Vulnerability Assessment & Penetration Testing Flashcards
7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Vulnerability Assessment & Penetration Testing flashcards as text
When conducting a vulnerability assessment, which tool is most commonly used to automatically audit Cisco ACL configurations for weaknesses?
Answer: Nipper or CIS-CAT for network device configuration analysis
Nipper and CIS-CAT are specialized tools designed to audit router and switch configurations, including ACL rules, against security best practices and known vulnerabilities.
A tester discovers an ACL that permits 'established' keyword for TCP return traffic. What vulnerability does improper use of this keyword introduce?
Answer: Attackers can craft packets with the ACK bit set to bypass the ACL and probe internal hosts
The 'established' keyword only checks for the ACK or RST bit in stateless ACLs, allowing attackers to send crafted packets with ACK set to bypass filtering without a prior legitimate connection.
During an ACL penetration test, a tester finds that management interfaces (SSH, SNMP) are not restricted by source IP in the ACL. What is the highest-priority remediation?
Answer: Add ACL entries restricting management protocol access to specific trusted management subnets only
Management interfaces should only be reachable from designated management networks; source IP restrictions in ACLs prevent attackers on untrusted networks from reaching these high-value targets.
A penetration tester uses fragmented IP packets to attempt to bypass an ACL. Which ACL feature is specifically designed to counter this technique?
Answer: IP Fragment handling with the 'fragments' keyword or stateful inspection
Cisco ACLs support a 'fragments' keyword that controls how non-initial IP fragments are handled, preventing attackers from hiding malicious traffic in packet fragments that skip layer-4 inspection.
Which OWASP testing technique most directly applies when assessing whether web application ACLs properly enforce authorization?
Answer: Horizontal and vertical privilege escalation testing to verify access control enforcement
Horizontal privilege escalation (accessing other users' resources) and vertical privilege escalation (accessing higher-privilege functions) directly test whether ACL-enforced authorization controls are correctly implemented.
A vulnerability assessment finds that a DMZ firewall ACL allows all traffic from DMZ servers to the internal network. Why is this a critical finding?
Answer: A compromised DMZ server can directly attack internal hosts without restriction
The DMZ is designed as a semi-trusted zone; unrestricted access from DMZ to internal networks means a single compromised DMZ server gives attackers a pivot point to attack the entire internal network.
During ACL testing, a penetration tester performs a 'time-based ACL evasion' attack. What does this exploit?
Answer: Time-based ACL rules that only restrict traffic during certain hours, leaving gaps attackers can exploit outside restricted windows
Time-based ACLs restrict certain traffic only during configured time windows; if not carefully designed, attackers can access restricted resources simply by initiating connections outside the restricted time period.