adplus-dvertising
frame-decoration

Question

What is a potential method for penetration testers to retain or obtain access by targeting virtual machine repositories?

a.

Exploiting VM escape vulnerabilities

b.

Modifying a system's configuration

c.

Placing compromised virtual machines in repositories

d.

Conducting denial-of-service attacks

Answer: (c).Placing compromised virtual machines in repositories Explanation:A potential method for penetration testers to retain or obtain access is by placing compromised virtual machines in repositories, making them available for adoption and use if the included exploit or vulnerability is not identified.

Engage with the Community - Add Your Comment

Confused About the Answer? Ask for Details Here.

Know the Explanation? Add it Here.

Q. What is a potential method for penetration testers to retain or obtain access by targeting virtual machine repositories?

Similar Questions

Discover Related MCQs

Q. What is a challenge with virtual machine escape exploits in most virtualization environments?

Q. In containerization, what is a common starting point for attacks against Docker and Kubernetes?

Q. How can a penetration tester attempt to access a container's host after compromising the container?

Q. What is a key focus of attacks on containerized workload vulnerabilities?

Q. What should a penetration tester look for when hunting for misconfigurations in containerized technologies?

Q. What additional aspect should penetration testers keep in mind regarding attacks against containerized environments?

Q. What is a consideration when planning a penetration test for cloud-hosted environments?

Q. What is a potential consequence of compromised credentials acquired through phishing campaigns or breaches in cloud environments?

Q. What does account takeover as a penetration tester typically involve?

Q. In cloud environments, what is a more effective focus for a penetration tester when attacking cloud services, compared to on-premises tools?

Q. What is the AWS Metadata service used for, and how might it be exploited by attackers?

Q. What does Azure's Metadata service provide information about, and how might it be utilized by attackers?

Q. What is one of the most common misconfigurations in cloud services that can lead to security issues?

Q. What is a common area where penetration testers may find valuable data due to misconfigurations in cloud services?

Q. When assessing an object store, what are some common things to look for?

Q. In AWS, how can you check the permissions of an S3 bucket using the command line?

Q. What type of attack focuses on secret keys and credentials to gain access to object storage buckets?

Q. In a federation scenario between on-site Active Directory environments and Azure AD, what is commonly used for authentication and authorization?

Q. What does federation allow organizations to do in the context of services?

Q. Which type of cloud attack involves injecting malicious code into service or code pipelines or adding malicious tools into existing cloud infrastructure?