Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam PT0-002 topic 1 question 267 discussion

Actual exam question from CompTIA's PT0-002
Question #: 267
Topic #: 1
[All PT0-002 Questions]

HOTSPOT
-

A penetration tester is performing reconnaissance for a web application assessment. Upon investigation, the tester reviews the robots.txt file for items of interest.


INSTRUCTIONS
-

Select the tool the penetration tester should use for further investigation.

Select the two entries in the robots.txt file that the penetration tester should recommend for removal.

If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
TiredOfTests
Highly Voted 6 months, 1 week ago
For the tool selection: Given that this is a web application assessment and we are investigating the robots.txt file, WPScan would be the most suitable tool to use for further investigation, assuming the web application is based on WordPress. WPScan is specifically designed to scan WordPress websites for vulnerabilities. For the entries in the robots.txt file that should be recommended for removal: Allow: /admin - This entry allows web crawlers to access the admin directory, which could expose sensitive information. Allow: /wp-login.php - Allowing access to the WordPress login page through robots.txt could attract unwanted attention from attackers. Both of these entries expose sensitive areas of the web application to potential attackers and should be removed.
upvoted 6 times
...
SimonR2
Highly Voted 4 months, 1 week ago
The tool selection will be WPScan, however I think the given answer is wrong for the pages to disallow for robot.txt. For Wordpress, it should be: "/wp-admin" and "/wp-login.php" - there is no "/admin" wordpress directory as default unless an administrator created it. If you google the default Wordpress admin directories or ask Chatgpt you'll find the answer to be similar to this: By default, the WordPress admin login page is located at http://yoursite.com/wp-admin or http://yoursite.com/wp-login.php. Replace "yoursite.com" with your actual domain.
upvoted 5 times
...
Cyber_Soter
Most Recent 1 week, 6 days ago
In a robots.txt file, the "Allow" directive is used to explicitly allow access to specific URLs for web crawlers. However, if you want to restrict access to certain sensitive or administrative URLs, you would typically use the "Disallow" directive instead of "Allow." Therefore, in this scenario, you would want to remove: Allow: /admin Allow: /wp-admin Removing these directives would prevent web crawlers from accessing URLs related to administrative sections of the website ("/admin" and "/wp-admin"), which can help improve security by restricting unauthorized access to sensitive areas. Allow:/wp-login.php This directive allows access to the "/wp-login.php" URL, which is typically the login page for WordPress sites. If you're aiming to restrict access to administrative areas, it's generally advisable to allow access to the login page so that legitimate users can authenticate and access the site's admin interface. Therefore, you would not remove this directive
upvoted 1 times
...
LiveLaughToasterBath
3 months, 1 week ago
The WordPress root directory contains the following files and folders: wp-admin wp-content wp-includes .htaccess index.php license.txt readme.html wp-activate.php wp-blog-header.php wp-comments-post.php wp-config-sample.php wp-cron.php wp-links-opml.php wp-load.php wp-login.php wp-mail.php wp-settings.php wp-signup.php wp-trackback.php xmlrpc.php wp-feed.php
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...