Browse all practice questions for the CertMaster PenTest+ Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Ace the 2026 CertMaster PenTest+ Challenge – Hack Your Way to Success! course image
All questions

These questions are part of the practice quiz. Start practicing

  • What is Hunter.io primarily used for?
  • What type of insurance is typically addressed in an MSA?
  • What does Canada's PIPEDA regulate?
  • In the context of a pass-the-hash attack, what should the pentester do if they cannot gain administrative access?
  • What does the methodology section of a penetration test report describe?
  • What kind of vulnerability does a deserialization attack exploit?
  • What is the primary focus of the SHIELD Act?
  • What does goal reprioritization involve in a cybersecurity environment?
  • Which aspect of IAST provides the most accurate assessments of application security?
  • What is the purpose of a Master Service Agreement (MSA) in a business context?
  • What does the Atomic Red Team provide for security testing?
  • What does a Service-Level Agreement (SLA) usually outline?
  • What does the Base CVSS ranking metric denote?
  • What capability does OpenVAS provide in its testing environments?
  • What type of information might be collected during a penetration test regarding systems and networking?
  • Which programming concept allows you to evaluate conditions and execute code accordingly?
  • What does it mean when a JWT is properly validated?
  • What functionality does Aircrack-ng offer within its suite of software?
  • What type of output can the snmp-netstat script generate?
  • Which of the following best describes the 'recommendations' section in a penetration test report?
  • Why would a penetration tester perform credential dumping attacks?
  • Which tool is designed to automate the gathering of intelligence about various targets?
  • What should be included in a contact information list during a penetration test?
  • What is required to activate the WinRM service on both machines?
  • What is the impact of a token not having a valid signature in a JWT?
  • What is the primary purpose of compressing and encrypting a payload?
  • Which command is typically used for a quick check of open ports on a server?
  • What does a successful attack narrative illustrate in a penetration test?
  • What information does the snmp-sysdescr script provide?
  • Which Nmap command allows for OS detection through TCP/IP stack fingerprinting?
  • Which of the following components may be included in a remediation section of a Pentest report?
  • What information is usually contained in the Technical References section of a pentest report?
  • What would you primarily use Amass for in cybersecurity?
  • What primarily limits the effectiveness of brute force attacks?
  • What does an NDA primarily protect?
  • What is Dradis primarily used for in penetration testing?
  • Which of the following best describes the role of a Terms of Service (ToS) document?
  • What action must a pentester take before beginning a legally-compliant penetration test?
  • Which programming construct allows execution to continue as long as a specified condition is met?
  • What is the role of an emergency contact in a cybersecurity context?
  • What is the primary purpose of the STRIDE threat model?
  • Which tool is specifically designed to exploit vulnerabilities in Active Directory Certificate Services?
  • Which PowerShell cmdlet retrieves permissions on files and directories?
  • What is the significance of using 'ZwUnmapViewofSection' during process hollowing?
  • What common data transmission protocols can Impacket test?
  • What is a key role of a PenTester in a penetration test?
  • What is typically included in a List of Tools section of a penetration test report?
  • What should the objectives of a penetration test include?
  • What is a Server-Side Template Injection (SSTI) vulnerability?
  • What action should a penetration tester recommend to reduce the risk of replay attacks on SAML assertions?
  • Which attack technique is likely used in a simulated relay attack?
  • What does risk analysis assess in an organization?
  • What do CVE Details typically provide information about?
  • What is the purpose of the Common Vulnerability Scoring System (CVSS) in a Pentest report?
  • Which aspect of an MSA ensures coverage of unforeseen charges?
  • What does "high-value assets" (HVA) refer to?
  • What does EXIF stand for in the context of digital images?
  • What should be implemented to ensure that each SAML token has a limited lifetime?
  • Which of the following must be included in the authorization for a penetration test?
  • What is a primary benefit of using classes in programming?
  • What role does the team lead or project manager play in relation to team members during a Pentest?
  • OCTAVE is designed to help organizations manage their information security risks through what method?
  • In PowerShell, how can you check the connectivity of multiple ports on a specific IP address?
  • Which of the following documents might contain architecture diagrams?
  • What three metrics are used to determine CVSS rankings?
  • Which command is used in shell scripting to ping an IP address?
  • What is a key component of the pre-test checklist?
  • What behavior does the Infection Monkey emulate?
  • What does the WHOIS database provide?
  • What is the Algorithm Confusion vulnerability in JWTs?
  • Which technique is NOT commonly associated with DLL injection?
  • What requirement does the CCPA impose on vendors handling consumer data?
  • Which aspect of penetration testing do screenshots best provide evidence for?
  • What does Nikto primarily test for?
  • Which command is used for quickly configuring WinRM?
  • Which vulnerability scanner is known for its extensive collection of tests and daily updates?
  • Which of the following best defines the term 'cost-benefit analysis' in cybersecurity?
  • What is the purpose of flow control in programming?
  • What does the Open Source Security Testing Methodology Manual specifically outline?
  • Which protocol ensures automation in the evaluation of security content?
  • In pentesting, what can be selected as targets by stakeholders?
  • What does Cross-Site Request Forgery (CSRF) aim to exploit?
  • Which scenario describes vertical privilege escalation?
  • What limitation affects the speed of brute force attacks?
  • What is indicated by the Temporal CVSS ranking metric?
  • What is included in the compensation specifics of an MSA?
  • How do containers differ from traditional virtual machines?
  • What is the purpose of risk rating in the context of cybersecurity?
  • Which of the following describes the intentional misuse of JWT algorithms for exploitation?
  • What does a directory traversal attack potentially allow an attacker to do?
  • What are the main components used in the network reconnaissance PowerShell script provided as an example?
  • Which document serves to clarify roles and expectations during a PenTest?
  • What is a vulnerability in the context of information security?
  • What does CWE stand for in the context of computer security?
  • What is a direct method used for VLAN hopping?
  • What role do API calls play in secure data transfer?
  • What is a common issue with Signature Verification of JWTs?
  • What is the primary function of Impacket in penetration testing?
  • What is the aim of the attack narrative in a PenTest?
  • What kind of vulnerabilities does CWE help to identify and classify?
  • What feature distinguishes Faraday in the context of penetration testing?
  • What does a class represent in programming?
  • What is one of the key outputs of the Penetration Testing Execution Standard (PTES)?
  • What should be established when limiting invasiveness based on scope during testing?
  • What is a low-level diagram used for in penetration testing?
  • In a pass-the-hash attack, what is the main goal of the attacker?
  • In a bash script, what command is used to generate a sequence of numbers?
  • Which method is NOT suitable for gathering information from a Windows machine without an interactive shell?
  • What is a key consideration when determining allowable tests in a pen testing engagement?
  • What is one of the primary goals of passive information gathering?
  • What type of attack does Server-Side Request Forgery (SSRF) involve?
  • What role does the Council of Registered Ethical Security Testers (CREST) serve in the cybersecurity industry?
  • Which type of logs captures timestamps of attacks during penetration testing?
  • What is the primary purpose of a sidecar container?
  • What does Nmap's -sO option accomplish during a penetration test?
  • InSSIDer is a tool used to analyze which aspect of wireless networks?
  • Which of the following best encapsulates the role of a PenTester?
  • What is a critical step in defining the scope of engagement for a penetration test?
  • What does the DREAD threat model assess?
  • How does manipulating the "kid" value in JWTs pose a security risk?
  • What type of data do vulnerability scanners like Nessus or OpenVAS provide?
  • What should be determined regarding permits and licensing in an MSA?
  • Which command is used to check if zone transfers are enabled for a domain?
  • What could be a potential outcome of a successful SQL injection attack?
  • What key concept delineates the responsibilities of service providers and clients in cloud computing?
  • What is the primary function of the snmp-processes script?
  • What tool must be compiled before it can scan a Windows machine for misconfigurations?
  • How is risk defined in a cybersecurity context?
  • Which of the following is a characteristic of vertical privilege escalation?
  • What distinguishes a DOM-based attack from other types of web attacks?
  • Which format is commonly used for executable and object code files on Unix systems?
  • What will happen when a while loop's condition is false?
  • Which command would NOT effectively hide an executable using an alternate data stream?
  • Why is a risk assessment conducted before a penetration test?
  • Why is verification of backups essential before a penetration test?
  • The purpose of establishing a testing threshold in penetration testing is to?
  • Which logs highlight security errors encountered during a penetration test?
  • Which of the following factors is NOT part of the DREAD threat model?
  • What is root cause analysis primarily used for?
  • Which elements are covered in the Appendix of a penetration test report?
  • What does assessing the 'Damage Potential' refer to in the DREAD model?
  • What does the TCP ACK scan (-sA) aim to determine?
  • The APPI specifically emphasizes the protection of which type of information?
  • What is Caldera designed to simulate in cybersecurity?
  • What does a Test Coverage Map summarize?
  • What licensing information does SCA analyze for third-party components?
  • Which Nmap option is appropriate for performing a ping sweep?
  • What is the primary purpose of the Evil-WinRM tool in penetration testing?
  • What purpose do Attack Logs serve in a penetration test?
  • What technique involves splitting packets into smaller chunks to evade detection by an Intrusion Detection System (IDS)?
  • What is a persistent attack also referred to as?
  • Which script attempts to brute-force SNMP community strings?
  • What is the SPAN technique used for in networking?
  • Which of the following best describes a technical contact's role?
  • What is the purpose of a TCP ACK -sA scan?
  • What type of information does a penetration testing report aim to convey to stakeholders?
  • What is Rubeus primarily used for in a Windows Domain environment?
  • What does the Nmap Scripting Engine (NSE) primarily extend for Nmap?
  • What is the purpose of the echo command in the provided network scanning script?
  • Which tool is known for performing network mapping and information gathering on a targeted network?
  • Which aspect of vulnerability scoring is explained in the CVSS section of a Pentest report?
  • Which of the following represents an activity conducted during scanning in pentesting?
  • In cybersecurity, what does the term 'threat' usually include?
  • What is a recommended approach to mitigate replay attacks on intercepted SAML assertions?
  • What is the primary focus of a social engineer during a penetration test?
  • In a pass-the-ticket attack, what is the main objective for the attacker?
  • Which tool is specifically designed for auditing multicloud platforms?
  • What is typically explored in the risk matrices section of a Pentest report?
  • Which technique involves collecting information about a target without direct engagement?
  • What information do architecture diagrams provide in a pentest report?
  • What aspect of cybersecurity does the NIS Directive primarily focus on?
  • What is primarily assessed during a business impact analysis (BIA)?
  • What consequence can occur from modifying the service account to a less privileged user?
  • What can be a consequence of having insecure configuration files?
  • What is a Statement of Work (SOW) primarily used for?
  • What is an important factor to consider regarding additional restrictions in a pen test?
  • What main aspect does the California Consumer Privacy Act (CCPA) address?
  • What kind of intelligence does the tool heHarvester collect?
  • What should be clearly defined in the scope of a penetration test?
  • Which tool is used to compare the costs and benefits of a cybersecurity solution?
  • What does the scan_ports function primarily check for on a given IP address?
  • What is Censys.io primarily used for?
  • What does patch information in a Pentest report typically include?
  • Which of the following are typically not included as evidence of a successful penetration test?
  • Which part of a pentest report refers to logs showing command execution results?
  • What does the executive summary of a PenTest report provide?
  • What function does Kismet serve in network security?
  • Which tool is used for network packet manipulation and analysis in Python?
  • Why is defining deliverables important in a Statement of Work (SOW)?
  • In the context of a pentest report, what purpose does a Tool Configurations section serve?
  • Modifying a service executable path to point to a malicious executable is an exploitation technique associated with what?
  • What aspect does the executive summary of a PenTest focus on?
  • In the context of BAS tools, what is a primary focus of the tests conducted by Atomic Red Team?
  • What type of software is Dradis classified as in penetration testing?
  • What defines the Environmental CVSS ranking metric?
  • What does BEC stand for in the context of cybersecurity?
  • Which organization provides security standards relevant to vulnerability management?
  • What does the WMIC tool allow a penetration tester to do?
  • What can be achieved by capturing hashed credentials?
  • What is the purpose of a confidentiality agreement in a penetration test?
  • Which type of tool is described as being both comprehensive and user-friendly, simulating various attack techniques?
  • Which of the following Nmap commands identifies services running on open ports?
  • What is the purpose of an Environmental - CVSS metric?
  • What type of logs show successful exploitation during penetration testing?
  • Which tool is specifically mentioned as developed by the MITRE corporation for cyber attack simulation?
  • Which of the following tools would you use to analyze security in a wireless network setting?
  • Which password-cracking tool supports GPU-based parallel processing for efficiency?
  • Which of the following topics is typically covered in a Master Service Agreement?
  • What term refers to flaws that can be exploited by an external threat?
  • During a penetration test, which command helps quickly identify live hosts on a network without a full port scan?
  • Which command conceals a malicious executable inside a text file using NTFS Alternate Data Streams?
  • A full TCP connect scan (-sT) utilizes what type of handshake?
  • What is Gobuster primarily used for in a penetration testing context?
  • Which of the following scripting features is used in the network scanning process?
  • What characterizes a reflected attack in web security?
  • What is the purpose of the Nmap -sP command?
  • What is the outcome of a persistent attack on a website?
  • What is the purpose of PowerSploit?
  • Which organization’s guidelines should be followed when conducting a penetration test?
  • What is the purpose of including command outputs in a pentest report?
  • What is a primary purpose of a vulnerability scanner like Nessus?
  • Which of the following does PowerView help with?
  • What is a characteristic of a password guessing attack?
  • What type of data does the tool WiGLE.net collect?
  • What is the key characteristic of functions in programming?
  • What does the term 'brute-force' refer to in the context of the snmp-brute script?
  • What is the main purpose of conducting a business impact analysis (BIA)?
  • What does the Prowler tool evaluate in a cloud environment?
  • What is the role of an IT manager in establishing communication paths for the PenTest team?
  • What does a threat represent in cybersecurity?
  • Which of the following would you likely find in Error Logs?
  • Which command would you choose to retrieve website headers for diagnosis?
  • In terms of testing methodology, what does a penetration test include?
  • What type of information does the ServiceEnumerator class retrieve?
  • What kind of information is typically gathered by PowerView?
  • Which method is most effective for a pentester to avoid detection when executing a payload?
  • Who is responsible for managing technology-related elements during a cybersecurity project?
  • Which tool is primarily used for banner grabbing?
  • Which tool is commonly used by social engineers during an assessment?
  • What key elements do JSON web tokens (JWTs) contain?
  • Which tool would be useful for gathering information like names, emails, IPs, and URLs?
  • What does Software Composition Analysis (SCA) primarily identify?
  • What is a feature of the Nessus vulnerability scanner?
  • What is Shoulder Surfing in the context of penetration testing?
  • Common locations where credentials may be stored include?
  • Which method is preferred for generating a simple integer sequence in Bash?
  • Null byte injection can lead to unexpected behavior in which part of a web application's functionality?
  • Which encoding method is considered a simple form of obfuscation that may not conceal payloads effectively?
  • What is the main purpose of an authorization letter in PenTesting?
  • What does using packing tools and multi-stage payloads achieve in penetration testing?
  • What is the purpose of the command "sed -i '/backdir/ d' /var/log/auth.log"?
  • Who typically selects the targets for penetration testing?
  • Which framework provides a comprehensive process for conducting penetration tests?
  • What is EXIF primarily used for?
  • What type of information can SpiderFoot gather about a target?
  • What is PowerView used for?
  • Why is it important to limit the use of tools to a particular engagement?
  • Which method should a penetration tester use to perform a VLAN hopping attack?
  • What is the importance of collaboration among red team members and PenTesters?
  • Who is responsible for overseeing the entire engagement in a Pentest?
  • What do remediation details in a Pentest report likely include?
  • Which tool specializes in obtaining a large volume of vulnerability data through its scanning capabilities?
  • Which method provides lateral movement within a network during a pass-the-ticket attack?
  • When retrieving a service banner using the ServiceEnumerator class, what might the class return if it encounters an issue?
  • In the context of the NetworkScanner class, which library is typically used to assemble ARP requests?
  • What type of analysis does Software Composition Analysis focus on?
  • What is the primary purpose of the Pacu tool?
  • What is the function of the 'VirtualAllocEx' in DLL injection?
  • Which term best describes how containers achieve resource separation?
  • Why is it critical for a server to properly validate the "kid" value in JWTs?
  • What vulnerability does the "none" algorithm attack exploit in JWTs?
  • What is the purpose of the attack narrative in a penetration test report?
  • What type of evidence can screenshots provide during a penetration test?
  • In a Pentest report, what is the purpose of including remediation scripts?
  • Which attack technique can effectively bypass an IDS by fragmenting packets?
  • What does the Threat - CVSS metric represent?
  • What do raw scan results often provide information about?
  • What type of issues can Nikto identify on web servers?
  • What key element should be documented during the scope definition of a penetration test?
  • In the context of penetration testing, what is the primary goal of using a packing tool?
  • What is a vital function of the authorization letter in penetration testing?
  • Which method or technique helps organizations of various sizes understand security risks?
  • Which of the following is essential before conducting a penetration test?
  • Why is regular feedback from team members essential in documentation?
  • Which of the following best describes a function of Breach and Attack Simulation (BAS)?
  • Which type of cross-site scripting (XSS) attack retains malicious scripts on the server?
  • What type of actions might recommendations involve after a PenTest?
  • What key role does Maltego play in the context of penetration testing?
  • Which scan utilizes a standard TCP three-way handshake?
  • The NetworkScanner class uses which type of request to identify live hosts?
  • What is important to establish in the rules of engagement for a penetration test?
  • Which command would you use to gather banner information from a web server running on port 80?
  • What is the primary objective of the NIS Directive?
  • What is the primary use of variables in programming?
  • What is the responsibility of a technical writer in a cybersecurity team?
  • What technique does a penetration tester use to intercept and poison LLMNR and NBT-NS requests?
  • What can be obtained through a PowerShell script that queries Active Directory?
  • What is the first step in the process hollowing technique?
  • Which of the following best describes Security Standards in a pentest report?
  • What does the output from tools such as Nmap typically detail?
  • What do vulnerability scanner outputs include?
  • What is the purpose of an Attack Path Map?
  • What is the primary function of nslookup and dig tools?
  • What function does heHarvester serve?
  • What does the Base - CVSS metric represent?
  • When using Bash's brace expansion, which method is preferred for performance?
  • Interactive Application Security Testing (IAST) is a combination of which two testing methods?
  • What occurs if a server uses a weak key for JWT signatures?
  • What does horizontal privilege escalation refer to?
  • What is the term for an attack that overloads users with requests for a second authentication approval?
  • What does staging data typically involve?
  • Conditional statements in programming are used for what purpose?
  • In what context is 'detailed findings' most relevant within a PenTest report?
  • What is a likely action for a penetration tester exploiting a misconfigured Windows service?
  • What structure is used to repeatedly perform actions for a specified number of times in programming?
  • What type of loop is designed to execute a block of code a specific number of times?
  • Which technique can lead an attacker to escalate their access privileges through an SQL injection?
  • What is the primary role of red team members during a cybersecurity engagement?
  • What types of files are examples of misconfigurations in a pentest report?
  • What is the reason for disabling Windows Defender Credential Guard during a pentest?
  • What is the purpose of the Executable and Linkable Format (ELF)?
  • What type of information does the snmp-info script return?
  • What do weak password lists typically include?
  • How does DLL injection in Windows typically start?
  • What does a Risk Matrix typically illustrate in a Pentest report?
  • What function does the primary contact serve in a cybersecurity engagement?
  • What role does the legal document play in a pen testing engagement?
  • What is a storyboard in the context of pentesting?
  • What is included in the detailed findings section of a PenTest report?
  • What does the 'FIN' flag in a TCP segment indicate?
  • What is the main purpose of network enumeration?
  • What is likely included in the reconnaissance phase of a pentest?
  • What is the purpose of the Security Content Automation Protocol (SCAP)?
  • A pass-the-hash attack utilizes what type of credentials to impersonate a user?
  • What is the main purpose of WiGLE.net?
  • Why are weak passwords considered a significant concern in cybersecurity?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy