PT0-001 Practice Questions
248 real PT0-001 exam questions with expert-verified answers and explanations. Page 2 of 5.
- Question #52Reconnaissance and enumeration
A penetration tester is reviewing the following output from a wireless sniffer: Which of the following can be extrapolated from the above information?
wireless sniffingMAC addressOUI lookupnetwork reconnaissance - Question #53Attacks and exploits
An email sent from the Chief Executive Officer (CEO) to the Chief Financial Officer (CFO) states a wire transfer is needed to pay a new vendor. Neither is aware of the vendor, and...
social engineeringauthority principleBECspear phishing - Question #54Engagement management
A security assessor completed a comprehensive penetration test of a company and its networks and systems. During the assessment, the tester identified a vulnerability in the crypto...
TLS vulnerabilitycompensating controlsACLrisk mitigation - Question #55Vulnerability discovery and analysis
A penetration tester reports an application is only utilizing basic authentication on an Internet- facing application. Which of the following would be the BEST remediation strategy...
HSTSbasic authenticationtransport securityweb remediation - Question #56Vulnerability discovery and analysis
A penetration tester is performing a code review. Which of the following testing techniques is being performed?
static analysiscode reviewSASTtesting techniques - Question #57Attacks and exploits
During a full-scope security assessment, which of the following is a prerequisite to social engineer a target by physically engaging them?
social engineeringpretextphysical engagementreconnaissance - Question #58Post-exploitation and lateral movement
Consider the following PowerShell command: Cmdlet Which of the following BEST describes the actions performed by this command?
PowerShellremote script executionWindowspost-exploitation - Question #59Engagement management
Which of the following excerpts would come from a corporate policy?
security policygovernancepassword policycompliance - Question #60Post-exploitation and lateral movement
In which of the following scenarios would a tester perform a Kerberoasting attack?
KerberoastingActive Directorycredential harvestinglateral movement - Question #61Post-exploitation and lateral movement
While trying to maintain persistence on a Windows system with limited privileges, which of the following registry keys should the tester use?
registry persistenceHKCUWindows privilegelimited privileges - Question #62Post-exploitation and lateral movement
A penetration tester has a full shell to a domain controller and wants to discover any user account that has not authenticated to the domain in 21 days. Which of the following comm...
dsqueryActive Directoryuser enumerationdomain controller - Question #63Engagement management
Which of the following properties of the penetration testing engagement agreement will have the LARGEST impact on observing and testing production systems at their highest loads?
testing scheduleengagement planningproduction systemsscope - Question #66Reconnaissance and enumeration
A penetration tester ran the following Nmap scan on a computer nmap -sV 192.168.1.5. The organization said it had disabled Telnet from its environment. However, the results of the...
Nmapport scanningservice identificationTelnet - Question #67Attacks and exploits
A penetration testet is attempting to capture a handshake between a client and an access point by monitoring a WPA2-PSK secured wireless network. The (ester is monitoring the corre...
WPA2deauthentication attackwireless handshake802.11 - Question #68Reconnaissance and enumeration
A penetration tester is performing initial intelligence gathering on some remote hosts prior to conducting a vulnerability scan. The tester runs the following command: nmap -D 192....
Nmap decoy scanstealth scanning-D flagreconnaissance - Question #69Post-exploitation and lateral movement
A penetration tester has compromised a host. Which of the following would be the correct syntax to create a Netcat listener on the device?
Netcatreverse shelllistenershell access - Question #70Vulnerability discovery and analysis
Which of the following commands will allow a tester to enumerate potential unquoted services paths on a host?
unquoted service pathwmicWindows enumerationprivilege escalation - Question #71Reconnaissance and enumeration
A constant wants to scan all the TCP Pots on an identified device. Which of the following Nmap switches will complete this task?
NmapTCP port scanningall ports-p flag - Question #72Post-exploitation and lateral movement
After successfully capturing administrator credentials to a remote Windows machine, a penetration tester attempts to access the system using PSExec but is denied permission. Which...
PSExecWindows shareslateral movementcredential use - Question #73Post-exploitation and lateral movement
The following command is run on a Linux file system: Chmod 4111 /usr/bin/sudo Which of the following issues may be exploited now?
SUID bitchmodsudo misconfigurationLinux privilege escalation - Question #74Attacks and exploits
A client is asking a penetration tester to evaluate a new web application for availability. Which of the following types of attacks should the tester use?
TCP SYN floodDoSavailability testingweb application - Question #75Post-exploitation and lateral movement
During a penetration test, a tester runs a phishing campaign and receives a shell from an internal PC running Windows 10 OS. The tester wants to perform credential harvesting with...
MimikatzWDigestcredential harvestingregistry modification - Question #76Vulnerability discovery and analysis
In which of the following components is an exploited vulnerability MOST likely to affect multiple running application containers at once?
container securityshared librariesvulnerability impactapplication containers - Question #77Reconnaissance and enumeration
Which of the following would be BEST for performing passive reconnaissance on a target's external domain?
passive reconnaissanceShodanOSINTexternal enumeration - Question #78Attacks and exploits
If a security consultant comes across a password hash that resembles the following: b117525b345470c29ca3d8ac0b556ba8 Which of the following formats is the correct hash type?
NTLM hashhash identificationpassword hashcredential analysis - Question #79Engagement management
A penetration tester was able to retrieve the initial VPN user domain credentials by phishing a member of the IT department. Afterward, the penetration tester obtained hashes over...
remediation recommendationsphishingVPN securitypassword policy - Question #80Vulnerability discovery and analysis
A software development team recently migrated to new application software on the on-premises environment Penetration test findings show that multiple vulnerabilities exist If a pen...
test environmentVM replicationservice configurationvulnerability confirmation - Question #81Vulnerability discovery and analysis
A security analyst has uncovered a suspicious request in the logs for a web application. Given the following URL: Which of the following attack types is MOST likely to be the vulne...
cross-site scriptingURL analysisweb application attacksattack identification - Question #82Reconnaissance and enumeration
An assessor begins an internal security test of the Windows domain internal. comptinet. The assessor is given network access via DHCP, but is not given any network maps or target I...
DNS SRV recordsKerberosdomain controller discoveryWindows domain - Question #83Engagement management
While prioritizing findings and recommendations for an executive summary, which of the following considerations would De MOST valuable to the client?
executive summaryrisk tolerancefindings prioritizationreporting - Question #84Attacks and exploits
After several attempts, an attacker was able to gain unauthorized access through a biometric sensor using the attacker's actual fingerprint without exploitation. Which of the follo...
biometric authenticationfalse positive ratephysical securityauthentication bypass - Question #85Post-exploitation and lateral movement
A penetration tester successfully exploits a DM2 server that appears to be listening on an outbound port The penetration tester wishes to forward that traffic back to a device. Whi...
SSH tunnelingport forwardingtraffic pivotingDMZ exploitation - Question #86Reconnaissance and enumeration
The results of a basic compliance scan show a subset of assets on a network. This data differs from what is shown on the network architecture diagram, which was supplied at the beg...
network discoverycompliance scanningasset inventoryscan discrepancy - Question #87Post-exploitation and lateral movement
A penetration tester has successfully exploited an application vulnerability and wants to remove the command history from the Linux session. Which of the following will accomplish...
command historyanti-forensicsLinux shellevidence removal - Question #88Engagement management
When performing compliance-based assessments, which of the following is the MOST important Key consideration?
compliance assessmentengagement planningregulatory complianceaudit scope - Question #89Engagement management
Which of the following BEST explains why it is important to maintain confidentiality of any identified findings when performing a penetration test?
confidentialityreport securityengagement ethicsdata handling - Question #90Reconnaissance and enumeration
A penetration tester is designing a phishing campaign and wants to build list of users (or the target organization. Which of the following techniques would be the MOST appropriate?...
user enumerationOSINTsocial media harvestingphishing preparation - Question #91Attacks and exploits
A penetration tester notices that the X-Frame-Optjons header on a web application is not set. Which of the following would a malicious actor do to exploit this configuration settin...
clickjackingX-Frame-Optionsweb security headersiframe attack - Question #92Reconnaissance and enumeration
A penetration tester is required to perform OSINT on staff at a target company after completing the infrastructure aspect. Which of the following would be the BEST step for the pen...
OSINTstaff enumerationsocial engineeringinformation gathering - Question #93Attacks and exploits
A security consultant found a SCADA device in one of the VLANs in scope. Which of the following actions would BEST create a potentially destructive outcome against device?
SCADAICS securitySNMP brute forceOT attacks - Question #94Engagement management
A client asks a penetration tester to add more addresses to a test currently in progress. Which of the following would defined the target list?
statement of workscope managementcontract documentsrules of engagement - Question #95Vulnerability discovery and analysis
A recently concluded penetration test revealed that a legacy web application is vulnerable lo SQL injection Research indicates that completely remediating the vulnerability would r...
SQL injectioninput validationwhitelist filteringvulnerability mitigation - Question #96Post-exploitation and lateral movement
Which of the following is the reason why a penetration tester would run the chkconfig --del servicename command at the end of an engagement?
persistence removalLinux serviceschkconfigpost-exploitation cleanup - Question #97Vulnerability discovery and analysis
A penetration tester is checking a script to determine why some basic persisting. The expected result was the program outputting "True." Given the output from the console above, wh...
bash scriptingscript debuggingsyntax errorsautomation tools - Question #98Reconnaissance and enumeration
Given the following Python script: Which of the following actions will it perform?
banner grabbingPython scriptingservice enumerationcode analysis - Question #99Vulnerability discovery and analysis
A company contracted a firm specializing in penetration testing to assess the security of a core business application. The company provided the firm with a copy of the Java bytecod...
static code analysisJava bytecodedecompilationapplication security testing - Question #100Post-exploitation and lateral movement
A penetration tester runs the following from a compromised box 'python -c -import pty;Pty.sPawn( "/bin/bash").' Which of the following actions is the tester taking?
shell upgradePTY spawnPythoninteractive shell - Question #101Engagement management
A financial institution is asking a penetration tester to determine if collusion capabilities to produce wire fraud are present. Which of the following threat actors should the pen...
threat actorsinsider threatwire fraudassessment scoping - Question #102Attacks and exploits
Given the following script: Which of the following BEST describes the purpose of this script?
keyloggerkeystroke monitoringmalwarescript analysis - Question #103Engagement management
Which of the following has a direct and significant impact on the budget of the security assessment?
scopingbudgetsecurity assessmentproject management