312-50v13 Exam Question 176
A penetration tester runs a vulnerability scan and identifies an outdated version of a web application running on the company's server. The scan flags this as a medium-risk vulnerability. What is the best next step for the tester?
312-50v13 Exam Question 177
A penetration tester completes a vulnerability scan showing multiple low-risk findings and one high-risk vulnerability tied to outdated server software. What should the tester prioritize as the next step?
312-50v13 Exam Question 178
What is the most plausible attack vector an APT group would use to compromise an IoT-based environmental control system?
312-50v13 Exam Question 179
A tester evaluates a login form that constructs SQL queries using unsanitized user input. By submitting 1 OR
'T'='T'; --, the tester gains unauthorized access to the application. What type of SQL injection has occurred?
'T'='T'; --, the tester gains unauthorized access to the application. What type of SQL injection has occurred?
312-50v13 Exam Question 180
A serverless application was compromised through an insecure third-party API used by a function. What is the most effective countermeasure?
