Free CompTIA PT1-002 Exam Braindumps (page: 11)

A penetration tester is exploring a client's website. The tester performs a curl command and obtains the following:
* Connected to 10.2.11.144 (::1) port 80 (#0)
> GET /readmine.html HTTP/1.1
> Host: 10.2.11.144
> User-Agent: curl/7.67.0
> Accept: */*
>
* Mark bundle as not supporting multiuse
< HTTP/1.1 200
< Date: Tue, 02 Feb 2021 21:46:47 GMT
< Server: Apache/2.4.41 (Debian)
< Content-Length: 317
< Content-Type: text/html; charset=iso-8859-1
<
<!DOCTYPE html>
<html lang=`en`>
<head>
<meta name=`viewport` content=`width=device-width` />
<meta http-equiv=`Content-Type` content=`text/html; charset=utf-8` />
<title>WordPress > ReadMe</title>
<link rel=`stylesheet` href=`wp-admin/css/install.css?ver=20100228` type=`text/css` /> </head>
Which of the following tools would be BEST for the penetration tester to use to explore this site further?

  1. Burp Suite
  2. DirBuster
  3. WPScan
  4. OWASP ZAP

Answer(s): A


Reference:

https://tools.kali.org/web-applications/burpsuite



A penetration tester wrote the following script to be used in one engagement:



Which of the following actions will this script perform?

  1. Look for open ports.
  2. Listen for a reverse shell.
  3. Attempt to ood open ports.
  4. Create an encrypted tunnel.

Answer(s): A



A company conducted a simulated phishing attack by sending its employees emails that included a link to a site that mimicked the corporate SSO portal. Eighty percent of the employees who received the email clicked the link and provided their corporate credentials on the fake site.
Which of the following recommendations would BEST address this situation?

  1. Implement a recurring cybersecurity awareness education program for all users.
  2. Implement multifactor authentication on all corporate applications.
  3. Restrict employees from web navigation by de ning a list of unapproved sites in the corporate proxy.
  4. Implement an email security gateway to block spam and malware from email communications.

Answer(s): A


Reference:

https://resources.infosecinstitute.com/topic/top-9-free-phishing-simulators/



A security professional wants to test an IoT device by sending an invalid packet to a proprietary service listening on TCP port 3011.
Which of the following would allow the security professional to easily and programmatically manipulate the TCP header length and checksum using arbitrary numbers and to observe how the proprietary service responds?

  1. Nmap
  2. tcpdump
  3. Scapy
  4. hping3

Answer(s): A


Reference:

https://www.mn.uio.no/i /english/research/groups/psy/completedmasters/2017/Kim_Jonatan_Wessel_Bjorneset/ kim_jonatan_wessel_bjorneset_testing_security_for_internet_of_things_a_survey_on_vulnerabilities_in_ip_cameras.pdf (24)



Viewing page 11 of 29
Viewing questions 41 - 44 out of 110 questions



Post your Comments and Discuss CompTIA PT1-002 exam prep with other Community members:

PT1-002 Exam Discussions & Posts