GPEN · Question #475
A tester has been contracted to perform a penetration test for a corporate client. The scope of the test is limited to end-user workstations and client programs only. Which of die following actions…
The correct answer is B. Activating bot clients and performing a denial-of-service against the gateway. Penetration test scope boundaries define which systems and attack methods are permitted; testers must restrict all actions to explicitly in-scope assets.
Question
A tester has been contracted to perform a penetration test for a corporate client. The scope of the test is limited to end-user workstations and client programs only. Which of die following actions is allowed in this test?
Options
- AAttempting to redirect the internal gateway through ARP poisoning
- BActivating bot clients and performing a denial-of-service against the gateway.
- CSniffing and attempting to crack the Domain Administrators password hash.
- DSending a malicious pdf to a user and exploiting a vulnerable Reader version.
How the community answered
(17 responses)- A6% (1)
- B71% (12)
- C12% (2)
- D12% (2)
Why each option
Penetration test scope boundaries define which systems and attack methods are permitted; testers must restrict all actions to explicitly in-scope assets.
ARP poisoning targets the network gateway at Layer 2, which is network infrastructure explicitly outside the defined scope of end-user workstations and client programs.
Bot clients are client-side software programs that execute on end-user workstations, placing their activation squarely within the defined scope of client programs. The primary action performed - activating client programs on workstations - is authorized under the engagement scope. The downstream denial-of-service effect is a consequence of that in-scope client-side activation.
Cracking Domain Administrator password hashes targets privileged domain identity infrastructure, which is beyond the authorized scope of end-user workstations and client programs.
Sending a malicious PDF relies on an external document delivery mechanism directed at a person, constituting a social engineering vector that is not authorized under a scope restricted to workstation and client program testing.
Concept tested: Penetration test scope compliance and authorization boundaries
Source: https://www.comptia.org/certifications/pentest
Topics
Community Discussion
No community discussion yet for this question.