PT0-003 Exam Details

  • Exam Code
    :PT0-003
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :404 Q&As
  • Last Updated
    :Jun 01, 2026

CompTIA PT0-003 Online Questions & Answers

  • Question 11:

    During a security assessment, a penetration tester gains access to an internal server and manipulates some data to hide its presence.

    Which of the following is the best way for the penetration tester to hide the activities performed?

    A. Clear the Windows event logs.
    B. Modify the system time.
    C. Alter the log permissions.
    D. Reduce the log retention settings.

  • Question 12:

    A penetration tester has been given an assignment to attack a series of targets in the 192.168.1.0/24 range, triggering as few alarms and countermeasures as possible.

    Which of the following Nmap scan syntaxes would BEST accomplish this objective?

    A. nmap -sT -vvv -O 192.168.1.2/24 -PO
    B. nmap -sV 192.168.1.2/24 -PO
    C. nmap -sA -v -O 192.168.1.2/24
    D. nmap -sS -O 192.168.1.2/24 -T1

  • Question 13:

    During the reconnaissance phase, a penetration tester collected the following information from the DNS records:

    A-----> www

    A-----> host

    TXT --> vpn.comptia.org

    SPF---> ip =2.2.2.2

    Which of the following DNS records should be in place to avoid phishing attacks using spoofing domain techniques?

    A. MX
    B. SOA
    C. DMARC
    D. CNAME

  • Question 14:

    A penetration tester needs to complete cleanup activities from the testing lead.

    Which of the following should the tester do to validate that reverse shell payloads are no longer running?

    A. Run scripts to terminate the implant on affected hosts.
    B. Spin down the C2 listeners.
    C. Restore the firewall settings of the original affected hosts.
    D. Exit from C2 listener active sessions.

  • Question 15:

    A penetration tester is testing a new version of a mobile application in a sandbox environment. To intercept and decrypt the traffic between the application and the external API, the tester has created a private root CA and issued a certificate from it. Even though the tester installed the root CA into the trusted stone of the smartphone used for the tests, the application shows an error indicating a certificate mismatch and does not connect to the server.

    Which of the following is the MOST likely reason for the error?

    A. TCP port 443 is not open on the firewall
    B. The API server is using SSL instead of TLS
    C. The tester is using an outdated version of the application
    D. The application has the API certificate pinned.

  • Question 16:

    During an assessment, a penetration tester gains access to one of the internal hosts. Given the following command:

    schtasks /create /sc onlogon /tn "Windows Update" /tr "cmd.exe /c reverse_shell.exe"

    Which of the following is the penetration tester trying to do with this code?

    A. Enumerate the scheduled tasks
    B. Establish persistence
    C. Deactivate the Windows Update functionality
    D. Create a binary application for Windows System Updates

  • Question 17:

    A penetration tester gains shell access to a Windows host. The tester needs to permanently turn off protections in order to install additional payload.

    Which of the following commands is most appropriate?

    A. sc config <svc_name> start=disabled
    B. sc query state= all
    C. pskill <pid_svc_name>
    D. net config <svc_name>

  • Question 18:

    A penetration tester ran a simple Python-based scanner. The following is a snippet of the code:

    Which of the following BEST describes why this script triggered a `probable port scan` alert in the organization's IDS?

    A. sock.settimeout(20) on line 7 caused each next socket to be created every 20 milliseconds.
    B. *range(1, 1025) on line 1 populated the portList list in numerical order.
    C. Line 6 uses socket.SOCK_STREAM instead of socket.SOCK_DGRAM
    D. The remoteSvr variable has neither been type-hinted nor initialized.

  • Question 19:

    A penetration tester needs to obtain sensitive data from several executives who regularly work while commuting by train.

    Which of the following methods should the tester use for this task?

    A. Shoulder surfing
    B. Credential harvesting
    C. Bluetooth spamming
    D. MFA fatigue

  • Question 20:

    Which of the following should a penetration tester attack to gain control of the state in the HTTP protocol after the user is logged in?

    A. HTTPS communication
    B. Public and private keys
    C. Password encryption
    D. Sessions and cookies

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.