PT0-002 · Question #335
A penetration tester who was exclusively authorized to conduct a physical assessment noticed there were no cameras pointed at the dumpster for the target company. The penetration tester returned at…
The correct answer is C. Scan the equipment and verify the findings. Dumpster diving revealed receipts showing the company purchased specific models of networking equipment known to be vulnerable. The next logical step in the penetration testing methodology is to scan those devices on the network and verify that the identified models are present…
Question
A penetration tester who was exclusively authorized to conduct a physical assessment noticed there were no cameras pointed at the dumpster for the target company. The penetration tester returned at night and collected garbage that contained receipts for recently purchased networking equipment. The models of equipment purchased are vulnerable to attack. Which of the following is the most likely NEXT step for the penetration tester?
Options
- AAlert the target company of the discovered information.
- BVerify the discovered information is correct with the manufacturer.
- CScan the equipment and verify the findings.
- DReturn to the dumpster for more information.
How the community answered
(48 responses)- A6% (3)
- B17% (8)
- C73% (35)
- D4% (2)
Explanation
Dumpster diving revealed receipts showing the company purchased specific models of networking equipment known to be vulnerable. The next logical step in the penetration testing methodology is to scan those devices on the network and verify that the identified models are present and that the known vulnerabilities are exploitable. This converts the passive OSINT finding into an active, validated finding. Simply alerting the client (A) skips validation. Contacting the manufacturer (B) is unnecessary. Returning to the dumpster (D) does not advance the current lead.
Topics
Community Discussion
No community discussion yet for this question.