Courseiva

CCNA Ptp Tools Code Questions

52 questions · Ptp Tools Code topic · All types, answers revealed

1
MCQeasy

A penetration tester needs to identify live hosts and open ports on a target network. Which tool is most appropriate for this task?

A.Burp Suite
B.Nmap
C.Metasploit
D.Wireshark
AnswerB

Nmap is the canonical tool for network discovery and security auditing because it actively crafts raw IP packets to determine which hosts are up and which ports are open on those hosts. It supports host discovery via ARP, ICMP, TCP ACK, and overhead protocols, and port scanning via techniques like SYN scan (-sS), TCP connect (-sT), and UDP scan (-sU), each of which sends controlled probes and interprets the responses. For example, a SYN-ACK reply indicates an open port, while an RST indicates closed or filtered depending on the context. Its ability to combine multi-layered probing and response analysis makes it the correct choice for this penetration testing stage.

Why this answer

Nmap is the standard tool for network discovery and port scanning.

2
MCQeasy

A penetration tester wants to exploit a vulnerable service on a target using a known module. Which framework provides a large database of exploit modules, payloads, and post-exploitation tools?

A.Burp Suite
B.Wireshark
C.Nmap
D.Metasploit Framework
AnswerD

The Metasploit Framework is the correct choice because it is a dedicated exploitation framework with a large, continuously updated database of exploit modules, payloads, encoders, and post-exploitation tools. It allows a penetration tester to pair a specific exploit (e.g., a buffer overflow in a network service) with a compatible payload (e.g., Meterpreter reverse shell), then launch the attack and maintain interactive access to the compromised host. This workflow directly matches the task of exploiting a vulnerable service, encompassing both the delivery and the post-exploitation phases that standalone tools like Wireshark or Nmap lack.

Why this answer

The Metasploit Framework (option D) is the correct answer because it is specifically designed as a penetration testing platform that includes a vast, regularly updated database of exploit modules, payloads, and post-exploitation tools. This framework allows a tester to select a known module for a vulnerable service, configure a payload, and execute the exploit against a target, making it the standard tool for this purpose.

Exam trap

The trap here is that candidates may confuse a general-purpose security tool (like Burp Suite or Nmap) with the specialized exploit framework, overlooking that only Metasploit provides a centralized database of exploit modules and payloads for direct exploitation.

How to eliminate wrong answers

Option A is wrong because Burp Suite is an intercepting proxy and web application security testing tool; it does not provide a database of exploit modules or payloads for exploiting vulnerable services—it focuses on HTTP/S traffic manipulation and scanning. Option B is wrong because Wireshark is a network protocol analyzer used for packet capture and traffic inspection; it has no exploit modules or payloads and is purely a passive analysis tool. Option C is wrong because Nmap is a network discovery and port scanning tool; while it includes some scripting capabilities (NSE) for vulnerability detection, it does not offer a comprehensive database of exploit modules or payloads for exploitation.

3
MCQeasy

A penetration tester has been given a target IP address and needs to quickly determine which services are running on the target. Which Nmap option should the tester use to perform a SYN scan with service version detection and default NSE scripts?

A.nmap -sS -sV -sC 192.168.1.10
B.nmap -sT -sV -sC 192.168.1.10
C.nmap -A 192.168.1.10
D.nmap -sS -O 192.168.1.10
AnswerA

Correct. SYN scan, version detection, and default scripts.

Why this answer

The -sS flag initiates a SYN stealth scan, -sV enables service version detection by probing open ports to determine application and version information, and -sC runs the default set of NSE scripts for common enumeration tasks. Together, these three options fulfill the requirement to quickly identify running services with version details and additional script-based reconnaissance, all while using a half-open TCP scan to minimize log generation.

Exam trap

The trap is that many test-takers select -A (Option C) believing it is the quickest way to meet all requirements. While -A does enable a SYN scan (when run with root privileges), version detection, and default scripts, it also activates OS detection and traceroute, which are not requested and may add unnecessary time and network activity. The question specifically asks for the combination -sS -sV -sC, which achieves only the required functions.

How to eliminate wrong answers

Option B is wrong because -sT performs a full TCP connect scan, which is slower, more detectable, and does not offer the stealth benefits of a SYN scan; it also completes the full three-way handshake, making it unsuitable for the quick, low-profile scan implied by the question. Option C is wrong because -A is an aggregate flag that enables OS detection (-O), version detection (-sV), script scanning (-sC), and traceroute, which goes beyond the specific requirement of 'SYN scan with service version detection and default NSE scripts' by adding unnecessary OS detection and traceroute, and it does not explicitly specify a SYN scan (it defaults to a connect scan if run without privileges). Option D is wrong because -sS performs a SYN scan but -O enables OS detection instead of service version detection (-sV) and does not include default NSE scripts (-sC), so it fails to meet the requirement for service version detection and script execution.

4
MCQmedium

During code review, a penetration tester identifies the following line in a PHP web application: $sql = "SELECT * FROM users WHERE username='" . $_GET['user'] . "'"; Which type of vulnerability is most likely present?

A.SQL injection
B.Insecure deserialization
C.Command injection
D.Cross-site scripting (XSS)
AnswerA

The $_GET['user'] value is concatenated directly into the SQL string without parameterisation or escaping, so an attacker can inject SQL syntax through the user parameter. This is classic SQL injection, allowing query manipulation or data exfiltration.

Why this answer

Direct concatenation of user input into an SQL query without sanitization results in SQL injection vulnerability.

5
MCQhard

A penetration tester is analyzing a Java application and finds the following code snippet: Object obj = ois.readObject(); where ois is an ObjectInputStream. What vulnerability is most likely present if the input is untrusted?

A.SQL injection
B.Path traversal
C.Insecure deserialization
D.Cross-site scripting
AnswerC

Insecure deserialization is the correct answer because the code likely invokes readObject() on an ObjectInputStream constructed from untrusted input. Attackers can craft a malicious serialized object that, when deserialized, triggers arbitrary code execution through gadget chains in the application's classpath. Java's default deserialization mechanism does not validate the object's class or state, allowing an attacker to exploit this trust boundary. The vulnerability is especially dangerous when the application does not use look-ahead object filtering or allowlist-based class checks before deserializing data.

Why this answer

Insecure deserialization occurs when readObject() is called on untrusted data, potentially leading to code execution.

6
Multi-Selectmedium

A tester is reviewing source code for security vulnerabilities. Which TWO of the following are examples of insecure coding practices that often lead to critical vulnerabilities?

Select 2 answers
A.Validating input with allowlists
B.Concatenating user input directly into SQL queries
C.Using parameterized queries for database operations
D.Storing plaintext credentials in configuration files
E.Using prepared statements in SQL
AnswersB, D

Building SQL statements by directly concatenating unsanitized user input into query strings is the classic SQL injection flaw. An attacker can craft input that alters the query's structure, such as injecting a tautology or a stacked query, to bypass authentication, exfiltrate data, or execute arbitrary database commands. This violates the principle of separating code from data and is a critical vulnerability under OWASP Top 10 injection risks.

Why this answer

Option B is correct because concatenating user input directly into SQL queries builds the query string from untrusted data, allowing SQL injection (e.g., ' OR '1'='1) to alter query logic and potentially read, modify, or delete database contents. Option D is correct because storing plaintext credentials in configuration files exposes secrets to anyone with file or repository access, leading to credential theft, lateral movement, and full account compromise. Options A and C are secure practices: allowlist validation restricts input to known-good values, and parameterized queries separate code from data to prevent injection.

Option E is also secure: prepared statements precompile the SQL structure so bound parameters cannot change query semantics.

Exam trap

The trap here is that candidates may confuse secure practices (like parameterized queries or allowlists) with insecure ones, or fail to recognize that storing plaintext credentials is a critical vulnerability because it exposes secrets if the configuration file is accessed.

7
MCQeasy

A penetration tester is analyzing a suspicious executable found on a compromised Windows host. The tester wants to identify if the executable is packed or obfuscated, which might indicate malware. Which tool is specifically designed for detecting packers and providing information about the executable's structure?

A.Nmap
B.PEiD
C.Metasploit
D.Wireshark
AnswerB

PEiD is a tool that detects most common packers, cryptors, and compilers for PE executables. It analyzes the executable's signatures to identify if it is packed and often provides the packer name. In this scenario, the tester can use PEiD to quickly determine if the executable is packed, which is a common characteristic of malware. This helps in deciding the next steps for analysis.

Why this answer

PEiD is a classic tool for detecting packers and identifying the compiler used to build a PE executable. It works by scanning for known signatures in the executable's entry point and other sections. If the executable is packed, PEiD will often display the packer's name, which is valuable information for malware analysis.

This helps the tester understand if the executable is obfuscated and may need to be unpacked before further analysis.

Exam trap

The trap here is selecting a network or exploitation tool for binary analysis, when the task specifically requires static inspection of a PE file for packing.

8
MCQmedium

During a code review, a penetration tester identifies a PHP function that executes arbitrary shell commands. Which function poses the greatest security risk if user input is not sanitized?

A.echo
B.strlen
C.system
D.array_pop
AnswerC

system() is a PHP function that schedules an external command for execution by the system shell and displays its output. When user-controlled input is concatenated into the command string without proper escaping, an attacker can inject shell metacharacters such as ; or && to chain arbitrary commands (e.g., system('ping ' . $_GET['ip'])). This direct OS interaction makes system() a classic command injection sink and the correct dangerous function in the review.

Why this answer

system() executes commands and returns output, allowing arbitrary command execution if input is unsanitized.

9
MCQhard

A penetration tester is analyzing a web application and discovers that it uses a JSON Web Token (JWT) for session management. The tester captures a token and notices that the signature algorithm is 'none'. The application accepts tokens with the 'none' algorithm. Which type of vulnerability does this represent, and what is the immediate impact?

A.Weak signing key vulnerability, allowing brute-force of the HMAC secret
B.Token replay attack due to lack of expiration validation
C.JWT signature bypass due to 'none' algorithm acceptance, enabling token forgery
D.Algorithm confusion attack, allowing token forgery with arbitrary claims
AnswerC

When a JWT is signed with the 'none' algorithm, it has no signature. If the application accepts such tokens, an attacker can modify the payload (e.g., change the username or role) and set the algorithm to 'none', and the token will be considered valid. This allows privilege escalation or impersonation. The immediate impact is that the tester can forge tokens with arbitrary claims, bypassing authentication and authorization.

Why this answer

Accepting JWTs with the 'none' algorithm means the application does not verify the token's integrity. An attacker can craft a token with any claims and set the algorithm to 'none', and the server will trust it. This is a critical authentication bypass.

The immediate impact is that the tester can impersonate any user or escalate privileges by modifying the token payload. Proper validation should reject tokens with 'none' unless explicitly intended and secured.

Exam trap

The trap here is confusing the 'none' algorithm vulnerability with algorithm confusion or weak key attacks, when in fact it is a straightforward signature bypass that allows arbitrary token forgery.

10
MCQmedium

In a Python script for a penetration test, you need to craft a custom TCP packet with specific flags. Which library is best suited for low-level packet manipulation?

A.requests
B.scapy
C.socket
D.impacket
AnswerB

Scapy is purpose-built for packet crafting and manipulation. It provides a declarative, layer-by-layer API where you can compose packets like `IP(src='10.0.0.1')/TCP(dport=80, flags='S')`, then send them with functions such as `send()`, `sendp()`, or `sr()`. Scapy also handles checksum calculation, fragmentation, retransmissions, and dissection of responses, making it the de facto standard for network exploration, fuzzing, and custom TCP flag testing in penetration tests.

Why this answer

Scapy allows crafting, sending, and sniffing network packets at a low level, supporting custom TCP flags.

11
Multi-Selecteasy

A penetration tester is reviewing source code and wants to identify common hardcoded credentials and input validation gaps. Which three checks should the tester perform? (Choose THREE.)

Select 3 answers
A.Verify the use of HTTPS
B.Identify usage of eval, exec, or system with user input
C.Search for hardcoded passwords or API keys
D.Look for SQL queries constructed with string concatenation
E.Check for proper session timeout implementation
AnswersB, C, D

Functions such as eval(), exec(), system(), and shell_exec() are extremely dangerous when they incorporate user-controlled data because they allow arbitrary code or OS commands to be executed. In a source review, you must trace every input that flows into these call sites, verify that proper allowlisting or input sanitization is in place, and consider replacing them with safer APIs. A single unguarded call can enable full command injection, making this a primary target for manual security review.

Why this answer

Hardcoded credentials, concatenated SQL queries, and dangerous functions like eval/exec/system are common vulnerabilities.

12
MCQmedium

A tester needs to enumerate Windows domain users and groups from a compromised system. Which PowerShell script would be most useful?

A.Invoke-Mimikatz
B.PowerView
C.Prowler
D.ScoutSuite
AnswerB

PowerView is a PowerShell tool from PowerSploit specifically designed for Active Directory enumeration. It uses LDAP queries to retrieve detailed information about domain users, groups, computers, and ACLs via cmdlets like Get-DomainUser and Get-DomainGroup. This directly fulfills the tester's requirement to enumerate Windows domain users and groups, making it the correct choice.

Why this answer

PowerView is a PowerShell tool specifically designed for Windows domain enumeration, allowing testers to query Active Directory for users, groups, computers, and permissions via LDAP. It leverages the Active Directory Services Interface (ADSI) to gather detailed information without requiring additional privileges beyond those already obtained on the compromised system.

Exam trap

The trap here is that candidates may confuse credential-dumping tools (like Mimikatz) with enumeration tools, or mistake cloud auditing tools (Prowler, ScoutSuite) for Windows domain enumeration scripts, because all are used in post-exploitation but serve fundamentally different purposes.

How to eliminate wrong answers

Option A is wrong because Invoke-Mimikatz is a PowerShell wrapper for Mimikatz, which focuses on credential dumping (e.g., extracting plaintext passwords, hashes, and Kerberos tickets) rather than enumerating domain users and groups. Option C is wrong because Prowler is an AWS security auditing tool that checks for misconfigurations in cloud environments, not Windows Active Directory enumeration. Option D is wrong because ScoutSuite is a multi-cloud security auditing tool (AWS, Azure, GCP) and does not perform Windows domain user or group enumeration.

13
MCQmedium

A penetration tester is reviewing a Python script used for a custom exploit. Which of the following code snippets contains a dangerous function that could lead to remote code execution?

A.input('Enter name:')
B.open(filename, 'r')
C.eval(user_input)
D.subprocess.run(['ls'])
AnswerC

eval() executes its argument as Python code, so attacker-controlled input runs arbitrary commands on the host. This is the dangerous function enabling remote code execution, unlike safer alternatives such as int() or json.loads(), which parse data without executing it.

Why this answer

The `eval()` function in Python interprets and executes the string passed to it as a Python expression. If an attacker can control the `user_input` string, they can inject arbitrary Python code, leading to remote code execution (RCE). This is a classic dangerous function in Python that should never be used with untrusted input.

Exam trap

CompTIA often tests the misconception that `input()` in Python 3 is dangerous like Python 2's `input()`, or that `subprocess.run` with a list is automatically safe, when the real danger is `eval()` and its equivalents (`exec()`, `compile()`).

How to eliminate wrong answers

Option A is wrong because `input()` in Python 3 simply returns the user's input as a string without evaluating it; it is safe from code injection (unlike Python 2's `input()` which used `eval()`). Option B is wrong because `open()` is a standard file operation that does not execute code; it only opens a file for reading or writing and is not inherently dangerous. Option D is wrong because `subprocess.run(['ls'])` runs a fixed command (`ls`) with no user-controlled arguments; while `subprocess.run` can be dangerous if user input is passed unsanitized, this specific snippet uses a hardcoded list, so it does not allow arbitrary command injection.

14
MCQeasy

A penetration tester needs to perform an online brute-force attack against an SSH service. Which tool is most appropriate?

A.Hydra
B.John the Ripper
C.CrackMapExec
D.Hashcat
AnswerA

Hydra is a network authentication brute-force tool designed to perform online attacks against live services. It actively submits username and password guesses to a running protocol such as SSH, HTTP, or FTP over the network, making it the correct choice for an online SSH brute-force attempt. Hydra supports many protocols, can employ custom wordlists, and offers concurrency controls to speed up the attack while respecting service limitations.

Why this answer

Hydra is a versatile online brute-force tool supporting many protocols including SSH.

15
MCQmedium

A penetration tester has captured a WPA2 handshake. Which tool from the Aircrack-ng suite is used to crack the pre-shared key?

A.airmon-ng
B.airodump-ng
C.aireplay-ng
D.aircrack-ng
AnswerD

Aircrack-ng performs the actual offline cryptanalysis of the captured four-way handshake, deriving the WPA2 pre-shared key by testing candidate passphrases against the MIC. Other suite tools only capture, inject or deauthenticate; aircrack-ng is the cracking component the scenario requires.

Why this answer

Aircrack-ng (option D) is the tool in the Aircrack-ng suite specifically designed to crack WPA2 pre-shared keys (PSK) by performing an offline dictionary or brute-force attack against the captured four-way handshake. It uses the handshake data (specifically the EAPOL frames) to derive the Pairwise Master Key (PMK) and verify it against candidate passphrases, making it the correct choice for this task.

Exam trap

The trap here is that candidates often confuse the tool that captures the handshake (airodump-ng) or the tool that forces the handshake (aireplay-ng) with the tool that actually performs the cryptographic cracking (aircrack-ng), leading them to select a wrong option.

How to eliminate wrong answers

Option A (airmon-ng) is wrong because it is used to enable or disable monitor mode on wireless interfaces, not to crack captured handshakes. Option B (airodump-ng) is wrong because it captures packets and handshakes but does not perform any cracking; it only outputs the handshake for later use. Option C (aireplay-ng) is wrong because it injects packets (e.g., deauthentication frames) to force a client to reconnect and generate a handshake, but it does not crack the PSK.

16
MCQmedium

A penetration tester wants to exploit a Windows system using a known vulnerability and gain a meterpreter session. Which tool is most appropriate?

A.CrackMapExec
B.Metasploit Framework
C.Impacket
D.Hydra
AnswerB

The Metasploit Framework is a comprehensive exploitation platform that ships with hundreds of ready-to-use exploits, payloads, encoders, and auxiliary modules. For Windows, it can target specific Common Vulnerabilities and Exposures (CVEs) such as MS17-010 EternalBlue or SMBv2 exploits and deliver a Meterpreter payload to establish a command-and-control session. It is purpose-built for the exploitation phase, directly triggering a vulnerability to gain initial code execution on the target.

Why this answer

Metasploit Framework (B) is the most appropriate tool because it provides a comprehensive exploit development and execution environment, including pre-built modules for known Windows vulnerabilities and seamless integration with Meterpreter payloads. Unlike the other options, Metasploit is specifically designed to deliver a Meterpreter session after exploitation, handling payload generation, staging, and post-exploitation tasks natively.

Exam trap

The trap here is that candidates confuse tools used for post-exploitation or credential attacks (CrackMapExec, Hydra) with the actual exploit delivery framework (Metasploit) required to gain a Meterpreter session from a known vulnerability.

How to eliminate wrong answers

Option A (CrackMapExec) is wrong because it is a post-exploitation and lateral movement tool that automates tasks like credential spraying and SMB enumeration, but it does not include exploit modules to trigger a known vulnerability or deliver a Meterpreter session. Option C (Impacket) is wrong because it is a collection of Python scripts for network protocol manipulation (e.g., SMB, Kerberos) and can be used for exploitation (e.g., PsExec), but it lacks a built-in exploit framework and does not natively generate or handle Meterpreter payloads. Option D (Hydra) is wrong because it is a network login cracker that performs brute-force attacks against authentication services (e.g., SSH, FTP, RDP) and has no capability to exploit software vulnerabilities or deliver a Meterpreter session.

17
MCQeasy

During a penetration test, the tester wants to capture network traffic for later analysis. Which tool is most appropriate for capturing packets and saving them to a pcap file?

A.Wireshark
B.Metasploit
C.Burp Suite
D.Nmap
AnswerA

Wireshark is a network protocol analyzer that captures live traffic by putting the network interface into promiscuous mode via libpcap (or Npcap on Windows) and decoding frames from the data-link layer through the application layer. It is the standard tool for raw packet capture because it passively observes all packets on a network segment, regardless of transport protocol (TCP/UDP) or application (HTTP, SSH, DNS, etc.). Its dissectors, filters, and follow-stream capability directly support analyzing captured traffic, making it the correct choice for this task.

Why this answer

Wireshark is a network protocol analyzer capable of capturing live traffic and saving it to pcap files.

18
MCQmedium

A penetration tester has obtained a set of NTLM password hashes from a Windows domain controller. The tester wants to perform an offline cracking attack using GPU acceleration. Which tool is best suited for this purpose?

A.Hashcat
B.CrackMapExec
C.John the Ripper
D.Hydra
AnswerA

Hashcat performs offline hash cracking and supports GPU acceleration through OpenCL and CUDA, making it suited to NTLM hashes at high speed. It also handles NTLM format directly, unlike tools built for network capture or online authentication attacks.

Why this answer

Hashcat is purpose-built for offline password cracking and is optimized for GPU acceleration via OpenCL and CUDA, supporting NTLM hashes with modes like '-m 1000'. It scales across multiple GPUs and offers rule-based, mask, and combinator attacks, making it the standard tool for high-speed offline cracking.

Exam trap

PT0-003 often tests the distinction between online brute-force tools (Hydra, Medusa) and offline crackers (Hashcat, John) — candidates pick John for GPU work, but Hashcat is the GPU-optimized choice.

How to eliminate wrong answers

Option B is wrong because CrackMapExec is a post-exploitation and lateral-movement tool for SMB/WinRM, not a GPU-accelerated hash cracker. Option C is wrong because John the Ripper, while capable of offline cracking, is primarily CPU-optimized (Jumbo builds support OpenCL but with less GPU efficiency and fewer GPU-specific optimizations than Hashcat). Option D is wrong because Hydra is an online brute-force tool for network services (SSH, FTP, HTTP), not an offline hash cracker.

19
Multi-Selectmedium

A penetration tester has captured network traffic and wants to analyze it using Wireshark. Which two actions can the tester perform to focus on specific types of communication? (Choose TWO.)

Select 2 answers
A.Use the Conversations window
B.Decrypt SSL/TLS traffic
C.Apply a display filter
D.Run a port scan
E.Generate a report with Nmap
AnswersA, C

The Conversations window aggregates captured traffic into endpoint pairs, showing byte counts, packet totals and duration per conversation. This satisfies the requirement to focus on specific communication types by revealing which hosts exchanged data and letting the tester drill into a chosen stream.

Why this answer

Option A is correct because Wireshark's Conversations window (Statistics > Conversations) groups captured packets by protocol and endpoint pairs (Ethernet, IPv4, IPv6, TCP, UDP), letting the tester quickly identify and isolate specific communication flows between hosts. Option C is correct because display filters (e.g., tcp.port == 443, ip.addr == 10.0.0.5, http) narrow the visible packet list to only the traffic matching specified protocol fields, which is the primary way to focus on particular types of communication. Option B is not appropriate here because decrypting SSL/TLS requires possessing the private key or session keys and is not a filtering/focusing action Wireshark performs on its own.

Option D is incorrect because a port scan is an active reconnaissance technique that generates new traffic rather than analyzing the already-captured traffic. Option E is incorrect because Nmap is a separate scanning tool and does not produce Wireshark analysis reports.

Exam trap

PT0-003 often tests the difference between passive analysis features in Wireshark (Conversations, display filters) and active techniques (port scanning, decryption setup), causing candidates to select actions that are not native Wireshark analysis steps.

20
MCQmedium

A tester needs to perform an online brute-force attack against an SSH service. Which tool is most suitable?

A.Hashcat
B.Hydra
C.John the Ripper
D.Aircrack-ng
AnswerB

Hydra is a well-known network authentication cracker that performs online brute-force attacks by repeatedly submitting login credentials to a live service over the TCP/IP stack. For SSH specifically, Hydra invokes the SSH protocol handshake, supplies candidate username/password pairs, and inspects the server's authentication response to determine success. Its parallelism and modular protocol support (including the 'ssh' module) make it the appropriate choice for attacking a remote host where the password is guessed at the service itself.

Why this answer

Hydra is a fast online brute-force tool that supports many protocols including SSH.

21
MCQhard

During a source code review of a PHP application, the tester finds the following line: $query = "SELECT * FROM users WHERE username = '" . $_POST['username'] . "'"; Which vulnerability is present?

A.Cross-site scripting (XSS)
B.Path traversal
C.Command injection
D.SQL injection
AnswerD

SQL injection is the correct answer because the source code concatenates user-supplied input directly into a SQL query without using parameterized prepared statements or proper escaping. For example, a query built as "SELECT * FROM users WHERE username = '" . $_POST['user'] . "'" can be exploited with a payload like ' OR '1'='1 to bypass authentication or with UNION-based queries to extract sensitive data. This flaw allows an attacker to read, modify, or delete database contents, and in some cases execute stored procedures, depending on the database user's privileges. The remediation is to use prepared statements with bound parameters, which separate data from SQL code and prevent the attack.

Why this answer

Concatenating user input directly into an SQL query without sanitization leads to SQL injection.

22
MCQhard

A penetration tester is analyzing a compiled Linux binary that appears to validate license keys. The tester wants to understand the validation logic without access to source code. The binary is stripped of symbols and uses anti-debugging techniques. Which approach is most effective for discovering the validation algorithm?

A.Perform a differential analysis by running the binary with valid and invalid keys and comparing system calls.
B.Run strings on the binary to extract all printable characters.
C.Use a debugger like GDB with anti-anti-debugging plugins to trace execution and set breakpoints on validation routines.
D.Use a hex editor to search for patterns in the binary that resemble known cryptographic constants.
AnswerC

A debugger such as GDB allows the tester to step through execution, inspect registers and memory, and set breakpoints on functions that handle input. With plugins like peda or gef, anti-debugging techniques can be bypassed or neutralized. This dynamic analysis reveals the actual validation logic as it runs, including comparisons and branching. It is the most effective way to understand a stripped binary's algorithm when static analysis is hindered.

Why this answer

Dynamic analysis with a debugger allows the tester to observe the binary's execution in real time, bypass anti-debugging protections, and identify the exact instructions that validate the license key. By setting breakpoints on input-handling functions and tracing comparisons, the tester can reconstruct the algorithm. Static methods like strings or hex pattern searches are insufficient for complex, stripped binaries.

Exam trap

The trap here is relying on static analysis alone when the binary is stripped and protected, missing the need for dynamic debugging to understand runtime behavior.

23
MCQhard

A penetration tester is performing a cloud security audit of an AWS environment. Which tool is specifically designed for AWS exploitation and post-exploitation, including privilege escalation and persistence?

A.Pacu
B.CrackMapExec
C.ScoutSuite
D.Prowler
AnswerA

Pacu is the correct answer because it is an open-source AWS exploitation framework designed specifically for offensive cloud security testing. It automates attack chains against AWS environments, including privilege escalation, Lambda backdooring, and S3 bucket misconfiguration exploitation, making it the only option that directly performs exploitation rather than just auditing or reconnaissance.

Why this answer

Pacu is an AWS exploitation framework that provides modules for enumeration, privilege escalation, and persistence.

24
Multi-Selectmedium

During a penetration test, a tester needs to perform a deauthentication attack to force a client to reconnect and capture the WPA handshake. Which two tools from the Aircrack-ng suite are required? (Choose TWO.)

Select 2 answers
A.airmon-ng
B.aircrack-ng
C.aireplay-ng
D.airodump-ng
E.airolib-ng
AnswersC, D

aireplay-ng is the correct tool because it can inject arbitrary 802.11 frames, including deauthentication packets. The command `aireplay-ng -0 <count> -a <BSSID> <interface>` sends repeated deauth frames to disconnect connected clients, forcing them to reconnect and generate new EAPOL handshakes that airodump-ng can capture. It is the active component of the deauthentication attack.

Why this answer

Airodump-ng captures the handshake, and aireplay-ng sends deauth packets.

25
MCQhard

During a reverse engineering task on a .NET binary, which tool would allow you to decompile the code into readable C# source code?

A.IDA Pro Free
B.Ghidra
C.jadx
D.dnSpy
AnswerD

dnSpy is a purpose-built .NET assembly editor, decompiler, and debugger that can read .NET metadata, decode CIL bytecode, and reconstruct readable C# or VB.NET source code. It also supports editing assemblies in place and debugging managed code, making it the correct choice when the target is a .NET binary.

Why this answer

dnSpy is a .NET decompiler that can produce high-level source code from .NET assemblies.

26
MCQeasy

Which tool would be best for capturing and analyzing network packets to troubleshoot a web application?

A.Nmap
B.Wireshark
C.Burp Suite
D.Aircrack-ng
AnswerB

Wireshark is a full-featured packet analyzer that captures frames in promiscuous mode via libpcap/WinPcap and dissects hundreds of protocols across all OSI layers. It supports live capture and offline analysis, with powerful display filters, color coding, TCP stream reassembly, and expert information to identify anomalies. This makes it the standard tool for traffic capture and analysis.

Why this answer

Wireshark is the correct tool because it is designed specifically for deep packet inspection, allowing you to capture live network traffic and analyze individual packets at multiple OSI layers. For troubleshooting a web application, you can filter HTTP/HTTPS requests and responses, examine TCP handshakes, and identify latency or payload issues, which is essential for diagnosing performance or functional problems.

Exam trap

The trap here is that candidates often confuse Burp Suite (a web application proxy) with a packet analyzer, but Burp Suite operates at the application layer and does not capture raw network packets or provide low-level protocol analysis like Wireshark does.

How to eliminate wrong answers

Option A is wrong because Nmap is a network scanning tool used for host discovery and port enumeration, not for capturing and analyzing the contents of network packets. Option C is wrong because Burp Suite is an intercepting proxy focused on web application security testing (e.g., manipulating HTTP requests), not a general-purpose packet capture and analysis tool like Wireshark. Option D is wrong because Aircrack-ng is a suite of tools for wireless network security auditing (e.g., cracking WEP/WPA keys), not for capturing and analyzing packets from a wired or wireless web application traffic stream.

27
MCQmedium

After gaining initial access to a Windows domain controller, a tester wants to extract password hashes from the SAM database and domain account hashes. Which Impacket tool is designed for this purpose?

A.psexec.py
B.GetUserSPNs.py
C.wmiexec.py
D.secretsdump.py
AnswerD

secretsdump.py is an Impacket tool that copies the SAM, SYSTEM, and SECURITY hives from a local Windows machine, or remotely retrieves NTDS.dit and registry data using Volume Shadow Copy or the DRSUAPI (DCSync) protocol. On a domain controller, it can extract all domain password hashes, including NTDS.dit database and cached credentials, without requiring additional tools on the target. Its ability to perform DCSync and remote registry reads makes it the standard for credential harvesting after gaining admin access to Active Directory.

Why this answer

D is correct because secretsdump.py is the Impacket tool specifically designed to extract password hashes from the SAM database and domain account hashes (NTDS.dit) on a Windows domain controller. It can perform remote dump operations using techniques like DRSUAPI replication or volume shadow copy, making it the standard choice for credential harvesting in penetration testing.

Exam trap

The trap here is that candidates confuse tools for remote execution (psexec.py, wmiexec.py) or Kerberoasting (GetUserSPNs.py) with the specific hash-dumping functionality of secretsdump.py, failing to recognize that only secretsdump.py directly extracts SAM and domain account hashes.

How to eliminate wrong answers

Option A is wrong because psexec.py is used for remote command execution via SMB, not for extracting password hashes. Option B is wrong because GetUserSPNs.py is designed to enumerate Service Principal Names (SPNs) for Kerberoasting attacks, targeting service account tickets rather than SAM or domain hashes. Option C is wrong because wmiexec.py enables remote command execution over WMI, lacking the functionality to dump SAM or NTDS.dit hashes.

28
MCQmedium

After gaining initial access to a Windows system, a penetration tester wants to extract password hashes from the local SAM database. Which Impacket tool should be used?

A.GetUserSPNs
B.secretsdump
C.psexec
D.wmiexec
AnswerB

secretsdump is the correct tool because it directly extracts credential material from multiple Windows sources: local SAM and SYSTEM hives via the registry, cached domain credentials from the LSA, NTDS.dit from domain controllers, and LSASS memory on a compromised machine. When run as SYSTEM or with administrator privileges, it can accomplish this remotely using SMB or execute locally, making it the standard Impacket utility for dumping password hashes. This aligns exactly with the post-compromise scenario described.

Why this answer

Secretsdump, because it is the Impacket tool specifically designed to extract password hashes from a Windows SAM database, as well as from NTDS.dit and LSA secrets. It remotely accesses the SAM hive via the Windows registry or uses Volume Shadow Copy to dump hashes without requiring interactive login.

Exam trap

The trap here is that candidates may confuse secretsdump with tools like psexec or wmiexec, which are for remote execution, not credential extraction, or with GetUserSPNs, which targets Kerberos tickets rather than local SAM hashes.

How to eliminate wrong answers

Option A is wrong because GetUserSPNs is used to request Kerberos service tickets for user accounts associated with Service Principal Names (SPNs), not to extract SAM hashes. Option C is wrong because psexec executes commands remotely via SMB and creates a service, but it does not dump password hashes. Option D is wrong because wmiexec executes commands via WMI, providing a semi-interactive shell, but it lacks the functionality to extract SAM hashes.

29
MCQmedium

A tester needs to brute-force SSH credentials on a target. Which tool is most appropriate for this task?

A.Aircrack-ng
B.Hashcat
C.Hydra
D.John the Ripper
AnswerC

Hydra is the correct choice because it is a network logon cracker that supports the SSH protocol among hundreds of others. It can supply username/password pairs from wordlists, perform parallel connection attempts, and handle SSH's banner and authentication exchange, making it ideal for online brute-force testing against a live target.

Why this answer

Hydra is a versatile online brute-force tool supporting many protocols including SSH.

30
Multi-Selectmedium

A penetration tester is writing a Bash script to automate scanning of multiple subnets with Nmap and parse the output. Which three features are commonly used in such a script? (Choose THREE.)

Select 3 answers
A.PowerShell cmdlets
B.Nmap XML output (-oX)
C.For loop
D.grep
E.PySerial
AnswersB, C, D

Nmap's -oX flag instructs the tool to write results in XML format, which is structured and machine-parseable, making it ideal for automated post-processing in a Bash script. Unlike plain text, XML can be reliably queried with tools such as xmlstarlet or xmllint to extract hosts, open ports, and service versions, enabling dynamic follow-up actions. This is the correct option because it is a native Nmap feature designed for automation.

Why this answer

Option B (Nmap XML output -oX) is correct because -oX writes scan results to a machine-readable XML file, which a Bash script can then parse reliably with tools like grep, awk, or xmllint. Option C (For loop) is correct because a Bash for loop iterates over a list of subnets or target ranges, invoking Nmap once per subnet to automate the scanning process. Option D (grep) is correct because grep filters the Nmap output (or XML file) for specific patterns such as open ports or host states, enabling the script to extract and act on relevant results.

Option A (PowerShell cmdlets) does not belong because cmdlets are PowerShell constructs, not Bash features, and would not run natively in a Bash script. Option E (PySerial) does not belong because PySerial is a Python library for serial-port communication, unrelated to Nmap scanning or Bash scripting.

Exam trap

The trap here is that candidates may confuse cross-platform scripting features (like PowerShell cmdlets) with Bash-native constructs, or mistakenly think PySerial is relevant for network scanning, when the exam focuses on Bash-specific tools (for loops, grep) and Nmap's structured output (-oX) for automation.

31
MCQmedium

A tester wants to perform an evil twin attack to capture WPA handshakes. Which tool from the Aircrack-ng suite is used to deauthenticate clients from a legitimate AP to force reconnection to the rogue AP?

A.airmon-ng
B.airodump-ng
C.aircrack-ng
D.aireplay-ng
AnswerD

aireplay-ng is the correct tool because it can inject frames, specifically deauthentication packets, into a wireless network. Sending deauth frames to a connected client forcibly disconnects it from the legitimate AP, prompting it to reconnect—and the evil twin rogue AP can then capture the WPA handshake. While aireplay-ng also supports other injection attacks, its ability to actively disrupt client associations makes it the standard tool for the deauth phase of an evil twin attack.

Why this answer

aireplay-ng can send deauthentication packets to disconnect clients, facilitating handshake capture.

32
MCQmedium

A tester wants to perform a Kerberoasting attack against an Active Directory environment. Which Impacket tool would be most appropriate?

A.wmiexec
B.psexec
C.secretsdump
D.GetUserSPNs
AnswerD

GetUserSPNs queries Active Directory for accounts with Service Principal Names, then requests Kerberos service tickets encrypted with those accounts' password hashes. This directly satisfies the Kerberoasting requirement: extracting crackable TGS tickets offline without triggering authentication failures.

Why this answer

GetUserSPNs is the correct Impacket tool for Kerberoasting because it queries Active Directory for Service Principal Names (SPNs) associated with user accounts, then requests TGS tickets for those services. These tickets can be cracked offline to recover the service account's password hash, enabling privilege escalation.

Exam trap

The exam often tests the distinction between tools that extract hashes (secretsdump) versus tools that request Kerberos tickets (GetUserSPNs), leading candidates to confuse hash dumping with Kerberoasting.

How to eliminate wrong answers

Option A is wrong because wmiexec is used for remote command execution via Windows Management Instrumentation (WMI), not for extracting Kerberos tickets. Option B is wrong because psexec executes commands remotely using SMB and service creation, not for Kerberoasting. Option C is wrong because secretsdump extracts password hashes from the SAM, NTDS.dit, and LSA secrets, but does not perform Kerberos TGS ticket requests or SPN enumeration.

33
MCQeasy

During a web application test, a penetration tester needs to intercept and modify HTTP requests before forwarding them to the server. Which tool is best suited for this task?

A.Hydra
B.Nmap
C.Wireshark
D.Burp Suite
AnswerD

Burp Suite's intercepting proxy is purpose-built for web application testing, allowing a tester to pause HTTP/S requests between browser and server, inspect them, and edit headers, parameters, or body content in real time. It also provides Repeater and Intruder for manual tweaking and automated attack payload generation, respectively. Its CA certificate enables TLS interception, making it the de facto standard tool for this exact task.

Why this answer

Burp Suite's proxy allows intercepting and modifying HTTP/S requests, making it the standard tool for web application testing.

34
MCQmedium

A penetration tester is writing a Python script to send a crafted TCP packet to a target. Which Python library should the tester use for low-level packet crafting and injection?

A.requests
B.impacket
C.scapy
D.socket
AnswerC

Scapy lets the tester construct and inject raw TCP packets at layer 3/4, defining flags, sequence numbers and payloads directly. Socket alone lacks this crafting depth, and requests operates at HTTP level, so scapy fits low-level packet manipulation.

Why this answer

Scapy is the correct choice because it is a powerful Python library specifically designed for low-level packet crafting, manipulation, and injection. It allows the tester to construct arbitrary TCP packets at the raw socket level, control individual flags, sequence numbers, and payloads, and send them directly over the wire using Layer 2 or Layer 3 sockets. This makes it ideal for tasks like SYN flooding, TCP handshake manipulation, or custom protocol fuzzing.

Exam trap

CompTIA often tests the distinction between high-level protocol libraries (requests, impacket) and low-level packet crafting tools (scapy), trapping candidates who confuse 'network scripting' with 'raw packet manipulation'.

How to eliminate wrong answers

Option A is wrong because the 'requests' library is a high-level HTTP client library used for sending and receiving HTTP requests; it operates at the application layer and cannot craft or inject raw TCP packets. Option B is wrong because 'impacket' is a collection of Python classes for working with network protocols, particularly SMB and Kerberos, but it is not designed for low-level packet crafting and injection; it focuses on protocol-level interactions rather than raw packet manipulation. Option D is wrong because the 'socket' library provides low-level networking interfaces (e.g., raw sockets) but lacks the high-level abstractions, protocol dissection, and packet-building utilities that Scapy offers; using raw sockets alone would require manually constructing all packet headers and handling checksums, which is error-prone and far less efficient.

35
MCQhard

A penetration tester is conducting a wireless assessment and needs to capture the four-way handshake to perform offline WPA cracking. Which tool is best suited for capturing the handshake?

A.aircrack-ng
B.aireplay-ng
C.Airmon-ng
D.airodump-ng
AnswerD

airodump-ng is the dedicated packet capture tool in the aircrack-ng suite, capable of placing the wireless interface into monitor mode and recording raw 802.11 frames to a pcap file. It actively hops channels, probes for access points, and lists associated clients, and it specifically captures the EAPOL four-way handshake frames when a client associates or reconnects. Its output is the direct input for aircrack-ng's offline cracking, making it the correct choice for this capture stage.

Why this answer

Airodump-ng (option D) is the correct tool for capturing the four-way handshake because it passively monitors wireless traffic and can save captured packets to a file (e.g., .cap or .pcap). The four-way handshake occurs during the WPA/WPA2 authentication process between a client and an access point, and airodump-ng's ability to filter on a specific channel and BSSID allows the tester to isolate and record the handshake frames for offline cracking.

Exam trap

The trap here is that candidates confuse airodump-ng (capture tool) with aircrack-ng (cracking tool) or aireplay-ng (injection tool), leading them to pick a tool that cannot actually capture the handshake.

How to eliminate wrong answers

Option A (aircrack-ng) is wrong because it is a WEP/WPA key cracking tool that uses captured handshake files, not a packet capture tool; it cannot capture the handshake itself. Option B (aireplay-ng) is wrong because it is used for packet injection and replay attacks (e.g., deauthentication attacks to force a client to reconnect), not for passively capturing the handshake. Option C (airmon-ng) is wrong because it is a utility to enable or disable monitor mode on a wireless interface, not a packet capture tool; it prepares the interface for capture but does not capture frames.

36
MCQmedium

A penetration tester is conducting a vulnerability assessment of a Linux web server. The tester runs a scan with Nikto and receives a finding indicating that the server is potentially vulnerable to a cross-site scripting (XSS) attack on a specific parameter. To confirm the finding, the tester wants to manually verify the XSS vulnerability. Which action should the tester take?

A.Use a SQL injection tool like sqlmap to test the parameter for injection flaws
B.Run a full port scan with Nmap to check for open ports related to the web service
C.Perform a directory brute-force with Gobuster to find hidden files
D.Use a web browser to inject a benign script payload into the parameter and observe if it executes
AnswerD

Manual verification of XSS involves injecting a harmless script, such as <script>alert(1)</script>, into the vulnerable parameter and checking if the browser executes it. This confirms the vulnerability without causing harm. In this scenario, the tester should use a browser or proxy to inject the payload and observe the response. This is the standard method to validate XSS findings.

Why this answer

To confirm an XSS vulnerability, the tester must inject a script payload into the vulnerable parameter and observe if it executes in the context of the application. This manual verification is crucial because automated scanners like Nikto can produce false positives. Using a browser or an intercepting proxy to inject a benign alert script is the most direct and reliable method.

It confirms that the application fails to sanitize input and that the payload is reflected or stored and executed.

Exam trap

The trap here is relying on other automated tools or scans to confirm XSS, when manual injection with a harmless payload is the definitive verification method.

37
MCQmedium

During a web application test, a penetration tester intercepts requests between the browser and server and modifies them in real time. Which Burp Suite tool is designed for this purpose?

A.Repeater
B.Sequencer
C.Intruder
D.Proxy
AnswerD

Burp Proxy is the component that acts as an intercepting forward proxy between the tester's browser and the target web application. With intercept mode enabled, it captures each HTTP/S request, lets the tester pause, inspect, modify, and forward it before the server sees it, and performs the same for responses. This live, bidirectional control over traffic in real time is exactly what makes Proxy the correct tool for request interception during a web application penetration test.

Why this answer

Burp Proxy intercepts and allows modification of HTTP/HTTPS requests.

38
MCQmedium

A penetration tester needs to perform a Kerberoasting attack against a Windows Active Directory environment. Which tool from the Impacket suite should the tester use to request service tickets and extract TGS hashes for offline cracking?

A.wmiexec.py
B.secretsdump.py
C.GetUserSPNs.py
D.psexec.py
AnswerC

GetUserSPNs.py (from Impacket) is the correct choice because it specifically enumerates user accounts registered as Service Principal Names (SPNs) and requests Kerberos service tickets for those SPNs, which are encrypted with the target user account's password-derived key. It outputs a John-the-Ripper/hashcat-ready hash that can be cracked offline to recover the plaintext password. This tool automates the full Kerberoasting workflow—querying for SPNs, requesting TGS tickets, and formatting the output—making it the canonical tool for this attack.

Why this answer

GetUserSPNs.py in the Impacket suite is used to find and request service principal names (SPNs) and retrieve TGS hashes for Kerberoasting.

39
MCQhard

A penetration tester is conducting a wireless security assessment. The target network uses WPA2-PSK. The tester has captured the four-way handshake. Which tool from the Aircrack-ng suite can be used to attempt to recover the pre-shared key by performing a dictionary attack?

A.airtun-ng
B.aircrack-ng
C.airodump-ng
D.aireplay-ng
AnswerB

aircrack-ng is the core cryptanalysis tool that takes captured 802.11 traffic and recovers wireless encryption keys. For WEP, it applies the PTW or KoreK/FMS attacks once enough IVs have been collected; for WPA/WPA2, it performs a dictionary or brute-force attempt against the MIC computed during the 4-way EAPOL handshake. It validates the correct key by matching the passphrase-specific PMK to the handshake's MIC, making it the exact utility needed to complete the cracking objective.

Why this answer

Aircrack-ng is the tool within the suite that performs dictionary or brute-force attacks on captured WPA/WPA2 handshakes to recover the PSK.

40
Multi-Selecthard

During a cloud security assessment of AWS, a tester wants to identify misconfigurations using automated tools. Which THREE tools are specifically designed for AWS security auditing?

Select 3 answers
A.Hashcat
B.Pacu
C.Prowler
D.CrackMapExec
E.ScoutSuite
AnswersB, C, E

Correct: AWS exploitation framework.

Why this answer

Pacu is an open-source AWS exploitation framework designed for offensive security testing. It automates the identification of misconfigurations, such as overly permissive IAM policies, exposed S3 buckets, and vulnerable Lambda functions, making it a correct choice for cloud security auditing.

Exam trap

CompTIA often tests candidates' ability to distinguish between general-purpose security tools (like Hashcat for cracking) and cloud-specific auditing tools (like Pacu, Prowler, and ScoutSuite), leading to confusion when tools have overlapping names or functions.

41
MCQeasy

Which PowerShell script is commonly used for post-exploitation enumeration of Active Directory, such as querying user accounts and group memberships?

A.Nishang
B.Empire
C.Invoke-Mimikatz
D.PowerView
AnswerD

PowerView is a PowerShell script—part of the PowerSploit project—that provides a suite of cmdlets for Active Directory reconnaissance, including Get-DomainUser, Get-DomainGroup, Find-DomainAdmin, and Get-DomainACL. It queries LDAP (and sometimes other AD services) to map the domain, identify privileged accounts, and reveal relationships that aid lateral movement. This makes it the standard tool for AD enumeration during post-exploitation, matching the question's intent.

Why this answer

PowerView (option D) is a PowerShell script within the PowerSploit framework specifically designed for post-exploitation enumeration of Active Directory. It provides cmdlets like Get-NetUser, Get-NetGroup, and Get-NetComputer to query user accounts, group memberships, and domain trust relationships via LDAP queries, making it the correct choice for this task.

Exam trap

The trap here is that candidates confuse post-exploitation frameworks (Empire) or credential-dumping tools (Invoke-Mimikatz) with the specific script designed for AD enumeration, or they assume Nishang's broad toolkit includes dedicated AD enumeration, when PowerView is the precise answer for querying user accounts and group memberships.

How to eliminate wrong answers

Option A (Nishang) is wrong because it is a collection of PowerShell scripts for penetration testing and offensive security, but it focuses on broader tasks like reverse shells, keylogging, and data exfiltration, not specifically on Active Directory enumeration. Option B (Empire) is wrong because it is a post-exploitation framework that uses PowerShell agents for command and control, but it is not a single script; it relies on modules like PowerView for AD enumeration, so it is not the script itself. Option C (Invoke-Mimikatz) is wrong because it is a PowerShell wrapper for Mimikatz, which extracts credentials (e.g., plaintext passwords, Kerberos tickets) from memory, not for querying AD user accounts or group memberships.

42
MCQmedium

During a web application penetration test, the tester captures a login request in Burp Suite and wants to automate a brute-force attack against the password field. Which Burp Suite tool is specifically designed for this purpose?

A.Intruder
B.Scanner
C.Sequencer
D.Repeater
AnswerA

Intruder is Burp Suite's dedicated automated fuzzing and brute-force engine. It enables you to define a request template, mark payload positions, and cycle through large wordlists using attack types like Sniper, Pitchfork, and Cluster Bomb. With features like payload processing, request throttling, and session handling macros, Intruder is purpose-built for credential guessing and dictionary attacks against authentication endpoints. That is why it is the correct tool for this task.

Why this answer

Intruder is the correct tool because it is specifically designed for automated customized attacks, including brute-force attacks, against web application parameters. It allows the tester to define a payload position (e.g., the password field in a login request) and iterate through a list of candidate passwords, automatically resending the request with each payload value and analyzing the responses.

Exam trap

The trap here is that candidates often confuse Repeater (which is for manual, single-request testing) with Intruder (which is for automated, multi-request attacks), leading them to choose Repeater because they think it can be used for brute-forcing by manually sending requests one by one.

How to eliminate wrong answers

Option B (Scanner) is wrong because Burp Scanner is an automated vulnerability detection tool that identifies security flaws (e.g., SQL injection, XSS) by passively and actively scanning requests, not for performing brute-force attacks against a specific field. Option C (Sequencer) is wrong because it analyzes the randomness of session tokens or other data to assess cryptographic strength, not for automating password guessing. Option D (Repeater) is wrong because it allows manual resending and modification of a single request for testing, but it lacks the ability to automate multiple requests with varying payloads, which is essential for a brute-force attack.

43
MCQeasy

A penetration tester needs to enumerate Active Directory users and groups from a Windows domain. Which PowerShell tool is specifically designed for AD enumeration and is commonly used in post-exploitation?

A.Invoke-Mimikatz
B.Nmap
C.CrackMapExec
D.PowerView
AnswerD

PowerView is a PowerShell post-exploitation framework that wraps directory services queries, enumerating users, groups, computers and trusts with minimal native tooling. It satisfies the AD enumeration requirement through functions such as Get-NetUser and Get-NetGroup, commonly loaded reflectively during engagements.

Why this answer

PowerView (option D) is a PowerShell tool specifically designed for Active Directory enumeration, providing functions to query users, groups, computers, and permissions via LDAP. It is widely used in post-exploitation because it runs in-memory, avoids writing to disk, and integrates seamlessly with PowerShell's pipeline for stealthy reconnaissance.

Exam trap

The trap here is that candidates confuse post-exploitation credential tools (like Invoke-Mimikatz) with enumeration tools, or assume general-purpose scanners (Nmap) or multi-function frameworks (CrackMapExec) are PowerShell-native AD enumeration tools, when PowerView is the correct specialized PowerShell module for this task.

How to eliminate wrong answers

Option A is wrong because Invoke-Mimikatz is a tool for credential dumping (e.g., extracting plaintext passwords, hashes, and Kerberos tickets), not for enumerating AD users and groups. Option B is wrong because Nmap is a network scanning tool that discovers hosts and services via raw packets, not a PowerShell-based AD enumeration tool. Option C is wrong because CrackMapExec is a post-exploitation tool that automates credential spraying, SMB enumeration, and lateral movement, but it is not a PowerShell tool specifically designed for AD user/group enumeration; PowerView fills that niche.

44
MCQmedium

A penetration tester is performing a password cracking task against a dump of NTLM hashes obtained from a Windows domain controller. Which tool would be the most efficient for this task?

A.Hydra
B.John the Ripper
C.Hashcat
D.CrackMapExec
AnswerC

Hashcat is the industry-standard for offline hash cracking, supporting GPU (CUDA/OpenCL) acceleration and highly optimized kernels for NTLM (mode 1000). It offers exhaustive rule-based attack modes, mask attacks, and support for pass-the-hash style hashes. For a penetration tester wanting the fastest NTLM cracking, Hashcat is the correct tool.

Why this answer

Hashcat is a GPU-accelerated password cracker that can crack NTLM hashes quickly, especially with a good wordlist and rules.

45
Multi-Selectmedium

A penetration tester is conducting a post-exploitation phase on a Windows target and wants to dump credentials. Which of the following tools can be used? (Choose TWO.)

Select 2 answers
A.secretsdump.py
B.Mimikatz
C.Nmap
D.Hydra
E.Wireshark
AnswersA, B

secretsdump.py is an Impacket script that extracts credential material from persistent Windows stores: the local SAM hive, cached domain credentials in the SECURITY hive, and NTDS.dit on domain controllers. It remotely reads registry hives (or receives a local hive dump) and uses the System key to decrypt the Boot Key, then outputs LM/NTLM hashes, Kerberos keys, and plaintext cached credentials. This makes it a powerful post-exploitation tool for lateral movement, but it operates on on-disk files rather than live processes.

Why this answer

Mimikatz is a well-known credential dumping tool, and secretsdump.py from Impacket can dump hashes remotely.

46
MCQmedium

A penetration tester needs to perform a dictionary attack against an SSH service. Which of the following tools is best suited for this task?

A.CrackMapExec
B.John the Ripper
C.Hashcat
D.Hydra
AnswerD

Hydra is the correct choice because it is a network login cracking tool designed specifically for online brute-force and dictionary attacks against live services. It supports SSH and dozens of other protocols, and its parallelized connection handling allows rapid testing of password lists against a remote target. Hydra sends actual authentication requests to the SSH daemon, making it the only listed option capable of performing an active dictionary attack against a running service.

Why this answer

Hydra is a versatile online brute-force tool that supports many protocols, including SSH.

47
Multi-Selectmedium

A penetration tester is reviewing a Java application for insecure deserialization vulnerabilities. Which of the following should the tester look for? (Choose TWO.)

Select 2 answers
A.Accepting serialized objects from user input without sanitization
B.Use of eval() functions
C.Hardcoded credentials in configuration files
D.Use of prepared statements for SQL queries
E.Use of ObjectInputStream without validation
AnswersA, E

The application's deserialization endpoint accepts a raw byte stream from the client and reconstructs objects without any validation or integrity check. An attacker can craft a malicious serialized payload containing a 'gadget chain' of existing library classes, causing the JVM to execute arbitrary commands during object reconstruction. Sanitizing the raw bytes or validating the incoming object's class hierarchy is essential; without it, the attack surface is fully exposed.

Why this answer

Insecure deserialization vulnerabilities often arise from using ObjectInputStream without filtering and from accepting serialized data from untrusted sources.

48
MCQhard

During a code review of a PHP web application, you encounter the following code: $result = mysql_query("SELECT * FROM users WHERE username='" . $_GET['user'] . "'");. Which vulnerability does this represent?

A.Cross-site scripting (XSS)
B.Path traversal
C.Command injection
D.SQL injection
AnswerD

SQL injection is confirmed when user input is embedded directly into an SQL query without sanitization or parameterization, allowing the attacker to modify the query's logic. For example, input like ' OR '1'='1 can bypass authentication, and UNION SELECT statements can extract data from other tables. This occurs because the database engine interprets the attacker's input as part of the SQL syntax, not just as data. Proper defense involves prepared statements with bound parameters or stored procedures, which separate data from SQL code.

Why this answer

Direct concatenation of user input into SQL query without sanitization or parameterization is classic SQL injection.

49
Multi-Selecthard

A penetration tester is performing a vulnerability assessment of a web application. The tester wants to identify input validation vulnerabilities that could lead to injection attacks. Which two techniques are most effective for discovering injection flaws such as SQL injection and command injection? (Choose two.)

Select 2 answers
A.Fuzzing input fields with a variety of special characters and payloads
B.Using a web proxy to intercept and manipulate requests with injection payloads
C.Performing a dictionary attack against authentication mechanisms
D.Reviewing the application's source code for improper input sanitization
E.Running a port scan to identify open ports and services
AnswersA, B

Fuzzing involves sending unexpected or malformed data to input fields to observe how the application handles it. For injection flaws, sending characters like single quotes, double quotes, semicolons, and command separators can trigger errors or unexpected behavior. This technique is effective for discovering SQL injection, command injection, and other injection vulnerabilities because it tests the application's input sanitization. It is a core method in dynamic application security testing.

Why this answer

Fuzzing input fields and using a web proxy to manipulate requests are both active testing techniques that directly probe the application's input handling. They allow the tester to send malicious payloads and observe if the application improperly processes them, leading to injection. These methods are effective in black-box testing scenarios where source code is not available.

They are standard practices in web application penetration testing for uncovering injection vulnerabilities.

Exam trap

The trap here is selecting source code review, which is effective but not always available in a penetration test, or selecting unrelated techniques like port scanning or password attacks.

50
Multi-Selecthard

A penetration tester is reverse-engineering a .NET binary to understand its authentication logic. Which three tools are suitable for decompiling .NET assemblies? (Choose THREE.)

Select 3 answers
A.jadx
B.dotPeek
C.Ghidra
D.ILSpy
E.dnSpy
AnswersB, D, E

JetBrains dotPeek is a free .NET decompiler that translates compiled .NET assemblies (CIL bytecode plus metadata) into readable C# source code. It is based on the method bodies and type information stored in the metadata, and it supports modern language features like LINQ and async/await. Beyond decompilation, dotPeek can also display raw IL and generate Visual Studio solutions, making it a complete tool for static analysis of .NET binaries.

Why this answer

dnSpy, ILSpy, and JetBrains dotPeek are decompilers for .NET. Ghidra is for native code, jadx for Android APK.

51
MCQhard

A penetration tester is analyzing a Linux binary and wants to decompile it to understand its logic. Which open-source tool is specifically designed for reverse engineering and can generate C-like pseudocode from compiled binaries?

A.IDA Pro Free
B.dnSpy
C.Ghidra
D.jadx
AnswerC

Ghidra is a free, open-source reverse-engineering suite developed by the NSA and includes a built-in decompiler that converts machine code into approximate C pseudocode. It supports a broad range of architectures and runs natively on Linux, making it ideal for analyzing ELF binaries. The decompiler output, though not perfect, dramatically accelerates understanding of program flow and logic, which is exactly what a penetration tester needs.

Why this answer

Ghidra, developed by the NSA, is a reverse engineering framework that can decompile binaries into C-like pseudocode.

52
Multi-Selecthard

A penetration tester is performing a wireless assessment and wants to set up an evil twin attack. Which of the following steps are necessary? (Choose THREE.)

Select 3 answers
A.Create a rogue access point with the same SSID as the target network
B.Configure WPA3 encryption on the rogue AP
C.Use Wireshark to decrypt the traffic
D.Capture the WPA handshake when clients attempt to connect
E.Send deauthentication frames to disconnect clients from the genuine AP
AnswersA, D, E

Cloning the target network's SSID is the essence of an evil twin attack because clients authenticate to networks by name and apparent signal strength rather than by verifying the AP's true identity. The attacker configures a rogue access point to broadcast the exact same SSID as the legitimate network, often also cloning the security type and any captive portal, so that a victim's device will associate with the attacker. Without this SSID masquerade, there is no evil twin with which to perform the subsequent steps of deauthentication and handshake capture.

Why this answer

An evil twin attack involves creating a rogue access point with the same SSID as a legitimate network, deauthenticating clients, and capturing the handshake.

Ready to test yourself?

Try a timed practice session using only Ptp Tools Code questions.