A municipal high-value server has antivirus disabled and no EDR present. How should the tester report that condition in a privilege-escalation / post-exploitation context?
Select an answer to reveal the explanation.
Short Explanation
No AV or EDR on a crown-jewel box is like leaving the alarm system unplugged. It does not invent vulnerabilities by itself, but it makes post-ex and priv-esc freer and noisier for defenders. Report the control gap and keep proving impact with real findings.
Full Explanation
Missing or disabled antivirus and EDR on high-value systems reduces detection and response friction for post-exploitation and privilege-escalation activity. Testers should document the control gap as an enabling risk while still evidencing concrete misconfigurations or privileges. Absence of tools does not remove the host from scope nor guarantee every technique works. Network firewalls do not substitute for healthy endpoint controls on the host itself.