Vulnerability Assessment & Penetration Testing Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Vulnerability Assessment & Penetration Testing flashcards as text
During red team exercises on federal systems, which methodology specifically simulates advanced persistent threat (APT) tactics, techniques, and procedures?
Answer: MITRE ATT&CK Framework
The MITRE ATT&CK Framework catalogs real-world APT tactics and techniques, making it the primary reference for simulating sophisticated threat actor behavior.
A tester exploits a buffer overflow vulnerability to gain root access on a Linux server. What phase of the penetration testing lifecycle comes immediately after achieving this initial access?
Answer: Post-Exploitation and Lateral Movement
After gaining initial access, testers move to post-exploitation to maintain persistence, escalate privileges, and move laterally through the network.
Which federal regulation requires agencies to conduct periodic security assessments of information systems, including vulnerability assessments?
Answer: FISMA (Federal Information Security Modernization Act)
FISMA mandates that federal agencies implement security programs including periodic assessments of controls for all federal information systems.
An assessor discovers that a web application is vulnerable to SQL injection. Which CWE identifier is most directly associated with this vulnerability class?
Answer: CWE-89
CWE-89 (Improper Neutralization of Special Elements used in an SQL Command) is the Common Weakness Enumeration entry for SQL injection vulnerabilities.
What is the primary security concern when a penetration tester finds that a federal system allows users to upload executable files without restriction?
Answer: Unrestricted File Upload enabling remote code execution
Unrestricted file upload vulnerabilities allow attackers to upload and execute malicious code (webshells) on the server, achieving full remote code execution.
In the context of CAP assessments, what document formally captures the results of a security assessment including vulnerability findings and their risk levels?
Answer: Security Assessment Report (SAR)
The Security Assessment Report documents all findings from the security assessment, including identified vulnerabilities, their severity, and recommendations.
During a physical penetration test, a tester gains unauthorized access to a server room by tailgating an authorized employee. What type of attack does this represent?
Answer: Social Engineering - Tailgating/Piggybacking
Tailgating (or piggybacking) is a physical social engineering technique where an unauthorized person follows an authorized individual through a secured entry point.