CompTIA PenTest+ (PT0-003) practice questions

242 free questions with answers and explanations.

Practice test
  1. 1.A penetration tester is performing reconnaissance against a target organization's public-facing infrastructure. They suspect that the organization's DNS server might be misconfigured to allow unauthorized zone transfers. The tester attempts to retrieve DNS zone information for `example.com` from `ns1.example.com` using the command `dig axfr @ns1.example.com example.com`. If the command is successful and returns a full list of DNS records, what vulnerability has been identified?Attacks and Exploits
  2. 2.A pentester is contracted to assess a client's security posture across AWS, Azure, and GCP environments simultaneously, focusing on identifying misconfigured storage permissions, overly permissive IAM roles, and insecure default settings across all three providers. Which tool is best suited for this multi-cloud configuration assessment?Vulnerability Discovery and Analysis
  3. 3.During an authorized physical security assessment, a tester wants to covertly capture the RF signal from an employee's proximity access card while standing nearby, then write that data to a blank card to test the badge reader's access controls. Which tool is best suited for this task?Vulnerability Discovery and Analysis
  4. 4.A penetration tester is performing network reconnaissance against a client's perimeter. They have identified a web server and want to determine if it is running on a common port (e.g., 80, 443) or an unusual one. Additionally, they need to identify the specific web server software (e.g., Apache, Nginx, IIS) and its version. Which Nmap command would achieve this most efficiently?Reconnaissance and Enumeration
  5. 5.A penetration tester is analyzing a web server that appears to be running on an unusual port, 8080. They want to determine the specific web server software (e.g., Apache, Nginx, IIS) and its version to identify potential vulnerabilities. Which Nmap command would be most effective for this task?Reconnaissance and Enumeration
  6. 6.A tester generates a reverse shell payload using msfvenom targeting a Windows host and configures a listener before delivering the payload. Which Metasploit component must the tester configure to receive the incoming connection once the payload executes?Attacks and Exploits
  7. 7.A penetration tester has successfully gained access to a Windows server within a client's internal network. During the post-exploitation phase, the tester aims to maintain persistent access. Which of the following methods, when implemented, would provide the MOST covert and resilient form of persistence?Post-exploitation and Lateral Movement
  8. 8.A penetration tester is analyzing a web application using Burp Suite and observes that a specific parameter in a GET request, `?id=123`, consistently returns data from a database. When attempting to manipulate this parameter to `?id=123 AND 1=1` and `?id=123 AND 1=2`, the application behaves identically, but when a single quote is introduced, `?id=123'`, the application returns a generic error page. The tester suspects a SQL injection vulnerability. Which of the following Burp Suite tools would be most effective for systematically identifying the specific database type and extracting data?Vulnerability Discovery and Analysis
  9. 9.A penetration tester is performing reconnaissance on an organization and wants to gather email addresses of employees. They decide to use a tool that queries Google and other search engines for email patterns, often combined with domain names. Which of the following tools is specifically designed for this type of OSINT email harvesting?Reconnaissance and Enumeration
  10. 10.A penetration tester's Rules of Engagement specify that all active scanning and exploitation must occur only between 20:00 and 06:00 to avoid disrupting production systems. At 14:00, while reviewing earlier reconnaissance data, the tester identifies a critical remote code execution vulnerability that could be exploited immediately with Metasploit. What should the tester do?Engagement Management
  11. 11.A penetration tester is analyzing network traffic captured during a reconnaissance phase. They observe several HTTP requests containing a 'User-Agent' header that reveals the operating system and browser version of the client making the request. This is an example of which type of fingerprinting?Reconnaissance and Enumeration
  12. 12.A penetration tester has obtained authenticated access to an internal network segment. The tester wants to quickly identify open ports and services on a range of target hosts without triggering aggressive firewall alerts. Which 'nmap' command would be the MOST appropriate for this initial reconnaissance?Post-exploitation and Lateral Movement
  13. 13.An uncredentialed vulnerability scan of a Windows server reports dozens of missing security patches, but the system administrator insists the server is fully patched via WSUS. What is the MOST likely cause of this discrepancy, and what should the tester do to obtain more reliable results?Vulnerability Discovery and Analysis
  14. 14.A pilot program deploys an AI chatbot that can browse and summarize web pages for users. A tester embeds hidden instructions in the HTML of a webpage, invisible to human readers, directing the model to reveal the user's active session token when the page is summarized. Which type of attack does this represent?Attacks and Exploits
  15. 15.During a web application assessment, a tester submits a product ID value of 5' UNION SELECT null,null,null-- - and observes the page display three columns of data that match the number of columns in the original query. Which type of SQL injection technique is the tester using?Attacks and Exploits
  16. 16.A tester attempting to compromise a WPA2-PSK wireless network notices the target access point has WPS enabled. The tester uses the reaver tool to systematically try PIN combinations against the AP's WPS interface. What is the primary weakness in the WPS protocol that this attack exploits?Attacks and Exploits
  17. 17.A penetration tester has obtained a password hash from a compromised system and needs to crack it using a wordlist. The hash is identified as an NTLM hash. Which hashcat mode would be used to perform this cracking operation?Reconnaissance and Enumeration
  18. 18.A penetration tester has compromised a web server and established a Meterpreter session. The tester identifies that the server is running an outdated version of Apache Tomcat. To establish persistence, the tester plans to deploy a malicious WAR file. Which Metasploit module is best suited for this task?Post-exploitation and Lateral Movement
  19. 19.A tester compromises a domain controller and uses Mimikatz to extract the krbtgt account's NTLM hash via a DCSync attack. The tester then forges a Kerberos ticket-granting ticket with arbitrary group memberships and a ten-year expiration, allowing continued domain admin access even after all user passwords are reset. Which attack technique does this describe?Attacks and Exploits
  20. 20.A penetration tester is evaluating a client's external network perimeter. They perform an Nmap scan with the command: `nmap -sV -O -p 1-65535 <target_IP>`. Which of the following statements accurately describes the information this scan aims to gather and its characteristics?Reconnaissance and Enumeration
  21. 21.During a penetration test, a web application is discovered to be running on an unusual port, 8443, and appears to be a custom-developed application. The tester needs to thoroughly analyze the traffic and identify potential vulnerabilities. Which tool is best suited for intercepting, modifying, and replaying HTTP/HTTPS requests to this application?Reconnaissance and Enumeration
  22. 22.A penetration tester is evaluating a web application that includes a feature for generating PDF reports. The application accepts a URL parameter, `template_url`, which is used to fetch an HTML template from a remote server to render the PDF. The tester provides a value of `http://169.254.169.254/latest/meta-data/` for the `template_url` parameter and observes that the generated PDF contains what appears to be AWS instance metadata. Which type of attack did the tester successfully execute?Attacks and Exploits
  23. 23.A red team repeatedly submits carefully varied inputs to a company's proprietary fraud-detection API and records the corresponding classification outputs. Using thousands of these input-output pairs, the team trains their own local model that closely mimics the target's decision boundaries, without ever accessing its source code or training data. Which attack technique does this describe?Attacks and Exploits
  24. 24.A penetration tester is evaluating a client's web application and needs to identify all possible HTTP methods supported by a specific endpoint without sending a full request body. Which Nmap script would be most appropriate for this task?Reconnaissance and Enumeration
  25. 25.A penetration tester is conducting OSINT for a client. They discover several public-facing documents on the client's website that contain employee names, email addresses, and phone numbers. Which of the following OSINT tools would be most effective for quickly extracting and organizing this type of information for further analysis?Reconnaissance and Enumeration
  26. 26.After compromising a workstation, a tester uses Mimikatz to extract an NTLM hash from memory and then uses that hash directly with a tool like psexec to authenticate to another server on the network, without ever needing to know or crack the plaintext password. Which attack technique does this describe?Attacks and Exploits
  27. 27.A client's Rules of Engagement state that active scanning and exploitation using tools such as Burp Suite's active scanner may only occur between 10:00 PM and 4:00 AM local time to avoid impacting production traffic. What is this restriction called?Engagement Management
  28. 28.During a web application test, a tester posts a malicious script into a public product review field. The application saves the review in its database, and every subsequent visitor who views that product page has the script execute in their browser. Which type of XSS is this?Attacks and Exploits
  29. 29.A penetration tester is performing a cloud security assessment. They discover an S3 bucket with a policy that allows `s3:GetObject` for `*` (all principals) but explicitly denies `s3:ListBucket` for `*`. The tester attempts to enumerate the contents of the bucket using `aws s3 ls s3://target-bucket-name` and receives an 'Access Denied' error. However, when the tester attempts to download a known file `report.pdf` using `aws s3 cp s3://target-bucket-name/report.pdf .`, the file downloads successfully. What type of misconfiguration does this indicate?Attacks and Exploits
  30. 30.A red team is assessing an organization's Machine Learning (ML) model used for fraud detection. Without any access to the model's training data or internal architecture, the team repeatedly submits carefully varied inputs to the model and observes its outputs. Their goal is to create new inputs that are subtly altered from legitimate transactions but are incorrectly classified as non-fraudulent by the ML model. Which type of AI attack are they performing?Attacks and Exploits
  31. 31.A penetration tester is evaluating a web application that allows users to submit support tickets. The application includes a file upload feature for attachments. The tester attempts to upload a file named `shell.php` containing a simple PHP web shell. However, the application rejects the upload with an error message: 'Invalid file type.' The tester then renames the file to `shell.php.jpg` and uploads it successfully. When attempting to access the uploaded file via a direct URL, the web server executes the PHP code, granting the tester remote code execution. Which web application vulnerability did the tester exploit?Attacks and Exploits
  32. 32.A penetration tester is performing reconnaissance on a target company and wants to identify publicly exposed Git repositories that might contain sensitive information. Which specialized OSINT tool is designed to search GitHub and other code hosting platforms for specific keywords or patterns to uncover such repositories?Reconnaissance and Enumeration
  33. 33.A pentester is performing cloud discovery against a client's AWS environment as part of the reconnaissance phase. The client is concerned about publicly exposed object storage containing sensitive data. Which approach would MOST effectively identify misconfigured or publicly accessible storage buckets?Vulnerability Discovery and Analysis
  34. 34.A tester needs to quickly determine which hosts are online across a 254-address subnet before running detailed service scans, without sending any TCP/UDP port probes to the targets. Which nmap command should the tester run?Attacks and Exploits
  35. 35.A penetration tester has gained access to a Linux system within a client's network. To understand the network connections established by the system and identify listening services, which command would be most effective for listing all active network connections and listening ports, including the associated process IDs and names?Reconnaissance and Enumeration
  36. 36.A penetration tester is performing a web application assessment and encounters a login form. The tester suspects the application might be vulnerable to command injection. Which of the following inputs, when entered into a username field, would be the MOST indicative of a successful command injection vulnerability on a Linux-based server?Attacks and Exploits
  37. 37.A penetration tester has gained a low-privileged shell on a Linux server. During the post-exploitation phase, the tester identifies that the 'find' command is installed with the SUID bit set for the 'root' user. Which of the following commands would allow the tester to escalate privileges to root?Post-exploitation and Lateral Movement
  38. 38.According to the Penetration Testing Execution Standard (PTES), during which phase do the tester and client formally agree on scope, objectives, and rules of engagement before any technical activity begins?Engagement Management
  39. 39.A tester extracted a large set of NTLM password hashes from a compromised domain controller during vulnerability validation. To efficiently crack as many hashes as possible by leveraging known corporate password patterns (e.g., 'Company2024!'), which hashcat attack configuration would be MOST effective as a first pass?Vulnerability Discovery and Analysis
  40. 40.A penetration tester is performing reconnaissance against a client's web application. They discover a login form and suspect it might be vulnerable to username enumeration. They want to systematically test common usernames against the form to see if the application responds differently to valid versus invalid usernames. Which Burp Suite tool is best suited for this task?Reconnaissance and Enumeration
  41. 41.A penetration tester is performing a network reconnaissance using Nmap. They need to quickly identify all active hosts within the 192.168.1.0/24 subnet without performing a full port scan on each host. Which Nmap command option should they use?Attacks and Exploits
  42. 42.A penetration tester is performing OSINT against a client organization. They want to find email addresses associated with the target domain. Which tool is specifically designed to harvest email addresses, employee names, and subdomains from public sources like search engines, PGP key servers, and SHODAN?Reconnaissance and Enumeration
  43. 43.A penetration tester discovers a web application that allows users to upload profile pictures. Upon uploading a file named `image.php.jpg`, the server processes it and saves it as `image.php.jpg` in a publicly accessible directory. When the tester navigates to the URL of the uploaded file, a 'PHP code execution' error is displayed. Which web application attack is MOST likely indicated by this behavior?Attacks and Exploits
  44. 44.A penetration tester's initial exploitation attempts using a staged Meterpreter payload consistently fail because the target network's firewall terminates outbound connections before the second stage can be downloaded. Which type of payload should the tester select to overcome this issue?Vulnerability Discovery and Analysis
  45. 45.A password policy requires exactly 8 characters formatted as one uppercase letter, followed by five lowercase letters, followed by two digits. Using a hashcat mask attack with the mask ?u?l?l?l?l?l?d?d, how many total password combinations must be tested?Attacks and Exploits
  46. 46.A penetration tester wants to quickly determine which ports are open on a target network while completing as few full TCP handshakes as possible to reduce log noise. Which Nmap scan type should the tester use?Vulnerability Discovery and Analysis
  47. 47.A penetration tester is performing initial reconnaissance against a target organization. They want to identify publicly accessible subdomains associated with the main domain without directly interacting with the target's servers. Which of the following techniques would be most effective for this purpose?Reconnaissance and Enumeration
  48. 48.A penetration tester is evaluating a wireless network. They observe that the network uses WPA2-PSK encryption and has Wi-Fi Protected Setup (WPS) enabled. The tester wants to exploit a known vulnerability in WPS to gain access to the network without needing to capture a full WPA2 handshake. Which tool and attack method would be most effective for this scenario?Attacks and Exploits
  49. 49.During contract negotiation, a client's legal team requests a clause specifying that the client will assume responsibility for legal costs and damages if a third party sues the penetration testing firm as a direct result of testing activities that were explicitly authorized within the agreed scope. Which type of clause is being requested?Engagement Management
  50. 50.A penetration tester has compromised a Linux server and established a reverse shell. The tester needs to pivot into an isolated network segment accessible only from the compromised server. To achieve this, the tester plans to set up an SSH tunnel. Which command initiates a local SSH port forwarding tunnel from the compromised server to the attacker's machine, allowing access to a target in the isolated segment?Post-exploitation and Lateral Movement