
EC-CouncilCertified Penetration Testing Professional
Domain 1Objective 1
Introduction to Penetration Testing and Methodologies CPENT Practice Questions (Page 4)
Part of the Penetration Testing Foundations and Scoping domain, which makes up ~15% of our current practice bank.
45questions here
9free pages
8concepts
Questions 16–20
- 16
A penetration tester is engaged by a client to assess a critical web application. The client has a strict change-freeze window during the test and requires that the application remain fully available. The tester discovers a SQL injection vulnerability that could be exploited to extract sensitive data, but exploitation may cause the application to crash. The client has not authorized denial-of-service testing. What should the tester do?
Select an answer first - 17
Why is it important to define the scope of a penetration test before starting?
Select an answer first - 18
Which statement accurately contrasts the goals of a vulnerability assessment and a penetration test?
Select an answer first - 19
What is typically included in the rules of engagement (RoE) for a penetration test?
Select an answer first - 20
After completing a penetration test, a tester must deliver a report to the client's executive team and IT staff. The executives need a high-level overview of business risk, while the IT staff need technical details for remediation. What is the best way to structure the report?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.