Exam Details

  • Exam Code
    :PT0-002
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :455 Q&As
  • Last Updated
    :Mar 28, 2025

CompTIA CompTIA Certifications PT0-002 Questions & Answers

  • Question 321:

    A penetration tester is preparing to perform activities for a client that requires minimal disruption to company operations. Which of the following are considered passive reconnaissance tools? (Choose two.)

    A. Wireshark

    B. Nessus

    C. Retina

    D. Burp Suite

    E. Shodan

    F. Nikto

  • Question 322:

    An assessor wants to use Nmap to help map out a stateful firewall rule set. Which of the following scans will the assessor MOST likely run?

    A. nmap 192.168.0.1/24

    B. nmap 192.168.0.1/24

    C. nmap oG 192.168.0.1/24

    D. nmap 192.168.0.1/24

  • Question 323:

    A penetration tester wrote the following script to be used in one engagement:

    Which of the following actions will this script perform?

    A. Look for open ports.

    B. Listen for a reverse shell.

    C. Attempt to flood open ports.

    D. Create an encrypted tunnel.

  • Question 324:

    A penetration tester writes the following script:

    Which of the following objectives is the tester attempting to achieve?

    A. Determine active hosts on the network.

    B. Set the TTL of ping packets for stealth.

    C. Fill the ARP table of the networked devices.

    D. Scan the system on the most used ports.

  • Question 325:

    Given the following output: User-agent:*

    Disallow: /author/

    Disallow: /xmlrpc.php

    Disallow: /wp-admin

    Disallow: /page/

    During which of the following activities was this output MOST likely obtained?

    A. Website scraping

    B. Website cloning

    C. Domain enumeration

    D. URL enumeration

  • Question 326:

    A physical penetration tester needs to get inside an organization's office and collect sensitive information without acting suspiciously or being noticed by the security guards. The tester has observed that the company's ticket gate does not scan the badges, and employees leave their badges on the table while going to the restroom. Which of the following techniques can the tester use to gain physical access to the office? (Choose two.)

    A. Shoulder surfing

    B. Call spoofing

    C. Badge stealing

    D. Tailgating

    E. Dumpster diving

    F. Email phishing

  • Question 327:

    A penetration tester is conducting an assessment against a group of publicly available web servers and notices a number of TCP resets returning from one of the web servers. Which of the following is MOST likely causing the TCP resets to occur during the assessment?

    A. The web server is using a WAF.

    B. The web server is behind a load balancer.

    C. The web server is redirecting the requests.

    D. The local antivirus on the web server Is rejecting the connection.

  • Question 328:

    A penetration tester has been hired to perform a physical penetration test to gain access to a secure room within a client's building. Exterior reconnaissance identifies two entrances, a WiFi guest network, and multiple security cameras connected to the Internet.

    Which of the following tools or techniques would BEST support additional reconnaissance?

    A. Wardriving

    B. Shodan

    C. Recon-ng

    D. Aircrack-ng

  • Question 329:

    Which of the following situations would MOST likely warrant revalidation of a previous security assessment?

    A. After detection of a breach

    B. After a merger or an acquisition

    C. When an organization updates its network firewall configurations

    D. When most of the vulnerabilities have been remediated

  • Question 330:

    A penetration tester found several critical SQL injection vulnerabilities during an assessment of a client's system. The tester would like to suggest mitigation to the client as soon as possible.

    Which of the following remediation techniques would be the BEST to recommend? (Choose two.)

    A. Closing open services

    B. Encryption users' passwords

    C. Randomizing users' credentials

    D. Users' input validation

    E. Parameterized queries

    F. Output encoding

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.