nerdexam
CompTIA

CAS-003 · Question #13

A penetration tester is conducting an assessment on Comptia.org and runs the following command from a coffee shop while connected to the public Internet: Which of the following should the…

The correct answer is A. The public/private views on the Comptia.org DNS servers are misconfigured. Answer B is incorrect, there’s no information about the server version Answer C is incorrect, there’s no SPF records here Answer D is incorrect. Usually the secondary MX record is simply a different route to the same Answer A is correct, 192.168.x.x is a private IP address and…

Enterprise Security Operations

Question

A penetration tester is conducting an assessment on Comptia.org and runs the following command from a coffee shop while connected to the public Internet:

Which of the following should the penetration tester conclude about the command output?

Exhibit

CAS-003 question #13 exhibit

Options

  • AThe public/private views on the Comptia.org DNS servers are misconfigured
  • BComptia.org is running an older mail server, which may be vulnerable to exploits
  • CThe DNS SPF records have not been updated for Comptia.org
  • D192.168.102.67 is a backup mail server that may be more vulnerable to attack

How the community answered

(58 responses)
  • A
    55% (32)
  • B
    7% (4)
  • C
    24% (14)
  • D
    14% (8)

Explanation

Answer B is incorrect, there’s no information about the server version Answer C is incorrect, there’s no SPF records here Answer D is incorrect. Usually the secondary MX record is simply a different route to the same Answer A is correct, 192.168.x.x is a private IP address and should not be displayed publicly.

Topics

#DNS split-horizon#DNS misconfiguration#penetration testing#public vs private views

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice