A penetration tester is reviewing the security of a web application running in an laaS compute instance. Which of the following payloads should the tester send to get the running process credentials?
A. file=http://192.168. 1. 78?+document.cookie
B. file =.. / .. / .. /proc/self/environ
C. file='%20or%2054365=54365 ;-
D. file=http://169.254.169.254/latest/meta-data/
A penetration tester is performing a vulnerability scan on a large ATM network. One of the organization's requirements is that the scan does not affect legitimate clients' usage of the ATMs. Which of the following should the tester do to best meet the company's vulnerability scan requirements?
A. Use Nmap's -T2 switch to run a slower scan and with less resources.
B. Run the scans using multiple machines.
C. Run the scans only during lunch hours.
D. Use Nmap's -host-timeout switch to skip unresponsive targets.
A company developed a new web application to allow its customers to submit loan applications. A penetration tester is reviewing the application and discovers that the application was developed in ASP and used MSSQL for its back-end
database. Using the application's search form, the penetration tester inputs the following code in the search input field:
IMG SRC=vbscript:msgbox ("Vulnerable_to_Attack") ; >originalAttribute="SRC"originalPath="vbscript;msgbox ("Vulnerable_to_Attack ") ;>"
When the tester checks the submit button on the search form, the web browser returns a pop-up windows that displays "Vulnerable_to_Attack."
Which of the following vulnerabilities did the tester discover in the web application?
A. SQL injection
B. Command injection
C. Cross-site request forgery
D. Cross-site scripting
A penetration tester observes an application enforcing strict access controls. Which of the following would allow the tester to bypass these controls and successfully access the organization's sensitive files?
A. Remote file inclusion
B. Cross-site scripting
C. SQL injection
D. Insecure direct object references
Which of the following tools would be best to use to conceal data in various kinds of image files?
A. Kismet
B. Snow
C. Responder
D. Metasploit
A penetration tester is reviewing the logs of a proxy server and discovers the following URLs: https://test.comptia.com/profile.php?userid=1546 https://test.cpmptia.com/profile.php?userid=5482 https://test.comptia.com/profile.php?userid=3618 Which of the following types of vulnerabilities should be remediated?
A. Insecure direct object reference
B. Improper error handling
C. Race condition
D. Weak or default configurations
During an assessment, a penetration tester discovers the following code sample in a web application: "(and(userid=*)(userid=*))(I(userid=*)(userPwd=(SHAl}a9993e364706816aba3e25717850c26 c9cd0d89d==)) Which of the following injections is being performed?
A. Boolean SQL
B. Command
C. Blind SQL
D. LDAP
A penetration tester is performing an assessment for an organization and must gather valid user credentials. Which of the following attacks would be best for the tester to use to achieve this objective?
A. Wardriving
B. Captive portal
C. Deauthentication
D. Impersonation
Which of the following describes how a penetration tester could prioritize findings in a report?
A. Business mission and goals
B. Cyberassets
C. Network infrastructure
D. Cyberthreats
A penetration tester is conducting an on-path link layer attack in order to take control of a key fob that controls an electric vehicle. Which of the following wireless attacks would allow a penetration tester to achieve a successful attack?
A. Bluejacking
B. Bluesnarfing
C. BLE attack
D. WPS PIN attack
Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.