PT0-002 · Question #103
A penetration tester was conducting a penetration test and discovered the network traffic was no longer reaching the client's IP address. The tester later discovered the SOC had used sinkholing on…
The correct answer is B. The planning process failed to ensure all teams were notified. Sinkholing is a defensive technique where traffic destined for a suspicious IP is redirected to a controlled server, effectively neutralizing the threat. In this scenario, the SOC (Security Operations Center) identified the penetration tester's IP as malicious and sinkholed it…
Question
A penetration tester was conducting a penetration test and discovered the network traffic was no longer reaching the client's IP address. The tester later discovered the SOC had used sinkholing on the penetration tester's IP address. Which of the following BEST describes what happened?
Options
- AThe penetration tester was testing the wrong assets
- BThe planning process failed to ensure all teams were notified
- CThe client was not ready for the assessment to start
- DThe penetration tester had incorrect contact information
How the community answered
(44 responses)- A5% (2)
- B70% (31)
- C18% (8)
- D7% (3)
Explanation
Sinkholing is a defensive technique where traffic destined for a suspicious IP is redirected to a controlled server, effectively neutralizing the threat. In this scenario, the SOC (Security Operations Center) identified the penetration tester's IP as malicious and sinkholed it because they were not informed the test was occurring. This is a classic deconfliction failure - during the planning phase of a penetration test, all relevant internal teams (SOC, NOC, IT security) must be notified and given the tester's IP addresses so they do not interfere with the assessment.
Topics
Community Discussion
No community discussion yet for this question.