
EC-CouncilCertified Security Specialist
Domain 4Objective 6
Penetration Testing Fundamentals ECSS Practice Questions (Page 6)
Part of the Ethical Hacking Advanced Attacks and Penetration Testing domain, which makes up ~17% of our current practice bank.
44questions here
9free pages
7concepts
Questions 26–30
- 26
A penetration tester is asked to assess the security of a financial application. The client wants to know if an attacker could steal funds or manipulate transactions. The tester has access to the application's source code and a test environment. Which type of testing would be most appropriate to answer the client's question?
Select an answer first - 27
A penetration testing contract specifies that the test must be conducted only between 2:00 AM and 6:00 AM on weekends to avoid impacting business operations. The tester discovers that a critical vulnerability can only be fully exploited during business hours when the application is under peak load. What should the tester do?
Select an answer first - 28
A company has a mature vulnerability management program that includes regular automated scans and patch management. They are now considering a penetration test. The security manager argues that the scans already identify vulnerabilities, so a penetration test is redundant. Which argument best justifies the need for a penetration test?
Select an answer first - 29
A retail company wants to assess its external web application for known vulnerabilities before a scheduled PCI DSS audit. The security team has limited time and budget and needs a report listing missing patches, misconfigurations, and outdated components with severity ratings. Which approach best meets this requirement?
Select an answer first - 30
In black-box penetration testing, what level of information is provided to the tester?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.