nerdexam
CompTIA

CAS-003 · Question #390

A security engineer has been hired to design a device that will enable the exfiltration of data from within a well-defended network perimeter during an authorized test. The device must bypass all…

The correct answer is D. Reverse shell endpoint listener. If you find yourself in one of the following scenarios (but not limited to), then you should consider using a reverse shell: The target machine is behind a different private network. The target machine’s firewall blocks incoming connection attempts to your bindshell. Your…

Enterprise Security Operations

Question

A security engineer has been hired to design a device that will enable the exfiltration of data from within a well-defended network perimeter during an authorized test. The device must bypass all firewalls and NIDS in place, as well as allow for the upload of commands from a centralized command and control answer. The total cost of the device must be kept to a minimum in case the device is discovered during an assessment. Which of the following tools should the engineer load onto the device being designed?

Options

  • ACustom firmware with routing key generation.
  • BAutomatic MITM proxy.
  • CTCP beacon broadcast software
  • DReverse shell endpoint listener

How the community answered

(61 responses)
  • A
    15% (9)
  • B
    7% (4)
  • C
    31% (19)
  • D
    48% (29)

Explanation

If you find yourself in one of the following scenarios (but not limited to), then you should consider using a reverse shell: The target machine is behind a different private network. The target machine’s firewall blocks incoming connection attempts to your bindshell. Your payload is unable to bind to the port it wants due to whatever reason. You simply can’t decide what to choose.

Topics

#penetration testing#reverse shell#data exfiltration#C2 communication

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice