Question 96

A company hires a penetration tester to perform an external attack surface review as part of a security engagement. The company informs the tester that the main company domain to investigate is comptia.org.
Which of the following should the tester do to accomplish the assessment objective?
  • Question 97

    Which of the following components should a penetration tester include in the final assessment report?
  • Question 98

    A penetration tester has been asked to conduct a blind web application test against a customer's corporate website. Which of the following tools would be best suited to perform this assessment?
  • Question 99

    A penetration tester performs the following scan:
    nmap -sU -p 53,161,162 192.168.1.51
    PORT | STATE
    53/udp | open|filtered
    161/udp | open|filtered
    162/udp | open|filtered
    The tester then manually uses snmpwalk against port 161 and receives valid SNMP responses. Which of the following best explains the scan result for port 161?
  • Question 100

    A penetration tester runs the unshadow command on a machine. Which of the following tools will the tester most likely use NEXT?