PT0-002 Exam Details

  • Exam Code
    :PT0-002
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :455 Q&As
  • Last Updated
    :May 31, 2026

CompTIA PT0-002 Online Questions & Answers

  • Question 371:

    A penetration tester analyzed a web-application log file and discovered an input that was sent to the company's web application. The input contains a string that says "WAITFOR."

    Which of the following attacks is being attempted?

    A. SQL injection
    B. HTML injection
    C. Remote command injection
    D. DLL injection

  • Question 372:

    HOTSPOT

    You are a security analyst tasked with hardening a web server.

    You have been given a list of HTTP payloads that were flagged as malicious.

    INSTRUCTIONS

    Given the following attack signatures, determine the attack type, and then identify the associated remediation to prevent the attack in the future.

    If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

  • Question 373:

    A penetration tester has obtained shell access to a Windows host and wants to run a specially crafted binary for later execution using the wmic.exe process call create function. Which of the following OS or filesystem mechanisms is MOST likely to support this objective?

    A. Alternate data streams
    B. PowerShell modules
    C. MP4 steganography
    D. PsExec

  • Question 374:

    During an assessment, a penetration tester manages to exploit an LFI vulnerability and browse the web log for a target Apache server. Which of the following steps would the penetration tester most likely try NEXT to further exploit the web server? (Choose two.)

    A. Cross-site scripting
    B. Server-side request forgery
    C. SQL injection
    D. Log poisoning
    E. Cross-site request forgery
    F. Command injection

  • Question 375:

    Which of the following documents describes specific activities, deliverables, and schedules for a penetration tester?

    A. NDA
    B. MSA
    C. SOW
    D. MOU

  • Question 376:

    During an assessment, a penetration tester gathered OSINT for one of the IT systems administrators from the target company and managed to obtain valuable information, including corporate email addresses. Which of the following techniques should the penetration tester perform NEXT?

    A. Badge cloning
    B. Watering-hole attack
    C. Impersonation
    D. Spear phishing

  • Question 377:

    A company obtained permission for a vulnerability scan from its cloud service provider and now wants to test the security of its hosted data. Which of the following should the tester verify FIRST to assess this risk?

    A. Whether sensitive client data is publicly accessible
    B. Whether the connection between the cloud and the client is secure
    C. Whether the client's employees are trained properly to use the platform
    D. Whether the cloud applications were developed using a secure SDLC

  • Question 378:

    Which of the following concepts defines the specific set of steps and approaches that are conducted during a penetration test?

    A. Scope details
    B. Findings
    C. Methodology
    D. Statement of work

  • Question 379:

    A penetration tester has found indicators that a privileged user's password might be the same on 30 different Linux systems.

    Which of the following tools can help the tester identify the number of systems on which the password can be used?

    A. Hydra
    B. John the Ripper
    C. Cain and Abel
    D. Medusa

  • Question 380:

    Penetration tester has discovered an unknown Linux 64-bit executable binary. Which of the following tools would be BEST to use to analyze this issue?

    A. Peach
    B. WinDbg
    C. GDB
    D. OllyDbg

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.