PT0-002 Exam Details

  • Exam Code
    :PT0-002
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :455 Q&As
  • Last Updated
    :May 31, 2026

CompTIA PT0-002 Online Questions & Answers

  • Question 111:

    A penetration tester fuzzes an internal server looking for hidden services and applications and obtains the following output:

    Which of the following is the most likely explanation for the output?

    A. The tester does not have credentials to access the server-status page.
    B. The admin directory cannot be fuzzed because it is forbidden.
    C. The admin, test, and db directories redirect to the log-in page.
    D. The robots.txt file has six entries in it.

  • Question 112:

    A penetration tester is evaluating a company's network perimeter. The tester has received limited information about defensive controls or countermeasures, and limited internal knowledge of the testing exists.

    Which of the following should be the FIRST step to plan the reconnaissance activities?

    A. Launch an external scan of netblocks.
    B. Check WHOIS and netblock records for the company.
    C. Use DNS lookups and dig to determine the external hosts.
    D. Conduct a ping sweep of the company's netblocks.

  • Question 113:

    A penetration tester uncovers access keys within an organization's source code management solution.

    Which of the following would BEST address the issue? (Choose two.)

    A. Setting up a secret management solution for all items in the source code management system
    B. Implementing role-based access control on the source code management system
    C. Configuring multifactor authentication on the source code management system
    D. Leveraging a solution to scan for other similar instances in the source code management system
    E. Developing a secure software development life cycle process for committing code to the source code management system
    F. Creating a trigger that will prevent developers from including passwords in the source code management system

  • Question 114:

    A penetration tester who is working remotely is conducting a penetration test using a wireless connection. Which of the following is the BEST way to provide confidentiality for the client while using this connection?

    A. Configure wireless access to use a AAA server.
    B. Use random MAC addresses on the penetration testing distribution.
    C. Install a host-based firewall on the penetration testing distribution.
    D. Connect to the penetration testing company's VPS using a VPN.

  • Question 115:

    During an assessment, a penetration tester found a suspicious script that could indicate a prior compromise. While reading the script, the penetration tester noticed the following lines of code:

    Which of the following was the script author trying to do?

    A. Spawn a local shell.
    B. Disable NIC.
    C. List processes.
    D. Change the MAC address

  • Question 116:

    What is the primary purpose of scoping in a penetration test?

    A. To identify potential risks and threats during testing
    B. To define the boundaries and objectives
    C. To ensure that all vulnerabilities are identified and addressed
    D. To validate the project timeline and resource allocations

  • Question 117:

    A penetration tester is conducting an unknown environment test and gathering additional information that can be used for later stages of an assessment. Which of the following would most likely produce useful information for additional testing?

    A. Searching for code repositories associated with a developer who previously worked for the target company code repositories associated with the
    B. Searching for code repositories target company's organization
    C. Searching for code repositories associated with the target company's organization
    D. Searching for code repositories associated with a developer who previously worked for the target company

  • Question 118:

    A penetration tester was able to gain access successfully to a Windows workstation on a mobile client's laptop. Which of the following can be used to ensure the tester is able to maintain access to the system?

    A. schtasks /create /sc /ONSTART /tr C:\Temp\WindowsUpdate.exe
    B. wmic startup get caption,command
    C. crontab -l; echo “@reboot sleep 200 andand ncat -lvp 4242 -e /bin/bash”) | crontab 2>/dev/null
    D. sudo useradd -ou 0 -g 0 user

  • Question 119:

    SIMULATION

    You are a penetration tester running port scans on a server.

    INSTRUCTIONS

    Part 1: Given the output, construct the command that was used to generate this output from the available options.

    Part 2: Once the command is appropriately constructed, use the given output to identify the potential attack vectors that should be investigated further.

    If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

    A. See explanation below.
    B. PlaceHolder
    C. PlaceHolder
    D. PlaceHolder

  • Question 120:

    A security consultant wants to perform a vulnerability assessment with an application that can effortlessly generate an easy-to-read report. Which of the following should the attacker use?

    A. Brakeman
    B. Nessus
    C. Metasploit
    D. SCAP

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.