nerdexam
(ISC)2

CAP · Question #101

Penetration testing (also called pen testing) is the practice of testing a computer system, network, or Web application to find vulnerabilities that an attacker could exploit. Which of the following…

The correct answer is A. Race conditions B. Social engineering D. Buffer overflows E. Kernel flaws F. Trojan horses G. File and directory permissions. Penetration testing can exploit nearly every technical and human weakness in a system. Race conditions (A) can be triggered to gain unauthorized access or corrupt data. Social engineering (B) manipulates people into revealing credentials or granting access. Buffer overflows (D)…

Assessment/Audit of Security and Privacy Controls

Question

Penetration testing (also called pen testing) is the practice of testing a computer system, network, or Web application to find vulnerabilities that an attacker could exploit. Which of the following areas can be exploited in a penetration test? Each correct answer represents a complete solution. Choose all that apply.

Options

  • ARace conditions
  • BSocial engineering
  • CInformation system architectures
  • DBuffer overflows
  • EKernel flaws
  • FTrojan horses
  • GFile and directory permissions

How the community answered

(54 responses)
  • A
    91% (49)
  • C
    9% (5)

Explanation

Penetration testing can exploit nearly every technical and human weakness in a system. Race conditions (A) can be triggered to gain unauthorized access or corrupt data. Social engineering (B) manipulates people into revealing credentials or granting access. Buffer overflows (D) allow attackers to overwrite memory and execute arbitrary code. Kernel flaws (E) are low-level OS vulnerabilities that can grant elevated privileges. Trojan horses (F) are malicious programs disguised as legitimate software that pen testers may deploy to test detection capabilities. File and directory permissions (G) are tested to check for misconfigured access controls. Information system architectures (C) is the exception - it is a design framework or blueprint, not an exploitable vulnerability itself. Pen testers attack flaws within an architecture, not the architecture concept.

Topics

#Penetration Testing#Vulnerability Exploitation#Attack Vectors#Security Testing

Community Discussion

No community discussion yet for this question.

Full CAP Practice