nerdexam
CompTIA

PT0-002 · Question #16

A company is concerned that its cloud VM is vulnerable to a cyberattack and proprietary data may be stolen. A penetration tester determines a vulnerability does exist and exploits the vulnerability…

The correct answer is D. Credential harvesting. Since the Pentester sort cloned the legit cloud VM, looks like this was a ruse to collect credentials from users who would attempt logins into the fake VM thinking it's the collect one.

Attacks and Exploits

Question

A company is concerned that its cloud VM is vulnerable to a cyberattack and proprietary data may be stolen. A penetration tester determines a vulnerability does exist and exploits the vulnerability by adding a fake VM instance to the IaaS component of the client's VM. Which of the following cloud attacks did the penetration tester MOST likely implement?

Options

  • ADirect-to-origin
  • BCross-site scripting
  • CMalware injection
  • DCredential harvesting

How the community answered

(52 responses)
  • A
    12% (6)
  • B
    4% (2)
  • C
    6% (3)
  • D
    79% (41)

Explanation

Since the Pentester sort cloned the legit cloud VM, looks like this was a ruse to collect credentials from users who would attempt logins into the fake VM thinking it's the collect one.

Topics

#Cloud security#Credential harvesting#IaaS#VM exploitation

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice