PT0-003 Exam Details

  • Exam Code
    :PT0-003
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :404 Q&As
  • Last Updated
    :Jun 01, 2026

CompTIA PT0-003 Online Questions & Answers

  • Question 361:

    A penetration tester is trying to restrict searches on Google to a specific domain.

    Which of the following commands should the penetration tester consider?

    A. inurl:
    B. link:
    C. site:
    D. intitle:

  • Question 362:

    A penetration tester wants to automatically enumerate all ciphers permitted on TLS/SSL configurations across a client's internet-facing and internal web servers.

    Which of the following tools or frameworks best supports this objective?

    A. Nmap Scripting Engine
    B. Shodan
    C. Impacket
    D. Netcat
    E. Burp Suite

  • Question 363:

    A penetration tester wants to use multiple TTPs to assess the reactions (alerted, blocked, and others) by the client's current security tools. The threat-modeling team indicates the TTPs in the list might affect their internal systems and servers.

    Which of the following actions would the tester most likely take?

    A. Use a BAS tool to test multiple TTPs based on the input from the threat-modeling team.
    B. Perform an internal vulnerability assessment with credentials to review the internal attack surface.
    C. Use a generic vulnerability scanner to test the TTPs and review the results with the threat-modeling team.
    D. Perform a full internal penetration test to review all the possible exploits that could affect the systems.

  • Question 364:

    A penetration tester conducts a scan on an exposed Linux web server and gathers the following data:

    Host: 192.168.55.23

    Open Ports:

    22/tcp Open OpenSSH 7.2p2 Ubuntu 4ubuntu2.10 80/tcp Open Apache httpd 2.4.18 (Ubuntu) 111/tcp Open rpcbind 2-4 (RPC #100000)

    Additional notes:

    Directory listing enabled on /admin Apache mod_cgi enabled

    No authentication required to access /cgi-bin/debug.sh

    X-Powered-By: PHP/5.6.40-0+deb8u12

    Which of the following is the most effective action to take?

    A. Launch a payload using msfvenom and upload it to the /admin directory.
    B. Review the contents of /cgi-bin/debug.sh.
    C. Use Nikto to scan the host and port 80.
    D. Attempt a brute-force attack against OpenSSH 7.2p2.

  • Question 365:

    A penetration tester wants to gather the names of potential phishing targets who have access to sensitive data.

    Which of the following would best meet this goal?

    A. WHOIS
    B. Censys.io
    C. SpiderFoot
    D. theHarvester

  • Question 366:

    A penetration tester executes multiple enumeration commands to find a path to escalate privileges. Given the following command:

    find / -user root -perm -4000 -exec ls -ldb {} \; 2>/dev/null

    Which of the following is the penetration tester attempting to enumerate?

    A. Attack path mapping
    B. API keys
    C. Passwords
    D. Permission

  • Question 367:

    A tester pivots into an internal network and wants to verify whether a discovered internal API leaks sensitive information.

    Which tool is BEST suited to perform structured API request testing?

    A. Burp Suite
    B. Hydra
    C. Netcat
    D. Nmap

  • Question 368:

    A penetration tester needs to recursively search through a large Windows file repository to locate all occurrences of the string "ProjectX" within file contents and return both file paths and matching lines.

    Which PowerShell command would BEST accomplish this task?

    A. gc * | select "ProjectX"
    B. dir /R | findstr "ProjectX"
    C. Get-ChildItem * | Select-String "ProjectX"
    D. gci -Path . -Recurse | Select-String -Pattern "ProjectX"

  • Question 369:

    A penetration tester sets up a C2 (Command and Control) server to manage and control payloads deployed in the target network.

    Which of the following tools is the most suitable for establishing a robust and stealthy connection?

    A. ProxyChains
    B. Covenant
    C. PsExec
    D. sshuttle

  • Question 370:

    A penetration tester is attempting to exfiltrate sensitive data from a client environment without alerting the client's blue team.

    Which of the following exfiltration methods most likely remain undetected?

    A. Cloud storage
    B. Email
    C. Domain Name System
    D. Test storage sites

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.