📢 Too many exams? Don’t know which one suits you best? Book Your Free Expert 👉 call Now!

  • google app store apple app store
  • ✖

      Question

      'Penetration testing'

      is:
      A Testing network bandwidth by sending maximum traffic loads Correct Answer Incorrect Answer
      B Authorized simulated cyberattacks on a system to identify vulnerabilities before malicious hackers do Correct Answer Incorrect Answer
      C Automated vulnerability scanning using commercial tools only that helps in assessment of risks associated Correct Answer Incorrect Answer
      D Physical security testing of bank branches and server rooms Correct Answer Incorrect Answer
      E Testing software performance under peak load conditions Correct Answer Incorrect Answer

      Solution

      Penetration testing phases:  1) Reconnaissance (passive/active information gathering — OSINT, network scanning).  2) Scanning/Enumeration (identifying open ports, services, vulnerabilities — Nmap, Nessus).  3) Exploitation (gaining access — Metasploit, custom exploits). 4) Post-exploitation/Maintaining Access (privilege escalation, lateral movement, persistence).  5) Reporting (documenting findings, CVSS scores, remediation recommendations). RBI mandates annual VAPT by CERT-In empanelled agencies for all banks. Types: Black box, White box, Grey box.

      Practice Next

      Relevant for Exams:

      ask-question