Question 86

During a vulnerability assessment, a penetration tester configures the scanner sensor and performs the initial vulnerability scanning under the client ' s internal network. The tester later discusses the results with the client, but the client does not accept the results. The client indicates the host and assets that were within scope are not included in the vulnerability scan results. Which of the following should the tester have done?
  • Question 87

    Which of the following is most important when communicating the need for vulnerability remediation to a client at the conclusion of a penetration test?
  • Question 88

    During an assessment, a penetration tester sends the following request:
    POST /services/v1/users/create HTTP/1.1
    Host: target-application.com
    Content-Type: application/json
    Content-Length: [dynamic]
    Authorization: Bearer [FUZZE]
    Which of the following attacks is the penetration tester performing?
  • Question 89

    SIMULATION 3
    You are a penetration tester reviewing a client's website through a web browser.
    INSTRUCTIONS
    Review all components of the website through the browser to determine if vulnerabilities are present.
    Remediate ONLY the highest vulnerability from either the certificate, source, or cookies.
    If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.






    Question 90

    A penetration-testing team is conducting a physical penetration test to gain entry to a building. Which of the following is the reason why the penetration testers should carry copies of the engagement documents with them?