nerdexam
CompTIA

PT0-002 · Question #22

A penetration tester is testing a web application that is hosted by a public cloud provider. The tester is able to query the provider's metadata and get the credentials used by the instance to…

The correct answer is B. Server-side request forgery. https://owasp.org/www-community/attacks/Server_Side_Request_Forgery

Attacks and Exploits

Question

A penetration tester is testing a web application that is hosted by a public cloud provider. The tester is able to query the provider's metadata and get the credentials used by the instance to authenticate itself. Which of the following vulnerabilities has the tester exploited?

Options

  • ACross-site request forgery
  • BServer-side request forgery
  • CRemote file inclusion
  • DLocal file inclusion

How the community answered

(53 responses)
  • A
    6% (3)
  • B
    74% (39)
  • C
    13% (7)
  • D
    8% (4)

Explanation

https://owasp.org/www-community/attacks/Server_Side_Request_Forgery

Topics

#Server-side request forgery#Cloud security#Metadata service exploitation#Credential theft

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice