Home > CompTIA PenTest+ Certification > Quizzes > CompTIA PenTest+ Certification Exam: Information Gathering and Vulnerability Scanning
CompTIA PenTest+ Certification Exam: Information Gathering and Vulnerability Scanning
Fast practice, instant feedback. Timer auto-submits when time’s up.
Avg score: 76% Most missed: “The CVE Dictionary is a standard used for documenting which type of vulnerabilit…”
CompTIA PenTest+ Certification Exam: Information Gathering and Vulnerability Scanning
Time left 00:00
8 Questions

1. During a pentest, you discover a sitemap.xml file and a crossdomain.xml file. These files can provide useful information for mapping out web directories and files that would otherwise have to be brute-forced. What is the name of another file that can provide URLs and URI locations that restricts search engines from crawling certain locations?
2. Which port scan method is also known as a half-open scan that never establishes a true connection with the target host over the network?
3. Active information gathering is best used during which of the following scenarios?
4. When conducting a port scan against a target, which Nmap flag is used to specify a port range?
5. Which Nmap flag was likely used to determine the state of each port?
6. Which Nmap script could you use to enumerate popular web directories from the service hosted on port 80?
7. Nessus plugins are written in which type of proprietary language?
8. The CVE Dictionary is a standard used for documenting which type of vulnerabilities?