Solved

A Penetration Tester Has Identified Several Newly Released CVEs on a VoIP

Question 51

Multiple Choice

A penetration tester has identified several newly released CVEs on a VoIP call manager. The scanning tool the tester used determined the possible presence of the CVEs based off the version number of the service. Which of the following methods would BEST support validation of the possible findings?


A) Manually check the version number of the VoIP service against the CVE release
B) Test with proof-of-concept code from an exploit database
C) Review SIP traffic from an on-path position to look for indicators of compromise
D) Utilize an nmap -sV scan against the service Utilize an nmap -sV scan against the service

Correct Answer:

verifed

Verified

Unlock this answer now
Get Access to more Verified Answers free of charge

Related Questions