Vulnerability Assessment & Penetration Testing Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Vulnerability Assessment & Penetration Testing flashcards as text
During a penetration test on a federal system, a tester successfully extracts password hashes from a domain controller. Which post-exploitation technique involves using these hashes without cracking them?
Answer: Pass-the-Hash
Pass-the-Hash allows attackers to authenticate using captured NTLM hashes directly without needing the plaintext password.
What is the primary purpose of a Rules of Engagement (ROE) document in the context of federal penetration testing?
Answer: To define the scope, constraints, and authorized actions for the assessment
Rules of Engagement define what is in scope, what actions are permitted, and the boundaries testers must operate within during the assessment.
A vulnerability assessment reveals that a system uses TLS 1.0 for encrypting data in transit. How should this finding be categorized under NIST guidelines?
Answer: High or Critical vulnerability due to known protocol weaknesses
TLS 1.0 has known vulnerabilities like POODLE and BEAST and is deprecated by NIST, making it a high-severity finding requiring remediation.
Which technique involves an attacker intercepting communication between two parties without their knowledge during a penetration test?
Answer: Man-in-the-Middle (MitM) Attack
A Man-in-the-Middle attack involves secretly intercepting and potentially altering communications between two parties who believe they are communicating directly.
In the CVSS scoring system, which metric group assesses the characteristics of a vulnerability that cannot be changed over time?
Answer: Base Metrics
CVSS Base Metrics represent the intrinsic characteristics of a vulnerability that are constant across all deployments and time.
A penetration tester finds a misconfigured S3 bucket containing sensitive federal data. Under FISMA and the RMF, what must occur before this vulnerability can be formally accepted as residual risk?
Answer: The Authorizing Official must formally accept the risk in writing
Under FISMA, the Authorizing Official must formally and explicitly accept residual risk in writing as part of the authorization decision.
What is the key difference between an authenticated and unauthenticated vulnerability scan?
Answer: Authenticated scans use valid credentials to assess vulnerabilities from an insider perspective
Authenticated scans use valid credentials to log into systems, providing deeper visibility into configuration weaknesses and patch levels than external unauthenticated scans.