PT0-003 · Question #46
A penetration tester discovers evidence of an advanced persistent threat on the network that is being tested. Which of the following should the tester do next?
The correct answer is A. Report the finding. Upon discovering evidence of an advanced persistent threat (APT) on the network, the penetration tester should report the finding immediately. Advanced Persistent Threat (APT): Definition: APTs are prolonged and targeted cyberattacks in which an intruder gains access to a…
Question
A penetration tester discovers evidence of an advanced persistent threat on the network that is being tested. Which of the following should the tester do next?
Options
- AReport the finding.
- BAnalyze the finding.
- CRemove the threat.
- DDocument the finding and continue testing.
How the community answered
(47 responses)- A55% (26)
- B15% (7)
- C6% (3)
- D23% (11)
Explanation
Upon discovering evidence of an advanced persistent threat (APT) on the network, the penetration tester should report the finding immediately. Advanced Persistent Threat (APT): Definition: APTs are prolonged and targeted cyberattacks in which an intruder gains access to a network and remains undetected for an extended period. Significance: APTs often involve sophisticated tactics, techniques, and procedures (TTPs) aimed at stealing data or causing disruption. Immediate Reporting: Criticality: Discovering an APT requires immediate attention from the organization's security team due to the potential impact and persistence of the threat. Chain of Command: Following the protocol for reporting such findings ensures that appropriate incident response measures are initiated promptly.
Topics
Community Discussion
No community discussion yet for this question.