PT0-003 Exam Details

  • Exam Code
    :PT0-003
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :404 Q&As
  • Last Updated
    :Jun 09, 2026

CompTIA PT0-003 Online Questions & Answers

  • Question 141:

    A penetration tester, who is doing an assessment, discovers an administrator has been exfiltrating proprietary company information. The administrator offers to pay the tester to keep quiet.

    Which of the following is the BEST action for the tester to take?

    A. Check the scoping document to determine if exfiltration is within scope.
    B. Stop the penetration test.
    C. Escalate the issue.
    D. Include the discovery and interaction in the daily report.

  • Question 142:

    During an assessment, a penetration tester runs the following command from a Linux machine:

    GetUsersSPNs.py -dc-ip 172.16.1.1 DOMAIN.LOCAL/aholliday -request

    Which of the following is the penetration tester trying to do?

    A. Crack the user password for aholliday
    B. Download all TGS tickets for offline processing
    C. Perform a pass-the-hash attack using the hash for aholliday
    D. Perform password spraying

  • Question 143:

    A penetration tester is able to capture the NTLM challenge-response traffic between a client and a server.

    Which of the following can be done with the pcap to gain access to the server?

    A. Perform vertical privilege escalation.
    B. Replay the captured traffic to the server to recreate the session.
    C. Use John the Ripper to crack the password.
    D. Utilize a pass-the-hash attack.

  • Question 144:

    During an assessment, a penetration tester wants to extend the vulnerability search to include the use of dynamic testing.

    Which of the following tools should the tester use?

    A. Mimikatz
    B. ZAP
    C. OllyDbg
    D. SonarQube

  • Question 145:

    A penetration tester exploited a unique flaw on a recent penetration test of a bank. After the test was completed, the tester posted information about the exploit online along with the IP addresses of the exploited machines.

    Which of the following documents could hold the penetration tester accountable for this action?

    A. ROE
    B. SLA
    C. MSA
    D. NDA

  • Question 146:

    A penetration tester is trying to get unauthorized access to a web application and executes the following command:

    GET /foo/images/file?

    id=2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fetc%2fpasswd Which of the following web application attacks is the tester performing?

    A. Insecure Direct Object Reference
    B. Cross-Site Request Forgery
    C. Directory Traversal
    D. Local File Inclusion

  • Question 147:

    A penetration tester is conducting an assessment on 192.168.1.112. Given the following output:

    Which of the following is the penetration tester conducting?

    A. Port scan
    B. Brute force
    C. Credential stuffing
    D. DoS attack

  • Question 148:

    During an assessment, a penetration tester runs the following command:

    dnscmd.exe /config /serverlevelplugindll C:\Users\necad-TA\Documents\adduser.dll

    Which of the following is the penetration tester trying to achieve?

    A. DNS enumeration
    B. Privilege escalation
    C. Command injection
    D. A list of available users

  • Question 149:

    A penetration tester assesses a complex web application and wants to explore potential security weaknesses by searching for subdomains that might have existed in the past.

    Which of the following tools should the penetration tester use?

    A. Censys.io
    B. Shodan
    C. Wayback Machine
    D. SpiderFoot

  • Question 150:

    A penetration tester gains access to a Windows machine and wants to further enumerate users with native operating system credentials.

    Which of the following should the tester use?

    A. route.exe print
    B. netstat.exe -ntp
    C. net.exe commands
    D. strings.exe -a

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.