Appendix AAnswers to Review Questions
Chapter 1: Penetration Testing
- D. Tom's attack achieved the goal of denial by shutting down the web server and preventing legitimate users from accessing it.
- B. By allowing students to change their own grades, this vulnerability provides a pathway to unauthorized alteration of information. Brian should recommend that the school deploy integrity controls that prevent unauthorized modifications.
- A. Snowden released sensitive information to individuals and groups who were not authorized to access that information. That is an example of a disclosure attack.
- C. PCI DSS requires that organizations conduct both internal and external penetration tests on at least an annual basis. Organizations must ...
Get CompTIA PenTest+ Study Guide, 2nd Edition now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.