← All Certified Ethical Hacker Flashcard Decks

Vulnerability Assessment and Exploitation Flashcards

6 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Vulnerability Assessment and Exploitation flashcards as text
  1. What is the difference between a vulnerability assessment and a penetration test?

    Answer: A vulnerability assessment identifies weaknesses; a pen test actively exploits them

    A vulnerability assessment identifies and reports security weaknesses without exploiting them, while a penetration test actively exploits vulnerabilities to demonstrate real-world impact.

  2. Which CVSS metric indicates how easily an attacker can repeat a successful exploit?

    Answer: Attack Complexity

    Attack Complexity (AC) in CVSS measures the conditions beyond the attacker's control required to exploit the vulnerability, indicating how reliably the exploit can be repeated.

  3. Which tool is an industry-standard open-source vulnerability scanner used in CEH assessments?

    Answer: OpenVAS

    OpenVAS (Greenbone Vulnerability Manager) is a widely used open-source vulnerability scanner that checks systems against thousands of known vulnerability tests.

  4. What type of vulnerability assessment is performed without any prior knowledge of the target environment?

    Answer: Black Box Assessment

    A black box assessment simulates an external attacker with no prior knowledge, testing the target purely from an outsider's perspective.

  5. Which Metasploit component stores information about discovered hosts, services, and vulnerabilities during an engagement?

    Answer: The Metasploit Database (msfdb)

    The Metasploit database (msfdb), backed by PostgreSQL, stores all workspace data including discovered hosts, open ports, services, and vulnerability findings.

  6. What does CVSS stand for in the context of vulnerability scoring?

    Answer: Common Vulnerability Scoring System

    CVSS stands for Common Vulnerability Scoring System, which provides a standardized method for rating the severity of security vulnerabilities.