PT0-002 Exam Details

  • Exam Code
    :PT0-002
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :455 Q&As
  • Last Updated
    :May 31, 2026

CompTIA PT0-002 Online Questions & Answers

  • Question 221:

    A security engineer identified a new server on the network and wants to scan the host to determine if it is running an approved version of Linux and a patched version of Apache. Which of the following commands will accomplish this task?

    A. nmap -f -sV -p80 192.168.1.20
    B. nmap -sS -sL -p80 192.168.1.20
    C. nmap -A -T4 -p80 192.168.1.20
    D. nmap -O -v -p80 192.168.1.20

  • Question 222:

    A penetration tester is performing an assessment against a customer's web application that is hosted in a major cloud provider's environment. The penetration tester observes that the majority of the attacks attempted are being blocked by the organization's WAF.

    Which of the following attacks would be most likely to succeed?

    A. Reflected XSS
    B. Brute-force
    C. DDoS
    D. Direct-to-origin

  • Question 223:

    A penetration tester downloaded the following Perl script that can be used to identify vulnerabilities in network switches. However, the script is not working properly.

    Which of the following changes should the tester apply to make the script work as intended?

    A. Change line 2 to $ip= 10.192.168.254;
    B. Remove lines 3, 5, and 6.
    C. Remove line 6.
    D. Move all the lines below line 7 to the top of the script.

  • Question 224:

    A penetration tester found several critical SQL injection vulnerabilities during an assessment of a client's system. The tester would like to suggest mitigation to the client as soon as possible.

    Which of the following remediation techniques would be the BEST to recommend? (Choose two.)

    A. Closing open services
    B. Encryption users' passwords
    C. Randomizing users' credentials
    D. Users' input validation
    E. Parameterized queries
    F. Output encoding

  • Question 225:

    Which of the following is the MOST effective person to validate results from a penetration test?

    A. Third party
    B. Team leader
    C. Chief Information Officer
    D. Client

  • Question 226:

    DRAG DROP

    You are a penetration tester reviewing a client's website through a web browser.

    INSTRUCTIONS

    Review all components of the website through the browser to determine if vulnerabilities are present.

    Remediate ONLY the highest vulnerability from either the certificate, source, or cookies.

    If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

    Select and Place:

  • Question 227:

    A penetration tester discovers during a recent test that an employee in the accounting department has been making changes to a payment system and redirecting money into a personal bank account. The penetration test was immediately stopped.

    Which of the following would be the BEST recommendation to prevent this type of activity in the future?

    A. Enforce mandatory employee vacations
    B. Implement multifactor authentication
    C. Install video surveillance equipment in the office
    D. Encrypt passwords for bank account information

  • Question 228:

    A penetration tester is conducting an on-path link layer attack in order to take control of a key fob that controls an electric vehicle. Which of the following wireless attacks would allow a penetration tester to achieve a successful attack?

    A. Bluejacking
    B. Bluesnarfing
    C. BLE attack
    D. WPS PIN attack

  • Question 229:

    Which of the following would be the most efficient way to write a Python script that interacts with a web application?

    A. Create a class for requests.
    B. Write a function for requests.
    C. Import the requests library.
    D. Use the cURL OS command.

  • Question 230:

    A penetration tester successfully performed an exploit on a host and was able to hop from VLAN 100 to VLAN 200. VLAN 200 contains servers that perform financial transactions, and the penetration tester now wants the local interface of the attacker machine to have a static ARP entry in the local cache. The attacker machine has the following:

    IP Address: 192.168.1.63

    Physical Address: 60-36-dd-a6-c5-33

    Which of the following commands would the penetration tester MOST likely use in order to establish a static ARP entry successfully?

    A. tcpdump -i eth01 arp and arp[6:2] == 2
    B. arp -s 192.168.1.63 60-36-DD-A6-C5-33
    C. ipconfig /all findstr /v 00-00-00 | findstr Physical
    D. route add 192.168.1.63 mask 255.255.255.255.0 192.168.1.1

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.