PenTest+ V2 Exploiting Misconfigured Services Quiz

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 8865 | Total Attempts: 106,055
| Questions: 20 | Updated: Aug 13, 2026
Please wait...
Question 1 / 21
🏆 Rank #--
0 %
0/100
Score 0/100

1. A Tomcat server exposes the manager interface without authentication. An attacker can use this to deploy malicious WAR files. What type of misconfiguration is this?

Submit
Please wait...
About This Quiz
PenTest+ V2 Exploiting Misconfigured Services Quiz - Quiz

This quiz assesses your knowledge of exploiting misconfigured services in penetration testing. You'll evaluate common misconfigurations in web servers, databases, and network services, identify attack vectors, and understand how to leverage weak configurations for unauthorized access. Essential for PenTest+ certification and real-world security assessments.

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. Which misconfiguration allows attackers to bypass authentication by exploiting predictable session tokens?

Submit

3. A misconfigured firewall rule allows traffic on port 22 from any IP address. This creates a ____ exposure.

Submit

4. An API endpoint returns sensitive information in response headers or error messages. What misconfiguration is this?

Submit

5. A backup server stores database dumps in a world-readable directory. This misconfiguration allows attackers to access ____.

Submit

6. Docker containers running with privileged mode represent which type of misconfiguration?

Submit

7. A misconfigured CORS policy allows requests from any origin. What vulnerability does this introduce?

Submit

8. An application uses HTTP instead of HTTPS for sensitive operations. This misconfiguration enables ____ attacks.

Submit

9. A Redis instance is accessible remotely without password protection. Which exploitation method is most direct?

Submit

10. Jenkins servers left unsecured allow attackers to execute arbitrary code. This represents a ____ misconfiguration.

Submit

11. Which HTTP method is most commonly left enabled on misconfigured web servers and can allow an attacker to upload malicious files?

Submit

12. Which of the following is NOT a typical misconfiguration that leads to exploitation?

Submit

13. A web server is running with directory listing enabled. Attackers can exploit this to ____.

Submit

14. An S3 bucket is configured with public read access. Which cloud misconfiguration does this represent?

Submit

15. SNMP community strings set to 'public' or 'private' allow attackers to gather sensitive network information. This is a ____ misconfiguration.

Submit

16. A web application displays detailed error messages revealing the backend database type and query syntax. What misconfiguration does this represent?

Submit

17. Which service typically runs on port 3306 and often has weak default configurations?

Submit

18. An FTP server allows anonymous login without a password. This is an example of ____.

Submit

19. SMB shares that are world-readable without credentials represent which security misconfiguration?

Submit

20. A database server is accessible over the network without authentication. What type of misconfiguration is this?

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (20)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
A Tomcat server exposes the manager interface without authentication....
Which misconfiguration allows attackers to bypass authentication by...
A misconfigured firewall rule allows traffic on port 22 from any IP...
An API endpoint returns sensitive information in response headers or...
A backup server stores database dumps in a world-readable directory....
Docker containers running with privileged mode represent which type of...
A misconfigured CORS policy allows requests from any origin. What...
An application uses HTTP instead of HTTPS for sensitive operations....
A Redis instance is accessible remotely without password protection....
Jenkins servers left unsecured allow attackers to execute arbitrary...
Which HTTP method is most commonly left enabled on misconfigured web...
Which of the following is NOT a typical misconfiguration that leads to...
A web server is running with directory listing enabled. Attackers can...
An S3 bucket is configured with public read access. Which cloud...
SNMP community strings set to 'public' or 'private' allow attackers to...
A web application displays detailed error messages revealing the...
Which service typically runs on port 3306 and often has weak default...
An FTP server allows anonymous login without a password. This is an...
SMB shares that are world-readable without credentials represent which...
A database server is accessible over the network without...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!