Skip to content
Oluma Cyber Security Awareness
๐ŸŽฏ
OLUMA CERTIFICATION ZONE

PenTest+Practice Range

100 scenario questions across engagement management, recon, exploitation, post-exploitation and reporting โ€” with ethics and authorization at the core. Select your range and stay in scope.

Engagement ManagementReconnaissance and EnumerationAttacks and ExploitsPost-ExploitationReporting and Communication
SELECT YOUR RANGE
01/100 Engagement Management

A consultant is asked to begin testing a client web application immediately. The project manager verbally says the test is approved, but the tester has not received a signed statement of work or rules of engagement. What should the tester do FIRST?

โœ” SCOPE RESPECTED

That's how an ethical hacker thinks โ€” authorized, precise, documented.

A penetration test must be explicitly authorized in writing before any testing occurs. The SOW and ROE define scope, timing, permitted techniques, escalation paths, and legal boundaries.

โœ– OUT OF SCOPE

Vector didn't land โ€” recon the takeaway:

A penetration test must be explicitly authorized in writing before any testing occurs. The SOW and ROE define scope, timing, permitted techniques, escalation paths, and legal boundaries.

โœ– OUT OF SCOPE

Vector didn't land โ€” recon the takeaway:

A penetration test must be explicitly authorized in writing before any testing occurs. The SOW and ROE define scope, timing, permitted techniques, escalation paths, and legal boundaries.

โœ– OUT OF SCOPE

Vector didn't land โ€” recon the takeaway:

A penetration test must be explicitly authorized in writing before any testing occurs. The SOW and ROE define scope, timing, permitted techniques, escalation paths, and legal boundaries.

02/100 Engagement Management

During testing, a subdomain resolves to an IP address owned by a third-party hosting provider and was not listed in scope. The application appears to be connected to the client. What is the BEST next step?

โœ” FINDING CONFIRMED

Clean tradecraft. The client would sign off on that.

Out-of-scope systems must not be tested without written approval. The tester should pause and ask the point of contact to confirm ownership and authorization.

โœ– DETECTED & BLOCKED

Blocked this time. Adjust your approach:

Out-of-scope systems must not be tested without written approval. The tester should pause and ask the point of contact to confirm ownership and authorization.

โœ– DETECTED & BLOCKED

Blocked this time. Adjust your approach:

Out-of-scope systems must not be tested without written approval. The tester should pause and ask the point of contact to confirm ownership and authorization.

โœ– DETECTED & BLOCKED

Blocked this time. Adjust your approach:

Out-of-scope systems must not be tested without written approval. The tester should pause and ask the point of contact to confirm ownership and authorization.

03/100 Engagement Management

A scan causes unexpected authentication failures against a production identity server. The ROE includes an emergency contact and a stop-test condition for availability issues. What should the tester do?

โœ– ROE CHECK FAILED

Every failed attempt is enumeration. Note this:

When a defined stop condition occurs, testing should pause and stakeholders should be notified through the agreed escalation path.

โœ– ROE CHECK FAILED

Every failed attempt is enumeration. Note this:

When a defined stop condition occurs, testing should pause and stakeholders should be notified through the agreed escalation path.

โœ– ROE CHECK FAILED

Every failed attempt is enumeration. Note this:

When a defined stop condition occurs, testing should pause and stakeholders should be notified through the agreed escalation path.

โœ” FOOTHOLD GAINED

You stayed in scope and got the objective. Textbook.

When a defined stop condition occurs, testing should pause and stakeholders should be notified through the agreed escalation path.

04/100 Engagement Management

A client prohibits password spraying, phishing, and denial-of-service testing but wants assurance around identity security. Which approach BEST respects the constraints?

โœ– PAYLOAD FIZZLED

Reset and re-engage with this insight:

When certain techniques are restricted, the tester should use allowed alternatives that still evaluate risk, such as policy review, logs, MFA coverage, and access analysis.

โœ– PAYLOAD FIZZLED

Reset and re-engage with this insight:

When certain techniques are restricted, the tester should use allowed alternatives that still evaluate risk, such as policy review, logs, MFA coverage, and access analysis.

โœ” EXPLOIT VALIDATED

Sharp โ€” you picked the move a professional tester makes.

When certain techniques are restricted, the tester should use allowed alternatives that still evaluate risk, such as policy review, logs, MFA coverage, and access analysis.

โœ– PAYLOAD FIZZLED

Reset and re-engage with this insight:

When certain techniques are restricted, the tester should use allowed alternatives that still evaluate risk, such as policy review, logs, MFA coverage, and access analysis.

05/100 Engagement Management

A tester discovers personal data while reviewing an exposed storage location. The ROE says sensitive data must not be downloaded. What is the MOST appropriate action?

โœ– RETRY THE VECTOR

Vector didn't land โ€” recon the takeaway:

Evidence collection should be minimized and aligned with the ROE. The tester can document filenames, counts, screenshots with redaction, or hashes if allowed.

โœ– RETRY THE VECTOR

Vector didn't land โ€” recon the takeaway:

Evidence collection should be minimized and aligned with the ROE. The tester can document filenames, counts, screenshots with redaction, or hashes if allowed.

โœ” OBJECTIVE CAPTURED

Methodical over flashy. That's what passes this exam.

Evidence collection should be minimized and aligned with the ROE. The tester can document filenames, counts, screenshots with redaction, or hashes if allowed.

โœ– RETRY THE VECTOR

Vector didn't land โ€” recon the takeaway:

Evidence collection should be minimized and aligned with the ROE. The tester can document filenames, counts, screenshots with redaction, or hashes if allowed.

06/100 Engagement Management

A client wants to evaluate how well its SOC detects an external attacker with no internal knowledge. Which test type BEST matches this objective?

โœ– OUT OF SCOPE

Blocked this time. Adjust your approach:

A black-box test simulates an external attacker with limited or no internal details, making it suitable for evaluating detection and response from an outside perspective.

โœ– OUT OF SCOPE

Blocked this time. Adjust your approach:

A black-box test simulates an external attacker with limited or no internal details, making it suitable for evaluating detection and response from an outside perspective.

โœ– OUT OF SCOPE

Blocked this time. Adjust your approach:

A black-box test simulates an external attacker with limited or no internal details, making it suitable for evaluating detection and response from an outside perspective.

โœ” CLEAN PIVOT

The red team would want you on the engagement.

A black-box test simulates an external attacker with limited or no internal details, making it suitable for evaluating detection and response from an outside perspective.

07/100 Engagement Management

Which document most directly defines approved targets, allowed testing windows, excluded techniques, and emergency contacts?

โœ” EVIDENCE LOGGED

That's how an ethical hacker thinks โ€” authorized, precise, documented.

The rules of engagement contain operational boundaries for the assessment, including targets, methods, timing, contacts, and stop conditions.

โœ– DETECTED & BLOCKED

Every failed attempt is enumeration. Note this:

The rules of engagement contain operational boundaries for the assessment, including targets, methods, timing, contacts, and stop conditions.

โœ– DETECTED & BLOCKED

Every failed attempt is enumeration. Note this:

The rules of engagement contain operational boundaries for the assessment, including targets, methods, timing, contacts, and stop conditions.

โœ– DETECTED & BLOCKED

Every failed attempt is enumeration. Note this:

The rules of engagement contain operational boundaries for the assessment, including targets, methods, timing, contacts, and stop conditions.

08/100 Engagement Management

A senior executive asks for daily updates but does not want technical details. What should the tester provide?

โœ” REPORT-READY

Clean tradecraft. The client would sign off on that.

Executive communication should focus on business impact, risk, progress, and decisions needed rather than raw technical details.

โœ– ROE CHECK FAILED

Reset and re-engage with this insight:

Executive communication should focus on business impact, risk, progress, and decisions needed rather than raw technical details.

โœ– ROE CHECK FAILED

Reset and re-engage with this insight:

Executive communication should focus on business impact, risk, progress, and decisions needed rather than raw technical details.

โœ– ROE CHECK FAILED

Reset and re-engage with this insight:

Executive communication should focus on business impact, risk, progress, and decisions needed rather than raw technical details.

09/100 Engagement Management

A healthcare client requires testing evidence without exposing patient data. Which evidence handling approach is BEST?

โœ– PAYLOAD FIZZLED

Vector didn't land โ€” recon the takeaway:

Sensitive evidence should be minimized, redacted, and stored according to approved handling requirements.

โœ” ROE HONORED

You stayed in scope and got the objective. Textbook.

Sensitive evidence should be minimized, redacted, and stored according to approved handling requirements.

โœ– PAYLOAD FIZZLED

Vector didn't land โ€” recon the takeaway:

Sensitive evidence should be minimized, redacted, and stored according to approved handling requirements.

โœ– PAYLOAD FIZZLED

Vector didn't land โ€” recon the takeaway:

Sensitive evidence should be minimized, redacted, and stored according to approved handling requirements.

10/100 Engagement Management

A client has a critical e-commerce freeze during a holiday sale. Which schedule is MOST appropriate for active testing?

โœ– RETRY THE VECTOR

Blocked this time. Adjust your approach:

Active testing should be scheduled in approved windows to reduce business risk and align with operational constraints.

โœ– RETRY THE VECTOR

Blocked this time. Adjust your approach:

Active testing should be scheduled in approved windows to reduce business risk and align with operational constraints.

โœ– RETRY THE VECTOR

Blocked this time. Adjust your approach:

Active testing should be scheduled in approved windows to reduce business risk and align with operational constraints.

โœ” TARGET CLEARED

Sharp โ€” you picked the move a professional tester makes.

Active testing should be scheduled in approved windows to reduce business risk and align with operational constraints.

CHECKPOINT โ€” 10 DOWN, KEEP CLIMBING
11/100 Engagement Management

The client asks how the team will determine whether the test is complete. What should be defined before testing?

โœ– OUT OF SCOPE

Every failed attempt is enumeration. Note this:

Success criteria clarify expected outcomes, coverage, reporting requirements, and evidence standards.

โœ– OUT OF SCOPE

Every failed attempt is enumeration. Note this:

Success criteria clarify expected outcomes, coverage, reporting requirements, and evidence standards.

โœ” SCOPE RESPECTED

Methodical over flashy. That's what passes this exam.

Success criteria clarify expected outcomes, coverage, reporting requirements, and evidence standards.

โœ– OUT OF SCOPE

Every failed attempt is enumeration. Note this:

Success criteria clarify expected outcomes, coverage, reporting requirements, and evidence standards.

12/100 Engagement Management

The client uses a SaaS platform and wants it tested. The SaaS provider terms require advance approval. What should happen before testing?

โœ– DETECTED & BLOCKED

Reset and re-engage with this insight:

Testing third-party services requires authorization from all relevant parties and must follow provider policies.

โœ– DETECTED & BLOCKED

Reset and re-engage with this insight:

Testing third-party services requires authorization from all relevant parties and must follow provider policies.

โœ” FINDING CONFIRMED

The red team would want you on the engagement.

Testing third-party services requires authorization from all relevant parties and must follow provider policies.

โœ– DETECTED & BLOCKED

Reset and re-engage with this insight:

Testing third-party services requires authorization from all relevant parties and must follow provider policies.

13/100 Engagement Management

After report delivery, the client asks how long evidence will be retained. What should govern retention?

โœ” FOOTHOLD GAINED

That's how an ethical hacker thinks โ€” authorized, precise, documented.

Evidence retention should follow contractual and legal requirements defined in the engagement.

โœ– ROE CHECK FAILED

Vector didn't land โ€” recon the takeaway:

Evidence retention should follow contractual and legal requirements defined in the engagement.

โœ– ROE CHECK FAILED

Vector didn't land โ€” recon the takeaway:

Evidence retention should follow contractual and legal requirements defined in the engagement.

โœ– ROE CHECK FAILED

Vector didn't land โ€” recon the takeaway:

Evidence retention should follow contractual and legal requirements defined in the engagement.

14/100 Engagement Management

A manufacturer identifies an internet-facing VPN, supplier portal, and internal file server as critical assets. Which planning action is BEST?

โœ– PAYLOAD FIZZLED

Blocked this time. Adjust your approach:

Risk-based scoping prioritizes assets that combine business criticality and exposure.

โœ– PAYLOAD FIZZLED

Blocked this time. Adjust your approach:

Risk-based scoping prioritizes assets that combine business criticality and exposure.

โœ” EXPLOIT VALIDATED

Clean tradecraft. The client would sign off on that.

Risk-based scoping prioritizes assets that combine business criticality and exposure.

โœ– PAYLOAD FIZZLED

Blocked this time. Adjust your approach:

Risk-based scoping prioritizes assets that combine business criticality and exposure.

15/100 Engagement Management

A tester previously configured the client firewall being assessed and may be biased. What is the BEST action?

โœ– RETRY THE VECTOR

Every failed attempt is enumeration. Note this:

Potential conflicts should be disclosed so the engagement can preserve independence and credibility.

โœ– RETRY THE VECTOR

Every failed attempt is enumeration. Note this:

Potential conflicts should be disclosed so the engagement can preserve independence and credibility.

โœ” OBJECTIVE CAPTURED

You stayed in scope and got the objective. Textbook.

Potential conflicts should be disclosed so the engagement can preserve independence and credibility.

โœ– RETRY THE VECTOR

Every failed attempt is enumeration. Note this:

Potential conflicts should be disclosed so the engagement can preserve independence and credibility.

16/100 Engagement Management

A client requests proof that a denial-of-service vulnerability can take down production. What is the BEST response?

โœ” CLEAN PIVOT

Sharp โ€” you picked the move a professional tester makes.

High-impact tests should use safe validation methods, approved windows, or nonproduction environments.

โœ– OUT OF SCOPE

Reset and re-engage with this insight:

High-impact tests should use safe validation methods, approved windows, or nonproduction environments.

โœ– OUT OF SCOPE

Reset and re-engage with this insight:

High-impact tests should use safe validation methods, approved windows, or nonproduction environments.

โœ– OUT OF SCOPE

Reset and re-engage with this insight:

High-impact tests should use safe validation methods, approved windows, or nonproduction environments.

17/100 Reconnaissance and Enumeration

A tester needs to identify subdomains without generating traffic to the client network. Which technique is MOST appropriate?

โœ” EVIDENCE LOGGED

Methodical over flashy. That's what passes this exam.

Certificate transparency logs are passive sources that can reveal public hostnames without touching the target infrastructure.

โœ– DETECTED & BLOCKED

Vector didn't land โ€” recon the takeaway:

Certificate transparency logs are passive sources that can reveal public hostnames without touching the target infrastructure.

โœ– DETECTED & BLOCKED

Vector didn't land โ€” recon the takeaway:

Certificate transparency logs are passive sources that can reveal public hostnames without touching the target infrastructure.

โœ– DETECTED & BLOCKED

Vector didn't land โ€” recon the takeaway:

Certificate transparency logs are passive sources that can reveal public hostnames without touching the target infrastructure.

18/100 Reconnaissance and Enumeration

A company recently acquired another firm. The tester wants to identify forgotten internet-facing assets from the acquisition. Which source is BEST to review first?

โœ– ROE CHECK FAILED

Blocked this time. Adjust your approach:

Historical DNS and certificate data often reveal old domains, subdomains, and hostnames associated with acquisitions.

โœ” REPORT-READY

The red team would want you on the engagement.

Historical DNS and certificate data often reveal old domains, subdomains, and hostnames associated with acquisitions.

โœ– ROE CHECK FAILED

Blocked this time. Adjust your approach:

Historical DNS and certificate data often reveal old domains, subdomains, and hostnames associated with acquisitions.

โœ– ROE CHECK FAILED

Blocked this time. Adjust your approach:

Historical DNS and certificate data often reveal old domains, subdomains, and hostnames associated with acquisitions.

19/100 Reconnaissance and Enumeration

A tester finds TXT records referencing SPF and DKIM. What security-relevant information can these records provide?

โœ– PAYLOAD FIZZLED

Every failed attempt is enumeration. Note this:

SPF, DKIM, and DMARC-related DNS records reveal approved mail senders and email security posture.

โœ– PAYLOAD FIZZLED

Every failed attempt is enumeration. Note this:

SPF, DKIM, and DMARC-related DNS records reveal approved mail senders and email security posture.

โœ” ROE HONORED

That's how an ethical hacker thinks โ€” authorized, precise, documented.

SPF, DKIM, and DMARC-related DNS records reveal approved mail senders and email security posture.

โœ– PAYLOAD FIZZLED

Every failed attempt is enumeration. Note this:

SPF, DKIM, and DMARC-related DNS records reveal approved mail senders and email security posture.

20/100 Reconnaissance and Enumeration

The ROE allows port scanning but requires low impact. Which scan configuration is BEST?

โœ” TARGET CLEARED

Clean tradecraft. The client would sign off on that.

Rate limiting and approved windows reduce operational impact and stay within authorization.

โœ– RETRY THE VECTOR

Reset and re-engage with this insight:

Rate limiting and approved windows reduce operational impact and stay within authorization.

โœ– RETRY THE VECTOR

Reset and re-engage with this insight:

Rate limiting and approved windows reduce operational impact and stay within authorization.

โœ– RETRY THE VECTOR

Reset and re-engage with this insight:

Rate limiting and approved windows reduce operational impact and stay within authorization.

CHECKPOINT โ€” 20 DOWN, KEEP CLIMBING
21/100 Reconnaissance and Enumeration

A host exposes TCP 443. The tester needs to determine the application and TLS configuration. Which approach is BEST?

โœ– OUT OF SCOPE

Vector didn't land โ€” recon the takeaway:

Service identification and TLS review reveal versions, certificates, protocols, and cipher risks without unnecessary disruption.

โœ– OUT OF SCOPE

Vector didn't land โ€” recon the takeaway:

Service identification and TLS review reveal versions, certificates, protocols, and cipher risks without unnecessary disruption.

โœ– OUT OF SCOPE

Vector didn't land โ€” recon the takeaway:

Service identification and TLS review reveal versions, certificates, protocols, and cipher risks without unnecessary disruption.

โœ” SCOPE RESPECTED

You stayed in scope and got the objective. Textbook.

Service identification and TLS review reveal versions, certificates, protocols, and cipher risks without unnecessary disruption.

22/100 Reconnaissance and Enumeration

A scanner reports an outdated SSH version. What should the tester do before rating the finding high?

โœ– DETECTED & BLOCKED

Blocked this time. Adjust your approach:

Scanner results can be false positives. Validation checks banner accuracy, backported patches, exposure, and business context.

โœ” FINDING CONFIRMED

Sharp โ€” you picked the move a professional tester makes.

Scanner results can be false positives. Validation checks banner accuracy, backported patches, exposure, and business context.

โœ– DETECTED & BLOCKED

Blocked this time. Adjust your approach:

Scanner results can be false positives. Validation checks banner accuracy, backported patches, exposure, and business context.

โœ– DETECTED & BLOCKED

Blocked this time. Adjust your approach:

Scanner results can be false positives. Validation checks banner accuracy, backported patches, exposure, and business context.

23/100 Reconnaissance and Enumeration

A web server responds normally but has no linked admin page. Which method is MOST appropriate to look for hidden directories within scope?

โœ– ROE CHECK FAILED

Every failed attempt is enumeration. Note this:

Controlled content discovery can identify unlinked resources while managing traffic impact.

โœ– ROE CHECK FAILED

Every failed attempt is enumeration. Note this:

Controlled content discovery can identify unlinked resources while managing traffic impact.

โœ” FOOTHOLD GAINED

Methodical over flashy. That's what passes this exam.

Controlled content discovery can identify unlinked resources while managing traffic impact.

โœ– ROE CHECK FAILED

Every failed attempt is enumeration. Note this:

Controlled content discovery can identify unlinked resources while managing traffic impact.

24/100 Reconnaissance and Enumeration

A tester receives an OpenAPI specification for a gray-box assessment. What should the tester do with it?

โœ– PAYLOAD FIZZLED

Reset and re-engage with this insight:

API specifications help testers build an endpoint inventory and design authorization, input validation, and business logic tests.

โœ– PAYLOAD FIZZLED

Reset and re-engage with this insight:

API specifications help testers build an endpoint inventory and design authorization, input validation, and business logic tests.

โœ” EXPLOIT VALIDATED

The red team would want you on the engagement.

API specifications help testers build an endpoint inventory and design authorization, input validation, and business logic tests.

โœ– PAYLOAD FIZZLED

Reset and re-engage with this insight:

API specifications help testers build an endpoint inventory and design authorization, input validation, and business logic tests.

25/100 Reconnaissance and Enumeration

A tester is authorized to assess corporate wireless from the parking lot. What information is MOST useful during initial enumeration?

โœ– RETRY THE VECTOR

Vector didn't land โ€” recon the takeaway:

Wireless enumeration commonly identifies network names, access point identifiers, channels, encryption, and coverage.

โœ– RETRY THE VECTOR

Vector didn't land โ€” recon the takeaway:

Wireless enumeration commonly identifies network names, access point identifiers, channels, encryption, and coverage.

โœ– RETRY THE VECTOR

Vector didn't land โ€” recon the takeaway:

Wireless enumeration commonly identifies network names, access point identifiers, channels, encryption, and coverage.

โœ” OBJECTIVE CAPTURED

That's how an ethical hacker thinks โ€” authorized, precise, documented.

Wireless enumeration commonly identifies network names, access point identifiers, channels, encryption, and coverage.

26/100 Reconnaissance and Enumeration

A company uses multiple cloud accounts. Which discovery method BEST identifies public cloud storage exposure?

โœ– OUT OF SCOPE

Blocked this time. Adjust your approach:

Cloud storage exposure is best identified through cloud inventory, configuration review, and public access checks.

โœ– OUT OF SCOPE

Blocked this time. Adjust your approach:

Cloud storage exposure is best identified through cloud inventory, configuration review, and public access checks.

โœ” CLEAN PIVOT

Clean tradecraft. The client would sign off on that.

Cloud storage exposure is best identified through cloud inventory, configuration review, and public access checks.

โœ– OUT OF SCOPE

Blocked this time. Adjust your approach:

Cloud storage exposure is best identified through cloud inventory, configuration review, and public access checks.

27/100 Reconnaissance and Enumeration

A Kubernetes API endpoint is exposed. What should the tester determine first?

โœ– DETECTED & BLOCKED

Every failed attempt is enumeration. Note this:

The tester must confirm scope and authentication posture before further enumeration.

โœ– DETECTED & BLOCKED

Every failed attempt is enumeration. Note this:

The tester must confirm scope and authentication posture before further enumeration.

โœ– DETECTED & BLOCKED

Every failed attempt is enumeration. Note this:

The tester must confirm scope and authentication posture before further enumeration.

โœ” EVIDENCE LOGGED

You stayed in scope and got the objective. Textbook.

The tester must confirm scope and authentication posture before further enumeration.

28/100 Reconnaissance and Enumeration

A tester sees employees posting conference photos with badges and laptop stickers. What is the primary security value of this information?

โœ– ROE CHECK FAILED

Reset and re-engage with this insight:

Social media OSINT can reveal technology stacks, facility details, and employee patterns useful for risk analysis.

โœ– ROE CHECK FAILED

Reset and re-engage with this insight:

Social media OSINT can reveal technology stacks, facility details, and employee patterns useful for risk analysis.

โœ– ROE CHECK FAILED

Reset and re-engage with this insight:

Social media OSINT can reveal technology stacks, facility details, and employee patterns useful for risk analysis.

โœ” REPORT-READY

Sharp โ€” you picked the move a professional tester makes.

Social media OSINT can reveal technology stacks, facility details, and employee patterns useful for risk analysis.

29/100 Reconnaissance and Enumeration

The tester wants to evaluate phishing resilience without sending emails yet. Which passive step is BEST?

โœ– PAYLOAD FIZZLED

Vector didn't land โ€” recon the takeaway:

Email DNS records provide insight into anti-spoofing controls and mail providers without interacting with users.

โœ– PAYLOAD FIZZLED

Vector didn't land โ€” recon the takeaway:

Email DNS records provide insight into anti-spoofing controls and mail providers without interacting with users.

โœ” ROE HONORED

Methodical over flashy. That's what passes this exam.

Email DNS records provide insight into anti-spoofing controls and mail providers without interacting with users.

โœ– PAYLOAD FIZZLED

Vector didn't land โ€” recon the takeaway:

Email DNS records provide insight into anti-spoofing controls and mail providers without interacting with users.

30/100 Reconnaissance and Enumeration

A client provides read-only credentials for a server assessment. What type of scan should be used to gain deeper, accurate results?

โœ” TARGET CLEARED

The red team would want you on the engagement.

Authenticated scans can inspect installed software, configuration, and missing patches more accurately than unauthenticated scans.

โœ– RETRY THE VECTOR

Blocked this time. Adjust your approach:

Authenticated scans can inspect installed software, configuration, and missing patches more accurately than unauthenticated scans.

โœ– RETRY THE VECTOR

Blocked this time. Adjust your approach:

Authenticated scans can inspect installed software, configuration, and missing patches more accurately than unauthenticated scans.

โœ– RETRY THE VECTOR

Blocked this time. Adjust your approach:

Authenticated scans can inspect installed software, configuration, and missing patches more accurately than unauthenticated scans.

CHECKPOINT โ€” 30 DOWN, KEEP CLIMBING
31/100 Reconnaissance and Enumeration

A vulnerability scanner flags SMB signing as disabled, but manual checks show it is required. What should the report say?

โœ– OUT OF SCOPE

Every failed attempt is enumeration. Note this:

Validated evidence should drive findings. False positives should not be reported as confirmed vulnerabilities.

โœ– OUT OF SCOPE

Every failed attempt is enumeration. Note this:

Validated evidence should drive findings. False positives should not be reported as confirmed vulnerabilities.

โœ– OUT OF SCOPE

Every failed attempt is enumeration. Note this:

Validated evidence should drive findings. False positives should not be reported as confirmed vulnerabilities.

โœ” SCOPE RESPECTED

That's how an ethical hacker thinks โ€” authorized, precise, documented.

Validated evidence should drive findings. False positives should not be reported as confirmed vulnerabilities.

32/100 Reconnaissance and Enumeration

Recon identifies 500 hosts. Which target should generally be prioritized first?

โœ– DETECTED & BLOCKED

Reset and re-engage with this insight:

Exposure, vulnerability likelihood, and business impact should guide prioritization.

โœ” FINDING CONFIRMED

Clean tradecraft. The client would sign off on that.

Exposure, vulnerability likelihood, and business impact should guide prioritization.

โœ– DETECTED & BLOCKED

Reset and re-engage with this insight:

Exposure, vulnerability likelihood, and business impact should guide prioritization.

โœ– DETECTED & BLOCKED

Reset and re-engage with this insight:

Exposure, vulnerability likelihood, and business impact should guide prioritization.

33/100 Reconnaissance and Enumeration

Which finding from a network scan is MOST likely to require immediate investigation?

โœ– ROE CHECK FAILED

Vector didn't land โ€” recon the takeaway:

Internet-exposed remote administration services create a significant attack surface and should be reviewed promptly.

โœ– ROE CHECK FAILED

Vector didn't land โ€” recon the takeaway:

Internet-exposed remote administration services create a significant attack surface and should be reviewed promptly.

โœ” FOOTHOLD GAINED

You stayed in scope and got the objective. Textbook.

Internet-exposed remote administration services create a significant attack surface and should be reviewed promptly.

โœ– ROE CHECK FAILED

Vector didn't land โ€” recon the takeaway:

Internet-exposed remote administration services create a significant attack surface and should be reviewed promptly.

34/100 Reconnaissance and Enumeration

In an authorized internal test, the team needs to understand privilege relationships without changing objects. Which approach is BEST?

โœ” EXPLOIT VALIDATED

Sharp โ€” you picked the move a professional tester makes.

Read-only enumeration can reveal privileged groups, nested memberships, and risky relationships safely.

โœ– PAYLOAD FIZZLED

Blocked this time. Adjust your approach:

Read-only enumeration can reveal privileged groups, nested memberships, and risky relationships safely.

โœ– PAYLOAD FIZZLED

Blocked this time. Adjust your approach:

Read-only enumeration can reveal privileged groups, nested memberships, and risky relationships safely.

โœ– PAYLOAD FIZZLED

Blocked this time. Adjust your approach:

Read-only enumeration can reveal privileged groups, nested memberships, and risky relationships safely.

35/100 Reconnaissance and Enumeration

A response header reveals an outdated framework. What is the BEST follow-up?

โœ– RETRY THE VECTOR

Every failed attempt is enumeration. Note this:

Headers can be misleading. The tester should validate version, exposure, exploitability, and compensating controls.

โœ– RETRY THE VECTOR

Every failed attempt is enumeration. Note this:

Headers can be misleading. The tester should validate version, exposure, exploitability, and compensating controls.

โœ– RETRY THE VECTOR

Every failed attempt is enumeration. Note this:

Headers can be misleading. The tester should validate version, exposure, exploitability, and compensating controls.

โœ” OBJECTIVE CAPTURED

Methodical over flashy. That's what passes this exam.

Headers can be misleading. The tester should validate version, exposure, exploitability, and compensating controls.

36/100 Reconnaissance and Enumeration

A breach database shows employee emails and old password hashes. What should the tester recommend first within an authorized assessment?

โœ– OUT OF SCOPE

Reset and re-engage with this insight:

Credential exposure should be handled carefully with client coordination, data minimization, and approved validation.

โœ– OUT OF SCOPE

Reset and re-engage with this insight:

Credential exposure should be handled carefully with client coordination, data minimization, and approved validation.

โœ” CLEAN PIVOT

The red team would want you on the engagement.

Credential exposure should be handled carefully with client coordination, data minimization, and approved validation.

โœ– OUT OF SCOPE

Reset and re-engage with this insight:

Credential exposure should be handled carefully with client coordination, data minimization, and approved validation.

37/100 Reconnaissance and Enumeration

A fragile legacy system is in scope but has caused outages during scans before. What is the BEST strategy?

โœ” EVIDENCE LOGGED

That's how an ethical hacker thinks โ€” authorized, precise, documented.

Fragile systems require careful planning, monitoring, and conservative testing to reduce availability risk.

โœ– DETECTED & BLOCKED

Vector didn't land โ€” recon the takeaway:

Fragile systems require careful planning, monitoring, and conservative testing to reduce availability risk.

โœ– DETECTED & BLOCKED

Vector didn't land โ€” recon the takeaway:

Fragile systems require careful planning, monitoring, and conservative testing to reduce availability risk.

โœ– DETECTED & BLOCKED

Vector didn't land โ€” recon the takeaway:

Fragile systems require careful planning, monitoring, and conservative testing to reduce availability risk.

38/100 Reconnaissance and Enumeration

Why should a tester document recon sources and timestamps?

โœ– ROE CHECK FAILED

Blocked this time. Adjust your approach:

Good documentation helps stakeholders verify findings, reproduce observations, and distinguish current from historical data.

โœ– ROE CHECK FAILED

Blocked this time. Adjust your approach:

Good documentation helps stakeholders verify findings, reproduce observations, and distinguish current from historical data.

โœ” REPORT-READY

Clean tradecraft. The client would sign off on that.

Good documentation helps stakeholders verify findings, reproduce observations, and distinguish current from historical data.

โœ– ROE CHECK FAILED

Blocked this time. Adjust your approach:

Good documentation helps stakeholders verify findings, reproduce observations, and distinguish current from historical data.

39/100 Attacks and Exploits

A web app locks accounts after five failures but allows unlimited password reset attempts without rate limiting. What vulnerability class is MOST relevant?

โœ– PAYLOAD FIZZLED

Every failed attempt is enumeration. Note this:

Authentication workflows must protect all paths, including password reset, from abuse such as brute force and enumeration.

โœ– PAYLOAD FIZZLED

Every failed attempt is enumeration. Note this:

Authentication workflows must protect all paths, including password reset, from abuse such as brute force and enumeration.

โœ” ROE HONORED

You stayed in scope and got the objective. Textbook.

Authentication workflows must protect all paths, including password reset, from abuse such as brute force and enumeration.

โœ– PAYLOAD FIZZLED

Every failed attempt is enumeration. Note this:

Authentication workflows must protect all paths, including password reset, from abuse such as brute force and enumeration.

40/100 Attacks and Exploits

A user can change the account ID in a request and view another customer invoice. What is the BEST classification?

โœ– RETRY THE VECTOR

Reset and re-engage with this insight:

Changing an object identifier to access another user data indicates broken authorization/IDOR.

โœ– RETRY THE VECTOR

Reset and re-engage with this insight:

Changing an object identifier to access another user data indicates broken authorization/IDOR.

โœ” TARGET CLEARED

Sharp โ€” you picked the move a professional tester makes.

Changing an object identifier to access another user data indicates broken authorization/IDOR.

โœ– RETRY THE VECTOR

Reset and re-engage with this insight:

Changing an object identifier to access another user data indicates broken authorization/IDOR.

CHECKPOINT โ€” 40 DOWN, KEEP CLIMBING
41/100 Attacks and Exploits

A search field returns database error messages when special characters are submitted. What should the tester do next?

โœ” SCOPE RESPECTED

Methodical over flashy. That's what passes this exam.

Detailed errors can indicate injection risk. The tester should validate safely under the ROE and document impact and remediation.

โœ– OUT OF SCOPE

Vector didn't land โ€” recon the takeaway:

Detailed errors can indicate injection risk. The tester should validate safely under the ROE and document impact and remediation.

โœ– OUT OF SCOPE

Vector didn't land โ€” recon the takeaway:

Detailed errors can indicate injection risk. The tester should validate safely under the ROE and document impact and remediation.

โœ– OUT OF SCOPE

Vector didn't land โ€” recon the takeaway:

Detailed errors can indicate injection risk. The tester should validate safely under the ROE and document impact and remediation.

42/100 Attacks and Exploits

A comment field stores user input that executes script when another user views the page. What type of issue is this?

โœ– DETECTED & BLOCKED

Blocked this time. Adjust your approach:

Stored XSS occurs when malicious script is saved by the application and later executed in another user browser.

โœ” FINDING CONFIRMED

The red team would want you on the engagement.

Stored XSS occurs when malicious script is saved by the application and later executed in another user browser.

โœ– DETECTED & BLOCKED

Blocked this time. Adjust your approach:

Stored XSS occurs when malicious script is saved by the application and later executed in another user browser.

โœ– DETECTED & BLOCKED

Blocked this time. Adjust your approach:

Stored XSS occurs when malicious script is saved by the application and later executed in another user browser.

43/100 Attacks and Exploits

A portal allows users to upload profile images. Which control BEST reduces risk of malicious file upload?

โœ” FOOTHOLD GAINED

That's how an ethical hacker thinks โ€” authorized, precise, documented.

Secure upload handling uses layered controls, including content validation, scanning, storage isolation, and execution prevention.

โœ– ROE CHECK FAILED

Every failed attempt is enumeration. Note this:

Secure upload handling uses layered controls, including content validation, scanning, storage isolation, and execution prevention.

โœ– ROE CHECK FAILED

Every failed attempt is enumeration. Note this:

Secure upload handling uses layered controls, including content validation, scanning, storage isolation, and execution prevention.

โœ– ROE CHECK FAILED

Every failed attempt is enumeration. Note this:

Secure upload handling uses layered controls, including content validation, scanning, storage isolation, and execution prevention.

44/100 Attacks and Exploits

A cloud role grants wildcard administrative permissions to a workload that only reads one storage bucket. Which principle is violated?

โœ– PAYLOAD FIZZLED

Reset and re-engage with this insight:

The role grants far more access than required. Least privilege limits permissions to the minimum necessary for the workload.

โœ– PAYLOAD FIZZLED

Reset and re-engage with this insight:

The role grants far more access than required. Least privilege limits permissions to the minimum necessary for the workload.

โœ– PAYLOAD FIZZLED

Reset and re-engage with this insight:

The role grants far more access than required. Least privilege limits permissions to the minimum necessary for the workload.

โœ” EXPLOIT VALIDATED

Clean tradecraft. The client would sign off on that.

The role grants far more access than required. Least privilege limits permissions to the minimum necessary for the workload.

45/100 Attacks and Exploits

An API allows unlimited requests to a one-time passcode verification endpoint. What is the BEST remediation recommendation?

โœ” OBJECTIVE CAPTURED

You stayed in scope and got the objective. Textbook.

Rate limiting and abuse monitoring reduce brute-force and automation risk.

โœ– RETRY THE VECTOR

Vector didn't land โ€” recon the takeaway:

Rate limiting and abuse monitoring reduce brute-force and automation risk.

โœ– RETRY THE VECTOR

Vector didn't land โ€” recon the takeaway:

Rate limiting and abuse monitoring reduce brute-force and automation risk.

โœ– RETRY THE VECTOR

Vector didn't land โ€” recon the takeaway:

Rate limiting and abuse monitoring reduce brute-force and automation risk.

46/100 Attacks and Exploits

A company guest Wi-Fi uses an old shared password that has not changed in years. What is the MAIN risk?

โœ– OUT OF SCOPE

Blocked this time. Adjust your approach:

Long-lived shared keys are difficult to control and may remain known to unauthorized users.

โœ– OUT OF SCOPE

Blocked this time. Adjust your approach:

Long-lived shared keys are difficult to control and may remain known to unauthorized users.

โœ” CLEAN PIVOT

Sharp โ€” you picked the move a professional tester makes.

Long-lived shared keys are difficult to control and may remain known to unauthorized users.

โœ– OUT OF SCOPE

Blocked this time. Adjust your approach:

Long-lived shared keys are difficult to control and may remain known to unauthorized users.

47/100 Attacks and Exploits

An authorized vishing test finds employees disclose internal ticket numbers and manager names. What is the BEST recommendation?

โœ– DETECTED & BLOCKED

Every failed attempt is enumeration. Note this:

Social engineering findings are best addressed with clear verification procedures, training, and reporting channels.

โœ– DETECTED & BLOCKED

Every failed attempt is enumeration. Note this:

Social engineering findings are best addressed with clear verification procedures, training, and reporting channels.

โœ– DETECTED & BLOCKED

Every failed attempt is enumeration. Note this:

Social engineering findings are best addressed with clear verification procedures, training, and reporting channels.

โœ” EVIDENCE LOGGED

Methodical over flashy. That's what passes this exam.

Social engineering findings are best addressed with clear verification procedures, training, and reporting channels.

48/100 Attacks and Exploits

A compromised workstation can connect directly to database administration ports. What control would BEST reduce blast radius?

โœ– ROE CHECK FAILED

Reset and re-engage with this insight:

Segmentation restricts lateral movement and limits access to sensitive services from user networks.

โœ– ROE CHECK FAILED

Reset and re-engage with this insight:

Segmentation restricts lateral movement and limits access to sensitive services from user networks.

โœ– ROE CHECK FAILED

Reset and re-engage with this insight:

Segmentation restricts lateral movement and limits access to sensitive services from user networks.

โœ” REPORT-READY

The red team would want you on the engagement.

Segmentation restricts lateral movement and limits access to sensitive services from user networks.

49/100 Attacks and Exploits

A password spraying test is authorized but must avoid account lockouts. Which control should be reviewed as a safer alternative validation?

โœ– PAYLOAD FIZZLED

Vector didn't land โ€” recon the takeaway:

Reviewing identity controls and logs can evaluate resilience while reducing operational risk.

โœ– PAYLOAD FIZZLED

Vector didn't land โ€” recon the takeaway:

Reviewing identity controls and logs can evaluate resilience while reducing operational risk.

โœ– PAYLOAD FIZZLED

Vector didn't land โ€” recon the takeaway:

Reviewing identity controls and logs can evaluate resilience while reducing operational risk.

โœ” ROE HONORED

That's how an ethical hacker thinks โ€” authorized, precise, documented.

Reviewing identity controls and logs can evaluate resilience while reducing operational risk.

50/100 Attacks and Exploits

A session token remains valid after logout and password change. What is the BEST finding title?

โœ” TARGET CLEARED

Clean tradecraft. The client would sign off on that.

Sessions should be invalidated on logout and significant account events such as password changes.

โœ– RETRY THE VECTOR

Blocked this time. Adjust your approach:

Sessions should be invalidated on logout and significant account events such as password changes.

โœ– RETRY THE VECTOR

Blocked this time. Adjust your approach:

Sessions should be invalidated on logout and significant account events such as password changes.

โœ– RETRY THE VECTOR

Blocked this time. Adjust your approach:

Sessions should be invalidated on logout and significant account events such as password changes.

CHECKPOINT โ€” 50 DOWN, KEEP CLIMBING
51/100 Attacks and Exploits

A public site supports deprecated TLS protocols. What is the BEST remediation?

โœ– OUT OF SCOPE

Every failed attempt is enumeration. Note this:

Modern TLS configuration should remove deprecated protocols and weak cipher suites while considering business compatibility.

โœ– OUT OF SCOPE

Every failed attempt is enumeration. Note this:

Modern TLS configuration should remove deprecated protocols and weak cipher suites while considering business compatibility.

โœ” SCOPE RESPECTED

You stayed in scope and got the objective. Textbook.

Modern TLS configuration should remove deprecated protocols and weak cipher suites while considering business compatibility.

โœ– OUT OF SCOPE

Every failed attempt is enumeration. Note this:

Modern TLS configuration should remove deprecated protocols and weak cipher suites while considering business compatibility.

52/100 Attacks and Exploits

A maintenance form passes user input to a backend system command. The application returns OS-level error output. What should the tester suspect?

โœ– DETECTED & BLOCKED

Reset and re-engage with this insight:

OS-level errors from user-controlled input can indicate command injection risk that requires safe validation.

โœ– DETECTED & BLOCKED

Reset and re-engage with this insight:

OS-level errors from user-controlled input can indicate command injection risk that requires safe validation.

โœ” FINDING CONFIRMED

Sharp โ€” you picked the move a professional tester makes.

OS-level errors from user-controlled input can indicate command injection risk that requires safe validation.

โœ– DETECTED & BLOCKED

Reset and re-engage with this insight:

OS-level errors from user-controlled input can indicate command injection risk that requires safe validation.

53/100 Attacks and Exploits

A web application fetches images from user-supplied URLs. Which additional risk should be assessed?

โœ” FOOTHOLD GAINED

Methodical over flashy. That's what passes this exam.

URL-fetching features can be abused to make server-side requests to internal systems if not restricted.

โœ– ROE CHECK FAILED

Vector didn't land โ€” recon the takeaway:

URL-fetching features can be abused to make server-side requests to internal systems if not restricted.

โœ– ROE CHECK FAILED

Vector didn't land โ€” recon the takeaway:

URL-fetching features can be abused to make server-side requests to internal systems if not restricted.

โœ– ROE CHECK FAILED

Vector didn't land โ€” recon the takeaway:

URL-fetching features can be abused to make server-side requests to internal systems if not restricted.

54/100 Attacks and Exploits

An application accepts serialized objects from clients and throws class loading errors. What is the BEST security concern?

โœ– PAYLOAD FIZZLED

Blocked this time. Adjust your approach:

Client-supplied serialized objects can create insecure deserialization risks if not validated and safely handled.

โœ– PAYLOAD FIZZLED

Blocked this time. Adjust your approach:

Client-supplied serialized objects can create insecure deserialization risks if not validated and safely handled.

โœ– PAYLOAD FIZZLED

Blocked this time. Adjust your approach:

Client-supplied serialized objects can create insecure deserialization risks if not validated and safely handled.

โœ” EXPLOIT VALIDATED

The red team would want you on the engagement.

Client-supplied serialized objects can create insecure deserialization risks if not validated and safely handled.

55/100 Attacks and Exploits

A container image includes old packages, secrets in environment variables, and runs as root. Which recommendation is BEST?

โœ– RETRY THE VECTOR

Every failed attempt is enumeration. Note this:

Container hardening includes patching, secret management, minimal images, and non-root execution.

โœ– RETRY THE VECTOR

Every failed attempt is enumeration. Note this:

Container hardening includes patching, secret management, minimal images, and non-root execution.

โœ– RETRY THE VECTOR

Every failed attempt is enumeration. Note this:

Container hardening includes patching, secret management, minimal images, and non-root execution.

โœ” OBJECTIVE CAPTURED

That's how an ethical hacker thinks โ€” authorized, precise, documented.

Container hardening includes patching, secret management, minimal images, and non-root execution.

56/100 Attacks and Exploits

During an internal test, a standard user can install a service that runs with elevated privileges due to misconfigured permissions. What is the impact?

โœ– OUT OF SCOPE

Reset and re-engage with this insight:

Misconfigured service permissions can allow a lower-privileged user to gain higher local privileges.

โœ– OUT OF SCOPE

Reset and re-engage with this insight:

Misconfigured service permissions can allow a lower-privileged user to gain higher local privileges.

โœ” CLEAN PIVOT

Clean tradecraft. The client would sign off on that.

Misconfigured service permissions can allow a lower-privileged user to gain higher local privileges.

โœ– OUT OF SCOPE

Reset and re-engage with this insight:

Misconfigured service permissions can allow a lower-privileged user to gain higher local privileges.

57/100 Attacks and Exploits

A critical vulnerability is reported on a server, but the vendor backported the fix without changing the displayed version. What should the tester do?

โœ– DETECTED & BLOCKED

Vector didn't land โ€” recon the takeaway:

Backported patches can make banner versions misleading. Verification should use reliable package or vendor data.

โœ– DETECTED & BLOCKED

Vector didn't land โ€” recon the takeaway:

Backported patches can make banner versions misleading. Verification should use reliable package or vendor data.

โœ– DETECTED & BLOCKED

Vector didn't land โ€” recon the takeaway:

Backported patches can make banner versions misleading. Verification should use reliable package or vendor data.

โœ” EVIDENCE LOGGED

You stayed in scope and got the objective. Textbook.

Backported patches can make banner versions misleading. Verification should use reliable package or vendor data.

58/100 Attacks and Exploits

A developer repository contains hard-coded API keys. What is the BEST immediate remediation sequence?

โœ– ROE CHECK FAILED

Blocked this time. Adjust your approach:

Exposed secrets should be considered compromised; rotation, cleanup, and preventive controls are required.

โœ” REPORT-READY

Sharp โ€” you picked the move a professional tester makes.

Exposed secrets should be considered compromised; rotation, cleanup, and preventive controls are required.

โœ– ROE CHECK FAILED

Blocked this time. Adjust your approach:

Exposed secrets should be considered compromised; rotation, cleanup, and preventive controls are required.

โœ– ROE CHECK FAILED

Blocked this time. Adjust your approach:

Exposed secrets should be considered compromised; rotation, cleanup, and preventive controls are required.

59/100 Attacks and Exploits

A web application database account has schema owner permissions but only needs read/write to specific tables. What is the finding?

โœ” ROE HONORED

Methodical over flashy. That's what passes this exam.

Overprivileged database accounts increase impact if the application is compromised.

โœ– PAYLOAD FIZZLED

Every failed attempt is enumeration. Note this:

Overprivileged database accounts increase impact if the application is compromised.

โœ– PAYLOAD FIZZLED

Every failed attempt is enumeration. Note this:

Overprivileged database accounts increase impact if the application is compromised.

โœ– PAYLOAD FIZZLED

Every failed attempt is enumeration. Note this:

Overprivileged database accounts increase impact if the application is compromised.

60/100 Attacks and Exploits

A download endpoint accepts a filename parameter and may access files outside the intended directory. What control BEST mitigates the issue?

โœ– RETRY THE VECTOR

Reset and re-engage with this insight:

Path traversal is mitigated by safe path handling, canonicalization, allowlists, and access controls.

โœ” TARGET CLEARED

The red team would want you on the engagement.

Path traversal is mitigated by safe path handling, canonicalization, allowlists, and access controls.

โœ– RETRY THE VECTOR

Reset and re-engage with this insight:

Path traversal is mitigated by safe path handling, canonicalization, allowlists, and access controls.

โœ– RETRY THE VECTOR

Reset and re-engage with this insight:

Path traversal is mitigated by safe path handling, canonicalization, allowlists, and access controls.

CHECKPOINT โ€” 60 DOWN, KEEP CLIMBING
61/100 Attacks and Exploits

A shopping cart quantity can be changed to a negative number, reducing the total price. What type of issue is this?

โœ” SCOPE RESPECTED

That's how an ethical hacker thinks โ€” authorized, precise, documented.

Business logic flaws occur when application workflows allow unintended actions not caught by technical controls.

โœ– OUT OF SCOPE

Vector didn't land โ€” recon the takeaway:

Business logic flaws occur when application workflows allow unintended actions not caught by technical controls.

โœ– OUT OF SCOPE

Vector didn't land โ€” recon the takeaway:

Business logic flaws occur when application workflows allow unintended actions not caught by technical controls.

โœ– OUT OF SCOPE

Vector didn't land โ€” recon the takeaway:

Business logic flaws occur when application workflows allow unintended actions not caught by technical controls.

62/100 Attacks and Exploits

A tester finds that users with legacy mail protocols can access mail without MFA. What is the BEST recommendation?

โœ– DETECTED & BLOCKED

Blocked this time. Adjust your approach:

Legacy protocols may bypass modern MFA controls. Disabling legacy authentication and enforcing modern auth reduces risk.

โœ– DETECTED & BLOCKED

Blocked this time. Adjust your approach:

Legacy protocols may bypass modern MFA controls. Disabling legacy authentication and enforcing modern auth reduces risk.

โœ– DETECTED & BLOCKED

Blocked this time. Adjust your approach:

Legacy protocols may bypass modern MFA controls. Disabling legacy authentication and enforcing modern auth reduces risk.

โœ” FINDING CONFIRMED

Clean tradecraft. The client would sign off on that.

Legacy protocols may bypass modern MFA controls. Disabling legacy authentication and enforcing modern auth reduces risk.

63/100 Attacks and Exploits

An internal chatbot can be prompted to reveal confidential policy content from restricted documents. What is the BEST classification?

โœ– ROE CHECK FAILED

Every failed attempt is enumeration. Note this:

AI systems must enforce authorization boundaries and prevent disclosure of restricted content.

โœ– ROE CHECK FAILED

Every failed attempt is enumeration. Note this:

AI systems must enforce authorization boundaries and prevent disclosure of restricted content.

โœ” FOOTHOLD GAINED

You stayed in scope and got the objective. Textbook.

AI systems must enforce authorization boundaries and prevent disclosure of restricted content.

โœ– ROE CHECK FAILED

Every failed attempt is enumeration. Note this:

AI systems must enforce authorization boundaries and prevent disclosure of restricted content.

64/100 Attacks and Exploits

While validating a web vulnerability, the tester notices no server-side logs are generated for failed authorization attempts. What additional finding may be appropriate?

โœ” EXPLOIT VALIDATED

Sharp โ€” you picked the move a professional tester makes.

Security-relevant events such as authorization failures should be logged and monitored to support detection and response.

โœ– PAYLOAD FIZZLED

Reset and re-engage with this insight:

Security-relevant events such as authorization failures should be logged and monitored to support detection and response.

โœ– PAYLOAD FIZZLED

Reset and re-engage with this insight:

Security-relevant events such as authorization failures should be logged and monitored to support detection and response.

โœ– PAYLOAD FIZZLED

Reset and re-engage with this insight:

Security-relevant events such as authorization failures should be logged and monitored to support detection and response.

65/100 Attacks and Exploits

A tester is authorized for external network testing only but notices an unlocked side door. What should the tester do?

โœ– RETRY THE VECTOR

Vector didn't land โ€” recon the takeaway:

Testing must stay within scope. Physical access attempts require explicit authorization.

โœ– RETRY THE VECTOR

Vector didn't land โ€” recon the takeaway:

Testing must stay within scope. Physical access attempts require explicit authorization.

โœ– RETRY THE VECTOR

Vector didn't land โ€” recon the takeaway:

Testing must stay within scope. Physical access attempts require explicit authorization.

โœ” OBJECTIVE CAPTURED

Methodical over flashy. That's what passes this exam.

Testing must stay within scope. Physical access attempts require explicit authorization.

66/100 Attacks and Exploits

Two vulnerabilities are found: one unauthenticated remote code execution on an internet-facing server and one low-severity missing header. Which should be prioritized for validation?

โœ– OUT OF SCOPE

Blocked this time. Adjust your approach:

Prioritization should consider exploitability, exposure, and business impact.

โœ– OUT OF SCOPE

Blocked this time. Adjust your approach:

Prioritization should consider exploitability, exposure, and business impact.

โœ” CLEAN PIVOT

The red team would want you on the engagement.

Prioritization should consider exploitability, exposure, and business impact.

โœ– OUT OF SCOPE

Blocked this time. Adjust your approach:

Prioritization should consider exploitability, exposure, and business impact.

67/100 Post-Exploitation

After gaining approved low-privilege access to a test host, the tester finds a possible privilege escalation path. What should happen before attempting it?

โœ– DETECTED & BLOCKED

Every failed attempt is enumeration. Note this:

Post-exploitation actions can increase risk and must be explicitly permitted and controlled.

โœ– DETECTED & BLOCKED

Every failed attempt is enumeration. Note this:

Post-exploitation actions can increase risk and must be explicitly permitted and controlled.

โœ” EVIDENCE LOGGED

That's how an ethical hacker thinks โ€” authorized, precise, documented.

Post-exploitation actions can increase risk and must be explicitly permitted and controlled.

โœ– DETECTED & BLOCKED

Every failed attempt is enumeration. Note this:

Post-exploitation actions can increase risk and must be explicitly permitted and controlled.

68/100 Post-Exploitation

A standard workstation has stored administrative credentials that can access many servers. What is the PRIMARY risk?

โœ” REPORT-READY

Clean tradecraft. The client would sign off on that.

Stored privileged credentials on endpoints can enable lateral movement if the workstation is compromised.

โœ– ROE CHECK FAILED

Reset and re-engage with this insight:

Stored privileged credentials on endpoints can enable lateral movement if the workstation is compromised.

โœ– ROE CHECK FAILED

Reset and re-engage with this insight:

Stored privileged credentials on endpoints can enable lateral movement if the workstation is compromised.

โœ– ROE CHECK FAILED

Reset and re-engage with this insight:

Stored privileged credentials on endpoints can enable lateral movement if the workstation is compromised.

69/100 Post-Exploitation

A client asks whether persistence can be established on production servers to test detection. What is the BEST response?

โœ” ROE HONORED

You stayed in scope and got the objective. Textbook.

Persistence testing must be explicitly approved, reversible, and documented with cleanup procedures.

โœ– PAYLOAD FIZZLED

Vector didn't land โ€” recon the takeaway:

Persistence testing must be explicitly approved, reversible, and documented with cleanup procedures.

โœ– PAYLOAD FIZZLED

Vector didn't land โ€” recon the takeaway:

Persistence testing must be explicitly approved, reversible, and documented with cleanup procedures.

โœ– PAYLOAD FIZZLED

Vector didn't land โ€” recon the takeaway:

Persistence testing must be explicitly approved, reversible, and documented with cleanup procedures.

70/100 Post-Exploitation

The ROE prohibits real data exfiltration but allows simulation. Which method is BEST?

โœ” TARGET CLEARED

Sharp โ€” you picked the move a professional tester makes.

Simulated exfiltration with benign files demonstrates control gaps without exposing sensitive data.

โœ– RETRY THE VECTOR

Blocked this time. Adjust your approach:

Simulated exfiltration with benign files demonstrates control gaps without exposing sensitive data.

โœ– RETRY THE VECTOR

Blocked this time. Adjust your approach:

Simulated exfiltration with benign files demonstrates control gaps without exposing sensitive data.

โœ– RETRY THE VECTOR

Blocked this time. Adjust your approach:

Simulated exfiltration with benign files demonstrates control gaps without exposing sensitive data.

CHECKPOINT โ€” 70 DOWN, KEEP CLIMBING
71/100 Post-Exploitation

A tester establishes access to a jump host and wants to test reachability to an internal subnet. What must be verified first?

โœ” SCOPE RESPECTED

Methodical over flashy. That's what passes this exam.

Pivoting changes the test path and can affect additional systems. It must be within scope.

โœ– OUT OF SCOPE

Every failed attempt is enumeration. Note this:

Pivoting changes the test path and can affect additional systems. It must be within scope.

โœ– OUT OF SCOPE

Every failed attempt is enumeration. Note this:

Pivoting changes the test path and can affect additional systems. It must be within scope.

โœ– OUT OF SCOPE

Every failed attempt is enumeration. Note this:

Pivoting changes the test path and can affect additional systems. It must be within scope.

72/100 Post-Exploitation

After completing a test, what should the tester do with test accounts, temporary files, and artifacts?

โœ– DETECTED & BLOCKED

Reset and re-engage with this insight:

Cleanup is a required post-exploitation activity to restore the environment and reduce residual risk.

โœ– DETECTED & BLOCKED

Reset and re-engage with this insight:

Cleanup is a required post-exploitation activity to restore the environment and reduce residual risk.

โœ– DETECTED & BLOCKED

Reset and re-engage with this insight:

Cleanup is a required post-exploitation activity to restore the environment and reduce residual risk.

โœ” FINDING CONFIRMED

The red team would want you on the engagement.

Cleanup is a required post-exploitation activity to restore the environment and reduce residual risk.

73/100 Post-Exploitation

A tester gains access to a file share containing sensitive HR records. What evidence approach is BEST?

โœ” FOOTHOLD GAINED

That's how an ethical hacker thinks โ€” authorized, precise, documented.

Minimize access to sensitive data and collect only approved evidence necessary to prove risk.

โœ– ROE CHECK FAILED

Vector didn't land โ€” recon the takeaway:

Minimize access to sensitive data and collect only approved evidence necessary to prove risk.

โœ– ROE CHECK FAILED

Vector didn't land โ€” recon the takeaway:

Minimize access to sensitive data and collect only approved evidence necessary to prove risk.

โœ– ROE CHECK FAILED

Vector didn't land โ€” recon the takeaway:

Minimize access to sensitive data and collect only approved evidence necessary to prove risk.

74/100 Post-Exploitation

A web server contains cloud access tokens in a configuration file. What is the BEST immediate recommendation?

โœ– PAYLOAD FIZZLED

Blocked this time. Adjust your approach:

Exposed tokens should be rotated, protected, and managed using secure secret storage.

โœ– PAYLOAD FIZZLED

Blocked this time. Adjust your approach:

Exposed tokens should be rotated, protected, and managed using secure secret storage.

โœ– PAYLOAD FIZZLED

Blocked this time. Adjust your approach:

Exposed tokens should be rotated, protected, and managed using secure secret storage.

โœ” EXPLOIT VALIDATED

Clean tradecraft. The client would sign off on that.

Exposed tokens should be rotated, protected, and managed using secure secret storage.

75/100 Post-Exploitation

During an assumed-breach test, lateral movement simulation is not detected. What should the tester include in the report?

โœ” OBJECTIVE CAPTURED

You stayed in scope and got the objective. Textbook.

Detection findings should be objective, evidence-based, and include actionable monitoring recommendations.

โœ– RETRY THE VECTOR

Every failed attempt is enumeration. Note this:

Detection findings should be objective, evidence-based, and include actionable monitoring recommendations.

โœ– RETRY THE VECTOR

Every failed attempt is enumeration. Note this:

Detection findings should be objective, evidence-based, and include actionable monitoring recommendations.

โœ– RETRY THE VECTOR

Every failed attempt is enumeration. Note this:

Detection findings should be objective, evidence-based, and include actionable monitoring recommendations.

76/100 Post-Exploitation

A tester needs to show how a low-privilege user could reach a privileged role through group nesting. What is the BEST evidence?

โœ– OUT OF SCOPE

Reset and re-engage with this insight:

Privilege path evidence helps stakeholders understand escalation risk and remediation steps.

โœ– OUT OF SCOPE

Reset and re-engage with this insight:

Privilege path evidence helps stakeholders understand escalation risk and remediation steps.

โœ” CLEAN PIVOT

Sharp โ€” you picked the move a professional tester makes.

Privilege path evidence helps stakeholders understand escalation risk and remediation steps.

โœ– OUT OF SCOPE

Reset and re-engage with this insight:

Privilege path evidence helps stakeholders understand escalation risk and remediation steps.

77/100 Post-Exploitation

An internal assessment permits collecting password hashes for offline strength analysis. What is the BEST handling practice?

โœ– DETECTED & BLOCKED

Vector didn't land โ€” recon the takeaway:

Password hashes are sensitive authentication material and must be tightly controlled.

โœ– DETECTED & BLOCKED

Vector didn't land โ€” recon the takeaway:

Password hashes are sensitive authentication material and must be tightly controlled.

โœ” EVIDENCE LOGGED

Methodical over flashy. That's what passes this exam.

Password hashes are sensitive authentication material and must be tightly controlled.

โœ– DETECTED & BLOCKED

Vector didn't land โ€” recon the takeaway:

Password hashes are sensitive authentication material and must be tightly controlled.

78/100 Post-Exploitation

The tester can access a sensitive database using an overprivileged service account. What is the safest way to demonstrate impact?

โœ– ROE CHECK FAILED

Blocked this time. Adjust your approach:

Impact should be demonstrated with minimal, approved evidence that avoids data exposure or system damage.

โœ” REPORT-READY

The red team would want you on the engagement.

Impact should be demonstrated with minimal, approved evidence that avoids data exposure or system damage.

โœ– ROE CHECK FAILED

Blocked this time. Adjust your approach:

Impact should be demonstrated with minimal, approved evidence that avoids data exposure or system damage.

โœ– ROE CHECK FAILED

Blocked this time. Adjust your approach:

Impact should be demonstrated with minimal, approved evidence that avoids data exposure or system damage.

79/100 Post-Exploitation

A client asks the tester to disable EDR on production systems to make testing easier. What should the tester recommend?

โœ– PAYLOAD FIZZLED

Every failed attempt is enumeration. Note this:

Security monitoring should generally remain in place; exceptions must be approved, limited, and documented.

โœ– PAYLOAD FIZZLED

Every failed attempt is enumeration. Note this:

Security monitoring should generally remain in place; exceptions must be approved, limited, and documented.

โœ– PAYLOAD FIZZLED

Every failed attempt is enumeration. Note this:

Security monitoring should generally remain in place; exceptions must be approved, limited, and documented.

โœ” ROE HONORED

That's how an ethical hacker thinks โ€” authorized, precise, documented.

Security monitoring should generally remain in place; exceptions must be approved, limited, and documented.

80/100 Post-Exploitation

A tester identifies that session cookies lack secure attributes. What is the BEST post-exploitation demonstration?

โœ” TARGET CLEARED

Clean tradecraft. The client would sign off on that.

Use controlled accounts and minimize sensitive exposure when demonstrating session risks.

โœ– RETRY THE VECTOR

Reset and re-engage with this insight:

Use controlled accounts and minimize sensitive exposure when demonstrating session risks.

โœ– RETRY THE VECTOR

Reset and re-engage with this insight:

Use controlled accounts and minimize sensitive exposure when demonstrating session risks.

โœ– RETRY THE VECTOR

Reset and re-engage with this insight:

Use controlled accounts and minimize sensitive exposure when demonstrating session risks.

CHECKPOINT โ€” 80 DOWN, KEEP CLIMBING
81/100 Post-Exploitation

After gaining access to a workstation, the tester can reach cardholder data systems despite segmentation claims. What should the report emphasize?

โœ– OUT OF SCOPE

Vector didn't land โ€” recon the takeaway:

Segmentation bypass can carry significant business and compliance impact and should be clearly documented.

โœ– OUT OF SCOPE

Vector didn't land โ€” recon the takeaway:

Segmentation bypass can carry significant business and compliance impact and should be clearly documented.

โœ” SCOPE RESPECTED

You stayed in scope and got the objective. Textbook.

Segmentation bypass can carry significant business and compliance impact and should be clearly documented.

โœ– OUT OF SCOPE

Vector didn't land โ€” recon the takeaway:

Segmentation bypass can carry significant business and compliance impact and should be clearly documented.

82/100 Post-Exploitation

The ROE states all remote access must be removed within 24 hours of test completion. What should the tester do?

โœ– DETECTED & BLOCKED

Blocked this time. Adjust your approach:

Access lifecycle management and cleanup must follow the ROE.

โœ” FINDING CONFIRMED

Sharp โ€” you picked the move a professional tester makes.

Access lifecycle management and cleanup must follow the ROE.

โœ– DETECTED & BLOCKED

Blocked this time. Adjust your approach:

Access lifecycle management and cleanup must follow the ROE.

โœ– DETECTED & BLOCKED

Blocked this time. Adjust your approach:

Access lifecycle management and cleanup must follow the ROE.

83/100 Post-Exploitation

A test path reaches an engineering design repository. Which additional context improves the finding?

โœ– ROE CHECK FAILED

Every failed attempt is enumeration. Note this:

Post-exploitation findings should translate technical access into business impact.

โœ– ROE CHECK FAILED

Every failed attempt is enumeration. Note this:

Post-exploitation findings should translate technical access into business impact.

โœ– ROE CHECK FAILED

Every failed attempt is enumeration. Note this:

Post-exploitation findings should translate technical access into business impact.

โœ” FOOTHOLD GAINED

Methodical over flashy. That's what passes this exam.

Post-exploitation findings should translate technical access into business impact.

84/100 Post-Exploitation

Which statement is BEST for documenting a successful privilege escalation?

โœ– PAYLOAD FIZZLED

Reset and re-engage with this insight:

Good reporting is specific, evidence-based, scoped, and professional.

โœ– PAYLOAD FIZZLED

Reset and re-engage with this insight:

Good reporting is specific, evidence-based, scoped, and professional.

โœ” EXPLOIT VALIDATED

The red team would want you on the engagement.

Good reporting is specific, evidence-based, scoped, and professional.

โœ– PAYLOAD FIZZLED

Reset and re-engage with this insight:

Good reporting is specific, evidence-based, scoped, and professional.

85/100 Reporting and Communication

Which statement is BEST suited for an executive summary?

โœ– RETRY THE VECTOR

Vector didn't land โ€” recon the takeaway:

Executives need business-focused risk, impact, and prioritization.

โœ” OBJECTIVE CAPTURED

That's how an ethical hacker thinks โ€” authorized, precise, documented.

Executives need business-focused risk, impact, and prioritization.

โœ– RETRY THE VECTOR

Vector didn't land โ€” recon the takeaway:

Executives need business-focused risk, impact, and prioritization.

โœ– RETRY THE VECTOR

Vector didn't land โ€” recon the takeaway:

Executives need business-focused risk, impact, and prioritization.

86/100 Reporting and Communication

What elements should a strong technical finding include?

โœ– OUT OF SCOPE

Blocked this time. Adjust your approach:

Complete findings allow technical teams to understand, validate, prioritize, and remediate issues.

โœ– OUT OF SCOPE

Blocked this time. Adjust your approach:

Complete findings allow technical teams to understand, validate, prioritize, and remediate issues.

โœ– OUT OF SCOPE

Blocked this time. Adjust your approach:

Complete findings allow technical teams to understand, validate, prioritize, and remediate issues.

โœ” CLEAN PIVOT

Clean tradecraft. The client would sign off on that.

Complete findings allow technical teams to understand, validate, prioritize, and remediate issues.

87/100 Reporting and Communication

A vulnerability is easy to exploit remotely and affects a system storing regulated data. How should risk generally be rated?

โœ– DETECTED & BLOCKED

Every failed attempt is enumeration. Note this:

Risk should consider likelihood, impact, exposure, data sensitivity, and compensating controls.

โœ– DETECTED & BLOCKED

Every failed attempt is enumeration. Note this:

Risk should consider likelihood, impact, exposure, data sensitivity, and compensating controls.

โœ– DETECTED & BLOCKED

Every failed attempt is enumeration. Note this:

Risk should consider likelihood, impact, exposure, data sensitivity, and compensating controls.

โœ” EVIDENCE LOGGED

You stayed in scope and got the objective. Textbook.

Risk should consider likelihood, impact, exposure, data sensitivity, and compensating controls.

88/100 Reporting and Communication

A report identifies excessive cloud permissions. Which recommendation is BEST?

โœ– ROE CHECK FAILED

Reset and re-engage with this insight:

Actionable recommendations should target root cause and include preventive and detective controls.

โœ– ROE CHECK FAILED

Reset and re-engage with this insight:

Actionable recommendations should target root cause and include preventive and detective controls.

โœ– ROE CHECK FAILED

Reset and re-engage with this insight:

Actionable recommendations should target root cause and include preventive and detective controls.

โœ” REPORT-READY

Sharp โ€” you picked the move a professional tester makes.

Actionable recommendations should target root cause and include preventive and detective controls.

89/100 Reporting and Communication

Which evidence practice is BEST for sensitive findings?

โœ– PAYLOAD FIZZLED

Vector didn't land โ€” recon the takeaway:

Reports should protect sensitive data while providing sufficient evidence.

โœ– PAYLOAD FIZZLED

Vector didn't land โ€” recon the takeaway:

Reports should protect sensitive data while providing sufficient evidence.

โœ” ROE HONORED

Methodical over flashy. That's what passes this exam.

Reports should protect sensitive data while providing sufficient evidence.

โœ– PAYLOAD FIZZLED

Vector didn't land โ€” recon the takeaway:

Reports should protect sensitive data while providing sufficient evidence.

90/100 Reporting and Communication

After remediation, what is the purpose of a retest?

โœ– RETRY THE VECTOR

Blocked this time. Adjust your approach:

Retesting verifies remediation and supports closure decisions.

โœ– RETRY THE VECTOR

Blocked this time. Adjust your approach:

Retesting verifies remediation and supports closure decisions.

โœ” TARGET CLEARED

The red team would want you on the engagement.

Retesting verifies remediation and supports closure decisions.

โœ– RETRY THE VECTOR

Blocked this time. Adjust your approach:

Retesting verifies remediation and supports closure decisions.

CHECKPOINT โ€” 90 DOWN, KEEP CLIMBING
91/100 Reporting and Communication

Developers request guidance for an injection finding. What should the tester provide?

โœ– OUT OF SCOPE

Every failed attempt is enumeration. Note this:

Developers need actionable technical detail to fix the issue safely.

โœ– OUT OF SCOPE

Every failed attempt is enumeration. Note this:

Developers need actionable technical detail to fix the issue safely.

โœ– OUT OF SCOPE

Every failed attempt is enumeration. Note this:

Developers need actionable technical detail to fix the issue safely.

โœ” SCOPE RESPECTED

That's how an ethical hacker thinks โ€” authorized, precise, documented.

Developers need actionable technical detail to fix the issue safely.

92/100 Reporting and Communication

How should automated scanner output be used in a final report?

โœ– DETECTED & BLOCKED

Reset and re-engage with this insight:

Scanner output is useful but must be validated and interpreted in context.

โœ– DETECTED & BLOCKED

Reset and re-engage with this insight:

Scanner output is useful but must be validated and interpreted in context.

โœ– DETECTED & BLOCKED

Reset and re-engage with this insight:

Scanner output is useful but must be validated and interpreted in context.

โœ” FINDING CONFIRMED

Clean tradecraft. The client would sign off on that.

Scanner output is useful but must be validated and interpreted in context.

93/100 Reporting and Communication

Multiple findings trace back to lack of MFA for privileged access. What should the report include?

โœ– ROE CHECK FAILED

Vector didn't land โ€” recon the takeaway:

A root-cause theme helps clients address systemic weaknesses rather than isolated symptoms.

โœ” FOOTHOLD GAINED

You stayed in scope and got the objective. Textbook.

A root-cause theme helps clients address systemic weaknesses rather than isolated symptoms.

โœ– ROE CHECK FAILED

Vector didn't land โ€” recon the takeaway:

A root-cause theme helps clients address systemic weaknesses rather than isolated symptoms.

โœ– ROE CHECK FAILED

Vector didn't land โ€” recon the takeaway:

A root-cause theme helps clients address systemic weaknesses rather than isolated symptoms.

94/100 Reporting and Communication

A vulnerable service cannot be patched immediately due to vendor support limits. What should the report recommend?

โœ– PAYLOAD FIZZLED

Blocked this time. Adjust your approach:

When immediate patching is not possible, compensating controls reduce risk while a long-term fix is planned.

โœ– PAYLOAD FIZZLED

Blocked this time. Adjust your approach:

When immediate patching is not possible, compensating controls reduce risk while a long-term fix is planned.

โœ” EXPLOIT VALIDATED

Sharp โ€” you picked the move a professional tester makes.

When immediate patching is not possible, compensating controls reduce risk while a long-term fix is planned.

โœ– PAYLOAD FIZZLED

Blocked this time. Adjust your approach:

When immediate patching is not possible, compensating controls reduce risk while a long-term fix is planned.

95/100 Reporting and Communication

A tester confirms a critical internet-facing vulnerability during week one of a month-long test. What should happen?

โœ– RETRY THE VECTOR

Every failed attempt is enumeration. Note this:

Critical findings should be communicated promptly according to the ROE so the client can reduce risk quickly.

โœ” OBJECTIVE CAPTURED

Methodical over flashy. That's what passes this exam.

Critical findings should be communicated promptly according to the ROE so the client can reduce risk quickly.

โœ– RETRY THE VECTOR

Every failed attempt is enumeration. Note this:

Critical findings should be communicated promptly according to the ROE so the client can reduce risk quickly.

โœ– RETRY THE VECTOR

Every failed attempt is enumeration. Note this:

Critical findings should be communicated promptly according to the ROE so the client can reduce risk quickly.

96/100 Reporting and Communication

Which metric combination BEST supports remediation prioritization?

โœ” CLEAN PIVOT

The red team would want you on the engagement.

Prioritization should combine risk and practical remediation factors.

โœ– OUT OF SCOPE

Reset and re-engage with this insight:

Prioritization should combine risk and practical remediation factors.

โœ– OUT OF SCOPE

Reset and re-engage with this insight:

Prioritization should combine risk and practical remediation factors.

โœ– OUT OF SCOPE

Reset and re-engage with this insight:

Prioritization should combine risk and practical remediation factors.

97/100 Reporting and Communication

Which report language is MOST professional?

โœ– DETECTED & BLOCKED

Vector didn't land โ€” recon the takeaway:

Professional reporting is objective, specific, and evidence-based.

โœ– DETECTED & BLOCKED

Vector didn't land โ€” recon the takeaway:

Professional reporting is objective, specific, and evidence-based.

โœ” EVIDENCE LOGGED

That's how an ethical hacker thinks โ€” authorized, precise, documented.

Professional reporting is objective, specific, and evidence-based.

โœ– DETECTED & BLOCKED

Vector didn't land โ€” recon the takeaway:

Professional reporting is objective, specific, and evidence-based.

98/100 Reporting and Communication

A finding requires changes by identity, network, and application teams. What should the report include?

โœ– ROE CHECK FAILED

Blocked this time. Adjust your approach:

Multi-team findings benefit from clear ownership mapping and coordinated action.

โœ” REPORT-READY

Clean tradecraft. The client would sign off on that.

Multi-team findings benefit from clear ownership mapping and coordinated action.

โœ– ROE CHECK FAILED

Blocked this time. Adjust your approach:

Multi-team findings benefit from clear ownership mapping and coordinated action.

โœ– ROE CHECK FAILED

Blocked this time. Adjust your approach:

Multi-team findings benefit from clear ownership mapping and coordinated action.

99/100 Reporting and Communication

After remediation, the client accepts a remaining low-risk issue due to business need. What should be documented?

โœ” ROE HONORED

You stayed in scope and got the objective. Textbook.

Accepted residual risks should be formally documented with ownership and review timelines.

โœ– PAYLOAD FIZZLED

Every failed attempt is enumeration. Note this:

Accepted residual risks should be formally documented with ownership and review timelines.

โœ– PAYLOAD FIZZLED

Every failed attempt is enumeration. Note this:

Accepted residual risks should be formally documented with ownership and review timelines.

โœ– PAYLOAD FIZZLED

Every failed attempt is enumeration. Note this:

Accepted residual risks should be formally documented with ownership and review timelines.

100/100 Reporting and Communication

What is the BEST agenda for a final penetration test readout?

โœ” TARGET CLEARED

Sharp โ€” you picked the move a professional tester makes.

A final readout should summarize scope, impact, priorities, and actionable next steps for stakeholders.

โœ– RETRY THE VECTOR

Reset and re-engage with this insight:

A final readout should summarize scope, impact, priorities, and actionable next steps for stakeholders.

โœ– RETRY THE VECTOR

Reset and re-engage with this insight:

A final readout should summarize scope, impact, priorities, and actionable next steps for stakeholders.

โœ– RETRY THE VECTOR

Reset and re-engage with this insight:

A final readout should summarize scope, impact, priorities, and actionable next steps for stakeholders.

ENGAGEMENT COMPLETE โ€” REPORT DELIVERED

A real test ends with a report that makes the client stronger. You just sharpened yours. Oluma respects the reps.

TARGETS CLEARED ENGAGED

These are original practice scenarios written for the Oluma community with an ethical, authorized-testing focus. CompTIAยฎ and PenTest+ยฎ are registered trademarks of CompTIA, Inc. Oluma is not affiliated with or endorsed by CompTIA. No official exam content is reproduced here โ€” learn the craft, never the dumps.