問題文
Before a run against a booking service the engineer is handed part of the network addressing map, part of the architecture documentation and one ordinary user account, but no source code at all. Which position does that briefing put the engineer in, and which technique suits the run?
選択肢
- This briefing puts the engineer in a white-box position, so the technique that suits the vulnerability hunt is compiler warning inspection against the deployed platform.
- This briefing puts the engineer in a closed-box position, so the technique that suits the vulnerability hunt is configuration file walkthrough against the deployed platform.
- This briefing puts the engineer in a black-box position, so the technique that suits the vulnerability hunt is data flow reading against the deployed platform.
- This briefing puts the engineer in a gray-box position, so the technique that suits the vulnerability hunt is unauthorized privilege exploration against the deployed platform.