exam questions

Exam PT1-002 All Questions

View all questions & answers for the PT1-002 exam

Exam PT1-002 topic 1 question 79 discussion

Actual exam question from CompTIA's PT1-002
Question #: 79
Topic #: 1
[All PT1-002 Questions]

A penetration tester would like to obtain FTP credentials by deploying a workstation as an on-path attack between the target and the server that has the FTP protocol. Which of the following methods would be the BEST to accomplish this objective?

  • A. Wait for the next login and perform a downgrade attack on the server.
  • B. Capture traffic using Wireshark.
  • C. Perform a brute-force attack over the server.
  • D. Use an FTP exploit against the server.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️
Reference:
https://shahmeeramir.com/penetration-testing-of-an-ftp-server-19afe538be4b

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
bieecop
1 year, 9 months ago
Selected Answer: B
By deploying a workstation as an on-path attack between the target and the FTP server, the penetration tester can intercept and capture network traffic exchanged between the two endpoints. Wireshark is a widely used network packet analyzer that allows the capturing and analysis of network traffic in real-time. By capturing the traffic, the penetration tester can analyze it to extract FTP credentials, including usernames and passwords, being transmitted in clear text.
upvoted 1 times
...
lifehacker0777
2 years, 1 month ago
Selected Answer: B
Answer: B. Capture traffic using Wireshark. FTP is not a secure protocol so your user name and password is in clear text
upvoted 1 times
...
carlo479
3 years ago
B... On-path = Man-in-the middle attack= wireshark.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago