Question 456

An attacker plans to compromise IoT devices to pivot into OT systems. What should be the immediate action?
  • Question 457

    In the financial hub of Charlotte, North Carolina, ethical hacker Raj Patel is contracted by TrustBank, a regional U.S. bank, to evaluate their online loan application portal. During testing, Raj submits crafted input into the portal's form fields and notices that the server's HTTP responses are unexpectedly altered. His payloads cause additional headers to appear and even inject unintended content into the output, creating opportunities for attackers to manipulate web page behavior and deliver malicious data to users. Which type of vulnerability is Raj most likely exploiting in TrustBank's online loan application portal?
  • Question 458

    During a red team assessment, an ethical hacker must map a large multinational enterprise's external attack surface. Due to strict rules of engagement, no active scans may be used. The goal is to identify publicly visible subdomains to uncover forgotten or misconfigured services. Which method should the ethical hacker use to passively enumerate the organization's subdomains?
  • Question 459

    Why is NTP responding with internal IP addresses and hostnames?
  • Question 460

    An attacker places a malicious VM on the same physical server as a target VM in a multi-tenant cloud environment. The attacker then extracts cryptographic keys using CPU timing analysis.
    What type of attack was conducted?