A penetration tester must use a staging environment to identify vulnerabilities in a live web application. The tester needs to detect whether the application is vulnerable to SQL injection and cross-site scripting flaws by using custom payloads. Which of the following vulnerability discovery techniques should the tester use?
A. Static analysis
B. Protocol fuzzing
C. Dynamic application security testing
D. Software composition analysis
Show Answer
Correct Answer: C
Explanation: Dynamic Application Security Testing (DAST) evaluates a running application by sending crafted requests and payloads to identify exploitable issues such as SQL injection and cross-site scripting. Static analysis examines source code without execution, protocol fuzzing targets protocol implementations rather than specifically web application flaws, and software composition analysis identifies vulnerable third-party components.
Question 62
During a penetration test, the tester executes the following command:
C:\> setspn -q */*
The tester receives the following output:
Which of the following attacks is the tester most likely trying to perform?
A. LDAP injection
B. SQL injection
C. Kerberoasting
D. Pass-the-hash
Show Answer
Correct Answer: C
Explanation: The command `setspn -q */*` queries Active Directory for all registered Service Principal Names (SPNs). Enumerating SPNs is a common reconnaissance step for a Kerberoasting attack, where the attacker requests Kerberos service tickets for SPN-associated service accounts and then attempts to crack the ticket hashes offline to recover service account passwords.
Question 63
A penetration tester performs an assessment for a company that uses several different office buildings throughout a downtown area. Which of the following techniques is the most effective way to identify the location of a designated target?
A. Use search engine analysis.
B. Use dumpster diving.
C. Execute a wardriving attack.
D. Use bluejacking.
Show Answer
Correct Answer: A
Explanation: Search engine analysis (OSINT) is the most effective reconnaissance technique to identify the location of a designated target across multiple office buildings. Public information such as company websites, directories, social media, business listings, and document metadata can reveal which building the target occupies. Dumpster diving is location-specific and requires already knowing where to search, wardriving identifies wireless networks but does not reliably identify a specific target's office among many buildings, and bluejacking is unrelated to locating a target.
Sources:
https://en.wikipedia.org/wiki/Penetration_test
Question 64
A penetration tester establishes an initial reverse shell in the perimeter network on a Linux-based host. The tester finds a NetworkService credential that is suitable for reuse and needs to pivot. Which of the following is the best way to accomplish the task?
A. Use tcpdump to examine traffic going in and out of the host.
B. Locate multihomed devices on the subnet, then use proxychains.
C. Execute whoami on the host to validate user privileges.
D. Use the nc utility to drop additional files on a disk for later execution.
Show Answer
Correct Answer: B
Explanation: Pivoting is the act of using a compromised host to access other network segments that are not directly reachable. Identifying multihomed systems and routing traffic through the compromised environment with proxychains is a standard pivoting approach. The other options involve traffic capture, privilege verification, or file transfer, none of which directly accomplish network pivoting.
Question 65
A penetration tester is performing a wireless assessment that is focused on accessing sensitive information. Which of the following is the best way for the tester to accomplish this task from a nearby coffee shop?
A. Deauthenticate clients as part of the attack.
B. Execute a WPS PIN attack.
C. Prepare an attack using SSID scanning.
D. Conduct an evil twin attack.
Show Answer
Correct Answer: D
Explanation: An evil twin attack is the best choice for capturing sensitive information from users remotely. The tester sets up a rogue access point impersonating the target network so nearby victims connect through it, enabling credential capture and traffic interception. Deauthentication is often used to encourage clients to join the rogue AP but is not the primary objective itself. WPS PIN attacks target vulnerable WPS implementations, and SSID scanning is only reconnaissance.
Question 66
During a penetration test, the tester configures a sniffing system to capture network traffic. While reviewing the results of the sniffing tool’s output, the tester discovers the following protocols:
• FTP
• MODBUS
• DNS
• SSH
Based on these protocols, which of the following steps should the tester complete next?
A. Perform an on-path attack against vulnerable protocols.
B. Gather information about ОТ/ICS protocols and systems within the network.
C. Use a tool to try to maintain access to the network in case of disconnection.
D. Execute a vulnerability scan on the network using automated tools.
Show Answer
Correct Answer: B
Explanation: The presence of MODBUS strongly suggests an OT/ICS environment. In penetration testing, the appropriate next step is to identify and understand the OT/ICS systems before performing intrusive actions, because industrial environments require special handling to avoid disrupting operations. The other options involve active attacks, persistence, or automated scanning, which are not the safest or most appropriate immediate next step after identifying MODBUS traffic.
Question 67
The following table shows the findings of an application security penetration test:
Which of the following recommendations should the penetration tester make? (Choose two.)
A. Use a next-generation firewall.
B. Implement an SCA tool.
C. Deploy an IPS system.
D. Define a change management process.
E. Form an internal red team.
F. Train developers on secure coding.
Show Answer
Correct Answer: B, F
Explanation: Recommendations should address the underlying findings rather than add perimeter controls. An SCA (Software Composition Analysis) tool helps identify and manage vulnerable third-party libraries and dependencies. Secure coding training helps reduce recurring application vulnerabilities such as injection flaws and other coding errors found during the penetration test.
Question 68
Due to a few recent unsolved break-ins, an organization hires a physical penetration tester to check internal and external areas for weaknesses. The organization's security officers receive some door and badge reader alerts during the testing window but cannot identify the cause. The tester's findings include the following:
Which of the following should the tester recommend? (Choose two.)
A. Installing an access control vestibule in the lobby and at the delivery door
B. Introducing scheduled security officer patrols and documentation requirements
C. Improving the visitor and delivery check-in process by requiring separate badges
D. Incorporating physical security content and procedures into employee security awareness training
E. Implementing a video management system and additional camera coverage
F. Updating the access control system to require a badge and personal identification number
Show Answer
Correct Answer: A, E
Explanation: The findings indicate weaknesses at entry points that allow unauthorized access (such as tailgating or doors being held open) and insufficient visibility for security staff to determine the cause of access control alerts. An access control vestibule (mantrap) helps prevent unauthorized entry through controlled access, while expanded camera coverage with a video management system enables officers to investigate and verify alarms in real time.
Question 69
A penetration tester uses a reverse shell to maintain connectivity to a target network. During the final phase of the exercise, the penetration tester removes the reverse shell. Which of the following is an example of these activities?
A. Removing persistence mechanisms
B. Uninstalling tools
C. Preserving artifacts
D. Reverting configuration changes
Show Answer
Correct Answer: A
Explanation: A reverse shell left on a target to allow continued access functions as a persistence mechanism. During the cleanup/final phase of a penetration test, removing that reverse shell is an example of removing persistence mechanisms. Uninstalling tools refers to removing tester-installed software more generally, preserving artifacts is the opposite of cleanup, and reverting configuration changes refers to restoring altered system settings rather than removing persistent access.
Question 70
Which of the following authorizations is mandatory when a penetration tester is involved in a complex IT infrastructure?
A. Customer authorization
B. Penetration tester authorization
C. Third-party authorization
D. Internal team authorization
Show Answer
Correct Answer: A
Explanation: A penetration test requires explicit authorization from the customer or system owner before testing begins. This written authorization establishes legal permission and defines the agreed scope. While third-party approvals may sometimes be needed if external systems are involved, the mandatory authorization is from the customer.
$19
Get all 342 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.