An unhandled error has occurred. Reload X
Ir al contenido principal

eLearnSecurity Junior Penetration Tester (eJPT) Practice Test

140 preguntas disponibles

The eLearnSecurity Junior Penetration Tester (eJPT) certification is a foundational, performance-based credential designed to validate the essential skills required for entry-level penetration testing roles. Administered by INE Security, this certification focuses on practical, hands-on abilities rather than theoretical knowledge alone. Candidates demonstrate proficiency in conducting a complete penetration test, from initial reconnaissance and information gathering to exploitation, post-exploitation, and professional report writing. The exam simulates a real-world network environment, requiring test-takers to apply methodologies learned in the associated PTS (Penetration Testing Student) training path. The eJPT is widely recognized as an excellent entry point into the cybersecurity field, providing tangible proof of a candidate's ability to perform basic offensive security tasks. It bridges the gap between academic knowledge and job-ready skills, making certified individuals immediately valuable to security teams. The certification's emphasis on a holistic attack chain and reporting makes it particularly relevant for roles such as Security Analyst, Junior Penetration Tester, and Vulnerability Assessment Specialist.

Examen de certificación
48 horas Límite de Tiempo
Banco de práctica
140 Preguntas de Práctica
2 horas 20 minutos Tiempo de Práctica
Comenzar Práctica
El banco 140 Preguntas de práctica verificadas con los objetivos oficiales.
eLearnSecurity140 preguntas de práctica2 respuestas con una referencia verificableTemario 1.0Banco actualizado el 2026-05-04

Preguntas de Muestra

Prueba algunas preguntas para ver cómo es el examen completo.

2 de 140 respuestas incluyen una referencia verificable.

Scanning & Vulnerability Assessment

During an authorized pentest, you are comparing Nessus and manual scanning results. Nessus flags port 3389/tcp with "Remote Desktop Protocol (RDP) Enabled" as Informational severity. You then manually test with `xfreerdp /v:10.10.10.80 /u:Administrator /p:'' ` and it connects with an empty password. Why did Nessus rate this as Informational while the empty-password RDP access represents a Critical finding?

Scanning & Vulnerability Assessment

You are performing an authorized pentest and use `nmap -T1 -sS 10.10.10.100` with Timing Template 1 (Sneaky). The scan is very slow. A colleague asks why you would use -T1 in an authorized assessment. What is the correct justification?

Scanning & Vulnerability Assessment

During an authorized pentest, you discover a service running on TCP port 5985. Nmap identifies it as `Microsoft WinRM (Windows Remote Management)`. What does this service enable, and which tool is commonly used to interact with it during a post-exploitation phase?

Scanning & Vulnerability Assessment

During an authorized assessment, you run `nmap -sV --script=smtp-commands 10.10.10.70 -p 25`. The NSE script output includes: `VRFY, EXPN, RCPT, STARTTLS`. You then test EXPN with `nc 10.10.10.70 25` and type `EXPN admin`. The server responds with `[email protected], [email protected]`. What does the EXPN command reveal, and how does it differ from VRFY?

System & Network Penetration Testing

During an authorized pentest, you achieve initial access via a phishing payload and have a low-privilege Windows shell. You run `whoami /priv` and see `SeImpersonatePrivilege` is enabled. What privilege escalation technique does this enable, which tools implement it, and what type of account typically has this privilege?

Plan de Estudio

Cada dominio está ponderado para coincidir con el examen de certificación real, por lo que una simulación de práctica completa predice tu resultado.

01Host and Network Penetration TestingIdentify and modify exploits, Conduct exploitation with metasploit, Demonstrate pivoting by adding a route and by port forwarding, Conduct brute-force password attacks and hash cracking
35%
02Assessment MethodologiesLocate endpoints on a network, Identify open ports and services on a target, Identify operating system of a target, Extract company information from public sources, Gather email addresses from public sources, Gather technical information from public sources
25%
03Host and Networking AuditingCompile information from files on target, Enumerate network information from files on target, Enumerate system information on target, Gather user account information on target, Transfer files to and from target, Gather hash/password information from target
25%
04Web Application Penetration TestingIdentify vulnerabilities in web applications, Locate hidden file and directories, Conduct brute-force login attack, Conduct web application reconnaissance
15%

Detalles del Examen eJPT | 48 horas

Preguntas Frecuentes

¿Cuáles son los requisitos previos para intentar la certificación eJPT?

¿Cómo difiere el formato del examen eJPT de las pruebas tradicionales de opción múltiple?

¿Es el eJPT un buen precursor para el OSCP (Offensive Security Certified Professional)?

¿Cuál es el valor profesional del eJPT para alguien sin experiencia previa en seguridad informática?

¿Qué temas son más críticos para dominar para el examen eJPT?