Question 106

Which of the following tasks would ensure the key outputs from a penetration test are not lost as part of the cleanup and restoration activities?
  • Question 107

    You are a penetration tester reviewing a client's website through a web browser.
    INSTRUCTIONS
    Review all components of the website through the browser to determine if vulnerabilities are present.
    Remediate ONLY the highest vulnerability from either the certificate, source, or cookies.
    If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.


    Question 108

    A penetration tester has discovered sensitive files on a system. Assuming exfiltration of the files is part of the scope of the test, which of the following is most likely to evade DLP systems?
  • Question 109

    During a REST API security assessment, a penetration tester was able to sniff JSON content containing user credentials. The JSON structure was as follows:
    <
    transaction_id: "1234S6", content: [ {
    user_id: "mrcrowley", password: ["54321#"] b <
    user_id: "ozzy",
    password: ["1112228"] ) ]
    Assuming that the variable json contains the parsed JSON data, which of the following Python code snippets correctly returns the password for the user ozzy?
  • Question 110

    A penetration tester ran the following commands on a Windows server:

    Which of the following should the tester do AFTER delivering the final report?