PT0-003 · Question #4
A penetration tester is evaluating a SCADA system. The tester receives local access to a workstation that is running a single application. While navigating through the application, the tester opens…
The correct answer is A. Kiosk escape. A kiosk escape attack occurs when a restricted interface (such as a locked-down SCADA application or kiosk mode system) is bypassed, allowing access to the underlying operating system. This is typically achieved through keyboard shortcuts, application misconfigurations, or…
Question
A penetration tester is evaluating a SCADA system. The tester receives local access to a workstation that is running a single application. While navigating through the application, the tester opens a terminal window and gains access to the underlying operating system. Which of the following attacks is the tester performing?
Options
- AKiosk escape
- BArbitrary code execution
- CProcess hollowing
- DLibrary injection
How the community answered
(22 responses)- A91% (20)
- B5% (1)
- C5% (1)
Explanation
A kiosk escape attack occurs when a restricted interface (such as a locked-down SCADA application or kiosk mode system) is bypassed, allowing access to the underlying operating system. This is typically achieved through keyboard shortcuts, application misconfigurations, or unprotected terminal access. In this scenario, the penetration tester breaks out of the restricted SCADA application and gains OS access, making kiosk escape the correct attack type.
Topics
Community Discussion
No community discussion yet for this question.