PT0-002 Exam Question 181

For a penetration test engagement, a security engineer decides to impersonate the IT help desk. The security engineer sends a phishing email containing an urgent request for users to change their passwords and a link to
https://example.com/index.html. The engineer has designed the attack so that once the users enter the credentials, the index.html page takes the credentials and then forwards them to another server that the security engineer is controlling. Given the following information:

Which of the following lines of code should the security engineer add to make the attack successful?
  • PT0-002 Exam Question 182

    Which of the following should a penetration tester do NEXT after identifying that an application being tested has already been compromised with malware?
  • PT0-002 Exam Question 183

    A penetration tester who is performing a physical assessment of a company's security practices notices the company does not have any shredders inside the office building. Which of the following techniques would be BEST to use to gain confidential information?
  • PT0-002 Exam Question 184

    You are a penetration tester running port scans on a server.
    INSTRUCTIONS
    Part 1: Given the output, construct the command that was used to generate this output from the available options.
    Part 2: Once the command is appropriately constructed, use the given output to identify the potential attack vectors that should be investigated further.
    If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

    PT0-002 Exam Question 185

    A penetration tester is evaluating a company's network perimeter. The tester has received limited information about defensive controls or countermeasures, and limited internal knowledge of the testing exists. Which of the following should be the FIRST step to plan the reconnaissance activities?