[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"me":3,"catalog:en:security\u002Fpt-vulnerability-assessment-vs-pentest":4,"config":232},null,{"field_key":5,"field_name":6,"seniority":7,"topic_key":8,"topic_name":9,"spec_key":7,"spec_name":7,"locale":10,"cell_total":11,"field_total":12,"seniorities":13,"topics":17,"specs":130,"samples":147},"security","Security","","pt-vulnerability-assessment-vs-pentest","Pt Vulnerability Assessment Vs Pentest","en",75,2850,[14,15,16],"junior","mid","senior",[18,21,24,27,30,33,36,39,42,45,48,51,54,57,60,63,66,69,72,75,78,81,84,87,90,93,96,99,102,105,106,109,112,115,118,121,124,127],{"key":19,"name":20,"count":11},"as-access-control-idor","As Access Control Idor",{"key":22,"name":23,"count":11},"as-api-security","As Api Security",{"key":25,"name":26,"count":11},"as-authentication-session","As Authentication Session",{"key":28,"name":29,"count":11},"as-crypto-implementation-pitfalls","As Crypto Implementation Pitfalls",{"key":31,"name":32,"count":11},"as-injection-input-validation","As Injection Input Validation",{"key":34,"name":35,"count":11},"as-secure-sdlc-sast-dast","As Secure Sdlc Sast Dast",{"key":37,"name":38,"count":11},"bt-crisis-communication-management","Bt Crisis Communication Management",{"key":40,"name":41,"count":11},"bt-detection-engineering-tuning","Bt Detection Engineering Tuning",{"key":43,"name":44,"count":11},"bt-digital-forensics-fundamentals","Bt Digital Forensics Fundamentals",{"key":46,"name":47,"count":11},"bt-incident-triage-classification","Bt Incident Triage Classification",{"key":49,"name":50,"count":11},"bt-ir-playbook-execution","Bt Ir Playbook Execution",{"key":52,"name":53,"count":11},"bt-threat-intelligence-application","Bt Threat Intelligence Application",{"key":55,"name":56,"count":11},"cse-container-workload-security","Cse Container Workload Security",{"key":58,"name":59,"count":11},"cse-cspm-misconfiguration","Cse Cspm Misconfiguration",{"key":61,"name":62,"count":11},"cse-data-protection-governance","Cse Data Protection Governance",{"key":64,"name":65,"count":11},"cse-detection-incident-response","Cse Detection Incident Response",{"key":67,"name":68,"count":11},"cse-iam-privilege-escalation","Cse Iam Privilege Escalation",{"key":70,"name":71,"count":11},"cse-network-perimeter-zero-trust","Cse Network Perimeter Zero Trust",{"key":73,"name":74,"count":11},"ds-iac-policy-as-code","Ds Iac Policy As Code",{"key":76,"name":77,"count":11},"ds-pipeline-security-gates","Ds Pipeline Security Gates",{"key":79,"name":80,"count":11},"ds-secrets-pipeline-management","Ds Secrets Pipeline Management",{"key":82,"name":83,"count":11},"ds-security-metrics-blameless-culture","Ds Security Metrics Blameless Culture",{"key":85,"name":86,"count":11},"ds-shift-left-security-culture","Ds Shift Left Security Culture",{"key":88,"name":89,"count":11},"ds-software-supply-chain-pipeline","Ds Software Supply Chain Pipeline",{"key":91,"name":92,"count":11},"pt-legal-ethical-boundaries","Pt Legal Ethical Boundaries",{"key":94,"name":95,"count":11},"pt-methodology-phases","Pt Methodology Phases",{"key":97,"name":98,"count":11},"pt-red-team-engagement-management","Pt Red Team Engagement Management",{"key":100,"name":101,"count":11},"pt-reporting-remediation-prioritization","Pt Reporting Remediation Prioritization",{"key":103,"name":104,"count":11},"pt-scoping-rules-of-engagement","Pt Scoping Rules Of Engagement",{"key":8,"name":9,"count":11},{"key":107,"name":108,"count":11},"security-authn-authz","Security Authn Authz",{"key":110,"name":111,"count":11},"security-cloud-infra-security","Security Cloud Infra Security",{"key":113,"name":114,"count":11},"security-compliance-risk","Security Compliance Risk",{"key":116,"name":117,"count":11},"security-cryptography-basics","Security Cryptography Basics",{"key":119,"name":120,"count":11},"security-incident-response","Security Incident Response",{"key":122,"name":123,"count":11},"security-network-security","Security Network Security",{"key":125,"name":126,"count":11},"security-secure-sdlc","Security Secure Sdlc",{"key":128,"name":129,"count":11},"security-web-vulnerabilities","Security Web Vulnerabilities",[131,135,138,141,144],{"key":132,"name":133,"count":134},"appsec","AppSec",450,{"key":136,"name":137,"count":134},"blue-team-incident","Blue Team \u002F Incident",{"key":139,"name":140,"count":134},"cloud-security","Cloud Security",{"key":142,"name":143,"count":134},"devsecops","DevSecOps",{"key":145,"name":146,"count":134},"offensive-pentest","Offensive \u002F Pentest",[148,166,179,192,205,218],{"id":149,"topic":9,"difficulty":150,"body":151,"options":152,"correct_key":157,"explanation":165},"019fadba-ffbb-796e-9e59-90cbac2d645e",1,"A company wants to know whether its systems have known, publicly documented weaknesses (like missing patches or outdated software versions). Which type of engagement is designed to answer exactly that question, at scale, on a recurring schedule?",[153,156,159,162],{"key":154,"text":155},"a","A red team engagement, because only adversary emulation can identify missing patches.",{"key":157,"text":158},"b","A vulnerability assessment (VA), because it uses automated scanning to compare systems against known vulnerability signatures.",{"key":160,"text":161},"c","A purple team workshop, because its structured collaborative sessions between attackers and defenders are designed to tune detection rules together, not to catalog missing patches across the fleet.",{"key":163,"text":164},"d","A safe-harbor legal review, because that document only covers authorization, not technical findings.","A vulnerability assessment is built for breadth and repeatability: automated scanners compare software versions and configurations against known-vulnerability databases across many hosts on a regular cadence. It does not attempt to prove exploitability the way a penetration test does.",{"id":167,"topic":9,"difficulty":150,"body":168,"options":169,"correct_key":160,"explanation":178},"019fadba-ffbc-7401-bc06-7d2b7e96b980","What is the main difference between a vulnerability assessment and a penetration test in terms of what each one proves?",[170,172,174,176],{"key":154,"text":171},"A vulnerability assessment definitively proves that a vulnerability is exploitable in the live production environment, while a pentest merely lists possible weaknesses without any hands-on validation.",{"key":157,"text":173},"There is no real difference; the two terms describe the same activity performed by different vendors.",{"key":160,"text":175},"A vulnerability assessment lists potential weaknesses found by scanning, while a pentest attempts to actively validate which of them can really be leveraged.",{"key":163,"text":177},"A vulnerability assessment always requires manual testing, while a pentest is always fully automated.","A VA produces a broad list of candidate issues from automated scanning, many of which may not be exploitable in practice. A pentest goes a step further and manually validates a subset of findings to confirm real-world impact and business risk.",{"id":180,"topic":9,"difficulty":150,"body":181,"options":182,"correct_key":154,"explanation":191},"019fadba-ffbe-71d2-b28a-048974683e44","A vulnerability scanner flags a web server as running an outdated software version with a known CVE. Before this finding is reported to the client as confirmed risk, what should happen first?",[183,185,187,189],{"key":154,"text":184},"Someone should verify whether the flagged version and configuration actually match the conditions required for that CVE to apply, since scanners can misidentify versions.",{"key":157,"text":186},"The finding should be published immediately, because automated scanner output is always accurate and needs no review.",{"key":160,"text":188},"The finding should be deleted immediately from every tracking system, because any automatically generated scanner result is assumed by default to be a false positive regardless of the specific CVE involved.",{"key":163,"text":190},"The client should be asked to patch the entire environment blindly without checking which system was actually flagged.","Scanners often rely on banner grabbing or version strings, which can be wrong or incomplete, leading to false positives. A quick verification step (checking the actual version, configuration, or exposure) avoids reporting non-issues as confirmed risk.",{"id":193,"topic":9,"difficulty":150,"body":194,"options":195,"correct_key":163,"explanation":204},"019fadba-ffbe-7b2b-9557-d8ce19d4c539","Which of the following best describes a 'false positive' in the context of a vulnerability scan?",[196,198,200,202],{"key":154,"text":197},"A real vulnerability that the scanner correctly identified from the start and that was later independently confirmed through careful manual penetration testing.",{"key":157,"text":199},"A vulnerability that exists but that the scanner failed to detect at all during the scan.",{"key":160,"text":201},"A finding that was intentionally hidden from the report because it was out of scope.",{"key":163,"text":203},"A finding the scanner reports as a vulnerability, but which does not actually exist or is not exploitable once checked manually.","A false positive is an incorrect alert: the tool reports a weakness that, upon closer inspection, is not really present or not actually exploitable in that context. Managing false positives well is central to keeping scan results trustworthy.",{"id":206,"topic":9,"difficulty":150,"body":207,"options":208,"correct_key":157,"explanation":217},"019fadba-ffbf-7395-be6d-2209d7288024","What is CVSS (Common Vulnerability Scoring System) primarily used for?",[209,211,213,215],{"key":154,"text":210},"It is a legal framework that defines which systems are in scope during a penetration test.",{"key":157,"text":212},"It is a standardized scoring system that expresses the technical severity of a vulnerability as a numeric score, helping teams compare and prioritize findings.",{"key":160,"text":214},"It is an exploit database that lists working attack code for every published CVE.",{"key":163,"text":216},"It is a mandatory government certification that a company must formally obtain and renew annually before regulators will ever allow it to run any red team exercise.","CVSS translates technical characteristics of a vulnerability (such as how it can be reached and what impact it has) into a numeric score, giving teams a common language to compare severity across many findings.",{"id":219,"topic":9,"difficulty":220,"body":221,"options":222,"correct_key":154,"explanation":231},"019fadba-ffbf-7f07-9cd3-9576cb4c1a6b",2,"A CVSS base score is meant to describe which aspect of a vulnerability?",[223,225,227,229],{"key":154,"text":224},"The intrinsic technical severity of the vulnerability itself, independent of whether it has been exploited in the wild or of a specific company's environment.",{"key":157,"text":226},"The exact financial loss a specific company will suffer if the vulnerability is exploited.",{"key":160,"text":228},"Whether the vulnerability has already been fixed by the vendor in the latest patch.",{"key":163,"text":230},"The specific personal legal liability that each individual security team member carries if a given finding is not formally reported to regulators within exactly 24 hours.","The base score captures characteristics that do not change over time or between deployments, such as how the vulnerability can be reached and what impact it can have. Temporal and environmental factors are handled separately and can adjust that base value.",{"fields":233,"seniorities":407,"interview_shapes":408,"locales":413,"oauth":415,"question_count":418,"coach_enabled":419,"jd_match_enabled":419},[234,259,279,296,320,333,352,371,381,388,394,401],{"key":235,"name_tr":236,"name_en":236,"sort":150,"specializations":237},"backend","Backend",[238,241,244,247,250,253,256],{"key":239,"name":240,"field":235},"general","Genel",{"key":242,"name":243,"field":235},"go","Go",{"key":245,"name":246,"field":235},"python","Python",{"key":248,"name":249,"field":235},"java","Java",{"key":251,"name":252,"field":235},"csharp","C#\u002F.NET",{"key":254,"name":255,"field":235},"nodejs","Node.js",{"key":257,"name":258,"field":235},"php","PHP",{"key":260,"name_tr":261,"name_en":261,"sort":220,"specializations":262},"frontend","Frontend",[263,264,267,270,273,276],{"key":239,"name":240,"field":260},{"key":265,"name":266,"field":260},"javascript","JavaScript",{"key":268,"name":269,"field":260},"typescript","TypeScript",{"key":271,"name":272,"field":260},"react","React",{"key":274,"name":275,"field":260},"vue","Vue",{"key":277,"name":278,"field":260},"angular","Angular",{"key":280,"name_tr":281,"name_en":281,"sort":282,"specializations":283},"fullstack","Fullstack",3,[284,285,286,287,288,289,290,291,292,293,294,295],{"key":239,"name":240,"field":280},{"key":242,"name":243,"field":235},{"key":245,"name":246,"field":235},{"key":248,"name":249,"field":235},{"key":251,"name":252,"field":235},{"key":254,"name":255,"field":235},{"key":257,"name":258,"field":235},{"key":265,"name":266,"field":260},{"key":268,"name":269,"field":260},{"key":271,"name":272,"field":260},{"key":274,"name":275,"field":260},{"key":277,"name":278,"field":260},{"key":297,"name_tr":298,"name_en":298,"sort":299,"specializations":300},"devops-cloud","DevOps \u002F Cloud",4,[301,302,305,308,311,314,317],{"key":239,"name":240,"field":297},{"key":303,"name":304,"field":297},"aws","AWS",{"key":306,"name":307,"field":297},"gcp","GCP",{"key":309,"name":310,"field":297},"azure","Azure",{"key":312,"name":313,"field":297},"kubernetes","Kubernetes",{"key":315,"name":316,"field":297},"terraform","Terraform",{"key":318,"name":319,"field":297},"linux","Linux",{"key":321,"name_tr":322,"name_en":322,"sort":323,"specializations":324},"ai-engineer","AI Engineer",5,[325,326,327,330],{"key":239,"name":240,"field":321},{"key":245,"name":246,"field":321},{"key":328,"name":329,"field":321},"llm-rag","LLM\u002FRAG",{"key":331,"name":332,"field":321},"mlops","MLOps",{"key":334,"name_tr":335,"name_en":336,"sort":337,"specializations":338},"database","Veritabanı","Database",6,[339,340,343,346,349],{"key":239,"name":240,"field":334},{"key":341,"name":342,"field":334},"postgresql","PostgreSQL",{"key":344,"name":345,"field":334},"mysql","MySQL",{"key":347,"name":348,"field":334},"mongodb","MongoDB",{"key":350,"name":351,"field":334},"redis","Redis",{"key":353,"name_tr":354,"name_en":355,"sort":356,"specializations":357},"mobile","Mobil","Mobile",7,[358,359,362,365,368],{"key":239,"name":240,"field":353},{"key":360,"name":361,"field":353},"ios-swift","iOS (Swift)",{"key":363,"name":364,"field":353},"android-kotlin","Android (Kotlin)",{"key":366,"name":367,"field":353},"flutter","Flutter",{"key":369,"name":370,"field":353},"react-native","React Native",{"key":5,"name_tr":372,"name_en":6,"sort":373,"specializations":374},"Güvenlik",8,[375,376,377,378,379,380],{"key":239,"name":240,"field":5},{"key":132,"name":133,"field":5},{"key":145,"name":146,"field":5},{"key":139,"name":140,"field":5},{"key":142,"name":143,"field":5},{"key":136,"name":137,"field":5},{"key":382,"name_tr":383,"name_en":384,"sort":385,"specializations":386},"qa-test-automation","QA \u002F Test Otomasyonu","QA \u002F Test Automation",9,[387],{"key":239,"name":240,"field":382},{"key":389,"name_tr":390,"name_en":390,"sort":391,"specializations":392},"data-engineer","Data Engineer",10,[393],{"key":239,"name":240,"field":389},{"key":395,"name_tr":396,"name_en":397,"sort":398,"specializations":399},"game-dev","Oyun Geliştirme","Game Development",11,[400],{"key":239,"name":240,"field":395},{"key":402,"name_tr":403,"name_en":403,"sort":404,"specializations":405},"ml-engineer","ML Engineer",12,[406],{"key":239,"name":240,"field":402},[14,15,16],{"junior":409,"mid":411,"senior":412},{"questions":410,"median_sec":3},20,{"questions":410,"median_sec":3},{"questions":410,"median_sec":3},[414,10],"tr",[416,417],"google","github",21750,true]