A penetration tester has identified several newly released CVEs on a VoIP call manager. The scanning tool the tester used determined the possible presence of the CVEs based off the version number of the service. Which of the following methods would BEST support validation of the possible findings?
A) Manually check the version number of the VoIP service against the CVE release
B) Test with proof-of-concept code from an exploit database
C) Review SIP traffic from an on-path position to look for indicators of compromise
D) Utilize an nmap -sV scan against the service Utilize an nmap -sV scan against the service
Correct Answer:
Verified
Q34: A penetration tester wants to scan a
Q35: A penetration tester runs the following command
Q36: A penetration tester has obtained root access
Q37: A penetration tester logs in as a
Q38: A software development team is concerned that
Q40: A penetration tester needs to perform a
Q41: A penetration tester was able to gain
Q42: Which of the following is the MOST
Q43: In an unprotected network file repository, a
Q44: A penetration tester has been hired to
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents