PT0-002 Exam Question 146

A company that developers embedded software for the automobile industry has hired a penetration-testing team to evaluate the security of its products prior to delivery. The penetration-testing team has stated its intent to subcontract to a reverse-engineering team capable of analyzing binaries to develop proof-of-concept exploits. The software company has requested additional background investigations on the reverse- engineering team prior to approval of the subcontract. Which of the following concerns would BEST support the software company's request?
  • PT0-002 Exam Question 147

    During a security assessment of a web application, a penetration tester was able to generate the following application response:
    Unclosed quotation mark after the character string Incorrect syntax near ".
    Which of the following is the most probable finding?
  • PT0-002 Exam Question 148

    The results of an Nmap scan are as follows:
    Starting Nmap 7.80 ( https://nmap.org ) at 2021-01-24 01:10 EST
    Nmap scan report for ( 10.2.1.22 )
    Host is up (0.0102s latency).
    Not shown: 998 filtered ports
    Port State Service
    80/tcp open http
    |_http-title: 80F 22% RH 1009.1MB (text/html)
    |_http-slowloris-check:
    | VULNERABLE:
    | Slowloris DoS Attack
    | <..>
    Device type: bridge|general purpose
    Running (JUST GUESSING) : QEMU (95%)
    OS CPE: cpe:/a:qemu:qemu
    No exact OS matches found for host (test conditions non-ideal).
    OS detection performed. Please report any incorrect results at https://nmap.org/submit/.
    Nmap done: 1 IP address (1 host up) scanned in 107.45 seconds
    Which of the following device types will MOST likely have a similar response? (Choose two.)
  • PT0-002 Exam Question 149

    Which of the following is a ROE component that provides a penetration tester with guidance on who and how to contact the necessary individuals in the event of a disaster during an engagement?
  • PT0-002 Exam Question 150

    A Chief Information Security Officer wants a penetration tester to evaluate whether a recently installed firewall is protecting a subnetwork on which many decades- old legacy systems are connected. The penetration tester decides to run an OS discovery and a full port scan to identify all the systems and any potential vulnerability. Which of the following should the penetration tester consider BEFORE running a scan?