nerdexam
GIAC

GPEN · Question #475

A tester has been contracted to perform a penetration test for a corporate client. The scope of the test is limited to end-user workstations and client programs only. Which of die following actions is

Sign in or unlock GPEN to reveal the answer and full explanation for question #475. The question stem and answer options stay visible for context.

Penetration Testing Foundations & Reconnaissance

Question

A tester has been contracted to perform a penetration test for a corporate client. The scope of the test is limited to end-user workstations and client programs only. Which of die following actions is allowed in this test?

Options

  • AAttempting to redirect the internal gateway through ARP poisoning
  • BActivating bot clients and performing a denial-of-service against the gateway.
  • CSniffing and attempting to crack the Domain Administrators password hash.
  • DSending a malicious pdf to a user and exploiting a vulnerable Reader version.

Unlock GPEN to see the answer

You've previewed enough free GPEN questions. Unlock GPEN for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#rules of engagement#scope definition#client-side exploitation#authorized actions
Full GPEN Practice