PT0-001 Practice Questions
248 real PT0-001 exam questions with expert-verified answers and explanations. Page 4 of 5.
- Question #157Vulnerability discovery and analysis
A penetration tester has performed a vulnerability scan of a specific host that contains a valuable database and has identified the following vulnerabilities: XSS HTTP DELETE metho...
vulnerability prioritizationSQL injectionHTTP DELETErisk assessment - Question #158Attacks and exploits
A security guard observes an individual entering the building after scanning a badge. The facility has a strict badge-in and badge-out requirement with a turnstile. The security gu...
badge cloningphysical securityRFIDaccess control bypass - Question #159Reconnaissance and enumeration
After successfully enumerating users on an Active Directory domain controller using enum4linux a penetration tester wants to conduct a password-guessing attack Given the below outp...
enum4linuxusername enumerationcommand-line parsingActive Directory - Question #160Post-exploitation and lateral movement
Joe, a penetration tester, was able to exploit a web application behind a firewall He is trying to get a reverse shell back to his machine but the firewall blocks the outgoing traf...
reverse shellegress filteringfirewall evasionHTTP tunneling - Question #161Engagement management
A penetration tester is performing an annual security assessment for a repeat client The tester finds indicators of previous compromise Which of the following would be the most log...
incident responseindicators of compromisereporting proceduresengagement management - Question #162Post-exploitation and lateral movement
A file contains several hashes. Which of the following can be used in a pass-the-hash attack?
pass-the-hashNTLMWindows authenticationcredential attacks - Question #163Engagement management
A penetration tester must assess a web service. Which of the following should the tester request during the scoping phase?
scopingWSDLweb servicesSOAP - Question #164Attacks and exploits
A penetration tester is exploiting the use of default public and private community strings Which of the following protocols is being exploited?
SNMPcommunity stringsdefault credentialsnetwork protocols - Question #165Reconnaissance and enumeration
A consultant is identifying versions of Windows operating systems on a network Which of the following Nmap commands should the consultant run?
NmapOS fingerprintingSMBnetwork scanning - Question #166Attacks and exploits
A penetration tester is using the Onesixtyone tool on Kali Linux to try to exploit the SNMP protocol on a target that has SNMP enabled Which of the following types of attacks is th...
SNMPdictionary attackOnesixtyonecommunity strings - Question #167Attacks and exploits
A web server is running PHP, and a penetration tester is using LFI to execute commands by passing parameters through the URL. This is possible because server logs were poisoned to...
LFIlog poisoningPHPweb exploitation - Question #168Reconnaissance and enumeration
When conducting reconnaissance against a target, which of the following should be used to avoid directory communicating with the target?
passive reconnaissanceOSINTMaltegoreconnaissance tools - Question #169Vulnerability discovery and analysis
A penetration tester generates a report for a host-based vulnerability management agent that is running on a production web server to gather a list of running processes. The tester...
process analysisweb server hardeningvulnerability assessmentunnecessary services - Question #170Vulnerability discovery and analysis
A penetration tester executed a vulnerability scan against a publicly accessible host and found a web server that is vulnerable to the DROWN attack. Assuming this web server is usi...
DROWN attackSSLv2OpenSSLvulnerability verification - Question #171Post-exploitation and lateral movement
A penetration tester obtained access to an internal host of a given target. Which of the following is the BEST tool to retrieve the passwords of users of the machine exploiting a w...
Mimikatzcredential harvestingLSASSWindows - Question #172Engagement management
Defining exactly what is to be tested and the results to be generated from the test will help prevent?
scope definitionscope creepengagement planningrules of engagement - Question #173Attacks and exploits
A consultant is attempting to harvest credentials from unsecure network protocols in use by the organization. Which of the following commands should the consultant use?
credential harvestingnetwork sniffingcleartext protocolstcpdump - Question #174Vulnerability discovery and analysis
An SMB server was discovered on the network, and the penetration tester wants to see if the server it vulnerable. Which of the following is a relevant approach to test this?
SMBnull sessionsvulnerability testingnetwork protocols - Question #175Vulnerability discovery and analysis
A penetration tester is reviewing a Zigbee Implementation for security issues. Which of the following device types is the tester MOST likely testing?
ZigbeeIoT securitywireless protocolsembedded systems - Question #176Vulnerability discovery and analysis
A vulnerability scan is run against a domain hosing a banking application that accepts connections over MTTPS and HTTP protocols Given the following results: · SSU3 supported · HST...
SSL/TLSHSTSrisk prioritizationweb security - Question #177Vulnerability discovery and analysis
A penetration tester discovers Heartbleed vulnerabilities in a target network Which of the following impacts would be a result of exploiting this vulnerability?
HeartbleedOpenSSLmemory disclosurevulnerability impact - Question #178Vulnerability discovery and analysis
A system security engineer is preparing to conduct a security assessment of some new applications. The applications were provided to the engineer as a set that contains only JAR fi...
reverse engineeringJavastatic analysisdynamic analysis - Question #179Attacks and exploits
Which of the following can be used with John the Ripper to crack passwords?
John the Ripperpassword crackingwordlistscredential attacks - Question #180Post-exploitation and lateral movement
What elements should you be sure to remove from an exploited system before finalizing a penetration test?
post-exploitation cleanupartifact removalpersistence removalengagement closure - Question #181Reconnaissance and enumeration
When running an Nmap SYN scan, what will be the Nmap result if ports on the target device do not respond?
NmapSYN scanport statesfirewall detection - Question #182Engagement management
A company's corporate policies state that employees are able to scan any global network as long as it is done within working hours. Government laws prohibit unauthorized scanning....
legal vs policyauthorizationrules of engagementcompliance - Question #183Post-exploitation and lateral movement
After successfully exploiting a local file inclusion vulnerability within a web application a limited reverse shell is spawned back to the penetration tester's workstation Which of...
LFIreverse shellTTY escapepty spawn - Question #184Reconnaissance and enumeration
When performing active information reconnaissance, which of the following should be tested FIRST before starting the exploitation process?
active reconnaissanceSQLmapenumeration orderweb scanning - Question #185Post-exploitation and lateral movement
During a penetration test a tester Identifies traditional antivirus running on the exploited server. Which of the following techniques would BEST ensure persistence in a post-explo...
persistenceantivirus evasionpost-exploitationdaemons - Question #186Attacks and exploits
Which of the following attacks is commonly combined with cross-site scripting for session hijacking?
XSSCSRFsession hijackingweb attacks - Question #187Post-exploitation and lateral movement
During an internal network penetration test the tester is able to compromise a Windows system and recover the NTLM hash for a local wrltsrnAdrain account Attempting to recover the...
pass-the-hashNTLMMedusalateral movement - Question #188Vulnerability discovery and analysis
A penetration tester is performing a validation scan after an organization remediated a vulnerability on port 443 The penetration tester observes the following output: Which of the...
port scanningservice migrationremediation validationNmap - Question #189Engagement management
When communicating the findings of a network vulnerability scan to a client's IT department which of the following metrics BEST prioritize the severity of the findings? (Select TWO...
CVSSseverity prioritizationvulnerability reportingimpact criticality - Question #190Attacks and exploits
While reviewing logs, a web developer notices the following user input string in a field: Which of the following types of attacks was done to the website?
XSSinput validationweb logsattack identification - Question #191Vulnerability discovery and analysis
You can find XSS vulnerabilities in which of the following?
XSSreflected XSSinput fieldsHTTP headers - Question #192Engagement management
A potential customer is looking to test the security of its network. One of the customer's primary concerns is the security awareness of its employees. Which type of test would you...
social engineeringsecurity awarenesspenetration test scopeemployee testing - Question #193Engagement management
Which tool included in Kali is most helpful in compiling a quality penetration testing report?
reporting toolsDradisKali Linuxpentest reporting - Question #194Attacks and exploits
Software developers should escape all characters (including spaces but excluding alphanumeric characters) with the HTML entity &#xHH; format to prevent what type of attack?
XSS preventionHTML entity encodinginput sanitizationsecure coding - Question #195Post-exploitation and lateral movement
A security consultant finds a folder in "C VProgram Files" that has writable permission from an unprivileged user account Which of the following can be used to gam higher privilege...
DLL hijackingprivilege escalationwritable permissionsWindows - Question #196Engagement management
Which of the following documents BEST describes the manner in which a security assessment will be conducted?
SOWassessment documentationrules of engagementengagement planning - Question #197Attacks and exploits
A penetration tester found a network with NAC enabled Which of the following commands can be used to bypass the NAC?
NAC bypassMAC spoofingmacchangernetwork access control - Question #198Attacks and exploits
An internal network penetration test is conducted against a network that is protected by an unknown NAC system In an effort to bypass the NAC restrictions the penetration tester sp...
NAC bypassMAC spoofingprinter impersonationnetwork access control - Question #199Vulnerability discovery and analysis
A penetration tester is performing a code review against a web application Given the following URL and source code: Which of the following vulnerabilities is present in the code ab...
command injectioncode reviewweb applicationsource code analysis - Question #200Reconnaissance and enumeration
After an Nmap NSE scan, a security consultant is seeing inconsistent results while scanning a host. Which of the following is the MOST likely cause?
Nmap NSEfirewall detectionIPSscan inconsistency - Question #201Attacks and exploits
Which of the following wordlists is BEST for cracking MD5 password hashes of an application's users from a compromised database?
password crackingMD5rockyou wordlisthashcat - Question #202Attacks and exploits
A penetration tester calls human resources and begins asking open-ended questions Which of the following social engineering techniques is the penetration tester using?
social engineeringelicitationhuman resourcesopen-ended questioning - Question #203Attacks and exploits
An attacker is attempting to gain unauthorized access to a WiR network that uses WPA2-PSK Which of the following attack vectors would the attacker MOST likely use?
WPA2-PSKwireless attacksfour-way handshakepassword cracking - Question #204Vulnerability discovery and analysis
The SELinux and AppArmor security frameworks include enforcement rules that attempt to prevent which of the following attacks?
SELinuxAppArmorsandbox escapemandatory access control - Question #205Vulnerability discovery and analysis
A _______ vulnerability scan would typically be focused on a specific set of requirements.
vulnerability scanningcompliance scanningscan typesPCI - Question #206Post-exploitation and lateral movement
Which of the following can be used for post-exploitation activities?
post-exploitationPowerShelltoolingscripting