Home β€Ί Blog β€Ί CompTIA

Comptia Pentest+ 2023 Questions and answer - Part 7

Mary Mary Smith
03 Mar 2023
2 min read
0 views
0 Comments
2 min read
302 words

1. Which of the following is not included in Active Online Attack?

A) Dictionary Attack
B) Brute Force Attack
C) Man-in-the-Middle Attack
D) Hash Injection



2. A password hacking tool for a USB drive is called ________________.

A) Pass View
B) Bypass View
C) Far View
D) None of the above



3. Which of the following is not a credential testing tool?

A) Oph Crack
B) Rainbow Crack
C) Smbclient
D) LOpht Crack



4. Which one of the following is not a type of proxy server?

A) Forward Proxy Server
B) Reverse Proxy Server
C) Closed Proxy Server
D) Open Proxy Server



5. In which type of injection attack, a malicious code that injects into existing queries is drafted to reveal or manipulate data stored in the tables within the database?

A) Command Injection
B) SQL Injection
C) XML eXternal Entity (XXE) Injection
D) Simple Shell Injection



1. Right Answer: C
Explanation: A man-in-the-middle attack is a passive online attack.

2. Right Answer: A
Explanation: In an active online attack, attackers plug in a USB drive containing a password hacking tool such as 'Pass view' in it.

3. Right Answer: C
Explanation: Smbclient is a tool for enumeration.

4. Right Answer: C
Explanation: There are three main types of proxy servers: 1. Forward Proxy Server 2. Reverse Proxy Server 3. Open Proxy Server

5. Right Answer: C
Explanation: SQL injection relies on the strategic injection of malicious code or script in existing queries. This malicious code is drafted to reveal or manipulate data that is stored in the tables within the database.

Mary
Written by
Comments
0