PT0-003: CompTIA PenTest+ Practice Exam — Free CompTIA Questions
QuestionQ1
Attacks and Exploits
Save question
A penetration tester tries to access a domain-joined Windows file server that requires authentication. Which of the following would most likely help gain access?
AIntercept proxy chains with tcpdump.
BCreate a reverse shell payload with msfvenom.
CGenerate a silver ticket with Impacket.
DConduct a relay attack using Responder.
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ2
Attacks and Exploits
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ3
Reconnaissance and Enumeration
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ4
Reconnaissance and Enumeration
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ5
Attacks and Exploits
0
Community Discussion
No comments yet. Be the first to start the discussion!
It's free
100% of the questions are free for all users. No strings attached.
A penetration tester has found sensitive files on a system. Assuming that exfiltrating the files is within the test scope, which option is most likely to evade DLP systems?
AEncoding the data and pushing through DNS to the tester's controlled server
BPadding the data and uploading the files through an external cloud storage service
CObfuscating the data and pushing through FTP to the tester's controlled server
DHashing the data and emailing the files to the tester's company inbox
A penetration tester is performing a wireless security assessment for a client that has 2.4GHz and 5GHz access points. The tester inserts a wireless USB dongle into the laptop to begin capturing WPA2 handshakes. Which of the following should the tester do next?
AEnable monitoring mode using Aircrack-ng.
BUse Kismet to automatically place the wireless dongle in monitor mode and collect handshakes.
CRun KARMA to break the password.
DResearch WIGLE.net for potential nearby client access points.
During a security audit, a penetration tester needs to run a process that gathers information about a target network’s domain structure and associated IP addresses. Which of the following tools should the tester use?
ADnsenum
BNmap
CNetcat
DWireshark
Which of the following is the LOLBin most likely to be used to carry out exfiltration in a Microsoft Windows environment?
Aprocdump.exe
Bmsbuild.exe
Cbitsadmin.exe
Dcscript.exe
QuestionQ6
Engagement Management
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Vulnerability Discovery and Analysis
QuestionQ8
Vulnerability Discovery and Analysis
QuestionQ9
Reconnaissance and Enumeration
QuestionQ10
Vulnerability Discovery and Analysis
QuestionQ11
Engagement Management
QuestionQ12
Post-exploitation and Lateral Movement
QuestionQ13
Engagement Management
QuestionQ14
Post-exploitation and Lateral Movement
QuestionQ15
Reconnaissance and Enumeration
QuestionQ16
Attacks and Exploits
QuestionQ17
Attacks and Exploits
QuestionQ18
Engagement Management
QuestionQ19
Engagement Management
QuestionQ20
Attacks and Exploits
QuestionQ21
Engagement Management
QuestionQ22
Engagement Management
QuestionQ23
Engagement Management
QuestionQ24
Reconnaissance and Enumeration
QuestionQ25
Reconnaissance and Enumeration
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
A penetration tester completes an assessment for a healthcare company. Several findings indicate possible exposure of sensitive patient data. Which of the following actions must the penetration tester take before concluding the engagement?
ACopy the patient data to an external hard disk drive.
BEnsure local copies of patient data are deleted.
CEncrypt any sensitive patient data that may be needed later.
DCapture the cryptographic hash of the patient data files.
A penetration tester accesses and enumerates a host, then executes these commands:
$ runlevel
$ ls -l /etc/rc5.d
$ vi /etc/rc5.d/S01ssh.dd
Which action is the tester most likely trying to perform?
AFind credentials within the SSH daemon
BEstablish persistence on the host
CAdd a key to the host for SSH.
DHarvest users' private keys.
A penetration tester is looking for vulnerabilities or configuration errors in a container environment. Which of the following tools would the tester most likely use to accomplish this objective?
ANikto
BTrivy
CNessus
DNmap
During a penetration test, a tester uses a vulnerability scanner to gather information about potential vulnerabilities that could be used to compromise the network. After receiving the results, the tester runs this command:
snmpwalk -v 2c -c public 192.168.1.23
What is the tester attempting to do based on the command used?
ABypass defensive systems to collect more information.
BUse an automation tool to perform the attacks.
CScript exploits to gain access to the systems and host.
DValidate the results and remove false positives.
A security analyst examines the following output while evaluating server configurations for weaknesses:
Which observation below best captures the key takeaways from this data?
ASSH is configured on a non-standard port.
BHTTP is redirecting to HTTPS.
CThe chosen algorithms provide forward secrecy.
DThe preference should be changed to client.
A penetration tester needs to enter a client’s office building without attracting attention. Which of the following should be the tester’s initial step?
AInteracting with security employees to clone a badge
BTrying to enter the back door after hours on a weekend
CCollecting building blueprints to run a site survey
DConducting surveillance of the office to understand foot traffic
After exploiting a vulnerability in an insecure service to gain access to a Linux system, a penetration tester runs these commands:
sudo -l
route
netstat -a
last
who
Which option best describes the tester's purpose for running these commands?
ATo obtain information about other systems in the network
BTo enumerate users and services in order to identify additional targets
CTo prepare for establishing persistence on the system
DTo gather data to prepare for lateral movement
A penetration tester performs phishing reconnaissance with various tools and accounts across multiple intelligence-gathering platforms. The tester wants to consolidate some of these tools and accounts into a single solution to analyze the output from the intelligence-gathering tools. Which of the following is the best tool for the penetration tester to use?
ACaldera
BSpiderFoot
CMaltego
DWiGLE.net
A penetration tester compromises a developer’s workstation and suspects that the person may be able to access Amazon cloud compute resources. Which command below is least likely to trigger SOC detections while confirming access?
Aaws sts get-caller-identity
Baws connect describe-user
Caws ec2 describe-instances --dry-run
Daws cloud9 list-environments --max-items
A penetration tester is enumerating a Linux system. The objective is to modify the following script to gather more comprehensive system information:
#!/bin/bash
ps aux >> linux enum.txt
Which of the following lines would provide the most comprehensive enumeration of the system?
Dlsof -i >> linux_enum.txtuname -a >> linux_enum.txtls /home/ >> linux_enum.txt
A penetration-testing team must determine whether wireless communications for PCs deployed in the client’s offices could be disrupted. Which technique should the penetration tester use?
APort mirroring
BSidecar scanning
CARP poisoning
DChannel scanning
Which of the following is the most effective mechanism for covertly and rapidly exfiltrating a large volume of data?
ANetwork Time Protocol
BInternet Control Message Protocol
CSimple Mail Transport Protocol
DDomain Name System Protocol
With one day remaining in the testing phase of an engagement, a penetration tester obtains these results from an Nmap scan:
Which of the following tools should the tester use to rapidly identify a potential attack path?
Amsfvenom
BSearchSploit
Csqlmap
DBeEF
During a penetration test, the tester sets up a backdoor to retain access to a compromised system. The tester also leaves a time card on the desktop of the compromised host. Which of the following is the most important activity the tester should perform after the engagement has concluded?
ARevert configuration changes.
BPreserve artifacts.
CRemove persistence mechanisms.
DSecure the data destruction.
Which of the following techniques should a physical penetration tester use to gain access through a rarely used door with electronic locking mechanisms?
ALock picking
BImpersonating
CJamming
DTailgating
EBypassing
Which of the following could help improve the quality and reliability of a vulnerability scan report?
ARisk analysis
BPeer review
CRoot cause analysis
DClient acceptance
Which task would ensure that the key outputs of a penetration test are not lost during cleanup and restoration activities?
APreserving artifacts
BReverting configuration changes
CKeeping chain of custody
DExporting credential data
A penetration tester is setting up a vulnerability management solution to run credentialed scans against an Active Directory server. Which of the following account types should the tester supply to the scanner?
ARead-only
BDomain administrator
CLocal user
DRoot
A penetration tester is conducting an assessment focused on attacking the authentication identity provider that is hosted within a cloud provider. During reconnaissance, the tester discovers that the system uses OpenID Connect with OAuth and has dynamic registration enabled. Which of the following attacks should the tester attempt first?
AA password-spraying attack against the authentication system
BA brute-force attack against the authentication system
CA replay attack against the authentication flow in the system
DA mask attack against the authentication system
While performing an assessment, a penetration tester identifies details about several unreleased products announced during a company-wide meeting. Which of the following attacks did the tester most likely use to obtain this information?
Community Discussion