312-49 · Question #364
You work as a penetration tester for Hammond Security Consultants. You are currently working on a contract for the state government of California. Your next step is to initiate a DoS attack on their n
The correct answer is B. List weak points on their network. During a penetration test, initiating a controlled DoS attack helps identify weak points in the network - such as services that crash, systems that fail to implement rate limiting, or infrastructure that lacks DoS mitigation (e.g., no IPS, no load balancing, no traffic scrubbing)
Question
You work as a penetration tester for Hammond Security Consultants. You are currently working on a contract for the state government of California. Your next step is to initiate a DoS attack on their network. Why would you want to initiate a DoS attack on a system you are testing?
Options
- ADemonstrate that no system can be protected againstDoS attacks
- BList weak points on their network
- CShow outdatedeQuipment so it can be replaced
- DUse attack as a launching point to penetrate deeper into the network
How the community answered
(19 responses)- B95% (18)
- C5% (1)
Explanation
During a penetration test, initiating a controlled DoS attack helps identify weak points in the network - such as services that crash, systems that fail to implement rate limiting, or infrastructure that lacks DoS mitigation (e.g., no IPS, no load balancing, no traffic scrubbing). The goal is not to cause damage but to document vulnerabilities so the client can remediate them. A legitimate pen test DoS is scoped and authorized, and its findings are reported to improve the client's defenses.
Topics
Community Discussion
No community discussion yet for this question.