Free PT1-002 Exam Braindumps (page: 2)

Page 1 of 29

A client wants a security assessment company to perform a penetration test against its hot site. The purpose of the test is to determine the effectiveness of the defenses that protect against disruptions to business continuity.
Which of the following is the MOST important action to take before starting this type of assessment?

  1. Ensure the client has signed the SOW.
  2. Verify the client has granted network access to the hot site.
  3. Determine if the failover environment relies on resources not owned by the client.
  4. Establish communication and escalation procedures with the client.

Answer(s): C



Performing a penetration test against an environment with SCADA devices brings additional safety risk because the:

  1. devices produce more heat and consume more power.
  2. devices are obsolete and are no longer available for replacement.
  3. protocols are more di cult to understand.
  4. devices may cause physical world effects.

Answer(s): C


Reference:

https://www.hindawi.com/journals/scn/2018/3794603/



Which of the following documents describes speci c activities, deliverables, and schedules for a penetration tester?

  1. NDA
  2. MSA
  3. SOW
  4. MOU

Answer(s): C



A company hired a penetration-testing team to review the cyber-physical systems in a manufacturing plant. The team immediately discovered the supervisory systems and PLCs are both connected to the company intranet.
Which of the following assumptions, if made by the penetration- testing team, is MOST likely to be valid?

  1. PLCs will not act upon commands injected over the network.
  2. Supervisors and controllers are on a separate virtual network by default.
  3. Controllers will not validate the origin of commands.
  4. Supervisory systems will detect a malicious injection of code/commands.

Answer(s): C






Post your Comments and Discuss CompTIA PT1-002 exam with other Community members:

PT1-002 Discussions & Posts