PT0-003 Exam Details

  • Exam Code
    :PT0-003
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :404 Q&As
  • Last Updated
    :Jun 09, 2026

CompTIA PT0-003 Online Questions & Answers

  • Question 331:

    auth=yYKGORbrpabgr842ajbvrpbptaui42342

    When the tester logs in, the server sends only one Set-Cookie header, and the value is exactly the same as shown above.

    Which of the following vulnerabilities has the tester discovered?

    A. JWT manipulation
    B. Cookie poisoning
    C. Session fixation
    D. Collision attack

  • Question 332:

    A penetration tester was able to gather MD5 hashes from a server and crack the hashes easily with rainbow tables.

    Which of the following should be included as a recommendation in the remediation report?

    A. Stronger algorithmic requirements
    B. Access controls on the server
    C. Encryption on the user passwords
    D. A patch management program

  • Question 333:

    During an assessment, a penetration tester obtains a low-privilege shell and then runs the following command:

    findstr /SIM /C:"pass" *.txt *.cfg *.

    xml Which of the following is the penetration tester trying to enumerate?

    A. Configuration files
    B. Permissions
    C. Virtual hosts
    D. Secrets

  • Question 334:

    A penetration tester enumerates a legacy Windows host on the same subnet. The tester needs to select exploit methods that will have the least impact on the host's operating stability.

    Which of the following commands should the tester try first?

    A. responder -I eth0 john responder_output.txt <rdp to target>
    B. hydra -L administrator -P /path/to/pwlist.txt -t 100 rdp://<target_host>
    C. msf > use <module_name> msf > set <options> msf > set PAYLOAD windows/meterpreter/reverse_tcp msf > run
    D. python3 ./buffer_overflow_with_shellcode.py <target> 445

  • Question 335:

    During an engagement, a penetration tester runs the following command against the host system:

    host -t axfr domain.com dnsl.domain.com

    Which of the following techniques best describes what the tester is doing?

    A. Zone transfer
    B. Host enumeration
    C. DNS poisoning
    D. DNS query

  • Question 336:

    A penetration tester observes the following output from an Nmap command while attempting to troubleshoot connectivity to a Linux server:

    Which of the following is the most likely reason for the connectivity issue?

    A. The SSH service is running on a different port.
    B. The SSH service is blocked by a firewall.
    C. The SSH service requires certificate authentication.
    D. The SSH service is not active.

  • Question 337:

    A penetration tester compromises a Windows OS endpoint that is joined to an Active Directory local environment.

    Which of the following tools should the tester use to manipulate authentication mechanisms to move laterally in the network?

    A. Rubeus
    B. WinPEAS
    C. NTLMRelayX
    D. Impacket

  • Question 338:

    A penetration tester attempts to obtain the preshared key for a client's wireless network.

    Which of the following actions will most likely aid the tester?

    A. Deploying an evil twin with a WiFi Pineapple
    B. Performing a password spraying attack with Hydra
    C. Setting up a captive portal using SET
    D. Deauthenticating clients using aireplay-ng

  • Question 339:

    A penetration tester needs to scan a remote infrastructure with Nmap.

    The tester issues the following command: nmap 10.10.1.0/24 Which of the following is the number of TCP ports that will be scanned?

    A. 256
    B. 1,000
    C. 1,024
    D. 65,535

  • Question 340:

    A penetration tester is conducting a penetration test and discovers a vulnerability on a web server that is owned by the client. Exploiting the vulnerability allows the tester to open a reverse shell. Enumerating the server for privilege escalation, the tester discovers the following:

    Which of the following should the penetration tester do NEXT?

    A. Close the reverse shell the tester is using.
    B. Note this finding for inclusion in the final report.
    C. Investigate the high numbered port connections.
    D. Contact the client immediately.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.