Question 126

During a penetration test, you gain access to a system with a limited user interface. This machine appears to have access to an isolated network that you would like to port scan.
INSTRUCTIONS
Analyze the code segments to determine which sections are needed to complete a port scanning script.
Drag the appropriate elements into the correct locations to complete the script.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Question 127

A penetration tester is authorized to perform a DoS attack against a host on a network. Given the following input:
ip = IP("192.168.50.2")
tcp = TCP(sport=RandShort(), dport=80, flags="S")
raw = RAW(b"X"*1024)
p = ip/tcp/raw
send(p, loop=1, verbose=0)
Which of the following attack types is most likely being used in the test?
  • Question 128

    A penetration tester reviews a SAST vulnerability scan report. The following lines of code have been reported as vulnerable:

    Which of the following is the best method to remediate this vulnerability?
  • Question 129

    A tester runs an Nmap scan against a Windows server and receives the following results:
    Nmap scan report for win_dns.local (10.0.0.5)
    Host is up (0.014s latency)
    Port State Service
    53/tcp open domain
    161/tcp open snmp
    445/tcp open smb-ds
    3389/tcp open rdp
    Which of the following TCP ports should be prioritized for using hash-based relays?
  • Question 130

    A penetration tester sets up a C2 (Command and Control) server to manage and control payloads deployed in the target network. Which of the following tools is the most suitable for establishing a robust and stealthy connection?