Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 1Objective 3

Penetration Testing Essential Concepts CPENT Practice Questions (Page 4)

Part of the Penetration Testing Foundations and Scoping domain, which makes up ~15% of our current practice bank.

48questions here
10free pages
8concepts

Questions 16–20

  1. 16foundation · easy

    Which testing approach provides the tester with full knowledge of the target environment, including source code and architecture?

    Select an answer first
  2. 17expert · hard

    A company has a mature security program and runs regular vulnerability scans. The CISO wants to understand whether the identified vulnerabilities are actually exploitable and what the business impact would be. The company has a limited budget and cannot afford both a full penetration test and a separate vulnerability assessment. What should the security team recommend?

    Select an answer first
  3. 18expert · hard

    A penetration tester is hired to assess the security of a client's external network. The client has provided a detailed rules of engagement document that specifies the exact IP ranges to test and the testing windows. During the test, the tester discovers a critical vulnerability on a server that is outside the specified IP range but is owned by the same client. The vulnerability could allow an attacker to access the internal network. The client's primary objective is to identify risks to the internal network. What is the most appropriate action for the tester to take?

    Select an answer first
  4. 19expert · hard

    A penetration tester is hired by a company to test the security of its new cloud-based application. The client has provided the tester with a test environment that mirrors the production environment. The rules of engagement specify that the tester must not access any production data. During the test, the tester discovers that the test environment is connected to the production database, and the credentials used in the test environment have access to production data. What is the most appropriate action for the tester to take?

    Select an answer first
  5. 20foundation · easy

    Which phase of a penetration test involves gathering information about the target without actively attacking it?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.