exam questions

Exam PT0-002 All Questions

View all questions & answers for the PT0-002 exam

Exam PT0-002 topic 1 question 17 discussion

Actual exam question from CompTIA's PT0-002
Question #: 17
Topic #: 1
[All PT0-002 Questions]

A penetration tester was conducting a penetration test and discovered the network traffic was no longer reaching the client's IP address. The tester later discovered the SOC had used sinkholing on the penetration tester's IP address.
Which of the following MOST likely describes what happened?

  • A. The penetration tester was testing the wrong assets.
  • B. The planning process failed to ensure all teams were notified.
  • C. The client was not ready for the assessment to start.
  • D. The penetration tester had incorrect contact information.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
RRabbit_111
Highly Voted 2 years, 3 months ago
Selected Answer: B
Answer: B. The planning process failed to ensure all teams were notified. Example: The penetration tester was unaware that the SOC had set up sinkholing on his IP address and was blocked from accessing the client's IP address because the SOC team was not notified of the penetration test.
upvoted 10 times
...
solutionz
Most Recent 7 months, 3 weeks ago
Selected Answer: B
Sinkholing is a practice where traffic is redirected away from its original destination, often to a benign location, in response to suspicious or malicious activity. In the context of a penetration test, if the Security Operations Center (SOC) has sinkholed the penetration tester's IP address, it could indicate that the SOC was not properly informed of the authorized testing. Therefore, the most likely explanation for this occurrence is that there was a failure in the planning process to ensure that all relevant teams were properly notified of the upcoming penetration test. The correct answer to this question would be: B. The planning process failed to ensure all teams were notified.
upvoted 3 times
...
pizzaThyme
9 months, 1 week ago
Selected Answer: B
B. Either the teams was not made aware by accident and corrective action was taken by the SOC, OR the team was intentionally left in the dark in the case of red vs. blue / purple teaming exercises. I guess based on the fact that the pentester is surprised, it would only make sense that the SOC was not made aware. :)
upvoted 1 times
...
IYKMba
1 year, 9 months ago
I choose D
upvoted 1 times
...
nickwen007
2 years, 2 months ago
Sinkholing is a security technique used to redirect malicious traffic away from its intended target. It involves creating a “black hole” of sorts by setting up a network of servers that will intercept and discard any packets sent to an IP address associated with malicious activity. This helps to prevent the malicious traffic from reaching its destination, thus reducing the impact of the attack.
upvoted 3 times
...
TCSNxS
2 years, 3 months ago
Answer is B. In a real world scenario, clients loved to test the ability of their SOCs to detect their PenTesters. Easiest way to was not inform them.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago