312-50v13 Exam Question 211

A penetration tester is assessing a mobile application and discovers that the app is vulnerable to improper session management. The session tokens are not invalidated upon logout, allowing the tokens to be reused.
What is the most effective way to exploit this vulnerability?
  • 312-50v13 Exam Question 212

    A penetration tester is conducting an external assessment of a corporate web server. They start by accessing
    https://www.targetcorp.com/robots.txt and observe multiple Disallow entries that reference directories such as
    /admin-panel/, /backup/, and /confidentialdocs/. When the tester directly visits these paths via a browser, they find that access is not restricted by authentication and gain access to sensitive files, including server configuration and unprotected credentials. Which stage of the web server attack methodology is demonstrated in this scenario?
  • 312-50v13 Exam Question 213

    Which defense MOST disrupts ransomware spread?
  • 312-50v13 Exam Question 214

    Which scenario best describes a slow, stealthy scanning technique?
  • 312-50v13 Exam Question 215

    During a recent security assessment, you discover the organization has one Domain Name Server (DNS) in a Demilitarized Zone (DMZ) and a second DNS server on the internal network. What is this type of DNS configuration commonly called?