ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 284 - SY0-601 discussion

Report
Export

A security analyst is investigating a report from a penetration test. During the penetration test, consultants were able to download sensitive data from a back-end server. The back-end server was exposing an API that should have only been available from the companVs mobile application. After reviewing the back-end server logs, the security analyst finds the following entries

Which of the following is the most likely cause of the security control bypass?

A.
IP address allow list
Answers
A.
IP address allow list
B.
user-agent spoofing
Answers
B.
user-agent spoofing
C.
WAF bypass
Answers
C.
WAF bypass
D.
Referrer manipulation
Answers
D.
Referrer manipulation
Suggested answer: B

Explanation:

User-agent spoofing is a technique that allows an attacker to modify the user-agent header of an HTTP request to impersonate another browser or device12. User-agent spoofing can be used to bypass security controls that rely on user-agent filtering or validation12. In this case, the attacker spoofed the user-agent header to match the company’s mobile application, which was allowed to access the back-end server’s API2.

asked 02/10/2024
Aidan Lear
49 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first