CompTIA PenTest+ Certification Exam PT0-002 Question # 62 Topic 7 Discussion

CompTIA PenTest+ Certification Exam PT0-002 Question # 62 Topic 7 Discussion

PT0-002 Exam Topic 7 Question 62 Discussion:
Question #: 62
Topic #: 7

A penetration tester is conducting an assessment of an organization that has both a web and mobile application. While testing the user profile page, the penetration tester notices that additional data is returned in the API response, which is not displayed in the web user interface. Which of the following is the most effective technique to extract sensitive user data?


A.

Compare PI I from data leaks to publicly exposed user profiles.


B.

Target the user profile page with a denial-of-service attack.


C.

Target the user profile page with a reflected XSS attack.


D.

Compare the API response fields to GUI fields looking for PH.


Get Premium PT0-002 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.