PT0-002 Exam Details

  • Exam Code
    :PT0-002
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :455 Q&As
  • Last Updated
    :May 31, 2026

CompTIA PT0-002 Online Questions & Answers

  • Question 331:

    Which of the following types of information should be included when writing the remediation section of a penetration test report to be viewed by the systems administrator and technical staff?

    A. A quick description of the vulnerability and a high-level control to fix it
    B. Information regarding the business impact if compromised
    C. The executive summary and information regarding the testing company
    D. The rules of engagement from the assessment

  • Question 332:

    A penetration tester discovered that a client uses cloud mail as the company's email system. During the penetration test, the tester set up a fake cloud mail login page and sent all company employees an email that stated their inboxes were full and directed them to the fake login page to remedy the issue.

    Which of the following BEST describes this attack?

    A. Credential harvesting
    B. Privilege escalation
    C. Password spraying
    D. Domain record abuse

  • Question 333:

    Which of the following describes the reason why a penetration tester would run the command sdelete mimikatz. * on a Windows server that the tester compromised?

    A. To remove hash-cracking registry entries
    B. To remove the tester-created Mimikatz account
    C. To remove tools from the server
    D. To remove a reverse shell from the system

  • Question 334:

    A penetration tester wrote the following script on a compromised system:

    #!/bin/bash

    network='10.100.100'

    ports='22 23 80 443'

    for x in {1 .. 254};

    do (nc -zv $network.$x $ports );

    done

    Which of the following would explain using this script instead of another tool?

    A. The typical tools could not be used against Windows systems.
    B. The configuration required the penetration tester to not utilize additional files.
    C. The Bash script will provide more thorough output.
    D. The penetration tester wanted to persist this script to run on reboot.

  • Question 335:

    A company developed a new web application to allow its customers to submit loan applications. A penetration tester is reviewing the application and discovers that the application was developed in ASP and used MSSQL for its back-end database. Using the application's search form, the penetration tester inputs the following code in the search input field:

    IMG SRC=vbscript:msgbox ("Vulnerable_to_Attack") ; >originalAttribute="SRC"originalPath="vbscript;msgbox ("Vulnerable_to_Attack ") ;>"

    When the tester checks the submit button on the search form, the web browser returns a pop-up windows that displays "Vulnerable_to_Attack." Which of the following vulnerabilities did the tester discover in the web application?

    A. SQL injection
    B. Command injection
    C. Cross-site request forgery
    D. Cross-site scripting

  • Question 336:

    A penetration tester wants to identify CVEs that can be leveraged to gain execution on a Linux server that has an SSHD running. Which of the following would BEST support this task?

    A. Run nmap with the -O, -p22, and -sC options set against the target.
    B. Run nmap with the -sV and -p22 options set against the target.
    C. Run nmap with the --script vulners option set against the target.
    D. Run nmap with the -sA option set against the target.

  • Question 337:

    Penetration tester who was exclusively authorized to conduct a physical assessment noticed there were no cameras pointed at the dumpster for company. The penetration tester returned at night and collected garbage that contained receipts for recently purchased networking :. The models of equipment purchased are vulnerable to attack.

    Which of the following is the most likely next step for the penetration?

    A. Alert the target company of the discovered information.
    B. Verify the discovered information is correct with the manufacturer.
    C. Scan the equipment and verify the findings.
    D. Return to the dumpster for more information.

  • Question 338:

    A red team completed an engagement and provided the following example in the report to describe how the team gained access to a web server:

    x' OR role LIKE '%admin%

    Which of the following should be recommended to remediate this vulnerability?

    A. Multifactor authentication
    B. Encrypted communications
    C. Secure software development life cycle
    D. Parameterized queries

  • Question 339:

    Given the following code:

    Which of the following data structures is systems?

    A. A tuple
    B. A tree
    C. An array
    D. A dictionary

  • Question 340:

    A new security firm is onboarding its first client. The client only allowed testing over the weekend and needed the results Monday morning. However, the assessment team was not able to access the environment as expected until Monday.

    Which of the following should the security company have acquired BEFORE the start of the assessment?

    A. A signed statement of work
    B. The correct user accounts and associated passwords
    C. The expected time frame of the assessment
    D. The proper emergency contacts for the client

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.