PT0-003 Exam Details

  • Exam Code
    :PT0-003
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :404 Q&As
  • Last Updated
    :Jun 09, 2026

CompTIA PT0-003 Online Questions & Answers

  • Question 241:

    A penetration tester needs to confirm the version number of a client's web application server.

    Which of the following techniques should the penetration tester use?

    A. SSL certificate inspection
    B. URL spidering
    C. Banner grabbing
    D. Directory brute forcing

  • Question 242:

    A company provided the following network scope for a penetration test:

    169.137.1.0/24

    221.10.1.0/24

    149.14.1.0/24

    A penetration tester discovered a remote command injection on IP address 149.14.1.24 and exploited the system. Later, the tester learned that this particular IP address belongs to a third party.

    Which of the following stakeholders is responsible for this mistake?

    A. The company that requested the penetration test
    B. The penetration testing company
    C. The target host's owner
    D. The penetration tester
    E. The subcontractor supporting the test

  • Question 243:

    During a routine penetration test, the client's security team observes logging alerts that indicate several ID badges were reprinted after working hours without authorization.

    Which of the following is the penetration tester most likely trying to do?

    A. Obtain long-term, valid access to the facility
    B. Disrupt the availability of facility access systems
    C. Change access to the facility for valid users
    D. Revoke access to the facility for valid users

  • Question 244:

    A penetration tester gains access to a host with many applications that load at startup and run as SYSTEM. The penetration tester runs a command and receives the following output:

    User accounts for \\COMPTIA-Host

    --------------------------------CompTIA

    User

    DefaultAccount

    Guest

    CompTIA Admin

    CompTIA Accountant

    The command completed successfully.

    Which of the following attacks will most likely allow the penetration tester to escalate privileges?

    A. Credential dumping
    B. Local file inclusion
    C. Unquoted service path injection
    D. Process hijacking

  • Question 245:

    During an external penetration test, a tester receives the following output from a tool:

    test.comptia.org

    info.comptia.org

    vpn.comptia.org

    exam.comptia.org

    Which of the following commands did the tester most likely run to get these results?

    A. nslookup -type=SOA comptia.org
    B. amass enum -passive -d comptia.org
    C. nmap -Pn -sV -vv -A comptia.org
    D. shodan host comptia.org

  • Question 246:

    A penetration tester is conducting reconnaissance for an upcoming assessment of a large corporate client.

    The client authorized spear phishing in the rules of engagement.

    Which of the following should the tester do first when developing the phishing campaign?

    A. Shoulder surfing
    B. Recon-ng
    C. Social media
    D. Password dumps

  • Question 247:

    A client wants a security assessment company to perform a penetration test against its hot site. The purpose of the test is to determine the effectiveness of the defenses that protect against disruptions to business continuity.

    Which of the following is the MOST important action to take before starting this type of assessment?

    A. Ensure the client has signed the SOW.
    B. Verify the client has granted network access to the hot site.
    C. Determine if the failover environment relies on resources not owned by the client.
    D. Establish communication and escalation procedures with the client.

  • Question 248:

    A penetration tester reviewing proxy logs finds:

    User-Agent: sqlmap/1.5.12#stable

    Which issue does this MOST likely indicate?

    A. A tester misconfigured passive reconnaissance tools
    B. A threat actor is actively performing SQL injection scanning
    C. The WAF is blocking authenticated user sessions
    D. The target database is misconfigured

  • Question 249:

    During an assessment, a penetration tester manages to get RDP access via a low-privilege user. The tester attempts to escalate privileges by running the following commands:

    Import-Module .\PrintNightmare.ps1

    Invoke-Nightmare -NewUser "hacker" -NewPassword "Password123!" -DriverName "Print"

    The tester then attempts to further enumerate the host with the new administrative privileges by using the runas command. However, the access level is still low.

    Which of the following actions should the penetration tester take next?

    A. Log off and log on with "hacker".
    B. Attempt to add another user.
    C. Bypass the execution policy.
    D. Add a malicious printer driver.

  • Question 250:

    Which of the following BEST describes why a client would hold a lessons-learned meeting with the penetration-testing team?

    A. To provide feedback on the report structure and recommend improvements
    B. To discuss the findings and dispute any false positives
    C. To determine any processes that failed to meet expectations during the assessment
    D. To ensure the penetration-testing team destroys all company data that was gathered during the test

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.