PT0-003 Exam Details

  • Exam Code
    :PT0-003
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :404 Q&As
  • Last Updated
    :Jun 09, 2026

CompTIA PT0-003 Online Questions & Answers

  • Question 161:

    A company requires that all hypervisors have the latest available patches installed.

    Which of the following would BEST explain the reason why this policy is in place?

    A. To provide protection against host OS vulnerabilities
    B. To reduce the probability of a VM escape attack
    C. To fix any misconfigurations of the hypervisor
    D. To enable all features of the hypervisor

  • Question 162:

    A penetration tester has found a web application that is running on a cloud virtual machine instance.

    Vulnerability scans show a potential SSRF for the same application URL path with an injectable parameter.

    Which of the following commands should the tester run to successfully test for secrets exposure exploitability?

    A. curl <url>?param=http://169.254.169.254/latest/meta-data/
    B. curl '<url>?param=http://127.0.0.1/etc/passwd'
    C. curl '<url>?param=<script>alert(1)<script>/'
    D. curl <url>?param=http://127.0.0.1/

  • Question 163:

    During a penetration testing engagement, a tester targets the internet-facing services used by the client.

    Which of the following describes the type of assessment that should be considered in this scope of work?

    A. Segmentation
    B. Mobile
    C. External
    D. Web

  • Question 164:

    A penetration tester is testing input validation on a search form that was discovered on a website.

    Which of the following characters is the BEST option to test the website for vulnerabilities?

    A. Comma
    B. Double dash
    C. Single quote
    D. Semicolon

  • Question 165:

    While conducting a reconnaissance activity, a penetration tester extracts the following information:

    Emails: - [email protected] - [email protected] - [email protected]

    Which of the following risks should the tester use to leverage an attack as the next step in the security assessment?

    A. Unauthorized access to the network
    B. Exposure of sensitive servers to the internet
    C. Likelihood of SQL injection attacks
    D. Indication of a data breach in the company

  • Question 166:

    A company has recruited a penetration tester to conduct a vulnerability scan over the network. The test is confirmed to be on a known environment.

    Which of the following would be the BEST option to identify a system properly prior to performing the assessment?

    A. Asset inventory
    B. DNS records
    C. Web-application scan
    D. Full scan

  • Question 167:

    A penetration tester was hired to test Wi-Fi equipment.

    Which of the following tools should be used to gather information about the wireless network?

    A. Kismet
    B. Burp Suite
    C. BeEF
    D. WHOIS

  • Question 168:

    During an assessment, a penetration tester plans to gather metadata from various online files, including pictures.

    Which of the following standards outlines the formats for pictures, audio, and additional tags that facilitate this type of reconnaissance?

    A. EXIF
    B. GIF
    C. COFF
    D. ELF

  • Question 169:

    A penetration tester finds it is possible to downgrade a web application's HTTPS connections to HTTP while performing on-path attacks on the local network. The tester reviews the output of the server response to:

    curl -s -i https://internalapp/HTTP/2 302

    date: Thu, 11 Jan 2024 15:56:24 GMT

    content-type: text/html; charset=iso-8659-1

    location: /login

    x-content-type-options: nosniff

    server: Prod

    Which of the following recommendations should the penetration tester include in the report?

    A. Add the HSTS header to the server.
    B. Attach the httponly flag to cookies.
    C. Front the web application with a firewall rule to block access to port 80.
    D. Remove the x-content-type-options header.

  • Question 170:

    A penetration tester has identified several newly released CVEs on a VoIP call manager. The scanning tool the tester used determined the possible presence of the CVEs based off the version number of the service.

    Which of the following methods would BEST support validation of the possible findings?

    A. Manually check the version number of the VoIP service against the CVE release
    B. Test with proof-of-concept code from an exploit database
    C. Review SIP traffic from an on-path position to look for indicators of compromise
    D. Utilize an nmap -sV scan against the service

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.