exam questions

Exam PT0-001 All Questions

View all questions & answers for the PT0-001 exam

Exam PT0-001 topic 1 question 40 discussion

Actual exam question from CompTIA's PT0-001
Question #: 40
Topic #: 1
[All PT0-001 Questions]

A penetration tester observes that the content security policy header is missing during a web application penetration test. Which of the following techniques would the penetration tester MOST likely perform?

  • A. Command injection attack
  • B. Clickjacking attack
  • C. Directory traversal attack
  • D. Remote file inclusion attack
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️
Reference:
https://geekflare.com/http-header-implementation/

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
mr_robot
Highly Voted 5 years, 3 months ago
PenTest+ Practice Tests Book B. - Clickjacking is when a tester uses multiple transparent layers to trick a user into clicking a button or link on another page when they were intending to click the toplevel page. The tester is “hijacking” clicks and routing them to another page. In web browsers, clickjacking is a browser security issue that is a vulnerability across a variety of browsers and platforms. A clickjack takes the form of embedded code or a script that can execute without the user’s knowledge, such as clicking a button that appears to perform another function.
upvoted 5 times
...
miabe
Most Recent 3 years ago
Selected Answer: B
looks good to me
upvoted 1 times
...
someguy1393
4 years, 7 months ago
This one was tough. Everything I read online said that CSP (Content Security Policy) helped to prevent XSS. However, I finally found a source that stated it protects against XSS and ClickJacking. Since XSS is not an option here ClickJacking is the best answer. Source: https://content-security-policy.com/
upvoted 3 times
tester27
4 years ago
the reference on the answer also mentioned clickjacking is prevented by CSP
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...