Question 91

A penetration tester is performing network reconnaissance. The tester wants to gather information about the network without causing detection mechanisms to flag the reconnaissance activities. Which of the following techniques should the tester use?
  • Question 92

    A penetration tester performs an assessment for a company that uses several different office buildings throughout a downtown area. Which of the following techniques is the most effective way to identify the location of a designated target?
  • Question 93

    A penetration tester is assessing the security of a web application. When the tester attempts to access the application, the tester receives an HTTP403response. Which of the following should the penetration tester do to overcome this issue?
  • Question 94

    Eight months after the completion of a penetration test, the client emails the penetration tester to debate the validity of several findings. The findings are now posing a hindrance to compliance certifications. Which of the following would most likely assist the penetration tester with de- escalation?
  • Question 95

    The results of an Nmap scan are as follows:
    Starting Nmap 7.80 ( https://nmap.org ) at 2021-01-24 01:10 EST
    Nmap scan report for ( 10.2.1.22 )
    Host is up (0.0102s latency).
    Not shown: 998 filtered ports
    Port State Service
    80/tcp open http
    |_http-title: 80F 22% RH 1009.1MB (text/html)
    |_http-slowloris-check:
    | VULNERABLE:
    | Slowloris DoS Attack
    | <..>
    Device type: bridge|general purpose
    Running (JUST GUESSING) : QEMU (95%)
    OS CPE: cpe:/a:qemu:qemu
    No exact OS matches found for host (test conditions non-ideal).
    OS detection performed. Please report any incorrect results at https://nmap.org/submit/.
    Nmap done: 1 IP address (1 host up) scanned in 107.45 seconds
    Which of the following device types will MOST likely have a similar response? (Choose two.)