Common penetration testing tools and their primary use cases tested on the CompTIA PenTest+ exam.
35 cards · basic cards · AI-written, checked twice. Edit anything.
- What is the primary use of Nmap?
- Network scanning and port discovery
- What does Metasploit primarily do?
- Exploitation and payload delivery framework
- What is Burp Suite used for?
- Web application security testing and analysis
- What does Wireshark do?
- Captures and analyzes network traffic packets
- What is Aircrack-ng primarily used for?
- Wireless network penetration testing and WEP/WPA cracking
- What does Hashcat do?
- Cracks password hashes using GPU acceleration
- What is John the Ripper used for?
- Password hash cracking and brute force attacks
- What does Hydra do?
- Performs credential brute force attacks against remote services
- What is SQLMap used for?
- Detecting and exploiting SQL injection vulnerabilities
- What does Nikto do?
- Scans web servers for known vulnerabilities and misconfigurations
- What is OpenVAS used for?
- Vulnerability scanning and threat assessment
- What does Nessus do?
- Performs comprehensive vulnerability scanning and asset assessment
- What is TheHarvester used for?
- Gathering open-source intelligence and email harvesting
- What does Shodan search for?
- Internet-connected devices and their metadata via search queries
- What is Maltego used for?
- Open-source intelligence gathering and data visualization