nerdexam
CompTIA

PT0-002 · Question #335

A penetration tester who was exclusively authorized to conduct a physical assessment noticed there were no cameras pointed at the dumpster for the target company. The penetration tester returned at…

The correct answer is C. Scan the equipment and verify the findings. Dumpster diving revealed receipts showing the company purchased specific models of networking equipment known to be vulnerable. The next logical step in the penetration testing methodology is to scan those devices on the network and verify that the identified models are present…

Information Gathering and Vulnerability Scanning

Question

A penetration tester who was exclusively authorized to conduct a physical assessment noticed there were no cameras pointed at the dumpster for the target company. The penetration tester returned at night and collected garbage that contained receipts for recently purchased networking equipment. The models of equipment purchased are vulnerable to attack. Which of the following is the most likely NEXT step for the penetration tester?

Options

  • AAlert the target company of the discovered information.
  • BVerify the discovered information is correct with the manufacturer.
  • CScan the equipment and verify the findings.
  • DReturn to the dumpster for more information.

How the community answered

(48 responses)
  • A
    6% (3)
  • B
    17% (8)
  • C
    73% (35)
  • D
    4% (2)

Explanation

Dumpster diving revealed receipts showing the company purchased specific models of networking equipment known to be vulnerable. The next logical step in the penetration testing methodology is to scan those devices on the network and verify that the identified models are present and that the known vulnerabilities are exploitable. This converts the passive OSINT finding into an active, validated finding. Simply alerting the client (A) skips validation. Contacting the manufacturer (B) is unnecessary. Returning to the dumpster (D) does not advance the current lead.

Topics

#Dumpster Diving#Physical Reconnaissance#Vulnerability Scanning#Penetration Testing Process

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice