ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 267 - PT0-002 discussion

Report
Export

During an assessment, a penetration tester gathered OSINT for one of the IT systems administrators from the target company and managed to obtain valuable information, including corporate email addresses. Which of the following techniques should the penetration tester perform NEXT?

A.
Badge cloning
Answers
A.
Badge cloning
B.
Watering-hole attack
Answers
B.
Watering-hole attack
C.
Impersonation
Answers
C.
Impersonation
D.
Spear phishing
Answers
D.
Spear phishing
Suggested answer: D

Explanation:

Spear phishing is a type of targeted attack where the attacker sends emails that appear to come from a legitimate source, often a company or someone familiar to the target, with the goal of tricking the target into clicking on a malicious link or providing sensitive information. In this case, the penetration tester has already gathered OSINT on the IT system administrator, so they can use this information to craft a highly targeted spear phishing attack to try and gain access to the target system.

asked 02/10/2024
Samantha Carpenter
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first