問題1
A penetration tester noticed that an employee was using a wireless headset with a smartphone.
Which of the following methods would be best to use to intercept the communications?
A penetration tester noticed that an employee was using a wireless headset with a smartphone.
Which of the following methods would be best to use to intercept the communications?
正確答案: A
說明:(僅 NewDumps 成員可見)
問題2
A penetration tester would like to collect permission details for objects within the domain. The tester has a valid AD user and access to an internal PC. Which of the following sets of steps is the best way for the tester to accomplish the desired outcome?
A penetration tester would like to collect permission details for objects within the domain. The tester has a valid AD user and access to an internal PC. Which of the following sets of steps is the best way for the tester to accomplish the desired outcome?
正確答案: A
說明:(僅 NewDumps 成員可見)
問題3
A penetration tester wants to automatically enumerate all ciphers permitted on TLS/SSL configurations across a client's internet-facing and internal web servers. Which of the following tools or frameworks best supports this objective?
A penetration tester wants to automatically enumerate all ciphers permitted on TLS/SSL configurations across a client's internet-facing and internal web servers. Which of the following tools or frameworks best supports this objective?
正確答案: B
說明:(僅 NewDumps 成員可見)
問題4
A penetration tester gains initial access to a Windows workstation on a client's network. The tester wants to determine the next target but does not want to install software on the workstation.
Which of the following is the best tool to list potential targets?
A penetration tester gains initial access to a Windows workstation on a client's network. The tester wants to determine the next target but does not want to install software on the workstation.
Which of the following is the best tool to list potential targets?
正確答案: E
說明:(僅 NewDumps 成員可見)
問題5
A penetration tester wants to gather the names of potential phishing targets who have access to sensitive data. Which of the following would best meet this goal?
A penetration tester wants to gather the names of potential phishing targets who have access to sensitive data. Which of the following would best meet this goal?
正確答案: C
說明:(僅 NewDumps 成員可見)
問題6
After a recent penetration test was conducted by the company's penetration testing team, a systems administrator notices the following in the logs:
2/10/2023 05:50AM C:\users\mgranite\schtasks /query
2/10/2023 05:53AM C:\users\mgranite\schtasks /CREATE /SC DAILY
Which of the following best explains the team's objective?
After a recent penetration test was conducted by the company's penetration testing team, a systems administrator notices the following in the logs:
2/10/2023 05:50AM C:\users\mgranite\schtasks /query
2/10/2023 05:53AM C:\users\mgranite\schtasks /CREATE /SC DAILY
Which of the following best explains the team's objective?
正確答案: A
說明:(僅 NewDumps 成員可見)
問題7
During an external penetration test, a tester receives the following output from a tool:
test.comptia.org
info.comptia.org
vpn.comptia.org
exam.comptia.org
Which of the following commands did the tester most likely run to get these results?
During an external penetration test, a tester receives the following output from a tool:
test.comptia.org
info.comptia.org
vpn.comptia.org
exam.comptia.org
Which of the following commands did the tester most likely run to get these results?
正確答案: D
說明:(僅 NewDumps 成員可見)
問題8
A penetration tester identifies multiple connections to public LLMs. The client's IT team has not authorized the use of all of these LLMs. Which of the following best describes the risk to the client?
A penetration tester identifies multiple connections to public LLMs. The client's IT team has not authorized the use of all of these LLMs. Which of the following best describes the risk to the client?
正確答案: D
說明:(僅 NewDumps 成員可見)
問題9
During a penetration test, a tester has confirmed stored XSS within a comment form on a site.
Which of the following payloads is required to exploit the vulnerability and provide a reverse shell against user browsers?
During a penetration test, a tester has confirmed stored XSS within a comment form on a site.
Which of the following payloads is required to exploit the vulnerability and provide a reverse shell against user browsers?
正確答案: A
說明:(僅 NewDumps 成員可見)