フリー問題

Certified Tester Security Test Engineer (CT-STE) v1.0.1 のフリー問題 5 / 20 問目

問題文

Before a run against a booking service the engineer is handed part of the network addressing map, part of the architecture documentation and one ordinary user account, but no source code at all. Which position does that briefing put the engineer in, and which technique suits the run?

選択肢

  1. This briefing puts the engineer in a white-box position, so the technique that suits the vulnerability hunt is compiler warning inspection against the deployed platform.
  2. This briefing puts the engineer in a closed-box position, so the technique that suits the vulnerability hunt is configuration file walkthrough against the deployed platform.
  3. This briefing puts the engineer in a black-box position, so the technique that suits the vulnerability hunt is data flow reading against the deployed platform.
  4. This briefing puts the engineer in a gray-box position, so the technique that suits the vulnerability hunt is unauthorized privilege exploration against the deployed platform.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。