nerdexam
McAfee

MA0-150 · Question #16

During an external penetration test, the consultant identifies a Windows-based server that is running Apache Tomcat Manager with a default username and password combination. After uploading a WAR…

The correct answer is A. Net user /add consultant Passwordl23 C. Net localgroup administrators /add consultant. See the full explanation below for the reasoning.

Question

During an external penetration test, the consultant identifies a Windows-based server that is running Apache Tomcat Manager with a default username and password combination. After uploading a WAR file, the consultant has the ability to execute commands via a browser under the context of NT AUTHORITY/SYSTEM. Which of the following commands would allow the consultant to create a user and put the newly created user in the administrators group? (Choose two)

Options

  • ANet user /add consultant Passwordl23
  • BNet localuser /add consultant Passwordl23
  • CNet localgroup administrators /add consultant
  • DNet administrators /add consultant Passwordl23
  • ECreating users under the context of SYSTEM is not allowed

How the community answered

(26 responses)
  • A
    73% (19)
  • B
    15% (4)
  • D
    8% (2)
  • E
    4% (1)

Community Discussion

No community discussion yet for this question.

Full MA0-150 Practice