▸case-01 You are auditing an internal corporate network subnet (10.0.4.0/24). You need to perform a rapid port scan to identify open TCP ports without completing full TCP three-way handshakes with the target systems, minimizing connection logging overhead. Recommend the specific Nmap scan flag for this task when standard full connect scan (-sT) would generate excessive log entries. | pass→pass | 8,015 | 9,005 | +12% | 1 | 1 | 0% | 1,189 | 1,479 | +24% | 0 | 0 | — |
▸case-02 A security auditor needs to determine the exact service names and version numbers running on open ports of host 192.168.1.50, rather than relying on default port assignments. Which specific Nmap option flag enables service version intensity probing? | pass→pass | 4,983 | 5,805 | +16% | 1 | 1 | 0% | 875 | 1,694 | +94% | 0 | 0 | — |
▸case-03 An administrator needs to audit UDP-based services such as DNS on port 53 and SNMP on port 161 across host 172.16.10.15. Standard SYN scans (-sS) ignore UDP ports entirely. Which Nmap scan flag must be used to inspect UDP services? | pass→pass | 3,411 | 3,740 | +10% | 1 | 1 | 0% | 576 | 1,269 | +120% | 0 | 0 | — |
▸case-04 An organization wants to perform automated CVE vulnerability scanning across 500 enterprise workstations to identify unpatched software vulnerabilities without attempting active exploitation. Recommend an open-source enterprise vulnerability scanner framework suitable for scheduled network-wide vulnerability assessment. | pass→pass | 16,396 | 13,339 | -19% | 1 | 1 | 0% | 2,333 | 2,477 | +6% | 0 | 0 | — |
▸case-05 Prior to performing security testing on a web application, a tester needs to automatically crawl and map all accessible URLs, forms, and parameter inputs across the web app. Standard static web crawlers like curl or wget fail on dynamic client-side rendering. Recommend a dedicated web application security proxy tool to crawl and spider the site. | pass→pass | 10,355 | 11,356 | +10% | 1 | 1 | 0% | 1,670 | 2,411 | +44% | 0 | 0 | — |
▸case-06 A developer wants to test a REST API input parameter for SQL injection vulnerabilities in an automated pipeline. Instead of running a general network port scanner like Nmap, which specialized open-source security tool automates the process of detecting and exploiting database injection flaws? | pass→pass | 4,734 | 18,454 | +290% | 1 | 1 | 0% | 786 | 1,887 | +140% | 0 | 0 | — |
▸case-07 During an authorized wireless audit of an enterprise Wi-Fi network, a penetration tester needs to capture a WPA2 4-way authentication handshake. Before running packet capture tools like airodump-ng, what mode must the wireless network interface card (NIC) be put into? | pass→pass | 4,699 | 4,355 | -7% | 1 | 1 | 0% | 835 | 1,427 | +71% | 0 | 0 | — |
▸case-08 During a wireless assessment, passive Wi-Fi monitoring reveals access points that suppress SSID broadcasting in beacon frames. What technique or frame type interaction exposes the hidden network name when authorized clients connect? | pass→pass | 8,839 | 9,051 | +2% | 1 | 1 | 0% | 1,556 | 2,089 | +34% | 0 | 0 | — |
▸case-09 A threat intelligence team publishes signature indicators for a new malware variant consisting of specific byte sequences and regular expressions. Which CLI scanner tool allows incident responders to scan disk files and memory dumps using custom rule files defined in a standardized text syntax? | pass→pass | 6,165 | 4,912 | -20% | 1 | 1 | 0% | 928 | 1,376 | +48% | 0 | 0 | — |
▸case-10 A DevOps team needs to audit their AWS cloud environment for security misconfigurations such as publicly accessible S3 buckets, permissive security groups, and unencrypted volumes against CIS Benchmarks. Network scanners like Nmap cannot inspect API configuration states. Recommend an open-source CLI tool built specifically for AWS cloud security posture assessment. | pass→pass | 9,298 | 9,612 | +3% | 1 | 1 | 0% | 1,741 | 1,995 | +15% | 0 | 0 | — |
▸case-11 A continuous integration pipeline needs a security scanner to inspect Docker container image layers for known OS package vulnerabilities and application dependency CVEs prior to deployment. Recommend a widely-used open-source container vulnerability scanner. | pass→pass | 10,683 | 7,756 | -27% | 1 | 1 | 0% | 1,801 | 1,799 | -0% | 0 | 0 | — |
▸case-12 A Linux system administrator must demonstrate that a Red Hat Enterprise Linux 8 server meets DISA STIG compliance standards. Which automated SCAP-compliant auditing tool evaluates the local operating system against official security profile XML files? | pass→pass | 33,771 | 5,914 | -82% | 1 | 1 | 0% | 820 | 1,728 | +111% | 0 | 0 | — |
▸case-13 An administrator runs an Nmap port scan against a known active remote host on port 443, but Nmap reports the port state as 'filtered' rather than 'open' or 'closed'. Explain what packet-level behavior causes Nmap to report a port as 'filtered'. | pass→pass | 12,254 | 11,120 | -9% | 1 | 1 | 0% | 2,360 | 2,624 | +11% | 0 | 0 | — |
▸case-14 While running an automated web application security scan against a staging server, the scanner begins receiving HTTP 429 status codes and reporting incomplete results. What server mechanism is causing this behavior, and what scan adjustment remedies it? | pass→pass | 6,800 | 8,396 | +23% | 1 | 1 | 0% | 1,120 | 2,032 | +81% | 0 | 0 | — |
▸case-15 A security analyst is scanning a large /16 subnet with Nmap, but the scan is taking over 12 hours due to slow host discovery and excessive packet retries on unresponsive IPs. Which Nmap timing parameter or retry limit option speeds up the scan performance on slow or dropped paths? | pass→pass | 9,847 | 9,151 | -7% | 1 | 1 | 0% | 1,729 | 2,315 | +34% | 0 | 0 | — |
▸case-16 A network security team is configuring a port scan to detect exposed Microsoft Remote Desktop services across external IP addresses. Which standard TCP port number corresponds to RDP? | pass→pass | 2,726 | 4,392 | +61% | 1 | 1 | 0% | 262 | 1,053 | +302% | 0 | 0 | — |
▸case-17 An engineer needs to scan network switches and routers to check if default community strings like 'public' or 'private' are accessible. Which standard UDP port number should be targeted for SNMP queries? | pass→pass | 2,432 | 3,393 | +40% | 1 | 1 | 0% | 352 | 1,069 | +204% | 0 | 0 | — |
▸case-18 Before starting a vulnerability scan against a third-party managed infrastructure or cloud provider host, what essential legal document and administrative step must be secured to avoid unlawful computer access violations? | pass→pass | 9,198 | 7,426 | -19% | 1 | 1 | 0% | 1,471 | 1,790 | +22% | 0 | 0 | — |
▸case-19 A developer identified a SQL injection vulnerability in a Python Flask application where dynamic strings were concatenated into raw SQL queries. Rewrite the query code using SQLAlchemy parameter binding to securely execute `SELECT * FROM users WHERE username = input_user`. | pass→pass | 11,159 | 8,146 | -27% | 1 | 1 | 0% | 1,773 | 2,159 | +22% | 0 | 0 | — |
▸case-20 A system administrator needs to configure Linux kernel packet filtering to permanently block all incoming TCP traffic on port 23 (Telnet). Provide the exact iptables command to drop incoming TCP traffic targeted at port 23. | fail→pass | 6,219 | 3,465 | -44% | 1 | 1 | 0% | 1,081 | 1,263 | +17% | 0 | 0 | — |
▸case-21 During an active malware incident on an Ubuntu server, an incident responder needs to isolate the host from the local network immediately via command line without shutting down system memory or processes. What Linux command brings down the primary network interface eth0? | pass→pass | 4,275 | 5,013 | +17% | 1 | 1 | 0% | 689 | 1,461 | +112% | 0 | 0 | — |
▸case-22 A web administrator needs to generate a new 4096-bit RSA private key using OpenSSL to create a Certificate Signing Request (CSR) for an HTTPS web server. Provide the OpenSSL CLI command to generate this key file named server.key. | pass→pass | 2,542 | 2,857 | +12% | 1 | 1 | 0% | 442 | 1,134 | +157% | 0 | 0 | — |