exam questions

Exam PT1-002 All Questions

View all questions & answers for the PT1-002 exam

Exam PT1-002 topic 1 question 65 discussion

Actual exam question from CompTIA's PT1-002
Question #: 65
Topic #: 1
[All PT1-002 Questions]

A penetration tester who is conducting a web-application test discovers a clickjacking vulnerability associated with a login page to financial data. Which of the following should the tester do with this information to make this a successful exploit?

  • A. Perform XSS.
  • B. Conduct a watering-hole attack.
  • C. Use BeEF.
  • D. Use browser autopwn.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
IamBlackFire
6 months, 3 weeks ago
BeEF has an active community supporting it – the developers release updates and new features monthly. BeEF is free, open-source, and a popular tool in the web security world. Integrating the clickjacking tool into BeEF is a good way to distribute the tool to a lot of security professionals who would find it most useful. Practical Clickjacking with BeEF Brigette Lundeen Center for Secure and Dependable Systems University of Idaho [email protected] Brigette Lundeen Center for Secure and Dependable Systems University of Idaho [email protected]
upvoted 2 times
...
[Removed]
2 years, 8 months ago
Answer is definitely A https://owasp.org/www-community/attacks/Clickjacking
upvoted 2 times
...
BinarySoldier
3 years, 5 months ago
A is correct. https://www.acunetix.com/blog/articles/clickjacking-blind-xss/
upvoted 4 times
Davar39
3 years, 3 months ago
Thanks, you are right.
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago