ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 287 - PT0-002 discussion

Report
Export

During a penetration tester found a web component with no authentication requirements. The web component also allows file uploads and is hosted on one of the target public web the following actions should the penetration tester perform next?

A.
Continue the assessment and mark the finding as critical.
Answers
A.
Continue the assessment and mark the finding as critical.
B.
Attempting to remediate the issue temporally.
Answers
B.
Attempting to remediate the issue temporally.
C.
Notify the primary contact immediately.
Answers
C.
Notify the primary contact immediately.
D.
Shutting down the web server until the assessment is finished
Answers
D.
Shutting down the web server until the assessment is finished
Suggested answer: C

Explanation:

The penetration tester should notify the primary contact immediately, as this is a serious security issue that may compromise the confidentiality, integrity, and availability of the web server and its data. A web component with no authentication requirements and file upload capabilities can allow an attacker to upload malicious files, such as web shells, backdoors, or malware, to the web server and gain remote access or execute arbitrary commands on the web server. This can lead to further attacks, such as data theft, data corruption, privilege escalation, lateral movement, or denial of service. The penetration tester should inform the primary contact of the issue and its potential impact, and provide recommendations for remediation, such as implementing authentication mechanisms, restricting file upload types and sizes, or scanning uploaded files for malware. The other options are not appropriate actions for the penetration tester at this stage. Continuing the assessment and marking the finding as critical would delay the notification and remediation of the issue, which may increase the risk of exploitation by other attackers. Attempting to remediate the issue temporarily would interfere with the normal operation of the web server and may cause unintended consequences or damage. Shutting down the web server until the assessment is finished would disrupt the availability of the web server and its services, and may violate the scope or agreement of the assessment.

asked 02/10/2024
Jon Jones
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first