PT0-003 Exam Details

  • Exam Code
    :PT0-003
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :404 Q&As
  • Last Updated
    :Jun 09, 2026

CompTIA PT0-003 Online Questions & Answers

  • Question 101:

    During a penetration testing exercise, a team decides to use a watering hole strategy.

    Which of the following is the most effective approach for executing this attack?

    A. Compromise a website frequently visited by the organization's employees.
    B. Launch a DDoS attack on the organization's website.
    C. Create fake social media profiles to befriend employees.
    D. Send phishing emails to the organization's employees.

  • Question 102:

    DRAG DROP

    Instructions:

    Analyze the code segments to determine which sections are needed to complete a port scanning script. Drag the appropriate elements into the correct locations to complete the script.

    If at any time you would like to bring back the initial state of the simulation, please click the reset all button.

    During a penetration test, you gain access to a system with a limited user interface. This machine appears to have access to an isolated network that you would like to port scan.

    Select and Place:

    drag and drop.jpg

  • Question 103:

    A penetration tester is evaluating a company's network perimeter. The tester has received limited information about defensive controls or countermeasures, and limited internal knowledge of the testing exists.

    Which of the following should be the FIRST step to plan the reconnaissance activities?

    A. Launch an external scan of netblocks.
    B. Check WHOIS and netblock records for the company.
    C. Use DNS lookups and dig to determine the external hosts.
    D. Conduct a ping sweep of the company's netblocks.

  • Question 104:

    Which of the following is a term used to describe a situation in which a penetration tester bypasses physical access controls and gains access to a facility by entering at the same time as an employee?

    A. Badge cloning
    B. Shoulder surfing
    C. Tailgating
    D. Site survey

  • Question 105:

    Which of the following post-exploitation activities allows a penetration tester to maintain persistent access in a compromised system?

    A. Creating registry keys
    B. Installing a bind shell
    C. Executing a process injection
    D. Setting up a reverse SSH connection

  • Question 106:

    A penetration tester gained a foothold within a network. The penetration tester needs to enumerate all users within the domain.

    Which of the following is the best way to accomplish this task?

    A. pwd.exe
    B. net.exe
    C. sc.exe
    D. msconfig.exe

  • Question 107:

    A tester completed a report for a new client.

    Prior to sharing the report with the client, which of the following should the tester request to complete a review?

    A. A generative AI assistant
    B. The customer's designated contact
    C. A cybersecurity industry peer
    D. A team member

  • Question 108:

    A penetration tester wants to analyze an organization's Active Directory environment to determine how a low-privileged user account could pivot through group and system relationships to eventually reach a high-value target. The tester needs a tool that can enumerate AD objects, map trust relationships, and visually model potential privilege escalation paths.

    Which of the following tools would BEST meet this objective?

    A. Responder
    B. Mimikatz
    C. Hydra
    D. BloodHound
    E. TruffleHog

  • Question 109:

    A penetration tester gains access to a host but does not have access to any type of shell.

    Which of the following is the best way for the tester to further enumerate the host and the environment in which it resides?

    A. ProxyChains
    B. Netcat
    C. PowerShell ISE
    D. Process IDs

  • Question 110:

    Which of the following authorizations is mandatory when a penetration tester is involved in a complex IT infrastructure?

    A. Customer authorization
    B. Penetration tester authorization
    C. Third-party authorization
    D. Internal team authorization

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.