ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 90 - PT0-003 discussion

Report
Export

While conducting a peer review for a recent assessment, a penetration tester finds the debugging mode is still enabled for the production system. Which of the following is most likely responsible for this observation?

A.
Configuration changes were not reverted.
Answers
A.
Configuration changes were not reverted.
B.
A full backup restoration is required for the server.
Answers
B.
A full backup restoration is required for the server.
C.
The penetration test was not completed on time.
Answers
C.
The penetration test was not completed on time.
D.
The penetration tester was locked out of the system.
Answers
D.
The penetration tester was locked out of the system.
Suggested answer: A

Explanation:

Debugging Mode:

Purpose: Debugging mode provides detailed error messages and debugging information, useful during development.

Risk: In a production environment, it exposes sensitive information and vulnerabilities, making the system more susceptible to attacks.

Common Causes:

Configuration Changes: During testing or penetration testing, configurations might be altered to facilitate debugging. If not reverted, these changes can leave the system in a vulnerable state.

Oversight: Configuration changes might be overlooked during deployment.

Best Practices:

Deployment Checklist: Ensure a checklist is followed that includes reverting any debug configurations before moving to production.

Configuration Management: Use configuration management tools to track and manage changes.

Reference from Pentesting Literature:

The importance of reverting configuration changes is highlighted in penetration testing guides to prevent leaving systems in a vulnerable state post-testing.

HTB write-ups often mention checking and ensuring debugging modes are disabled in production environments.

Penetration Testing - A Hands-on Introduction to Hacking

HTB Official Writeups

asked 02/10/2024
josh hill
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first