nerdexam
CompTIA

PT0-002 · Question #341

During enumeration, a red team discovered that an external web server was frequented by employees. After compromising the server, which of the following attacks would BEST support compromising…

The correct answer is C. A watering-hole attack. The best attack that would support compromising company systems after compromising an external web server frequented by employees is a watering-hole attack, which is an attack that involves compromising a website that is visited by a specific group of users, such as employees…

Attacks and Exploits

Question

During enumeration, a red team discovered that an external web server was frequented by employees. After compromising the server, which of the following attacks would BEST support compromising company systems?

Options

  • AA side-channel attack
  • BA command injection attack
  • CA watering-hole attack
  • DA cross-site scripting attack

How the community answered

(41 responses)
  • A
    7% (3)
  • B
    10% (4)
  • C
    80% (33)
  • D
    2% (1)

Explanation

The best attack that would support compromising company systems after compromising an external web server frequented by employees is a watering-hole attack, which is an attack that involves compromising a website that is visited by a specific group of users, such as employees of a target company, and injecting malicious code or content into the website that can infect or exploit the users' devices when they visit the website. A watering-hole attack can allow an attacker to compromise company systems by targeting their employees who frequent the external web server, and taking advantage of their trust or habit of visiting the website. A watering-hole attack can be performed by using tools such as BeEF, which is a tool that can hook web browsers and execute commands on them. The other options are not likely attacks that would support compromising company systems after compromising an external web server frequented by employees. A side- channel attack is an attack that involves exploiting physical characteristics or implementation flaws of a system or device, such as power consumption, electromagnetic radiation, timing, or sound, to extract sensitive information or bypass security mechanisms. A command injection attack is an attack that exploits a vulnerability in a system or application that allows an attacker to execute arbitrary commands on the underlying OS or shell. A cross-site scripting attack is an attack that exploits a vulnerability in a web application that allows an attacker to inject malicious scripts into web pages that are viewed by other users.

Topics

#Watering Hole Attack#Red Team Strategy#Initial Access#Client-Side Exploitation

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice