Scanners & Recon
Port and vulnerability scanners, web proxies, packet capture, artefact and IaC scanners, and abusable-binary catalogues. Interviewers check you have driven these tools, not just named them.
on this pageshowhide
explore
- Nmapempty
- Host Discoveryempty
- Scan Typesempty
- OS Fingerprintingempty
- Timing & Evasionempty
- NSE Scriptingempty
- hpingempty
- Vulnerability Assessment28 questions
- Scanning Concepts11 questions
- Nessus6 questions
- OpenVAS6 questions
- Qualys5 questions
- Burp Suiteempty
- Repeaterempty
- Intruderempty
- Scanner & Auditempty
- Extensions & BAppsempty
- OWASP ZAP121 questions
- Program and Packaging16 questions
- Traffic Capture11 questions
- Logged-In Access11 questions
- Building the Request List16 questions
- Scan Engines21 questions
- Findings and Output14 questions
- Machine-Driven Runs22 questions
- Permission and Fit10 questions
- Wireshark36 questions
- Capture Interfaces and Setup6 questions
- Capture Filters3 questions
- Display Filters6 questions
- Protocol Dissectors5 questions
- Stream Following and Reassembly5 questions
- Expert Info and Statistics6 questions
- TLS Decryption5 questions
- tcpdump18 questions
- Capture Options and Files6 questions
- BPF Filter Expressions6 questions
- Packet Lines and Flags6 questions
- Trivy28 questions
- Scanning Targets5 questions
- Vulnerability DB and Filters6 questions
- Misconfig and Secret Scanning6 questions
- SBOM and License Scanning6 questions
- CI Integration and Output5 questions
- Checkov6 questions
- KICS6 questions
- GTFOBinsempty
- LOLBASempty
questions
243 · 7 sectionsIn Nessus, what is a plugin, and what do its plugin ID, family and type tell you about a finding?
basics
~20 sA Nessus plugin is a NASL program from Tenable, usually testing for one issue. Its numeric ID names the finding, its family groups it for selection in a policy, and its type says how it gathered evidence.
In Qualys VMDR, what is a QID, and why is it not the same thing as a CVE?
basics
~20 sA QID (Qualys ID) is the number of one detection in the Qualys KnowledgeBase. A CVE names a published flaw; a QID is Qualys's test and verdict, may list several CVEs, and can carry none at all.
How does an unauthenticated network vulnerability scan decide a host is vulnerable, and how does a credentialed scan decide differently?
basics
~20 sAn unauthenticated scan infers from what services expose on the network: banners, version strings, protocol behaviour. A credentialed scan logs in and reads installed package versions and configuration, so it decides from the host's own record instead of a guess.
What does a quarterly point-in-time vulnerability scan miss that continuous assessment of the same estate catches?
basics
~20 sA point-in-time scan proves the state of the hosts it reached on the day it ran. It misses hosts that came and went between runs, changes made since, and newly disclosed flaws in software it already saw.
How does the Greenbone Community Feed differ from the Greenbone Enterprise Feed, and is the free feed really delayed behind the paid one?
basics
~20 sBoth Greenbone feeds publish daily. The free Community Feed carries the most important VTs plus basic configs, without VTs for enterprise products and with no warranty; the commercial Enterprise Feed adds those VTs, compliance checks, more report formats and an SLA.
What do the exit codes of ZAP's packaged baseline scan script mean, and what does its -I flag change?
basics
~20 szap-baseline.py exits 1 if a rule marked FAIL alerted, 2 if only WARN-bucket rules did, 0 if at least one rule ran and raised nothing, and 3 for everything else. -I removes only the exit-2 branch.
Why does ZAP's `openapi` import reach endpoints that its `spider` add-on never finds?
basics
~20 sA definition lists every operation whether or not anything links to it, and the openapi add-on sends a real request for each one. A link-following crawl can only enqueue what a response already points at.
On an OWASP ZAP alert, what do the risk value and the confidence value each tell you?
basics
~10 sRisk is how damaging the finding would be if it is real. Confidence is how sure the scan rule is that it is real. They are two separate fields on the alert, set independently.
Does ZAP check that you are allowed to scan a target, and what does it ship instead?
basics
~20 sZAP performs no ownership or authorisation check on a target — nothing in it resolves who owns a host. It ships only a permission warning on rendered screens such as its welcome text and Quick Start panel.
In OWASP ZAP, which capabilities live in the core program and which arrive as add-ons?
basics
~20 sCore is one versioned program: the command line, the control API, the active-scan engine, and the alert and context models. Almost everything else — the local proxy, the passive-scan engine, the crawlers, automation, reports — ships as separately versioned add-ons.
In Wireshark, how does a capture filter differ from a display filter, and when would you filter at capture time?
basics
~20 sA capture filter, written in libpcap's filter language, decides which packets are ever recorded; anything it rejects is gone for good. A display filter, written in Wireshark's field syntax, only hides packets already captured and can be changed freely.
In Wireshark, how do you choose the capture interface, and why does traffic to a service on 127.0.0.1 never appear on the Ethernet adapter?
basics
~20 sCapture on the interface the flow really crosses; the welcome screen's activity sparklines and dumpcap -D show which interfaces are live. Traffic to 127.0.0.1 is delivered inside the operating system and never reaches the Ethernet adapter, so capture it on the loopback interface.
In Wireshark, how does a display filter such as `http.response.code >= 500` reach into dissected fields, and what does a bare field name test?
basics
~20 sA Wireshark display filter compares typed fields the dissectors registered: http.response.code >= 500 is a numeric test. A bare field name only tests that the field exists, so tcp.flags.syn alone matches nearly every TCP packet.
In Wireshark, what does the Expert Information dialog show, how are its severity levels ranked, and how far should you trust it?
basics
~20 sExpert Information lists anomalies that dissectors flagged, ranked Chat, Note, Warn, Error from lowest to highest (packet comments sit below Chat) and grouped by kind, such as Sequence or Malformed. It shows where to look; it never diagnoses.
In Wireshark, what does Follow TCP Stream show that the packet list cannot, and what does it do to your display filter?
basics
~20 sFollow TCP Stream rebuilds one connection's payload as the applications exchanged it, both directions in sequence order with retransmitted bytes shown once, and applies the display filter tcp.stream eq N, which Back removes and Close keeps.
On a Linux server, how do you use tcpdump to choose the right interface and save traffic for later analysis in Wireshark?
basics
~20 sList capture devices with tcpdump -D, capture with tcpdump -i eth0 -w /var/tmp/web.pcap and a filter, stop with -c or Ctrl-C, then read the file with -r or Wireshark. Use -i any only to find the interface.
How do you write a tcpdump filter for TCP traffic with 192.0.2.10 on port 5432, and what do its type, dir and proto qualifiers do?
basics
~20 sUse tcp port 5432 and host 192.0.2.10. Each primitive is an id with qualifiers: proto (tcp, ip, ip6), dir (src, dst) and type (host, net, port, portrange). Missing ones default to host, src or dst, and every consistent protocol.
In a tcpdump TCP line, what do the flag fields [S], [S.], [P.], [F.], [R.] and a bare [.] each tell you?
basics
~20 sEach character is one TCP control bit that is set: S SYN, F FIN, P PSH, R RST, U URG, and a dot for ACK. So [S.] is SYN plus ACK, [P.] data with ACK, and [.] a bare acknowledgment.
Which tcpdump filter shows only the initial SYN of each TCP handshake, not the SYN-ACK, and why is `tcp[tcpflags] & tcp-syn != 0` not enough?
basics
~20 stcp[tcpflags] & (tcp-syn|tcp-ack) == tcp-syn keeps the SYN and ACK bits and requires SYN alone. Testing only the SYN bit also matches every SYN-ACK, because the reply carries SYN too. The numeric form is tcp[13] & 0x12 == 2.
A client tcpdump shows one SYN to port 443 sent three times unanswered; how does that look different from a refused connection?
basics
~20 sThree [S] lines with the same source port and seq are one SYN retransmitted because nothing reached this capture point in reply. A refused attempt is one [S] answered within a round trip by [R.] acking the SYN's seq plus one.
Does a Trivy 0.74 scan fail a CI job by default when it finds a CRITICAL vulnerability, and what makes it fail?
basics
~10 sNo. Trivy 0.74 exits 0 whatever it finds; setting --exit-code to a non-zero value makes it exit with that code when any finding survives filtering, and --severity HIGH,CRITICAL decides which findings survive.
With Trivy 0.74, how do you scan a folder of Terraform, Kubernetes and Dockerfiles for misconfigurations, and how do you read one finding?
basics
~20 sRun trivy config on the folder; it detects each file's type and applies the built-in trivy-checks bundle. Each failure gives severity, check ID, title, an AVD link and file lines. fs, image and repo skip this unless --scanners misconfig is set.
With Trivy, how do you generate an SBOM for a container image and later re-check it against new advisories without pulling the image?
basics
~20 sRun trivy image with --format cyclonedx, spdx or spdx-json and --output to save the package inventory with the release. Later, trivy sbom on that file matches the recorded packages against Trivy's current vulnerability database, with no image pull.
Why does Trivy 0.74 report different vulnerabilities for one service when you run `trivy fs`, `trivy repo`, `trivy image` and `trivy rootfs` against it?
basics
~20 sEach Trivy subcommand enables a different set of analyzers: fs and repo read pre-build lockfiles, while image, rootfs and vm read post-build evidence such as OS package databases, installed package metadata, Go binaries and JARs, and skip most lockfiles.
In Trivy 0.74, what do --severity and --ignore-unfixed each remove from a vulnerability report, and what do they leave alone?
basics
~20 s--severity keeps only findings whose assigned severity is listed, all five levels by default; --ignore-unfixed drops findings whose status is not fixed. Both filter the finished report, so neither changes what was detected or how it was rated.
In a CI job running `checkov -d .` over Terraform, what decides the exit code, and what does `--soft-fail` change?
basics
~20 sCheckov exits 0 when every check passed or was skipped and 1 when any check failed. With -s or --soft-fail it always exits 0 but still reports every failure, which is different from skipping a check, which never runs.
In Checkov, how does a CKV2_ graph check differ from a CKV_ attribute check, and why can one bucket pass one and fail the other?
basics
~20 sA CKV_ check reads one resource's own settings; a CKV2_ graph check tests how resources are connected, such as a bucket and its public access block. A clean bucket still fails when that linked resource is missing or unreferenced.
You add Checkov to a Terraform repo with hundreds of existing failures — how do `--create-baseline` and `--baseline` gate only new ones, and where does the match leak?
basics
~20 s--create-baseline writes the current failures to a .checkov.baseline file; later runs with --baseline report only failures not in it. Matching uses resource address plus check ID, ignoring the file, so renames resurface old debt and same-named resources slip through.
A Checkov scan of Terraform source passes a bucket whose `acl = var.acl` is public-read only in `prod.tfvars` — why, and how do you make Checkov see the production value?
basics
~10 sCheckov renders variables only from defaults, TF_VAR_ variables and Terraform's automatic tfvars files, so it judged the default. Pass --var-file prod.tfvars, or scan the plan JSON with the terraform_plan framework.
Which Checkov behaviours silently narrow a scan of a repo holding Terraform, Helm charts and workflow files, so fewer resources get checked?
basics
~10 sCheckov drops the helm framework when no helm 3 binary is installed, skips registry and git modules unless --download-external-modules true is set, ignores .terraform, and runs only the listed checks when --check is used.
When you run `kics scan -p . -o ./kics-out` against a repository, what does KICS scan and which report files does it write?
basics
~10 sKICS detects which supported IaC types the path contains, runs the matching built-in Rego queries, prints the findings, and writes results.json into ./kics-out; other formats need --report-formats, and without -o no file is written.
A KICS 2.2 scan in CI exits with status 40 — what does that mean, and how do `--fail-on` and `--ignore-on-exit` change it?
basics
~20 sStatus 40 means the worst counted finding was MEDIUM, with no counted CRITICAL (60) or HIGH (50). --fail-on lists which severities may set the status, and --ignore-on-exit can mute result codes, engine-error codes, or both.
In KICS, how is a built-in query identified, and how do you run only selected queries or skip others in a scan?
basics
~10 sEach built-in query is a folder holding query.rego and a metadata.json whose id is a UUID; that UUID is what --include-queries and --exclude-queries take, alongside --exclude-categories, --exclude-severities, --type and --queries-path.
A KICS scan of your repository passes, yet a Terraform file with a known misconfiguration produced no finding — what in KICS's report and defaults do you check?
basics
~20 sWalk the pipeline: was the file collected (.gitignore, --exclude-paths, kics.config, the 5 MB cap, --type), parsed, evaluated (query filters, timeouts), resolved (tfvars, functions, custom modules), suppressed (kics-scan comments, -x), or merely not counted by --fail-on?
In KICS, what do `kics-scan` comment directives do, and why does `# kics-scan ignore` inside a Terraform resource block have no effect?
basics
~20 skics-scan comments suppress results from inside the scanned file. ignore, enable= and disable= are file-level and work only above the first real line; ignore-line and ignore-block work anywhere, so an ignore inside a resource is disregarded.