PT0-002 Exam Question 41

An Nmap network scan has found five open ports with identified services. Which of the following tools should a penetration tester use NEXT to determine if any vulnerabilities with associated exploits exist on the open ports?
  • PT0-002 Exam Question 42

    During a penetration test, you gain access to a system with a limited user interface. This machine appears to have access to an isolated network that you would like to port scan.
    INSTRUCTIONS
    Analyze the code segments to determine which sections are needed to complete a port scanning script.
    Drag the appropriate elements into the correct locations to complete the script.
    If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

    PT0-002 Exam Question 43

    A penetration tester is reviewing the following SOW prior to engaging with a client:
    "Network diagrams, logical and physical asset inventory, and employees' names are to be treated as client confidential. Upon completion of the engagement, the penetration tester will submit findings to the client's Chief Information Security Officer (CISO) via encrypted protocols and subsequently dispose of all findings by erasing them in a secure manner."
    Based on the information in the SOW, which of the following behaviors would be considered unethical? (Choose two.)
  • PT0-002 Exam Question 44

    Which of the following would MOST likely be included in the final report of a static application-security test that was written with a team of application developers as the intended audience?
  • PT0-002 Exam Question 45

    A penetration tester has identified several newly released CVEs on a VoIP call manager. The scanning tool the tester used determined the possible presence of the CVEs based off the version number of the service. Which of the following methods would BEST support validation of the possible findings?