ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 326 - PT0-002 discussion

Report
Export

A penetration tester is testing a company's public API and discovers that specific input allows the execution of arbitrary commands on the base operating system. Which of the following actions should the penetration tester take next?

A.
Include the findings in the final report.
Answers
A.
Include the findings in the final report.
B.
Notify the client immediately.
Answers
B.
Notify the client immediately.
C.
Document which commands can be executed.
Answers
C.
Document which commands can be executed.
D.
Use this feature to further compromise the server.
Answers
D.
Use this feature to further compromise the server.
Suggested answer: B

Explanation:

The Nmap command uses the Xmas scan technique, which sends packets with the FIN, PSH, and URG flags set. This is an attempt to bypass firewall rules and elicit a response from open ports. However, if the target responds with an RST packet, it means that the port is closed. Open ports will either ignore the Xmas scan packets or send back an ACK packet. Therefore, the information most likely indicates that all of the ports in the target range are closed.

Reference: [Nmap Scan Types], [Nmap Port Scanning Techniques], [CompTIA PenTest+ Study Guide: Exam PT0-002, Chapter 4: Conducting Passive Reconnaissance, page 127]

asked 02/10/2024
Chris OMalley
26 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first