PT0-002 Exam Details

  • Exam Code
    :PT0-002
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :455 Q&As
  • Last Updated
    :May 31, 2026

CompTIA PT0-002 Online Questions & Answers

  • Question 391:

    A penetration tester is able to use a command injection vulnerability in a web application to get a reverse shell on a system After running a few commands, the tester runs the following:

    python -c 'import pty; pty.spawn("/bin/bash")'

    Which of the following actions Is the penetration tester performing?

    A. Privilege escalation
    B. Upgrading the shell
    C. Writing a script for persistence
    D. Building a bind shell

  • Question 392:

    Which of the following should a penetration tester do NEXT after identifying that an application being tested has already been compromised with malware?

    A. Analyze the malware to see what it does.
    B. Collect the proper evidence and then remove the malware.
    C. Do a root-cause analysis to find out how the malware got in.
    D. Remove the malware immediately.
    E. Stop the assessment and inform the emergency contact.

  • Question 393:

    Which section of a penetration testing report provides a high-level overview of findings, focusing on critical issues and their impact, and is intended for non-technical stakeholders?

    A. Executive summary
    B. Testing scope
    C. Statement of work
    D. Technical report

  • Question 394:

    A penetration tester utilized Nmap to scan host 64.13.134.52 and received the following results:

    Based on the output, which of the following services are MOST likely to be exploited? (Choose two.)

    A. Telnet
    B. HTTP
    C. SMTP
    D. DNS
    E. NTP
    F. SNMP

  • Question 395:

    A penetration tester is performing an assessment for an organization and must gather valid user credentials. Which of the following attacks would be best for the tester to use to achieve this objective?

    A. Wardriving
    B. Captive portal
    C. Deauthentication
    D. Impersonation

  • Question 396:

    Which of the following documents would be the most helpful in determining who is at fault for a temporary outage that occurred during a penetration test?

    A. Non-disclosure agreement
    B. Business associate agreement
    C. Assessment scope and methodologies
    D. Executive summary

  • Question 397:

    A penetration tester has prepared the following phishing email for an upcoming penetration test:

    Which of the following is the penetration tester using MOST to influence phishing targets to click on the link?

    A. Familiarity and likeness
    B. Authority and urgency
    C. Scarcity and fear
    D. Social proof and greed

  • Question 398:

    A company becomes concerned when the security alarms are triggered during a penetration test. Which of the following should the company do NEXT?

    A. Halt the penetration test.
    B. Contact law enforcement.
    C. Deconflict with the penetration tester.
    D. Assume the alert is from the penetration test.

  • Question 399:

    During an assessment, a penetration tester needs to perform a cloud asset discovery of an organization.

    Which of the following tools would most likely provide more accurate results in this situation?

    A. Pacu
    B. Scout Suite
    C. Shodan
    D. TruffleHog

  • Question 400:

    Which of the following tools is specifically designed for detecting and exploiting SQL injection vulnerabilities in a database server penetration test?

    A. Burp Suite
    B. Nessus
    C. Nikto
    D. SQLmap

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.