PT0-003 Exam Details

  • Exam Code
    :PT0-003
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :404 Q&As
  • Last Updated
    :Jun 09, 2026

CompTIA PT0-003 Online Questions & Answers

  • Question 91:

    A penetration tester performs the following command:

    curl -l -http2 https://www.comptia.org

    Which of the following snippets of output will the tester MOST likely receive?

    A. Option A
    B. Option B
    C. Option C
    D. Option D

  • Question 92:

    A penetration tester must identify vulnerabilities within an ICS (Industrial Control System) that is not connected to the internet or enterprise network.

    Which of the following should the tester utilize to conduct the testing?

    A. Channel scanning
    B. Stealth scans
    C. Source code analysis
    D. Manual assessment

  • Question 93:

    A penetration tester is performing a cloud-based penetration test against a company. Stakeholders have indicated the priority is to see if the tester can get into privileged systems that are not directly accessible from the internet. Given the following scanner information:

    1. Server-side request forgery (SSRF) vulnerability in test.comptia.org

    2. Reflected cross-site scripting (XSS) vulnerability in test2.comptia.org

    3. Publicly accessible storage system named static_comptia_assets

    4. SSH port 22 open to the internet on test3.comptia.org

    5. Open redirect vulnerability in test4.comptia.org

    Which of the following attack paths should the tester prioritize first?

    A. Synchronize all the information from the public bucket and scan it with Trufflehog.
    B. Run Pacu to enumerate permissions and roles within the cloud-based systems.
    C. Perform a full dictionary brute-force attack against the open SSH service using Hydra.
    D. Use the reflected cross-site scripting attack within a phishing campaign to attack administrators.
    E. Leverage the SSRF to gain access to credentials from the metadata service.

  • Question 94:

    A penetration tester must identify hosts without alerting an IPS. The tester has access to a local network segment.

    Which of the following is the most logical action?

    A. Performing reverse DNS lookups
    B. Utilizing Nmap using a ping sweep
    C. Conducting LLMNR poisoning using Responder
    D. Viewing the local routing table on the host

  • Question 95:

    A penetration tester conducts reconnaissance for a client's network and identifies the following system of interest:

    The tester notices numerous open ports on the system of interest.

    Which of the following best describes this system?

    A. A honeypot
    B. A Windows endpoint
    C. A Linux server
    D. An already-compromised system

  • Question 96:

    Which of the following should be included in scope documentation?

    A. Service accounts
    B. Tester experience
    C. Disclaimer
    D. Number of tests

  • Question 97:

    As part of a security audit, a penetration tester finds an internal application that accepts unexpected user inputs, leading to the execution of arbitrary commands.

    Which of the following techniques would the penetration tester most likely use to access the sensitive data?

    A. Logic bomb
    B. SQL injection
    C. Brute-force attack
    D. Cross-site scripting

  • Question 98:

    During an assessment, a penetration tester obtains a list of 30 email addresses by crawling the target company's website and then creates a list of possible usernames based on the email address format.

    Which of the following types of attacks would MOST likely be used to avoid account lockout?

    A. Mask
    B. Rainbow
    C. Dictionary
    D. Password spraying

  • Question 99:

    A penetration tester performs the following scan:

    nmap -sU -p 53,161,162 192.168.1.51

    PORT STATE

    53/udp open|filtered

    161/udp open|filtered

    162/udp open|filtered

    The tester then manually uses snmpwalk against port 161 and receives valid SNMP responses.

    Which of the following best explains the scan result for port 161?

    A. The SNMP daemon delayed its response beyond Nmap's UDP scan timeout.
    B. Nmap marked the port as open|filtered because no response was received.
    C. The scanned host applied rate limiting to its responses to prevent UDP fingerprinting.
    D. The Nmap scan lacked root privileges, which reduced packet inspection accuracy.

  • Question 100:

    During an assessment, a penetration tester runs the following command:

    setspn.exe -Q /

    Which of the following attacks is the penetration tester preparing for?

    A. LDAP injection
    B. Pass-the-hash
    C. Kerberoasting
    D. Dictionary

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.