A penetration tester found the following valid URL while doing a manual assessment of a web application: http://www.example.com/product.php?id=123987.
Which of the following automated tools would be best to use NEXT to try to identify a vulnerability in this URL?
A. DirBuster
B. Nessus
C. Nikto
D. SQLmap
正解:B
質問 2:
A penetration tester obtained the following results after scanning a web server using the dirb utility:
...
GENERATED WORDS: 4612
---- Scanning URL: http://10.2.10.13/ ----
+ http://10.2.10.13/about (CODE:200|SIZE:1520)
+ http://10.2.10.13/home.html (CODE:200|SIZE:214)
+ http://10.2.10.13/index.html (CODE:200|SIZE:214)
+ http://10.2.10.13/info (CODE:200|SIZE:214)
...
DOWNLOADED: 4612 - FOUND: 4
Which of the following elements is MOST likely to contain useful information for the penetration tester?
A. index.html
B. info
C. about
D. home.html
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
Company.com has hired a penetration tester to conduct a phishing test. The tester wants to set up a fake log-in page and harvest credentials when target employees click on links in a phishing email. Which of the following commands would best help the tester determine which cloud email provider the log-in page needs to mimic?
A. dig company.com A
B. cur1 www.company.com
C. whois company.com
D. dig company.com MX
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
During a vulnerability scan a penetration tester enters the following Nmap command against all of the non-Windows clients:
nmap -sX -T4 -p 21-25, 67, 80, 139, 8080 192.168.11.191
The penetration tester reviews the packet capture in Wireshark and notices that the target responds with an RST packet flag set for all of the targeted ports. Which of the following does this information most likely indicate?
A. All of the ports in the target range are open
B. Nmap needs more time to scan the ports in the target range.
C. The ports in the target range cannot be scanned because they are common UDP ports.
D. All of the ports in the target range are closed.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
Which of the following is a rules engine for managing public cloud accounts and resources?
A. Cloud Brute
B. Cloud Custodian
C. Scout Suite
D. Pacu
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
A company recently moved its software development architecture from VMs to containers. The company has asked a penetration tester to determine if the new containers are configured correctly against a DDoS attack. Which of the following should a tester perform first?
A. Test the strength of the encryption settings.
B. Perform a vulnerability check against the hypervisor.
C. Determine if security tokens are easily available.
D. .Scan the containers for open ports.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
1057 お客様のコメント
クリック」





メロ** -
持ち歩きは面倒というのであれば、Pass4Test全ページが電子化されているので、PT0-002のPDFファイルでダウンロードすることもできるところが大好きです。