates at Layer 2 and is the only method that avoids IP packets entirely on a local subnet.

How to eliminate wrong answers

Option A is wrong because a TCP SYN scan sends IP packets (TCP segments over IP) to common ports, which violates the requirement of not sending IP packets. Option B is wrong because Nmap's `-sn` ping sweep typically uses ICMP echo requests, TCP SYN to port 443, or ICMP timestamp requests—all of which are IP-based packets. Option D is wrong because an SNMP walk uses UDP/IP packets to query SNMP-enabled devices, requiring IP communication and not suitable for discovering all live hosts on a local subnet without IP packets.

38
MCQhard

A penetration tester is conducting a web application assessment and discovers that the target uses WordPress. The tester wants to identify installed plugins, themes, and potential vulnerabilities. Which of the following tools is best suited for this task?

A.WPScan
B.OpenVAS
C.Nikto
D.Gobuster
AnswerA

WPScan is purpose-built for WordPress security assessments: it queries the WPScan vulnerability database, enumerates installed plugins, themes, and users, and can test for weak credentials against wp-login. Its fingerprinting goes beyond generic HTTP probing, identifying specific core versions and CVEs, making it the correct choice for a WordPress web application assessment.

Why this answer

WPScan is a dedicated WordPress security scanner that enumerates installed plugins, themes, and known vulnerabilities by querying the WordPress API and fingerprinting version-specific files. It is purpose-built for WordPress assessments, making it the best choice for this task.

Exam trap

The trap here is that candidates often confuse Nikto's general web scanning with CMS-specific enumeration, but Nikto cannot identify WordPress plugins or themes without custom rules.

How to eliminate wrong answers

Option B (OpenVAS) is wrong because it is a general-purpose vulnerability scanner that lacks WordPress-specific enumeration capabilities and does not directly identify plugins or themes. Option C (Nikto) is wrong because it is a web server scanner focused on misconfigurations and outdated server software, not on CMS-specific components like WordPress plugins. Option D (Gobuster) is wrong because it is a directory/file brute-forcing tool that does not perform vulnerability scanning or plugin/theme enumeration.

39
MCQmedium

A penetration tester is conducting passive reconnaissance on a target organization. The tester wants to discover subdomains and associated email addresses without directly interacting with the target's infrastructure. Which combination of tools and sources would be most effective for this task?

A.Wireshark capturing network traffic
B.Nikto scanning the web server
C.theHarvester with Shodan and Google dorks
D.Nmap with subdomain bruteforce
AnswerC

theHarvester is an OSINT tool that passively aggregates data by querying public APIs and search engines such as Shodan and Google dorks. It searches publicly indexed emails, subdomains, and hostnames without ever sending packets directly to the target's own systems, preserving anonymity and leaving no traces in target logs. This makes it a legitimate passive reconnaissance technique.

Why this answer

theHarvester is an OSINT tool that can gather emails, subdomains, and other data from public sources like search engines, PGP key servers, and the Shodan database. It performs passive collection. Maltego can also be used but requires more setup.

Shodan and Google dorks are specific searches but theHarvester automates multiple sources.

40
MCQmedium

A penetration tester is using Nmap to perform an aggressive scan of a target. Which command combines OS detection, version detection, script scanning, and traceroute?

A.nmap -sV -O target
B.nmap -A target
C.nmap -sC -O target
D.nmap -T4 -sV target
AnswerB

The -A flag is Nmap's built-in alias for aggressive scanning, expanding to -O (OS detection), -sV (version detection), -sC (default NSE scripts), and --traceroute. This single command gives a penetration tester the full suite of enumeration techniques in one pass, which is exactly what the question's 'aggressive' wording refers to. Keep in mind that -A can be intrusive and generate significant network traffic, but that is the intended trade-off for thorough reconnaissance.

Why this answer

The -A flag enables aggressive scanning which includes OS detection (-O), version detection (-sV), script scanning (-sC), and traceroute (--traceroute).

41
MCQmedium

During a penetration test, the tester is using Gobuster to enumerate directories on a web server. Which flag would the tester use to specify a list of file extensions to append to each word in the wordlist for discovering files like 'admin.php' or 'config.bak'?

A.-e
B.-x
C.-w
D.-t
AnswerB

-x is the correct flag for this scenario because it appends a comma-separated list of file extensions to each word from the wordlist when fuzzing directories. For example, using -x php,bak makes Gobuster test each word as-is, then with .php appended, and then with .bak appended, which is exactly how a tester discovers hidden backup files such as index.php.bak. Without this flag, Gobuster only requests the literal word paths, missing extension-based files entirely. This is why -x is the right answer for enumerating files with specific suffixes.

Why this answer

The -x flag in Gobuster allows specifying extensions to append to each word during directory/file bruteforcing, enabling discovery of files with those extensions.

42
MCQeasy

A penetration tester is conducting a vulnerability scan on a web server using Nikto. The scan report lists several findings, including a directory listing vulnerability and outdated server headers. Which type of scanner is Nikto?

A.Network port scanner
B.WordPress vulnerability scanner
C.Web server vulnerability scanner
D.General vulnerability scanner
AnswerC

Nikto is a purpose-built web server vulnerability scanner that performs automated HTTP/HTTPS checks for over 7,000 potentially dangerous files and programs, outdated server software, and server misconfigurations, such as insecure HTTP methods and default credentials. It inspects response headers and content to fingerprint the exact server version and cross-references it against known vulnerabilities, covering platforms like Apache, Nginx, and IIS. This makes 'web server vulnerability scanner' the precise and correct classification for Nikto's role in a penetration test.

Why this answer

Nikto is a web server scanner that tests for misconfigurations, outdated software, and common vulnerabilities. Nessus is a general vulnerability scanner, WPScan is for WordPress, and OpenVAS is also a general vulnerability scanner.

43
MCQhard

A penetration tester is reviewing SSL/TLS certificate information for a target domain and wants to discover additional subdomains that share the same certificate. Which resource is best for this purpose?

A.crt.sh
B.Shodan
C.Google Dorks
D.Wayback Machine
AnswerA

crt.sh is a certificate transparency (CT) log search engine that queries public CT logs for any certificate issued for a given domain. Because every publicly trusted TLS certificate must be logged, crt.sh lets a penetration tester enumerate subdomains, including non-indexed or internal-looking hosts, simply by searching the domain name. This makes it the most direct and comprehensive source for SSL/TLS certificate information.

Why this answer

Certificate Transparency logs (e.g., crt.sh) allow searching by domain or certificate fingerprint to find all certificates issued for that domain, often revealing subdomains.

44
MCQhard

A penetration tester is performing a security assessment of a network that uses SNMP. The tester successfully connects to a device using the community string 'public'. Which tool would the tester MOST likely use to enumerate the entire Management Information Base (MIB) tree to extract system information, running processes, and network interfaces?

A.snmp-check
B.MIB Browser
C.snmpwalk
D.Nmap with snmp-brute script
AnswerC

snmpwalk is the standard command-line tool for walking the MIB tree, using SNMP GETNEXT and GETBULK operations to sequentially retrieve all OIDs in a subtree. It recursively enumerates every accessible managed object from the root (or a specified OID), making it the definitive tool for full SNMP information disclosure testing. When an assessment requires a complete snapshot of a device's SNMP-accessible data, snmpwalk is the correct and most comprehensive choice.

Why this answer

snmpwalk is the correct tool because it uses SNMP GETNEXT requests to systematically traverse the entire Management Information Base (MIB) tree, retrieving all OID values from a device. Given the tester already has a valid community string ('public'), snmpwalk can extract detailed system information, running processes, and network interfaces without needing to guess or brute-force credentials.

Exam trap

The trap here is that candidates confuse snmp-check with snmpwalk, assuming both perform the same MIB traversal, but snmp-check only queries a fixed set of OIDs while snmpwalk recursively retrieves the entire tree.

How to eliminate wrong answers

Option A is wrong because snmp-check is a passive information-gathering tool that queries specific SNMP OIDs for known vulnerabilities and misconfigurations, but it does not perform a full recursive walk of the entire MIB tree. Option B is wrong because a MIB Browser is a graphical tool for browsing MIB structures, but it is not the most likely command-line tool used in a penetration test for bulk enumeration; snmpwalk is the standard CLI utility for this task. Option D is wrong because Nmap with snmp-brute script is used to brute-force SNMP community strings, not to enumerate the MIB tree after a valid community string is already obtained.

45
MCQmedium

A penetration tester is using Nmap to perform host discovery on a target network 192.168.1.0/24. The tester wants to identify live hosts without scanning ports. Which Nmap command should be used?

A.nmap -A 192.168.1.0/24
B.nmap -sS 192.168.1.0/24
C.nmap -sV 192.168.1.0/24
D.nmap -sn 192.168.1.0/24
AnswerD

Ping sweep discovers live hosts without port scanning.

Why this answer

The `-sn` flag in Nmap performs a ping sweep (host discovery) without scanning any ports. It sends ICMP echo requests, TCP SYN to port 443, TCP ACK to port 80, and ICMP timestamp requests by default to determine which hosts are alive on the 192.168.1.0/24 network, making it the ideal choice for identifying live hosts without port scanning.

Exam trap

The trap here is that candidates often confuse `-sn` with `-sS` or `-A`, mistakenly thinking that a stealth scan or aggressive scan is needed for host discovery, when in fact `-sn` is the dedicated, port-free host discovery option.

How to eliminate wrong answers

Option A is wrong because `-A` enables aggressive scanning, which includes OS detection, version detection, script scanning, and traceroute — all of which involve port scanning and are not limited to host discovery. Option B is wrong because `-sS` performs a TCP SYN stealth scan, which scans ports on each host to determine their state, not just host discovery. Option C is wrong because `-sV` performs version detection on open ports, which requires an initial port scan and thus does not meet the requirement of identifying live hosts without scanning ports.

46
MCQeasy

During the information gathering phase, a penetration tester wants to discover subdomains of a target domain using DNS queries and potentially brute-forcing common subdomain names. Which of the following tools is specifically designed for subdomain enumeration and can perform both passive and active techniques?

A.Nmap
B.dirsearch
C.Gobuster
D.Amass
AnswerD

Amass is a dedicated open-source subdomain enumeration and attack surface mapping tool developed under the OWASP umbrella. It aggregates passive data from a wide range of public sources—including certificate transparency logs (e.g., crt.sh), DNS archives, search engines, and security APIs like VirusTotal, Shodan, and AlienVault—then supplements that with active techniques such as DNS brute-forcing, zone transfer attempts, and recursive resolution to validate each discovered name. Its graph-based correlation engine links subdomains to related domains and IPs, uncovering infrastructure that a simple brute-forcer or directory scanner would never reveal. This makes Amass not just a subdomain finder, but a foundational tool for building a complete target asset inventory during the information gathering phase.

Why this answer

Amass is a tool that performs subdomain enumeration using passive sources and active brute-forcing. Gobuster and dirsearch are for directory/file enumeration. Nmap is for port scanning.

47
MCQhard

A penetration tester has discovered a web application that appears to be built with WordPress. The tester wants to identify installed plugins, themes, and potential vulnerabilities without triggering intrusion detection systems. Which tool is BEST suited for this task?

A.OpenVAS
B.Nikto
C.WPScan
D.Gobuster
AnswerC

WPScan is the correct choice because it is a purpose-built WordPress security scanner. It enumerates WordPress core, plugin, and theme versions, checks them against known CVE databases, and can identify usernames, weak passwords, and vulnerable components. Its specialized fingerprinting engine and integration with the WPScan API give it far higher accuracy for WordPress-specific vulnerabilities than any general-purpose scanner.

Why this answer

WPScan is a dedicated WordPress vulnerability scanner that can enumerate plugins, themes, users, and known vulnerabilities. It can be configured to use passive methods or throttle requests to avoid detection.

48
MCQhard

A penetration tester uses Shodan to find internet-facing devices belonging to a target company. Which of the following Shodan search filters would most effectively identify devices with a specific organization name?

A.hostname:company.com
B.ssl:company.com
C.org:CompanyName
D.net:192.168.0.0/16
AnswerC

This is the correct approach because Shodan's org field is populated from IP address ownership records via regional internet registries (ARIN, RIPE, APNIC, etc.) and groups every IP address registered to the organization irrespective of hostname, certificate, or service. A penetration tester can thereby enumerate the entire internet-facing footprint of the company in one query, making org:CompanyName the definitive starting point for external reconnaissance rather than relying on incomplete metadata.

Why this answer

The 'org' filter in Shodan allows searching by organization name, which is the most direct way to find devices associated with a company.

49
MCQmedium

A penetration tester is using theHarvester to gather email addresses associated with a target domain. The tool returns several email addresses. What is the primary limitation of using theHarvester for this purpose?

A.It requires authentication to the target's mail server
B.It only searches Google
C.It only finds publicly available email addresses
D.It cannot find subdomains
AnswerC

This is correct because theHarvester is an open-source intelligence (OSINT) tool that collects email addresses from publicly indexed web pages, PGP keys, and other exposed data. It cannot penetrate internal directories, address books, or private mail servers, so emails that are never published online won't be discovered. The result set is limited to those addresses that the target or third parties have intentionally or accidentally made public.

Why this answer

theHarvester collects data from public sources, so its results are limited to what is publicly available. It may miss internal email addresses and can include outdated information. It does not require authentication, and it is not limited to Google only.

50
MCQhard

A penetration tester is assessing a web application and wants to identify hidden parameters that the application accepts. Which tool is specifically designed for parameter discovery?

A.WPScan
B.Arjun
C.Nikto
D.Gobuster
AnswerB

Arjun is a purpose-built tool for discovering hidden GET and POST parameters. It sends requests containing candidate parameter names from a large wordlist and uses response-differential analysis—comparing status codes, response size, and reflected content—to determine whether a parameter affects the server's response. Crucially, it has heuristics for 'reflect' detection, where the parameter name or value appears in the response, a strong signal of parameter existence. This makes it ideal for finding custom parameters not advertised in the UI or API documentation.

Why this answer

Arjun is a tool for discovering HTTP parameters by brute-forcing common parameter names and analyzing responses for changes, making it suitable for parameter discovery.

51
MCQeasy

A penetration tester is conducting passive reconnaissance and wants to find historical snapshots of a target website to identify past vulnerabilities or hidden endpoints. Which online service should the tester use?

A.Shodan
B.Censys
C.Wayback Machine
D.Pastebin
AnswerC

The Wayback Machine archives historical snapshots of websites, letting the tester review past pages, retired endpoints and old vulnerabilities without touching the target. This passive source satisfies the reconnaissance requirement without generating traffic against the organisation.

Why this answer

The Wayback Machine (archive.org) is the correct choice because it archives historical snapshots of websites, allowing a penetration tester to review past versions of a target site to identify previously exposed vulnerabilities, hidden endpoints, or outdated configurations. This aligns with passive reconnaissance, as the tester does not interact directly with the live target.

Exam trap

The trap here is that candidates may confuse passive reconnaissance tools like Shodan or Censys (which focus on live infrastructure) with the Wayback Machine, which is specifically designed for historical web content retrieval.

How to eliminate wrong answers

Option A is wrong because Shodan is a search engine for internet-connected devices and services (e.g., open ports, banners), not for historical website snapshots. Option B is wrong because Censys is a platform for discovering and analyzing internet-connected hosts and certificates, not for retrieving archived web pages. Option D is wrong because Pastebin is a text-sharing service often used for leaked data or code snippets, not for storing historical snapshots of entire websites.

52
MCQhard

During a penetration test, you find a web application that uses JavaScript to make API calls. You want to discover hidden API endpoints and potential secrets (e.g., API keys) embedded in the client-side code. Which approach is most appropriate?

A.Download and analyze the JavaScript files
B.Perform a DNS zone transfer
C.Run a Nikto scan against the application
D.Use theHarvester to search for API endpoints
AnswerA

Downloading and analyzing the JavaScript files is the correct approach because client-side web applications commonly expose API endpoints, authentication logic, and hardcoded secrets within their scripts. By fetching every .js file referenced by the page (including bundled and lazy-loaded modules), you can inspect source maps, search for strings like 'api/', 'token', 'secret', or 'Bearer', and reconstruct the application's internal routing. Tools like Burp Suite, Chrome DevTools, and JSParser can automate extraction, and even minified code can be beautified to reveal hidden functionality that is not visible in normal page interaction.

Why this answer

JavaScript files in client-side web applications often contain hardcoded API endpoints, API keys, and other secrets that developers inadvertently leave in the source code. By downloading and analyzing these files (e.g., via browser developer tools or wget), you can discover hidden endpoints and sensitive tokens that are not exposed in the HTML or network traffic alone.

Exam trap

The trap here is that candidates may confuse information gathering techniques (e.g., DNS zone transfer or OSINT) with client-side code analysis, assuming that API endpoints must be found through network scanning rather than by examining the application's own source code.

How to eliminate wrong answers

Option B is wrong because DNS zone transfer is a network-level technique used to enumerate DNS records (e.g., subdomains) from a DNS server, not to extract API endpoints or secrets from client-side code. Option C is wrong because Nikto is a web server vulnerability scanner that checks for known vulnerabilities and misconfigurations, but it does not parse JavaScript files to find hidden API endpoints or embedded secrets. Option D is wrong because theHarvester is an OSINT tool designed to gather emails, subdomains, and other public information from search engines and PGP servers, not to analyze client-side JavaScript for API endpoints or secrets.

53
MCQeasy

Which of the following tools would best assist a penetration tester in identifying known vulnerabilities in a WordPress installation?

A.OpenVAS
B.WPScan
C.Nessus
D.Nikto
AnswerB

WPScan queries the WordPress vulnerability database and enumerates core version, plugins and themes, matching each against known CVEs. That directly satisfies the stem's requirement to identify known vulnerabilities in a WordPress installation, unlike generic scanners that lack WordPress-specific signature data.

Why this answer

WPScan is specifically designed to enumerate and identify vulnerabilities in WordPress installations, including outdated plugins, themes, and core files. It uses a comprehensive database of WordPress CVEs and security issues, making it the most targeted tool for this task.

Exam trap

The trap here is that candidates often choose a general-purpose vulnerability scanner like Nessus or OpenVAS because they are familiar with them, but the question specifically asks for the best tool to identify known vulnerabilities in a WordPress installation, which requires a specialized scanner like WPScan.

How to eliminate wrong answers

Option A (OpenVAS) is wrong because it is a general-purpose vulnerability scanner that covers a wide range of systems and services, but it lacks the specialized WordPress-focused checks and plugin/theme enumeration that WPScan provides. Option C (Nessus) is wrong because, while it can detect some WordPress vulnerabilities, it is a broad-scope scanner that does not offer the deep, WordPress-specific fingerprinting and database of known vulnerabilities that WPScan does. Option D (Nikto) is wrong because it is a web server scanner that checks for common misconfigurations and outdated server software, but it does not perform the detailed WordPress core, plugin, and theme version analysis that WPScan excels at.

54
MCQhard

A penetration tester is performing active reconnaissance on a target network and wants to enumerate SNMP devices to gather system information. The tester uses snmpwalk with a common community string. Which community string is most likely to provide read-write access if misconfigured?

A.private
B.public
C.internal
D.manager
AnswerA

'private' is the default read-write community string in SNMP v1 and v2c, granting full write access to the device's MIB tree. With this string, an attacker can alter configuration parameters, change routing tables, disable interfaces, or even cause a denial of service by modifying system settings. In active reconnaissance, discovering 'private' is a high-severity finding because it signals complete administrative control over the SNMP-managed device, which is exactly why it is the correct answer here.

Why this answer

SNMP community strings are like passwords. 'public' is the default read-only community string, 'private' is the default read-write community string. 'internal' and 'manager' are less common defaults. The tester should try 'private' for potential read-write access.

55
MCQmedium

During a penetration test, the tester performs a SYN scan with Nmap on a target network. The results show that port 443 is open on a web server. The tester then runs a service version detection scan and discovers the server is running Apache 2.4.41. Which Nmap flags were used in sequence?

A.nmap -A then nmap -O
B.nmap -sS then nmap -sV
C.nmap -sV then nmap -sS
D.nmap -sS then nmap -sC
AnswerB

This is the correct sequential approach: -sS performs a half-open SYN scan to quickly and quietly identify which TCP ports are open, while -sV then sends targeted service probes and performs banner grabs on those exact open ports to enumerate application versions. Separating discovery from version detection allows the tester to control scope and avoid wasting time probing closed or filtered ports. This two-phase methodology is a foundational best practice in network service enumeration.

Why this answer

The tester first performed a SYN scan with -sS to identify open ports, then used -sV for service version detection. -sC runs default scripts, -O is for OS detection, and -A enables aggressive scanning (includes OS detection, version detection, script scanning, and traceroute).

56
MCQhard

A penetration tester is enumerating SMB shares on a Windows host during an internal assessment. The tester has valid domain credentials for a low-privileged user and wants to list shares and identify accessible files without triggering account lockouts. Which tool and approach is most appropriate?

A.Use smbclient with the -L option and the low-privileged credentials to list shares, then connect to accessible shares
B.Run Nmap with the smb-enum-shares script using the guest account
C.Use enum4linux with the -a option to perform all enumeration checks without credentials
D.Run a brute-force SMB login attack with Medusa using a password list against the low-privileged account
AnswerA

smbclient with -L lists shares using provided credentials and does not perform password guessing, so it will not cause lockouts. It allows the tester to connect to shares the low-privileged user can access and browse files. This approach respects the credential constraint and avoids brute-force behavior that could lock the account.

Why this answer

smbclient with the -L option uses the supplied low-privileged credentials to list shares without password guessing, avoiding lockouts. It then allows connecting to shares the user can access to browse files. Brute-forcing is unnecessary and risky, unauthenticated enumeration may be blocked, and using the guest account ignores available valid credentials.

Exam trap

The trap here is assuming brute-forcing or unauthenticated enumeration is needed, when valid low-privileged credentials already allow safe, authenticated SMB share enumeration.

57
MCQmedium

During a penetration test, a tester discovers a web application that uses JavaScript to load API endpoints dynamically. Which technique would be most effective for discovering hidden API endpoints?

A.Analyzing JavaScript files for API endpoints
B.Performing a DNS zone transfer
C.Running a Nikto scan
D.Using Nmap to scan for open ports and services
AnswerA

Analyzing JavaScript files is the definitive technique here because modern single-page applications bundle most of their client-side logic into JavaScript. Static analysis of the code (or dynamic inspection via browser DevTools' Network tab) can reveal backend API URLs, request parameters, authentication tokens, and webpack chunk references that are never publicly documented. Source maps, if left exposed, can even reconstruct the original source to expose hidden or internal endpoints that network scanners cannot see.

Why this answer

JavaScript analysis involves inspecting JavaScript files for hardcoded API endpoints, secrets, and other useful information, making it effective for discovering hidden API endpoints.

58
MCQeasy

Which of the following tools is most commonly used for passive reconnaissance by querying certificate transparency logs to discover subdomains?

A.crt.sh
B.Censys
C.theHarvester
D.Shodan
AnswerA

crt.sh is a dedicated web service and API that aggregates and searches public Certificate Transparency (CT) logs, making it the most commonly used tool for passively discovering subdomains by querying issued SSL/TLS certificates. Because it queries the CT logs directly, it requires no interaction with the target's infrastructure and returns a comprehensive list of subdomains for free without API keys. This passive approach is a standard first step in reconnaissance during penetration testing and bug bounty engagements.

Why this answer

crt.sh is a certificate transparency log search tool that can be used to find subdomains by querying SSL/TLS certificates issued for a domain.

59
Multi-Selectmedium

A penetration tester is performing active reconnaissance on a target web application. Which TWO tools are specifically designed for directory and file enumeration? (Select TWO.)

Select 2 answers
A.Wappalyzer
B.Feroxbuster
C.Nmap
D.Gobuster
E.WhatWeb
AnswersB, D

Feroxbuster is a Rust-based recursive content discovery tool specifically engineered for fast directory and file brute-forcing. It supports wordlist-driven scanning, multiple file extensions, recursion, and automatic filtering of irrelevant status codes and response sizes, allowing penetration testers to efficiently map out hidden web resources. Its speed and recursive crawling make it an excellent choice for active reconnaissance on web applications.

Why this answer

Gobuster and Feroxbuster are both tools specifically designed for directory and file brute-forcing on web servers.

60
MCQmedium

A penetration tester is tasked with performing active reconnaissance on an internal network. The tester wants to identify live hosts and their open ports efficiently while minimizing noise. Which Nmap scan type should be used first to quickly discover which hosts are online?

A.nmap -sS -sV 192.168.1.0/24
B.nmap -A 192.168.1.0/24
C.nmap -sn 192.168.1.0/24
D.nmap -sT 192.168.1.0/24
AnswerC

Correct. Ping sweep quickly identifies live hosts.

Why this answer

The `-sn` flag (ping scan) sends ICMP echo requests, TCP SYN to port 443, TCP ACK to port 80, and ICMP timestamp requests by default to determine if hosts are online without performing port scans. This minimizes network noise and quickly identifies live hosts on the subnet, which is the first step in active reconnaissance before deeper scanning.

Exam trap

Candidates often choose full port scans (-sS or -sT) for initial discovery, overlooking that -sn is specifically designed for low-noise host discovery.

How to eliminate wrong answers

Option A is wrong because `-sS` (SYN stealth scan) combined with `-sV` (version detection) performs a full port scan and service fingerprinting on every host, generating excessive traffic and noise for initial host discovery. Option B is wrong because `-A` enables aggressive scanning (OS detection, version detection, script scanning, traceroute), which is heavy and inappropriate for a quick live-host discovery phase. Option D is wrong because `-sT` (TCP connect scan) completes the full three-way handshake for each port, creating more noise and connection logs than a simple ping sweep.

61
MCQmedium

You are performing a vulnerability scan on an internal network using an authenticated scanner. Which of the following is a primary benefit of authenticated scanning compared to unauthenticated scanning?

A.It eliminates false positives entirely
B.It reduces network traffic
C.It provides more accurate identification of vulnerabilities that require credentials
D.It avoids detection by intrusion detection systems
AnswerC

With valid credentials, the scanner can log in to the target and perform local checks, such as inspecting installed patches, configuration files, running services, and file permissions, rather than relying solely on remote banner grabbing and version inference. This enables the scanner to identify vulnerabilities that only manifest post-authentication, such as weak local security policies or missing cumulative updates, with far greater accuracy.

Why this answer

Authenticated scanning provides deeper insight by checking for missing patches, misconfigurations, and vulnerabilities that require valid credentials to detect, such as local privilege escalation issues.

62
MCQmedium

A penetration tester is performing active reconnaissance on a web application and wants to discover hidden directories and files. Which tool would be most effective for brute-forcing directory names based on a wordlist?

A.Gobuster
B.Nikto
C.theHarvester
D.WPScan
AnswerA

It's a brute-force tool that uses wordlists to discover directories and files on web servers by sending HTTP requests and matching status codes. Unlike vulnerability scanners, Gobuster focuses purely on resource enumeration, making it ideal for mapping an application's structure. In active reconnaissance, it directly interacts with the target to reveal hidden paths.

Why this answer

Gobuster is a tool used for directory/file brute-forcing using wordlists. Dirb is similar but older; gobuster is more modern and flexible.

63
Multi-Selectmedium

A penetration tester is performing host discovery on a subnet. Which TWO of the following Nmap options can be used to discover live hosts?

Select 2 answers
A.-sn
B.-O
C.-sP
D.-sV
E.-sS
AnswersA, C

The -sn flag tells Nmap to skip port scanning entirely and perform only host discovery, sending ICMP echo requests, TCP SYN to port 443, TCP ACK to port 80, and an ICMP timestamp request by default when run as root. It is the canonical ping sweep option for enumerating live hosts on a subnet without probing open ports, making it the correct choice for host discovery.

Why this answer

Both -sn (ping sweep) and -sP (older alias for ping sweep) perform host discovery without port scanning. -sS and -sV are for port scanning and version detection respectively, not host discovery.

64
MCQmedium

A penetration tester is performing DNS reconnaissance and wants to enumerate all subdomains of a target domain by querying DNS servers in an attempt to transfer the entire zone file. Which technique is the tester using?

A.DNS zone transfer
B.DNS reverse lookup
C.DNS cache snooping
D.DNS tunneling
AnswerA

A DNS zone transfer (AXFR) is a legitimate replication mechanism that copies the entire zone file from a primary to a secondary DNS server. When misconfigured to allow unrestricted AXFR, it exposes every record in the zone, including internal host names, IP addresses, and service records, giving an attacker a complete map of the target's network. This makes it the definitive enumeration technique because it returns the full data set in one query.

Why this answer

DNS zone transfer (AXFR) is a mechanism that allows a secondary DNS server to replicate the entire zone file from a primary server. If misconfigured, anyone can request it.

65
MCQmedium

A penetration tester is using Nmap to identify the operating system of a target host. Which Nmap option should be used to enable OS detection?

A.-sV
B.-O
C.-sC
D.-A
AnswerB

-O is the correct answer because it is the dedicated Nmap flag for operating system detection. This option works by sending specially crafted TCP and UDP probes to the target and comparing the responses against Nmap's large database of OS fingerprints, thereby identifying the likely operating system. It is the precise, purpose-built switch for this task, unlike broader or unrelated flags.

Why this answer

The -O option enables OS detection in Nmap.

66
MCQmedium

A penetration tester wants to perform a directory brute-force attack against a web server to discover hidden files and directories. Which tool is best suited for this task?

A.WPScan
B.Nikto
C.Gobuster
D.Nmap
AnswerC

Gobuster is a purpose-built content discovery tool for brute-forcing directories, files, DNS subdomains, and virtual hosts. It loads a wordlist and sends HTTP requests to the target, distinguishing valid resources by filterable response status codes (e.g., 200, 301, 403) and configurable patterns. Its multi-threading, support for file extensions, wildcard detection, and performance make it the standard choice for directory brute-forcing in penetration tests.

Why this answer

Gobuster is a popular tool for directory and file brute-forcing using wordlists, making it ideal for discovering hidden resources on web servers.

67
MCQhard

A penetration tester is analyzing the output of a Nessus vulnerability scan and notices a critical vulnerability reported against a web server that is actually a false positive due to outdated plugin data. What is the best course of action for the tester?

A.Accept the finding as accurate and include it in the report
B.Remove the finding from the report entirely
C.Manually verify the vulnerability by testing it
D.Ignore the finding because it's a false positive
AnswerC

Manual verification entails actively reproducing the vulnerability—e.g., sending a crafted HTTP request to confirm a SQL injection, or checking if a specific CVE applies by reviewing patch levels and exploiting the target in a controlled manner. This step distinguishes real security gaps from false positives generated by the scanner, and also collects proof-of-concept evidence necessary for a credible, actionable penetration test report.

Why this answer

A false positive due to outdated plugin data must be manually verified before any action is taken. The tester should use a tool like `curl` or a browser to send the exact request that Nessus simulated (e.g., an HTTP GET to a specific endpoint) and inspect the response headers or body to confirm whether the vulnerability actually exists. Only after manual validation can the tester decide to include, exclude, or note the finding in the report.

Exam trap

The trap here is that candidates may think a false positive should be removed or ignored outright, but the correct approach is to manually verify the finding to ensure the vulnerability is truly absent before making any reporting decision.

How to eliminate wrong answers

Option A is wrong because blindly accepting a known false positive would introduce inaccurate risk into the report, potentially causing unnecessary remediation efforts. Option B is wrong because removing the finding entirely without documentation violates reporting integrity; the tester should note the false positive and the manual verification steps taken. Option D is wrong because ignoring the finding without verification could miss a real vulnerability if the plugin data was outdated but the vulnerability still exists in a different form.

68
MCQmedium

A tester wants to identify the technologies used by a web application before conducting a deeper assessment. Which tool would be most appropriate for passive technology fingerprinting?

A.Nmap
B.Wappalyzer
C.OpenVAS
D.Nikto
AnswerB

Wappalyzer is a browser extension and library that performs passive technology fingerprinting by inspecting HTTP response headers (e.g., X-Powered-By, Set-Cookie), HTML meta tags, script sources, and other client-side content returned by the web application. It does not send a single request to the target beyond what the browser itself makes, so it identifies frameworks, CMSs, analytics tools, and server software entirely from normal page loads. This makes it the correct tool for passive identification in this scenario.

Why this answer

Wappalyzer is a browser extension or online tool that identifies web technologies (CMS, frameworks, analytics) by analyzing page content and headers without sending probes.

69
MCQmedium

During a penetration test, the tester wants to discover publicly exposed IoT devices related to the target organization. Which OSINT tool is specifically designed for searching devices connected to the internet?

A.Censys
B.Shodan
C.Maltego
D.theHarvester
AnswerB

Shodan is the correct answer because it is a dedicated search engine for internet-connected devices. It works by scanning the entire IPv4 (and IPv6) address space and indexing the banners returned by services like HTTP, SSH, FTP, and Telnet. Penetration testers use Shodan to quickly identify public-facing devices, exposed industrial control systems, and services running on unusual ports, making it the industry-standard tool for internet-facing device discovery.

Why this answer

Shodan is a search engine that indexes banners from internet-connected devices, including IoT, webcams, routers, and industrial control systems.

70
Multi-Selecthard

A penetration tester is performing active reconnaissance on a web application and needs to discover parameters that the application accepts. Which TWO tools are most commonly used for parameter discovery? (Select TWO.)

Select 2 answers
A.ffuf
B.theHarvester
C.WPScan
D.Nikto
E.Arjun
AnswersA, E

ffuf performs fuzzing by substituting wordlist entries into request positions, detecting accepted parameters through response differences in status codes, length or reflection. This directly satisfies the stem's requirement to discover parameters the application accepts during active reconnaissance, using its `-w` wordlist and filter flags to isolate valid hits.

Why this answer

ffuf (A) is correct because it is a fast web fuzzer that can brute-force URL parameters, directories, and POST data using wordlists, making it a standard tool for parameter discovery during active reconnaissance. Arjun (E) is correct because it is purpose-built for HTTP parameter discovery, using a large built-in wordlist and heuristics to find hidden GET/POST parameters efficiently. theHarvester (B) is not correct because it focuses on OSINT gathering of emails, subdomains, and hosts from public sources rather than discovering application parameters. WPScan (C) is not correct because it targets WordPress-specific vulnerabilities and enumeration, not generic parameter discovery.

Nikto (D) is not correct because it is a web server scanner for misconfigurations and known issues, not a parameter brute-forcing tool.

Exam trap

In the CompTIA Pentest+ context, the trap is that candidates often confuse general-purpose web scanners (like Nikto) or CMS-specific tools (like WPScan) with dedicated parameter discovery tools, leading them to select options that perform different reconnaissance tasks.

71
Multi-Selecthard

During a web application penetration test, the tester wants to discover hidden parameters that the application accepts. Which THREE tools are BEST suited for parameter bruteforcing? (Select THREE.)

Select 3 answers
A.WPScan
B.Arjun
C.Nikto
D.ffuf
E.Burp Suite Intruder
AnswersB, D, E

Arjun is a dedicated parameter discovery tool that tries thousands of common parameter names against a target endpoint and detects hidden parameters by analyzing response differences such as reflected values, status code or content-length changes, and timing anomalies. It uses a built-in curated wordlist and supports heuristics, making it far more specialized and efficient for this task than general-purpose scanners. This purpose-built design is why it is the correct answer here.

Why this answer

Arjun (B) is purpose-built for hidden parameter discovery, sending large wordlists of parameter names and analyzing response differences (length, status, reflection) to identify accepted parameters. ffuf (D) is a fast web fuzzer that can brute-force parameter names by fuzzing the query string or POST body with the FUZZ keyword and filtering responses by size, words, or status code. Burp Suite Intruder (E) supports parameter bruteforcing by placing payload positions on parameter names and using sniper/cluster-bomb attacks with wordlists, then reviewing response length or status changes. WPScan (A) is a WordPress vulnerability scanner focused on plugins, themes, and users, not generic parameter discovery.

Nikto (C) is a web server scanner that checks for misconfigurations and known files, but it does not perform parameter-name bruteforcing.

Exam trap

The trap here is that candidates may confuse general web vulnerability scanners (like Nikto or WPScan) with tools that are purpose-built for parameter bruteforcing, leading them to select tools that lack the specific functionality for discovering hidden parameters.

72
MCQmedium

During a web application penetration test, the tester wants to discover hidden directories and files on the target web server. Which tool is best suited for this task, and what technique does it use?

A.Curl - manual HTTP requests
B.Whatweb - web server identification
C.Wappalyzer - technology fingerprinting
D.Gobuster - directory brute forcing
AnswerD

Gobuster is a tool specifically designed for brute-forcing URIs (directories and files) by systematically sending HTTP requests for each entry in a wordlist against the target web server. It is highly efficient, supporting multi-threading, status-code filtering, and extensions, making it ideal for discovering hidden or unlisted resources. Because it automates the iterative request-response cycle and parses responses for valid HTTP status codes, it is the appropriate choice for directory brute forcing in a penetration test. Unlike the other tools, it directly addresses the task of enumerating directory structure.

Why this answer

Directory enumeration tools like gobuster, dirbuster, and dirsearch use wordlist-based brute force to discover hidden directories and files. Gobuster is a common choice. Wappalyzer is for technology fingerprinting, whatweb is for web server identification, and curl is for HTTP requests but lacks directory brute force functionality.

73
MCQhard

A penetration tester is using OpenVAS to perform an authenticated vulnerability scan of a Linux server. The tester has provided valid SSH credentials. Which of the following is a primary benefit of performing an authenticated scan over an unauthenticated scan?

A.Ability to detect vulnerabilities that require local access
B.Reduced network bandwidth usage
C.Faster scan completion time
D.Elimination of all false positives
AnswerA

Authenticated scanning leverages valid credentials to log into the target OS and perform local checks, such as inspecting file permissions, registry keys, installed software versions, and missing security patches. These truly local vulnerabilities are invisible to unauthenticated network-based scans, which can only observe remotely reachable services and banners. This credential-based access is the primary technical justification for choosing an authenticated scan.

Why this answer

Authenticated scans have deeper access to the system, allowing the scanner to check configuration files, patch levels, and local vulnerabilities that are not visible externally.

74
MCQmedium

During a penetration test, a tester wants to discover all live hosts on a subnet without performing a full port scan. Which Nmap command is most appropriate for this purpose?

A.nmap -sS 192.168.1.0/24
B.nmap -sn 192.168.1.0/24
C.nmap -O 192.168.1.0/24
D.nmap -A 192.168.1.0/24
AnswerB

-sn instructs Nmap to skip port scanning entirely and perform host discovery only, sending a blend of ICMP echo requests, TCP SYN to port 443, TCP ACK to port 80, and ICMP timestamp requests to see if targets respond. This quickly identifies live hosts on the 192.168.1.0/24 subnet without enumerating services, reducing time, noise, and the risk of a false negative from a single probe type. It is the correct, purpose-built flag for this task.

Why this answer

The -sn flag performs a ping sweep (host discovery) without port scanning, which is the standard method to discover live hosts on a subnet efficiently.

75
MCQmedium

After gaining initial access to an internal network, a penetration tester wants to identify live hosts on a subnet without generating excessive traffic. Which Nmap command would be most appropriate for host discovery using ICMP echo requests and TCP SYN to port 80?

A.nmap -A 192.168.1.0/24
B.nmap -sS 192.168.1.0/24
C.nmap -O 192.168.1.0/24
D.nmap -sn 192.168.1.0/24
AnswerD

-sn, historically called -sP or "ping sweep," disables port scanning completely and tells Nmap to perform only host discovery, reporting every IP address that is currently reachable on the target subnet. On a local Ethernet network, Nmap uses ARP requests for discovery because they are highly reliable and cannot be filtered without breaking normal IP communications; for remote targets, it combines ICMP echo requests, TCP SYN probes to ports 80 and 443, and ICMP timestamp requests to determine liveness. This yields a fast, low-noise inventory of live systems, which is exactly the right first step when mapping an internal network after gaining initial access, before deciding which IPs warrant deeper port scanning.

Why this answer

Nmap's -sn flag performs a ping sweep, which by default uses ICMP echo, TCP SYN to port 80, and other probes. The other options are for port scanning or OS detection.

Page 1 of 2 · 99 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Reconnaissance and Enumeration questions.