PT0-003 Exam Details

  • Exam Code
    :PT0-003
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :404 Q&As
  • Last Updated
    :Jun 09, 2026

CompTIA PT0-003 Online Questions & Answers

  • Question 151:

    A penetration tester established an initial compromise on a host. The tester wants to pivot to other targets and set up an appropriate relay. The tester needs to enumerate through the compromised host as a relay from the tester's machine.

    Which of the following commands should the tester use to do this task from the tester's host?

    A. attacker_host$ nmap -sT <target_cidr> | nc -n <compromised_host> 22
    B. attacker_host$ mknod backpipe p attacker_host$ nc -l -p 8000 | 0<backpipe | nc <target_cidr> 80 | tee backpipe
    C. attacker_host$ nc -nlp 8000 | nc -n <target_cidr> attacker_host$ nmap -sT 127.0.0.1
    D. attacker_host$ proxychains nmap -sT <target_cidr>

  • Question 152:

    HOTSPOT

    A penetration tester is performing reconnaissance for a web application assessment. Upon investigation, the tester reviews the robots.txt file for items of interest.

    INSTRUCTIONS

    Select the tool the penetration tester should use for further investigation.

    Select the two entries in the robots.txt file that the penetration tester should recommend for removal.

    If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

  • Question 153:

    Which of the following tools would be best to use to conceal data in various kinds of image files?

    A. Kismet
    B. Snow
    C. Responder
    D. Metasploit

  • Question 154:

    A penetration tester has been asked to conduct a blind web application test against a customer's corporate website.

    Which of the following tools would be best suited to perform this assessment?

    A. ZAP
    B. Nmap
    C. Wfuzz
    D. Trufflehog

  • Question 155:

    Which of the following describes a globally accessible knowledge base of adversary tactics and techniques based on real-world observations?

    A. OWASP Top 10
    B. MITRE ATT&CK
    C. Cyber Kill Chain
    D. Well-Architected Framework

  • Question 156:

    While conducting OSINT, a penetration tester discovers the client's administrator posted part of an unsanitized firewall configuration to a troubleshooting message board.

    Which of the following did the penetration tester most likely use?

    A. HTML scraping
    B. Public code repository scanning
    C. Wayback Machine
    D. Search engine enumeration

  • Question 157:

    Which of the following techniques is the best way to avoid detection by data loss prevention tools?

    A. Encoding
    B. Compression
    C. Encryption
    D. Obfuscation

  • Question 158:

    A company hired a penetration-testing team to review the cyber-physical systems in a manufacturing plant.

    The team immediately discovered the supervisory systems and PLCs are both connected to the company intranet.

    Which of the following assumptions, if made by the penetration-testing team, is MOST likely to be valid?

    A. PLCs will not act upon commands injected over the network.
    B. Supervisors and controllers are on a separate virtual network by default.
    C. Controllers will not validate the origin of commands.
    D. Supervisory systems will detect a malicious injection of code/commands.

  • Question 159:

    A company that requires minimal disruption to its daily activities needs a penetration tester to perform information gathering around the company's web presence.

    Which of the following would the tester find MOST helpful in the initial information-gathering steps? (Choose two.)

    A. IP addresses and subdomains
    B. Zone transfers
    C. DNS forward and reverse lookups
    D. Internet search engines
    E. Externally facing open ports
    F. Shodan results

  • Question 160:

    Which of the following components of a penetration test report most directly contributes to prioritizing remediations?

    A. Proof of concept
    B. Risk scoring
    C. Attack narrative
    D. Executive summary

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.