exam questions

Exam PT0-001 All Questions

View all questions & answers for the PT0-001 exam

Exam PT0-001 topic 1 question 152 discussion

Actual exam question from CompTIA's PT0-001
Question #: 152
Topic #: 1
[All PT0-001 Questions]

A vulnerability scan report shows what appears to be evidence of a memory disclosure vulnerability on one of the target hosts. The administrator claims the system is patched and the evidence is a false positive. Which of the following is the BEST method for a tester to confirm the vulnerability exists?

  • A. Manually run publicly available exploit code.
  • B. Confirm via evidence of the updated version number.
  • C. Run the vulnerability scanner again.
  • D. Perform dynamic analysis on the vulnerable service.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kloug
2 years, 2 months ago
ddddddddddddddddd
upvoted 1 times
...
miabe
2 years, 9 months ago
Selected Answer: B
looks good to me
upvoted 1 times
...
onikafei
2 years, 11 months ago
Going with D
upvoted 1 times
onikafei
2 years, 11 months ago
b actually
upvoted 1 times
...
...
MrRiver
3 years, 7 months ago
I'M pretty sure it's B. c. is like: Insanity is doing the same thing over and over and expecting different results. sooo, just no. D.) i guess if you have too much time you can perform a Dynamic anlysis and verify that ... but a little to complex for my taste ... definitly not the BEST way. A.) Yeah Just run run some Exploits against the client Sytems. We are Enumerating ... we don't know if we are even allowed to attack the system. Also We don't know if ther a Public exploits ... and even exploits are unreliabel ... so thats not a good proof ... far from the Best. So B: Just do a quick google search an check if the Vulnerability is fix in the reported Version. Sounds just like a simple and quick solution. In my opinion the one i would do as First step, seems to be the BEST.
upvoted 1 times
...
carletten
3 years, 8 months ago
In my opinion it's B. Scanners like Nessus provide the evidence or proof of a vulnerability.
upvoted 1 times
...
CybeSecN
3 years, 8 months ago
I would go for D. https://software.intel.com/content/www/us/en/develop/documentation/inspector-user-guide-windows/top/getting-started/dynamic-analysis-vs-static-analysis.html
upvoted 1 times
...
versun
3 years, 9 months ago
Answer is D Because Memory leak detection is a form of dynamic analysis that eliminates programmer leak vulnerabilities. https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=&cad=rja&uact=8&ved=2ahUKEwiemLff4s3xAhVDjeYKHWwDCssQFnoECAkQAA&url=https%3A%2F%2Fwww.embedded.com%2Fstatic-vs-dynamic-analysis-for-secure-code-development-part-2%2F&usg=AOvVaw2on391jti52Qru0lJUGJez
upvoted 1 times
MrRiver
3 years, 7 months ago
Memory memory disclosure is NOT a Memory leak.
upvoted 2 times
...
...
boooliyooo
3 years, 10 months ago
B, since the admin claims to have patched, to show the version to proof it.
upvoted 4 times
...
varo82
3 years, 10 months ago
Why answer is C and no D?
upvoted 1 times
...
sknath
3 years, 10 months ago
Can anyone please explain why the answer is C? It seems to me if we do the vulnerability scan again, the result will be the same unless we do not change any scanner configuration. As per the another reading material, to deal with the false positive, it says "Comparing these results with other information gathered may lead to the conclusion that the scan results are incorrect." In that sense, the answer could be B. Any thought from others?
upvoted 1 times
x0hmei
3 years, 10 months ago
I'd be more incline to go with D not sure I understand why you would pick B it's memory vuln are you thinking the updated version of the vuln scanner? I hate comptia never 100% clear
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago