ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 56 - PT0-003 discussion

Report
Export

A penetration tester is performing an authorized physical assessment. During the test, the tester observes an access control vestibule and on-site security guards near the entry door in the lobby. Which of the following is the best attack plan for the tester to use in order to gain access to the facility?

A.
Clone badge information in public areas of the facility to gain access to restricted areas.
Answers
A.
Clone badge information in public areas of the facility to gain access to restricted areas.
B.
Tailgate into the facility during a very busy time to gain initial access.
Answers
B.
Tailgate into the facility during a very busy time to gain initial access.
C.
Pick the lock on the rear entrance to gain access to the facility and try to gain access.
Answers
C.
Pick the lock on the rear entrance to gain access to the facility and try to gain access.
D.
Drop USB devices with malware outside of the facility in order to gain access to internal machines.
Answers
D.
Drop USB devices with malware outside of the facility in order to gain access to internal machines.
Suggested answer: B

Explanation:

In an authorized physical assessment, the goal is to test physical security controls. Tailgating is a common and effective technique in such scenarios. Here's why option B is correct:

Tailgating: This involves following an authorized person into a secure area without proper credentials. During busy times, it's easier to blend in and gain access without being noticed. It tests the effectiveness of physical access controls and security personnel.

Cloning Badge Information: This can be effective but requires proximity to employees and specialized equipment, making it more complex and time-consuming.

Picking Locks: This is a more invasive technique that carries higher risk and is less stealthy compared to tailgating.

Dropping USB Devices: This tests employee awareness and response to malicious devices but does not directly test physical access controls.

Reference from Pentest:

Writeup HTB: Demonstrates the effectiveness of social engineering and tailgating techniques in bypassing physical security measures.

Forge HTB: Highlights the use of non-invasive methods like tailgating to test physical security without causing damage or raising alarms.

Conclusion:

Option B, tailgating into the facility during a busy time, is the best attack plan to gain access to the facility in an authorized physical assessment.

asked 02/10/2024
Peter Unterasinger
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first