Question 26

Given the following Python script:

Which of the following actions will it perform?
  • Question 27

    A penetration tester notices that the X-Frame-Optjons header on a web application is not set. Which of the following would a malicious actor do to exploit this configuration setting?
  • Question 28

    An attacker receives a DHCP address and notices the hostname was populated in the corporate DNS server. Which of the following BEST describes how the attacker can use this information?
  • Question 29

    Which of the following are MOST important when planning for an engagement? (Select TWO).
  • Question 30

    A penetration tester is performing a remote internal penetration test by connecting to the testing system from the Internet via a reverse SSH tunnel. The testing system has been placed on a general user subnet with an IP address of 192.168.1.13 and a gateway of 192.168.1.1. Immediately after running the command below, the penetration tester's SSH connection to the testing platform drops:

    Which of the following ettercap commands should the penetration tester use in the future to perform ARP spoofing while maintaining a reliable connection?
    # sudo ettercap -Tq -w output.cap -M ARP /192.168.1.0/ /192.168.1.255/