Information Gathering & Enumeration
CPTS · 40 questions
- A city network team wants host discovery on an approved /24 before deep port scans. Which approach best fits rules of engagement while reducing unnecessary noise?
- A county SOC reports that a full TCP connect scan across all ports saturated a fragile SCADA historian VLAN that was mistakenly treated as fair game. What is the soundest lesson for scan aggressiveness?
- A municipal admin asks why service version detection matters after open ports are already listed. What is the primary reason to collect versions?
- A library IT lead treats a quick top-ports scan as the complete enumeration plan for an engagement. How should the tester correct that view?
- A transit blue team sees NSE-class scripts run during a test and asks what those scripts are for. Which answer best describes their role?
- A water utility asks whether UDP services can be ignored because TCP scans looked quiet. What should the tester explain?
- City firewall logs show a tester scanning out-of-scope partner ranges discovered via traceroute. What is the correct response to that discovery?
- A county wants stealthy scan timing but also has a short engagement window. How should the tester judge the tradeoff?
- A municipal DMZ review finds many filtered ports. What is the most accurate interpretation for next enumeration steps?
- A civic Wi-Fi guest VLAN is in scope for discovery only, but a tester proposes starting credential attacks immediately. What should happen?
- A school district asks why repeating scans after mid-engagement changes matters. What is the best answer?
- A city asks whether banner grabbing is hacking or enumeration. How should the tester classify it?
- A county mail gateway exposes rich SMTP behaviors and user-enumeration traits during approved probing. What should the tester emphasize about that footprinting?
- A municipal file share answers detailed SMB dialect and OS clues to unauthenticated probes. Why does that matter during footprinting?
- A library's internal DNS allows zone data leakage to the tester's approved network. How should that finding be framed?
- A city still uses well-known default SNMP communities on printers reachable in scope. What should the tester recognize?
- A transit database listener responds with version strings to simple approved probes. What is the best use of that footprinting result?
- A county VPN concentrator's management path is reachable from the test VLAN during footprinting. What should the tester flag?
- A civic application's FTP service allows anonymous listing during approved testing. How should the tester handle that result?
- A municipal AD-integrated web portal leaks internal naming via remote desktop gateway banners. What should the tester do with those multi-protocol clues?
- A city marketing site is in scope, and the tester starts with passive archive and certificate transparency review before active crawling. Why is that judgment sound?
- A county portal's HTTP headers reveal framework and server versions. How should the tester use that fingerprinting?
- A library site hides admin paths, so content discovery is planned. What is the proper purpose of that activity?
- A transit booking app's DNS reveals staging and admin subdomains. Why is subdomain enumeration core web recon?
- A city API gateway exposes verbose error messages with stack traces during recon. How should that be framed?
- A municipal public website starts returning 429 and gateway errors after the tester launches aggressive automated crawls. Rules of engagement cap request rates and protect availability. What should the tester do next?
- A county security lead asks whether searching public indexes for exposed PDFs, backups, and forgotten endpoints is still useful during a scoped external assessment. What is the best guidance?
- A civic identity portal returns "account not found" for some usernames and "invalid password" for others during login attempts the RoE permits. What finding class should the tester report?
- A city application sits behind a CDN that hides origin addresses, and the RoE allows origin discovery if it stays non-disruptive. Which recon approach best matches that goal?
- While reviewing a school district web app, the tester finds HTML comments pointing to forgotten VCS directories and backup archive paths still reachable in scope. How should those artifacts be treated?
- A county IT manager points at a green vulnerability-scanner dashboard and says the annual penetration test is finished. What clarification should the assessor give?
- A city VA report lists hundreds of low-severity findings and buries one critical default credential on an internet-facing admin portal. How should prioritization work?
- A municipal scanner flags a TLS configuration issue on an internal tool that manual review shows is a false positive. What should the tester do before delivering the finding as confirmed?
- A public library asks how approved credentialed scanning differs from unauthenticated scanning on the same subnet. What is the accurate distinction?
- A transit authority VA must serve both executives and system owners. Which reporting quality best drives remediation?
- A city wants to treat continuous vulnerability scanning as continuous penetration testing and cancel periodic adversarial assessments. What should the tester advise?
- A county risk register wants to import scanner base scores unchanged for every civic asset. What caution should guide severity mapping?
- A water-utility SCADA vendor appliance is fragile; scanning policy and RoE require it to be excluded. What is the professional handling?
- A municipal team asks the tester to run the vulnerability scanner and leave without analysis. What professional stance fits a complete VA?
- A city compares last year's vulnerability assessment to this year's penetration-test scope and wants to skip fresh enumeration because "the VA already listed everything." What should the tester do?