Pre-Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65pass65

PT0-003 CompTIA PenTest+ Exam is now Stable and With Pass Result | Test Your Knowledge for Free

Exams4sure Dumps

PT0-003 Practice Questions

CompTIA PenTest+ Exam

Last Update 3 days ago
Total Questions : 330

Dive into our fully updated and stable PT0-003 practice test platform, featuring all the latest PenTest+ exam questions added this week. Our preparation tool is more than just a CompTIA study aid; it's a strategic advantage.

Our free PenTest+ practice questions crafted to reflect the domains and difficulty of the actual exam. The detailed rationales explain the 'why' behind each answer, reinforcing key concepts about PT0-003. Use this test to pinpoint which areas you need to focus your study on.

PT0-003 PDF

PT0-003 PDF (Printable)
$54.25
$154.99

PT0-003 Testing Engine

PT0-003 PDF (Printable)
$59.5
$169.99

PT0-003 PDF + Testing Engine

PT0-003 PDF (Printable)
$74.55
$212.99
Question # 61

While performing an internal assessment, a tester uses the following command:

crackmapexec smb 192.168.1.0/24 -u user.txt -p Summer123@

Which of the following is the main purpose of the command?

Options:

A.  

To perform a pass-the-hash attack over multiple endpoints within the internal network

B.  

To perform common protocol scanning within the internal network

C.  

To perform password spraying on internal systems

D.  

To execute a command in multiple endpoints at the same time

Discussion 0
Question # 62

A penetration tester wants to collect credentials against an organization with a PEAP infrastructure. Which of the following tools should the tester use?

Options:

A.  

InSSIDer

B.  

HackRF One

C.  

WiFi-Pumpkin

D.  

Aircrack-ng

Discussion 0
Question # 63

During the reconnaissance phase, a penetration tester collected the following information from the DNS records:

A----- > www

A----- > host

TXT -- > vpn.comptia.org

SPF--- > ip =2.2.2.2

Which of the following DNS records should be in place to avoid phishing attacks using spoofing domain techniques?

Options:

A.  

MX

B.  

SOA

C.  

DMARC

D.  

CNAME

Discussion 0
Question # 64

During a penetration test, a tester compromises a Windows computer. The tester executes the following command and receives the following output:

mimikatz # privilege::debug

mimikatz # lsadump::cache

---Output---

lapsUser

27dh9128361tsg2€459210138754ij

---OutputEnd---

Which of the following best describes what the tester plans to do by executing the command?

Options:

A.  

The tester plans to perform the first step to execute a Golden Ticket attack to compromise the Active Directory domain.

B.  

The tester plans to collect application passwords or hashes to compromise confidential information within the local computer.

C.  

The tester plans to use the hash collected to perform lateral movement to other computers using a local administrator hash.

D.  

The tester plans to collect the ticket information from the user to perform a Kerberoasting attack on the domain controller.

Discussion 0
Question # 65

A penetration tester gains access to a Windows machine and wants to further enumerate users with native operating system credentials. Which of the following should the tester use?

Options:

A.  

route

B.  

nbtstat

C.  

net

D.  

whoami

Discussion 0
Question # 66

While conducting OSINT, a penetration tester discovers the client ' s administrator posted part of an unsanitized firewall configuration to a troubleshooting message board. Which of the following did the penetration tester most likely use?

Options:

A.  

HTML scraping

B.  

Public code repository scanning

C.  

Wayback Machine

D.  

Search engine enumeration

Discussion 0
Question # 67

A penetration tester plans to conduct reconnaissance during an engagement using readily available resources. Which of the following resources would most likely identify hardware and software being utilized by the client?

Options:

A.  

Cryptographic flaws

B.  

Protocol scanning

C.  

Cached pages

D.  

Job boards

Discussion 0
Question # 68

A tester wants to pivot from a compromised host to another network with encryption and the least amount of interaction with the compromised host. Which of the following is the best way to accomplish this objective?

Options:

A.  

Create an SSH tunnel using sshuttle to forward all the traffic to the compromised computer.

B.  

Configure a VNC server on the target network and access the VNC server from the compromised computer.

C.  

Set up a Metasploit listener on the compromised computer and create a reverse shell on the target network.

D.  

Create a Netcat connection to the compromised computer and forward all the traffic to the target network.

Discussion 0
Question # 69

A penetration tester is conducting reconnaissance on a target network. The tester runs the following Nmap command: nmap -sv -sT -p - 192.168.1.0/24. Which of the following describes the most likely purpose of this scan?

Options:

A.  

OS fingerprinting

B.  

Attack path mapping

C.  

Service discovery

D.  

User enumeration

Discussion 0
Question # 70

A penetration tester needs to use the native binaries on a system in order to download a file from the internet and evade detection. Which of the following tools would the tester most likely use?

Options:

A.  

netsh.exe

B.  

certutil.exe

C.  

nc.exe

D.  

cmdkey.exe

Discussion 0
Get PT0-003 dumps and pass your exam in 24 hours!

Free Exams Sample Questions