IT Exam Items Repository Why is the Common Vulnerabilities and Exposures (CVE) resource useful when investigating vulnerabilities detected by a penetration test?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerWhen a penetration test identifies a vulnerability, how should the vulnerability be further verified?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerWhat is the disadvantage of running a TCP Connect scan compared to running a TCP SYN scan during a penetration test?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerWhat can be deduced when a tester enters the nmap -sF command to perform a TCP FIN scan and the target host port does not respond?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerWhat is the purpose of host enumeration when beginning a penetration test?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerWhy would a penetration tester use the nmap -sF command?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerIn which circumstance would a penetration tester perform an unauthenticated scan of a target?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerWhat is required for a penetration tester to conduct a comprehensive authenticated scan against a Linux host?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerWhat is the disadvantage of conducting an unauthenticated scan of a target when performing a penetration test?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerWhat type of server is a penetration tester enumerating when they enter the nmap -sU command?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerWhy would a penetration tester perform a passive reconnaissance scan instead of an active one?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerWhich specification defines the format used by image and sound files to capture metadata?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerWhen performing passive reconnaissance, which Linux command can be used to identify the technical and administrative contacts of a given domain?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerWhich two tools could be used to gather DNS information passively? (Choose two.)ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerA user has found a USB pen drive in the corporate parking lot. What should the user do with this pen drive?ITExamAnswers Editorial Team asked 3 years ago • Ethical Hacker