PT0-003 Exam Details

  • Exam Code
    :PT0-003
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :404 Q&As
  • Last Updated
    :Jun 01, 2026

CompTIA PT0-003 Online Questions & Answers

  • Question 1:

    SIMULATION

    A penetration tester has been provided with only the public domain name and must enumerate additional information for the public-facing assets.

    INSTRUCTIONS

    Select the appropriate answer(s), given the output from each section.

  • Question 2:

    During a pre-engagement activity with a new customer, a penetration tester looks for assets to test.

    Which of the following is an example of a target that can be used for testing?

    A. API
    B. HTTP
    C. IPA
    D. ICMP

  • Question 3:

    A penetration tester identifies the URL for an internal administration application while following DevOps team members on their commutes.

    Which of the following attacks did the penetration tester most likely use?

    A. Shoulder surfing
    B. Dumpster diving
    C. Spear phishing
    D. Tailgating

  • Question 4:

    A penetration tester conducts OSINT for a client and discovers the robots.txt file explicitly blocks a major search engine.

    Which of the following would most likely help the penetration tester achieve the objective?

    A. Modifying the WAF
    B. Utilizing a CSRF attack
    C. Changing the robots.txt file
    D. Leveraging a competing provider

  • Question 5:

    A penetration tester wants to check the security awareness of specific workers in the company with targeted attacks.

    Which of the following attacks should the penetration tester perform?

    A. Phishing
    B. Tailgating
    C. Whaling
    D. Spear phishing

  • Question 6:

    Given the following statements:

    1. Implement a web application firewall.

    2. Upgrade end-of-life operating systems.

    Implement a secure software development life cycle.

    In which of the following sections of a penetration test report would the above statements be found?

    A. Executive summary
    B. Attack narrative
    C. Detailed findings
    D. Recommendations

  • Question 7:

    A penetration tester is authorized to perform a DoS attack against a host on a network.

    Given the following input:

    ip = IP("192.168.50.2")

    tcp = TCP(sport=RandShort(), dport=80, flags="S")

    raw = RAW(b"X"*1024)

    p = ip/tcp/raw

    send(p, loop=1, verbose=0)

    Which of the following attack types is most likely being used in the test?

    A. MDK4
    B. Smurf attack
    C. FragAttack
    D. SYN flood

  • Question 8:

    A penetration tester exports the following CSV data from a scanner. The tester wants to parse the data using Bash and input it into another tool.

    CSV data before parsing:

    cat data.csv

    Host, IP, Username, Password

    WINS212, 10.111.41.74, admin, Spring11

    HRDB, 10.13.9.212, hradmin, HRForTheWin

    WAS01, 192.168.23.13, admin, Snowfall97

    Intended output:

    admin Spring11

    hradmin HRForTheWin

    admin Snowfall97

    Which of the following will provide the intended output?

    A. cat data.csv | grep -v "IP" | cut -d"," -f 3,4 | sed -e 's/,/ /'
    B. cat data.csv | find . -iname Username,Password
    C. cat data.csv | grep 'username|Password'
    D. cat data.csv | grep -i "admin" | grep -v "WINS212\|HRDB\|WAS01\|10.111.41.74\|10.13.9.212\| 192.168.23.13"

  • Question 9:

    A penetration tester wants to create a malicious QR code to assist with a physical security assessment.

    Which of the following tools has the built-in functionality most likely needed for this task?

    A. BeEF
    B. John the Ripper
    C. ZAP
    D. Evilginx

  • Question 10:

    During an internal penetration test, the tester uses the following command:

    C:\> Invoke-mimikatz.ps1 "kerberos::golden /domain:test.local /sid:S-1-5-21-3234... /target:dc01.test.local /

    service:CIFS /rc4:237749d82...

    /user:support /ptt" Which of the following best describes the tester's goal when executing this command?

    A. Bypassing normal authentication
    B. Enumerating shares
    C. Obtaining current user credentials
    D. Using password spraying

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.