Câu 53: PT0-003: CompTIA PenTest+
A penetration tester finds it is possible to downgrade a web application's HTTPS connections to HTTP while performing on-path attacks on the local network. The tester reviews the output of the server response to curl -s -I https://internalapp/.HTTP/2 302 -date: Thu, 11 Jan 2024 15:56:24 GMTcontent-type: text/html, cha…
Nội dung câu hỏi
A penetration tester finds it is possible to downgrade a web application's HTTPS connections to HTTP while performing on-path attacks on the local network. The tester reviews the output of the server response to curl -s -I https://internalapp/.HTTP/2 302 -date: Thu, 11 Jan 2024 15:56:24 GMTcontent-type: text/html, charset=iso-8859-llocation: /loginx-content-type-options: nosniffserver: ProdWhich of the following recommendations should the penetration tester include in the report?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Add the HSTS header to the server. — đáp án hiện tại
- B. Attach the httponly flag to cookies.
- C. Front the web application with a firewall rule to block access to port 80.
- D. Remove the x-content-type-options header.
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.