QuestionQ688

Scanning and Mapping

How could the information below be used during a penetration test?

Question Image

  • A Attempt to use an Apache exploit on the server
  • B Make a zone transfer request on the DNS server
  • C Harvest the user information to attempt to gain access
  • D Use the heartbleed vulnerability to pull all user data off the server
Explanation

Document metadata can reveal usernames and other identity information that may support account enumeration, targeted phishing, password spraying, or other attempts to obtain authorized access during a penetration test.

Community Discussion

No comments yet. Be the first to start the discussion!