Tools · Pentest interview questions

45 real Tools · Pentest questions from the Security bank, as asked in Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd — free to start.

1. What does Nmap do?

Junior
  1. A.toolkit for TLS, certificates, and cryptographic operations from the command line
  2. B.password-strength auditing tool that tests hashes against wordlists and rules
  3. C.network scanner that discovers hosts, open ports, and running services
  4. D.OpenSSL command that opens a TLS connection to inspect a server's certificate and handshake
Reveal the answer + AI explanation — free account

3. Which statement is correct?

Junior
  1. A.Nmap — DNS lookup utility for querying name servers and inspecting DNS records
  2. B.Nmap — network scanner that discovers hosts, open ports, and running services
  3. C.Nmap — toolkit for TLS, certificates, and cryptographic operations from the command line
  4. D.Nmap — open-source web application scanner and intercepting proxy for security testing
Reveal the answer + AI explanation — free account

4. What does Wireshark do?

Junior
  1. A.web server scanner that checks for outdated software and common misconfigurations
  2. B.intercepting web proxy used to inspect and test HTTP(S) requests and responses
  3. C.network scanner that discovers hosts, open ports, and running services
  4. D.packet analyzer that captures and inspects network traffic for troubleshooting and analysis
Reveal the answer + AI explanation — free account

6. Which statement is correct?

Junior
  1. A.Wireshark — password-strength auditing tool that tests hashes against wordlists and rules
  2. B.Wireshark — commercial vulnerability scanner that assesses hosts for known weaknesses
  3. C.Wireshark — packet analyzer that captures and inspects network traffic for troubleshooting and analysis
  4. D.Wireshark — tool that automates detection of SQL injection in authorized testing
Reveal the answer + AI explanation — free account

7. What does Burp Suite do?

Junior
  1. A.exploitation framework used in authorized penetration tests to validate vulnerabilities
  2. B.password-strength auditing tool that tests hashes against wordlists and rules
  3. C.Nmap service/version detection that probes open ports to identify software versions
  4. D.intercepting web proxy used to inspect and test HTTP(S) requests and responses
Reveal the answer + AI explanation — free account

9. Which statement is correct?

Junior
  1. A.Burp Suite — exploitation framework used in authorized penetration tests to validate vulnerabilities
  2. B.Burp Suite — intercepting web proxy used to inspect and test HTTP(S) requests and responses
  3. C.Burp Suite — GPU-accelerated password-recovery tool used to audit password hash strength
  4. D.Burp Suite — command-line packet capture tool for recording and filtering network traffic
Reveal the answer + AI explanation — free account

10. What does OpenSSL do?

Junior
  1. A.toolkit for TLS, certificates, and cryptographic operations from the command line
  2. B.password-strength auditing tool that tests hashes against wordlists and rules
  3. C.Nmap service/version detection that probes open ports to identify software versions
  4. D.intercepting web proxy used to inspect and test HTTP(S) requests and responses
Reveal the answer + AI explanation — free account

12. Which statement is correct?

Junior
  1. A.OpenSSL — DNS lookup utility for querying name servers and inspecting DNS records
  2. B.OpenSSL — intercepting web proxy used to inspect and test HTTP(S) requests and responses
  3. C.OpenSSL — toolkit for TLS, certificates, and cryptographic operations from the command line
  4. D.OpenSSL — OpenSSL command that opens a TLS connection to inspect a server's certificate and handshake
Reveal the answer + AI explanation — free account

13. What does tcpdump do?

Junior
  1. A.GPU-accelerated password-recovery tool used to audit password hash strength
  2. B.command-line packet capture tool for recording and filtering network traffic
  3. C.Nmap service/version detection that probes open ports to identify software versions
  4. D.OpenSSL command that opens a TLS connection to inspect a server's certificate and handshake
Reveal the answer + AI explanation — free account

15. Which statement is correct?

Junior
  1. A.tcpdump — network scanner that discovers hosts, open ports, and running services
  2. B.tcpdump — packet analyzer that captures and inspects network traffic for troubleshooting and analysis
  3. C.tcpdump — OpenSSL command that opens a TLS connection to inspect a server's certificate and handshake
  4. D.tcpdump — command-line packet capture tool for recording and filtering network traffic
Reveal the answer + AI explanation — free account

16. What does dig do?

Junior
  1. A.exploitation framework used in authorized penetration tests to validate vulnerabilities
  2. B.web server scanner that checks for outdated software and common misconfigurations
  3. C.DNS lookup utility for querying name servers and inspecting DNS records
  4. D.command-line packet capture tool for recording and filtering network traffic
Reveal the answer + AI explanation — free account

18. Which statement is correct?

Junior
  1. A.dig — intercepting web proxy used to inspect and test HTTP(S) requests and responses
  2. B.dig — password-strength auditing tool that tests hashes against wordlists and rules
  3. C.dig — DNS lookup utility for querying name servers and inspecting DNS records
  4. D.dig — OpenSSL command that opens a TLS connection to inspect a server's certificate and handshake
Reveal the answer + AI explanation — free account

19. What does nmap -sV do?

Mid
  1. A.tool that automates detection of SQL injection in authorized testing
  2. B.OpenSSL command that opens a TLS connection to inspect a server's certificate and handshake
  3. C.Nmap service/version detection that probes open ports to identify software versions
  4. D.packet analyzer that captures and inspects network traffic for troubleshooting and analysis
Reveal the answer + AI explanation — free account

21. Which statement is correct?

Mid
  1. A.nmap -sV — intercepting web proxy used to inspect and test HTTP(S) requests and responses
  2. B.nmap -sV — Nmap service/version detection that probes open ports to identify software versions
  3. C.nmap -sV — commercial vulnerability scanner that assesses hosts for known weaknesses
  4. D.nmap -sV — password-strength auditing tool that tests hashes against wordlists and rules
Reveal the answer + AI explanation — free account

22. What does Metasploit do?

Mid
  1. A.exploitation framework used in authorized penetration tests to validate vulnerabilities
  2. B.network scanner that discovers hosts, open ports, and running services
  3. C.toolkit for TLS, certificates, and cryptographic operations from the command line
  4. D.tool that automates detection of SQL injection in authorized testing
Reveal the answer + AI explanation — free account

24. Which statement is correct?

Mid
  1. A.Metasploit — web server scanner that checks for outdated software and common misconfigurations
  2. B.Metasploit — DNS lookup utility for querying name servers and inspecting DNS records
  3. C.Metasploit — password-strength auditing tool that tests hashes against wordlists and rules
  4. D.Metasploit — exploitation framework used in authorized penetration tests to validate vulnerabilities
Reveal the answer + AI explanation — free account

25. What does Nikto do?

Mid
  1. A.password-strength auditing tool that tests hashes against wordlists and rules
  2. B.DNS lookup utility for querying name servers and inspecting DNS records
  3. C.web server scanner that checks for outdated software and common misconfigurations
  4. D.Nmap service/version detection that probes open ports to identify software versions
Reveal the answer + AI explanation — free account

27. Which statement is correct?

Mid
  1. A.Nikto — toolkit for TLS, certificates, and cryptographic operations from the command line
  2. B.Nikto — web server scanner that checks for outdated software and common misconfigurations
  3. C.Nikto — OpenSSL command that opens a TLS connection to inspect a server's certificate and handshake
  4. D.Nikto — intercepting web proxy used to inspect and test HTTP(S) requests and responses
Reveal the answer + AI explanation — free account

28. What does sqlmap do?

Mid
  1. A.command-line packet capture tool for recording and filtering network traffic
  2. B.open-source web application scanner and intercepting proxy for security testing
  3. C.web server scanner that checks for outdated software and common misconfigurations
  4. D.tool that automates detection of SQL injection in authorized testing
Reveal the answer + AI explanation — free account

30. Which statement is correct?

Mid
  1. A.sqlmap — web server scanner that checks for outdated software and common misconfigurations
  2. B.sqlmap — OpenSSL command that opens a TLS connection to inspect a server's certificate and handshake
  3. C.sqlmap — tool that automates detection of SQL injection in authorized testing
  4. D.sqlmap — DNS lookup utility for querying name servers and inspecting DNS records
Reveal the answer + AI explanation — free account

Showing 30 of 45 Tools · Pentest questions — the full set, with answers, explanations and an AI tutor on every question, is inside.

Free to start

Answers, AI explanations, and a scored voice mock interview

Sign up free to check your answers with explanations, ask the AI tutor anything on any question, and take one full AI mock interview — scored like a real panel.

Practice Tools · Pentest free