nerdexam
CompTIA

PT0-003 · Question #242

During a routine penetration test, the client's security team observes logging alerts that indicate several ID badges were reprinted after working hours without the appropriate authorization. Which of

The correct answer is A. Obtain long-term, valid access to the facility.. Explanation Reprinting ID badges after hours without authorization is a classic physical penetration testing technique aimed at creating cloned or duplicate access credentials, allowing the tester to gain persistent, legitimate-looking entry to the facility over an extended perio

Submitted by chiamaka_o· Mar 6, 2026Post-exploitation and Lateral Movement

Question

During a routine penetration test, the client's security team observes logging alerts that indicate several ID badges were reprinted after working hours without the appropriate authorization. Which of the following is the penetration tester most likely trying to do?

Options

  • AObtain long-term, valid access to the facility.
  • BDisrupt the availability of facility access systems.
  • CChange access to the facility for valid users.
  • DRevoke access to the facility for valid users.

How the community answered

(28 responses)
  • A
    79% (22)
  • B
    7% (2)
  • C
    11% (3)
  • D
    4% (1)

Explanation

Explanation

Reprinting ID badges after hours without authorization is a classic physical penetration testing technique aimed at creating cloned or duplicate access credentials, allowing the tester to gain persistent, legitimate-looking entry to the facility over an extended period. Option A is correct because the goal is to possess a valid-appearing badge that grants repeated, undetected access - a hallmark of long-term physical infiltration.

Why the distractors are wrong:

  • B (Disrupt availability): Reprinting badges doesn't disable or crash access systems; it exploits them covertly rather than causing downtime.
  • C (Change access for valid users): The tester is creating access for themselves, not modifying another user's existing permissions.
  • D (Revoke access): Revoking access would deny entry to legitimate users, which is a destructive action inconsistent with gaining personal access - and counterproductive to the tester's goal.

Memory Tip

Think: "Reprint = Retain Access." A penetration tester reprinting badges is like making a copy of a house key - the goal is to keep getting in, not to lock others out or break the door. If you see badge cloning/reprinting on the exam, think long-term covert physical access.

Topics

#Physical penetration testing#Access control bypass#Credential generation#Persistence

Community Discussion

No community discussion yet for this question.

Full PT0-003 Practice