exam questions

Exam PT1-002 All Questions

View all questions & answers for the PT1-002 exam

Exam PT1-002 topic 1 question 9 discussion

Actual exam question from CompTIA's PT1-002
Question #: 9
Topic #: 1
[All PT1-002 Questions]

A penetration tester recently completed a review of the security of a core network device within a corporate environment. The key findings are as follows:
* The following request was intercepted going to the network device:

GET /login HTTP/1.1 -

Host: 10.50.100.16 -
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Firefox/31.0

Accept-Language: en-US,en;q=0.5 -

Connection: keep-alive -
Authorization: Basic WU9VUilOQU1FOnNlY3JldHBhc3N3b3jk
* Network management interfaces are available on the production network.
* An Nmap scan returned the following:

Which of the following would be BEST to add to the recommendations section of the final report? (Choose two.)

  • A. Enforce enhanced password complexity requirements.
  • B. Disable or upgrade SSH daemon.
  • C. Disable HTTP/301 redirect configuration.
  • D. Create an out-of-band network for management.
  • E. Implement a better method for authentication.
  • F. Eliminate network management and control interfaces.
Show Suggested Answer Hide Answer
Suggested Answer: DE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Bluedegard
Highly Voted 1 year, 3 months ago
Selected Answer: DE
You guys are stupid. Let's see my discussion A. is wrong because using complex password is useless if you still rely on basic authentication that the password can be simply revealed by decoding base64 on HTTP traffic. B. is wrong because SSH daemon is already secure. Protocol 2.0 mean this is SSH v2. Moreover, how do you know whether this Cisco version is outdated or not without searchin for internet while examing? remember, CompTIA is vender-neutral not a sponsored by Cisco. C. is also incorrect! if you disable redirect. how the hell the function to redirect http to https will work????? this is essential function for security F. WTF if you eliminate network management and control interfaces, how can you configure and manage the system????????????? C is correct because you should not show the management publicly especially in production. It should have a separate network for management. E. is correct. You should have better method for authentication rather than simple base64 encoding! (Authentication Basic)
upvoted 6 times
...
Slimeball
Most Recent 1 year, 5 months ago
Since this all about PenTesting I would go B and D B. Running an old SSH protocol, needs to be upgraded. Upgrading SSH would make the network harder to penetrate - old protocols are vulnerable. D. Out of Band Network for management. Moving the network out of band would make the network management less vulnerable and harder to penetrate. B and D would make the network harder to penetrate. A. is irrelevant. C. is a redirect misconfiguration but doesn't affect how penetrable the network is E. Not enough info to determine this imo F. Eliminating Network Management can't be the solution lol
upvoted 1 times
...
bieecop
1 year, 10 months ago
Selected Answer: BF
B. Disable or upgrade SSH daemon: The Nmap scan shows that the SSH service on port 22 is open and running a relatively old version of the Cisco SSH protocol (1.25). It is recommended to disable SSH if it is not required or upgrade to a more secure and up-to-date version. This helps mitigate potential security vulnerabilities associated with older versions of SSH. F. Eliminate network management and control interfaces: The finding that network management interfaces are available on the production network indicates a potential security risk. It is generally recommended to separate network management traffic onto a dedicated out-of-band network, separate from the production network. By creating an out-of-band network for management purposes, the risk of unauthorized access or interference with critical network devices can be reduced.
upvoted 1 times
...
Inamati
2 years, 10 months ago
Selected Answer: CD
It has to be C&D
upvoted 3 times
...
[Removed]
3 years, 2 months ago
I agree with C & D
upvoted 3 times
...
Davar39
3 years, 4 months ago
I'll go with C&D, having management interfaces on production networks is never a good idea.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago