- Home
- All questions
- Question 56
CISSP study material · question 56 of 500
During an authorised penetration test of a retailer's payment portal, the assessors gain a shell on a web host and immediately find stored credentials for a second server they had never enumerated. Which action matches the staged methodology they are following?
Show the answer
Answer: D. Return to discovery, using the new access to gather and analyse information about the second server before attacking it
The attack phase loops back into discovery whenever fresh access reveals new information; reporting runs throughout the engagement rather than beginning after a single exploit.
Source: NIST SP 800-115 (NIST) — SP 800-115 > Section 5.2.1, Penetration Testing Phases