CompTIA PenTest+ Certification Practice Exam CHAPTER 1 Solved 100%
A - Answer A company has been hacked, and several e-mails that are embarrassing to the CFO and potentially indicative of criminal activity on their part have been leaked to the press. Incident response has determined that only three user accounts accessed the organization's mail server in the 24 hours immediately preceding the disclosure. One of these accounts was assigned to an employee who was fired two weeks before the incident. No other access to the system has been found by incident response. What type of threat actor should be considered a likely culprit for this breach first? A. Insider threat B. Advanced persistent threat (APT) C. Hacktivist D. Script kiddie B - Answer Which step in Microsoft's published guidance on threat modeling consists of documenting the technologies in use in the architecture of an information systems environment and discovering how they are implemented therein? A. Rate the threats B. Architecture overview C. Identify assets D. Decompose the application D - Answer In the scoping phase of a penetration testing engagement, how might a penetration tester effectively obtain the information necessary to begin testing? A. Waiting for the client to tell them B. Asking previous penetration test providers what they looked at C. Starting an e-mail chain with business leadership so communications are documented D. Sending a pre-engagement survey (also known as a scoping document) to the client for them to fill out C - Answer Which contractual document is a confidentiality agreement that protects the proprietary information and intellectual property of a business? A. Master service agreement (MSA) B. Statement of work (SOW) C. Nondisclosure agreement (NDA) D. Written authorization letter C - Answer With respect to penetration testing conducted behind perimeter defenses, what does it mean to be provided limited access? A. Client personnel will only be available for limited periods of time. B. Network access to the target systems or networks will only be permitted during predefined hours. C. The penetration tester is only provided with initial, basic connectivity to target systems. D. The penetration tester is provided with an administrative user account. D - Answer A red team assessment is typically conducted in a manner consistent with what type of threat actor? A. Hacktivist B. Insider threat C. Script kiddie D. Advanced persistent threat C - Answer As noted in Microsoft's threat modeling procedures, the formula used to calculate total risk is as follows: Risk = Probability * Damage Potential During a penetration test, you identify a vulnerability with a relatively high damage potential (8/10) and an above-average probability of occurrence (7/10). Per the preceding formula, what is the associated risk value for this vulnerability? A. 15 B. 1 C. 56 D. 560 A - Answer Per Microsoft's threat modeling system, what would the final risk prioritization be for this vulnerability? A. Medium B. Low C. High D. Urgent C - Answer In Microsoft's guidance on threat modeling, which step involves the categorization of external and internal threats to an organization? A. Rate the threats B. Decompose the application C. Identify threats D. Identify assets B - Answer A swagger document is intended to serve what purpose? A. To describe functionality offering through a web service B. To provide API descriptions and test cases C. To offer simulated testing scenarios, allow inspection and debugging of requests, or possibly uncover undocumented APIs D. To elaborate on the framework in use for development of a software application B - Answer If travel to remote field offices or data centers is required as part of a penetration test, in what contractual document would this usually be found? A. Nondisclosure agreement B. Statement of work C. Written authorization letter D. Rules of engagement B - Answer All the following assets may be candidates for target selection for a penetration test except:
Documentinformatie
- Geüpload op
- 8 september 2023
- Aantal pagina's
- 10
- Geschreven in
- 2023/2024
- Type
- Tentamen (uitwerkingen)
- Bevat
- Vragen en antwoorden