Sign In
Home/CompTIA/PT0-003: CompTIA PenTest+/Free questions

PT0-003: CompTIA PenTest+ — Free Practice Questions

10 free sample questions from a bank of 608, with the correct answers and explanations. No signup required — start practising right now.

1A penetration tester wants to send a specific network packet with custom flags and sequence numbers to a vulnerable target. Which of the following should the tester use?
  • tcprelay
  • Bluecrack
  • Scapy
  • tcpdump
Answer: C
2Which of the following explains the reason a tester would opt to use DREAD over PTES during the planning phase of a penetration test?
  • The tester is conducting a web application test.
  • The tester is assessing a mobile application.
  • The tester is evaluating a thick client application.
  • The tester is creating a threat model.
Answer: D
3A penetration tester is performing a security review of a web application. Which of the following should the tester leverage to identify the presence of vulnerable open-source libraries?
  • VM
  • IAST
  • DAST
  • SCA
Answer: D
4A penetration tester finds that an application responds with the contents of the /etc/passwd file when the following payload is sent: Which of the following should the tester recommend in the report to best prevent this type of vulnerability?
PT0-003: CompTIA PenTest+ question 4
  • Drop all excessive file permissions with chmod o-rwx.
  • Ensure the requests application access logs are reviewed frequently.
  • Disable the use of external entities.
  • Implement a WAF to filter all incoming requests.
Answer: C
5A penetration tester is conducting reconnaissance for an upcoming assessment of a large corporate client. The client authorized spear phishing in the rules of engagement. Which of the following should the tester do first when developing the phishing campaign?
  • Shoulder surfing
  • Recon-ng
  • Social media
  • Password dumps
Answer: C
6A penetration tester needs to test a very large number of URLs for public access. Given the following code snippet: Which of the following changes is required?
PT0-003: CompTIA PenTest+ question 6
  • The condition on line 6
  • The method on line 5
  • The import on line 1
  • The delimiter in line 3
Answer: A
7During a penetration test, a tester captures information about an SPN account. Which of the following attacks requires this information as a prerequisite to proceed?
  • Golden Ticket
  • Kerberoasting
  • DCShadow
  • LSASS dumping
Answer: B
8While performing an internal assessment, a tester uses the following command: crackmapexec smb 192.168.1.0/24 -u user.txt -p Summer123@ Which of the following is the main purpose of the command?
  • To perform a pass-the-hash attack over multiple endpoints within the internal network
  • To perform common protocol scanning within the internal network
  • To perform password spraying on internal systems
  • To execute a command in multiple endpoints at the same time
Answer: C
9A penetration testing team needs to determine whether it is possible to disrupt the wireless communications for PCs deployed in the client's offices. Which of the following techniques should the penetration tester leverage?
  • Port mirroring
  • Sidecar scanning
  • ARP poisoning
  • Channel scanning
Answer: D
10Which of the following tasks would ensure the key outputs from a penetration test are not lost as part of the cleanup and restoration activities?
  • Preserving artifacts
  • Reverting configuration changes
  • Keeping chain of custody
  • Exporting credential data
Answer: A

Want the full bank of 608 questions for PT0-003: CompTIA PenTest+? See all practice exams.