CompTIA PenTest+ (PT0-003) practice questions

242 free questions with answers and explanations.

Practice test
  1. 101.A penetration tester is performing a black-box assessment against a client's external web servers. They discover that one server is running Apache HTTP Server. To further enumerate potential vulnerabilities, the tester wants to identify common, non-standard web directories and files that might expose sensitive information. Which Nmap script category would be most effective for this type of web enumeration without relying on a full vulnerability scanner?Reconnaissance and Enumeration
  2. 102.A penetration tester wants to determine the specific software product and version running on each open port of a target host without performing full OS fingerprinting. Which nmap option should the tester use?Attacks and Exploits
  3. 103.A penetration tester has compromised a Linux workstation and plans to establish a reverse shell back to their attacking machine. To blend in with normal network traffic and evade basic firewall rules, which common outbound port should the tester configure their reverse shell to use on the attacking machine?Post-exploitation and Lateral Movement
  4. 104.A tester on an internal engagement captures NTLM authentication traffic using Responder and then relays the intercepted authentication attempt to a target server using ntlmrelayx, gaining access without ever cracking the password hash. Which attack technique is being demonstrated?Attacks and Exploits
  5. 105.A tester has a curated wordlist of common passwords and wants hashcat to apply common human mutation patterns, such as appending digits or capitalizing the first letter, to each word without generating a new wordlist manually. Which hashcat configuration accomplishes this?Vulnerability Discovery and Analysis
  6. 106.A penetration tester is performing a black-box assessment against a web server. They discover a login form and want to test for common username enumeration vulnerabilities by trying a list of usernames and observing the server's responses. Which Metasploit auxiliary module is specifically designed for this type of web enumeration?Reconnaissance and Enumeration
  7. 107.A penetration tester is performing reconnaissance against a target organization's public-facing web infrastructure. The tester wants to identify all subdomains associated with example.com, including those that might not be directly linked from the main website. Which of the following Nmap commands would be most effective for this task?Attacks and Exploits
  8. 108.A penetration tester is analyzing a web application that uses a custom API. They observe that user input is directly embedded into a URL path, like `/api/v1/users/lookup/JohnDoe`. The tester suspects that path traversal might be possible to access sensitive files outside the intended directory. Which of the following Burp Suite features would be most effective for systematically testing various path traversal payloads against this endpoint?Attacks and Exploits
  9. 109.A penetration tester is performing a web application assessment. They identify a login form and attempt to bypass authentication. They submit the username `admin' AND 1=SLEEP(5)--` and a random password. The server takes approximately 5 seconds longer to respond than with a normal, invalid login attempt. Which type of SQL Injection is the tester likely exploiting?Attacks and Exploits
  10. 110.A client requests a penetration test focused on their customer-facing web application, specifically wanting the assessment to cover categories such as injection flaws, broken authentication, and business logic vulnerabilities using a structured, widely recognized methodology. Which framework should the tester primarily reference to structure this assessment?Engagement Management
  11. 111.A penetration tester is performing network reconnaissance against a client's external IP range. They want to identify active hosts and open ports without significantly increasing the risk of detection. Which Nmap scan type is best suited for this objective while minimizing noise?Reconnaissance and Enumeration
  12. 112.A penetration tester is performing an internal network assessment. They use `nmap` to scan a subnet and receive the following output for a specific host: ``` Nmap scan report for 192.168.1.100 Host is up (0.002s latency). PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.5 (Ubuntu Linux; protocol 2.0) 80/tcp open http Apache httpd 2.4.41 ((Ubuntu)) 3389/tcp filtered ms-wbt-server ``` Based on this `nmap` output, which of the following is the MOST accurate conclusion regarding the `3389/tcp` port?Attacks and Exploits
  13. 113.A penetration tester is performing a black-box assessment of a client's web application. During the discovery phase, the tester wants to identify publicly exposed subdomains that might not be directly linked from the main website but could host other applications or services. Which passive reconnaissance technique would be most effective for this purpose?Vulnerability Discovery and Analysis
  14. 114.During a penetration test, a tester identifies two findings for the final report: a CVE with a CVSS base score of 9.8 on an isolated development server containing no sensitive data, and a misconfiguration on the production authentication server (CVSS 6.5) that allowed the tester to harvest and crack multiple domain administrator NTLM hashes using hashcat. When prioritizing remediation recommendations, which finding should be ranked as the higher priority?Engagement Management
  15. 115.A penetration tester is targeting an Active Directory environment. They successfully compromise a low-privileged user account. The tester discovers that this user account has a Service Principal Name (SPN) registered. The tester wants to obtain the NTLM hash of the service account associated with this SPN for offline cracking. Which Active Directory attack method should the tester employ?Attacks and Exploits
  16. 116.A penetration tester following the OSSTMM methodology wants to quantify the target's actual security posture by comparing existing operational controls (limitations, porosity) against an idealized secure state, producing a normalized numeric score. Which OSSTMM concept does this describe?Engagement Management
  17. 117.A web application hosted on an AWS EC2 instance accepts a URL parameter used to fetch and display remote images. A tester modifies the parameter to point to an internal address and successfully retrieves temporary IAM credentials. Which attack was performed?Attacks and Exploits
  18. 118.A tester on an internal network engagement floods a switch segment with forged DHCPDISCOVER packets to exhaust the legitimate DHCP server's address pool, then stands up an attacker-controlled DHCP server that assigns clients a malicious default gateway, enabling traffic interception. What is this attack called?Attacks and Exploits
  19. 119.A penetration tester is performing an internal network assessment. They discover that several legacy Windows servers are configured to use LM hashes for authentication, in addition to NTLM. The tester captures an LM hash from network traffic. Which of the following tools is most effective for quickly cracking this LM hash?Attacks and Exploits
  20. 120.A penetration tester wants to run Nmap using the Nmap Scripting Engine to check open ports for known, publicly disclosed vulnerabilities. Which script category should the tester specify with the --script option?Vulnerability Discovery and Analysis
  21. 121.A penetration tester has identified a web server running Apache and wants to enumerate potential directories and files that might expose sensitive information. They want to use a tool that can perform dictionary-based brute-forcing of common web paths and extensions. Which tool would be most effective for this task?Reconnaissance and Enumeration
  22. 122.An organization runs an automated vulnerability scan against its web servers. Weeks later, a manual penetration test uncovers an unpatched, actively exploitable OpenSSL vulnerability that the scanner never flagged. How should this scanning outcome be classified?Vulnerability Discovery and Analysis
  23. 123.A red team is conducting an assessment of an organization's cloud environment. They discover an S3 bucket configured for public read access. The bucket contains several Python scripts that appear to be used for data processing, along with configuration files containing API keys and database credentials. Which of the following attack types BEST describes this scenario?Attacks and Exploits
  24. 124.A penetration tester has gained a shell on a Linux server that is part of a highly segmented network. Outbound connections are heavily restricted, but DNS queries appear to be allowed to external DNS servers. The tester wants to establish a persistent command and control (C2) channel that can bypass these restrictions and allow for data exfiltration. Which of the following techniques would be MOST effective for achieving this goal?Post-exploitation and Lateral Movement
  25. 125.A penetration tester is evaluating a client's web server. They have discovered that the server is configured to allow directory listing by default. To efficiently enumerate all accessible directories and files, including those that might contain sensitive information, which Nmap script would be most suitable?Reconnaissance and Enumeration
  26. 126.A penetration tester is performing an on-site physical security assessment. While attempting to badge into a server room, the tester is confronted by building security, who calls the local police. What should the tester immediately provide to avoid being arrested?Engagement Management
  27. 127.During a wireless assessment, a tester detects an access point broadcasting the corporate SSID but with a different BSSID, open authentication, and stronger signal strength than the legitimate AP. What is this most likely an example of?Vulnerability Discovery and Analysis
  28. 128.A tester is conducting passive cloud reconnaissance and wants to identify a client's internet-facing devices, exposed services, and misconfigured cloud assets without sending any direct traffic to those assets. Which tool should the tester use?Vulnerability Discovery and Analysis
  29. 129.A penetration tester is assessing an organization's Machine Learning (ML) model used for fraud detection. The tester repeatedly submits carefully crafted, slightly perturbed inputs to the model and observes the model's predictions. The goal is to understand the model's decision boundaries and potentially create inputs that cause misclassifications. Which type of AI attack is BEST described by this scenario?Attacks and Exploits
  30. 130.A penetration tester is evaluating an organization's wireless network. They observe that the network uses WPA2-PSK and has a weak pre-shared key. The tester wants to perform an offline brute-force attack against the captured WPA2 handshake. Which of the following commands, using `hashcat`, would be most suitable for this task if the handshake was captured in a .cap file?Attacks and Exploits
  31. 131.During a wireless assessment, a tester identifies an access point with WPS enabled and wants to determine whether it is vulnerable to an offline PIN brute-force attack that could ultimately recover the WPA2 passphrase. Which tool is specifically designed to perform this WPS PIN attack?Vulnerability Discovery and Analysis
  32. 132.A penetration tester is performing reconnaissance against a target organization's web infrastructure. They want to identify all subdomains associated with the primary domain example.com by scraping various public data sources, including search engines, certificate transparency logs, and DNS records. Which command-line tool is best suited for this comprehensive subdomain enumeration?Reconnaissance and Enumeration
  33. 133.A client has requested a wireless security assessment to detect unauthorized access points near their headquarters. Which tool is BEST suited for passively capturing SSIDs, BSSIDs, channels, and encryption types from nearby wireless networks?Vulnerability Discovery and Analysis
  34. 134.A red team is assessing a machine learning-based fraud detection system that is periodically retrained on new transaction data. Over several weeks, the team submits a large volume of carefully crafted fraudulent transactions labeled as legitimate into the system's training pipeline, aiming to degrade the model's future ability to detect similar fraud patterns. Which type of AI attack is being conducted?Attacks and Exploits
  35. 135.A penetration tester is evaluating an organization's cloud environment. They discover an S3 bucket named `company-internal-backups-2023` that is configured with public read access. The bucket contains several compressed archives and database dumps. Which type of cloud attack is this an example of?Attacks and Exploits
  36. 136.A penetration tester has established a Meterpreter session on a Windows workstation. The tester wants to quickly obtain password hashes from the local system for offline cracking. Which 'Metasploit' command would achieve this MOST efficiently?Post-exploitation and Lateral Movement
  37. 137.During an active engagement, a tester's nmap scan against an in-scope subnet triggers the client's intrusion prevention system, which blocks the tester's IP address and pages the client's SOC on-call engineer. Per the Rules of Engagement, what should the tester do next?Engagement Management
  38. 138.A hospital hires a penetration testing firm specifically to demonstrate adherence to HIPAA Security Rule requirements ahead of an annual audit. The SOW requires the tester to validate a predefined checklist of technical safeguards rather than freely explore the environment for creative attack paths. This engagement is best classified as which type of assessment?Engagement Management
  39. 139.A penetration tester has successfully compromised a Linux workstation and obtained root privileges. The tester needs to establish a persistent backdoor that can be triggered by a specific HTTP request, even if the primary C2 channel is detected. Which of the following methods would be most effective and stealthy for this purpose?Post-exploitation and Lateral Movement
  40. 140.A tester is assessing a login form and submits the username field value: admin' AND SLEEP(5)-- -. The application returns no error and displays the normal login failure page, but the response consistently takes about 5 seconds longer to load than a baseline request. Which SQL injection technique is being used?Attacks and Exploits
  41. 141.A penetration tester has gained a shell on a Linux server that is restricted from making direct outbound connections to the internet, except for DNS queries. The tester wants to establish a persistent C2 channel for data exfiltration and command execution without alerting network defenders. Which technique is most suitable for this scenario?Post-exploitation and Lateral Movement
  42. 142.A penetration tester is conducting an external black-box assessment against a client's network. They want to identify publicly exposed services and their associated versions running on common ports without generating excessive traffic that might trigger intrusion detection systems. Which Nmap command would be most appropriate for this initial reconnaissance phase?Reconnaissance and Enumeration
  43. 143.A penetration testing contract requires that all client data, including cracked password hashes recovered with hashcat and any captured credentials, be securely wiped from the testing firm's systems within 30 days of final report delivery. This requirement is most likely found in which part of the engagement documentation?Engagement Management
  44. 144.A penetration tester is conducting a reconnaissance phase and suspects that a target organization might have internal DNS records that are not publicly exposed but could be useful for further enumeration. They want to attempt a DNS zone transfer from the primary DNS server. Which command would they use for this purpose?Reconnaissance and Enumeration
  45. 145.A vulnerability report lists a CVSS v3.1 vector segment of PR:H for a critical finding. During a risk-prioritization meeting, a client asks what this metric value means for exploitability. Which explanation is correct?Vulnerability Discovery and Analysis
  46. 146.While performing cloud reconnaissance, a tester finds a CNAME record for dev.clientcorp.com pointing to an Azure App Service subdomain that now returns a 'Web App Not Found' error, indicating the resource was deleted but the DNS record was never removed. What vulnerability does this represent?Vulnerability Discovery and Analysis
  47. 147.A client's password policy requires passwords that begin with one uppercase letter, followed by six lowercase letters, and end with one digit, for a total of eight characters. A tester wants to build a hashcat mask attack (attack mode 3) that exactly reflects this policy. Which mask should be used?Vulnerability Discovery and Analysis
  48. 148.A penetration testing team following PTES has completed intelligence gathering on a target organization. Before running vulnerability scans, the team categorizes potential threat agents, maps them to specific business assets, and derives plausible attack scenarios based on the attackers' likely capabilities and motivations. Which PTES phase does this activity represent?Engagement Management
  49. 149.A tester wants to send traffic from a compromised access port into VLANs other than the one it is assigned to, without negotiating a trunk link. The tester crafts Ethernet frames with two stacked 802.1Q VLAN tags, relying on the switch stripping the outer tag that matches the native VLAN and forwarding the inner tagged frame to another VLAN. Which attack is being performed?Attacks and Exploits
  50. 150.During a web application assessment, a tester wants Burp Suite Scanner to identify vulnerabilities by analyzing HTTP traffic that has already been captured through the proxy, without sending any additional crafted requests to the live application, to reduce the risk of account lockouts. Which scan type should the tester run?Vulnerability Discovery and Analysis