Exam Details

  • Exam Code
    :PT0-003
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :271 Q&As
  • Last Updated
    :

CompTIA CompTIA Certifications PT0-003 Questions & Answers

  • Question 51:

    A penetration tester was contracted to test a proprietary application for buffer overflow vulnerabilities. Which of the following tools would be BEST suited for this task?

    A. GDB

    B. Burp Suite

    C. SearchSpliot

    D. Netcat

  • Question 52:

    A penetration tester is testing input validation on a search form that was discovered on a website. Which of the following characters is the BEST option to test the website for vulnerabilities?

    A. Comma

    B. Double dash

    C. Single quote

    D. Semicolon

  • Question 53:

    A penetration tester ran the following command on a staging server:

    python

  • Question 54:

    A penetration tester is working on a scoping document with a new client. The methodology the client uses includes the following:

    Pre-engagement interaction (scoping and ROE) Intelligence gathering (reconnaissance) Threat modeling Vulnerability analysis Exploitation and post exploitation Reporting

    Which of the following methodologies does the client use?

    A. OWASP Web Security Testing Guide

    B. PTES technical guidelines

    C. NIST SP 800-115

    D. OSSTMM

  • Question 55:

    Which of the following BEST describes why a client would hold a lessons-learned meeting with the penetration-testing team?

    A. To provide feedback on the report structure and recommend improvements

    B. To discuss the findings and dispute any false positives

    C. To determine any processes that failed to meet expectations during the assessment

    D. To ensure the penetration-testing team destroys all company data that was gathered during the test

  • Question 56:

    A penetration tester is conducting an engagement against an internet-facing web application and planning a phishing campaign. Which of the following is the BEST passive method of obtaining the technical contacts for the website?

    A. WHOIS domain lookup

    B. Job listing and recruitment ads

    C. SSL certificate information

    D. Public data breach dumps

  • Question 57:

    Which of the following is a regulatory compliance standard that focuses on user privacy by implementing the right to be forgotten?

    A. NIST SP 800-53

    B. ISO 27001

    C. GDPR

  • Question 58:

    A penetration tester needs to upload the results of a port scan to a centralized security tool.

    Which of the following commands would allow the tester to save the results in an interchangeable format?

    A. nmap -iL results 192.168.0.10-100

    B. nmap 192.168.0.10-100 -O > results

    C. nmap -A 192.168.0.10-100 -oX results

    D. nmap 192.168.0.10-100 | grep "results"

  • Question 59:

    A penetration tester has been given an assignment to attack a series of targets in the 192.168.1.0/24 range, triggering as few alarms and countermeasures as possible.

    Which of the following Nmap scan syntaxes would BEST accomplish this objective?

    A. nmap -sT -vvv -O 192.168.1.2/24 -PO

    B. nmap -sV 192.168.1.2/24 -PO

    C. nmap -sA -v -O 192.168.1.2/24

    D. nmap -sS -O 192.168.1.2/24 -T1

  • Question 60:

    A company requires that all hypervisors have the latest available patches installed. Which of the following would BEST explain the reason why this policy is in place?

    A. To provide protection against host OS vulnerabilities

    B. To reduce the probability of a VM escape attack

    C. To fix any misconfigurations of the hypervisor

    D. To enable all features of the hypervisor

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.