As a penetration tester, you are tasked with assessing the security of an AI system used by an organization for customer support. You need to explain potential vulnerabilities and attacks that could be exploited. Which of the following BEST describes a prompt injection attack on an AI system?
A penetration tester is conducting an assessment of cloud wo…
A penetration tester is conducting an assessment of cloud workloads and identifies a vulnerable API that could potentially be exploited during the workload runtime. Which of the following actions would BEST help the tester leverage this vulnerability?
During a security assessment, a pentester discovers that a w…
During a security assessment, a pentester discovers that a web application allows users to access other users’ data by changing the user ID parameter in the URL. What should the pentester recommend as the first step to mitigate this vulnerability?
Which of the following BEST describes the use of scripts dur…
Which of the following BEST describes the use of scripts during the enumeration and scanning phases of a penetration test?
During a physical penetration test, you encounter a locked d…
During a physical penetration test, you encounter a locked door with an access card lock. After evaluating the situation, which of the following actions would be the MOST appropriate to gain access, assuming you are working within legal and ethical constraints of the pentest?
Which of the following BEST describes the purpose of network…
Which of the following BEST describes the purpose of network vulnerability scans in penetration testing?
During a penetration test, the Rules of Engagement (RoE) are…
During a penetration test, the Rules of Engagement (RoE) are established to define the guidelines and boundaries within which the test should be conducted. Which of the following is NOT typically covered by the RoE?
A penetration tester is tasked with assessing the security o…
A penetration tester is tasked with assessing the security of a client’s cloud environment, which includes both AWS and Kubernetes clusters. The tester needs to evaluate the security configurations of the AWS account, audit Kubernetes clusters for vulnerabilities, and ensure a comprehensive AWS compliance audit occurs following CIS benchmarks. Which combination of tools should the tester use to perform these tasks efficiently?
An attacker wants to maintain persistence on a compromised W…
An attacker wants to maintain persistence on a compromised Windows system by configuring a program to run at startup for the current user. Which registry key would be MOST appropriate for this purpose, and what is a potential limitation of using this key?
You have been contracted to conduct a Penetration Testing (P…
You have been contracted to conduct a Penetration Testing (PenTest) exercise for an organization. After gathering all the project requirements and scoping the engagement, you proceed to obtain formal permission to begin testing. The PenTest will involve testing internal resources, including Active Directory, which could potentially disrupt services if breached. Additionally, you need to ensure that sensitive information accessed during the PenTest is protected, and all parties involved are clear on their responsibilities and liabilities. Which of the following documents should be signed and reviewed to ensure a clear understanding of the scope, data handling and confidentiality, risk management, and legal protections?