Test your Penetration Testing knowledge with a free interactive quiz — 20 questions with answers and explanations. No signup needed to play.
Question 1/12Score 0
What does "exploitation" mean as a phase of penetration testing, following identification of a candidate vulnerability?
In this round
What does "exploitation" mean as a phase of penetration testing, following identification of a candidate vulnerability?
What is the purpose of a "Common Vulnerability Scoring System" (CVSS) score commonly attached to findings in a penetration test report?
What is "social engineering" as a category of technique sometimes included in a broader penetration testing or red team engagement?
What is penetration testing?
What is the general difference in scope and depth between a "vulnerability assessment" and a full "penetration test"?
Why is explicit authorization ("scope" and permission from the system owner) considered essential before conducting a penetration test?
What is the difference between a "black box," "white box," and "gray box" penetration test in terms of the information given to the tester beforehand?
What is a realistic reason an organization might choose to conduct regular, recurring penetration tests rather than treating it as a single, one-time activity?
What is the purpose of a "rules of engagement" document agreed upon before a penetration test begins?
What does "vulnerability scanning" typically contribute to a penetration test, and how does it differ from the exploitation phase?
Why might a penetration tester need to be especially careful when testing against production systems, as opposed to a dedicated test/staging environment?
What is "reconnaissance" (or "information gathering") as an early phase of a typical penetration testing methodology?