ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 358 - PT0-002 discussion

Report
Export

A penetration tester is preparing a credential stuffing attack against a company's website. Which of the following can be used to passively get the most relevant information?

A.
Shodan
Answers
A.
Shodan
B.
BeEF
Answers
B.
BeEF
C.
HavelBeenPwned
Answers
C.
HavelBeenPwned
D.
Maltego
Answers
D.
Maltego
Suggested answer: C

Explanation:

HaveIBeenPwned is a website that allows users to check if their personal data has been compromised by data breaches. For a penetration tester preparing a credential stuffing attack, HaveIBeenPwned can provide valuable information about which accounts and passwords have been exposed, making them more likely targets for successful credential stuffing. This passive information gathering tool can help in identifying the most relevant credentials without actively probing the target's systems. The other tools listed (Shodan, BeEF, Maltego) serve different purposes, such as device and service enumeration, client-side exploitation, and information gathering through different means, respectively.

asked 02/10/2024
rafael Flores
52 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first