PT0-002 Exam Details

  • Exam Code
    :PT0-002
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :455 Q&As
  • Last Updated
    :May 31, 2026

CompTIA PT0-002 Online Questions & Answers

  • Question 291:

    The provision that defines the level of responsibility between the penetration tester and the client for preventing unauthorized disclosure is found in the:

    A. NDA
    B. SLA
    C. MSA
    D. SOW

  • Question 292:

    Which of the following tools would be BEST suited to perform a manual web application security assessment? (Choose two.)

    A. OWASP ZAP
    B. Nmap
    C. Nessus
    D. BeEF
    E. Hydra
    F. Burp Suite

  • Question 293:

    A penetration tester exploits a vulnerable service to gain a shell on a target server. The tester receives the following:

    Directory of C:\Users\Guest 05/13/2022 09:23 PM mimikatz.exe 05/18/2022 09:24 PM mimidrv.sys 05/18/2022 09:24 PM mimilib.dll

    Which of the following best describes these findings?

    A. Indicators of prior compromise
    B. Password encryption tools
    C. False positives
    D. De-escalation attempts

  • Question 294:

    A penetration tester who is doing a company-requested assessment would like to send traffic to another system using double tagging.

    Which of the following techniques would BEST accomplish this goal?

    A. RFID cloning
    B. RFID tagging
    C. Meta tagging
    D. Tag nesting

  • Question 295:

    A penetration tester noticed that an employee was using a wireless headset with a smartphone.

    Which of the following methods would be best to use to intercept the communications?

    A. Multiplexing
    B. Bluejacking
    C. Zero-day attack
    D. Smurf attack

  • Question 296:

    Which of the following elements of a penetration testing report aims to provide a normalized and standardized representation of discovered vulnerabilities and the overall threat they present to an affected system or network?

    A. Executive summary
    B. Vulnerability severity rating
    C. Recommendations of mitigation
    D. Methodology

  • Question 297:

    A penetration tester receives the following results from an Nmap scan:

    Which of the following OSs is the target MOST likely running?

    A. CentOS
    B. Arch Linux
    C. Windows Server
    D. Ubuntu

  • Question 298:

    Which of the following is most important to include in the final report of a static application- security test that was written with a team of application developers as the intended audience?

    A. Executive summary of the penetration-testing methods used
    B. Bill of materials including supplies, subcontracts, and costs incurred during assessment
    C. Quantitative impact assessments given a successful software compromise
    D. Code context for instances of unsafe typecasting operations

  • Question 299:

    A penetration tester ran a simple Python-based scanner. The following is a snippet of the code:

    Which of the following BEST describes why this script triggered a `probable port scan` alert in the organization's IDS?

    A. sock.settimeout(20) on line 7 caused each next socket to be created every 20 milliseconds.
    B. *range(1, 1025) on line 1 populated the portList list in numerical order.
    C. Line 6 uses socket.SOCK_STREAM instead of socket.SOCK_DGRAM
    D. The remoteSvr variable has neither been type-hinted nor initialized.

  • Question 300:

    Which of the following provides an exploitation suite with payload modules that cover the broadest range of target system types?

    A. Nessus
    B. Metasploit
    C. Burp Suite
    D. Ethercap

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.