โ† All CCT Flashcard Decks

CCT Ethical Hacking & Penetration Testing Flashcards

6 cards from real CCT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CCT Ethical Hacking & Penetration Testing flashcards as text
  1. What is the goal of the 'post-exploitation' phase in a penetration test?

    Answer: Maintaining access, pivoting, and demonstrating the impact of a compromise

    Post-exploitation demonstrates the real-world impact of a compromise by pivoting to other systems, escalating privileges, and exfiltrating data to show what an attacker could achieve.

  2. Which tool is commonly used for password cracking by performing dictionary and brute-force attacks against password hashes?

    Answer: John the Ripper

    John the Ripper is a popular open-source password security auditing tool that can crack password hashes using dictionary attacks, brute-force attacks, and rule-based attacks.

  3. What is a 'pivot' in penetration testing?

    Answer: Using a compromised system as a relay to attack other internal systems not directly accessible

    Pivoting uses a compromised host as a jump point to reach and attack other network segments or systems that are not directly reachable from the attacker's machine.

  4. What is the OWASP Testing Guide primarily used for?

    Answer: Providing a comprehensive methodology for web application security testing

    The OWASP Testing Guide provides a structured framework with test cases for identifying security vulnerabilities in web applications, covering authentication, authorization, input validation, and more.

  5. Which type of social engineering attack involves creating a fabricated scenario to manipulate a target into divulging information?

    Answer: Pretexting

    Pretexting involves constructing a fabricated scenario (a pretext) to extract information or gain trust from a target, such as impersonating IT support to get a user's password.

  6. What does a vulnerability scanner like Nessus do that a port scanner like Nmap does not?

    Answer: Test vulnerabilities and misconfigurations against known CVE databases and provide risk ratings

    Vulnerability scanners go beyond port scanning by probing detected services for known vulnerabilities, misconfigurations, and missing patches, then correlating findings with CVE databases and assigning severity scores.