PT0-002 Exam Details

  • Exam Code
    :PT0-002
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :455 Q&As
  • Last Updated
    :May 31, 2026

CompTIA PT0-002 Online Questions & Answers

  • Question 121:

    A penetration tester wants to perform a SQL injection test.

    Which of the following characters should the tester use to start the SQL injection attempt?

    A. Colon
    B. Double quote mark
    C. Single quote mark
    D. Semicolon

  • Question 122:

    Which of the following should a penetration tester attack to gain control of the state in the HTTP protocol after the user is logged in?

    A. HTTPS communication
    B. Public and private keys
    C. Password encryption
    D. Sessions and cookies

  • Question 123:

    A penetration tester was able to compromise a web server and move laterally into a Linux web server. The tester now wants to determine the identity of the last user who signed in to the web server. Which of the following log files will show this activity?

    A. /var/log/messages
    B. /var/log/last_user
    C. /var/log/user_log
    D. /var/log/lastlog

  • Question 124:

    Which of the following situations would MOST likely warrant revalidation of a previous security assessment?

    A. After detection of a breach
    B. After a merger or an acquisition
    C. When an organization updates its network firewall configurations
    D. When most of the vulnerabilities have been remediated

  • Question 125:

    Which of the following components should a penetration tester most likely include in a report at the end of an assessment?

    A. Metrics and measures
    B. Client interviews
    C. Compliance information
    D. Business policies

  • Question 126:

    When accessing the URL http://192.168.0-1/validate/user.php, a penetration tester obtained the following output:

    ..d index: eid in /apache/www/validate/user.php line 12

    ..d index: uid in /apache/www/validate/user.php line 13

    ..d index: pw in /apache/www/validate/user.php line 14

    ..d index: acl in /apache/www/validate/user.php line 15

    A. Lack of code signing
    B. Incorrect command syntax
    C. Insufficient error handling
    D. Insecure data transmission

  • Question 127:

    A penetration tester uses Hashcat to crack hashes discovered during a penetration test and obtains the following output:

    ad09cd16529b5f5a40a3e15344e57649f4a43a267a97f008af01af803603c4c8 : Summer2023 !!

    7945bb2bb08731fc8d57680ffa4aefec91c784d231de029c610b778eda5ef48b:p@ssWord12 ea88ceab69cb2fb8bdcf9ef4df884af219fffbffab473ec13f20326dc6f84d13: Love-You999

    Which of the following is the best way to remediate the penetration tester's discovery?

    A. Requiring passwords to follow complexity rules
    B. Implementing a blocklist of known bad passwords
    C. Setting the minimum password length to ten characters
    D. Encrypting the passwords with a stronger algorithm

  • Question 128:

    A penetration tester runs the unshadow command on a machine. Which of the following tools will the tester most likely use NEXT?

    A. John the Ripper
    B. Hydra
    C. Mimikatz
    D. Cain and Abel

  • Question 129:

    A penetration tester joins the assessment team in the middle of the assessment. The client has asked the team, both verbally and in the scoping document, not to test the production networks. However, the new tester is not aware of this request and proceeds to perform exploits in the production environment.

    Which of the following would have MOST effectively prevented this misunderstanding?

    A. Prohibiting exploitation in the production environment
    B. Requiring all testers to review the scoping document carefully
    C. Never assessing the production networks
    D. Prohibiting testers from joining the team during the assessment

  • Question 130:

    A penetration tester conducted a discovery scan that generated the following:

    Which of the following commands generated the results above and will transform them into a list of active hosts for further analysis?

    A. nmap 璷G list.txt 192.168.0.1-254 , sort
    B. nmap 璼n 192.168.0.1-254 , grep "Nmap scan" | awk `{print S5}'
    C. nmap ?open 192.168.0.1-254, uniq
    D. nmap 璷 192.168.0.1-254, cut 璮 2

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.