PT0-003 Exam Questions
302 real PT0-003 exam questions with expert-verified answers and explanations. Page 2 of 7.
- Question #53Reconnaissance and Enumeration
A penetration tester is performing network reconnaissance. The tester wants to gather information about the network without causing detection mechanisms to flag the reconnaissance...
network reconnaissancepassive reconnaissancestealth techniquesnetwork sniffing - Question #54Post-exploitation and Lateral Movement
After a recent penetration test was conducted by the company's penetration testing team, a systems administrator notices the following in the logs: 2/10/2023 05:50AM C:\users\mgran...
persistencescheduled taskspost-exploitation commandsWindows commands - Question #55Vulnerability Discovery and Analysis
A penetration tester is conducting a vulnerability scan. The tester wants to see any vulnerabilities that may be visible from outside of the organization. Which of the following sc...
vulnerability scanningexternal scanunauthenticated scan - Question #56Post-exploitation and Lateral Movement
A penetration tester gains initial access to a target system by exploiting a recent RCE vulnerability. The patch for the vulnerability will be deployed at the end of the week. Whic...
persistenceWindows commandsscheduled tasksservice creation - Question #57Reconnaissance and Enumeration
A penetration tester is conducting reconnaissance for an upcoming assessment of a large corporate client. The client authorized spear phishing in the rules of engagement. Which of...
social engineeringspear phishingopen-source intelligencereconnaissance - Question #58Post-exploitation and Lateral Movement
A penetration tester established an initial compromise on a host. The tester wants to pivot to other targets and set up an appropriate relay. The tester needs to enumerate through...
pivotingproxychainslateral movementnetwork relay - Question #59Reconnaissance and Enumeration
A penetration tester needs to confirm the version number of a client's web application server. Which of the following techniques should the penetration tester use?
banner grabbingweb server reconnaissanceversion enumeration - Question #60Engagement Management
While conducting a peer review for a recent assessment, a penetration tester finds the debugging mode is still enabled for the production system. Which of the following is most lik...
post-engagement cleanupconfiguration managementsecurity hygienepenetration test reporting - Question #61Attacks and Exploits
A tester runs an Nmap scan against a Windows server and receives the following results: Which of the following TCP ports should be prioritized for using hash-based relays?
SMBhash-based attacksWindows serviceslateral movement - Question #62Attacks and Exploits
During an assessment, a penetration tester runs the following command: setspn.exe -Q / Which of the following attacks is the penetration tester preparing for?
KerberoastingService Principal NamesActive Directory attacksWindows commands - Question #63Post-exploitation and Lateral Movement
During an assessment, a penetration tester obtains a low-privilege shell and then runs the following command: findstr /SIM /C:"pass" *.txt *.cfg *.xml Which of the following is the...
local enumerationsecrets discoverypost-exploitation commandsWindows commands - Question #64Vulnerability Discovery and Analysis
During an assessment, a penetration tester wants to extend the vulnerability search to include the use of dynamic testing. Which of the following tools should the tester use?
dynamic application security testingweb vulnerability scannerDASTvulnerability discovery tools - Question #65Engagement Management
During an engagement, a penetration tester found some weaknesses that were common across the customer's entire environment. The weaknesses included the following: Weaker password s...
configuration managementvulnerability remediationsecurity policy enforcementpost-engagement recommendations - Question #66Attacks and Exploits
A penetration tester obtains password dumps associated with the target and identifies strict lockout policies. The tester does not want to lock out accounts when attempting access....
credential stuffingpassword attacksaccount lockout policies - Question #67Vulnerability Discovery and Analysis
A penetration tester runs a vulnerability scan that identifies several issues across numerous customer hosts. The executive report outlines the following information: The client is...
vulnerability prioritizationrisk assessmentbusiness impactvulnerability analysis - Question #68Attacks and Exploits
A penetration tester is conducting a wireless security assessment for a client with 2.4GHz and 5GHz access points. The tester places a wireless USB dongle in the laptop to start ca...
wireless penetration testingWPA2 crackingmonitor modeAircrack-ng - Question #69Attacks and Exploits
During a red-team exercise, a penetration tester obtains an employee's access badge. The tester uses the badge's information to create a duplicate for unauthorized entry. Which of...
physical securityRFID cloningaccess badge attacks - Question #71Reconnaissance and Enumeration
A penetration tester wants to use PowerView in an AD environment. Which of the following is the most likely reason?
Active Directory enumerationPowerViewdomain reconnaissanceuser group enumeration - Question #72Vulnerability Discovery and Analysis
A penetration tester is configuring a vulnerability management solution to perform credentialed scans of an Active Directory server. Which of the following account types should the...
credentialed scanningActive Directory securityvulnerability scanningprivilege management - Question #73Attacks and Exploits
A penetration tester writes the following script, which is designed to hide communication and bypass some restrictions on a client's network: $base64cmd = Resolve-DnsName foo.compt...
DNS tunnelingdata exfiltrationcovert communication - Question #74Engagement Management
Which of the following components should a penetration tester include in the final assessment report?
report writingattack narrativepenetration test report - Question #75Engagement Management
Which of the following elements of a penetration test report can be used to most effectively prioritize the remediation efforts for all the findings?
risk scoringremediation prioritizationpenetration test report - Question #76Attacks and Exploits
During a security assessment, a penetration tester needs to exploit a vulnerability in a wireless network's authentication mechanism to gain unauthorized access to the network. Whi...
wireless attacksKARMA attackauthentication bypass - Question #77Vulnerability Discovery and Analysis
A penetration tester needs to evaluate the order in which the next systems will be selected for testing. Given the following output: Which of the following targets should the teste...
target prioritizationnetwork analysisvulnerability assessment - Question #78Post-exploitation and Lateral Movement
During a security assessment, a penetration tester gains access to an internal server and manipulates some data to hide its presence. Which of the following is the best way for the...
anti-forensicslog clearingpost-exploitation - Question #79Post-exploitation and Lateral Movement
A tester enumerated a firewall policy and now needs to stage and exfiltrate data captured from the engagement. Given the following firewall policy: Which of the following commands...
data exfiltrationfirewall bypassnetcattar - Question #80Attacks and Exploits
Which of the following elements in a lock should be aligned to a specific level to allow the key cylinder to turn?
physical securitylock mechanismlock picking - Question #81Reconnaissance and Enumeration
A penetration tester assesses an application allow list and has limited command-line access on the Windows system. Which of the following would give the penetration tester informat...
Windows command-linenltest.exedomain enumeration - Question #82Engagement Management
A penetration tester wants to use multiple TTPs to assess the reactions (alerted, blocked, and others) by the client's current security tools. The threat-modeling team indicates th...
BAS toolsthreat modelingsecurity assessment methodology - Question #83Attacks and Exploits
As part of a security audit, a penetration tester finds an internal application that accepts unexpected user inputs, leading to the execution of arbitrary commands. Which of the fo...
SQL injectionweb application exploitsdata access - Question #84Attacks and Exploits
A penetration tester identifies an exposed corporate directory containing first and last names and phone numbers for employees. Which of the following attack techniques would be th...
social engineeringsmishingaccount compromise - Question #85Vulnerability Discovery and Analysis
A penetration tester enters a command into the shell and receives the following output: C:\Users\UserX\Desktop>vmic service get name, pathname, displayname, startmode | findstr /i...
unquoted service pathprivilege escalationWindows vulnerability - Question #86Engagement Management
Which of the following is the most secure way to protect a final report file when delivering the report to the client/customer?
secure communicationPGP encryptionreport delivery - Question #87Engagement Management
During an engagement, a junior penetration tester found a multihomed host that led to an unknown network segment. The penetration tester ran a port scan against the network segment...
Rules of Engagementscope creepengagement planning - Question #88Engagement Management
A penetration tester is compiling the final report for a recently completed engagement. A junior QA team member wants to know where they can find details on the impact, overall sec...
executive summaryreport structurepenetration test report - Question #89Engagement Management
A tester completed a report for a new client. Prior to sharing the report with the client, which of the following should the tester request to complete a review?
report reviewclient communicationengagement management - Question #90CompTIA PenTest+ - Attacks and Exploits / Web Application Attacks
During an assessment, a penetration tester exploits an SQLi vulnerability. Which of the following commands would allow the penetration tester to enumerate password hashes?
SQLisqlmappenetration testingcredential enumeration - Question #91Post-exploitation and Lateral Movement
During an assessment, a penetration tester obtains an NTLM hash from a legacy Windows machine. Which of the following tools should the penetration tester use to continue the attack...
NTLM hashespass-the-hashCrackMapExeclateral movement - Question #93Reconnaissance and Enumeration
A penetration tester wants to use the following Bash script to identify active servers on a network: 1 network_addr="192.168.1" 2 for h in {1..254}; do 3 ping -c 1 -W 1 $network_ad...
Bash scriptingnetwork scanningscripting error - Question #94Vulnerability Discovery and Analysis
A penetration tester is attempting to discover vulnerabilities in a company's web application. Which of the following tools would most likely assist with testing the security of th...
web application testingvulnerability scanningNikto - Question #95Reconnaissance and Enumeration
A penetration tester needs to launch an Nmap scan to find the state of the port for both TCP and UDP services. Which of the following commands should the tester use?
Nmapport scanningTCP scanUDP scan - Question #96Post-exploitation and Lateral Movement
A tester plans to perform an attack technique over a compromised host. The tester prepares a payload using the following command: msfvenom -p windows/x64/meterpreter/reverse_tcp LH...
payload executionLOLBINsMSBuildpost-exploitation - Question #97Attacks and Exploits
A penetration tester is performing an assessment for an organization and must gather valid user credentials. Which of the following attacks would be best for the tester to use to a...
wireless attackscredential gatheringdeauthentication attack - Question #98Engagement Management
Which of the following is the most important to include in the scope of a wireless security assessment?
wireless assessmentscope definitionAccess Points - Question #99Reconnaissance and Enumeration
As part of active reconnaissance, penetration testers need to determine whether a protection mechanism is in place to safeguard the target's website against web application attacks...
active reconnaissanceWAF detectionweb application security - Question #100Vulnerability Discovery and Analysis
During an assessment, a penetration tester found an application with the default credentials enabled. Which of the following best describes the technical control required to fix th...
vulnerability remediationsystem hardeningdefault credentials - Question #101Reconnaissance and Enumeration
A penetration tester runs a reconnaissance script and would like the output in a standardized machine-readable format in order to pass the data to another application. Which of the...
data formatsmachine-readableJSONreconnaissance output - Question #102Attacks and Exploits
A penetration tester is performing an assessment against a customer's web application that is hosted in a major cloud provider's environment. The penetration tester observes that t...
WAF bypassdirect-to-origin attackweb application attackscloud security - Question #103Engagement Management
Which of the following components should a penetration tester most likely include in a report at the end of an assessment?
reportingpenetration test reportmetrics - Question #104Post-exploitation and Lateral Movement
A penetration testing team has gained access to an organization's data center, but the team requires more time to test the attack strategy. Which of the following wireless attack t...
wireless attacksevil twinpersistencecovert operations