IT Exam Items Repository What is the purpose of bug bounty programs used by companies?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerWhen conducting an application-based penetration test on a web application, the assessment should also include testing access to which resources?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerWhat two resources are evaluated by a network infrastructure penetration test? (Choose two.)ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerWhat kind of security weakness is evaluated by application-based penetration tests?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerWhat is an insider threat attack?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerWhat is a state-sponsored attack?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerWhich type of threat actor uses cybercrime to steal sensitive data and reveal it publicly to embarrass a target?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerWhich threat actor term describes a well-funded and motivated group that will use the latest attack techniques for financial gain?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerWhich statement best describes the term ethical hacker?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerA company hires a cybersecurity consultant to perform penetration tests. What is the key difference between unknown-environment testing and known-environment testing?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerA company hires a cybersecurity consultant to perform penetration tests. The consultant is discussing with the company about the penetration testing strategy. Which statement describes the term unknown-environment testing?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerA company hires a cybersecurity consultant to perform penetration tests. The consultant is working with the company to set up communication procedures. Which two protocols should be considered for exchanging emails securely? (Choose two.)ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerA company hires a cybersecurity consultant to perform penetration tests. What should be the consultant's first step in validating the engagement scope?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerA company hires a cybersecurity consultant to perform penetration tests. What can cause scope creep of the engagement?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerA company hires a cybersecurity consultant to assess vulnerability on crucial web application devices such as web and database servers. Which document should the company provide to help the consultant document and define what systems are in the testing?ITExamAnswers Editorial Team asked 3 years ago • Ethical Hacker