A company contracts a security engineer to perform a penetration test of its client-facing web portal. Which of the following activities would be MOST appropriate?
A) Use a protocol analyzer against the site to see if data input can be replayed from the browser
B) Scan the website through an interception proxy and identify areas for the code injection
C) Scan the site with a port scanner to identify vulnerable services running on the web server
D) Use network enumeration tools to identify if the server is running behind a load balancer
Correct Answer:
Verified
Q48: A company wants to extend its help
Q49: A recent CRM upgrade at a branch
Q50: A threat advisory alert was just emailed
Q51: An architect was recently hired by a
Q52: A software development manager is running a
Q54: A new cluster of virtual servers has
Q55: While attending a meeting with the human
Q56: An organization enables BYOD but wants to
Q57: A security analyst sees some suspicious entries
Q58: A network engineer is attempting to design-in
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents