PT0-003 Exam Details

  • Exam Code
    :PT0-003
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :404 Q&As
  • Last Updated
    :Jun 09, 2026

CompTIA PT0-003 Online Questions & Answers

  • Question 221:

    A penetration tester identifies an exposed corporate directory containing first and last names and phone numbers for employees.

    Which of the following attack techniques would be the most effective to pursue if the penetration tester wants to compromise user accounts?

    A. Smishing
    B. Impersonation
    C. Tailgating
    D. Whaling

  • Question 222:

    A penetration tester is working on an engagement in which a main objective is to collect confidential information that could be used to exfiltrate data and perform a ransomware attack. During the engagement, the tester is able to obtain an internal foothold on the target network.

    Which of the following is the next task the tester should complete to accomplish the objective?

    A. Initiate a social engineering campaign.
    B. Perform credential dumping.
    C. Compromise an endpoint.
    D. Share enumeration.

  • Question 223:

    Which of the following is the most efficient way to infiltrate a file containing data that could be sensitive?

    A. Use steganography and send the file over FTP
    B. Compress the file and send it using TFTP
    C. Split the file in tiny pieces and send it over dnscat
    D. Encrypt and send the file over HTTPS

  • Question 224:

    During an engagement, a penetration tester found some weaknesses that were common across the customer's entire environment. The weaknesses included the following:

    1. Weaker password settings than the company standard

    2. Systems without the company's endpoint security software installed

    3. Operating systems that were not updated by the patch management system.

    Which of the following recommendations should the penetration tester provide to address the root issue?

    A. Add all systems to the vulnerability management system.
    B. Implement a configuration management system.
    C. Deploy an endpoint detection and response system.
    D. Patch the out-of-date operating systems.

  • Question 225:

    A penetration tester is conducting reconnaissance on a target network. The tester runs the following Nmap

    command: nmap -sv -sT -p - 192.168.1.0/24.

    Which of the following describes the most likely purpose of this scan?

    A. OS fingerprinting
    B. Attack path mapping
    C. Service discovery
    D. User enumeration

  • Question 226:

    A penetration tester obtains a regular domain user's set of credentials. The tester wants to attempt a dictionary attack by creating a custom word list based on the Active Directory password policy.

    Which of the following tools should the penetration tester use to retrieve the password policy?

    A. Responder
    B. CrackMapExec
    C. Hydra
    D. msfvenom

  • Question 227:

    The following line-numbered Python code snippet is being used in reconnaissance:

    Which of the following line numbers from the script MOST likely contributed to the script triggering a "probable port scan" alert in the organization's IDS?

    A. Line 01
    B. Line 02
    C. Line 07
    D. Line 08

  • Question 228:

    SIMULATION

    A penetration tester has been provided with only the public domain name and must enumerate additional information for the public-facing assets.

    INSTRUCTIONS

    Select the appropriate answer(s), given the output from each section.

  • Question 229:

    A penetration tester wants to send a specific network packet with custom flags and sequence numbers to a vulnerable target.

    Which of the following should the tester use?

    A. tcprelay
    B. Bluecrack
    C. Scapy
    D. tcpdump

  • Question 230:

    An internal penetration tester is on site assessing network access for company-owned mobile devices.

    Which of the following would be the best tool to identify the available networks?

    A. Wireshark
    B. theHarvester
    C. Recon-ng
    D. WiGLE.net

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.