According to the SNORT alert, what is the attacker performing?
A.
brute-force attack against the web application user accounts
B.
XSS attack against the target webserver
C.
brute-force attack against directories and files on the target webserver
D.
SQL injection attack against the target webserver
The Answer Is:
C
This question includes an explanation.
Explanation:
The alert clearly identifies ET SCAN DirBuster Web App Scan in Progress, referencingSID 2008186, which is a Snort signature that specifically detectsDirBusteractivity. DirBuster is a well-known tool used for brute-forcing hidden directories and files on web servers.
The Cisco CyberOps Associate guide and OWASP both identifydirectory brute-forcingas a reconnaissance technique to find unprotected or misconfigured endpoints on web applications, typically prior to launching deeper attacks.
Therefore, the correct interpretation of the alert is:
C. brute-force attack against directories and files on the target webserver.
300-215 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"