Penetration Testing and Vulnerability Analysis (CY-702 (A)) - Important Questions
-
9 Marks High Priority Asked: 2025, 2024
What is a vulnerability scanner / vulnerability scanning, its tools and techniques, and how it helps organizations assess their security posture?
Appeared 3x (2025, 2024)
-
7 Marks High Priority Asked: 2025
Explain why reconnaissance / information gathering and footprinting is the first and crucial phase of ethical hacking / penetration testing, including its process and techniques.
Appeared 2x (2025)
-
7 Marks High Priority Asked: 2025, 2024
Explain the legal and ethical considerations associated with penetration testing and their impact on organizational decision-making.
Appeared 2x (2025, 2024)
-
7 Marks High Priority Asked: 2025
What are the common stages of a penetration testing methodology?
Appeared 1x (2025)
-
7 Marks High Priority Asked: 2025
Define penetration testing and explain its various types with suitable examples.
Appeared 1x (2025)
-
7 Marks High Priority Asked: 2025
Explain penetration testing and differentiate between internal and external penetration testing.
Appeared 1x (2025)
-
7 Marks High Priority Asked: 2025
Differentiate between black-box, white-box and grey-box penetration testing.
Appeared 1x (2025)
-
7 Marks Medium Priority Asked: 2024
Compare network penetration testing vs application penetration testing, including use cases and specific considerations.
Appeared 1x (2024)
-
7 Marks Medium Priority Asked: 2024
Explain the purpose of DNS reconnaissance for gathering information about an organization's external presence before penetration testing.
Appeared 1x (2024)
-
7 Marks High Priority Asked: 2025
What are some common tools used for privilege escalation? Explain in detail.
Appeared 1x (2025)
-
7 Marks High Priority Asked: 2025
Explain how web applications are tested for security vulnerabilities and discuss common web application vulnerabilities.
Appeared 1x (2025)
-
7 Marks High Priority Asked: 2025
Describe SQL injection and Cross-Site Scripting (XSS) attacks and how these vulnerabilities can be mitigated.
Appeared 1x (2025)
-
7 Marks High Priority Asked: 2025
Define confidentiality, integrity and availability in the context of web security.
Appeared 1x (2025)
-
7 Marks High Priority Asked: 2025
Explain what business logic testing is, why it is important, and give examples.
Appeared 1x (2025)
-
7 Marks Medium Priority Asked: 2024
Why is it important for penetration testers to have a thorough understanding of the target system's architecture before attempting exploitation?
Appeared 1x (2024)
-
7 Marks Medium Priority Asked: 2024
Explain why employing HTTP Strict Transport Security (HSTS) is crucial to enhance web application security.
Appeared 1x (2024)
-
7 Marks Medium Priority Asked: 2024
Explain the primary risk associated with SQL injection vulnerabilities in web applications.
Appeared 1x (2024)
-
7 Marks High Priority Asked: 2025, 2024
Explain common social engineering techniques used in cyber-attacks.
Appeared 2x (2025, 2024)
-
7 Marks High Priority Asked: 2025
Discuss the importance of wireless network security and explain Wi-Fi vulnerabilities and attacks.
Appeared 1x (2025)
-
7 Marks High Priority Asked: 2025
How can an attacker perform reconnaissance on a physical facility to identify vulnerabilities?
Appeared 1x (2025)
-
7 Marks High Priority Asked: 2025
What are the different Wi-Fi security protocols explain in detail.
Appeared 1x (2025)
-
7 Marks High Priority Asked: 2025
Explain the main types of Wi-Fi vulnerabilities in detail.
Appeared 1x (2025)
-
7 Marks Medium Priority Asked: 2024
Explain the importance of packet sniffing in wireless penetration testing.
Appeared 1x (2024)
-
7 Marks Medium Priority Asked: 2024
Explain how employee training programs contribute to the mitigation of social engineering risks.
Appeared 1x (2024)
-
14 Marks High Priority Asked: 2025
Calculate the number of possible keys for AES-256 encryption.
Appeared 1x (2025)
-
7 Marks High Priority Asked: 2025
What is Cryptography? Explain the role of encryption and decryption in secure communication.
Appeared 1x (2025)
-
7 Marks High Priority Asked: 2025
Describe different cryptographic algorithms and their applications.
Appeared 1x (2025)
-
7 Marks High Priority Asked: 2025
How does symmetric encryption differ from asymmetric encryption?
Appeared 1x (2025)
-
7 Marks High Priority Asked: 2025
Explain the process for tracking and resolving issues identified during testing.
Appeared 1x (2025)
-
7 Marks High Priority Asked: 2025
Perform RSA encryption and decryption for given primes $p$, $q$, public exponent $e$, and message $M$.
Appeared 1x (2025)
-
7 Marks Medium Priority Asked: 2024
Demonstrate how the RSA algorithm can be applied to achieve secure communication.
Appeared 1x (2024)
-
7 Marks Medium Priority Asked: 2024
List the key elements that should be included in a documentation report for a cryptography audit.
Appeared 1x (2024)
-
7 Marks Medium Priority Asked: 2024
Explain the importance of stakeholder engagement in the successful implementation of cryptographic measures.
Appeared 1x (2024)
-
10 Marks High Priority Asked: 2025
Define red teaming and compare it with penetration testing.
Appeared 2x (2025)
-
7 Marks High Priority Asked: 2025
Types of common CTF challenges in detail
Appeared 1x (2025)
-
7 Marks Medium Priority Asked: 2024
Discuss the primary objectives of the penetration test in a specific case?
Appeared 1x (2024)
-
7 Marks Medium Priority Asked: 2024
How Capture the Flag competitions simulate real-world cybersecurity scenarios
Appeared 1x (2024)
-
14 Marks High Priority Asked: 2025
Compute the total number of possible password combinations for an 8-character alphanumeric password (including uppercase, lowercase and digits).
Appeared 1x (2025)
Quick Add to Notes
Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.
Create free accountHave an account? Log in
Notes Panel