Which section of a penetration test report is designed to pr…
Which section of a penetration test report is designed to provide a high-level overview for non-technical stakeholders, summarizing the scope, key findings, overall risk assessment, and strategic recommendations without delving into technical details?
Read DetailsA penetration tester has successfully gained access to a tar…
A penetration tester has successfully gained access to a target system and identified sensitive customer data. The tester now needs to exfiltrate the data covertly to avoid detection. Which of the following methods would be the MOST appropriate for ensuring the data is both hidden and protected during the exfiltration process?
Read DetailsA penetration tester is assessing a web application that use…
A penetration tester is assessing a web application that uses OpenID for authentication. The tester notices that the web app improperly stores authentication tokens in the browser’s local storage without encryption. Which potential vulnerability is the application exposed to due to this misconfiguration?
Read Details