PT0-003 Exam Details

  • Exam Code
    :PT0-003
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :404 Q&As
  • Last Updated
    :Jun 01, 2026

CompTIA PT0-003 Online Questions & Answers

  • Question 51:

    SIMULATION A penetration tester has been provided with only the public domain name and must enumerate additional information for the public-facing assets. INSTRUCTIONS Select the appropriate answer(s), given the output from each section. Output 1

    A. See explanation below.
    B. PlaceHolder
    C. PlaceHolder
    D. PlaceHolder

  • Question 52:

    During a web application assessment, a penetration tester identifies an input field that allows JavaScript injection. The tester inserts a line of JavaScript that results in a prompt, presenting a text box when browsing to the page going forward.

    Which of the following types of attacks is this an example of?

    A. SQL injection
    B. SSRF
    C. XSS
    D. Server-side template injection

  • Question 53:

    A penetration tester finishes an initial discovery scan for hosts on a /24 customer subnet. The customer states that the production network is composed of Windows servers but no container clusters. The following are the last several lines from the scan log:

    Line 1: 112 hosts found... trying ports

    Line 2: FOUND 22 with OpenSSH 1.2p2 open on 99 hosts Line 3: FOUND 161 with UNKNOWN banner open on 110 hosts Line 4: TCP RST received on ports 21, 3389, 80 Line 5: Scan complete.

    Which of the following is the most likely reason for the results?

    A. Multiple honeypots were encountered
    B. The wrong subnet was scanned
    C. Windows is using WSL
    D. IPS is blocking the ports

  • Question 54:

    A tester gains initial access to a server and needs to enumerate all corporate domain DNS records.

    Which of the following commands should the tester use?

    A. dig +short A AAAA local.domain
    B. nslookup local.domain
    C. dig axfr @local.dns.server
    D. nslookup -server local.dns.server local.domain *

  • Question 55:

    During a penetration test, a junior tester uses Hunter.io for an assessment and plans to review the information that will be collected.

    Which of the following describes the information the junior tester will receive from the Hunter.io tool?

    A. A collection of email addresses for the target domain that is available on multiple sources on the internet
    B. DNS records for the target domain and subdomains that could be used to increase the external attack surface
    C. Data breach information about the organization that could be used for additional enumeration
    D. Information from the target's main web page that collects usernames, metadata, and possible data exposures

  • Question 56:

    Before starting an assessment, a penetration tester needs to scan a Class B IPv4 network for open ports in a short amount of time.

    Which of the following is the best tool for this task?

    A. Burp Suite
    B. masscan
    C. Nmap
    D. hping

  • Question 57:

    A company hires a penetration tester to test the security of its wireless networks. The main goal is to intercept and access sensitive data.

    Which of the following tools should the security professional use to best accomplish this task?

    A. Metasploit
    B. WiFi-Pumpkin
    C. SET
    D. theHarvester
    E. WiGLE.net

  • Question 58:

    Which of the following types of information would MOST likely be included in an application security assessment report addressed to developers? (Choose two.)

    A. Use of non-optimized sort functions
    B. Poor input sanitization
    C. Null pointer dereferences
    D. Non-compliance with code style guide
    E. Use of deprecated Javadoc tags
    F. A cydomatic complexity score of 3

  • Question 59:

    Which of the following tasks would ensure the key outputs from a penetration test are not lost as part of the cleanup and restoration activities?

    A. Preserving artifacts
    B. Reverting configuration changes
    C. Keeping chain of custody
    D. Exporting credential data

  • Question 60:

    A penetration tester is conducting an unknown environment test and gathering additional information that can be used for later stages of an assessment.

    Which of the following would most likely produce useful information for additional testing?

    A. Searching for code repositories associated with a developer who previously worked for the target company code repositories associated with the
    B. Searching for code repositories target company's organization
    C. Searching for code repositories associated with the target company's organization
    D. Searching for code repositories associated with a developer who previously worked for the target company

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.