PT0-002 Exam Details

  • Exam Code
    :PT0-002
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :455 Q&As
  • Last Updated
    :May 31, 2026

CompTIA PT0-002 Online Questions & Answers

  • Question 301:

    A penetration tester is attempting to get more people from a target company to download and run an executable.

    Which of the following would be the MOST effective way for the tester to achieve this objective?

    A. Dropping USB flash drives around the company campus with the file on it
    B. Attaching the file in a phishing SMS that warns users to execute the file or they will be locked out of their accounts
    C. Sending a pretext email from the IT department before sending the download instructions later
    D. Saving the file in a common folder with a name that encourages people to click it

  • Question 302:

    A penetration tester gives the following command to a systems administrator to execute on one of the target servers:

    rm -f /var/www/html/G679h32gYu.php

    Which of the following BEST explains why the penetration tester wants this command executed?

    A. To trick the systems administrator into installing a rootkit
    B. To close down a reverse shell
    C. To remove a web shell after the penetration test
    D. To delete credentials the tester created

  • Question 303:

    A penetration tester would like to crack a hash using a list of hashes and a predefined set of rules. The tester runs the following command:

    hashcat.exe -a 0 .\hash.txt .\rockyou.txt -r .\rules\replace.rule

    Which of the following is the penetration tester using to crack the hash?

    A. Hybrid attack
    B. Dictionary
    C. Rainbow table
    D. Brute-force method

  • Question 304:

    An assessor wants to use Nmap to help map out a stateful firewall rule set.

    Which of the following scans will the assessor MOST likely run?

    A. nmap 192.168.0.1/24
    B. nmap 192.168.0.1/24
    C. nmap oG 192.168.0.1/24
    D. nmap 192.168.0.1/24

  • Question 305:

    A penetration tester exploited a vulnerability on a server and remotely ran a payload to gain a shell. However, a connection was not established, and no errors were shown on the payload execution. The penetration tester suspected that a network device, like an IPS or next-generation firewall, was dropping the connection.

    Which of the following payloads are MOST likely to establish a shell successfully?

    A. windows/x64/meterpreter/reverse_tcp
    B. windows/x64/meterpreter/reverse_http
    C. windows/x64/shell_reverse_tcp
    D. windows/x64/powershell_reverse_tcp
    E. windows/x64/meterpreter/reverse_https

  • Question 306:

    A penetration tester executes the following Nmap command and obtains the following output:

    Which of the following commands would best help the penetration tester discover an exploitable service?

    A. nmap -v -p 25 -- soript smtp-enum-users remotehost
    B. nmap -v -- script=mysql-info.nse remotehost
    C. nmap --ocript=omb-brute.noe remotehoat
    D. nmap -p 3306 -- script "http*vuln*" remotehost

  • Question 307:

    A penetration tester is conducting an assessment on 192.168.1.112. Given the following output:

    Which of the following is the penetration tester conducting?

    A. Port scan
    B. Brute force
    C. Credential stuffing
    D. DoS attack

  • Question 308:

    Which of the following tools would be best to use to conceal data in various kinds of image files?

    A. Kismet
    B. Snow
    C. Responder
    D. Metasploit

  • Question 309:

    Which of the following describes how a penetration tester could prioritize findings in a report?

    A. Business mission and goals
    B. Cyberassets
    C. Network infrastructure
    D. Cyberthreats

  • Question 310:

    A penetration tester discovers passwords in a publicly available data breach during the reconnaissance phase of the penetration test.

    Which of the following is the best action for the tester to take?

    A. Add thepasswords to an appendix in the penetration test report.
    B. Do nothing. Using passwords from breached data is unethical.
    C. Contactthe client and inform them of the breach.
    D. Use thepasswords in a credential stuffing attack when the external penetration test begins.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.