CompTIA PenTest+ Exam PT0-003 Question # 39 Topic 4 Discussion

CompTIA PenTest+ Exam PT0-003 Question # 39 Topic 4 Discussion

PT0-003 Exam Topic 4 Question 39 Discussion:
Question #: 39
Topic #: 4

A penetration tester is performing an assessment focused on attacking the authentication identity provider hosted within a cloud provider. During the reconnaissance phase, the tester finds that the system is using OpenID Connect with OAuth and has dynamic registration enabled. Which of the following attacks should the tester try first?


A.

A password-spraying attack against the authentication system


B.

A brute-force attack against the authentication system


C.

A replay attack against the authentication flow in the system


D.

A mask attack against the authentication system


Get Premium PT0-003 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.