ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 52 - PT0-002 discussion

Report
Export

A penetration tester was conducting a penetration test and discovered the network traffic was no longer reaching the client's IP address. The tester later discovered the SOC had used sinkholing on the penetration tester's IP address. Which of the following BEST describes what happened?

A.
The penetration tester was testing the wrong assets
Answers
A.
The penetration tester was testing the wrong assets
B.
The planning process failed to ensure all teams were notified
Answers
B.
The planning process failed to ensure all teams were notified
C.
The client was not ready for the assessment to start
Answers
C.
The client was not ready for the assessment to start
D.
The penetration tester had incorrect contact information
Answers
D.
The penetration tester had incorrect contact information
Suggested answer: B

Explanation:

Sinkholing is a technique used by security teams to redirect malicious or unwanted network traffic to a controlled destination, such as a black hole or a honeypot. This can help prevent or mitigate attacks, analyze malware behavior, or isolate infected hosts. If the SOC used sinkholing on the penetration tester's IP address, it means that they detected the tester's activity and blocked it from reaching the client's network. This indicates that the planning process failed to ensure all teams were notified about the penetration testing engagement, which could have avoided this situation.

asked 02/10/2024
Tanner Blair
31 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first