Courseiva

CCNA Reconnaissance and Enumeration Questions

24 of 99 questions · Page 2/2 · Reconnaissance and Enumeration · Answers revealed

76
Multi-Selectmedium

A penetration tester is performing reconnaissance on a target network and wants to identify all live hosts without sending many packets. Which TWO techniques are MOST effective for host discovery in a local subnet? (Select TWO.)

Select 2 answers
A.ARP scan using arp-scan
B.TCP SYN scan on port 80
C.UDP scan on port 161
D.ICMP ping sweep using nmap -sn
E.DNS zone transfer
AnswersA, D

ARP scanning with arp-scan is a Layer 2 host discovery technique that broadcasts ARP requests to an IP range and identifies live hosts by their ARP replies, which include MAC addresses. It is highly effective on the local subnet because ARP is a required protocol for IP communication and cannot be blocked by host-based firewalls, making it a reliable and stealthy way to map live systems without generating TCP or UDP traffic.

Why this answer

Option A (ARP scan using arp-scan) is correct because ARP is a Layer 2 protocol that operates within the local subnet broadcast domain, and arp-scan sends a single ARP request per target IP; any live host must reply with its MAC address, making it fast, reliable, and impossible to block without breaking normal network communication. Option D (ICMP ping sweep using nmap -sn) is correct because nmap -sn performs host discovery by sending ICMP echo requests (plus TCP SYN to 443 and TCP ACK to 80 by default when run as root) and requires only one or a few packets per host, efficiently identifying live systems across a subnet. Option B (TCP SYN scan on port 80) is not a dedicated host-discovery technique; it probes only a single port and will miss hosts that are alive but not listening on port 80, while also generating more packets per host than a ping sweep.

Option C (UDP scan on port 161) targets SNMP and is unreliable for host discovery since closed UDP ports may not respond and many hosts do not run SNMP, producing false negatives. Option E (DNS zone transfer) is an information-gathering technique for enumerating DNS records, not a method for identifying live hosts on a local subnet.

Exam trap

The trap here is that candidates often overlook ARP scans because they think only ICMP or TCP techniques are valid for host discovery, but on a local subnet ARP is the most efficient and stealthy method, while ICMP ping sweeps are also correct but can be blocked by host firewalls.

77
MCQeasy

A penetration tester is performing passive reconnaissance on a target organization. Which of the following tools is best suited for gathering information from public sources such as search engines, social media, and website scraping?

A.theHarvester
B.Metasploit
C.Nessus
D.Nmap
AnswerA

theHarvester is an OSINT tool that passively collects email addresses, subdomains, hostnames, and employee names from public sources such as Google, Bing, LinkedIn, and PGP key servers. It operates without sending any packets directly to the organization's own infrastructure, so it is undetectable and strictly non-intrusive. While it can optionally perform DNS brute forcing when run in active mode, its standard use aligns with passive reconnaissance efforts during the planning phase.

Why this answer

theHarvester is an OSINT tool designed to gather emails, subdomains, IPs, and URLs from public sources like search engines and social media.

78
Multi-Selecthard

A penetration tester is conducting a vulnerability assessment and wants to minimize false positives. Which THREE actions should the tester take? (Select THREE.)

Select 3 answers
A.Run the same scan multiple times
B.Verify findings manually
C.Cross-reference results with multiple scanners
D.Ignore all high-severity findings initially
E.Use authenticated scanning where possible
AnswersB, C, E

Manual verification involves a human analyst inspecting the actual service, configuration, or response to determine if the scanner's reported condition truly exists and is exploitable. For example, a scanner may flag a TLS version based on advertised ciphers, but manual testing (e.g., checking effective protocols via openssl or reviewing server config) can confirm if the issue is real or a misconfiguration that doesn't apply. This step is the gold standard for eliminating false positives because it applies context, logic, and exploitability assessment that automated tools lack.

Why this answer

Option B (Verify findings manually) is correct because manual validation confirms whether a scanner-detected vulnerability is actually exploitable and present, eliminating false positives that automated tools report due to version banners or heuristics. Option C (Cross-reference results with multiple scanners) is correct because different scanners use distinct detection signatures and logic, so correlating findings across tools (e.g., Nessus, OpenVAS, Qualys) helps filter out tool-specific false positives and increases confidence in true findings. Option E (Use authenticated scanning where possible) is correct because credentialed scans log into the target and inspect actual patch levels, configurations, and installed software rather than inferring from remote banners, dramatically reducing false positives.

Option A (Run the same scan multiple times) is not correct because repetition with the same tool and signatures does not resolve false positives and may simply reproduce the same erroneous results. Option D (Ignore all high-severity findings initially) is not correct because dismissing high-severity findings without validation risks missing genuine critical vulnerabilities and does not address false-positive reduction.

Exam trap

The trap here is that candidates may think running the same scan multiple times (Option A) improves accuracy, but it actually increases noise without validating findings, whereas manual verification and cross-referencing are the proven methods to minimize false positives.

79
MCQmedium

A penetration tester is conducting active reconnaissance on a target network and wants to perform a SYN scan to identify open ports without completing the full TCP handshake. Which Nmap flag should the tester use?

A.-sS
B.-sA
C.-sU
D.-sT
AnswerA

The -sS option initiates a TCP SYN scan, often called a half-open scan, because it never completes the three-way handshake. The scanner sends a SYN packet and evaluates the response: a SYN/ACK marks the port as open, while an RST indicates closed. This technique is faster and less likely to be logged by application daemons, though it still requires raw packet privileges and can be detected by modern IDS/IPS.

Why this answer

The -sS flag specifies a SYN scan, which is stealthy and does not complete the three-way handshake.

80
Multi-Selectmedium

A penetration tester is performing initial reconnaissance on a target domain. Which THREE sources can provide historical data about the target? (Select THREE.)

Select 3 answers
A.Wayback Machine
B.Pastebin
C.Shodan
D.Certificate Transparency logs (crt.sh)
E.Nmap
AnswersA, B, D

The Wayback Machine, operated by the Internet Archive, captures and archives web pages at various points in time, allowing a penetration tester to retrieve old versions of a target's website. This is valuable for discovering historical content, previously exposed endpoints, old default pages, or configuration files that were later removed but may still be active or reveal security misconfigurations. Because these snapshots are timestamped, the tester can track changes over time and pinpoint when certain technologies or vulnerabilities were introduced. Unlike live tools, it provides a passive, non-intrusive source of historical data.

Why this answer

The Wayback Machine archives web pages, Pastebin may contain leaked historical data, and certificate transparency logs (crt.sh) provide historical certificate issuance data.

81
MCQeasy

Which of the following is a common community string used in SNMP enumeration?

A.root
B.snmp
C.public
D.admin
AnswerC

The default read-only community string in virtually all SNMPv1/v2c implementations is 'public.' It is a well-known, publicly documented string that attackers test first when discovering an SNMP service. Many devices ship with 'public' enabled, and leaving it unchanged is a critical misconfiguration. This ubiquity is why 'public' is the correct answer to the question.

Why this answer

The default community strings for SNMP are often 'public' for read-only and 'private' for read-write access.

82
MCQeasy

A penetration tester is performing passive reconnaissance and wants to identify subdomains associated with a target domain without directly querying the target's DNS servers. Which tool is specifically designed for this purpose?

A.WPScan
B.Nmap
C.theHarvester
D.Gobuster
AnswerC

theHarvester aggregates subdomains from public sources such as search engines, certificate transparency logs and OSINT datasets, so no packets reach the target's authoritative DNS servers. That satisfies the passive-reconnaissance constraint in the stem, unlike active brute-forcing or zone-transfer tools that query the domain directly.

Why this answer

TheHarvester is specifically designed for passive reconnaissance, gathering subdomains from public sources like search engines (Google, Bing), PGP key servers, and the Shodan database without querying the target's DNS servers directly. This aligns with the requirement to avoid direct interaction with the target's infrastructure, making it the correct choice for passive subdomain enumeration.

Exam trap

The trap is that candidates often confuse passive reconnaissance with tools that perform subdomain enumeration via active queries (e.g., Gobuster or Nmap's dns-brute script), causing them to overlook theHarvester's passive data collection from public sources.

How to eliminate wrong answers

Option A is wrong because WPScan is a WordPress vulnerability scanner that actively probes the target web server, not a passive reconnaissance tool for subdomain discovery. Option B is wrong because Nmap is an active network scanner that sends packets to target hosts, directly querying DNS servers if used with scripts like dns-brute, which violates the passive requirement. Option D is wrong because Gobuster performs active brute-force enumeration of subdomains by sending DNS queries to the target's DNS servers, making it an active technique, not passive.

83
MCQmedium

During a web application penetration test, the tester wants to identify the technologies used by the target website. Which of the following tools is best suited for technology fingerprinting?

A.Nikto
B.Nmap
C.Gobuster
D.WhatWeb
AnswerD

WhatWeb is a dedicated website fingerprinting tool that uses a vast repository of plugins and signatures to identify the technologies powering a web application. It analyzes a wide range of signals, including HTTP headers, HTML source code, meta tags, cookies, script URLs, and inline JavaScript variables, to detect CMS platforms, web frameworks, JavaScript libraries, analytics tools, and even specific version numbers. WhatWeb assigns confidence ratings to each detection, allowing a penetration tester to accurately map the technology stack before selecting targeted attack techniques. This purpose-built nature and comprehensive signature coverage make WhatWeb the correct choice for website technology fingerprinting.

Why this answer

WhatWeb (option D) is the correct choice because it is a dedicated web technology fingerprinting tool that identifies CMS platforms, JavaScript libraries, web servers, and frameworks by analyzing HTTP responses, headers, meta tags, and file signatures. In a web application penetration test, this directly addresses the goal of enumerating the technologies behind the target site. Nikto (A) is a web server vulnerability scanner, not a technology fingerprinter, though it may incidentally reveal some server details.

Nmap (B) is a network/host discovery and port scanning tool with limited HTTP fingerprinting via NSE scripts, and Gobuster (C) is a directory and DNS brute-forcing tool, neither of which is purpose-built for identifying web technologies.

84
MCQmedium

A penetration tester is performing service enumeration on a discovered host and wants to grab banners from open ports to identify the exact software and version running. Which of the following command-line tools would be most appropriate for this task?

A.traceroute target.com
B.ping target.com
C.curl http://target.com
D.nc -v target.com 22
AnswerD

Netcat's verbose flag prints the service banner returned on connect, so nc -v target.com 22 reveals the SSH software and version string. It satisfies the banner-grabbing requirement directly on a chosen port without extra scripting.

Why this answer

`nc -v target.com 22` uses Netcat in verbose mode to connect to port 22 on the target, which triggers the SSH server to send its banner (e.g., "SSH-2.0-OpenSSH_8.9p1"). This banner directly reveals the exact software and version running on that port, making it ideal for service enumeration and banner grabbing.

Exam trap

CompTIA Pentest+ tests the distinction between general connectivity tools (ping, traceroute) and service-specific tools (nc, telnet, nmap -sV), expecting candidates to recognize that only raw TCP connection tools can perform banner grabbing on arbitrary ports.

How to eliminate wrong answers

Option A is wrong because `traceroute` is used to map the network path (hops) between the source and destination, not to connect to open ports or retrieve banners. Option B is wrong because `ping` uses ICMP Echo Requests to test host reachability and does not interact with TCP/UDP services to grab banners. Option C is wrong because `curl http://target.com` sends an HTTP request and retrieves the web page content, but it does not perform raw TCP banner grabbing on arbitrary ports (e.g., SSH on port 22) and may not reveal the exact software version unless the server leaks it in HTTP headers.

85
MCQhard

A penetration tester is performing web application reconnaissance and wants to discover API endpoints and hidden parameters that may not be linked from the main application. Which technique would be most effective for this purpose?

A.Running Nikto for web server vulnerabilities
B.JavaScript analysis for endpoint discovery
C.Directory bruteforcing with gobuster
D.Using Wappalyzer to fingerprint technologies
AnswerB

JavaScript analysis is the correct approach because modern single-page applications often hard-code the API surface in their client-side code, such as REST URLs, GraphQL operation names, and route parameters. By examining network calls (fetch, XHR, WebSocket) and string literals, you can uncover undocumented endpoints that are not linked anywhere else in the HTML or robots.txt. This directly expands the attack surface and is a core web app recon technique.

Why this answer

JavaScript analysis often reveals AJAX API endpoints, keys, and parameters that are not visible in HTML. Directory bruteforcing may find endpoints but JS analysis is more targeted for hidden APIs.

86
MCQmedium

A penetration tester runs a SYN scan against a target and receives SYN-ACK responses from several ports. The tester then runs version detection on those ports. What is the primary purpose of version detection?

A.To identify the operating system of the target
B.To perform a vulnerability scan
C.To determine if the host is online
D.To identify the software and version running on open ports
AnswerD

Version detection is a post-scan enumeration step that sends specially crafted probes to open ports and analyzes the responses to determine the exact software and version, such as 'OpenSSH 8.2p1 Ubuntu 4ubuntu0.5' on port 22. This is typically performed using a tool like Nmap with the -sV flag, which may also try to infer service protocol and back-end. Unlike OS detection, it focuses on the application layer, and unlike vulnerability scanning, it does not evaluate security. The information gathered is essential for matching services to known CVEs and planning further exploitation.

Why this answer

Version detection (-sV) in Nmap identifies the specific software and version running on open ports, helping assess potential vulnerabilities and plan further exploitation.

87
MCQmedium

A penetration tester is performing passive reconnaissance and wants to find historical versions of the target website, including old pages that may contain sensitive information. Which resource should the tester use?

A.Pastebin
B.Shodan
C.Wayback Machine
D.Google dorks
AnswerC

The Wayback Machine, operated by the Internet Archive, automatically crawls and preserves dated snapshots of web pages across the internet. Penetration testers use it during passive reconnaissance to review a target's historical site versions, uncovering removed content, old file paths, or legacy technology. This makes it the definitive resource for viewing a website's past states without directly interacting with the target.

Why this answer

The Wayback Machine (archive.org) archives historical snapshots of websites. Pastebin is for pasted text, Google dorks are for search queries, and Shodan is for device discovery.

88
Multi-Selecthard

A penetration tester is assessing a web application and wants to discover hidden directories, files, and parameters. Which THREE of the following tools are most appropriate for this task?

Select 3 answers
A.Nikto
B.dirsearch
C.Wappalyzer
D.feroxbuster
E.Gobuster
AnswersB, D, E

Dirsearch is an open-source, Python-based command-line tool explicitly built for directory brute-forcing and content discovery. It takes a wordlist of candidate path names, sends HTTP requests for each, and identifies valid resources by analyzing response status codes, sizes, and redirects. It supports recursive scanning, multi-threading, custom HTTP methods, and filters, making it a direct and effective answer to discovering hidden web paths.

Why this answer

dirsearch (B) is a Python-based web path scanner that brute-forces directories and files using wordlists and supports extensions, recursion, and custom headers, making it ideal for discovering hidden content. feroxbuster (D) is a fast Rust-based content discovery tool that performs recursive directory brute-forcing with wordlists and can also fuzz parameters, directly matching the task. Gobuster (E) is a Go-based tool whose dir and vhost modes enumerate hidden directories/files (and DNS subdomains) via wordlist brute-forcing, which is exactly the required discovery activity. Nikto (A) is a web server vulnerability scanner that checks for misconfigurations and known issues rather than brute-forcing hidden paths, Wappalyzer (C) is a technology fingerprinting tool that identifies CMS, frameworks, and libraries from page content, and neither is designed for directory/file/parameter brute-force discovery.

Exam trap

The trap here is that candidates confuse vulnerability scanners (Nikto) or technology fingerprinters (Wappalyzer) with directory brute-forcing tools, leading them to select options that serve different phases of the penetration testing methodology.

89
MCQeasy

A penetration tester is performing reconnaissance on a target web application. The tester wants to identify the web server software and version without causing any disruption. Which tool is specifically designed for this purpose and can also enumerate other web technologies?

A.Nikto
B.Wireshark
C.WhatWeb
D.Nmap with the -sV flag
AnswerC

WhatWeb is a web scanner designed to fingerprint web technologies, including server software, CMS, JavaScript libraries, and more. It sends requests to the target and analyzes responses to identify the technologies in use. It is non-intrusive and ideal for reconnaissance, making it the best choice for this scenario.

Why this answer

WhatWeb is specifically designed for web technology fingerprinting, including server software and version, CMS, and JavaScript libraries. It is non-intrusive and efficient for reconnaissance. Nmap is more general, Wireshark requires manual analysis, and Nikto focuses on vulnerabilities rather than enumeration.

Exam trap

The trap here is assuming that any tool that can identify a web server is equally suited for detailed technology enumeration, when specialized tools like WhatWeb provide more comprehensive and accurate results.

90
MCQeasy

A penetration tester wants to use Google dorking to find publicly accessible documents containing sensitive information on a target domain 'example.com'. Which Google dork would be MOST appropriate to locate PDF files with the word 'confidential'?

A.site:example.com intitle:confidential pdf
B.filetype:pdf site:example.com password
C.site:example.com filetype:pdf confidential
D.site:example.com inurl:pdf confidential
AnswerC

This is the correct Google dork for the objective. The site:example.com operator confines results to the target domain, filetype:pdf restricts results to PDF files, and the standalone keyword 'confidential' matches pages where that term appears within the indexed text of the PDF. Search engines like Google extract and index text content from PDFs, so this query effectively surfaces PDF documents on example.com that contain the word 'confidential,' which is exactly what a penetration tester would want to find during reconnaissance.

Why this answer

The Google dork 'site:example.com filetype:pdf confidential' combines the site restriction to the target domain, the filetype filter for PDFs, and the keyword 'confidential' to search for PDF documents containing that word. This directly matches the requirement to locate publicly accessible PDF files with the word 'confidential' on example.com.

Exam trap

The trap here is that candidates often confuse 'filetype:pdf' with 'inurl:pdf' or 'intitle:pdf', not realizing that 'filetype' specifically filters by file extension, while 'inurl' and 'intitle' search for text in the URL or title, which may not correspond to actual PDF files.

How to eliminate wrong answers

Option A is wrong because 'intitle:confidential pdf' searches for the word 'confidential' in the page title and the literal word 'pdf' anywhere in the page, not for PDF files containing 'confidential'. Option B is wrong because it searches for PDF files containing the word 'password', not 'confidential'. Option D is wrong because 'inurl:pdf confidential' looks for the string 'pdf' in the URL and the word 'confidential' anywhere on the page, which does not guarantee the file is a PDF and may miss PDFs with 'confidential' in the content.

91
Multi-Selectmedium

A penetration tester is conducting a vulnerability scan of a Linux server using OpenVAS. Which TWO scan configurations would provide the MOST comprehensive results? (Select TWO.)

Select 2 answers
A.Scan using the 'Full and fast' configuration
B.Scan using only the 'Discovery' category
C.Authenticated scan with SSH credentials
D.Scan using the 'Denial of Service' configuration
E.Unauthenticated scan with default settings
AnswersA, C

The 'Full and fast' profile in Nessus is the recommended comprehensive scan policy: it activates all plugins except those tagged as 'Denial of Service' or potentially disruptive, and it enables safe port scanning techniques. This ensures maximum vulnerability coverage across all plugin families (such as Windows, Linux, web applications, and databases) while still avoiding outright service disruption. It is the default starting point for a penetration test's vulnerability assessment phase.

Why this answer

Authenticated scans with credentials allow the scanner to log in and check for missing patches, misconfigurations, and vulnerabilities that are not visible externally. Full and fast scan configurations are typical for comprehensive coverage.

92
MCQeasy

When performing vulnerability scanning, which of the following best describes a false positive?

A.A vulnerability that is correctly identified and verified.
B.A vulnerability that is exploited during the test.
C.A vulnerability that the scanner reports but does not actually exist.
D.A vulnerability that exists but the scanner fails to detect it.
AnswerC

This is the definition of a false positive: the scanner generates an alert based on a signature, version banner, or service fingerprint, but the claimed vulnerability does not actually exist in the target environment. For example, an automated scanner might flag a TLS configuration or an installed software version as vulnerable because the detection logic matches a generic CVE, even though the vendor has backported security patches or the vulnerable component is disabled. Such erroneous reports consume remediation resources and cause confusion, which is why manual verification is required before acting on scan results.

Why this answer

A false positive in vulnerability scanning occurs when the scanner reports a vulnerability that does not actually exist. This is option C. False positives are caused by factors such as overly aggressive signature matching, misconfigured scan profiles, or incomplete verification of service responses.

They waste resources by prompting unnecessary remediation efforts.

Exam trap

The trap here is confusing false positives with false negatives; candidates often pick option D because they misremember the definition, but false negatives are missed vulnerabilities, not incorrect reports.

How to eliminate wrong answers

Option A is wrong because a vulnerability that is correctly identified and verified is a true positive, not a false positive. Option B is wrong because a vulnerability that is exploited during the test is a confirmed exploit, not a false positive; false positives are not exploitable. Option D is wrong because a vulnerability that exists but the scanner fails to detect it is a false negative, not a false positive.

93
Multi-Selectmedium

A penetration tester is conducting passive reconnaissance using OSINT techniques. Which TWO of the following are examples of passive OSINT sources?

Select 2 answers
A.Social engineering
B.Certificate transparency logs (crt.sh)
C.snmpwalk
D.WHOIS databases
E.Nmap SYN scan
AnswersB, D

Certificate transparency logs are publicly published records of issued TLS certificates, so querying crt.sh never touches the target's infrastructure. This satisfies the stem's passive constraint, unlike active scanning or direct enumeration, which would generate traffic visible to the target's monitoring.

Why this answer

Certificate transparency logs (crt.sh) (B) are a passive OSINT source because they are public, third-party repositories of issued TLS certificates that a tester can query without sending any traffic to the target's infrastructure, revealing subdomains and hostnames. WHOIS databases (D) are also passive OSINT, as registration records for domains and IP ranges are queried from registry/RIR servers rather than the target itself, exposing registrant, contact, and nameserver data. By contrast, social engineering (A) is an active engagement technique that involves direct interaction with people, not passive collection. snmpwalk (C) actively sends SNMP queries to a device, and an Nmap SYN scan (E) actively probes target ports with TCP SYN packets, so both generate traffic toward the target and are not passive.

Exam trap

CompTIA Pentest+ often tests the distinction between passive reconnaissance (no direct interaction with the target) and active reconnaissance (generates traffic or requires interaction), and candidates may mistakenly classify tools like snmpwalk or Nmap scans as passive because they are automated or do not require credentials.

94
Multi-Selectmedium

A penetration tester is performing active reconnaissance on a web application and wants to discover hidden API endpoints. Which TWO tools are BEST suited for this task? (Select TWO.)

Select 2 answers
A.Wappalyzer
B.Nikto
C.theHarvester
D.Feroxbuster
E.Gobuster
AnswersD, E

Feroxbuster is a fast, recursive content discovery tool written in Rust that uses brute-forcing with a wordlist to find directories and files on web servers. It is specifically effective for API discovery because it supports recursion, file extensions, status-code filtering, and concurrent requests, allowing a tester to uncover hidden REST endpoints such as /api/v1/users or /admin. Its performance and flexibility make it a top choice for active reconnaissance against web APIs.

Why this answer

Gobuster can be used to bruteforce directories and files, including API paths. Feroxbuster is a similar tool written in Rust that is faster and supports recursion. Both are effective for API endpoint discovery.

95
MCQmedium

You are tasked with identifying the technologies used by a web application (e.g., web server, frameworks, libraries) during the reconnaissance phase. Which tool would you use?

A.Gobuster
B.theHarvester
C.Nmap
D.WhatWeb
AnswerD

WhatWeb is a dedicated web technology identification tool that queries the target and analyzes a vast range of indicators, including HTTP headers, meta tags, cookie names, HTML source, and JavaScript variables. Its plugin-based architecture matches thousands of known signatures and reports technologies with confidence levels, covering CMS, frameworks, libraries, and server software. This makes it the correct choice for the stated task of identifying technologies used by a website.

Why this answer

WhatWeb is a tool for fingerprinting web technologies. It identifies software, frameworks, and other components by analyzing HTTP responses and page content. Wappalyzer is a browser extension but WhatWeb is command-line and scriptable.

96
Multi-Selectmedium

A penetration tester is preparing to perform an authenticated vulnerability scan of a network. Which THREE of the following are important considerations before starting the scan? (Select THREE.)

Select 3 answers
A.Using default community strings for SNMP
B.Configuring the scanner to use the appropriate credentials
C.Ensuring the scan will not disrupt production services
D.Selecting a random scan time to avoid detection
E.Obtaining written authorization from the target organization
AnswersB, C, E

Configuring the scanner with valid, appropriately privileged credentials is what makes the scan authenticated and is the single most important technical setup step. Without the correct credentials, the scanner reverts to an unauthenticated posture, producing incomplete results that overlook missing patches, insecure registry entries, local privilege escalation paths, and other authentication-dependent vulnerabilities. The credentials must be stored securely, scoped to the engagement, and granted only the permissions needed to enumerate software versions and system configuration without causing unintended changes.

Why this answer

Authenticated scans require valid credentials to log into systems for deeper assessment. It's important to understand the risk of service disruption, ensure credentials have appropriate privileges, and obtain written authorization to avoid legal issues.

97
MCQmedium

While performing web application reconnaissance, a tester wants to enumerate hidden directories and files on a web server. Which of the following tools is specifically designed for directory brute-forcing?

A.Nikto
B.Gobuster
C.WPScan
D.Nmap
AnswerB

Gobuster is a specialized tool for brute-forcing directories, files, and DNS subdomains using user-supplied wordlists. It generates HTTP requests and evaluates response codes to identify valid paths, making it highly efficient for web application reconnaissance. The tool supports multiple modes (dir, dns, vhost), custom extensions, and threading options, giving testers precise control over enumeration depth and speed. This dedicated focus on resource discovery is exactly what the scenario requires.

Why this answer

Gobuster is specifically designed for directory brute-forcing by using a wordlist to discover hidden directories and files on a web server. It sends HTTP GET requests to the target and reports valid responses (e.g., 200, 301, 403), making it the correct tool for this task.

Exam trap

The trap here is that candidates may confuse Nikto's web scanning capabilities with directory brute-forcing, but Nikto's focus is on vulnerability detection rather than enumerating hidden paths via wordlists.

How to eliminate wrong answers

Option A is wrong because Nikto is a web server vulnerability scanner that checks for known vulnerabilities, outdated software, and misconfigurations, not a directory brute-forcer. Option C is wrong because WPScan is a specialized scanner for WordPress sites, focusing on themes, plugins, and user enumeration, not generic directory brute-forcing. Option D is wrong because Nmap is a network port scanner and host discovery tool, not designed for HTTP-based directory enumeration.

98
MCQmedium

A penetration tester is evaluating the security of a WordPress site. Which tool is specifically designed to scan WordPress installations for vulnerabilities?

A.Nessus
B.WPScan
C.OpenVAS
D.Nikto
AnswerB

WPScan is an open-source security scanner purpose-built for WordPress, included by default in distributions like Kali Linux. It enumerates the WordPress core version, installed themes and plugins, user accounts, and backup or configuration files, then cross-references findings against the WPScan API vulnerability database. This allows it to identify known vulnerabilities in plugins and themes that generic scanners often miss. Because the question asks for a tool specifically for evaluating WordPress security, WPScan is the correct answer.

Why this answer

WPScan is a dedicated WordPress vulnerability scanner that checks for known vulnerabilities in WordPress core, plugins, and themes.

99
MCQeasy

In the context of OSINT, which resource would you use to find historical versions of a company's website that may reveal outdated information or hidden directories?

A.crt.sh
B.Censys
C.Shodan
D.Wayback Machine
AnswerD

The Wayback Machine is an archival service operated by the Internet Archive that crawls the web and stores full snapshots of websites over time, including HTML, CSS, JavaScript, and images. It allows OSINT researchers to query a URL and retrieve the exact version of a page as it appeared on a chosen date, making it the definitive resource for historical website content. Unlike certificate or network-focused search engines, it preserves the actual user-facing content rather than infrastructure metadata.

Why this answer

The Wayback Machine (archive.org) is the correct resource because it archives historical snapshots of websites, allowing you to view past versions that may contain outdated information, hidden directories, or old configurations no longer present on the live site. This is a core OSINT technique for discovering legacy content or forgotten endpoints.

Exam trap

The trap here is that candidates confuse OSINT tools focused on current infrastructure (Shodan, Censys) or certificate data (crt.sh) with the only tool that provides historical web content snapshots, the Wayback Machine.

How to eliminate wrong answers

Option A is wrong because crt.sh is a certificate transparency log search tool that retrieves SSL/TLS certificates issued for domains, not historical website content or directory structures. Option B is wrong because Censys is a search engine for internet-connected devices and certificates, focusing on current network exposure and services, not archived web pages. Option C is wrong because Shodan is a search engine for internet-connected devices (e.g., IoT, servers, routers) and their banners, not for browsing historical versions of a website.

← PreviousPage 2 of 2 · 99 questions total

Ready to test yourself?

Try a timed practice session using only Reconnaissance and Enumeration questions.