Question 96

A penetration tester ran the following commands on a Windows server:

Which of the following should the tester do AFTER delivering the final report?
  • Question 97

    A mail service company has hired a penetration tester to conduct an enumeration of all user accounts on an SMTP server to identify whether previous staff member accounts are still active. Which of the following commands should be used to accomplish the goal?
  • Question 98

    An exploit developer is coding a script that submits a very large number of small requests to a web server until the server is compromised. The script must examine each response received and compare the data to a large number of strings to determine which data to submit next. Which of the following data structures should the exploit developer use to make the string comparison and determination as efficient as possible?
  • Question 99

    During a web application test, a penetration tester was able to navigate to https://company.com and view all links on the web page. After manually reviewing the pages, the tester used a web scanner to automate the search for vulnerabilities. When returning to the web application, the following message appeared in the browser: unauthorized to view this page. Which of the following BEST explains what occurred?
  • Question 100

    The attacking machine is on the same LAN segment as the target host during an internal penetration test.
    Which of the following commands will BEST enable the attacker to conduct host delivery and write the discovery to files without returning results of the attack machine?