CISSP · Question #1063
When assessing web vulnerabilities, how can navigating the dark web add value to a penetration test?
The correct answer is B. Information may be found on related breaches and hacking. The dark web is often a source of illicit information, including data dumps, hacking tools, exploit kits, and discussions about known vulnerabilities, breaches, and cyberattacks. By navigating the dark web, penetration testers can gain insights into: Exploits that attackers are…
Question
When assessing web vulnerabilities, how can navigating the dark web add value to a penetration test?
Options
- AThe actual origin and tools used for the test can be hidden.
- BInformation may be found on related breaches and hacking.
- CVulnerabilities can be tested without impact on the tested environment.
- DInformation may be found on hidden vendor patches.
How the community answered
(27 responses)- A4% (1)
- B78% (21)
- C4% (1)
- D15% (4)
Explanation
The dark web is often a source of illicit information, including data dumps, hacking tools, exploit kits, and discussions about known vulnerabilities, breaches, and cyberattacks. By navigating the dark web, penetration testers can gain insights into: Exploits that attackers are using against systems, which may help in identifying vulnerabilities within the target environment. Credential dumps and other sensitive data that may indicate a breach in the target organization or its related entities. Discussion threads where attackers or malicious actors share techniques or vulnerabilities they are exploiting, which could be relevant to the system being tested.
Topics
Community Discussion
No community discussion yet for this question.