45 Tools · Pentest questions from the Security bank, written for Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd.
Free to start: the 2-minute IT readiness check — six questions and a result.
A.toolkit for TLS, certificates, and cryptographic operations from the command line
B.password-strength auditing tool that tests hashes against wordlists and rules
C.network scanner that discovers hosts, open ports, and running services
D.OpenSSL command that opens a TLS connection to inspect a server's certificate and handshake
Answer + AI explanation with Pro
2. Which command will network scanner that discovers hosts, open ports, and running services?
Junior
A.Nmap
B.tcpdump
C.nmap -sV
D.Metasploit
Answer + AI explanation with Pro
3. Which statement is correct?
Junior
A.Nmap — DNS lookup utility for querying name servers and inspecting DNS records
B.Nmap — network scanner that discovers hosts, open ports, and running services
C.Nmap — toolkit for TLS, certificates, and cryptographic operations from the command line
D.Nmap — open-source web application scanner and intercepting proxy for security testing
Answer + AI explanation with Pro
4. What does Wireshark do?
Junior
A.web server scanner that checks for outdated software and common misconfigurations
B.intercepting web proxy used to inspect and test HTTP(S) requests and responses
C.network scanner that discovers hosts, open ports, and running services
D.packet analyzer that captures and inspects network traffic for troubleshooting and analysis
Answer + AI explanation with Pro
5. Which command will packet analyzer that captures and inspects network traffic for troubleshooting and analysis?
Junior
A.Wireshark
B.OpenSSL
C.hashcat
D.OWASP ZAP
Answer + AI explanation with Pro
6. Which statement is correct?
Junior
A.Wireshark — password-strength auditing tool that tests hashes against wordlists and rules
B.Wireshark — commercial vulnerability scanner that assesses hosts for known weaknesses
C.Wireshark — packet analyzer that captures and inspects network traffic for troubleshooting and analysis
D.Wireshark — tool that automates detection of SQL injection in authorized testing
Answer + AI explanation with Pro
7. What does Burp Suite do?
Junior
A.exploitation framework used in authorized penetration tests to validate vulnerabilities
B.password-strength auditing tool that tests hashes against wordlists and rules
C.Nmap service/version detection that probes open ports to identify software versions
D.intercepting web proxy used to inspect and test HTTP(S) requests and responses
Answer + AI explanation with Pro
8. Which command will intercepting web proxy used to inspect and test HTTP(S) requests and responses?
Junior
A.sqlmap
B.Burp Suite
C.nmap -sV
D.Metasploit
Answer + AI explanation with Pro
9. Which statement is correct?
Junior
A.Burp Suite — exploitation framework used in authorized penetration tests to validate vulnerabilities
B.Burp Suite — intercepting web proxy used to inspect and test HTTP(S) requests and responses
C.Burp Suite — GPU-accelerated password-recovery tool used to audit password hash strength
D.Burp Suite — command-line packet capture tool for recording and filtering network traffic
Answer + AI explanation with Pro
10. What does OpenSSL do?
Junior
A.toolkit for TLS, certificates, and cryptographic operations from the command line
B.password-strength auditing tool that tests hashes against wordlists and rules
C.Nmap service/version detection that probes open ports to identify software versions
D.intercepting web proxy used to inspect and test HTTP(S) requests and responses
Answer + AI explanation with Pro
11. Which command will toolkit for TLS, certificates, and cryptographic operations from the command line?
Junior
A.sqlmap
B.Burp Suite
C.Nikto
D.OpenSSL
Answer + AI explanation with Pro
12. Which statement is correct?
Junior
A.OpenSSL — DNS lookup utility for querying name servers and inspecting DNS records
B.OpenSSL — intercepting web proxy used to inspect and test HTTP(S) requests and responses
C.OpenSSL — toolkit for TLS, certificates, and cryptographic operations from the command line
D.OpenSSL — OpenSSL command that opens a TLS connection to inspect a server's certificate and handshake
Answer + AI explanation with Pro
13. What does tcpdump do?
Junior
A.GPU-accelerated password-recovery tool used to audit password hash strength
B.command-line packet capture tool for recording and filtering network traffic
C.Nmap service/version detection that probes open ports to identify software versions
D.OpenSSL command that opens a TLS connection to inspect a server's certificate and handshake
Answer + AI explanation with Pro
14. Which command will command-line packet capture tool for recording and filtering network traffic?
Junior
A.tcpdump
B.openssl s_client
C.Nessus
D.Burp Suite
Answer + AI explanation with Pro
15. Which statement is correct?
Junior
A.tcpdump — network scanner that discovers hosts, open ports, and running services
B.tcpdump — packet analyzer that captures and inspects network traffic for troubleshooting and analysis
C.tcpdump — OpenSSL command that opens a TLS connection to inspect a server's certificate and handshake
D.tcpdump — command-line packet capture tool for recording and filtering network traffic
Answer + AI explanation with Pro
16. What does dig do?
Junior
A.exploitation framework used in authorized penetration tests to validate vulnerabilities
B.web server scanner that checks for outdated software and common misconfigurations
C.DNS lookup utility for querying name servers and inspecting DNS records
D.command-line packet capture tool for recording and filtering network traffic
Answer + AI explanation with Pro
17. Which command will DNS lookup utility for querying name servers and inspecting DNS records?
Junior
A.Wireshark
B.dig
C.sqlmap
D.nmap -sV
Answer + AI explanation with Pro
18. Which statement is correct?
Junior
A.dig — intercepting web proxy used to inspect and test HTTP(S) requests and responses
B.dig — password-strength auditing tool that tests hashes against wordlists and rules
C.dig — DNS lookup utility for querying name servers and inspecting DNS records
D.dig — OpenSSL command that opens a TLS connection to inspect a server's certificate and handshake
Answer + AI explanation with Pro
19. What does nmap -sV do?
Mid
A.tool that automates detection of SQL injection in authorized testing
B.OpenSSL command that opens a TLS connection to inspect a server's certificate and handshake
C.Nmap service/version detection that probes open ports to identify software versions
D.packet analyzer that captures and inspects network traffic for troubleshooting and analysis
Answer + AI explanation with Pro
20. Which command will Nmap service/version detection that probes open ports to identify software versions?
Mid
A.Metasploit
B.nmap -sV
C.John the Ripper
D.dig
Answer + AI explanation with Pro
21. Which statement is correct?
Mid
A.nmap -sV — intercepting web proxy used to inspect and test HTTP(S) requests and responses
B.nmap -sV — Nmap service/version detection that probes open ports to identify software versions
C.nmap -sV — commercial vulnerability scanner that assesses hosts for known weaknesses
D.nmap -sV — password-strength auditing tool that tests hashes against wordlists and rules
Answer + AI explanation with Pro
22. What does Metasploit do?
Mid
A.exploitation framework used in authorized penetration tests to validate vulnerabilities
B.network scanner that discovers hosts, open ports, and running services
C.toolkit for TLS, certificates, and cryptographic operations from the command line
D.tool that automates detection of SQL injection in authorized testing
Answer + AI explanation with Pro
23. Which command will exploitation framework used in authorized penetration tests to validate vulnerabilities?
Mid
A.Nikto
B.dig
C.Wireshark
D.Metasploit
Answer + AI explanation with Pro
24. Which statement is correct?
Mid
A.Metasploit — web server scanner that checks for outdated software and common misconfigurations
B.Metasploit — DNS lookup utility for querying name servers and inspecting DNS records
C.Metasploit — password-strength auditing tool that tests hashes against wordlists and rules
D.Metasploit — exploitation framework used in authorized penetration tests to validate vulnerabilities
Answer + AI explanation with Pro
25. What does Nikto do?
Mid
A.password-strength auditing tool that tests hashes against wordlists and rules
B.DNS lookup utility for querying name servers and inspecting DNS records
C.web server scanner that checks for outdated software and common misconfigurations
D.Nmap service/version detection that probes open ports to identify software versions
Answer + AI explanation with Pro
26. Which command will web server scanner that checks for outdated software and common misconfigurations?
Mid
A.Burp Suite
B.Nikto
C.dig
D.nmap -sV
Answer + AI explanation with Pro
27. Which statement is correct?
Mid
A.Nikto — toolkit for TLS, certificates, and cryptographic operations from the command line
B.Nikto — web server scanner that checks for outdated software and common misconfigurations
C.Nikto — OpenSSL command that opens a TLS connection to inspect a server's certificate and handshake
D.Nikto — intercepting web proxy used to inspect and test HTTP(S) requests and responses
Answer + AI explanation with Pro
28. What does sqlmap do?
Mid
A.command-line packet capture tool for recording and filtering network traffic
B.open-source web application scanner and intercepting proxy for security testing
C.web server scanner that checks for outdated software and common misconfigurations
D.tool that automates detection of SQL injection in authorized testing
Answer + AI explanation with Pro
29. Which command will tool that automates detection of SQL injection in authorized testing?
Mid
A.sqlmap
B.OpenSSL
C.Wireshark
D.Nmap
Answer + AI explanation with Pro
30. Which statement is correct?
Mid
A.sqlmap — web server scanner that checks for outdated software and common misconfigurations
B.sqlmap — OpenSSL command that opens a TLS connection to inspect a server's certificate and handshake
C.sqlmap — tool that automates detection of SQL injection in authorized testing
D.sqlmap — DNS lookup utility for querying name servers and inspecting DNS records
Answer + AI explanation with Pro
Showing 30 of 45 Tools · Pentest questions — the full set, with answers, explanations and an AI tutor on every question, is inside.
Free to start
Start with a free readiness check
Sign up free for the 2-minute IT readiness check and a scored result. Answers, explanations and the AI tutor on every Tools · Pentest question come with Pro.