PT0-003 Exam Details

  • Exam Code
    :PT0-003
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :404 Q&As
  • Last Updated
    :Jun 09, 2026

CompTIA PT0-003 Online Questions & Answers

  • Question 131:

    During an engagement, a penetration tester discovers a web application vulnerability that affects multiple devices. The tester creates and runs the following script:

    #!/bin/sh

    for addr in $(cat targets)

    do

    curl http://$addr//atod.php?execf=echo%20%22ssh-ed25519%20AAAC3NzaC1lZDI1NTE5AAAA...

    %22%20%3E%3E%20/root/authorized_users done Which of the following best describes what the tester is attempting to do?

    A. Staging payloads to make bind shells
    B. Creating a backdoor on several weak targets
    C. Adding a password for the root user on the targets
    D. Generating SSH keys to decrypt data on each target

  • Question 132:

    A penetration tester who is performing a physical assessment of a company's security practices notices the company does not have any shredders inside the office building.

    Which of the following techniques would be BEST to use to gain confidential information?

    A. Badge cloning
    B. Dumpster diving
    C. Tailgating
    D. Shoulder surfing

  • Question 133:

    A tester performs a vulnerability scan and identifies several outdated libraries used within the customer SaaS product offering.

    Which of the following types of scans did the tester use to identify the libraries?

    A. IAST
    B. SBOM
    C. DAST
    D. SAST

  • Question 134:

    While performing a penetration testing exercise, a tester executes the following command:

    bash

    Copy code

    PS c:\tools> c:\hacks\PsExec.exe \\server01.

    comptia.org -accepteula cmd.exe Which of the following best explains what the tester is trying to do?

    A. Test connectivity using PSExec on the server01 using CMD.exe.
    B. Perform a lateral movement attack using PsExec.
    C. Send the PsExec binary file to the server01 using CMD.exe.
    D. Enable CMD.exe on the server01 through PsExec.

  • Question 135:

    A penetration tester has been hired to examine a website for flaws. During one of the time windows for testing, a network engineer notices a flood of GET requests to the web server, reducing the website's response time by 80%. The network engineer contacts the penetration tester to determine if these GET requests are part of the test.

    Which of the following BEST describes the purpose of checking with the penetration tester?

    A. Situational awareness
    B. Rescheduling
    C. DDoS defense
    D. Deconfliction

  • Question 136:

    During a security assessment, a penetration tester needs to exploit a vulnerability in a wireless network's authentication mechanism to gain unauthorized access to the network.

    Which of the following attacks would the tester most likely perform to gain access?

    A. KARMA attack
    B. Beacon flooding
    C. MAC address spoofing
    D. Eavesdropping

  • Question 137:

    A penetration tester launches an attack against company employees. The tester clones the company's intranet log-in page and sends the link via email to all employees.

    Which of the following best describes the objective and tool selected by the tester to perform this activity?

    A. Gaining remote access using BeEF
    B. Obtaining the list of email addresses using theHarvester
    C. Harvesting credentials using SET
    D. Launching a phishing campaign using Gophish

  • Question 138:

    As part of an engagement, a penetration tester wants to maintain access to a compromised system after rebooting.

    Which of the following techniques would be best for the tester to use?

    A. Establishing a reverse shell
    B. Executing a process injection attack
    C. Creating a scheduled task
    D. Performing a credential-dumping attack

  • Question 139:

    Which of the following documents describes specific activities, deliverables, and schedules for a penetration tester?

    A. NDA
    B. MSA
    C. SOW
    D. MOU

  • Question 140:

    Which of the following best explains why communication is a vital phase of a penetration test?

    A. To discuss situational awareness
    B. To build rapport with the emergency contact
    C. To explain the data destruction process
    D. To ensure the likelihood of future assessments

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.