Skip to content

Vulnerability Discovery and Analysis Questions

Practice questions for Vulnerability Discovery and Analysis topic in CompTIA PenTest+. 17 questions covering this domain.

17 questions4 easy8 medium5 hard
Q1
medium

A penetration tester is using Nikto to scan a web server. What category of vulnerabilities is Nikto PRIMARILY designed to detect?

Q2
easy

What is the term for a vulnerability scan result that incorrectly reports a vulnerability on a system that is NOT actually vulnerable?

Q3
medium

A penetration tester is performing DAST (Dynamic Application Security Testing) on a web application. Which characteristic distinguishes DAST from SAST...

Q4
easy

Which vulnerability scanning tool is commonly associated with credentialed (authenticated) scanning that provides deeper visibility into installed sof...

Q5
hard

A penetration tester performs a credentialed Nessus scan of a Linux server and receives a critical finding related to an unpatched kernel vulnerabilit...

Q6
medium

A penetration tester performs an unauthenticated vulnerability scan and receives a result flagging a service as vulnerable to a known CVE. Before atte...

Q7
medium

A penetration tester is assessing a web application and needs to identify vulnerabilities in the application's source code without running the applica...

Q8
hard

A penetration tester reviews a Nessus scan report and notices that a Windows server is flagged for MS17-010 (EternalBlue). The server is running Windo...

Q9
hard

A penetration tester performs a vulnerability scan and discovers a finding for CVE-2021-44228 (Log4Shell) on a Java-based application server. Before a...

Q10
medium

A penetration tester discovers that a web application uses an older version of a third-party JavaScript library with a known XSS vulnerability. The ap...

Q11
medium

A penetration tester is performing a web application security assessment and uses Burp Suite's scanner to identify an injection vulnerability. What ty...

Q12
easy

Which term describes a vulnerability for which no patch or fix is currently available from the vendor, often because the vendor is unaware of it?

Q13
medium

A penetration tester is reviewing a web application and notices that the server responds with verbose error messages including database names, table s...

Q14
easy

What does the CVSS (Common Vulnerability Scoring System) base score measure?

Q15
hard

A penetration tester performs an authenticated Nessus scan of a Windows domain controller and discovers a finding titled "MS14-068: Microsoft Kerberos...

Q16
medium

A penetration tester is reviewing the output of an OpenVAS vulnerability scan. The tool reports a finding rated CVSS 9.8 on a public-facing server. Be...

Q17
hard

A penetration tester is assessing a web application and discovers that the application uses JWT (JSON Web Token) authentication. When inspecting a cap...

Sign in to see all 17 questions

Create a free account to browse all questions — completely free during our launch phase.