Tools · Pentest interview questions

45 Tools · Pentest questions from the Security bank, written for Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd.

Free to start: the 2-minute IT readiness check — six questions and a result.

Take the free IT readiness check

or take a mock interview set up for this area

1. What does Nmap do?

Junior
  1. A.toolkit for TLS, certificates, and cryptographic operations from the command line
  2. B.password-strength auditing tool that tests hashes against wordlists and rules
  3. C.network scanner that discovers hosts, open ports, and running services
  4. D.OpenSSL command that opens a TLS connection to inspect a server's certificate and handshake

Answer + AI explanation with Pro

2. Which command will network scanner that discovers hosts, open ports, and running services?

Junior
  1. A.Nmap
  2. B.tcpdump
  3. C.nmap -sV
  4. D.Metasploit

Answer + AI explanation with Pro

3. Which statement is correct?

Junior
  1. A.Nmap — DNS lookup utility for querying name servers and inspecting DNS records
  2. B.Nmap — network scanner that discovers hosts, open ports, and running services
  3. C.Nmap — toolkit for TLS, certificates, and cryptographic operations from the command line
  4. D.Nmap — open-source web application scanner and intercepting proxy for security testing

Answer + AI explanation with Pro

4. What does Wireshark do?

Junior
  1. A.web server scanner that checks for outdated software and common misconfigurations
  2. B.intercepting web proxy used to inspect and test HTTP(S) requests and responses
  3. C.network scanner that discovers hosts, open ports, and running services
  4. D.packet analyzer that captures and inspects network traffic for troubleshooting and analysis

Answer + AI explanation with Pro

5. Which command will packet analyzer that captures and inspects network traffic for troubleshooting and analysis?

Junior
  1. A.Wireshark
  2. B.OpenSSL
  3. C.hashcat
  4. D.OWASP ZAP

Answer + AI explanation with Pro

6. Which statement is correct?

Junior
  1. A.Wireshark — password-strength auditing tool that tests hashes against wordlists and rules
  2. B.Wireshark — commercial vulnerability scanner that assesses hosts for known weaknesses
  3. C.Wireshark — packet analyzer that captures and inspects network traffic for troubleshooting and analysis
  4. D.Wireshark — tool that automates detection of SQL injection in authorized testing

Answer + AI explanation with Pro

7. What does Burp Suite do?

Junior
  1. A.exploitation framework used in authorized penetration tests to validate vulnerabilities
  2. B.password-strength auditing tool that tests hashes against wordlists and rules
  3. C.Nmap service/version detection that probes open ports to identify software versions
  4. D.intercepting web proxy used to inspect and test HTTP(S) requests and responses

Answer + AI explanation with Pro

8. Which command will intercepting web proxy used to inspect and test HTTP(S) requests and responses?

Junior
  1. A.sqlmap
  2. B.Burp Suite
  3. C.nmap -sV
  4. D.Metasploit

Answer + AI explanation with Pro

9. Which statement is correct?

Junior
  1. A.Burp Suite — exploitation framework used in authorized penetration tests to validate vulnerabilities
  2. B.Burp Suite — intercepting web proxy used to inspect and test HTTP(S) requests and responses
  3. C.Burp Suite — GPU-accelerated password-recovery tool used to audit password hash strength
  4. D.Burp Suite — command-line packet capture tool for recording and filtering network traffic

Answer + AI explanation with Pro

10. What does OpenSSL do?

Junior
  1. A.toolkit for TLS, certificates, and cryptographic operations from the command line
  2. B.password-strength auditing tool that tests hashes against wordlists and rules
  3. C.Nmap service/version detection that probes open ports to identify software versions
  4. D.intercepting web proxy used to inspect and test HTTP(S) requests and responses

Answer + AI explanation with Pro

11. Which command will toolkit for TLS, certificates, and cryptographic operations from the command line?

Junior
  1. A.sqlmap
  2. B.Burp Suite
  3. C.Nikto
  4. D.OpenSSL

Answer + AI explanation with Pro

12. Which statement is correct?

Junior
  1. A.OpenSSL — DNS lookup utility for querying name servers and inspecting DNS records
  2. B.OpenSSL — intercepting web proxy used to inspect and test HTTP(S) requests and responses
  3. C.OpenSSL — toolkit for TLS, certificates, and cryptographic operations from the command line
  4. D.OpenSSL — OpenSSL command that opens a TLS connection to inspect a server's certificate and handshake

Answer + AI explanation with Pro

13. What does tcpdump do?

Junior
  1. A.GPU-accelerated password-recovery tool used to audit password hash strength
  2. B.command-line packet capture tool for recording and filtering network traffic
  3. C.Nmap service/version detection that probes open ports to identify software versions
  4. D.OpenSSL command that opens a TLS connection to inspect a server's certificate and handshake

Answer + AI explanation with Pro

14. Which command will command-line packet capture tool for recording and filtering network traffic?

Junior
  1. A.tcpdump
  2. B.openssl s_client
  3. C.Nessus
  4. D.Burp Suite

Answer + AI explanation with Pro

15. Which statement is correct?

Junior
  1. A.tcpdump — network scanner that discovers hosts, open ports, and running services
  2. B.tcpdump — packet analyzer that captures and inspects network traffic for troubleshooting and analysis
  3. C.tcpdump — OpenSSL command that opens a TLS connection to inspect a server's certificate and handshake
  4. D.tcpdump — command-line packet capture tool for recording and filtering network traffic

Answer + AI explanation with Pro

16. What does dig do?

Junior
  1. A.exploitation framework used in authorized penetration tests to validate vulnerabilities
  2. B.web server scanner that checks for outdated software and common misconfigurations
  3. C.DNS lookup utility for querying name servers and inspecting DNS records
  4. D.command-line packet capture tool for recording and filtering network traffic

Answer + AI explanation with Pro

17. Which command will DNS lookup utility for querying name servers and inspecting DNS records?

Junior
  1. A.Wireshark
  2. B.dig
  3. C.sqlmap
  4. D.nmap -sV

Answer + AI explanation with Pro

18. Which statement is correct?

Junior
  1. A.dig — intercepting web proxy used to inspect and test HTTP(S) requests and responses
  2. B.dig — password-strength auditing tool that tests hashes against wordlists and rules
  3. C.dig — DNS lookup utility for querying name servers and inspecting DNS records
  4. D.dig — OpenSSL command that opens a TLS connection to inspect a server's certificate and handshake

Answer + AI explanation with Pro

19. What does nmap -sV do?

Mid
  1. A.tool that automates detection of SQL injection in authorized testing
  2. B.OpenSSL command that opens a TLS connection to inspect a server's certificate and handshake
  3. C.Nmap service/version detection that probes open ports to identify software versions
  4. D.packet analyzer that captures and inspects network traffic for troubleshooting and analysis

Answer + AI explanation with Pro

20. Which command will Nmap service/version detection that probes open ports to identify software versions?

Mid
  1. A.Metasploit
  2. B.nmap -sV
  3. C.John the Ripper
  4. D.dig

Answer + AI explanation with Pro

21. Which statement is correct?

Mid
  1. A.nmap -sV — intercepting web proxy used to inspect and test HTTP(S) requests and responses
  2. B.nmap -sV — Nmap service/version detection that probes open ports to identify software versions
  3. C.nmap -sV — commercial vulnerability scanner that assesses hosts for known weaknesses
  4. D.nmap -sV — password-strength auditing tool that tests hashes against wordlists and rules

Answer + AI explanation with Pro

22. What does Metasploit do?

Mid
  1. A.exploitation framework used in authorized penetration tests to validate vulnerabilities
  2. B.network scanner that discovers hosts, open ports, and running services
  3. C.toolkit for TLS, certificates, and cryptographic operations from the command line
  4. D.tool that automates detection of SQL injection in authorized testing

Answer + AI explanation with Pro

23. Which command will exploitation framework used in authorized penetration tests to validate vulnerabilities?

Mid
  1. A.Nikto
  2. B.dig
  3. C.Wireshark
  4. D.Metasploit

Answer + AI explanation with Pro

24. Which statement is correct?

Mid
  1. A.Metasploit — web server scanner that checks for outdated software and common misconfigurations
  2. B.Metasploit — DNS lookup utility for querying name servers and inspecting DNS records
  3. C.Metasploit — password-strength auditing tool that tests hashes against wordlists and rules
  4. D.Metasploit — exploitation framework used in authorized penetration tests to validate vulnerabilities

Answer + AI explanation with Pro

25. What does Nikto do?

Mid
  1. A.password-strength auditing tool that tests hashes against wordlists and rules
  2. B.DNS lookup utility for querying name servers and inspecting DNS records
  3. C.web server scanner that checks for outdated software and common misconfigurations
  4. D.Nmap service/version detection that probes open ports to identify software versions

Answer + AI explanation with Pro

26. Which command will web server scanner that checks for outdated software and common misconfigurations?

Mid
  1. A.Burp Suite
  2. B.Nikto
  3. C.dig
  4. D.nmap -sV

Answer + AI explanation with Pro

27. Which statement is correct?

Mid
  1. A.Nikto — toolkit for TLS, certificates, and cryptographic operations from the command line
  2. B.Nikto — web server scanner that checks for outdated software and common misconfigurations
  3. C.Nikto — OpenSSL command that opens a TLS connection to inspect a server's certificate and handshake
  4. D.Nikto — intercepting web proxy used to inspect and test HTTP(S) requests and responses

Answer + AI explanation with Pro

28. What does sqlmap do?

Mid
  1. A.command-line packet capture tool for recording and filtering network traffic
  2. B.open-source web application scanner and intercepting proxy for security testing
  3. C.web server scanner that checks for outdated software and common misconfigurations
  4. D.tool that automates detection of SQL injection in authorized testing

Answer + AI explanation with Pro

29. Which command will tool that automates detection of SQL injection in authorized testing?

Mid
  1. A.sqlmap
  2. B.OpenSSL
  3. C.Wireshark
  4. D.Nmap

Answer + AI explanation with Pro

30. Which statement is correct?

Mid
  1. A.sqlmap — web server scanner that checks for outdated software and common misconfigurations
  2. B.sqlmap — OpenSSL command that opens a TLS connection to inspect a server's certificate and handshake
  3. C.sqlmap — tool that automates detection of SQL injection in authorized testing
  4. D.sqlmap — DNS lookup utility for querying name servers and inspecting DNS records

Answer + AI explanation with Pro

Showing 30 of 45 Tools · Pentest questions — the full set, with answers, explanations and an AI tutor on every question, is inside.

Free to start

Start with a free readiness check

Sign up free for the 2-minute IT readiness check and a scored result. Answers, explanations and the AI tutor on every Tools · Pentest question come with Pro.

Take the free IT readiness check

or take a mock interview set up for this area

24,000+ questions & coding problemsSoftware & IT16,274 questionsGovernment jobs26 examsAptitudenew questions every timeAI practice interviewwith feedback65 topics to practiseMechanical1,149 questionsGATE ME9 papersEngineering Mathematics381 questions2-minute checkfreeDSA Problems1,422Civil1,005 questionsGATE CE9 papersCS Fundamentals1,209 questionsYour scores6 skillsSystem Design25Electrical / EEE1,047 questionsGATE EE9 papersRun your codeC++ · Java · PythonLow-Level Design144Electronics & Comm.975 questionsGATE EC9 papersAI help on every questionFull-Stack6,282Chemical1,005 questionsGATE CH9 papersAI whiteboardsystem designWork abroadEurope · remote · transfersESE ME1 paperGATE practice papers2019–2026ESE CE1 paperDate alertsbefore the last dateESE EE1 paperBehavioural courseHR round practiceESE ET1 paperResume optimizerProSSC JE ME1 paperApplication trackerSSC JE CE1 paperCompany-wise prepSSC JE EE1 paperRole roadmapsRRB JE1 subjectPriced in ₹UPI · cardsISRO SC1 paperGATE CS9 papersIBPS SO IT1 paperUGC NET CS1 paperSSC CGL26 papersIBPS PO26 papersRRB NTPC26 papersSSC CHSL26 papersIBPS Clerk26 papersSBI Clerk26 papersRRB Group D26 papersSSC CPO26 papersSSC GD26 papers