PT0-003 Exam Details

  • Exam Code
    :PT0-003
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :404 Q&As
  • Last Updated
    :Jun 01, 2026

CompTIA PT0-003 Online Questions & Answers

  • Question 31:

    A penetration tester intercepts HTTP traffic and sees:

    Set-Cookie: sessionid=12345abcd; SameSite=None; Secure

    The tester later observes that session cookies remain unchanged after authentication.

    What vulnerability is MOST likely present?

    A. Cookie poisoning
    B. Session fixation
    C. Cross-site scripting
    D. Header injection

  • Question 32:

    A penetration tester found several critical SQL injection vulnerabilities during an assessment of a client's system. The tester would like to suggest mitigation to the client as soon as possible.

    Which of the following remediation techniques would be the BEST to recommend? (Choose two.)

    A. Closing open services
    B. Encryption users' passwords
    C. Randomizing users' credentials
    D. Users' input validation
    E. Parameterized queries
    F. Output encoding

  • Question 33:

    A penetration tester finds that an application responds with the contents of the /etc/passwd file when the following payload is sent:

    xml

    Copy code

    <?xml version="1.0"?>

    <!DOCTYPE data [ <!ENTITY foo SYSTEM "file:///etc/passwd" >

    ]>

    <test>&foo;</test>

    Which of the following should the tester recommend in the report to best prevent this type of vulnerability?

    A. Drop all excessive file permissions with chmod o-rwx.
    B. Ensure the requests application access logs are reviewed frequently.
    C. Disable the use of external entities.
    D. Implement a WAF to filter all incoming requests.

  • Question 34:

    A penetration testing firm performs an assessment every six months for the same customer. While performing network scanning for the latest assessment, the penetration tester observes that several of the target hosts appear to be residential connections associated with a major television and ISP in the area.

    Which of the following is the most likely reason for the observation?

    A. The penetration tester misconfigured the network scanner.
    B. The network scanning tooling is not functioning properly.
    C. The IP ranges changed ownership.
    D. The network scanning activity is being blocked by a firewall.

  • Question 35:

    During an engagement, a penetration tester needs to break the key for the Wi-Fi network that uses WPA2 encryption.

    Which of the following attacks would accomplish this objective?

    A. ChopChop
    B. Replay
    C. Initialization vector
    D. KRACK

  • Question 36:

    A penetration tester is developing the rules of engagement for a potential client.

    Which of the following would most likely be a function of the rules of engagement?

    A. Testing window
    B. Terms of service
    C. Authorization letter
    D. Shared responsibilities

  • Question 37:

    A penetration tester aims to exploit a vulnerability in a wireless network that lacks proper encryption. The lack of proper encryption allows malicious content to infiltrate the network.

    Which of the following techniques would most likely achieve the goal?

    A. Packet injection
    B. Bluejacking
    C. Beacon flooding
    D. Signal jamming

  • Question 38:

    A penetration tester recently performed a social-engineering attack in which the tester found an employee of the target company at a local coffee shop and over time built a relationship with the employee. On the employee's birthday, the tester gave the employee an external hard drive as a gift.

    Which of the following social-engineering attacks was the tester utilizing?

    A. Phishing
    B. Tailgating
    C. Baiting
    D. Shoulder surfing

  • Question 39:

    Which of the following elements of a penetration test report can be used to most effectively prioritize the remediation efforts for all the findings?

    A. Methodology
    B. Detailed findings list
    C. Risk score
    D. Executive summary

  • Question 40:

    A penetration tester is conducting an Nmap scan and wants to scan for ports without establishing a connection. The tester also wants to find version data information for services running on Projects.

    Which of the following Nmap commands should the tester use?

    A. ..nmap -sU -sV -T4 -F target.company.com
    B. ..nmap -sS -sV -F target.company.com
    C. ..nmap -sT -v -T5 target.company.com
    D. ..nmap -sX -sC target.company.com

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.