PT0-003 Exam Details

  • Exam Code
    :PT0-003
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :404 Q&As
  • Last Updated
    :Jun 01, 2026

CompTIA PT0-003 Online Questions & Answers

  • Question 21:

    A penetration tester is assessing a Linux host and discovers the following cron job owned by root:

    */5 * * * * /usr/local/bin/backup.sh

    The tester also finds that the script /usr/local/bin/backup.sh is world-writable.

    Which of the following is the MOST likely outcome if the tester modifies the script?

    A. The script will fail to execute due to permission mismatch
    B. The tester can achieve privilege escalation to root
    C. The cron daemon will remove the writable script
    D. System logs will automatically revert the script

  • Question 22:

    A penetration tester is assessing the security of a web application. When the tester attempts to access the application, the tester receives an HTTP 403 response.

    Which of the following should the penetration tester do to overcome this issue?

    A. Reset file and folder permissions on the web server.
    B. Obtain a valid X.509 certificate.
    C. Spoof the server's MAC address.
    D. Use a legacy browser to access the page.

  • Question 23:

    A penetration tester attempts unauthorized entry to the company's server room as part of a security assessment.

    Which of the following is the best technique to manipulate the lock pins and open the door without the original key?

    A. Plug spinner
    B. Bypassing
    C. Decoding
    D. Raking

  • Question 24:

    Which of the following is a reason to use a template when creating a penetration testing report?

    A. To articulate risks accurately
    B. To enhance the testing approach
    C. To contextualize collected data
    D. To standardize needed information
    E. To improve testing time

  • Question 25:

    During a penetration test, the tester gains full access to the application's source code. The application repository includes thousands of code files.

    Given that the assessment timeline is very short, which of the following approaches would allow the tester to identify hard-coded credentials most effectively?

    A. Run TruffleHog against a local clone of the application
    B. Scan the live web application using Nikto
    C. Perform a manual code review of the Git repository
    D. Use SCA software to scan the application source code

  • Question 26:

    DRAG DROP

    You are a penetration tester reviewing a client's website through a web browser.

    INSTRUCTIONS

    Review all components of the website through the browser to determine if vulnerabilities are present.

    Remediate ONLY the highest vulnerability from either the certificate, source, or cookies.

    If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

    Select and Place:

  • Question 27:

    While performing an internal assessment, a tester uses the following command:

    crackmapexec smb 192.168.1.0/24 -u user.txt -p Summer123@

    Which of the following is the main purpose of the command?

    A. To perform a pass-the-hash attack over multiple endpoints within the internal network
    B. To perform common protocol scanning within the internal network
    C. To perform password spraying on internal systems
    D. To execute a command in multiple endpoints at the same time

  • Question 28:

    A penetration tester gains access to the target network and observes a running SSH server.

    Which of the following techniques should the tester use to obtain the version of SSH running on the target server?

    A. Network sniffing
    B. IP scanning
    C. Banner grabbing
    D. DNS enumeration

  • Question 29:

    A penetration tester would like to leverage a CSRF vulnerability to gather sensitive details from an application's end users.

    Which of the following tools should the tester use for this task?

    A. Browser Exploitation Framework
    B. Maltego
    C. Metasploit
    D. theHarvester

  • Question 30:

    A security analyst needs to perform an on-path attack on BLE smart devices.

    Which of the following tools would be BEST suited to accomplish this task?

    A. Wireshark
    B. Gattacker
    C. tcpdump
    D. Netcat

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.