Valid PT0-003 Dumps shared by ExamDiscuss.com for Helping Passing PT0-003 Exam! ExamDiscuss.com now offer the newest PT0-003 exam dumps, the ExamDiscuss.com PT0-003 exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com PT0-003 dumps with Test Engine here:
A penetration tester finds it is possible to downgrade a web application's HTTPS connections to HTTP while performing on-path attacks on the local network. The tester reviews the output of the server response to: curl -s -i https://internalapp/ HTTP/2 302 date: Thu, 11 Jan 2024 15:56:24 GMT content-type: text/html; charset=iso-8659-1 location: /login x-content-type-options: nosniff server: Prod Which of the following recommendations should the penetration tester include in the report?
Correct Answer: A
The tester identified an HTTPS downgrade attack (e.g., SSL stripping). The best mitigation is to enforce HSTS (HTTP Strict Transport Security). HSTS (Option A): HSTS (Strict-Transport-Security) ensures that the browser always uses HTTPS, preventing downgrade attacks. Example header: Strict-Transport-Security: max-age=31536000; includeSubDomains Reference: CompTIA PenTest+ PT0-003 Official Study Guide - "Web Security Headers and HTTPS Enforcements" Incorrect options: Option B (httponly flag): Protects cookies from JavaScript access but does not enforce HTTPS. Option C (Firewall rule on port 80): Helps, but does not force browsers to use HTTPS. Option D (Removing x-content-type-options): Unrelated; nosniff prevents MIME-type sniffing.