PT0-002 Exam Details

  • Exam Code
    :PT0-002
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :455 Q&As
  • Last Updated
    :May 31, 2026

CompTIA PT0-002 Online Questions & Answers

  • Question 131:

    During an engagement, a penetration tester found the following list of strings inside a file:

    Which of the following is the BEST technique to determine the known plaintext of the strings?

    A. Dictionary attack
    B. Rainbow table attack
    C. Brute-force attack
    D. Credential-stuffing attack

  • Question 132:

    Penetration on an assessment for a client organization, a penetration tester notices numerous outdated software package versions were installed ...s-critical servers.

    Which of the following would best mitigate this issue?

    A. Implementation of patching and change control programs
    B. Revision of client scripts used to perform system updates
    C. Remedial training for the client's systems administrators
    D. Refrainment from patching systems until quality assurance approves

  • Question 133:

    Which of the following would MOST likely be included in the final report of a static application-security test that was written with a team of application developers as the intended audience?

    A. Executive summary of the penetration-testing methods used
    B. Bill of materials including supplies, subcontracts, and costs incurred during assessment
    C. Quantitative impact assessments given a successful software compromise
    D. Code context for instances of unsafe type-casting operations

  • Question 134:

    The following PowerShell snippet was extracted from a log of an attacker machine:

    A penetration tester would like to identify the presence of an array. Which of the following line numbers would define the array?

    A. Line 8
    B. Line 13
    C. Line 19
    D. Line 20

  • Question 135:

    Which of the following best explains why communication is a vital phase of a penetration test?

    A. To discuss situational awareness
    B. To build rapport with the emergency contact
    C. To explain the data destruction process
    D. To ensure the likelihood of future assessments

  • Question 136:

    Which of the following tools should a penetration tester use to crawl a website and build a wordlist using the data recovered to crack the password on the website?

    A. DirBuster
    B. CeWL
    C. w3af
    D. Patator

  • Question 137:

    A penetration tester needs to upload the results of a port scan to a centralized security tool.

    Which of the following commands would allow the tester to save the results in an interchangeable format?

    A. nmap -iL results 192.168.0.10-100
    B. nmap 192.168.0.10-100 -O > results
    C. nmap -A 192.168.0.10-100 -oX results
    D. nmap 192.168.0.10-100 | grep "results"

  • Question 138:

    A penetration tester is performing DNS reconnaissance and has obtained the following output using different dig comrr ;; ANSWER SECTION company.com.5INMX10 mxa.company.com company.com.5IN-MX10 mxb.company.com company.com.5INMX100 mxc.company.com ;; ANSWER SECTION company.com.5INA120.73.220.53 ;; ANSWER SECTION company.com.5INNSnsl.nsvr.com Which of the following can be concluded from the output the penetration tester obtained?

    A. mxc.company.com is the preferred mail server.
    B. The company.com record can be cached for five minutes.
    C. The company's website is hosted at 120.73.220.53.
    D. The nameservers are not redundant.

  • Question 139:

    A penetration tester discovered a vulnerability that provides the ability to upload to a path via directory traversal. Some of the files that were discovered through this vulnerability are:

    Which of the following is the BEST method to help an attacker gain internal access to the affected machine?

    A. Edit the discovered file with one line of code for remote callback
    B. Download .pl files and look for usernames and passwords
    C. Edit the smb.conf file and upload it to the server
    D. Download the smb.conf file and look at configurations

  • Question 140:

    During passive reconnaissance of a target organization's infrastructure, a penetration tester wants to identify key contacts and job responsibilities within the company. Which of the following techniques would be the most effective for this situation?

    A. Social media scraping
    B. Website archive and caching
    C. DNS lookup
    D. File metadata analysis

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.