Question 321

During an assessment, a penetration tester manages to exploit an LFI vulnerability and browse the web log for a target Apache server. Which of the following steps would the penetration tester most likely try NEXT to further exploit the web server? (Choose two.)
  • Question 322

    An organization wants to identify whether a less secure protocol is being utilized on a wireless network.
    Which of the following types of attacks will achieve this goal?
  • Question 323

    A penetration tester successfully performed an exploit on a host and was able to hop from VLAN 100 to VLAN 200. VLAN 200 contains servers that perform financial transactions, and the penetration tester now wants the local interface of the attacker machine to have a static ARP entry in the local cache. The attacker machine has the following:
    IP Address: 192.168.1.63
    Physical Address: 60-36-dd-a6-c5-33
    Which of the following commands would the penetration tester MOST likely use in order to establish a static ARP entry successfully?
  • Question 324

    A penetration tester conducted a vulnerability scan against a client's critical servers and found the following:

    Which of the following would be a recommendation for remediation?
  • Question 325

    You are a penetration tester reviewing a client's website through a web browser.
    INSTRUCTIONS
    Review all components of the website through the browser to determine if vulnerabilities are present.
    Remediate ONLY the highest vulnerability from either the certificate, source, or cookies.
    If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.