WGUl D484l Finall Examl Reviewl (Latestl 2025/l 2026l Update)l Penetrationl Testingl |l Questionsl &l Answers|l Gradel A|l 100%l Correctl (Verifiedl Solutions)
Q:l Al penetrationl testerl isl workingl onl al projectl andl seesl al fairlyl recentl VoIPl vulnerabilityl hasl comel out.l Whichl ofl thel followingl recordsl wouldl bestl helpl theml narrowl downl potentiall targets?A.l TXT B.l NS C.l SRV D.l MX
Answer:
C.l SRV
Servicel (SRV)l recordl providesl hostl andl portl informationl onl servicesl suchl asl voicel overl IPl (VoIP)l andl instantl messagingl (IM).l
Q:l NS
Answer:
Nameserverl (NS)l recordl listsl thel authoritativel DNSl serverl forl al particularl domain.l Al standardl DNSl queryl willl usel DNSl serversl tol identifyl thel Internetl Protocoll (IP)l addressl behindl al particularl domainl orl resourcel name.l
Q:l MX
Answer:
Maill Exchangel (MX)l recordl providesl thel maill serverl thatl acceptsl emaill messagesl forl al particularl domain.l
Q:l Al penetrationl testerl wantsl tol gatherl emaill informationl forl al targetedl phishingl campaign.l Whichl ofl thel followingl toolsl couldl theyl usel tol collectl this? 1 / 4
A.l Shodan B.l Dirbuster C.l Metagoofil D.l theHarvester
Answer:
D.l theHarvester
Q:l Shodan
Answer:
Shodanl isl al searchl enginel designedl tol locatel andl indexl IoTl devicesl thatl arel connectedl tol thel Internet.l
Q:l Dirbuster
Answer:
Dirbusterl isl specificallyl gearedl towardsl websitel enumeration.l DirBusterl isl al webl applicationl brute-forcel finderl forl directoriesl andl files.l Itl comesl withl ninel differentl lists,l includingl defaultl directoriesl andl commonl namesl givenl byl developers.l
Q:l Metagoofil
Answer:
Metagoofill usesl variousl pythonl librariesl suchl asl PdfMiner,l GoogleSearch,l andl Hachoirl tol scrapel thel metadata,l andl thenl displaysl thel informationl usingl Hypertextl Markupl Languagel (HTML).l
Q:l Al securityl professionall isl checkingl forl domainsl basedl onl certificatesl thatl arel nol longerl allowed.l Whatl couldl theyl checkl forl this?A.l ncpa.l cpl B.l SAN C.l SET D.l CRL
Answer:
D.l CRL 2 / 4
Thel Certificationl Revocationl Listl (CRL)l isl al listl ofl certificatesl thatl inl somel wayl havel beenl deemedl invalid.l Althoughl effective,l mostl onlinel servicesl havel movedl tol thel newerl OCSPl tol checkl thel validityl ofl thel certificate.l
Q:l SET
Answer:
Thel Sociall Engineeringl Toolkitl (SET)l isl al Python-basedl collectionl ofl toolsl thatl canl bel usedl whenl conductingl al sociall engineeringl PenTest.l
Q:l Al cyberl attackerl hasl managedl tol manipulatel DNSl entries,l leadingl victimsl tol al maliciousl websitel thatl looksl likel al legitimatel one,l evenl whenl theyl typel thel correctl URLl inl theirl browsers.l Whatl typel ofl attackl isl this?A.l Phishing B.l Pharming C.l Baiting D.l Malvertising
Answer:
B.l Pharming
Q:l Al penetrationl testerl covertlyl followsl anl authorizedl employeel whol isl unawarel thatl anyonel isl behindl them.l Whatl isl thisl called?A.l Tailgating B.l Piggybacking C.l Badgel cloning D.l Scaling
Answer:
A.l Tailgating
Tailgatingl isl anl attackl wherel thel maliciousl actorl slipsl inl throughl al securel areal whilel covertlyl followingl anl authorizedl employeel whol isl unawarel thatl anyonel isl behindl them.l
Q:l Al penetrationl testerl isl tryingl tol usel Googlel Hackingl tol findl morel instancesl ofl Ciscol CallManager.l Whatl shouldl theyl use? 3 / 4
A.l intitle:"DPH"l "webl loginl setting"
B.l inurl:"ccmuser/logon.l asp"
C.l intitle:"Grandstreaml Devicel Configuration"l password
D.l inurl:"CallManager"
Answer:
B.l inurl:"ccmuser/logon.l asp"
inurl:"ccmuser/logon.l asp"l wouldl bel usedl tol findl Ciscol CallManagerl instances.l Theyl canl alsol tryl somel otherl Googlel Hackingl tol findl morel informationl onl VoIPl phonesl thatl youl canl usel tol launchl thel attack.l
Q:l Al securityl consultantl isl attemptingl tol lookl forl defaultl passwordsl forl al client'sl D- Linkl phones.l Whichl ofl thel followingl shouldl theyl use?
A.l intitle:"DPH"l "webl loginl setting"
B.l inurl:"ccmuser/logon.l asp"
C.l intitle:"Grandstreaml Devicel Configuration"l password
D.l inurl:"CallManager"
Answer:
A.l intitle:"DPH"l "webl loginl setting"
Q:l Thel Sociall Engineeringl Toolkitl isl beingl employedl forl al targetedl attackl towardsl personnel.l Whichl ofl thel followingl canl SETl NOTl do?A.l Massl maill attacks B.l Infectiousl media C.l Scaling D.l PowerShelll attacks
Answer:
C.l Scaling
Q:l Al securityl professionall wantsl tol usel SETl forl al targetedl attackl towardsl personnel.l Whichl ofl thel followingl canl SETl NOTl do?A.l Spearl phishing B.l Badgel cloning C.l Websitel attacks D.l Wirelessl attacks
- / 4