PT0-002 Exam Details

  • Exam Code
    :PT0-002
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :455 Q&As
  • Last Updated
    :May 31, 2026

CompTIA PT0-002 Online Questions & Answers

  • Question 261:

    A potential reason for communicating with the client point of contact during a penetration test is to provide resolution if a testing component crashes a system or service and leaves them unavailable for both legitimate users and further testing. Which of the following best describes this concept?

    A. Retesting
    B. De-escalation
    C. Remediation
    D. Collision detection

  • Question 262:

    A penetration tester who is performing an engagement notices a specific host is vulnerable to EternalBlue. Which of the following would BEST protect against this vulnerability?

    A. Network segmentation
    B. Key rotation
    C. Encrypted passwords
    D. Patch management

  • Question 263:

    A penetration tester is using the following script:

    Which of the following BEST describes the purpose of this script?

    A. To determine if a web server's date/time function is susceptible to attack
    B. To determine if a web server's time zone has been misconfigured
    C. To determine the difference between local and server time
    D. To determine and display the round-trip time of HTTP requests

  • Question 264:

    During a penetration test of a server application, a security consultant found that the application randomly crashed or remained stable after opening several simultaneous connections to the application and always submitting the same packets of data.

    Which of the following is the best sequence of steps the tester should use to understand and exploit the vulnerability?

    A. Attacha remoteprofiler to the server application. Establish a random number of connections to the server application. Send fixed packets of data simultaneously using those connections.
    B. Attacha remotedebugger to the server application. Establish a large number of connections to the server application. Send fixed packets of data simultaneously using those connections.
    C. Attacha local disassembler to the server application. Establish a single connection to the server application. Send fixed packets of data simultaneously using that connection.
    D. Attacha remotedisassembler to the server application. Establish a small number of connections to the server application. Send fixed packets of data simultaneously using those connections.

  • Question 265:

    A penetration tester is able to capture the NTLM challenge-response traffic between a client and a server. Which of the following can be done with the pcap to gain access to the server?

    A. Perform vertical privilege escalation.
    B. Replay the captured traffic to the server to recreate the session.
    C. Use John the Ripper to crack the password.
    D. Utilize a pass-the-hash attack.

  • Question 266:

    A client has requested that the penetration test scan include the following UDP services:

    SNMP, NetBIOS, and DNS.

    Which of the following Nmap commands will perform the scan?

    A. nmap ג€andquot;vv sUV ג€andquot;p 53, 123-159 10.10.1.20/24 ג€andquot;oA udpscan
    B. nmap ג€andquot;vv sUV ג€andquot;p 53,123,161-162 10.10.1.20/24 ג€andquot;oA udpscan
    C. nmap ג€andquot;vv sUV ג€andquot;p 53,137-139,161-162 10.10.1.20/24 ג€andquot;oA udpscan
    D. nmap ג€andquot;vv sUV ג€andquot;p 53, 122-123, 160-161 10.10.1.20/24 ג€andquot;oA udpscan

  • Question 267:

    Which of the following documents should be consulted if a client has an issue accepting a penetration test report that was provided?

    A. Rules of engagement
    B. Signed authorization letter
    C. Statement of work
    D. Non-disclosure agreement

  • Question 268:

    A penetration tester has been given eight business hours to gain access to a client's financial system. Which of the following techniques will have the highest likelihood of success?

    A. Attempting to tailgate an employee going into the client's workplace
    B. Dropping a malicious USB key with the company's logo in the parking lot
    C. Using a brute-force attack against the external perimeter to gain a foothold
    D. Performing spear phishing against employees by posing as senior management

  • Question 269:

    The following line-numbered Python code snippet is being used in reconnaissance:

    Which of the following line numbers from the script MOST likely contributed to the script triggering a "probable port scan" alert in the organization's IDS?

    A. Line 01
    B. Line 02
    C. Line 07
    D. Line 08

  • Question 270:

    A red team gained access to the internal network of a client during an engagement and used the Responder tool to capture important data. Which of the following was captured by the testing team?

    A. Multiple handshakes
    B. IP addresses
    C. Encrypted file transfers
    D. User hashes sent over SMB

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.