ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 346 - PT0-002 discussion

Report
Export

As part of an active reconnaissance, a penetration tester intercepts and analyzes network traffic, including API requests and responses. Which of the following can be gained by capturing and examining the API traffic?

A.
Assessing the performance of the network's API communication
Answers
A.
Assessing the performance of the network's API communication
B.
Identifying the token/authentication detail
Answers
B.
Identifying the token/authentication detail
C.
Enumerating all users of the application
Answers
C.
Enumerating all users of the application
D.
Extracting confidential user data from the intercepted API responses
Answers
D.
Extracting confidential user data from the intercepted API responses
Suggested answer: B

Explanation:

By intercepting and analyzing the API traffic, a penetration tester can gain valuable information about the authentication mechanism and the tokens used by the API. Tokens are typically used to identify and authorize users or applications that access the API. A penetration tester can use this information to perform attacks such as token hijacking, token tampering, or token replay. The other options are not directly related to the API traffic, but rather to the application logic or the network performance.

Reference:

* CompTIA PenTest+ Certification Exam Objectives, Domain 2.0 Attacks and Exploits, Objective 2.1: Given a scenario, exploit network-based vulnerabilities, Subobjective 2.1.3: Compare and contrast web server attacks, Subobjective 2.1.3.2: Authentication attacks.

* The Official CompTIA PenTest+ Instructor and Student Guides (PT0-002), Lesson 4: Exploiting Network Vulnerabilities, Topic 4.2: Exploiting Web Application Vulnerabilities, Topic 4.2.2: Authentication Attacks.

asked 02/10/2024
Lucile Jeanneret
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first