Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 1Objective 3

Penetration Testing Essential Concepts CPENT Practice Questions (Page 5)

Part of the Penetration Testing Foundations and Scoping domain, which makes up ~15% of our current practice bank.

48questions here
10free pages
8concepts

Questions 21–25

  1. 21application · medium

    A penetration tester is preparing for an engagement with a new client. The client has provided a document that outlines the scope, objectives, timelines, and boundaries of the test. The document also specifies the testing techniques that are allowed and the points of contact for the engagement. What is this document called?

    Select an answer first
  2. 22application · medium

    A penetration tester is conducting an engagement for a client. During the test, the tester discovers that the client's web server is vulnerable to SQL injection. The tester decides to exploit this vulnerability to extract the entire database, including customer records, to prove the impact. The rules of engagement specify that testing should be limited to demonstrating vulnerability and should not involve extracting sensitive data. What is the most appropriate action for the tester to take?

    Select an answer first
  3. 23expert · hard

    A penetration testing team is asked to assess a critical infrastructure environment. The client is concerned about system availability and wants to minimize the risk of disruption. The team must decide between a black-box test that includes active exploitation and a white-box test that focuses on configuration review and static analysis. Which approach best balances the client's need for thorough security validation with the constraint on availability?

    Select an answer first
  4. 24application · medium

    A penetration testing team is hired to assess the security of a new mobile application. The client provides the team with the app's API documentation and a valid tester account but does not provide the source code. The team is expected to test the app's behavior and server-side APIs. Which type of penetration test does this describe?

    Select an answer first
  5. 25application · medium

    A penetration testing team is planning an engagement for a client that has a complex network infrastructure. The client wants to ensure that the testing methodology is comprehensive and covers all aspects of the network, including physical security, social engineering, and wireless testing. The team lead needs to select a framework that provides a broad, operational security testing methodology. Which framework is the most appropriate choice?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.