ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 416 - PT0-002 discussion

Report
Export

As part of active reconnaissance, penetration testers need to determine whether a protection mechanism is in place to safeguard the target's website against web application attacks. Which of the following methods would be the most suitable?

A.
Direct-to-origin testing
Answers
A.
Direct-to-origin testing
B.
Antivirus scanning
Answers
B.
Antivirus scanning
C.
Scapy packet crafting
Answers
C.
Scapy packet crafting
D.
WAF detection
Answers
D.
WAF detection
Suggested answer: D

Explanation:

* Detecting a Web Application Firewall (WAF) helps penetration testers understand the protective measures in place and tailor their testing methods to bypass these defenses.

* Details:

A . Direct-to-origin testing: Useful for bypassing CDN but not specifically for detecting protective mechanisms like WAF.

B . Antivirus scanning: Not relevant for web application attacks.

C . Scapy packet crafting: Useful for network-level testing but not for detecting web application protections.

D . WAF detection: Identifies if a WAF is present, which is critical for understanding and bypassing web application defenses.

*

Reference: WAF detection techniques are documented in web application security testing methodologies such as OWASP.

asked 02/10/2024
Robert Petty
52 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first