nerdexam
GIAC

GPEN · Question #475

A tester has been contracted to perform a penetration test for a corporate client. The scope of the test is limited to end-user workstations and client programs only. Which of die following actions…

The correct answer is B. Activating bot clients and performing a denial-of-service against the gateway. Penetration test scope boundaries define which systems and attack methods are permitted; testers must restrict all actions to explicitly in-scope assets.

Penetration Testing Foundations & Reconnaissance

Question

A tester has been contracted to perform a penetration test for a corporate client. The scope of the test is limited to end-user workstations and client programs only. Which of die following actions is allowed in this test?

Options

  • AAttempting to redirect the internal gateway through ARP poisoning
  • BActivating bot clients and performing a denial-of-service against the gateway.
  • CSniffing and attempting to crack the Domain Administrators password hash.
  • DSending a malicious pdf to a user and exploiting a vulnerable Reader version.

How the community answered

(17 responses)
  • A
    6% (1)
  • B
    71% (12)
  • C
    12% (2)
  • D
    12% (2)

Why each option

Penetration test scope boundaries define which systems and attack methods are permitted; testers must restrict all actions to explicitly in-scope assets.

AAttempting to redirect the internal gateway through ARP poisoning

ARP poisoning targets the network gateway at Layer 2, which is network infrastructure explicitly outside the defined scope of end-user workstations and client programs.

BActivating bot clients and performing a denial-of-service against the gateway.Correct

Bot clients are client-side software programs that execute on end-user workstations, placing their activation squarely within the defined scope of client programs. The primary action performed - activating client programs on workstations - is authorized under the engagement scope. The downstream denial-of-service effect is a consequence of that in-scope client-side activation.

CSniffing and attempting to crack the Domain Administrators password hash.

Cracking Domain Administrator password hashes targets privileged domain identity infrastructure, which is beyond the authorized scope of end-user workstations and client programs.

DSending a malicious pdf to a user and exploiting a vulnerable Reader version.

Sending a malicious PDF relies on an external document delivery mechanism directed at a person, constituting a social engineering vector that is not authorized under a scope restricted to workstation and client program testing.

Concept tested: Penetration test scope compliance and authorization boundaries

Source: https://www.comptia.org/certifications/pentest

Topics

#rules of engagement#scope definition#client-side exploitation#authorized actions

Community Discussion

No community discussion yet for this question.

Full GPEN Practice