After concluding a penetration test, a tester must remove all credentials created during the test to ensure no unauthorized access remains. What method should the tester use to remove Active Directory (AD) accounts created for testing purposes?
The latest changes and updates from the administration for this exam.
Latest Update: Jun 15 2026
All questions are working fine.
After concluding a penetration test, a tester must remove all credentials created during the test to ensure no unauthorized access remains. What method should the tester use to remove Active Directory (AD) accounts created for testing purposes?
Simon has infiltrated an organization's internal network and intercepted authentication in the form of IDs being passed between a client and server. He decides to use these IDs to authenticate himself as a legitimate user without knowing the user's actual password. Which type of attack is Simon performing?
A penetration tester is conducting software assurance testing on a web application for an organization. You discover the web application is vulnerable to an SQL injection and could disclose a regular user's password. Which of the following actions should you perform?
A cybersecurity analyst working at a major university is reviewing the SQL server log of completed transactions and notices the following suspicious entry:
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
"select ID, GRADE from GRADES where ID=1235235; UPDATE GRADES set GRADE='A' where ID=1235235;"
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Upon further investigation, the analyst determines that the query did not originate from an authorized application or administrator account. Instead, it was triggered by unusual input submitted through a publicly accessible web form. Multiple similar queries targeting other student IDs within the same period were also discovered. Based on this information, which of the following MOST likely occurred?
You need to quickly determine which hosts are active on a network by sending ICMP echo requests. Which of the following tools is specifically designed for this purpose?
During a reconnaissance engagement, you are updating a Bash script to validate whether domains discovered through Domain Name System (DNS) enumeration match the authorized scope file provided in the Statement of Work (SoW). The script must trigger an alert if any domain name differs to prevent out-of-scope scanning. Which of the following operators should be used as the conditional check?
Zack is trying to crack a password by testing all possible combinations of characters that match a specific pattern, such as starting with a capital letter followed by four digits. Which type of attack is Zack performing?
During an engagement, you execute the following script to gather additional system information:

have Several IP addresses return hostnames that were not previously identified during scanning. Which of the following techniques have you performed?
Which of the following is exploited by an SQL injection to give the attacker access to a database?
Which technique would provide the largest increase in security on a network with ICS, SCADA, or IoT devices?