PT0-002 Exam Question 161

A compliance-based penetration test is primarily concerned with:
  • PT0-002 Exam Question 162

    During a client engagement, a penetration tester runs the following Nmap command and obtains the following output:
    nmap -sV -- script ssl-enum-ciphers -p 443 remotehost
    | TLS_ECDHE_ECDSA_WITH_RC4_128_SHA
    | TLS_ECDHE_RSA_WITH_RC4_128_SHA
    TLS_RSA_WITH_RC4_128_SHA (rsa 2048)
    TLS_RSA_WITH_RC4_128_MD5 (rsa 2048)
    Which of the following should the penetration tester include in the report?
  • PT0-002 Exam Question 163

    During a web application test, a penetration tester was able to navigate to https://company.com and view all links on the web page. After manually reviewing the pages, the tester used a web scanner to automate the search for vulnerabilities. When returning to the web application, the following message appeared in the browser: unauthorized to view this page. Which of the following BEST explains what occurred?
  • PT0-002 Exam Question 164

    A penetration tester is assessing a wireless network. Although monitoring the correct channel and SSID, the tester is unable to capture a handshake between the clients and the AP. Which of the following attacks is the MOST effective to allow the penetration tester to capture a handshake?
  • PT0-002 Exam Question 165

    A penetration tester is conducting an assessment for an e-commerce company and successfully copies the user database to the local machine. After a closer review, the penetration tester identifies several high-profile celebrities who have active user accounts with the online service. Which of the following is the most appropriate next step?