PT0-002 Exam Details

  • Exam Code
    :PT0-002
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :455 Q&As
  • Last Updated
    :May 31, 2026

CompTIA PT0-002 Online Questions & Answers

  • Question 231:

    Which of the following assessment methods is MOST likely to cause harm to an ICS environment?

    A. Active scanning
    B. Ping sweep
    C. Protocol reversing
    D. Packet analysis

  • Question 232:

    A penetration-testing team is conducting a physical penetration test to gain entry to a building.

    Which of the following is the reason why the penetration testers should carry copies of the engagement documents with them?

    A. As backup in case the original documents are lost
    B. To guide them through the building entrances
    C. To validate the billing information with the client
    D. As proof in case they are discovered

  • Question 233:

    During a test of a custom-built web application, a penetration tester identifies several vulnerabilities. Which of the following would be the most interested in the steps to reproduce these vulnerabilities?

    A. Operations staff
    B. Developers
    C. Third-party stakeholders
    D. C-suite executives

  • Question 234:

    During a web application test, a penetration tester was able to navigate to https://company.com and view all links on the web page. After manually reviewing the pages, the tester used a web scanner to automate the search for vulnerabilities.

    When returning to the web application, the following message appeared in the browser:

    unauthorized to view this page.

    Which of the following BEST explains what occurred?

    A. The SSL certificates were invalid.
    B. The tester IP was blocked.
    C. The scanner crashed the system.
    D. The web page was not found.

  • Question 235:

    A penetration tester is conducting a test after hours and notices a critical system was taken down. Which of the following contacts should be notified first?

    A. Secondary
    B. Emergency
    C. Technical
    D. Primary

  • Question 236:

    Which of the following is the most appropriate action to take when a client requests a penetration testing report that may be subject to confidentiality agreements?

    A. Provide an example report from a prior penetration test engagement.
    B. Allow the client to only view the information while in secure spaces.
    C. Determine which reports are no longer under a period of confidentiality.
    D. Provide raw output from penetration testing tools.

  • Question 237:

    A penetration tester is performing an assessment for an application that is used by large organizations operating in the heavily regulated financial services industry. The penetration tester observes that the default Admin User account is enabled and appears to be used several times a day by unfamiliar IP addresses.

    Which of the following is the most appropriate way to remediate this issue?

    A. Increase password complexity.
    B. Implement system hardening.
    C. Restrict simultaneous user log-ins.
    D. Require local network access.

  • Question 238:

    A penetration tester is reviewing the security of a web application running in an laaS compute instance. Which of the following payloads should the tester send to get the running process credentials?

    A. file=http://192.168. 1. 78?+document.cookie
    B. file =.. / .. / .. /proc/self/environ
    C. file='%20or%2054365=54365 ;-
    D. file=http://169.254.169.254/latest/meta-data/

  • Question 239:

    Which of the following provides a matrix of common tactics and techniques used by attackers along with recommended mitigations?

    A. NIST SP 800-53
    B. OWASP Top 10
    C. MITRE ATTandCK framework
    D. PTES technical guidelines

  • Question 240:

    A penetration tester, who is doing an assessment, discovers an administrator has been exfiltrating proprietary company information. The administrator offers to pay the tester to keep quiet.

    Which of the following is the BEST action for the tester to take?

    A. Check the scoping document to determine if exfiltration is within scope.
    B. Stop the penetration test.
    C. Escalate the issue.
    D. Include the discovery and interaction in the daily report.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.