Why is an intentionally vulnerable VM such as Metasploitable2 appropriate for learning penetration testing?
It grants permission to scan any unrelated Internet host
It teaches testing without any network communication
It is intended to host production data securely
It provides a controlled, authorized target designed for security practice