โ† All CAP Flashcard Decks

Vulnerability Assessment & Penetration Testing Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Vulnerability Assessment & Penetration Testing flashcards as text
  1. During a penetration test, a tester discovers that a web application reflects user input directly in HTTP responses without encoding. Which vulnerability class does this represent?

    Answer: Cross-Site Scripting (XSS)

    Reflected XSS occurs when unsanitized user input is echoed back in HTTP responses, allowing script injection in the victim's browser.

  2. Which NIST publication provides the primary framework for conducting security assessments and authorizations under the RMF?

    Answer: NIST SP 800-115

    NIST SP 800-115 is the Technical Guide to Information Security Testing and Assessment, specifically covering penetration testing methodologies.

  3. A penetration tester uses a tool to automatically map out all hosts, open ports, and services on a target network. What phase of penetration testing does this represent?

    Answer: Reconnaissance and Discovery

    Reconnaissance and discovery involves active scanning to enumerate hosts, ports, and services on the target network.

  4. What distinguishes a vulnerability scan from a penetration test in the context of federal system assessments?

    Answer: Penetration tests actively attempt to exploit vulnerabilities while scans only identify them

    Penetration tests go beyond identification by actively attempting to exploit vulnerabilities to demonstrate actual impact and risk.

  5. Under the CAP framework, who is ultimately responsible for authorizing penetration testing activities on a federal information system?

    Answer: The Authorizing Official (AO)

    The Authorizing Official has the authority and accountability to accept risk, including approving assessment activities like penetration testing.

  6. A security team identifies a critical vulnerability in a production system but cannot patch it immediately due to operational constraints. What is the most appropriate interim measure from an RMF perspective?

    Answer: Implement a compensating control and document it in the POA&M

    Compensating controls mitigate risk when direct remediation is not feasible, and the residual risk must be documented in the Plan of Action and Milestones.

  7. Which type of penetration test provides the tester with full knowledge of the target system's architecture, source code, and network diagrams?

    Answer: White-box testing

    White-box testing gives testers complete knowledge of the target environment, enabling thorough assessment of internal logic and configurations.