Free CompTIA PenTest+ PT0-002 Practice Question

During a security assessment of a web application, you discover that a component of the software is affected by a documented security weakness that permits unauthorized code execution on the server. This flaw is noted as having a unique identifier in a globally recognized database for security weaknesses. What is your FIRST course of action to acquire detailed and trustworthy information about this specific issue?

  • Craft a proof-of-concept to exploit the weakness based solely on the general knowledge of the component's issue.

  • Deploy an automated scanning tool to run a general vulnerability check in hopes it will flag and provide details regarding the issue.

  • Browse community forums for discussions related to the vulnerability, hoping to find informal patches or mitigation strategies.

  • Use the specific security flaw identifier to query the National Vulnerability Database (NVD) for extensive details about the weakness.

This question's topic:
CompTIA PenTest+ PT0-002 / 
Information Gathering and Vulnerability Scanning
Your Score:

Check or uncheck an objective to set which questions you will receive.