Exam Details

  • Exam Code
    :PT0-003
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :271 Q&As
  • Last Updated
    :Mar 30, 2025

CompTIA CompTIA Certifications PT0-003 Questions & Answers

  • Question 201:

    During a penetration test, the tester gains full access to the application's source code. The application repository includes thousands of code files. Given that the assessment timeline is very short, which of the following approaches would allow the tester to identify hard- coded credentials most effectively?

    A. Run TruffleHog against a local clone of the application

    B. Scan the live web application using Nikto

    C. Perform a manual code review of the Git repository

    D. Use SCA software to scan the application source code

  • Question 202:

    A penetration tester is conducting reconnaissance on a target network. The tester runs the following Nmap command: nmap -sv -sT -p - 192.168.1.0/24. Which of the following describes the most likely purpose of this scan?

    A. OS fingerprinting

    B. Attack path mapping

    C. Service discovery

    D. User enumeration

  • Question 203:

    A penetration tester gains access to a Windows machine and wants to further enumerate users with native operating system credentials. Which of the following should the tester use?

    A. route.exe print

    B. netstat.exe -ntp

    C. net.exe commands

    D. strings.exe -a

  • Question 204:

    A penetration tester would like to leverage a CSRF vulnerability to gather sensitive details from an application's end users. Which of the following tools should the tester use for this task?

    A. Browser Exploitation Framework

    B. Maltego

    C. Metasploit

    D. theHarvester

  • Question 205:

    A penetration tester needs to complete cleanup activities from the testing lead. Which of the following should the tester do to validate that reverse shell payloads are no longer running?

    A. Run scripts to terminate the implant on affected hosts.

    B. Spin down the C2 listeners.

    C. Restore the firewall settings of the original affected hosts.

    D. Exit from C2 listener active sessions.

  • Question 206:

    A tester performs a vulnerability scan and identifies several outdated libraries used within the customer SaaS product offering. Which of the following types of scans did the tester use to identify the libraries?

    A. IAST

    B. SBOM

    C. DAST

    D. SAST

  • Question 207:

    A penetration tester cannot find information on the target company's systems using common OSINT methods. The tester's attempts to do reconnaissance against internet- facing resources have been blocked by the company's WAF. Which of the following is the best way to avoid the WAF and gather information about the target company's systems?

    A. HTML scraping

    B. Code repository scanning

    C. Directory enumeration

    D. Port scanning

  • Question 208:

    A penetration tester writes the following script to enumerate a 1724 network:

    1 #!/bin/bash

    2 for i in {1..254}; do

    3 ping -c1 192.168.1.$i

    4 done

    The tester executes the script, but it fails with the following error:

    -bash: syntax error near unexpected token 'ping'

    Which of the following should the tester do to fix the error?

    A. Add do after line 2.

    B. Replace {1..254} with $(seq 1 254).

    C. Replace bash with tsh.

    D. Replace $i with ${i}.

  • Question 209:

    Which of the following elements in a lock should be aligned to a specific level to allow the key cylinder to turn?

    A. Latches

    B. Pins

    C. Shackle

    D. Plug

  • Question 210:

    A penetration tester attempts to run an automated web application scanner against a target URL. The tester validates that the web page is accessible from a different device. The tester analyzes the following HTTP request header logging output:

    200; GET /login.aspx HTTP/1.1 Host: foo.com; User-Agent: Mozilla/5.0

    200; GET /login.aspx HTTP/1.1 Host: foo.com; User-Agent: Mozilla/5.0

    No response; POST /login.aspx HTTP/1.1 Host: foo.com; User-Agent: curl 200; POST /login.aspx HTTP/1.1 Host: foo.com; User-Agent: Mozilla/5.0

    No response; GET /login.aspx HTTP/1.1 Host: foo.com; User-Agent: python Which of the following actions should the tester take to get the scans to work properly?

    A. Modify the scanner to slow down the scan.

    B. Change the source IP with a VPN.

    C. Modify the scanner to only use HTTP GET requests.

    D. Modify the scanner user agent.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.