PT0-002 Exam Details

  • Exam Code
    :PT0-002
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :455 Q&As
  • Last Updated
    :May 31, 2026

CompTIA PT0-002 Online Questions & Answers

  • Question 271:

    A penetration tester is cleaning up and covering tracks at the conclusion of a penetration test. Which of the following should the tester be sure to remove from the system? (Choose two.)

    A. Spawned shells
    B. Created user accounts
    C. Server logs
    D. Administrator accounts
    E. Reboot system
    F. ARP cache

  • Question 272:

    During an assessment, a penetration tester inspected a log and found a series of thousands of requests coming from a single IP address to the same URL. A few of the requests are listed below.

    Which of the following vulnerabilities was the attacker trying to exploit?

    A. ..Session hijacking
    B. ..URL manipulation
    C. ..SQL injection
    D. ..Insecure direct object reference

  • Question 273:

    A penetration tester opened a shell on a laptop at a client's office but is unable to pivot because of restrictive ACLs on the wireless subnet. The tester is also aware that all laptop users have a hard-wired connection available at their desks.

    Which of the following is the BEST method available to pivot and gain additional access to the network?

    A. Set up a captive portal with embedded malicious code.
    B. Capture handshakes from wireless clients to crack.
    C. Span deauthentication packets to the wireless clients.
    D. Set up another access point and perform an evil twin attack.

  • Question 274:

    A company conducted a simulated phishing attack by sending its employees emails that included a link to a site that mimicked the corporate SSO portal. Eighty percent of the employees who received the email clicked the link and provided their corporate credentials on the fake site.

    Which of the following recommendations would BEST address this situation?

    A. Implement a recurring cybersecurity awareness education program for all users.
    B. Implement multifactor authentication on all corporate applications.
    C. Restrict employees from web navigation by defining a list of unapproved sites in the corporate proxy.
    D. Implement an email security gateway to block spam and malware from email communications.

  • Question 275:

    A penetration tester is reviewing the following DNS reconnaissance results for comptia.org from dig:

    comptia.org. 3569 IN MX comptia.org-mail.protection.outlook.com. comptia.org. 3569 IN A 3.219.13.186. comptia.org.

    3569 IN NS ns1.comptia.org. comptia.org. 3569 IN SOA haven. administrator.comptia.org. comptia.org. 3569 IN MX new.mx0.comptia.org. comptia.org. 3569 IN MX new.mx1.comptia.org.

    Which of the following potential issues can the penetration tester identify based on this output?

    A. At least one of the records is out of scope.
    B. There is a duplicate MX record.
    C. The NS record is not within the appropriate domain.
    D. The SOA records outside the comptia.org domain.

  • Question 276:

    During enumeration, a red team discovered that an external web server was frequented by employees.

    After compromising the server, which of the following attacks would BEST support compromising company systems?

    A. A side-channel attack
    B. A command injection attack
    C. A watering-hole attack
    D. A cross-site scripting attack

  • Question 277:

    A penetration tester would like to obtain FTP credentials by deploying a workstation as an on-path attack between the target and the server that has the FTP protocol.

    Which of the following methods would be the BEST to accomplish this objective?

    A. Wait for the next login and perform a downgrade attack on the server.
    B. Capture traffic using Wireshark.
    C. Perform a brute-force attack over the server.
    D. Use an FTP exploit against the server.

  • Question 278:

    During a security assessment of a web application, a penetration tester was able to generate the following application response:

    Unclosed quotation mark after the character string Incorrect syntax near ".

    Which of the following is the most probable finding?

    A. SQL injection
    B. Cross-site scripting
    C. Business logic flaw
    D. Race condition

  • Question 279:

    During a penetration test, a tester is able to change values in the URL from example.com/login.php?id=5 to example.com/login.php?id=10 and gain access to a web application. Which of the following vulnerabilities has the penetration tester exploited?

    A. Command injection
    B. Broken authentication
    C. Direct object reference
    D. Cross-site scripting

  • Question 280:

    A penetration tester was able to gain access to a plaintext file on a user workstation. Upon opening the file, the tester notices some strings of randomly generated text. The tester is able to use these strings to move laterally throughout the network by accessing the fileshare on a web application.

    Which of the following should the organization do to remediate the issue?

    A. Sanitize user input.
    B. Implement password management solution.
    C. Rotate keys.
    D. Utilize certificate management.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.