PT0-002 Exam Details

  • Exam Code
    :PT0-002
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :455 Q&As
  • Last Updated
    :May 31, 2026

CompTIA PT0-002 Online Questions & Answers

  • Question 81:

    A consultant is reviewing the following output after reports of intermittent connectivity issues:

    (192.168.1.1) at 0a:d1:fa:b1:01:67 on en0 ifscope [ethernet]

    (192.168.1.12) at 34:a4:be:09:44:f4 on en0 ifscope [ethernet]

    (192.168.1.17) at 92:60:29:12:ac:d2 on en0 ifscope [ethernet]

    (192.168.1.34) at 88:de:a9:12:ce:fb on en0 ifscope [ethernet]

    (192.168.1.136) at 0a:d1:fa:b1:01:67 on en0 ifscope [ethernet]

    (192.168.1.255) at ff:ff:ff:ff:ff:ff on en0 ifscope [ethernet]

    (224.0.0.251) at 01:02:5e:7f:ff:fa on en0 ifscope permanent [ethernet]

    (239.255.255.250)

    at ff:ff:ff:ff:ff:ff on en0 ifscope permanent [ethernet] Which of the following is MOST likely to be reported by the consultant?

    A. A device on the network has an IP address in the wrong subnet.
    B. A multicast session was initiated using the wrong multicast group.
    C. An ARP flooding attack is using the broadcast address to perform DDoS.
    D. A device on the network has poisoned the ARP cache.

  • Question 82:

    After running the enum4linux.pl command, a penetration tester received the following output: Which of the following commands should the penetration tester run NEXT?

    A. smbspool //192.160.100.56/print$
    B. net rpc share -S 192.168.100.56 -U ''
    C. smbget //192.168.100.56/web -U ''
    D. smbclient //192.168.100.56/web -U '' -N

  • Question 83:

    In the process of active service enumeration, a penetration tester identifies an SMTP daemon running on one of the target company's servers.

    Which of the following actions would BEST enable the tester to perform phishing in a later stage of the assessment?

    A. Test for RFC-defined protocol conformance.
    B. Attempt to brute force authentication to the service.
    C. Perform a reverse DNS query and match to the service banner.
    D. Check for an open relay configuration.

  • Question 84:

    The output from a penetration testing tool shows 100 hosts contained findings due to improper patch management. Which of the following did the penetration tester perform?

    A. A vulnerability scan
    B. A WHOIS lookup
    C. A packet capture
    D. An Nmap scan

  • Question 85:

    A penetration tester needs to perform a test on a finance system that is PCI DSS v3.2.1 compliant. Which of the following is the MINIMUM frequency to complete the scan of the system?

    A. Weekly
    B. Monthly
    C. Quarterly
    D. Annually

  • Question 86:

    A penetration tester was conducting a penetration test and discovered the network traffic was no longer reaching the client's IP address. The tester later discovered the SOC had used sinkholing on the penetration tester's IP address. Which of the following BEST describes what happened?

    A. The penetration tester was testing the wrong assets
    B. The planning process failed to ensure all teams were notified
    C. The client was not ready for the assessment to start
    D. The penetration tester had incorrect contact information

  • Question 87:

    Which of the following expressions in Python increase a variable val by one (Choose two.)

    A. val++
    B. +val
    C. val=(val+1)
    D. ++val
    E. val=val++
    F. val+=1

  • Question 88:

    HOTSPOT

    A penetration tester is performing reconnaissance for a web application assessment. Upon investigation, the tester reviews the robots.txt file for items of interest.

    INSTRUCTIONS

    Select the tool the penetration tester should use for further investigation.

    Select the two entries in the robots.txt file that the penetration tester should recommend for removal.

    If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

  • Question 89:

    In Python socket programming, SOCK_DGRAM type is:

    A. reliable.
    B. matrixed.
    C. connectionless.
    D. slower.

  • Question 90:

    The results of an Nmap scan are as follows:

    Starting Nmap 7.80 ( https://nmap.org ) at 2021-01-24 01:10 EST

    Nmap scan report for ( 10.2.1.22 )

    Host is up (0.0102s latency).

    Not shown: 998 filtered ports

    Port State Service

    80/tcp open http

    |_http-title: 80F 22% RH 1009.1MB (text/html)

    |_http-slowloris-check:

    | VULNERABLE:

    | Slowloris DoS Attack

    | <..>

    Device type: bridge|general purpose

    Running (JUST GUESSING) : QEMU (95%)

    OS CPE: cpe:/a:qemu:qemu

    No exact OS matches found for host (test conditions non-ideal).

    OS detection performed. Please report any incorrect results at https://nmap.org/submit/.

    Nmap done: 1 IP address (1 host up) scanned in 107.45 seconds

    Which of the following device types will MOST likely have a similar response? (Choose two.)

    A. Network device
    B. Public-facing web server
    C. Active Directory domain controller
    D. IoT/embedded device
    E. Exposed RDP
    F. Print queue

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-002 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.