A penetration tester is cleaning up and covering tracks at t - CompTIA Pentest+ PT0-003

Question

A penetration tester is cleaning up and covering tracks at the conclusion of a penetration test. Which of the following should the tester be sure to remove from the system? (Choose two.)

Answers
  1. correct
  2. correct
Explanation

Correct Answers:A. Spawned shells  B. Created user accounts

At the conclusion of a penetration test, a tester must remove any artifacts left behind to avoid leaving security risks. This is part of ethical penetration testing best practices.

  • Spawned shells 

    • Any backdoors, shells, or remote access mechanisms should be removed to ensure the system is returned to its original state.
    • These could allow unintended access if not cleaned up.
  • Created user accounts 

    • If the tester created dummy accounts or privilege-escalation accounts, these must be removed to prevent unauthorized future access.

Why the Other Options Are Incorrect:

Server logs 

  • Ethical penetration testers should NOT delete logs because they are important for incident response and auditing.
  • Instead, they should report any modified logs to the client.

Administrator accounts 

  • A penetration tester should not delete legitimate admin accounts.
  • If a new admin account was created for testing purposes, that should be removed, but legitimate ones must remain.

Reboot system

  • Rebooting alone does not effectively cover tracks and may even alert the client to suspicious activity.
  • Some persistence techniques might survive a reboot.

ARP cache 

  • Clearing the ARP cache does not contribute significantly to covering tracks.
  • The cache is dynamic and will refresh automatically

No Payment Cards Needed

Related Courses

Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.

a prepsaret exam featured image
CompTIA Prep

220-1201 - CompTIA A+ Exam Core 1

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

220-1202 - CompTIA A+ Exam Core 2

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA SecurityX CAS-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud Essentials+ CLO-002

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Network+ N10-009

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Security+ SY0-701

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Data + DA0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Linux+ XK0-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA CySA+ CSO-003

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA DataSys+ DS0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Tech+ FC0-U71

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud+ CV0-004

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Server+ SK0-005

Start Course Prep

Easy way to pass your test within a week with prepsaret

You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams

View Courses Offered