Exam Details

  • Exam Code
    :PT0-003
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :272 Q&As
  • Last Updated
    :Apr 02, 2025

CompTIA CompTIA Certifications PT0-003 Questions & Answers

  • Question 131:

    A penetration tester is working on an engagement in which a main objective is to collect confidential information that could be used to exfiltrate data and perform a ransomware attack. During the engagement, the tester is able to obtain an internal foothold on the target network. Which of the following is the next task the tester should complete to accomplish the objective?

    A. Initiate a social engineering campaign.

    B. Perform credential dumping.

    C. Compromise an endpoint.

    D. Share enumeration.

  • Question 132:

    Which of the following OT protocols sends information in cleartext?

    A. TTEthernet

    B. DNP3

    C. Modbus

    D. PROFINET

  • Question 133:

    A penetration tester needs to launch an Nmap scan to find the state of the port for both TCP and UDP services. Which of the following commands should the tester use?

    A. nmap -sU -sW -p 1-65535 example.com

    B. nmap -sU -sY -p 1-65535 example.com

    C. nmap -sU -sT -p 1-65535 example.com

    D. nmap -sU -sN -p 1-65535 example.com

  • Question 134:

    A penetration tester performs a service enumeration process and receives the following result after scanning a server using the Nmap tool: PORT STATE SERVICE

    22/tcp open ssh 25/tcp filtered smtp

    111/tcp open rpcbind

    2049/tcp open nfs

    Based on the output, which of the following services provides the best target for launching an attack?

    A. Database

    B. Remote access

    C. Email

    D. File sharing

  • Question 135:

    A penetration tester wants to check the security awareness of specific workers in the company with targeted attacks. Which of the following attacks should the penetration tester perform?

    A. Phishing

    B. Tailgating

    C. Whaling

    D. Spear phishing

  • Question 136:

    During a penetration testing engagement, a tester targets the internet-facing services used by the client. Which of the following describes the type of assessment that should be considered in this scope of work?

    A. Segmentation

    B. Mobile

    C. External

    D. Web

  • Question 137:

    During a security audit, a penetration tester wants to run a process to gather information about a target network's domain structure and associated IP addresses. Which of the following tools should the tester use?

    A. Dnsenum

    B. Nmap

    C. Netcat

    D. Wireshark

  • Question 138:

    During an assessment, a penetration tester wants to extend the vulnerability search to include the use of dynamic testing. Which of the following tools should the tester use?

    A. Mimikatz

    B. ZAP

    C. OllyDbg

    D. SonarQube

  • Question 139:

    A penetration tester needs to help create a threat model of a custom application. Which of the following is the most likely framework the tester will use?

    A. MITRE ATTandCK

    B. OSSTMM

    C. CI/CD

    D. DREAD

  • Question 140:

    During the reconnaissance phase, a penetration tester collected the following information from the DNS records:

    A-----> www

    A-----> host

    TXT --> vpn.comptia.org

    SPF---> ip =2.2.2.2

    Which of the following DNS records should be in place to avoid phishing attacks using spoofing domain techniques?

    A. MX

    B. SOA

    C. DMARC

    D. CNAME

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.