ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 64 - PT0-002 discussion

Report
Export

Which of the following should a penetration tester do NEXT after identifying that an application being tested has already been compromised with malware?

A.
Analyze the malware to see what it does.
Answers
A.
Analyze the malware to see what it does.
B.
Collect the proper evidence and then remove the malware.
Answers
B.
Collect the proper evidence and then remove the malware.
C.
Do a root-cause analysis to find out how the malware got in.
Answers
C.
Do a root-cause analysis to find out how the malware got in.
D.
Remove the malware immediately.
Answers
D.
Remove the malware immediately.
E.
Stop the assessment and inform the emergency contact.
Answers
E.
Stop the assessment and inform the emergency contact.
Suggested answer: E

Explanation:

Stopping the assessment and informing the emergency contact is the best thing to do next after identifying that an application being tested has already been compromised with malware. This is because continuing the assessment might interfere with an ongoing investigation or compromise evidence collection. The emergency contact is the person designated by the client who should be notified in case of any critical issues or incidents during the penetration testing engagement.

Reference: https://www.redteamsecure.com/blog/my-company-was-hacked-now-what

asked 02/10/2024
Maksim Alpatov
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first