CompTIA PenTest+ (PT0-003) PT0-003 — Question 91
Topic 1 · Question 91 of 334
Topic 1 · Question 91
A penetration tester finds it is possible to downgrade a web application's HTTPS connections to HTTP while performing on-path attacks on the local network. The tester reviews the output of the server response to curl -s -I https://internalapp/. HTTP/2 302 - date: Thu, 11 Jan 2024 15:56:24 GMT content-type: text/html; charset=iso-8859-l location: /login x-content-type-options: nosniff server: Prod Which of the following recommendations should the penetration tester include in the report?