Study. uk . com
  1. Home
  2. All questions
  3. Question 56

CISSP study material · question 56 of 500

During an authorised penetration test of a retailer's payment portal, the assessors gain a shell on a web host and immediately find stored credentials for a second server they had never enumerated. Which action matches the staged methodology they are following?

  1. Move on to reporting, because one successful exploitation already proves the weakness the engagement was scoped to prove
  2. Return to planning, because the goals and ground rules must be renegotiated once a host has actually been compromised
  3. Attack the second server immediately with the credentials, because discovery closes when the attack phase opens
  4. Return to discovery, using the new access to gather and analyse information about the second server before attacking it
Show the answer

Answer: D. Return to discovery, using the new access to gather and analyse information about the second server before attacking it

The attack phase loops back into discovery whenever fresh access reveals new information; reporting runs throughout the engagement rather than beginning after a single exploit.

Source: NIST SP 800-115 (NIST) — SP 800-115 > Section 5.2.1, Penetration Testing Phases

Challenge yourself on this topic → Study as cards