nerdexam
CompTIA

PT0-003 · Question #25

A tester is performing an external phishing assessment on the top executives at a company. Two- factor authentication is enabled on the executives' accounts that are in the scope of work. Which of…

The correct answer is A. Configure an external domain using a typosquatting technique. Configure Evilginx to bypass two-. To bypass two-factor authentication (2FA) and gain access to the executives' accounts, the tester should use Evilginx with a typosquatting domain. Evilginx is a man-in-the-middle attack framework used to bypass 2FA by capturing session tokens.

Submitted by mateo_ar· Mar 6, 2026Attacks and Exploits

Question

A tester is performing an external phishing assessment on the top executives at a company. Two- factor authentication is enabled on the executives' accounts that are in the scope of work. Which of the following should the tester do to get access to these accounts?

Options

  • AConfigure an external domain using a typosquatting technique. Configure Evilginx to bypass two-
  • BConfigure Gophish to use an external domain. Clone the email portal web page from the
  • CConfigure an external domain using a typosquatting technique. Configure SET to bypass two-
  • DConfigure Gophish to use an external domain. Clone the email portal web page from the

How the community answered

(32 responses)
  • A
    53% (17)
  • B
    16% (5)
  • C
    6% (2)
  • D
    25% (8)

Explanation

To bypass two-factor authentication (2FA) and gain access to the executives' accounts, the tester should use Evilginx with a typosquatting domain. Evilginx is a man-in-the-middle attack framework used to bypass 2FA by capturing session tokens.

Topics

#phishing#2FA bypass#typosquatting#Evilginx#social engineering

Community Discussion

No community discussion yet for this question.

Full PT0-003 Practice