Unit 6: Communication and Reporting - Practice Quiz

INT245 — Penetration Testing 50 Questions
0 Correct 0 Wrong 50 Left
0/50

1 Which of the following best describes the primary goal of the Executive Summary in a penetration test report?

A. To provide a step-by-step guide on how to patch software vulnerabilities
B. To explain the high-level business risks and impact to non-technical stakeholders
C. To provide raw scanning logs and exploit code to system administrators
D. To list every specific command used during the engagement

2 In the context of communication triggers, what constitutes a Critical Finding that requires immediate notification?

A. Discovering a vulnerability that allows immediate remote code execution on a production server
B. Finding a server that does not respond to ICMP ping requests
C. Identifying an outdated version of jQuery with no known exploits
D. Locating a sub-domain that returns a 404 error

3 Which tool is specifically designed to facilitate collaborative reporting and vulnerability management during a penetration test?

A. Dradis
B. Nmap
C. John the Ripper
D. Wireshark

4 When defining the Communication Path at the start of an engagement, what is the most important information to establish?

A. The specific Linux kernel versions of the targets
B. The brand of router used by the ISP
C. The preferred font size for the final PDF report
D. A contact list with primary and secondary contacts, including emergency numbers

5 Which section of a penetration test report is primarily intended for system administrators and developers?

A. Document Control
B. Executive Summary
C. Statement of Scope
D. Technical Findings and Remediation

6 What is the purpose of the 'Methodology' section in a penetration test report?

A. To provide a biography of the penetration tester
B. To list the hardware specifications of the tester's laptop
C. To list the prices of the tools used
D. To describe the approach, standards (e.g., PTES, OWASP), and phases undertaken during the test

7 When recommending remediation, which of the following is considered a best practice?

A. Recommending the purchase of the tester's own software product exclusively
B. Suggesting the organization takes the server offline permanently
C. Telling the client to 'Google the solution'
D. Providing a prioritized list of fixes based on risk severity

8 What is the primary function of a Proof of Concept (PoC) in a report?

A. To demonstrate the existence of a vulnerability with evidence (screenshots, code, logs)
B. To prove that the tester is skilled
C. To show the theoretical math behind an encryption algorithm
D. To increase the page count of the report

9 Which metric is commonly used in reports to objectively score the severity of a vulnerability?

A. CVSS (Common Vulnerability Scoring System)
B. ROI (Return on Investment)
C. MTBF (Mean Time Between Failures)
D. TTL (Time To Live)

10 What is the definition of 'Cleanup' in the context of post-report delivery activities?

A. Wiping the client's database to ensure privacy
B. Removing all artifacts, shells, user accounts, and tools created or uploaded during the test
C. Deleting the final report from the client's inbox
D. Formatting the tester's hard drive

11 Why is encryption important when delivering the final penetration test report?

A. It compresses the file size significantly
B. The report contains sensitive vulnerability data that could be exploited if intercepted
C. It prevents the client from printing the report
D. It is required by the HTTP protocol

12 In an IoT environment, what is Binwalk primarily used for during the analysis phase?

A. Performing SQL injection on the cloud dashboard
B. Analyzing and extracting filesystem images from firmware binaries
C. Brute-forcing SSH passwords
D. Scanning for open WiFi networks

13 Which of the following describes a 'de-confliction' communication trigger?

A. Two penetration testers attack the same IP simultaneously
B. The report format conflicts with the printer settings
C. The tester argues with the client about payment
D. The client notices an attack signature and contacts the tester to confirm it is them

14 When writing a report, avoiding False Positives is crucial because:

A. They damage the credibility of the tester and waste the client's resources
B. They are not supported by the CVSS scoring system
C. They make the report file size too large
D. They prevent the use of automated scanning tools

15 What is the correct LaTeX representation for a CVSS temporal score calculation where ?

A. Score equals Base times TemporalMetric
B.
C. Score == Base * TemporalMetric
D. // Score = Base x TemporalMetric

16 Which IoT attack vector involves analyzing power consumption or electromagnetic emissions to extract cryptographic keys?

A. Cross-Site Scripting
B. Side-Channel Attack
C. Buffer Overflow
D. SQL Injection

17 Who is the primary audience for the Scope section of the report?

A. Both technical and management stakeholders
B. Only the external auditors
C. The marketing department
D. The end-users of the application

18 Serpico (SimplE RePort wrIting and COllaboration) aids penetration testers by:

A. Automatically hacking the target
B. Decrypting HTTPS traffic
C. Compiling C++ code
D. Generating report templates and managing findings databases

19 Which of the following is an example of an IoT-specific communication protocol that might be analyzed during a test?

A. PHP (Hypertext Preprocessor)
B. MQTT (Message Queuing Telemetry Transport)
C. HTML (HyperText Markup Language)
D. CSS (Cascading Style Sheets)

20 During the presentation of findings, why is it important to begin with the Executive Summary?

A. It allows the tester to avoid answering technical questions
B. It is the only part of the report that matters
C. It sets the business context before diving into technical minutiae
D. It allows the technical staff to leave early

21 What is Retesting (or Verification) in the post-report phase?

A. Running the exact same scan immediately after the first one
B. Testing the fixes implemented by the client to ensure the vulnerabilities are closed
C. Testing a different target that wasn't in the original scope
D. Verifying that the client has paid the invoice

22 If a penetration tester finds default credentials (admin:admin) on an IoT device, how should this be categorized in the report?

A. Low Risk - hard to guess
B. High/Critical Risk - trivial exploitation
C. Not a vulnerability - intended design
D. Informational - no risk

23 Which component is NOT typically part of the Executive Summary?

A. Business Impact Analysis
B. Overall Security Posture
C. Key Recommendations (High Level)
D. Full Hex Dumps of Network Packets

24 What is the UART interface often used for in IoT penetration testing?

A. Serial communication for debugging and root shell access
B. Connecting to the cloud via 5G
C. Wireless charging
D. Displaying 4K video

25 When recommending remediation for a vulnerability that cannot be patched immediately (e.g., legacy system), what should be suggested?

A. Delete the data on the server
B. Resign from the contract
C. Compensating controls (e.g., network segmentation, firewall rules)
D. Ignore the risk

26 Which formatting feature helps improve the readability of technical reports?

A. Using yellow text on a white background
B. Using a monospaced font for code snippets and command output
C. Using complex vocabulary to sound more intelligent
D. Writing the entire report in a single paragraph

27 What is the primary risk associated with JTAG (Joint Test Action Group) ports on IoT devices?

A. They allow direct access to the CPU and firmware memory
B. They are expensive to manufacture
C. They consume too much electricity
D. They interfere with WiFi signals

28 In the context of reporting, what does 'Attribution' refer to?

A. Assigning credit to the penetration tester who found the bug
B. Identifying the specific hacker group responsible for an attack
C. Linking a finding to a specific host, IP, or URL
D. Listing the sources of open-source intelligence used

29 Which of the following is a critical step in post-report delivery?

A. Publicly tweeting the vulnerabilities found
B. Keeping the VPN access open indefinitely
C. Sending the report to the client's competitors
D. Securely destroying client data stored on tester machines according to the retention policy

30 Why should a report include a 'Limitations' section?

A. To document constraints such as time limits, restricted scopes, or fragile systems that affected testing
B. To complain about the client's network speed
C. To list the tools the tester could not afford
D. To explain why the tester is not liable for anything

31 What is the best way to present statistical data regarding findings (e.g., 5 High, 10 Medium, 20 Low)?

A. A complex algebraic equation
B. Visual charts (Pie charts or Bar graphs)
C. A long comma-separated string of text
D. Hidden metadata in the PDF

32 When defining best practices for reports, the tone should be:

A. Accusatory toward the IT staff
B. Subjective and emotional
C. Objective, professional, and non-judgmental
D. Humorous and sarcastic

33 Which tool is commonly used to take screenshots and annotate them for reports?

A. Aircrack-ng
B. Netcat
C. Metasploit
D. Greenshot or Snagit

34 What is a 'Lessons Learned' meeting?

A. A session to install antivirus software
B. A meeting where the client lectures the tester
C. A training session for the penetration tester
D. A post-engagement meeting to discuss what went well, what didn't, and how to improve future processes

35 In IoT security, what does 'Firmware extraction' allow a tester to do?

A. Physically break the device
B. Access the file system to look for hardcoded keys, configuration files, and binaries
C. Increase the device's Wi-Fi range
D. Bypass the need for electricity

36 What is the formula often used to calculate Risk in a report context?

A.
B.
C.
D.

37 Which of the following is an example of an 'Out-of-band' communication method?

A. Using an encrypted messaging app (Signal) or phone call instead of the client's corporate email
B. Using the client's internal chat server
C. Writing the report in the comments of the client's website
D. Sending an email through the compromised mail server

38 What is the primary security concern regarding Zigbee in IoT devices?

A. It uses excessive battery power
B. It requires a fiber optic connection
C. It is too fast for modern computers
D. Replay attacks and lack of encryption in older implementations

39 When presenting findings, what does 'Reproducibility' ensure?

A. That the client's technical team can follow the steps to trigger the vulnerability themselves
B. That the vulnerability can never be fixed
C. That the report can be printed on any printer
D. That the vulnerability happens automatically every day

40 Which section of the report protects the penetration testing firm from legal liability?

A. Statement of Scope and Authorization
B. Tool Output
C. CVSS Calculator
D. Executive Summary

41 What is a 'Living Document' in the context of long-term security engagements?

A. A document that contains biological viruses
B. A video recording of the test
C. A report that is continuously updated as new vulnerabilities are found and fixed (e.g., in Purple Teaming)
D. A report written on paper only

42 Why is it important to version control the report (e.g., v0.1, v1.0)?

A. To confuse the client
B. To increase the price of the report
C. To track changes between the draft, review, and final release
D. To use more hard drive space

43 Which of the following is a Post-Exploitation activity that must be reported?

A. Checking IP address reputation
B. Data exfiltration and lateral movement
C. Reading the privacy policy
D. Scanning ports

44 What is the recommended file format for the final deliverable report?

A. Executable file (.exe)
B. Proprietary format requiring a paid viewer
C. Microsoft Word (.docx) and PDF (.pdf)
D. Plain Text (.txt) only

45 In IoT testing, what is 'SPI' (Serial Peripheral Interface)?

A. Synchronous Serial Communication interface used for short-distance communication in embedded systems
B. Standard Protocol for Internet
C. Stateful Packet Inspection
D. Security Policy Infrastructure

46 What is the primary purpose of the 'Strategic Recommendations' section?

A. To list specific code patches
B. To sell hardware
C. To suggest long-term improvements like architecture changes, training, or policy updates
D. To criticize the CEO

47 Identify the incorrect statement regarding Report Quality Assurance (QA).

A. QA should check for grammar and spelling errors
B. QA is unnecessary if the tester is senior
C. QA verifies that the severity ratings are consistent
D. QA ensures the findings map to the scope

48 If a tester identifies a Zero-Day vulnerability in a third-party vendor product during a test, what is the best practice?

A. Follow Responsible Disclosure guidelines (notify vendor, wait for patch)
B. Post it on social media immediately
C. Sell the exploit on the dark web
D. Ignore it

49 What tool helps organize findings by mapping them to the MITRE ATT&CK framework in reports?

A. Paint
B. Calculator
C. Notepad
D. Vectr

50 When analyzing IoT network traffic, why might Bluetooth Low Energy (BLE) sniffing be required?

A. To intercept communications between a smartphone app and the IoT device
B. To speed up the internet connection
C. To decrypt SSL/TLS on the web server
D. To hack the satellite connection