Courseiva

CCNA Vulnerability Scanning and Penetration Testing Questions

8 questions · Vulnerability Scanning and Penetration Testing · All types, answers revealed

1
MCQmedium

During an authorized penetration test, a tester obtains a low-privilege shell on a Windows server and wants to identify missing patches and insecure configurations that a remote unauthenticated scan may have missed. Which action BEST supports this goal?

A.Perform a TCP SYN scan of the internal subnet from the compromised host
B.Run a credentialed vulnerability scan from the scanner appliance using domain admin credentials
C.Capture traffic with tcpdump on the compromised host for several hours
D.Upload and execute a local enumeration script such as WinPEAS or Seatbelt
AnswerD

Local enumeration tools like WinPEAS and Seatbelt run from the compromised host and collect patch levels, missing updates, weak service permissions, saved credentials, and misconfigurations that remote scans often miss. Because the tester already has a shell, this approach directly answers the goal of finding local vulnerabilities without needing additional credentials or scanner access.

Why this answer

After gaining a foothold, a penetration tester should perform local enumeration to find patch gaps and misconfigurations that remote scanning cannot see. WinPEAS and Seatbelt are purpose-built for this, collecting system, patch, and configuration data directly from the host. The other options either require additional credentials, focus on network discovery, or capture traffic without addressing local vulnerability state.

Exam trap

The trap here is confusing remote vulnerability scanning with local post-exploitation enumeration, and assuming that any network-based technique will reveal host patch levels once a shell is obtained.

2
Multi-Selectmedium

A penetration tester is planning a web application assessment for a client. The tester wants to combine automated scanning with manual techniques to maximize coverage. Which two actions are MOST appropriate to include in the plan? (Choose two.)

Select 2 answers
A.Launch a denial-of-service test against the production application to check resilience
B.Use a network protocol analyzer to capture all traffic between the tester and the application
C.Perform manual testing of authentication and session management flows
D.Run an automated web vulnerability scanner such as OWASP ZAP against the application
E.Run a full TCP port scan of the web server before testing the application
AnswersC, D

Manual testing is essential for logic flaws, broken authentication, and session management issues that automated scanners often miss. By exercising login, logout, password reset, and session fixation scenarios by hand, the tester uncovers vulnerabilities that require contextual understanding, which complements the automated scan and increases overall assessment quality.

Why this answer

A thorough web application assessment pairs automated scanning with manual techniques. Automated tools like OWASP ZAP provide broad coverage of common vulnerabilities, while manual testing of authentication and session management uncovers logic and access control flaws that scanners cannot reliably detect. The other options either address infrastructure rather than the application or introduce unnecessary risk without improving coverage.

Exam trap

The trap here is treating automated scanning as sufficient on its own, or including high-risk actions like denial-of-service testing that fall outside a typical web application assessment scope.

3
MCQeasy

A junior security analyst at a healthcare company must scan a subnet of 254 hosts for known vulnerabilities. The analyst has no budget for commercial tools and needs a scanner that is open source, actively maintained, and capable of authenticated and unauthenticated checks. Which tool BEST meets these requirements?

A.OpenVAS (Greenbone Vulnerability Management)
B.Nessus Essentials
C.Nmap with the NSE vuln category
D.Wireshark
AnswerA

OpenVAS, now delivered through Greenbone Vulnerability Management, is an open-source vulnerability scanner with a continuously updated feed and support for both authenticated and unauthenticated scans. It has no per-host licensing limit, making it suitable for scanning a 254-host subnet at no cost while still meeting the maintenance and capability requirements.

Why this answer

OpenVAS, maintained as Greenbone Vulnerability Management, is the only option that is open source, actively updated, and free of per-host licensing limits. It supports both authenticated and unauthenticated scanning across large subnets, which matches the analyst's constraints. The other tools are either license-limited, not true vulnerability scanners, or designed for traffic analysis rather than vulnerability assessment.

Exam trap

The trap here is assuming that any free security tool can substitute for a dedicated, feed-driven vulnerability scanner when the requirement explicitly calls for maintained authenticated and unauthenticated checks.

4
MCQeasy

A security analyst is preparing to run an authenticated vulnerability scan against a Windows Server 2019 host. The analyst has domain credentials with local administrator rights on the target. Which Nmap scan type should the analyst use to perform a full TCP connect scan without requiring raw packet privileges?

A.nmap -sU
B.nmap -sA
C.nmap -sS
D.nmap -sT
AnswerD

The -sT option performs a TCP connect scan using the operating system's connect() system call, which does not require raw socket privileges. This makes it ideal when running Nmap as a non-root user or when the analyst lacks the ability to send raw packets. It completes the full TCP three-way handshake against each target port.

Why this answer

The TCP connect scan (-sT) is the correct choice because it relies on the operating system's networking stack and does not need raw socket access, making it usable by unprivileged users. Other scan types such as SYN, UDP, or ACK scanning require raw packet privileges and serve different purposes.

Exam trap

The trap here is assuming that all Nmap scan types require root or administrator privileges, when the TCP connect scan is specifically designed to work without them.

5
MCQmedium

A penetration tester is preparing an authorized internal assessment and must decide how to handle the discovery phase before running exploitation attempts. The client's rules of engagement permit scanning but forbid any action that could cause a denial of service on production hosts. The tester's goal is to map live hosts, open ports, and service versions with minimal impact while still gathering enough data to plan later exploitation. Which approach best satisfies both the engagement constraints and the assessment objective?

A.Perform a phased Nmap discovery using host discovery first, then targeted service/version detection with conservative timing options such as -T2 and limited port ranges, documenting results before any exploitation phase.
B.Skip active scanning entirely and rely only on the client's existing asset inventory spreadsheet, then begin exploitation attempts against the listed hosts.
C.Run a full Nmap scan with -sS and no timing adjustments across the entire /16, then immediately launch the exploitation framework against every discovered service.
D.Use a single aggressive Nmap scan with -T5 and the default top-1000 ports, then treat every open port as an exploitable finding in the final report.
AnswerA

A phased approach separates live-host discovery from service enumeration, letting the tester narrow the target set and apply conservative timing and port scope. Version detection with controlled timing reduces the chance of overwhelming fragile services, directly honoring the no-denial-of-service constraint. Documenting results before exploitation supports repeatable planning and keeps later phases tied to validated findings rather than assumptions.

Why this answer

The phased approach with host discovery followed by conservative service/version detection controls packet volume and timing, which is what keeps a scan from disrupting production services. Narrowing targets before enumeration also makes later exploitation planning more accurate. Aggressive timing, immediate exploitation, or relying on stale inventory all conflict with either the safety constraint or the objective of verifying live services.

Exam trap

The trap here is assuming that a faster or broader scan always produces better assessment data, when in a production environment the engagement's safety constraints make scan pacing and scope the deciding factors.

6
Multi-Selecthard

A security consultant is configuring a Tenable Nessus scan to assess a mixed environment of Windows and Linux servers. The consultant needs to ensure the scan can authenticate to targets and perform local checks without relying on agent installation. Which two Nessus scan settings should the consultant configure to provide credentials for authenticated scanning? (Choose two.)

Select 2 answers
A.Kerberos ticket for domain authentication
B.SSH credentials for Linux hosts
C.Database credentials for SQL Server instances
D.SNMP community strings for network devices
E.SMB credentials for Windows hosts
AnswersB, E

Nessus uses SSH credentials to log into Linux and Unix hosts and run local commands for patch level, configuration, and vulnerability checks. Without valid SSH credentials, the scan falls back to unauthenticated checks, which are less accurate. Configuring SSH credentials is essential for authenticated scanning of Linux systems in a mixed environment.

Why this answer

Authenticated scanning in Nessus for a mixed environment requires SSH credentials for Linux hosts and SMB credentials for Windows hosts. These allow the scanner to log in and perform local checks, increasing accuracy. Other credential types are for network devices or databases and do not fulfill the requirement.

Exam trap

The trap here is assuming that any credential type enables authenticated scanning, when Nessus uses specific protocols like SSH and SMB for host-based checks on Linux and Windows respectively.

7
MCQhard

A security team is configuring an authenticated vulnerability scan of a Linux server farm using SSH. The scanner reports that it cannot log in to several hosts even though the same credentials work manually. Which configuration change is MOST likely to resolve the issue?

A.Allow the scanner's public key in the authorized_keys file for the scan account
B.Enable password authentication on the target hosts
C.Change the SSH port on the targets to 2222
D.Disable SELinux on the target hosts
AnswerA

Authenticated SSH scans typically use a key pair generated by the scanner. If the scanner's public key is not present in the target account's authorized_keys file, the scanner cannot authenticate even when manual password logins succeed. Adding the scanner's public key to the authorized_keys file for the scan account directly resolves this failure.

Why this answer

Authenticated SSH scans rely on the scanner presenting a key that the target accepts. When manual logins work but the scanner fails, the usual cause is that the scanner's public key has not been installed in the scan account's authorized_keys file. Adding that key restores authentication without weakening the host's security posture, unlike enabling password authentication or disabling SELinux.

Exam trap

The trap here is assuming that because manual SSH with a password works, the scanner must also use passwords, when in fact the scanner may be configured for key-based authentication that has not been provisioned.

8
MCQhard

A vulnerability scan of a production web server reports a critical remote code execution vulnerability, but the system administrator insists the server is fully patched. The scanner used only unauthenticated checks. Which step should the security analyst take FIRST to resolve the discrepancy?

A.Rescan the server with a different unauthenticated scanner to compare results
B.Immediately take the server offline to prevent exploitation
C.Accept the administrator's statement and close the finding as a false positive
D.Perform an authenticated scan and manually verify the vulnerability on the host
AnswerD

Authenticated scanning reads the actual installed package versions and patch levels, providing far more accurate results than banner-based inference. Manually verifying the vulnerability on the host confirms whether the issue truly exists. This approach resolves the discrepancy between the scanner's report and the administrator's claim without causing unnecessary disruption or acting on a possible false positive.

Why this answer

Unauthenticated scans infer vulnerabilities from banners and service responses, which can produce false positives. To resolve the conflict between the scanner and the administrator, the analyst should perform an authenticated scan that reads installed package versions and manually verify the issue on the host. This provides definitive evidence and avoids both unnecessary downtime and premature closure of a critical finding.

Exam trap

The trap here is trusting either the unauthenticated scan or the administrator's assurance without independent verification, when the real answer lies in authenticated, host-level validation.

Ready to test yourself?

Try a timed practice session using only Vulnerability Scanning and Penetration Testing questions.