โ† All CAP Flashcard Decks

Vulnerability Assessment & Penetration Testing Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Vulnerability Assessment & Penetration Testing flashcards as text
  1. A security assessor is evaluating a system's resistance to brute-force attacks and finds no account lockout policy. Which NIST SP 800-53 control family is most directly relevant to this finding?

    Answer: IA - Identification and Authentication

    The IA (Identification and Authentication) control family includes controls like IA-5 that address authenticator management, including account lockout policies.

  2. What is the term for a vulnerability assessment approach that examines only externally visible attack surfaces without any internal system knowledge?

    Answer: Black-box assessment

    Black-box assessments simulate an external attacker with no prior knowledge, testing only what is visible from outside the organization's perimeter.

  3. During a penetration test, a tester discovers a system running an unpatched version of Apache with a known remote code execution vulnerability. What is the FIRST step before attempting exploitation?

    Answer: Verify the finding is within the authorized scope of the Rules of Engagement

    Before exploiting any vulnerability, testers must confirm the target system is within the authorized scope defined in the Rules of Engagement to avoid unauthorized access.

  4. Which tool is commonly used for network vulnerability scanning in federal security assessments and is referenced in many NIST guidelines?

    Answer: Nessus

    Nessus is a widely referenced vulnerability scanner in federal assessments that identifies vulnerabilities, misconfigurations, and compliance violations across network hosts.

  5. A penetration tester successfully performs DNS spoofing to redirect users to a malicious site. Which security principle is primarily violated in this attack scenario?

    Answer: Integrity

    DNS spoofing violates integrity by corrupting the authentic mapping between domain names and IP addresses, directing users to unauthorized destinations.

  6. Under the RMF, what is the minimum frequency for conducting vulnerability assessments on high-impact federal information systems per NIST SP 800-137?

    Answer: Continuously or near-continuously

    NIST SP 800-137 recommends continuous monitoring strategies for high-impact systems, moving beyond periodic snapshots to ongoing vulnerability detection.

  7. What is the purpose of maintaining a chain of custody during a penetration test on a federal system?

    Answer: To ensure evidence integrity and accountability for all test artifacts and findings

    Chain of custody ensures that all evidence and artifacts collected during testing are properly documented, handled, and protected to maintain their integrity and admissibility.