ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 129 - PT0-002 discussion

Report
Export

A security company has been contracted to perform a scoped insider-threat assessment to try to gain access to the human resources server that houses PII and salary data. The penetration testers have been given an internal network starting position.

Which of the following actions, if performed, would be ethical within the scope of the assessment?

A.
Exploiting a configuration weakness in the SQL database
Answers
A.
Exploiting a configuration weakness in the SQL database
B.
Intercepting outbound TLS traffic
Answers
B.
Intercepting outbound TLS traffic
C.
Gaining access to hosts by injecting malware into the enterprise-wide update server
Answers
C.
Gaining access to hosts by injecting malware into the enterprise-wide update server
D.
Leveraging a vulnerability on the internal CA to issue fraudulent client certificates
Answers
D.
Leveraging a vulnerability on the internal CA to issue fraudulent client certificates
E.
Establishing and maintaining persistence on the domain controller
Answers
E.
Establishing and maintaining persistence on the domain controller
Suggested answer: B
asked 02/10/2024
harinder giri
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first