A penetration tester creates the following Python script that can be used to enumerate information about email accounts on a target mail server:

Which of the following logic constructs would permit the script to continue despite failure?
A. Add an if/elseconditional.
B. Add a try/exceptblock.
C. Add an iterator.
D. Add a do/whileloop.
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
Which of the following is most likely a function of the legal department?
A. Authorization letters
B. Third-party responsibilities
C. Rules of engagement
D. Shared responsibility model
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
A penetration tester is unable to identify the Wi-Fi SSID on a client's cell phone. Which of the following techniques would be most effective to troubleshoot this issue?
A. Stealth scanning
B. Static analysis scanning
C. Sidecar scanning
D. Channel scanning
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
During a discussion of a penetration test final report, the consultant shows the following payload used to attack a system:
?/<sCRitP>aLeRt("pwned")</ScriPt>
Based on the code, which of the following options represents the attack executed by the tester and the associated countermeasure?
A. Arbitrary code execution: the affected computer should be placed on a perimeter network
B. Cross-site request forgery: should be detected and prevented by a firewall
C. SQL injection attack: should be detected and prevented by a web application firewall
D. XSS obfuscated: should be prevented by input sanitization
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
A penetration tester is working on an engagement in which a main objective is to collect confidential information that could be used to exfiltrate data and perform a ransomware attack.
During the engagement, the tester is able to obtain an internal foothold on the target network.
Which of the following is the next task the tester should complete to accomplish the objective?
A. Share enumeration.
B. Initiate a social engineering campaign.
C. Perform credential dumping.
D. Compromise an endpoint.
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
Eight months after the completion of a penetration test, the client emails the penetration tester to debate the validity of several findings. The findings are now posing a hindrance to compliance certifications. Which of the following would most likely assist the penetration tester with de- escalation?
A. Terms of use
B. Business impact analysis
C. Client acceptance
D. Testing methodology
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 7:
A penetration tester achieves shell access. The tester tries to use the following command, but it fails:
netsh advfirewall set domainprofile state off
Which of the following should the tester do to help correct this issue?
A. Find other attack paths.
B. Validate the target system's fingerprint.
C. Gather more data about the network.
D. Perform privilege escalation.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 8:
As part of an engagement, a penetration tester needs to scan several hundred public-facing URLs for dangerous files or outdated web server versions. Which of the following should the tester use?
A. BloodHound
B. Nmap
C. Nikto
D. ZAP
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
457 お客様のコメント





Nagata -
前回の試験では及ばず落ちましが4月の試験でPass4Testのこの問題集を購入して今回合格出来ました。