exam questions

Exam PT0-002 All Questions

View all questions & answers for the PT0-002 exam

Exam PT0-002 topic 1 question 124 discussion

Actual exam question from CompTIA's PT0-002
Question #: 124
Topic #: 1
[All PT0-002 Questions]

A penetration tester wants to find hidden information in documents available on the web at a particular domain. Which of the following should the penetration tester use?

  • A. Netcraft
  • B. CentralOps
  • C. Responder
  • D. FOCA
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
RRabbit_111
Highly Voted 9 months, 3 weeks ago
D. FOCA FOCA (Fingerprinting Organizations with Collected Archives) is a tool that is used to find hidden information in documents available on the web. It can be used to extract metadata from documents such as PDF, Microsoft Office, OpenOffice, and others. The metadata can include information such as the author, creation date, and software used to create the document. FOCA can also extract information from the document's properties such as the title, keywords, and comments. This tool can also identify specific keywords and patterns in the document and can be useful in identifying sensitive information that may have been inadvertently left in the document. A. Netcraft is a tool that can be used to gather information about websites and domains, such as the IP address, hosting provider, and server software. B. CentralOps is a tool that can be used to gather information about IP addresses, such as geolocation and ownership. C. Responder is a tool that can be used to perform rogue DHCP and LLMNR/NBT-NS Poisoning attacks to extract information from network clients.
upvoted 8 times
...
NotAHackerJustYet
Most Recent 9 months, 1 week ago
Selected Answer: D
The correct answer is D. FOCA. FOCA (Fingerprinting Organizations with Collected Archives) is a tool used by penetration testers to uncover hidden information in documents available on the web. It can be used to analyze file metadata, such as authors, dates, and keywords, and generate reports that reveal potentially sensitive information. It can also identify files stored on external domains or hidden within the website, such as in the source code, which can be used to gain access to the system.
upvoted 3 times
NotAHackerJustYet
9 months, 1 week ago
A. Netcraft is a website security and domain name analysis tool, but it does not provide the same type of analysis that FOCA does. B. CentralOps is a network security tool that provides information about the domain name and its associated IP address, but it does not provide the same type of analysis that FOCA does. C. Responder is a tool used for network reconnaissance, but it does not provide the same type of analysis that FOCA does.
upvoted 2 times
...
...
Neolot
1 year, 1 month ago
Selected Answer: D
https://kalilinuxtutorials.com/foca-metadata-hidden-documents/
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago