Client-side exploits rely on which network condition to deliver an attack?

Study for the SANS560 GIAC Penetration Tester (GPEN) Test. Study with flashcards and multiple choice questions, each question has hints and explanations. Get ready for your exam!

Multiple Choice

Client-side exploits rely on which network condition to deliver an attack?

Explanation:
Client-side exploits depend on the target machine being able to reach the attacker over the network to receive the payload or deliver data. If outbound access is allowed by the firewall, a user’s browser or application can contact the attacker’s server to fetch the malicious payload, run the exploit, or exfiltrate information, enabling the attack to proceed in the victim’s environment. When outbound connections are blocked, the exploit chain can’t reach the attacker to deliver the payload, so the attack is effectively prevented. The other options aren’t about a network condition that enables delivery: using USB is a physical vector, requiring local access; the target being offline blocks any network contact; bypassing antivirus is a defensive evasion measure, not a network access condition needed for delivery.

Client-side exploits depend on the target machine being able to reach the attacker over the network to receive the payload or deliver data. If outbound access is allowed by the firewall, a user’s browser or application can contact the attacker’s server to fetch the malicious payload, run the exploit, or exfiltrate information, enabling the attack to proceed in the victim’s environment. When outbound connections are blocked, the exploit chain can’t reach the attacker to deliver the payload, so the attack is effectively prevented. The other options aren’t about a network condition that enables delivery: using USB is a physical vector, requiring local access; the target being offline blocks any network contact; bypassing antivirus is a defensive evasion measure, not a network access condition needed for delivery.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy