nerdexam
CompTIA

PT0-002 · Question #250

The following output is from reconnaissance on a public-facing banking website: Based on these results, which of the following attacks is MOST likely to succeed?

The correct answer is D. A Heartbleed attack. Based on these results, the most likely attack to succeed is a Heartbleed attack. The Heartbleed attack is a vulnerability in the OpenSSL implementation of the TLS/SSL protocol that allows an attacker to read the memory of the server and potentially steal sensitive information…

Vulnerability discovery and analysis

Question

The following output is from reconnaissance on a public-facing banking website:

Based on these results, which of the following attacks is MOST likely to succeed?

Exhibit

PT0-002 question #250 exhibit

Options

  • AA birthday attack on 64-bit ciphers (Sweet32)
  • BAn attack that breaks RC4 encryption
  • CAn attack on a session ticket extension (Ticketbleed)
  • DA Heartbleed attack

How the community answered

(33 responses)
  • A
    15% (5)
  • B
    3% (1)
  • C
    9% (3)
  • D
    73% (24)

Explanation

Based on these results, the most likely attack to succeed is a Heartbleed attack. The Heartbleed attack is a vulnerability in the OpenSSL implementation of the TLS/SSL protocol that allows an attacker to read the memory of the server and potentially steal sensitive information, such as private keys, passwords, or session tokens. The results show that the website is using OpenSSL 1.0.1f, which is vulnerable to the Heartbleed attack.

Topics

#Heartbleed#Vulnerability Analysis#Reconnaissance#SSL/TLS Vulnerabilities

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice