Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

[CCPA] Hacking 101 Check Point Certified PenTesting Associate CCPA Certification Review Guide

Rating
-
Sold
-
Pages
90
Grade
A+
Uploaded on
27-02-2026
Written in
2025/2026

This cybersecurity-focused guide covers ethical hacking fundamentals, penetration testing methodologies, network security, vulnerability assessment, and threat mitigation strategies. Designed for entry-level penetration testing certification readiness.

Show more Read less
Institution
Course

Content preview

[CCPA] Hacking 101 Check Point Certified PenTesting
Associate CCPA Certification Review Guide
**Question 1. Which component of the CIA triad is most directly targeted when an attacker
exfiltrates proprietary source code from a server?**

A) Confidentiality

B) Integrity

C) Availability

D) Authentication

Answer: A

Explanation: Exfiltrating data compromises the confidentiality of the information, revealing it to
unauthorized parties.



**Question 2. In the context of ethical hacking, what does the term “white hat” refer to?**

A) A hacker who sells exploits on the dark web

B) A security professional who tests systems with permission

C) An attacker who only targets government agencies

D) A hacker who uses only social engineering techniques

Answer: B

Explanation: White‑hat hackers are authorized security professionals who perform penetration
testing under a legal agreement.



**Question 3. Which phase of the penetration testing lifecycle involves creating a detailed
document that includes remediation recommendations?**

A) Reconnaissance

B) Exploitation

C) Post‑Exploitation

D) Reporting

Answer: D

, [CCPA] Hacking 101 Check Point Certified PenTesting
Associate CCPA Certification Review Guide
Explanation: The reporting phase is where findings are compiled, explained, and mitigation
steps are suggested.



**Question 4. Under the Computer Fraud and Abuse Act (CFAA), which of the following actions
is explicitly prohibited?**

A) Scanning a network without a written contract

B) Using a password manager to store credentials

C) Performing a penetration test after obtaining verbal consent

D) Conducting a vulnerability assessment on your own system

Answer: A

Explanation: The CFAA makes it illegal to access a computer without authorization, which
includes unauthenticated scanning.



**Question 5. What is the primary purpose of a “Rules of Engagement” (RoE) document in a
penetration test?**

A) To list all discovered vulnerabilities

B) To define the scope, limitations, and acceptable actions for the test

C) To provide a step‑by‑step exploitation guide

D) To outline the pricing model for the service

Answer: B

Explanation: RoE sets the boundaries, targets, and permissible techniques for the engagement.



**Question 6. Which OSINT technique is most useful for discovering subdomains of a target
domain?**

A) WHOIS lookup

B) Google dorking with “site:example.com”

C) Reverse DNS lookup on IP addresses

, [CCPA] Hacking 101 Check Point Certified PenTesting
Associate CCPA Certification Review Guide
D) Shodan search for open ports

Answer: B

Explanation: Google dorking with “site:example.com” can reveal indexed subdomains.



**Question 7. Which DNS query type is used to attempt a zone transfer?**

A) A

B) MX

C) AXFR

D) TXT

Answer: C

Explanation: AXFR requests a full zone transfer, which can expose all DNS records if allowed.



**Question 8. In Nmap, which scan type is considered “stealthy” because it does not complete
the TCP three‑way handshake?**

A) TCP Connect scan (-sT)

B) SYN scan (-sS)

C) UDP scan (-sU)

D) ACK scan (-sA)

Answer: B

Explanation: The SYN scan sends only SYN packets and analyses responses, avoiding a full
handshake.



**Question 9. When using Nessus, which of the following is NOT a typical output format?**

A) HTML report

B) PDF summary

C) JSON feed

, [CCPA] Hacking 101 Check Point Certified PenTesting
Associate CCPA Certification Review Guide
D) Executable binary

Answer: D

Explanation: Nessus generates reports in formats like HTML, PDF, or JSON, but never as an
executable.



**Question 10. Banner grabbing is primarily used to determine what?**

A) The physical location of a server

B) The operating system and service versions running on a host

C) The encryption keys used by a VPN

D) The number of users logged in

Answer: B

Explanation: By connecting to a service and reading its banner, attackers can infer OS and
version information.



**Question 11. Which layer of the OSI model is responsible for routing packets between
different networks?**

A) Data Link

B) Network

C) Transport

D) Session

Answer: B

Explanation: The Network layer (Layer 3) handles logical addressing and routing.



**Question 12. In a TCP three‑way handshake, which flag combination is sent by the client in
the final packet?**

A) SYN

B) SYN‑ACK

Written for

Course

Document information

Uploaded on
February 27, 2026
Number of pages
90
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$85.99
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
teamdiginova2 Independent publisher
Follow You need to be logged in order to follow users or courses
Sold
20
Member since
4 months
Number of followers
0
Documents
9159
Last sold
4 days ago

3.6

5 reviews

5
1
4
1
3
3
2
0
1
0

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions