PT0-002 Exam Details

  • Exam Code
    :PT0-002
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :455 Q&As
  • Last Updated
    :May 31, 2026

CompTIA PT0-002 Online Questions & Answers

  • Question 91:

    Which of the following types of information would MOST likely be included in an application security assessment report addressed to developers? (Choose two.)

    A. Use of non-optimized sort functions
    B. Poor input sanitization
    C. Null pointer dereferences
    D. Non-compliance with code style guide
    E. Use of deprecated Javadoc tags
    F. A cydomatic complexity score of 3

  • Question 92:

    During an engagement, a junior penetration tester found a multihomed host that led to an unknown network segment. The penetration tester ran a port scan against the network segment, which caused an outage at the customer's factory.

    Which of the following documents should the junior penetration tester most likely follow to avoid this issue in the future?

    A. NDA
    B. MSA
    C. ROE
    D. SLA

  • Question 93:

    Which of the following is a ROE component that provides a penetration tester with guidance on who and how to contact the necessary individuals in the event of a disaster during an engagement?

    A. Engagementscope
    B. Communication escalation path
    C. SLA
    D. SOW

  • Question 94:

    Which of the following would assist a penetration tester the MOST when evaluating the susceptibility of top-level executives to social engineering attacks?

    A. Scraping social media for personal details
    B. Registering domain names that are similar to the target company's
    C. Identifying technical contacts at the company
    D. Crawling the company's website for company information

  • Question 95:

    A consultant just performed a SYN scan of all the open ports on a remote host and now needs to remotely identify the type of services that are running on the host. Which of the following is an active reconnaissance tool that would be BEST to use to accomplish this task?

    A. tcpdump
    B. Snort
    C. Nmap
    D. Netstat
    E. Fuzzer

  • Question 96:

    A client would like to have a penetration test performed that leverages a continuously updated TTPs framework and covers a wide variety of enterprise systems and networks. Which of the following methodologies should be used to BEST meet the client's expectations?

    A. OWASP Top 10
    B. MITRE ATTandCK framework
    C. NIST Cybersecurity Framework
    D. The Diamond Model of Intrusion Analysis

  • Question 97:

    A company that developers embedded software for the automobile industry has hired a penetration-testing team to evaluate the security of its products prior to delivery. The penetration-testing team has stated its intent to subcontract to a reverse-engineering team capable of analyzing binaries to develop proof-of-concept exploits. The software company has requested additional background investigations on the reverse- engineering team prior to approval of the subcontract.

    Which of the following concerns would BEST support the software company's request?

    A. The reverse-engineering team may have a history of selling exploits to third parties.
    B. The reverse-engineering team may use closed-source or other non-public information feeds for its analysis.
    C. The reverse-engineering team may not instill safety protocols sufficient for the automobile industry.
    D. The reverse-engineering team will be given access to source code for analysis.

  • Question 98:

    Which of the following documents must be signed between the penetration tester and the client to govern how any provided information is managed before, during, and after the engagement?

    A. MSA
    B. NDA
    C. SOW
    D. ROE

  • Question 99:

    A consulting company is completing the ROE during scoping. Which of the following should be included in the ROE?

    A. Cost ofthe assessment
    B. Report distribution
    C. Testing restrictions
    D. Liability

  • Question 100:

    A company uses a cloud provider with shared network bandwidth to host a web application on dedicated servers. The company's contact with the cloud provider prevents any activities that would interfere with the cloud provider's other customers.

    When engaging with a penetration-testing company to test the application, which of the following should the company avoid?

    A. Crawling the web application's URLs looking for vulnerabilities
    B. Fingerprinting all the IP addresses of the application's servers
    C. Brute forcing the application's passwords
    D. Sending many web requests per second to test DDoS protection

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.