ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 220 - PT0-002 discussion

Report
Export

The following output is from reconnaissance on a public-facing banking website:

Based on these results, which of the following attacks is MOST likely to succeed?

A.
A birthday attack on 64-bit ciphers (Sweet32)
Answers
A.
A birthday attack on 64-bit ciphers (Sweet32)
B.
An attack that breaks RC4 encryption
Answers
B.
An attack that breaks RC4 encryption
C.
An attack on a session ticket extension (Ticketbleed)
Answers
C.
An attack on a session ticket extension (Ticketbleed)
D.
A Heartbleed attack
Answers
D.
A Heartbleed attack
Suggested answer: D

Explanation:

Based on these results, the most likely attack to succeed is a Heartbleed attack. The Heartbleed attack is a vulnerability in the OpenSSL implementation of the TLS/SSL protocol that allows an attacker to read the memory of the server and potentially steal sensitive information, such as private keys, passwords, or session tokens. The results show that the website is using OpenSSL 1.0.1f, which is vulnerable to the Heartbleed attack1.

asked 02/10/2024
Guillermo Fontaine
47 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first