Question 156

A penetration tester who is conducting a web-application test discovers a clickjacking vulnerability associated with a login page to financial data. Which of the following should the tester do with this information to make this a successful exploit?
  • Question 157

    A consulting company is completing the ROE during scoping.
    Which of the following should be included in the ROE?
  • Question 158

    An internal penetration tester is on site assessing network access for company-owned mobile devices. Which of the following would be the best tool to identify the available networks?
  • Question 159

    A penetration tester has found a web application that is running on a cloud virtual machine instance.
    Vulnerability scans show a potential SSRF for the same application URL path with an injectable parameter.
    Which of the following commands should the tester run to successfully test for secrets exposure exploitability?
  • Question 160

    You are a security analyst tasked with hardening a web server.
    You have been given a list of HTTP payloads that were flagged as malicious.
    INSTRUCTIONS
    Given the following attack signatures, determine the attack type, and then identify the associated remediation to prevent the attack in the future.
    If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.