PT0-003 Exam Details

  • Exam Code
    :PT0-003
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :404 Q&As
  • Last Updated
    :Jun 09, 2026

CompTIA PT0-003 Online Questions & Answers

  • Question 231:

    During an assessment, a penetration tester sends the following request:

    Which of the following attacks is the penetration tester performing?

    A. Directory traversal
    B. API abuse
    C. Server-side request forgery
    D. Privilege escalation

  • Question 232:

    A penetration tester is conducting a vulnerability scan. The tester wants to see any vulnerabilities that may be visible from outside of the organization.

    Which of the following scans should the penetration tester perform?

    A. SAST
    B. Sidecar
    C. Unauthenticated
    D. Host-based

  • Question 233:

    During a penetration test, a tester attempts to pivot from one Windows 10 system to another Windows system. The penetration tester thinks a local firewall is blocking connections.

    Which of the following command-line utilities built into Windows is most likely to disable the firewall?

    A. certutil.exe
    B. bitsadmin.exe
    C. msconfig.exe
    D. netsh.exe

  • Question 234:

    A penetration tester is performing an assessment focused on attacking the authentication identity provider hosted within a cloud provider. During the reconnaissance phase, the tester finds that the system is using OpenID Connect with OAuth and has dynamic registration enabled.

    Which of the following attacks should the tester try first?

    A. A password-spraying attack against the authentication system
    B. A brute-force attack against the authentication system
    C. A replay attack against the authentication flow in the system
    D. A mask attack against the authentication system

  • Question 235:

    Severity: HIGH

    Vulnerability: ABC Load Balancer: Alpha OS httpd TLS vulnerability

    An Nmap scan of the affected device produces the following results:

    Host is up (0.0000040s latency).

    Not shown: 98 closed tcp ports (reset)

    PORT STATE SERVICE

    22/tcp open ssh

    80/tcp open http

    443/tcp closed https

    Which of the following best describes this scenario?

    A. True negative
    B. True positive
    C. False negative
    D. False positive

  • Question 236:

    During an assessment, a penetration tester obtains access to a Microsoft SQL server using sqlmap and runs the following command:

    sql> xp_cmdshell whoami /all

    Which of the following is the tester trying to do?

    A. List database tables
    B. Show logged-in database users
    C. Enumerate privileges
    D. Display available SQL commands

  • Question 237:

    During an assessment, a penetration tester was able to access the organization's wireless network from outside of the building using a laptop running Aircrack-ng.

    Which of the following should be recommended to the client to remediate this issue?

    A. Changing to Wi-Fi equipment that supports strong encryption
    B. Using directional antennae
    C. Using WEP encryption
    D. Disabling Wi-Fi

  • Question 238:

    During a security assessment, a penetration tester wants to compromise user accounts without triggering

    IDS/IPS detection rules.

    Which of the following is the most effective way for the tester to accomplish this task?

    A. Crack user accounts using compromised hashes.
    B. Brute force accounts using a dictionary attack.
    C. Bypass authentication using SQL injection.
    D. Compromise user accounts using an XSS attack.

  • Question 239:

    During an assessment, a penetration tester obtains access to an internal server and would like to perform further reconnaissance by capturing LLMNR traffic.

    Which of the following tools should the tester use?

    A. Burp Suite
    B. Netcat
    C. Responder
    D. Nmap

  • Question 240:

    A penetration tester needs to launch an Nmap scan to find the state of the port for both TCP and UDP services.

    Which of the following commands should the tester use?

    A. nmap -sU -sW -p 1-65535 example.com
    B. nmap -sU -sY -p 1-65535 example.com
    C. nmap -sU -sT -p 1-65535 example.com
    D. nmap -sU -sN -p 1-65535 example.com

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.