nerdexam
CompTIA

PT0-003 · Question #227

A penetration tester identifies the URL for an internal administration application while following DevOps team members on their commutes. Which of the following attacks did the penetration tester…

The correct answer is A. Shoulder surfing. By following team members on their commute and visually observing the URL as they accessed the internal admin application, the tester is engaging in shoulder surfing, directly watching someone’s screen to capture sensitive information.

Submitted by jian89· Mar 6, 2026Reconnaissance and Enumeration

Question

A penetration tester identifies the URL for an internal administration application while following DevOps team members on their commutes. Which of the following attacks did the penetration tester most likely use?

Options

  • AShoulder surfing
  • BDumpster diving
  • CSpear phishing
  • DTailgating

How the community answered

(48 responses)
  • A
    90% (43)
  • B
    2% (1)
  • C
    4% (2)
  • D
    4% (2)

Explanation

By following team members on their commute and visually observing the URL as they accessed the internal admin application, the tester is engaging in shoulder surfing, directly watching someone’s screen to capture sensitive information.

Topics

#shoulder surfing#social engineering#information gathering

Community Discussion

No community discussion yet for this question.

Full PT0-003 Practice