A penetration tester is performing a remote internal penetration test by connecting to the testing system from the Internet via a reverse SSH tunnel. The testing system has been placed on a general user subnet with an IP address of 192.168.1.13 and a gateway of 192.168.1.1. Immediately after running the command below, the penetration tester's SSH connection to the testing platform drops:

Which of the following ettercap commands should the penetration tester use in the future to perform ARP spoofing while maintaining a reliable connection?
A. # proxychains ettercap -Tq -w output.cap -M ARP /192.168.1.13/ /192.168.1.1/
B. # ettercap -Tq -w output.cap -M ARP 00:00:00:00:00:00//80
FF:FF:FF:FF:FF:FF//80
C. # ettercap --safe-mode -Tq -w output.cap -M ARP /192.168.1.2-
255/ /192.168.1.13/
D. # ettercap -Tq -w output.cap -M ARP /192.168.1.2-12;192.168.1.14-
255/ /192.168.1.1/
E. # sudo ettercap -Tq -w output.cap -M ARP /192.168.1.0/ /192.168.1.255/
正解:E
質問 2:
Which of the following attacks is commonly combined with cross-site scripting for session hijacking?
A. CSRF
B. SQLI
C. RFI
D. Clickjacking
正解:A
質問 3:
A penetration tester ran the following Nmap scan on a computer:
nmap -aV 192.168.1.5
The organization said it had disabled Telnet from its environment. However, the results of the Nmap scan show port 22 as closed and port 23 as open to SSH. Which of the following is the BEST explanation for what happened?
A. The service is running on a non-standard port.
B. Nmap results contain a false positive for port 23.
C. The organization failed to disable Telnet.
D. Port 22 was filtered.
正解:C
質問 4:
During post-exploitation, a tester identifies that only system binaries will pass an egress filter and store a file with the following command:
c: \creditcards.db>c:\winit\system32\calc.exe:creditcards.db
Which of the following file system vulnerabilities does this command take advantage of?
A. Alternate data streams
B. Backdoor success
C. Hierarchical file system
D. Extended file system
正解:A
質問 5:
Which of the following BEST describes some significant security weaknesses with an ICS, such as those used in electrical utility facilities, natural gas facilities, dams, and nuclear facilities?
A. ICS vendors are slow to implement adequate security controls.
B. There is a lack of compliance for ICS facilities.
C. ICS staff are not adequately trained to perform basic duties.
D. There is a scarcity of replacement equipment for critical devices.
正解:C
質問 6:
Which of the following properties of the penetration testing engagement agreement will have the largest impact on observing and testing production systems at their highest loads?
A. Creating a scope of the critical production systems
B. Setting a schedule of testing access times
C. Having management sign-off on intrusive testing
D. Establishing a white-box testing engagement
正解:C
質問 7:
A penetration tester has been assigned to perform an external penetration assessment of a company. Which of the following steps would BEST help with the passive-information-gathering process? (Choose two.)
A. Use domain and IP registry websites to identify the company's external netblocks and external facing applications.
B. Perform a vulnerability scan against the company's external netblock, identify exploitable vulnerabilities, and attempt to gain access.
C. Identify the company's external facing webmail application, enumerate user accounts and attempt password guessing to gain access.
D. Wait outside of the company's building and attempt to tailgate behind an employee.
E. Search social media for information technology employees who post information about the technologies they work with.
正解:C,E
1234 お客様のコメント
クリック」





Hirosue -
Pass4Testの問題集のおかげで高得点で受かりました。これまで行われた答練の中から本試験と遜色のないPT0-001問題集ですね!これを勉強させて無事合格です!