<< Prev Question Next Question >>

Question 42/257

During an engagement an unsecure direct object reference vulnerability was discovered that allows the extraction of highly sensitive PII. The tester is required to extract and then exfil the information from a web application with identifiers 1 through 1000 inclusive. When running the following script, an error is encountered:

Which of the following lines of code is causing the problem?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (257q)
Question 1: A penetration tester is performing a remote internal penetra...
Question 2: A penetration tester has been asked to conduct OS fingerprin...
Question 3: A security consultant is trying to attack a device with a pr...
Question 4: Which of the following types of intrusion techniques is the ...
Question 5: A penetration tester is reviewing the following output from ...
Question 6: A penetration tester is performing a code review against a w...
Question 7: A security guard observes an individual entering the buildin...
Question 8: A technician is reviewing the following report. Given this i...
Question 9: During the information gathering phase of a network penetrat...
Question 10: During a penetration test a tester Identifies traditional an...
Question 11: A penetration tester ran the following Nmap scan on a comput...
Question 12: When negotiating a penetration testing contract with a prosp...
Question 13: Which of the following has a direct and significant impact o...
Question 14: Joe, a penetration tester, has received basic account creden...
Question 15: A penetration tester wants to target NETBIOS name service. W...
1 commentQuestion 16: A penetration tester has been asked to conduct OS fingering ...
Question 17: Click the exhibit button. (Exhibit) A penetration tester is ...
Question 18: A penetration tester has been asked to conduct OS fingerprin...
Question 19: Instructions: Analyze the code segments to determine which s...
Question 20: An email sent from the Chief Executive Officer (CEO) to the ...
Question 21: A penetration tester ran the following Nmap scan on a comput...
Question 22: Which of the following commands starts the Metasploit databa...
Question 23: After a recent penetration test, a company has a finding reg...
Question 24: A penetration tester has gained access to a marketing employ...
Question 25: Which of the following situations would cause a penetration ...
Question 26: Which of the following would be the BEST for performing pass...
Question 27: A penetration tester has discovered through automated scanni...
Question 28: A manager calls upon a tester to assist with diagnosing an i...
Question 29: During testing, a critical vulnerability is discovered on a ...
Question 30: An internal network penetration test is conducted against a ...
Question 31: A penetration tester has been asked to conduct OS fingering ...
Question 32: Which of the following commands will allow a tester to enume...
Question 33: A client's systems administrator requests a copy of the repo...
Question 34: A penetration tester is scanning a network for SSH and has a...
Question 35: A penetration tester is performing a code review against a w...
Question 36: A security consultant found a SCADA device in one of the VLA...
Question 37: A penetration tester discovers Heartbleed vulnerabilities in...
Question 38: A penetration tester is utilizing social media to gather inf...
Question 39: During an internal network penetration test the tester is ab...
Question 40: A penetration tester has compromised a host. Which of the fo...
Question 41: A penetration tester is reviewing the following output from ...
Question 42: During an engagement an unsecure direct object reference vul...
Question 43: A security team is switching firewall vendors. The director ...
Question 44: A penetration tester has been asked to conduct a penetration...
Question 45: Which of the following commands starts the Metasploit databa...
Question 46: When considering threat actor scoping prior to an engagement...
Question 47: A penetration tester is checking a script to determine why s...
Question 48: A security analyst was provided with a detailed penetration ...
Question 49: A tester intends to run the following command on a target sy...
Question 50: A penetration tester is checking a script to determine why s...
Question 51: The results of a basic compliance scan show a subset of asse...
Question 52: After successfully capturing administrator credentials to a ...
Question 53: A penetration tester needs to provide the code used to explo...
Question 54: During a penetration test, you gain access to a system with ...
Question 55: When performing compliance-based assessments, which of the f...
Question 56: A penetration tester successfully exploits a system, receivi...
Question 57: Click the exhibit button. (Exhibit) Given the Nikto vulnerab...
Question 58: A penetration tester is in the process of writing a report t...
Question 59: A penetration tester reports an application is only utilizin...
Question 60: A penetration tester has been asked to conduct OS fingerprin...
Question 61: A penetration tester is required to perform OSINT on staff a...
Question 62: A client requests that a penetration tester emulate a help d...
Question 63: Which of the following CPU register does the penetration tes...
Question 64: A security consultant is trying to attack a device with a pr...
Question 65: A malicious user wants to perform an MITM attack on a comput...
Question 66: A malicious user wants to perform an MITM attach on a comput...
Question 67: Consider the following PowerShell command: Powershell.exe IE...
Question 68: A penetration tester is planning to conduct a distributed di...
Question 69: During an internal network penetration test, a tester recove...
Question 70: Given the following HTTP response: http/1.0 200 OK Server: A...
Question 71: Given the following script: (Exhibit) Which of the following...
Question 72: A penetration tester notices that the X-Frame-Optjons header...
Question 73: A penetration tester has a full shell to a domain controller...
Question 74: Which of the following is an example of a spear phishing att...
Question 75: A recently concluded penetration test revealed that a legacy...
Question 76: A penetration tester directly connects to an internal networ...
Question 77: During a web application assessment, a penetration tester di...
Question 78: Which of the following is the BEST initial attack against an...
Question 79: An attacker uses SET to make a copy of a company's cloud-hos...
Question 80: Which of the following CPU registers does the penetration te...
Question 81: D18912E1457D5D1DDCBD40AB3BF70D5D Which of the following is t...
Question 82: Place each of the following passwords in order of complexity...
Question 83: A penetration tester is reviewing the following output from ...
Question 84: A penetration tester is connected to a client's local networ...
Question 85: During a penetration test, a tester runs a phishing campaign...
Question 86: Consider the following PowerShell command: powershell.exe IE...
Question 87: A penetration tester has a full shell to a domain controller...
Question 88: An organization has requested that a penetration test be per...
Question 89: A penetration tester compromises a system that has unrestric...
Question 90: A vulnerability scan identifies that an SSL certificate does...
Question 91: After successfully enumerating users on an Active Directory ...
Question 92: Joe, a penetration tester, is asked to assess a company's ph...
Question 93: A recently concluded penetration test revealed that a legacy...
Question 94: At the beginning of a penetration test, the tester finds a f...
Question 95: After successfully exploiting a local file inclusion vulnera...
Question 96: A security consultant is trying to attack a device with a pr...
Question 97: A penetration tester was able to enter an SQL injection comm...
Question 98: A penetration tester runs the following from a compromised b...
Question 99: Given the following Python script: (Exhibit) Which of the fo...
Question 100: Which of the following types of intrusion techniques is the ...
Question 101: If a security consultant comes across a password hash that r...
Question 102: Which of the following commands would allow a penetration te...
Question 103: A penetration tester was able to retrieve the initial VPN us...
Question 104: A penetration tester is connected to a client's local networ...
Question 105: An email sent from the Chief Executive Officer (CEO) to the ...
Question 106: A software developer wants to test the code of an applicatio...
Question 107: A penetration tester wants to check manually if a "ghost" vu...
Question 108: While trying to maintain persistence on a Windows system wit...
Question 109: An attacker uses SET to make a copy of a company's cloud-hos...
Question 110: A penetration tester has compromised a Windows server and is...
Question 111: A consultant is attempting to harvest credentials from unsec...
Question 112: A penetration tester identifies the following findings durin...
Question 113: During an engagement, a consultant identifies a number of ar...
Question 114: Which of the following tools can be used to perform a basic ...
Question 115: Which of Ihe following commands would allow a penetration te...
Question 116: : 88 A penetration tester was able to enter an SQL injection...
Question 117: A penetration tester is performing a wireless penetration te...
Question 118: A company planned for and secured the budget to hire a consu...
Question 119: An individual has been hired by an organization after passin...
Question 120: A penetration tester has compromised a system and wishes to ...
Question 121: An attacker receives a DHCP address and notices the hostname...
Question 122: While engaging clients for a penetration test from highly re...
Question 123: During a vulnerability assessment, the security consultant f...
Question 124: A technician is reviewing the following report. Given this i...
Question 125: A financial institution is asking a penetration tester to de...
Question 126: A penetration tester is checking a script to determine why s...
Question 127: An energy company contracted a security firm to perform a pe...
Question 128: A penetration tester has identified a directory traversal vu...
Question 129: Given the following: http://example.com/download.php?id-.../...
Question 130: A tester identifies an XSS attack vector during a penetratio...
Question 131: An organization has requested that a penetration test be per...
Question 132: A client has scheduled a wireless penetration test. Which of...
Question 133: A manager calls upon a tester to assist with diagnosing an i...
Question 134: A security guard observes an individual entering the buildin...
Question 135: Which of the following tools would a penetration tester leve...
Question 136: A tester has captured a NetNTLMv2 hash using Responder Which...
Question 137: DRAG DROP Performance based You are a penetration Inter revi...
Question 138: DRAG DROP A manager calls upon a tester to assist with diagn...
Question 139: Black box penetration testing strategy provides the tester w...
Question 140: During a penetration test, a host is discovered that appears...
Question 141: Given the following script: (Exhibit) Which of the following...
Question 142: Click the exhibit button. (Exhibit) A penetration tester is ...
Question 143: A penetration tester executes the following commands: C:\&gt...
Question 144: If a security consultant comes across a password hash that r...
Question 145: A penetration testet is attempting to capture a handshake be...
Question 146: During a physical security review, a detailed penetration te...
Question 147: A company contracted a firm specializing in penetration test...
Question 148: At the information gathering stage, a penetration tester is ...
Question 149: A penetration tester identifies the following findings durin...
Question 150: While trying to maintain persistence on a Windows system wit...
Question 151: A company received a report with the following finding While...
Question 152: The following command is run on a Linux file system: Chmod 4...
Question 153: A client requests that a penetration tester emulate a help d...
Question 154: Which of the following BEST describes why an MSA is helpful?...
Question 155: During a penetration test, you gain access to a system with ...
Question 156: A penetration tester has been asked to conduct OS fingering ...
Question 157: Click the exhibit button. (Exhibit) Given the Nikto vulnerab...
Question 158: Which of the following describe a susceptibility present in ...
Question 159: The scope of a penetration test requires the tester to be st...
Question 160: A client needs to be PCI compliant and has external-facing w...
Question 161: A security consultant is trying to attack a device with a pr...
Question 162: During an engagement, a consultant identifies a number of ar...
Question 163: A client requests that a penetration tester emulate a help d...
Question 164: A penetration tester is performing a black-box test of a cli...
Question 165: A penetration tester has compromised a host. Which of the fo...
Question 166: A client has voiced concern about the number of companies be...
Question 167: A penetration tester reviews the scan results of a web appli...
Question 168: A malicious user wants to perform an MITM attach on a comput...
Question 169: Given the following Python script: (Exhibit) Which of the fo...
Question 170: The results of a basic compliance scan show a subset of asse...
Question 171: A penetration tester is performing a black box assessment on...
Question 172: A company hires a penetration tester to determine if there a...
Question 173: Performance based You are a penetration Inter reviewing a cl...
Question 174: A company's corporate policies state that employees are able...
Question 175: A vulnerability scan identifies that an SSL certificate does...
Question 176: Which of the following are MOST important when planning for ...
Question 177: A security consultant is trying to attack a device with a pr...
Question 178: When communicating the findings of a network vulnerability s...
Question 179: Which of the following tools is used to perform a credential...
Question 180: A penetration tester has gained a root shell on a target Lin...
Question 181: Performance based You are a penetration Inter reviewing a cl...
Question 182: A penetration tester reviews the scan results of a web appli...
Question 183: A tester has determined that null sessions are enabled on a ...
Question 184: A penetration tester wants to launch a graphic console windo...
Question 185: During a penetration test, a tester runs a phishing campaign...
Question 186: During an internal network penetration test, a tester recove...
Question 187: A malicious user wants to perform an MITM attack on a comput...
Question 188: Joe, a penetration tester, is asked to assess a company's ph...
Question 189: A manager calls upon a tester to assist with diagnosing an i...
Question 190: A penetration tester notices that the X-Frame-Optjons header...
Question 191: When performing compliance-based assessments, which of the f...
Question 192: In a physical penetration tester testing scenario. the penet...
Question 193: Instructions: Given the following attack signatures, determi...
Question 194: A system security engineer is preparing to conduct a securit...
Question 195: A security assessor completed a comprehensive penetration te...
Question 196: Which of the following is the reason why a penetration teste...
Question 197: A recent vulnerability scan of all web servers in an environ...
Question 198: A penetration tester is preparing to conduct API testing. Wh...
Question 199: A penetration tester is attempting to open a socket in a bas...
Question 200: During a physical security review, a detailed penetration te...
Question 201: A penetration tester runs the following from a compromised b...
Question 202: Instructions: Analyze the code segments to determine which s...
Question 203: Which of the following reasons does penetration tester needs...
Question 204: A penetration tester is reviewing a Zigbee Implementation fo...
Question 205: A penetration tester has compromised a host. Which of the fo...
Question 206: A client needs to be PCI compliant and has external-facing w...
Question 207: A penetration tester is reviewing a Zigbee implementation fo...
Question 208: Which of the following BEST describes some significant secur...
Question 209: A company hires a penetration tester to determine if there a...
Question 210: During testing, a critical vulnerability is discovered on a ...
Question 211: A penetration testing company was hired to conduct a penetra...
Question 212: A tester has captured a NetNTLMv2 hash using Responder Which...
Question 213: A penetration tester reviews the scan results of a web appli...
Question 214: A penetration tester locates a few unquoted service paths du...
Question 215: A client is asking a penetration tester to evaluate a new we...
Question 216: In a physical penetration testing scenario, the penetration ...
Question 217: A company decides to remediate issues identified from a thir...
Question 218: A penetration tester executes the following commands: C:\&gt...
Question 219: Which of the following is an important stakeholder to notify...
Question 220: A penetration tester generates a report for a host-based vul...
Question 221: When conducting reconnaissance against a target, which of th...
Question 222: Click the exhibit button. (Exhibit) Given the Nikto vulnerab...
Question 223: A penetration tester was able to retrieve the initial VPN us...
Question 224: A penetration tester is able to move laterally throughout a ...
Question 225: A penetration tester is able to move laterally throughout a ...
Question 226: Which of the following is an example of a spear phishing att...
Question 227: A malicious user wants to perform an MITM attack on a comput...
Question 228: A company planned for and secured the budget to hire a consu...
Question 229: A recently concluded penetration test revealed that a legacy...
Question 230: A penetration tester has obtained access to an IP network su...
Question 231: A penetration tester is preparing to conduct API testing Whi...
Question 232: A penetration tester successfully exploits a Windows host an...
Question 233: Place each of the following passwords in order of complexity...
Question 234: A penetration tester is required to perform OSINT on staff a...
Question 235: A penetration tester successfully exploits a Windows host an...
Question 236: While monitoring WAF logs, a security analyst discovers a su...
Question 237: Which of the following types of physical security attacks do...
Question 238: Black box penetration testing strategy provides the tester w...
Question 239: A penetration tester identifies the following findings durin...
Question 240: Which of the following tools would a penetration tester leve...
Question 241: A malicious user wants to perform an MITM attack on a comput...
Question 242: A penetration tester observes that several high-numbered por...
Question 243: Which of the following tools is used to perform a credential...
Question 244: Which of the following wordlists is BEST for cracking MD5 pa...
Question 245: A penetration tester observes that the content security poli...
Question 246: A penetration tester is reviewing a Zigbee Implementation fo...
Question 247: A penetration tester is attempting to capture a handshake be...
Question 248: A penetration tester has successfully deployed an evil twin ...
Question 249: Instructions: Analyze the code segments to determine which s...
Question 250: Click the exhibit button. (Exhibit) A penetration tester is ...
Question 251: A penetration tester is performing a wireless penetration te...
Question 252: You are a security analyst tasked with hardening a web serve...
Question 253: During a web application assessment, a penetration tester di...
Question 254: A security analyst has uncovered a suspicious request in the...
Question 255: During a penetration test, a tester runs a phishing campaign...
Question 256: Which of the following would be BEST for performing passive ...
Question 257: A client gives a penetration tester a /8 network range to sc...