List of questions
Related questions
Question 368 - PT0-002 discussion
A penetration tester is conducting an assessment of an organization that has both a web and mobile application. While testing the user profile page, the penetration tester notices that additional data is returned in the API response, which is not displayed in the web user interface. Which of the following is the most effective technique to extract sensitive user data?
A.
Compare PI I from data leaks to publicly exposed user profiles.
B.
Target the user profile page with a denial-of-service attack.
C.
Target the user profile page with a reflected XSS attack.
D.
Compare the API response fields to GUI fields looking for PH.
Your answer:
0 comments
Sorted by
Leave a comment first