CompTIA PenTest+ (PT0-003) practice questions
242 free questions with answers and explanations.
- 51.A tester configures Burp Suite Intruder with two payload positions: a username field and a password field. The tester supplies a list of 50 usernames and a list of 100 passwords and wants every possible combination tested. Which Intruder attack type should be selected?Attacks and Exploits
- 52.While running an authorized nmap scan against a client's approved /24 subnet, a tester discovers a live host with an IP address that falls just outside the documented scope but appears to be owned by the same client. What is the correct next step before scanning or exploiting that host?Engagement Management
- 53.A penetration tester is conducting an internal assessment and has gained access to a Windows workstation. They dump credentials from memory using Mimikatz and obtain the following NTLM hash for the `Administrator` account: `Administrator:::1000:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::`. The tester wants to quickly use this hash to authenticate to other systems without needing the plaintext password. Which technique should the tester employ?Attacks and Exploits
- 54.A tester's Rules of Engagement explicitly prohibit denial-of-service testing. While using Metasploit to exploit a vulnerable service, an exploit module unexpectedly crashes the target application, causing an outage. What is the tester's correct immediate action?Engagement Management
- 55.During an active engagement, a penetration tester uses Metasploit to exploit a vulnerable service and discovers evidence of an existing, unrelated malware infection with active command-and-control traffic on the compromised host. The rules of engagement include a communication plan for adverse events. What should the tester do first?Engagement Management
- 56.A penetration tester is evaluating a client's external network perimeter. They discover a web server responding on port 80. To determine if the server supports WebDAV and identify available methods, which Nmap script would be most effective?Reconnaissance and Enumeration
- 57.While testing a login form parameter with Burp Repeater, a tester notices that injecting `' AND SLEEP(5)-- -` causes a consistent five-second delay in the server response, while other injected payloads produce output identical to normal requests. The tester then runs SQLMap against the parameter to confirm and exploit the flaw. Which SQL injection technique is being leveraged?Vulnerability Discovery and Analysis
- 58.A penetration tester needs to gather information about a target's network infrastructure, including router details, ISP, and geographic location, without sending any direct traffic to the target's IP address. Which OSINT tool is specifically designed for querying Border Gateway Protocol (BGP) routing information from public sources?Reconnaissance and Enumeration
- 59.A client insists on adding a clause to the SOW that caps the testing firm's total financial responsibility at the value of the contract, regardless of any damages caused during testing. This is an example of which type of contract clause?Engagement Management
- 60.A penetration tester is evaluating an Active Directory environment. They have compromised a low-privilege user account and are attempting to escalate privileges. During their reconnaissance, they discover that the `svc_backup` service account has a Service Principal Name (SPN) registered for `MSSQLSvc/db.corp.local:1433`. The tester uses `setspn -query svc_backup` to confirm this. Which type of attack should the tester attempt next to potentially retrieve the service account's password hash?Attacks and Exploits
- 61.A security firm has a five-year Master Service Agreement (MSA) with a large enterprise client that establishes payment terms, liability caps, and confidentiality obligations for all future engagements. The client now wants a new penetration test performed on a recently acquired subsidiary's network. Which document should be created next before testing begins?Engagement Management
- 62.A vulnerability scan returns a finding with a CVSS v3.1 base score of 7.8. Using the CVSS Qualitative Severity Rating Scale, how should the tester categorize this finding in the report?Vulnerability Discovery and Analysis
- 63.After gaining access to a web server, a penetration tester discovers that outbound HTTP/HTTPS connections are heavily filtered, but DNS traffic is allowed. To maintain a covert channel for command and control (C2), which 'Burp Suite' feature or related technique would be MOST useful?Post-exploitation and Lateral Movement
- 64.During a web application test, a tester intercepts a funds-transfer request in Burp Suite and wants to manually resend the request multiple times, tweaking the transfer amount and account number each time while carefully reviewing each individual response for business logic flaws. Which Burp Suite tool is best suited for this task?Attacks and Exploits
- 65.While running an nmap scan against the client's authorized /24 subnet, a penetration tester discovers a responsive host whose IP address falls outside the range documented in the SOW. What is the BEST course of action?Engagement Management
- 66.A penetration tester is targeting a corporate network and has identified several public-facing IP addresses. They want to gather as much information as possible about the network infrastructure, including routing information and potential administrative contacts, without directly scanning the target. Which OSINT technique would be most effective for this purpose?Reconnaissance and Enumeration
- 67.A tester runs hcxdumptool against a WPA2-PSK access point and captures a PMKID from a single management frame exchange, without requiring any connected client to complete a four-way handshake. The tester then feeds the captured hash into hashcat mode 16800 for offline cracking. What attack technique is being used?Attacks and Exploits
- 68.An attacker calls a company's help desk, impersonating a traveling executive who claims to be locked out, and convinces the technician to reset the executive's password over the phone. Which social engineering technique was used?Attacks and Exploits
- 69.A penetration tester is using Burp Suite Intruder against a login form and wants to test every combination of a list of 50 usernames against a list of 100 passwords, using two separate payload positions (username and password). Which Intruder attack type will iterate through all possible combinations of both payload sets?Vulnerability Discovery and Analysis
- 70.A penetration tester is performing reconnaissance against a dark-web forum known to be frequented by threat actors. They need to collect information about the forum's structure, user base, and common topics without directly exposing their IP address or leaving any identifiable traces. Which of the following best describes this approach?Reconnaissance and Enumeration
- 71.During an internal engagement, a tester enumerates several Active Directory accounts with Service Principal Names (SPNs) and requests TGS tickets for each. The tickets are exported to a file for offline cracking. Which hashcat mode should be specified to crack these extracted tickets?Attacks and Exploits
- 72.A tester uses Mimikatz on a compromised Windows workstation to extract the following credential pair from LSASS memory: aad3b435b51404eeaad3b435b51404ee:8846f7eaee8fb117ad06bdd830b7586c. The tester wants to crack the second hash value offline using hashcat. Which hashcat mode should the tester specify?Attacks and Exploits
- 73.A penetration tester is performing reconnaissance against a target organization. They have identified several subdomains and want to check if any of them are associated with cloud services like AWS S3 buckets or Azure Blob storage, which might be misconfigured. Which tool is specifically designed to identify and enumerate public cloud resources associated with a target?Reconnaissance and Enumeration
- 74.A penetration tester is evaluating a web server that uses an old version of Apache. They suspect that directory listing might be enabled on some parts of the server, potentially exposing sensitive files. Which of the following web enumeration techniques would be most effective for quickly identifying if directory listing is enabled on common web paths?Reconnaissance and Enumeration
- 75.A CVSS v3.1 vector reads: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. A client asks why the risk score is lower than expected given the high confidentiality, integrity, and availability impacts. Which base metric best explains this?Vulnerability Discovery and Analysis
- 76.A penetration tester is performing a black-box assessment against a client's web application. They suspect the application might be vulnerable to directory traversal. Which Burp Suite tool would be most effective for systematically testing various directory traversal payloads in URL parameters?Reconnaissance and Enumeration
- 77.A penetration tester needs to perform a comprehensive host discovery on an internal network segment (192.168.1.0/24) where ICMP echo requests might be blocked by firewalls or host-based security. To reliably identify live hosts even when ICMP is filtered, which Nmap command combination would be most effective?Reconnaissance and Enumeration
- 78.A penetration testing firm requires both parties to sign a document before any engagement details are discussed, legally binding them to protect confidential information (such as network diagrams, findings, and client business data) from unauthorized disclosure. Which document is this?Engagement Management
- 79.A penetration tester is performing post-exploitation on a compromised Linux server within a client's internal network. They need to identify other active hosts on the local subnet to expand their foothold, but they want to avoid using traditional active scanning tools like Nmap directly from the compromised host to minimize detection. Which of the following methods could potentially achieve this goal passively or semi-passively?Reconnaissance and Enumeration
- 80.During an on-site physical security assessment, a tester follows closely behind an employee who badges into a secured server room, entering without presenting their own credentials or being challenged. Which social engineering technique does this describe?Vulnerability Discovery and Analysis
- 81.A penetration tester has gained root access on a Linux server and wants to ensure that all traces of their activity are removed. This includes shell history, temporary files, and log entries. Which of the following cleanup actions is MOST critical to prevent detection and forensic analysis?Post-exploitation and Lateral Movement
- 82.After a client's IT team applies patches for all critical findings from a penetration test report, they ask the testing firm to confirm the vulnerabilities have actually been fixed before closing out the engagement. What should the testing firm perform to satisfy this request?Engagement Management
- 83.A tester wants to harvest employee credentials during a physical/wireless assessment. The tester configures an access point broadcasting the same SSID as the corporate wireless network but with a stronger signal, and sets up a captive portal that mimics the company's login page. Which attack is being performed?Attacks and Exploits
- 84.A penetration tester is performing a black-box assessment against a client's web application. They notice that requests to a specific API endpoint return different error messages depending on the length of the input string in a particular parameter. Which Burp Suite tool would be most effective for systematically testing various input lengths and observing the responses?Reconnaissance and Enumeration
- 85.A penetration tester has compromised a web application and wants to establish a persistent backdoor. The application allows file uploads, but restricts executable formats. The tester successfully uploads a web shell (e.g., 'shell.php'). To ensure persistence even if the web shell is discovered and removed, which technique would be the MOST effective for establishing a secondary, more resilient backdoor?Post-exploitation and Lateral Movement
- 86.A penetration tester is analyzing a web server and observes that it responds differently to HTTP requests based on the `User-Agent` header. Specifically, requests with a mobile `User-Agent` receive a simplified page, while desktop `User-Agent` requests receive the full site. To effectively enumerate all possible content and functionality, the tester needs to systematically test the application with various `User-Agent` strings. Which Burp Suite tool is best suited for this automated, iterative testing?Reconnaissance and Enumeration
- 87.As part of an authorized physical security assessment, a tester applies light rotational pressure to a pin tumbler lock with a tension wrench while using a hook pick to manipulate each pin individually until it sets at the shear line, eventually allowing the lock to open without the original key. Which technique is being demonstrated?Vulnerability Discovery and Analysis
- 88.A penetration tester has gained a low-privileged shell on a Linux server. During the privilege escalation phase, the tester discovers a SUID (Set User ID) bit set on a custom utility 'backup_script.sh' owned by root. When executed, this script runs 'tar -czf /tmp/backup.tar.gz /var/www/html'. What is the MOST effective method for the tester to escalate privileges?Post-exploitation and Lateral Movement
- 89.A penetration tester receives a vulnerability scan report indicating a Windows host is vulnerable to MS17-010 (EternalBlue). Before launching an exploit, the tester wants to non-intrusively confirm the vulnerability using Metasploit. Which type of module should the tester run first?Vulnerability Discovery and Analysis
- 90.An ethical hacker is performing an external penetration test and has identified several public-facing web servers. Before attempting any direct attacks, they want to gather as much information as possible about the web technologies in use, such as server versions, CMS, and plugins, without actively probing or sending malicious requests. Which of the following methods represents the most passive approach for this type of web technology fingerprinting?Reconnaissance and Enumeration
- 91.A penetration tester has established a foothold on a Windows domain controller. The tester needs to exfiltrate critical Active Directory database files (NTDS.dit) without triggering immediate alerts. Which of the following methods would be MOST suitable for a covert data exfiltration?Post-exploitation and Lateral Movement
- 92.A penetration tester has compromised an Active Directory domain controller. Using `Mimikatz`, they extract the `krbtgt` account's NTLM hash. The tester then plans to use this hash to create a forged Kerberos Ticket Granting Ticket (TGT) for any user, allowing them to authenticate to any service in the domain as that user for an extended period, even if the user's password changes. Which type of attack is the tester preparing to execute?Attacks and Exploits
- 93.A penetration tester runs the command dig axfr @ns1.example.com example.com against a target's authoritative name server and receives a complete list of every subdomain, internal hostname, and associated IP address for the domain. What does this result indicate?Attacks and Exploits
- 94.A tester enumerates Active Directory user accounts and identifies several with the 'Do not require Kerberos preauthentication' flag enabled. The tester requests authentication service tickets for these accounts without supplying valid credentials, then extracts the encrypted timestamp portion for offline cracking. What attack is being performed?Attacks and Exploits
- 95.A penetration tester has gained access to a Linux system and needs to identify running services and their associated open ports to further enumerate the system. They are looking for a command that provides a comprehensive list of listening sockets and their corresponding processes. Which of the following commands would best achieve this goal?Reconnaissance and Enumeration
- 96.A red team assesses a facial-recognition-based access control system. Without any access to the model's training pipeline, the team crafts subtle, carefully calculated pixel perturbations to a photo of an unauthorized team member's face. When presented to the camera, the modified image is misclassified by the model as an authorized employee, even though the perturbations are imperceptible to a human observer. What type of attack does this describe?Attacks and Exploits
- 97.A tester runs a cloud reconnaissance tool that enumerates common bucket-naming patterns and discovers an AWS S3 bucket named company-backups configured with public read and write access control lists. The tester downloads sensitive backup files and uploads a test file without authentication. What is this finding an example of?Attacks and Exploits
- 98.During a cloud assessment, a tester discovers an IAM user has the iam:PassRole and ec2:RunInstances permissions attached, but no direct administrative privileges. An IAM role named AdminRole with full administrative access also exists in the account. Which technique would allow the tester to escalate privileges to that of an administrator?Attacks and Exploits
- 99.During a cloud assessment, a tester discovers an SSRF vulnerability in an application hosted on an AWS EC2 instance. The tester uses the vulnerable parameter to send a request to http://169.254.169.254/latest/meta-data/iam/security-credentials/WebAppRole and receives temporary AWS access keys in the response. What does this scenario demonstrate?Attacks and Exploits
- 100.A client requests a penetration test of a single, well-defined web application with a fixed set of test cases and a firm two-week timeline. The client wants cost certainty and is unwilling to accept invoices that fluctuate based on hours worked. Which contract pricing structure should the penetration testing firm propose?Engagement Management