exam questions

Exam PT0-002 All Questions

View all questions & answers for the PT0-002 exam

Exam PT0-002 topic 1 question 130 discussion

Actual exam question from CompTIA's PT0-002
Question #: 130
Topic #: 1
[All PT0-002 Questions]

A software company has hired a penetration tester to perform a penetration test on a database server. The tester has been given a variety of tools used by the company's privacy policy. Which of the following would be the BEST to use to find vulnerabilities on this server?

  • A. OpenVAS
  • B. Nikto
  • C. SQLmap
  • D. Nessus
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Sodatex
14 hours, 51 minutes ago
Selected Answer: C
SQLMap is seen as a scanning tool in Comptia Pentest+. SO as long as this is a database server, sqlmap would be our best choice
upvoted 1 times
...
IamBlackFire
1 month, 4 weeks ago
Selected Answer: D
Who said that Database is SQL? The question asks about vulnerabilities and SQLmap is a injection oriented tool pretty. At the end Nessus is powerful and can also find the same flaws needed by the SQLmap.
upvoted 2 times
...
Bimbo_12
2 months ago
Selected Answer: C
It is a database server, simple as that. The answer should be SQLMap.
upvoted 2 times
...
fuzzyguzzy
3 months, 2 weeks ago
Selected Answer: C
Nessus and SQLMap are correct answers, but SQLmap is the best answer as it's dedicated to find vulns in SQL databases.
upvoted 2 times
...
djash22
5 months ago
Given that the target is a database server, and the aim is to find vulnerabilities that could potentially be exploited in a database, Option C: SQLmap would be the best choice. SQLmap is dedicated to testing databases for SQL injection vulnerabilities, which are among the most critical and common vulnerabilities in database servers. This tool would provide the most direct and relevant insights into the security of the database.
upvoted 2 times
...
Hedwig74
8 months, 1 week ago
OpenVAS has more capabilities than Nessus, though it is more complicated, as well. With that said, if you're selecting D, then your argument should be between those two. Therefore, the ONE specific answer given related to the question is SQLmap....
upvoted 3 times
...
KeToopStudy
11 months, 1 week ago
Selected Answer: C
SQLMap seems to be the answer because it specifies againts a database. Although Nessus can be used to detect vulnerabilities for database SQLMap is dedicated for that specific task.
upvoted 2 times
...
danscbe
11 months, 3 weeks ago
Selected Answer: D
I'm going with Nessus here. Nessus is a widely used vulnerability scanner that can help identify vulnerabilities in a system. While tools like OpenVAS, Nikto, and SQLmap also have their specific uses, Nessus is known for its comprehensive vulnerability scanning capabilities, making it a strong choice for a penetration tester examining a database server.
upvoted 2 times
...
b0ad9e1
11 months, 3 weeks ago
Selected Answer: C
This is a tricky question. If we are just going off the fact the target is a database server, then SQLmap is most certainly the answer. However, this sentence gives me pause, "The tester has been given a variety of tools used by the company's privacy policy. " What is CompTIA trying to convey with this sentence? Should we use Nessus instead of SQLmap? Why are they mentioning the privacy policy and other tools?
upvoted 1 times
...
solutionz
1 year, 4 months ago
Selected Answer: C
Given that the target is a database server, the BEST tool to use for finding vulnerabilities specifically related to databases, such as SQL injection, would be: C. SQLmap
upvoted 1 times
...
kips
1 year, 4 months ago
Selected Answer: D
Find vulnerabilities
upvoted 3 times
...
bieecop
1 year, 5 months ago
Selected Answer: D
Nessus provides a variety of scanning capabilities, including the ability to perform remote vulnerability checks, configuration audits, and compliance checks. It can detect known vulnerabilities, misconfigurations, and weaknesses in the database server's security posture. While options (Nikto), (OpenVAS), and (SQLmap) are valuable tools for specific tasks, they are not as well-suited as Nessus for comprehensive vulnerability assessment of a database server.
upvoted 3 times
...
ciguy935yaknow
1 year, 8 months ago
C https://www.google.com/search?q=can+sqlmap+test+for+vulnerabilities+on+database&sxsrf=APwXEdcLRM8VTF8rCeLaWd0tKYK2lRCiog%3A1680789493527&ei=9c8uZJbmH-jFkPIP7JOg2A0&oq=can+sqlmap+test+for+&gs_lcp=Cgxnd3Mtd2l6LXNlcnAQAxgBMgUIIRCgATIFCCEQoAEyBQghEKsCMggIIRAWEB4QHToKCAAQRxDWBBCwAzoECCMQJzoICAAQigUQkQI6EQguEIAEELEDEIMBEMcBENEDOgsIABCABBCxAxCDAToICAAQgAQQsQM6EQguEIMBEMcBELEDENEDEIAEOg4ILhCABBCxAxDHARDRAzoLCC4QigUQsQMQgwE6CAguEIAEELEDOgsILhCABBCxAxCDAToFCAAQgAQ6FAguEIAEELEDEIMBEMcBENEDENQCOgoIABCABBAUEIcCOgYIABAWEB46CAgAEIoFEIYDSgQIQRgAUKUOWLU0YIpDaANwAXgAgAGjAYgB1RSSAQQwLjIwmAEAoAEByAEIwAEB&sclient=gws-wiz-serp
upvoted 1 times
...
Maniact165
1 year, 8 months ago
Selected Answer: D
Its D no?
upvoted 2 times
...
cy_analyst
1 year, 9 months ago
Selected Answer: C
SQLmap is a specialized tool designed to identify and exploit vulnerabilities in database servers, including SQL injection flaws, which are a common vulnerability in database systems. It can be used to detect database management systems, enumerate databases, tables, and columns, dump data from databases, and perform a range of other penetration testing tasks.
upvoted 4 times
[Removed]
1 year, 9 months ago
Yes C is correct
upvoted 2 times
...
...
kloug
1 year, 9 months ago
cc correct
upvoted 4 times
...
kloug
1 year, 9 months ago
ddddddd
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago