Question 81

Which of the following web-application security risks are part of the OWASP Top 10 v2017? (Choose two.)
  • Question 82

    An Nmap scan shows open ports on web servers and databases. A penetration tester decides to run WPScan and SQLmap to identify vulnerabilities and additional information about those systems.
    Which of the following is the penetration tester trying to accomplish?
  • Question 83

    A security professional wants to test an IoT device by sending an invalid packet to a proprietary service listening on TCP port 3011. Which of the following would allow the security professional to easily and programmatically manipulate the TCP header length and checksum using arbitrary numbers and to observe how the proprietary service responds?
  • Question 84

    A penetration tester received a .pcap file to look for credentials to use in an engagement.
    Which of the following tools should the tester utilize to open and read the .pcap file?
  • Question 85

    A penetration tester exploited a unique flaw on a recent penetration test of a bank. After the test was completed, the tester posted information about the exploit online along with the IP addresses of the exploited machines. Which of the following documents could hold the penetration tester accountable for this action?