PT0-003 Exam Question 46
During an engagement, a penetration tester found some weaknesses that were common across the customer's entire environment. The weaknesses included the following:
* Weaker password settings than the company standard
* Systems without the company's endpoint security software installed
* Operating systems that were not updated by the patch management system Which of the following recommendations should the penetration tester provide to address the root issue?
* Weaker password settings than the company standard
* Systems without the company's endpoint security software installed
* Operating systems that were not updated by the patch management system Which of the following recommendations should the penetration tester provide to address the root issue?
PT0-003 Exam Question 47
While conducting an assessment, a penetration tester identifies details for several unreleased products announced at a company-wide meeting.
Which of the following attacks did the tester most likely use to discover this information?
Which of the following attacks did the tester most likely use to discover this information?
PT0-003 Exam Question 48
A penetration tester launches an attack against company employees. The tester clones the company's intranet login page and sends the link via email to all employees.
Which of the following best describes the objective and tool selected by the tester to perform this activity?
Which of the following best describes the objective and tool selected by the tester to perform this activity?
PT0-003 Exam Question 49
During a web application assessment, a penetration tester identifies an input field that allows JavaScript injection. The tester inserts a line of JavaScript that results in a prompt, presenting a text box when browsing to the page going forward. Which of the following types of attacks is this an example of?
PT0-003 Exam Question 50
A penetration tester is performing a security review of a web application. Which of the following should the tester leverage to identify the presence of vulnerable open-source libraries?
