An attacker wants to maintain persistence on a compromised W…
An attacker wants to maintain persistence on a compromised Windows system by configuring a program to run at startup for the current user. Which registry key would be MOST appropriate for this purpose, and what is a potential limitation of using this key?
Read DetailsA penetration tester is tasked with assessing the security o…
A penetration tester is tasked with assessing the security of a client’s cloud environment, which includes both AWS and Kubernetes clusters. The tester needs to evaluate the security configurations of the AWS account, audit Kubernetes clusters for vulnerabilities, and ensure a comprehensive AWS compliance audit occurs following CIS benchmarks. Which combination of tools should the tester use to perform these tasks efficiently?
Read DetailsDuring a security assessment, a pentester discovers that a w…
During a security assessment, a pentester discovers that a web application allows users to access other users’ data by changing the user ID parameter in the URL. What should the pentester recommend as the first step to mitigate this vulnerability?
Read DetailsA penetration tester is simulating a relay attack to gain un…
A penetration tester is simulating a relay attack to gain unauthorized access to a network. The tester captures authentication data and uses it to impersonate a legitimate user. Which of the following techniques is the tester most likely using in this scenario?
Read Details