Question 56

A company is concerned that its cloud VM is vulnerable to a cyberattack and proprietary data may be stolen.
A penetration tester determines a vulnerability does exist and exploits the vulnerability by adding a fake VM instance to the IaaS component of the client's VM. Which of the following cloud attacks did the penetration tester MOST likely implement?
  • Question 57

    A penetration tester initiated the transfer of a large data set to verify a proof-of-concept attack as permitted by the ROE. The tester noticed the client's data included PII, which is out of scope, and immediately stopped the transfer. Which of the following MOST likely explains the penetration tester's decision?
  • Question 58

    A penetration tester who is working remotely is conducting a penetration test using a wireless connection.
    Which of the following is the BEST way to provide confidentiality for the client while using this connection?
  • Question 59

    A penetration tester has obtained a low-privilege shell on a Windows server with a default configuration and now wants to explore the ability to exploit misconfigured service permissions. Which of the following commands would help the tester START this process?
  • Question 60

    Which of the following documents describes activities that are prohibited during a scheduled penetration test?