PT0-003 Exam Details

  • Exam Code
    :PT0-003
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :404 Q&As
  • Last Updated
    :Jun 09, 2026

CompTIA PT0-003 Online Questions & Answers

  • Question 121:

    Which of the following tools would be BEST suited to perform a manual web application security assessment? (Choose two.)

    A. OWASP ZAP
    B. Nmap
    C. Nessus
    D. BeEF
    E. Hydra
    F. Burp Suite

  • Question 122:

    Which of the following tools would be best suited to perform a cloud security assessment?

    A. OpenVAS
    B. Scout Suite
    C. Nmap
    D. ZAP
    E. Nessus

  • Question 123:

    Which of the following frameworks can be used to classify threats?

    A. PTES
    B. STRIDE
    C. OSSTMM
    D. OCTAVE

  • Question 124:

    A penetration tester would like to collect permission details for objects within the domain. The tester has a valid AD user and access to an internal PC.

    Which of the following sets of steps is the best way for the tester to accomplish the desired outcome?

    A. Escalate privileges. Execute Rubeus. Run a Cypher query on Rubeus to get the results.
    B. Run SharpHound. Install CrackMapExec. Perform a CrackMapExec database query on CME to get the results.
    C. Run SharpHound. Install BloodHound. Perform a Cypher query on BloodHound to get the results.
    D. Escalate privileges. Get Windows Registry data. Perform a query to get results.

  • Question 125:

    openssl passwd password

    $1$OjxLvZ85$Fdr51vn/Z4zXWsQR/Xrj.

    The tester then adds the following line to the world-writable script:

    echo 'root2:$1$0jxLvZ85$Fdr51vn/Z4zXWsQR/Xrj .

    : 1001:1001:,,,:/root:/bin/bash">> /etc/passwd Which of the following should the penetration tester do to enable this exploit to work correctly?

    A. Use only a single redirect to /etc/password.
    B. Generate the password using md5sum.
    C. Log in to the host using SSH.
    D. Change the 1001 entries to 0.

  • Question 126:

    A penetration tester discovers evidence of an advanced persistent threat on the network that is being tested.

    Which of the following should the tester do next?

    A. Report the finding.
    B. Analyze the finding.
    C. Remove the threat.
    D. Document the finding and continue testing.

  • Question 127:

    SIMULATION

    A previous penetration test report identified a host with vulnerabilities that was successfully exploited. Management has requested that an internal member of the security team reassess the host to determine if the vulnerability still exists.

    Part 1:

    Analyze the output and select the command to exploit the vulnerable service.

    Part 2:

    Analyze the output from each command.

    Select the appropriate set of commands to escalate privileges.

    Identify which remediation steps should be taken.

    A. See explanation below.
    B. PlaceHolder
    C. PlaceHolder
    D. PlaceHolder

  • Question 128:

    During a penetration test, the tester uses a vulnerability scanner to collect information about any possible vulnerabilities that could be used to compromise the network. The tester receives the results and then executes the following command:

    snmpwalk -v 2c -c public 192.168.1.23

    Which of the following is the tester trying to do based on the command they used?

    A. Bypass defensive systems to collect more information.
    B. Use an automation tool to perform the attacks.
    C. Script exploits to gain access to the systems and host.
    D. Validate the results and remove false positives.

  • Question 129:

    A penetration tester completed a vulnerability scan against a web server and identified a single but severe vulnerability.

    Which of the following is the BEST way to ensure this is a true positive?

    A. Run another scanner to compare.
    B. Perform a manual test on the server.
    C. Check the results on the scanner.
    D. Look for the vulnerability online.

  • Question 130:

    A company wants to perform a BAS (Breach and Attack Simu-lation) to measure the efficiency of the corporate security controls.

    Which of the following would most likely help the tester with simple command examples?

    A. Infection Monkey
    B. Exploit-DB
    C. Atomic Red Team
    D. Mimikatz

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.