Skip to content
CY-702 (A) · Penetration Testing and Vulnerability Analysis/Important Questions

Penetration Testing and Vulnerability Analysis (CY-702 (A)) - Important Questions

  1. 9 Marks High Priority Asked: 2025, 2024

    What is a vulnerability scanner / vulnerability scanning, its tools and techniques, and how it helps organizations assess their security posture?

    Appeared 3x (2025, 2024)

  2. 7 Marks High Priority Asked: 2025

    Explain why reconnaissance / information gathering and footprinting is the first and crucial phase of ethical hacking / penetration testing, including its process and techniques.

    Appeared 2x (2025)

  3. 7 Marks High Priority Asked: 2025, 2024

    Explain the legal and ethical considerations associated with penetration testing and their impact on organizational decision-making.

    Appeared 2x (2025, 2024)

  4. 7 Marks High Priority Asked: 2025

    What are the common stages of a penetration testing methodology?

    Appeared 1x (2025)

  5. 7 Marks High Priority Asked: 2025

    Define penetration testing and explain its various types with suitable examples.

    Appeared 1x (2025)

  6. 7 Marks High Priority Asked: 2025

    Explain penetration testing and differentiate between internal and external penetration testing.

    Appeared 1x (2025)

  7. 7 Marks High Priority Asked: 2025

    Differentiate between black-box, white-box and grey-box penetration testing.

    Appeared 1x (2025)

  8. 7 Marks Medium Priority Asked: 2024

    Compare network penetration testing vs application penetration testing, including use cases and specific considerations.

    Appeared 1x (2024)

  9. 7 Marks Medium Priority Asked: 2024

    Explain the purpose of DNS reconnaissance for gathering information about an organization's external presence before penetration testing.

    Appeared 1x (2024)

  10. 7 Marks High Priority Asked: 2025

    What are some common tools used for privilege escalation? Explain in detail.

    Appeared 1x (2025)

  11. 7 Marks High Priority Asked: 2025

    Explain how web applications are tested for security vulnerabilities and discuss common web application vulnerabilities.

    Appeared 1x (2025)

  12. 7 Marks High Priority Asked: 2025

    Describe SQL injection and Cross-Site Scripting (XSS) attacks and how these vulnerabilities can be mitigated.

    Appeared 1x (2025)

  13. 7 Marks High Priority Asked: 2025

    Define confidentiality, integrity and availability in the context of web security.

    Appeared 1x (2025)

  14. 7 Marks High Priority Asked: 2025

    Explain what business logic testing is, why it is important, and give examples.

    Appeared 1x (2025)

  15. 7 Marks Medium Priority Asked: 2024

    Why is it important for penetration testers to have a thorough understanding of the target system's architecture before attempting exploitation?

    Appeared 1x (2024)

  16. 7 Marks Medium Priority Asked: 2024

    Explain why employing HTTP Strict Transport Security (HSTS) is crucial to enhance web application security.

    Appeared 1x (2024)

  17. 7 Marks Medium Priority Asked: 2024

    Explain the primary risk associated with SQL injection vulnerabilities in web applications.

    Appeared 1x (2024)

  18. 7 Marks High Priority Asked: 2025, 2024

    Explain common social engineering techniques used in cyber-attacks.

    Appeared 2x (2025, 2024)

  19. 7 Marks High Priority Asked: 2025

    Discuss the importance of wireless network security and explain Wi-Fi vulnerabilities and attacks.

    Appeared 1x (2025)

  20. 7 Marks High Priority Asked: 2025

    How can an attacker perform reconnaissance on a physical facility to identify vulnerabilities?

    Appeared 1x (2025)

  21. 7 Marks High Priority Asked: 2025

    What are the different Wi-Fi security protocols explain in detail.

    Appeared 1x (2025)

  22. 7 Marks High Priority Asked: 2025

    Explain the main types of Wi-Fi vulnerabilities in detail.

    Appeared 1x (2025)

  23. 7 Marks Medium Priority Asked: 2024

    Explain the importance of packet sniffing in wireless penetration testing.

    Appeared 1x (2024)

  24. 7 Marks Medium Priority Asked: 2024

    Explain how employee training programs contribute to the mitigation of social engineering risks.

    Appeared 1x (2024)

  25. 14 Marks High Priority Asked: 2025

    Calculate the number of possible keys for AES-256 encryption.

    Appeared 1x (2025)

  26. 7 Marks High Priority Asked: 2025

    What is Cryptography? Explain the role of encryption and decryption in secure communication.

    Appeared 1x (2025)

  27. 7 Marks High Priority Asked: 2025

    Describe different cryptographic algorithms and their applications.

    Appeared 1x (2025)

  28. 7 Marks High Priority Asked: 2025

    How does symmetric encryption differ from asymmetric encryption?

    Appeared 1x (2025)

  29. 7 Marks High Priority Asked: 2025

    Explain the process for tracking and resolving issues identified during testing.

    Appeared 1x (2025)

  30. 7 Marks High Priority Asked: 2025

    Perform RSA encryption and decryption for given primes $p$, $q$, public exponent $e$, and message $M$.

    Appeared 1x (2025)

  31. 7 Marks Medium Priority Asked: 2024

    Demonstrate how the RSA algorithm can be applied to achieve secure communication.

    Appeared 1x (2024)

  32. 7 Marks Medium Priority Asked: 2024

    List the key elements that should be included in a documentation report for a cryptography audit.

    Appeared 1x (2024)

  33. 7 Marks Medium Priority Asked: 2024

    Explain the importance of stakeholder engagement in the successful implementation of cryptographic measures.

    Appeared 1x (2024)

  34. 10 Marks High Priority Asked: 2025

    Define red teaming and compare it with penetration testing.

    Appeared 2x (2025)

  35. 7 Marks High Priority Asked: 2025

    Types of common CTF challenges in detail

    Appeared 1x (2025)

  36. 7 Marks Medium Priority Asked: 2024

    Discuss the primary objectives of the penetration test in a specific case?

    Appeared 1x (2024)

  37. 7 Marks Medium Priority Asked: 2024

    How Capture the Flag competitions simulate real-world cybersecurity scenarios

    Appeared 1x (2024)

  38. 14 Marks High Priority Asked: 2025

    Compute the total number of possible password combinations for an 8-character alphanumeric password (including uppercase, lowercase and digits).

    Appeared 1x (2025)

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in