← All CCP Flashcard Decks

Vulnerability Assessment & Penetration Testing Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Vulnerability Assessment & Penetration Testing flashcards as text
  1. What is 'fuzzing' in the context of vulnerability testing?

    Answer: Sending large volumes of random, malformed, or unexpected inputs to a target application to discover crashes or unexpected behavior

    Fuzzing (or fuzz testing) automatically submits random, invalid, or unexpected input data to an application to uncover crashes, exceptions, or security vulnerabilities such as buffer overflows and injection flaws.

  2. What is the key characteristic of a 'grey-box' penetration test?

    Answer: The tester has partial knowledge, such as network diagrams or low-privilege credentials, simulating an insider threat

    A grey-box penetration test provides the tester with partial information about the target environment — such as network topology, user-level credentials, or application documentation — simulating a partially informed attacker or insider threat.

  3. According to the Penetration Testing Execution Standard (PTES), which phase involves maintaining access and establishing a persistent presence on a compromised system?

    Answer: Post-exploitation

    The post-exploitation phase in PTES involves maintaining persistent access, escalating privileges, pivoting to other systems, and collecting evidence to demonstrate the full business impact of a successful compromise.

  4. Which type of Cross-Site Scripting (XSS) attack stores malicious script in the target server's database and serves it to all users who view the affected page?

    Answer: Stored (Persistent) XSS

    Stored (persistent) XSS embeds malicious script into a server-side data store (e.g., a database or comment field), where it is permanently served to any user who loads the affected page, making it more dangerous than reflected XSS.

  5. What is the primary advantage of an authenticated vulnerability scan over an unauthenticated scan?

    Answer: Authenticated scans can detect vulnerabilities inside the system, such as missing patches and misconfigurations, resulting in fewer false positives and more complete results

    Authenticated scans log into target systems with credentials, allowing the scanner to inspect installed software versions, patch levels, and configuration settings from the inside, producing more accurate and comprehensive results than unauthenticated network-only scans.

  6. What defines a zero-day vulnerability?

    Answer: A vulnerability that is unknown to the software vendor and for which no official patch exists

    A zero-day vulnerability is an undisclosed security flaw unknown to the vendor, meaning developers have had zero days to address it — no official patch or mitigation is available, making it extremely valuable to attackers.

  7. What does 'lateral movement' refer to in the context of a penetration test or cyberattack?

    Answer: Moving horizontally across a network from one compromised system to other systems to expand access

    Lateral movement describes techniques used by attackers to progressively move through a network environment after initial compromise, accessing additional hosts and resources horizontally to expand their foothold and reach high-value targets.