Geschreven door studenten die geslaagd zijn Direct beschikbaar na je betaling Online lezen of als PDF Verkeerd document? Gratis ruilen 4,6 TrustPilot
logo-home
Tentamen (uitwerkingen)

PT0-002 Practice Exam Questions and Answers 100% GRADE A+ GUARANTEED

Beoordeling
-
Verkocht
-
Pagina's
66
Cijfer
A+
Geüpload op
17-05-2024
Geschreven in
2023/2024

Question # 1 Which of the following is the MOST common vulnerability associated with IoT devices that are directly connected to the Internet? Options: A.   Unsupported operating systems B.   Susceptibility to DDoS attacks C.   Inability to network D.   The existence of default passwords Question # 2 Which of the following should a penetration tester do NEXT after identifying that an application being tested has already been compromised with malware? Options: A.   Analyze the malware to see what it does. B.   Collect the proper evidence and then remove the malware. C.   Do a root-cause analysis to find out how the malware got in. D.   Remove the malware immediately. E.   Stop the assessment and inform the emergency contact. Question # 3 Which of the following should a penetration tester do NEXT after identifying that an application being tested has already been compromised with malware? Options: A.   Root user B.   Local administrator C.   Service D.   Network administrator Question # 4 A penetration tester has gained access to part of an internal network and wants to exploit on a different network segment. Using Scapy, the tester runs the following command: Which of the following represents what the penetration tester is attempting to accomplish? Options: A.   DNS cache poisoning B.   MAC spoofing C.   ARP poisoning D.   Double-tagging attack Question # 5 A penetration tester has completed an analysis of the various software products produced by the company under assessment. The tester found that over the past several years the company has been including vulnerable third-party modules in multiple products, even though the quality of the organic code being developed is very good. Which of the following recommendations should the penetration tester include in the report? Options: A.   Add a dependency checker into the tool chain. B.   Perform routine static and dynamic analysis of committed code. C.   Validate API security settings before deployment. D.   Perform fuzz testing of compiled binaries. Question # 6 Which of the following BEST describe the OWASP Top 10? (Choose two.) Options: A.   The most critical risks of web applications B.   A list of all the risks of web applications C.   The risks defined in order of importance D.   A web-application security standard E.   A risk-governance and compliance framework F.   A checklist of Apache vulnerabilities Question # 7 The results of an Nmap scan are as follows: Starting Nmap 7.80 ( ) at :10 EST Nmap scan report for ( 10.2.1.22 ) Host is up (0.0102s latency). Not shown: 998 filtered ports Port State Service 80/tcp open http |_http-title: 80F 22% RH 1009.1MB (text/html) |_http-slowloris-check: | VULNERABLE: | Slowloris DoS Attack | .. Device type: bridge|general purpose CONTINUED......

Meer zien Lees minder
Instelling
Vak

Voorbeeld van de inhoud

PT0-002 Practice Exam Questions
and Answers 100% GRADE A+
GUARANTEED


Question # 1

Which of the following is the MOST common vulnerability associated with IoT
devices that are directly connected to the Internet?

Options:

A.

Unsupported operating systems

B.

Susceptibility to DDoS attacks

C.

Inability to network

D.

The existence of default passwords

Question # 2

Which of the following should a penetration tester do NEXT after identifying that an
application being tested has already been compromised with malware?

Options:

A.

Analyze the malware to see what it does.

B.

Collect the proper evidence and then remove the malware.

,C.

Do a root-cause analysis to find out how the malware got in.

D.

Remove the malware immediately.

E.

Stop the assessment and inform the emergency contact.

Question # 3

A penetration tester has been hired to configure and conduct authenticated scans of all
the servers on a software company’s network. Which of the following accounts
should the tester use to return the MOST results?

Options:

A.

Root user

B.

Local administrator

C.

Service

D.

Network administrator

Question # 4

A penetration tester has gained access to part of an internal network and wants to
exploit on a different network segment. Using Scapy, the tester runs the following
command:




Which of the following represents what the penetration tester is attempting to
accomplish?

Options:

,A.

DNS cache poisoning

B.

MAC spoofing

C.

ARP poisoning

D.

Double-tagging attack

Question # 5

A penetration tester has completed an analysis of the various software products
produced by the company under assessment. The tester found that over the past
several years the company has been including vulnerable third-party modules in
multiple products, even though the quality of the organic code being developed is
very good. Which of the following recommendations should the penetration tester
include in the report?

Options:

A.

Add a dependency checker into the tool chain.

B.

Perform routine static and dynamic analysis of committed code.

C.

Validate API security settings before deployment.

D.

Perform fuzz testing of compiled binaries.

Question # 6

Which of the following BEST describe the OWASP Top 10? (Choose two.)

Options:

, A.

The most critical risks of web applications

B.

A list of all the risks of web applications

C.

The risks defined in order of importance

D.

A web-application security standard

E.

A risk-governance and compliance framework

F.

A checklist of Apache vulnerabilities

Question # 7

The results of an Nmap scan are as follows:

Starting Nmap 7.80 ( https://nmap.org ) at 2021-01-24 01:10 EST

Nmap scan report for ( 10.2.1.22 )

Host is up (0.0102s latency).

Not shown: 998 filtered ports

Port State Service

80/tcp open http

|_http-title: 80F 22% RH 1009.1MB (text/html)

|_http-slowloris-check:

| VULNERABLE:

| Slowloris DoS Attack

| <..>

Geschreven voor

Vak

Documentinformatie

Geüpload op
17 mei 2024
Aantal pagina's
66
Geschreven in
2023/2024
Type
Tentamen (uitwerkingen)
Bevat
Vragen en antwoorden

Onderwerpen

$15.49
Krijg toegang tot het volledige document:

Verkeerd document? Gratis ruilen Binnen 14 dagen na aankoop en voor het downloaden kun je een ander document kiezen. Je kunt het bedrag gewoon opnieuw besteden.
Geschreven door studenten die geslaagd zijn
Direct beschikbaar na je betaling
Online lezen of als PDF

Maak kennis met de verkoper
Seller avatar
munyuabeatrice92

Maak kennis met de verkoper

Seller avatar
munyuabeatrice92 K
Volgen Je moet ingelogd zijn om studenten of vakken te kunnen volgen
Verkocht
1
Lid sinds
2 jaar
Aantal volgers
1
Documenten
347
Laatst verkocht
2 jaar geleden

0.0

0 beoordelingen

5
0
4
0
3
0
2
0
1
0

Recent door jou bekeken

Waarom studenten kiezen voor Stuvia

Gemaakt door medestudenten, geverifieerd door reviews

Kwaliteit die je kunt vertrouwen: geschreven door studenten die slaagden en beoordeeld door anderen die dit document gebruikten.

Niet tevreden? Kies een ander document

Geen zorgen! Je kunt voor hetzelfde geld direct een ander document kiezen dat beter past bij wat je zoekt.

Betaal zoals je wilt, start meteen met leren

Geen abonnement, geen verplichtingen. Betaal zoals je gewend bent via iDeal of creditcard en download je PDF-document meteen.

Student with book image

“Gekocht, gedownload en geslaagd. Zo makkelijk kan het dus zijn.”

Alisha Student

Bezig met je bronvermelding?

Maak nauwkeurige citaten in APA, MLA en Harvard met onze gratis bronnengenerator.

Bezig met je bronvermelding?

Veelgestelde vragen