ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 232 - PT0-002 discussion

Report
Export

A company provided the following network scope for a penetration test:

169.137.1.0/24

221.10.1.0/24

149.14.1.0/24

A penetration tester discovered a remote command injection on IP address 149.14.1.24 and exploited the system. Later, the tester learned that this particular IP address belongs to a third party.

Which of the following stakeholders is responsible for this mistake?

A.
The company that requested the penetration test
Answers
A.
The company that requested the penetration test
B.
The penetration testing company
Answers
B.
The penetration testing company
C.
The target host's owner
Answers
C.
The target host's owner
D.
The penetration tester
Answers
D.
The penetration tester
E.
The subcontractor supporting the test
Answers
E.
The subcontractor supporting the test
Suggested answer: A

Explanation:

The company that requested the penetration test is responsible for providing the correct and accurate network scope for the test. The network scope defines the boundaries and limitations of the test, such as which IP addresses, domains, systems, or networks are in scope or out of scope. If the company provided an incorrect network scope that included an IP address that belongs to a third party, then it is responsible for this mistake. The penetration testing company, the target host's owner, the penetration tester, and the subcontractor supporting the test are not responsible for this mistake, as they relied on the network scope provided by the company that requested the penetration test.

asked 02/10/2024
Lizbeth Perea Joseph
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first