PT0-002 Exam Details

  • Exam Code
    :PT0-002
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :455 Q&As
  • Last Updated
    :May 31, 2026

CompTIA PT0-002 Online Questions & Answers

  • Question 281:

    A penetration tester needs to perform a vulnerability scan against a web server. Which of the following tools is the tester MOST likely to choose?

    A. Nmap
    B. Nikto
    C. Cain and Abel
    D. Ethercap

  • Question 282:

    Which of the following is the MOST common vulnerability associated with IoT devices that are directly connected to the Internet?

    A. Unsupported operating systems
    B. Susceptibility to DDoS attacks
    C. Inability to network
    D. The existence of default passwords

  • Question 283:

    A company recruited a penetration tester to configure wireless IDS over the network.

    Which of the following tools would BEST test the effectiveness of the wireless IDS solutions?

    A. Aircrack-ng
    B. Wireshark
    C. Wifite
    D. Kismet

  • Question 284:

    During an engagement, a penetration tester was able to upload to a server a PHP file with the following content:

    Which of the following commands should the penetration tester run to successfully achieve RCE?

    A. python3 -c "import requests;print (requests.post (url='http://172.16.200.10/uploads/shell.php', data={'cmd=id'}))"
    B. python3 -c "import requests;print (requests.post(url='http://172.16.200.10/uploads/shell.php', data= ('cmd':'id') ) .text) "
    C. python3 -c "import requests;print (requests.get (url='http://172.16.200.10/uploads/shell.php', params= {'cmd':'id'}) )"
    D. python3 -c "import requests;print (requests.get (url='http://172.16.200.10/uploads/shell.php', params= ('cmd':'id'}) .text) "

  • Question 285:

    A penetration tester is conducting an authorized, physical penetration test to attempt to enter a client's building during non-business hours.

    Which of the following are MOST important for the penetration tester to have during the test? (Choose two.)

    A. A handheld RF spectrum analyzer
    B. A mask and personal protective equipment
    C. Caution tape for marking off insecure areas
    D. A dedicated point of contact at the client
    E. The paperwork documenting the engagement
    F. Knowledge of the building's normal business hours

  • Question 286:

    A penetration tester conducted a vulnerability scan against a client's critical servers and found the following:

    Which of the following would be a recommendation for remediation?

    A. Deploy a user training program
    B. Implement a patch management plan
    C. Utilize the secure software development life cycle
    D. Configure access controls on each of the servers

  • Question 287:

    A penetration tester writes the following script:

    Which of the following is the tester performing?

    A. Searching for service vulnerabilities
    B. Trying to recover a lost bind shell
    C. Building a reverse shell listening on specified ports
    D. Scanning a network for specific open ports

  • Question 288:

    A penetration tester has gained access to a network device that has a previously unknown IP range on an interface. Further research determines this is an always-on VPN tunnel to a third-party supplier. Which of the following is the BEST action for the penetration tester to take?

    A. Utilize the tunnel as a means of pivoting to other internal devices.
    B. Disregard the IP range, as it is out of scope.
    C. Stop the assessment and inform the emergency contact.
    D. Scan the IP range for additional systems to exploit.

  • Question 289:

    During a code review assessment, a penetration tester finds the following vulnerable code inside one of the web application files:

    <% String id = request.getParameter("id"); %>

    Employee ID: <%= id %>

    Which of the following is the best remediation to prevent a vulnerability from being exploited, based on this code?

    A. Parameterized queries
    B. Patch application
    C. Output encoding

  • Question 290:

    A security firm is discussing the results of a penetration test with a client. Based on the findings, the client wants to focus the remaining time on a critical network segment. Which of the following best describes the action taking place?

    A. Maximizing the likelihood of finding vulnerabilities
    B. Reprioritizing the goals/objectives
    C. Eliminating the potential for false positives
    D. Reducing the risk to the client environment

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.