PT0-003 Exam Details

  • Exam Code
    :PT0-003
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :404 Q&As
  • Last Updated
    :Jun 09, 2026

CompTIA PT0-003 Online Questions & Answers

  • Question 261:

    A penetration tester writes a Bash script to automate the execution of a ping command on a Class C network:

    for var in --MISSING TEXT-- do

    ping -c 1 192.168.10.$var

    done

    Which of the following pieces of code should the penetration tester use in place of the --MISSING TEXT-- placeholder?

    A. crunch 1 254 loop
    B. seq 1 254
    C. echo 1-254
    D. {1.-254}

  • Question 262:

    A tester scans a subnet and receives the following results for a Linux host:

    22/tcp open ssh

    111/tcp open rpcbind

    2049/tcp open nfs

    Which is the BEST next action to check for exposed data?

    A. Attempt to enumerate NFS shares
    B. Attempt SSH brute force
    C. Perform banner grabbing on rpcbind
    D. Launch a kernel exploit against the host

  • Question 263:

    During a penetration tester found a web component with no authentication requirements.

    The web component also allows file uploads and is hosted on one of the target public web the following actions should the penetration tester perform next?

    A. Continue the assessment and mark the finding as critical.
    B. Attempting to remediate the issue temporally.
    C. Notify the primary contact immediately.
    D. Shutting down the web server until the assessment is finished

  • Question 264:

    A penetration tester needs to help create a threat model of a custom application.

    Which of the following is the most likely framework the tester will use?

    A. MITRE ATT&CK
    B. OSSTMM
    C. CI/CD
    D. DREAD

  • Question 265:

    A penetration tester currently conducts phishing reconnaissance using various tools and accounts for multiple intelligence-gathering platforms. The tester wants to consolidate some of the tools and accounts into one solution to analyze the output from the intelligence-gathering tools.

    Which of the following is the best tool for the penetration tester to use?

    A. Caldera
    B. SpiderFoot
    C. Maltego
    D. WIGLE.net

  • Question 266:

    A penetration tester performs a service enumeration process and receives the following result after scanning a server using the Nmap tool:

    Based on the output, which of the following services provides the best target for launching an attack?

    A. Database
    B. Remote access
    C. Email
    D. File sharing

  • Question 267:

    A penetration tester needs to upload the results of a port scan to a centralized security tool.

    Which of the following commands would allow the tester to save the results in an interchangeable format?

    A. nmap -iL results 192.168.0.10-100
    B. nmap 192.168.0.10-100 -O > results
    C. nmap -A 192.168.0.10-100 -oX results
    D. nmap 192.168.0.10-100 | grep "results"

  • Question 268:

    During a vulnerability assessment, a penetration tester configures the scanner sensor and performs the initial vulnerability scanning under the client's internal network. The tester later discusses the results with the client, but the client does not accept the results. The client indicates the host and assets that were within scope are not included in the vulnerability scan results.

    Which of the following should the tester have done?

    A. Rechecked the scanner configuration.
    B. Performed a discovery scan.
    C. Used a different scan engine.
    D. Configured all the TCP ports on the scan.

  • Question 269:

    A penetration tester is conducting a wireless security assessment for a client with 2.4GHz and 5GHz access points. The tester places a wireless USB dongle in the laptop to start capturing WPA2 handshakes.

    Which of the following steps should the tester take next?

    A. Enable monitoring mode using Aircrack-ng.
    B. Use Kismet to automatically place the wireless dongle in monitor mode and collect handshakes.
    C. Run KARMA to break the password.
    D. Research WiGLE.net for potential nearby client access points.

  • Question 270:

    A penetration tester is conducting an authorized, physical penetration test to attempt to enter a client's building during non-business hours.

    Which of the following are MOST important for the penetration tester to have during the test? (Choose two.)

    A. A handheld RF spectrum analyzer
    B. A mask and personal protective equipment
    C. Caution tape for marking off insecure areas
    D. A dedicated point of contact at the client
    E. The paperwork documenting the engagement
    F. Knowledge of the building's normal business hours

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.