ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 293 - PT0-002 discussion

Report
Export

During enumeration, a red team discovered that an external web server was frequented by employees. After compromising the server, which of the following attacks would best support ---------

---company systems?

A.
Aside-channel attack
Answers
A.
Aside-channel attack
B.
A command injection attack
Answers
B.
A command injection attack
C.
A watering-hole attack
Answers
C.
A watering-hole attack
D.
A cross-site scripting attack
Answers
D.
A cross-site scripting attack
Suggested answer: C

Explanation:

The best attack that would support compromising company systems after compromising an external web server frequented by employees is a watering-hole attack, which is an attack that involves compromising a website that is visited by a specific group of users, such as employees of a target company, and injecting malicious code or content into the website that can infect or exploit the users' devices when they visit the website. A watering-hole attack can allow an attacker to compromise company systems by targeting their employees who frequent the external web server, and taking advantage of their trust or habit of visiting the website. A watering-hole attack can be performed by using tools such as BeEF, which is a tool that can hook web browsers and execute commands on them2. The other options are not likely attacks that would support compromising company systems after compromising an external web server frequented by employees. A sidechannel attack is an attack that involves exploiting physical characteristics or implementation flaws of a system or device, such as power consumption, electromagnetic radiation, timing, or sound, to extract sensitive information or bypass security mechanisms. A command injection attack is an attack that exploits a vulnerability in a system or application that allows an attacker to execute arbitrary commands on the underlying OS or shell. A cross-site scripting attack is an attack that exploits a vulnerability in a web application that allows an attacker to inject malicious scripts into web pages that are viewed by other users.

asked 02/10/2024
Floran Pikaar
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first