nerdexam
CompTIA

PT0-003 · Question #171

A penetration tester launches an attack against company employees. The tester clones the company's intranet log-in page and sends the link via email to all employees. Which of the following best…

The correct answer is C. Harvesting credentials using SET. Explanation Harvesting credentials using SET (Social Engineering Toolkit) is correct because the scenario describes two classic SET capabilities working together: cloning a legitimate webpage (credential harvester attack) and sending a phishing email to lure victims to that…

Submitted by helene.fr· Mar 6, 2026Attacks and Exploits

Question

A penetration tester launches an attack against company employees. The tester clones the company's intranet log-in page and sends the link via email to all employees. Which of the following best describes the objective and tool selected by the tester to perform this activity?

Options

  • AGaining remote access using BeEF
  • BObtaining the list of email addresses using theHarvester
  • CHarvesting credentials using SET
  • DLaunching a phishing campaign using Gophish

How the community answered

(37 responses)
  • A
    11% (4)
  • B
    5% (2)
  • C
    81% (30)
  • D
    3% (1)

Explanation

Explanation

Harvesting credentials using SET (Social Engineering Toolkit) is correct because the scenario describes two classic SET capabilities working together: cloning a legitimate webpage (credential harvester attack) and sending a phishing email to lure victims to that cloned page - the primary goal being to capture usernames and passwords when employees attempt to log in.

Why the distractors are wrong:

  • A (BeEF) - BeEF (Browser Exploitation Framework) is used to hook browsers and gain remote control/execute client-side attacks, not to clone pages and harvest credentials
  • B (theHarvester) - theHarvester is a passive reconnaissance tool used to collect email addresses from public sources, not to conduct phishing attacks
  • D (Gophish) - While Gophish can run phishing campaigns, it is primarily a phishing simulation/awareness platform, not typically the tool associated with credential harvesting via page cloning in exam contexts; SET is the more precise answer for the combined cloning + credential harvesting objective

Memory Tip

Think SET = Social Engineering Toolkit = Steal Every Token - it's the go-to tool when you see cloned pages + email delivery + credential theft in a question. If you see "phishing campaign tracking/simulation," think Gophish; if you see "credential harvesting via a cloned site," think SET.

Topics

#Social engineering#Phishing#Credential harvesting#SET

Community Discussion

No community discussion yet for this question.

Full PT0-003 Practice