Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Penetration Testing Professional

Domain 1Objective 3

Penetration Testing Essential Concepts CPENT Practice Questions (Page 6)

Part of the Penetration Testing Foundations and Scoping domain, which makes up ~15% of our current practice bank.

48questions here
10free pages
8concepts

Questions 26–30

  1. 26expert · hard

    A penetration tester is hired to assess a company's cloud infrastructure. The rules of engagement authorize testing of the company's own AWS account. During reconnaissance, the tester discovers that a misconfigured S3 bucket in the company's account contains customer data and is publicly accessible. The tester also notices that the bucket's access logs are stored in a separate logging account that is NOT mentioned in the rules of engagement. What should the tester do?

    Select an answer first
  2. 27foundation · easy

    What is a key goal of a vulnerability assessment that is NOT a primary goal of a penetration test?

    Select an answer first
  3. 28foundation · easy

    What is the typical final phase of a penetration test?

    Select an answer first
  4. 29expert · hard

    A security team has been asked to assess the security of a new customer-facing web portal. The team has a limited budget and needs to provide a clear, actionable list of vulnerabilities to the development team. The team decides to use an automated vulnerability scanner to identify common issues. After the scan, they manually verify the findings to eliminate false positives. They do not attempt to exploit the vulnerabilities or chain them together to demonstrate impact. What is the primary difference between this assessment and a full penetration test?

    Select an answer first
  5. 30expert · hard

    A penetration tester is hired to assess a legacy application that is critical to a client's business operations. The client is concerned about the stability of the application and has strict rules of engagement that prohibit any testing that could cause a denial of service or data corruption. The tester has been given the application's source code and architecture documentation. The primary objective is to identify as many vulnerabilities as possible without disrupting operations. Which testing approach is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CPENT” is a trademark of its owner, used for identification only.