nerdexam
CompTIA

PT0-002 · Question #502

A client claims that a ransomware attack has crippled its corporate network following a penetration test assessment. Which of the following is the most likely root cause of this issue?

The correct answer is D. Failure to remove tester-created credentials. The most probable root cause for a ransomware attack immediately following a penetration test is the failure to remove tester-created credentials, leaving backdoors for malicious actors.

Post-exploitation and lateral movement

Question

A client claims that a ransomware attack has crippled its corporate network following a penetration test assessment. Which of the following is the most likely root cause of this issue?

Options

  • AClient reluctance to accept findings
  • BLack of attestation
  • CIncomplete data destruction process
  • DFailure to remove tester-created credentials

How the community answered

(32 responses)
  • A
    22% (7)
  • B
    6% (2)
  • C
    9% (3)
  • D
    63% (20)

Why each option

The most probable root cause for a ransomware attack immediately following a penetration test is the failure to remove tester-created credentials, leaving backdoors for malicious actors.

AClient reluctance to accept findings

Client reluctance to accept findings might lead to unaddressed vulnerabilities in the future, but it would not directly cause a ransomware attack immediately after the test concludes unless the test itself introduced the vulnerability.

BLack of attestation

Lack of attestation refers to the absence of a third-party declaration of compliance or findings, which is an administrative issue and does not directly cause a technical compromise like a ransomware attack.

CIncomplete data destruction process

An incomplete data destruction process typically relates to the secure erasure of sensitive data, not the creation of persistent access points that could lead to a network compromise post-test.

DFailure to remove tester-created credentialsCorrect

During a penetration test, testers often create temporary accounts, backdoors, or leave tools on the network to simulate real-world attacks. If these artifacts, especially credentials or access points, are not thoroughly removed and secured post-assessment, they can be exploited by threat actors who may discover and leverage them to launch attacks like ransomware.

Concept tested: Post-penetration test hygiene

Topics

#Post-exploitation cleanup#Tester artifacts#Credential management#Persistence

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice