CCT Ethical Hacking & Penetration Testing Flashcards
6 cards from real CCT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 CCT Ethical Hacking & Penetration Testing flashcards as text
What is the final deliverable of a professional penetration test engagement?
Answer: A comprehensive written report detailing findings, risk ratings, evidence, and remediation recommendations
The penetration test report communicates discovered vulnerabilities with proof-of-concept evidence, CVSS risk ratings, business impact analysis, and prioritized remediation steps to help the client fix issues.
What is 'fuzzing' as a security testing technique?
Answer: Sending large volumes of random, malformed, or unexpected input to an application to trigger crashes or unexpected behavior
Fuzzing (fuzz testing) involves feeding random, invalid, or unexpected inputs to an application to discover crashes, memory leaks, or unexpected behaviors that may indicate exploitable vulnerabilities.
What is the Common Vulnerability Scoring System (CVSS) used for?
Answer: Providing a standardized numerical score to represent the severity of a security vulnerability
CVSS provides a standardized framework to score vulnerabilities from 0 to 10 based on exploitability, scope, and impact metrics, helping organizations prioritize remediation efforts.
Which technique do penetration testers use to intercept and manipulate web application traffic between a browser and server?
Answer: Using a web proxy like Burp Suite as a man-in-the-middle
A web proxy like Burp Suite sits between the browser and server, allowing testers to inspect, modify, and replay HTTP/HTTPS requests to test for web application vulnerabilities.
What is a 'zero-day' vulnerability?
Answer: A vulnerability that is unknown to the vendor and has no official patch available
A zero-day vulnerability is a security flaw unknown to the software vendor, meaning zero days have passed since the vendor became aware, so no patch or official mitigation exists.
What does the term 'scope' define in a penetration testing engagement?
Answer: The specific systems, networks, applications, and methods that are authorized for testing
Scope defines the boundaries of the test — which IP ranges, domains, and applications are in-scope versus out-of-scope — ensuring testers stay within authorized limits and avoid disrupting unintended systems.