ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 230 - PT0-002 discussion

Report
Export

A penetration tester gives the following command to a systems administrator to execute on one of the target servers:

rm -f /var/www/html/G679h32gYu.php

Which of the following BEST explains why the penetration tester wants this command executed?

A.
To trick the systems administrator into installing a rootkit
Answers
A.
To trick the systems administrator into installing a rootkit
B.
To close down a reverse shell
Answers
B.
To close down a reverse shell
C.
To remove a web shell after the penetration test
Answers
C.
To remove a web shell after the penetration test
D.
To delete credentials the tester created
Answers
D.
To delete credentials the tester created
Suggested answer: C

Explanation:

A web shell is a malicious script that allows remote access and control of a web server. A penetration tester may use a web shell to execute commands on the target server during a penetration test. However, after the test is completed, the penetration tester should remove the web shell to avoid leaving any traces or backdoors on the server. The command rm -f /var/www/html/G679h32gYu.php deletes the file G679h32gYu.php from the web server's document root directory, which is likely the location of the web shell. The other options are not plausible explanations for why the penetration tester wants this command executed.

asked 02/10/2024
Krishnan S Sridhar
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first