Penetration Testing Methodology and Execution Questions
Running structured penetration-testing engagements end to end. Covers the pentest lifecycle, reconnaissance and information gathering, network scanning and enumeration (Nmap, service/version detection), tool selection and usage (Metasploit, Burp Suite), engagement scoping and planning, testing across target types, and findings reporting. The methodical offensive-assessment workflow.
Propose a set of KPIs and measurable metrics to evaluate the health and effectiveness of a multi-team penetration testing program over time. For each metric state the purpose, calculation method, data sources, and a sample target or threshold. Include metrics for: coverage (% assets tested), time-to-remediation, severity-trend, false-positive-rate, mean-time-to-detect-exploit, and tester-efficiency.
Explain how you would construct a timeline for a 3-month organizational penetration testing program using a Work Breakdown Structure (WBS) and critical-path analysis. Include example tasks (asset-inventory, automated-scanning, manual-testing-per-bucket, remediation-validation), dependencies, buffer strategies, parallel work opportunities, and an example WBS fragment that maps tasks to weeks and owners.
Compare and contrast three popular subdomain enumeration tools (for example Amass, Sublist3r, and assetfinder). For each tool explain primary data sources it queries (OSINT feeds, CT logs, brute force), strengths and limitations (speed, noise, active vs passive), typical performance characteristics, and an example use-case where that tool is the best fit during a scoped engagement.
You have three findings to prioritize: A) CVSS 9.8 SQL injection on a dev server accessible only from the corporate network, B) CVSS 6.5 stored XSS on the public-facing payment page, C) CVSS 4.3 missing security headers on an authentication microservice used by multiple products. Asset criticality: payment page is high, dev server is low, authentication microservice is critical. Propose a prioritized remediation plan, detail your scoring method combining CVSS and asset criticality, and justify the ordering.
Describe how you would perform web content discovery (directory/file brute forcing) against a single web host in scope. Include tool choices, recommended wordlists, options for handling rate-limiting and auth-protected areas, techniques to detect wildcard or custom error pages, and safeguards to avoid triggering intrusion prevention systems.
Unlock Full Question Bank
Get access to all Penetration Testing Methodology and Execution interview questions and detailed answers.
Sign in to ContinueJoin thousands of developers preparing for their dream job.