exam questions

Exam PT0-001 All Questions

View all questions & answers for the PT0-001 exam

Exam PT0-001 topic 1 question 125 discussion

Actual exam question from CompTIA's PT0-001
Question #: 125
Topic #: 1
[All PT0-001 Questions]

A client is asking a penetration tester to evaluate a new web application for availability. Which of the following types of attacks should the tester use?

  • A. TCP SYN flood
  • B. SQL injection
  • C. XSS
  • D. XMAS scan
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️
Reference:
https://www.softwaretestinghelp.com/getting-started-with-web-application-penetration-testing/

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
GOKU1984
Highly Voted 5 years, 1 month ago
TCP SYN flood is a type of DOS attack. I think A
upvoted 17 times
who__cares123456789___
4 years, 2 months ago
WARNING!! They are asking about AVAILABILITY... This is a question designed to throw you off! ANSWER IS A
upvoted 8 times
...
...
mr_robot
Highly Voted 5 years, 1 month ago
PenTest+ Practice Tests Book - SYBEX - Chapter 7 A. A TCP SYN flood (also known as a SYN flood) is a form of denial of service (DoS) attack in which a tester sends a succession of SYN requests to the target’s system in an attempt to consume enough server resources to make the system unresponsive to genuine traffic. This exploits part of the normal TCP three-way handshake and consumes resources on the targeted server and renders it unresponsive.
upvoted 10 times
deathfrom
5 years ago
That is a DOS attack. I would agree that this is B, SQL injection. https://owasp.org/www-project-top-ten/
upvoted 3 times
deathfrom
4 years, 11 months ago
Key word here is availability... I agree it is A
upvoted 7 times
who__cares123456789___
4 years, 2 months ago
WARNING!! They are asking about AVAILABILITY... This is a question designed to throw you off! ANSWER IS A
upvoted 2 times
Mo911
4 years, 1 month ago
the question is: do pentesters use DoS attack on a system in real scenario. maybe hackers but not ethical hackers (pentesters).
upvoted 1 times
eroms
3 years, 10 months ago
Pentesters will perform whatever the client wants as long as there is permission to do that. if it is in the SOW, then DOS attack can be performed. are you a pentester, or you just cram to pass exams?
upvoted 2 times
...
...
...
...
Loosi
4 years, 11 months ago
question is to check the website for availability. for that DDOS attack would work better as it exhausts the system resources.
upvoted 1 times
...
...
...
kloug
Most Recent 2 years, 2 months ago
aaaaaaaaaaaaaaaa
upvoted 1 times
...
miabe
2 years, 9 months ago
Selected Answer: A
looks good to me
upvoted 1 times
...
Cock
3 years, 2 months ago
It was on the exam. And one similar new question
upvoted 2 times
...
likeahoss
3 years, 6 months ago
I'm going with B. It's asking you to test the WebApp for availability not the server it's being hosted on. SQL injection tests the web app and could also render the WebApp unavailable by deleting the underlying DB content.
upvoted 1 times
...
dp12
3 years, 10 months ago
Definitely A
upvoted 1 times
...
Joker20
3 years, 10 months ago
availability = Flood attack answer A
upvoted 1 times
...
mar7865p123
3 years, 11 months ago
it is A
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago