Câu 105: PT0-003: CompTIA PenTest+
A penetration tester is performing an assessment focused on attacking the authentication identity provider hosted within a cloud provider. During the reconnaissance phase, the tester finds that the system is using OpenID connect with OAuth and has dynamic registration enabled. Which of the following attacks should the…
Nội dung câu hỏi
A penetration tester is performing an assessment focused on attacking the authentication identity provider hosted within a cloud provider. During the reconnaissance phase, the tester finds that the system is using OpenID connect with OAuth and has dynamic registration enabled. Which of the following attacks should the tester try first?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. A password-spraying attack against the authentication system
- B. A brute-force attack against the authentication system
- C. A replay attack against the authentication flow in the system — đáp án hiện tại
- D. A mask attack against the authentication system
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.