Unit1 - Subjective Questions

INT245 • Practice Questions with Detailed Answers

1

Define Penetration Testing and distinguish it from Vulnerability Assessment.

2

Compare and contrast Black Box, White Box, and Grey Box penetration testing strategies.

3

Explain the importance of the Rules of Engagement (RoE) in the planning phase of a penetration test.

4

Describe the Penetration Testing Execution Standard (PTES) and list its seven main sections.

5

Discuss the concept of Scope Creep in penetration testing and how it can be managed.

6

How does compliance (e.g., PCI-DSS, HIPAA) influence the planning of a penetration test?

7

Differentiate between Internal and External penetration testing.

8

What are the environmental considerations when planning a penetration test? Discuss Production vs. Staging environments.

9

Write a short note on the OSSTMM (Open Source Security Testing Methodology Manual).

10

Explain the Post-Exploitation phase. Why is it critical in determining the business impact?

11

Derive the basic relationship for Risk in the context of planning a pentest. How does this formula guide the scoping process?

12

What are Red Teaming, Blue Teaming, and Purple Teaming?

13

List five critical questions that must be answered during the Scoping/Pre-engagement phase.

14

Explain the NIST SP 800-115 methodology for technical security testing.

15

What is Social Engineering in the context of pentesting, and why is it often excluded from the scope?

16

Describe the Blind and Double-Blind testing strategies.

17

Why is Reconnaissance (Information Gathering) considered the most critical phase for a successful penetration test?

18

What are the risks associated with penetration testing, and how are they mitigated during the planning phase?

19

Explain the significance of Cloud-based penetration testing constraints compared to traditional on-premise testing.

20

Draft a sample structure for a Penetration Testing Final Report.