PT0-003 Exam Details

  • Exam Code
    :PT0-003
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :404 Q&As
  • Last Updated
    :Jun 09, 2026

CompTIA PT0-003 Online Questions & Answers

  • Question 201:

    A penetration tester uses the Intruder tool from the Burp Suite Community Edition while assessing a web application. The tester notices the test is taking too long to complete.

    Which of the following tools can the tester use to accelerate the test and achieve similar results?

    A. TruffleHog
    B. Postman
    C. Wfuzz
    D. WPScan

  • Question 202:

    A penetration tester obtains the following output during an Nmap scan:

    Which of the following should be the next step for the tester?

    A. Search for vulnerabilities on msrpc.
    B. Enumerate shares and search for vulnerabilities on the SMB service.
    C. Execute a brute-force attack against the Remote Desktop Services.
    D. Execute a new Nmap command to search for another port.

  • Question 203:

    SIMULATION

    A penetration tester performs several Nmap scans against the web application for a client.

    INSTRUCTIONS

    Click on the WAF and servers to review the results of the Nmap scans. Then click on each tab to select the appropriate vulnerability and remediation options.

    If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

    A. See explanation below.
    B. PlaceHolder
    C. PlaceHolder
    D. PlaceHolder

  • Question 204:

    Which of the following tasks would ensure the key outputs from a penetration test are not lost as part of the cleanup and restoration activities?

    A. Preserving artifacts
    B. Reverting configuration changes
    C. Keeping chain of custody
    D. Exporting credential data

  • Question 205:

    A penetration tester runs a vulnerability scan that identifies several issues across numerous customer hosts. The executive report outlines the following.

    The client is concerned about the availability of its consumer-facing production application.

    Which of the following hosts should the penetration tester select for additional manual testing?

    A. Server 1
    B. Server 2
    C. Server 3
    D. Server 4

  • Question 206:

    A penetration tester gains access to a Windows machine and wants to further enumerate users with native operating system credentials.

    Which of the following should the tester use?

    A. route.exe print
    B. netstat.exe -ntp
    C. net.exe commands
    D. strings.exe -a

  • Question 207:

    A tester is performing an external phishing assessment on the top executives at a company. Two-factor authentication is enabled on the executives' accounts that are in the scope of work.

    Which of the following should the tester do to get access to these accounts?

    A. Configure an external domain using a typosquatting technique. Configure Evilginx to bypass two-factor authentication using a phishlet that simulates the mail portal for the company.
    B. Configure Gophish to use an external domain. Clone the email portal web page from the company and get the two-factor authentication code using a brute-force attack method.
    C. Configure an external domain using a typosquatting technique. Configure SET to bypass two-factor authentication using a phishlet that mimics the mail portal for the company.
    D. Configure Gophish to use an external domain. Clone the email portal web page from the company and get the two-factor authentication code using a vishing method.

  • Question 208:

    During a test of a custom-built web application, a penetration tester identifies several vulnerabilities.

    Which of the following would be the most interested in the steps to reproduce these vulnerabilities?

    A. Operations staff
    B. Developers
    C. Third-party stakeholders
    D. C-suite executives

  • Question 209:

    During a penetration test, a tester captures information about an SPN account.

    Which of the following attacks requires this information as a prerequisite to proceed?

    A. Golden Ticket
    B. Kerberoasting
    C. DCShadow
    D. LSASS dumping

  • Question 210:

    A penetration tester finished a security scan and uncovered numerous vulnerabilities on several hosts.

    Based on the targets' EPSS and CVSS scores, which of the following targets is the most likely to get attacked?

    Host | CVSS | EPSS

    Target 1 | 4 | 0.6

    Target 2 | 2 | 0.3

    Target 3 | 1 | 0.6

    Target 4 | 4.5 | 0.4

    A. Target 1: CVSS Score = 4 and EPSS Score = 0.6
    B. Target 2: CVSS Score = 2 and EPSS Score = 0.3
    C. Target 3: CVSS Score = 1 and EPSS Score = 0.6
    D. Target 4: CVSS Score = 4.5 and EPSS Score = 0.4

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.