ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 270 - PT0-002 discussion

Report
Export

A penetration tester is conducting an assessment against a group of publicly available web servers and notices a number of TCP resets returning from one of the web servers. Which of the following is MOST likely causing the TCP resets to occur during the assessment?

A.
The web server is using a WAF.
Answers
A.
The web server is using a WAF.
B.
The web server is behind a load balancer.
Answers
B.
The web server is behind a load balancer.
C.
The web server is redirecting the requests.
Answers
C.
The web server is redirecting the requests.
D.
The local antivirus on the web server Is rejecting the connection.
Answers
D.
The local antivirus on the web server Is rejecting the connection.
Suggested answer: A

Explanation:

A Web Application Firewall (WAF) is designed to monitor, filter or block traffic to a web application. A WAF will monitor incoming and outgoing traffic from a web application and is often used to protect web servers from attacks such as SQL Injection, Cross-Site Scripting (XSS), and other forms of attacks.

If a WAF detects an attack, it will often reset the TCP connection, causing the connection to be terminated. As a result, a penetration tester may see TCP resets when a WAF is present. Therefore, the most likely reason for the TCP resets returning from the web server is that the web server is using a WAF.

asked 02/10/2024
Hans Walter Katzengruber
27 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first