Question 211

A penetration tester has obtained root access to a Linux-based file server and would like to maintain persistence after reboot. Which of the following techniques would BEST support this objective?
  • Question 212

    A new security firm is onboarding its first client. The client only allowed testing over the weekend and needed the results Monday morning. However, the assessment team was not able to access the environment as expected until Monday. Which of the following should the security company have acquired BEFORE the start of the assessment?
  • Question 213

    You are a penetration tester running port scans on a server.
    INSTRUCTIONS
    Part 1: Given the output, construct the command that was used to generate this output from the available options.
    Part 2: Once the command is appropriately constructed, use the given output to identify the potential attack vectors that should be investigated further.
    If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

    Question 214

    A company is concerned that its cloud service provider is not adequately protecting the VMs housing its software development. The VMs are housed in a datacenter with other companies sharing physical resources. Which of the following attack types is MOST concerning to the company?
  • Question 215

    Which of the following tools should a penetration tester use to crawl a website and build a wordlist using the data recovered to crack the password on the website?