CompTIA PenTest+ (PT0-003) practice questions
242 free questions with answers and explanations.
- 151.A penetration tester has obtained several NTLM hashes from a Windows server. The tester wants to crack these hashes using a GPU-accelerated tool. Which of the following 'hashcat' commands would be used to perform a dictionary attack against NTLM hashes?Post-exploitation and Lateral Movement
- 152.A penetration tester wants to run an Nmap scan against a subnet and have the results automatically stored in the Metasploit Framework database for later use by exploit modules, all without leaving the msfconsole prompt. Which command should the tester use?Vulnerability Discovery and Analysis
- 153.A penetration tester has identified several open ports on a target host using an Nmap SYN scan. To determine the specific software product and version running on each open port for later CVE correlation, which Nmap option should the tester use?Vulnerability Discovery and Analysis
- 154.A penetration tester is performing a web application assessment. They encounter a login form and want to test for SQL injection. They enter the username `admin' -- ` and a random password. The application returns an error message: 'Incorrect username or password.' The tester then tries `admin' OR 1=1 -- ` and a random password. This time, the application successfully logs in the tester as an administrator. Which type of SQL injection did the tester successfully perform?Attacks and Exploits
- 155.A penetration tester is performing OSINT against a target company. They are particularly interested in finding any accidentally exposed credentials, API keys, or sensitive configuration files that might have been committed to public Git repositories. Which specialized OSINT tool is designed to scan Git repositories for such sensitive information?Reconnaissance and Enumeration
- 156.A penetration tester has gained access to a Windows workstation and extracted several NTLM hashes using Mimikatz. The tester wants to use these hashes to authenticate to other systems on the network without knowing the plaintext passwords. Which attack technique is the tester planning to use?Attacks and Exploits
- 157.A tester has a wordlist of common passwords but wants to automatically generate mutated variations, such as appending '123', capitalizing the first letter, and substituting 'a' with '@', without manually typing every possible combination. Which hashcat attack mode should the tester use?Attacks and Exploits
- 158.A tester needs to quickly identify outdated server software versions, dangerous default files, and insecure HTTP headers on a company's public web server before performing deeper manual testing. Which tool is best suited for this initial pass?Vulnerability Discovery and Analysis
- 159.A penetration tester is assessing the wireless network of a coffee shop. They observe an open Wi-Fi network named 'FreeCoffee_Guest' that requires users to accept terms and conditions on a web portal before gaining internet access. The tester notices that after connecting to 'FreeCoffee_Guest', their device is assigned an IP address, but all web requests are redirected to `portal.freecoffee.local`. Which of the following attacks could the tester leverage to bypass the captive portal and gain direct internet access?Attacks and Exploits
- 160.A penetration test's scope includes a web application hosted on a third-party cloud provider's infrastructure. Before launching active Burp Suite scans against the application's endpoints, what additional step MUST the tester verify has been completed?Engagement Management
- 161.A penetration tester is performing a web application assessment. They discover a form that allows users to upload profile pictures. Upon inspecting the HTTP requests, they notice that while the client-side validation enforces `.jpg` or `.png` extensions, the server-side code does not adequately validate the file type or contents. The tester attempts to upload a file named `shell.php` with PHP code designed to execute commands on the server. Which vulnerability is the tester attempting to exploit?Attacks and Exploits
- 162.A penetration tester is conducting reconnaissance against a target organization's network perimeter. They perform an Nmap scan with the '-sS' and '-T4' flags against a range of public IP addresses. However, many ports are reported as 'filtered'. Which of the following is the most likely reason for this result?Reconnaissance and Enumeration
- 163.A penetration tester has compromised a web application and gained initial access. To maintain persistent access, the tester wants to deploy a web shell without being easily detected by file integrity monitoring (FIM) or anti-malware solutions. Which of the following is the most stealthy approach?Post-exploitation and Lateral Movement
- 164.A penetration tester is conducting an internal network assessment. They identify a critical server that is not patched against the 'EternalBlue' vulnerability (CVE-2017-0144). The tester decides to use Metasploit to exploit this vulnerability. Which Metasploit module would be the most appropriate to use for gaining initial access to the vulnerable server?Attacks and Exploits
- 165.A penetration tester is performing a web application assessment and encounters a login form. When attempting to log in with common credentials, the application responds with a generic "Invalid username or password" message, even for valid usernames paired with incorrect passwords. The tester suspects that a username enumeration vulnerability might exist. Which of the following Burp Suite features would be most effective for systematically testing this hypothesis?Vulnerability Discovery and Analysis
- 166.A penetration tester has compromised an internal Windows server and established a Meterpreter session. The tester identifies that the server is part of an Active Directory domain. To facilitate lateral movement, the tester wants to obtain credentials from memory. Which Meterpreter command should the tester use for this purpose?Post-exploitation and Lateral Movement
- 167.A penetration tester is conducting a black-box assessment of an organization's external presence. They have identified numerous subdomains and are now looking for publicly exposed API endpoints or development environments. Which OSINT tool is specifically designed to discover a wide range of public-facing assets, including subdomains, IP addresses, open ports, and potentially vulnerable services by querying various public data sources?Reconnaissance and Enumeration
- 168.During a physical security assessment, an attacker walks past an employee's unlocked phone and exploits a vulnerable OBEX Push service to silently copy the contact list, photos, and text messages from the paired Bluetooth device without the owner's knowledge. Which attack is being performed?Attacks and Exploits
- 169.A penetration tester is analyzing a web application using Burp Suite. They notice that a specific parameter in a POST request, 'userID', seems to control the data displayed to the user. To test for Insecure Direct Object Reference (IDOR) vulnerabilities, they want to systematically increment the 'userID' value and observe the responses. Which Burp Suite Intruder attack type is best suited for this scenario?Reconnaissance and Enumeration
- 170.A client has requested a penetration test of their internal network. During the reconnaissance phase, the tester needs to identify all active hosts and their associated operating systems on a specific `/24` subnet without causing significant network disruption. Which Nmap command would best achieve this objective?Vulnerability Discovery and Analysis
- 171.A penetration tester has successfully escalated privileges to root on a Linux server. To ensure all traces of the compromise are removed and to avoid detection, the tester needs to clean up logs and temporary files. Which directory would be LEAST likely to contain evidence of the compromise that needs manual cleanup?Post-exploitation and Lateral Movement
- 172.A penetration tester has successfully compromised an initial host within a segmented network. To reach a high-value target in a different, isolated segment, the tester needs to establish a proxy. The compromised host has access to both segments, but direct routing between segments is blocked for the tester's attacking machine. Which 'nmap' feature, combined with an appropriate tool, can be used to scan the isolated segment through the compromised host?Post-exploitation and Lateral Movement
- 173.A penetration tester has gained initial access to a Windows server and discovered a password hash, 'aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:6b5b15b5e3c3b5d2e0c089c0b73c59d7'. They need to crack this hash to potentially gain access to other accounts. Which tool and mode would be most appropriate for attempting to crack this specific NTLM hash, assuming no salt is present in a standard format?Reconnaissance and Enumeration
- 174.A penetration test report will be reviewed by both C-suite executives with no technical background and the IT security team responsible for remediation. Which reporting approach BEST serves both audiences?Engagement Management
- 175.A penetration tester has established a Meterpreter session on a Windows workstation. The tester wants to ensure continued access by creating a new local administrator account without leaving obvious traces in the event logs. Which Meterpreter post-exploitation module could best assist with this goal?Post-exploitation and Lateral Movement
- 176.A penetration tester has compromised an internal workstation and needs to scan other hosts in the same network segment. However, the workstation's firewall blocks all outbound TCP connections except for established ones. Which Nmap scan type is most likely to succeed in this scenario by leveraging existing connections or being less intrusive?Post-exploitation and Lateral Movement
- 177.An attacker compromises the email account of a company's trusted vendor and, mimicking the vendor's writing style and past invoice format, sends an urgent email to the client's accounts payable department requesting that future payments be redirected to a new bank account. The finance employee, recognizing the familiar contact and context, updates the payment details and wires $85,000. Which social engineering attack does this best describe?Attacks and Exploits
- 178.An automated scanner flags a web server as vulnerable to a critical remote code execution CVE based on the reported software version banner. When the penetration tester manually attempts to trigger the exploit, the server rejects it because the vendor's patch was actually applied but the version string was not updated. How should the tester classify this scanner finding?Vulnerability Discovery and Analysis
- 179.A penetration tester is performing an internal network assessment. They identify a critical server that uses NTLM authentication. The tester wants to capture NTLMv2 hashes from a legitimate user when they authenticate to this server without being on the same subnet as the user. Which of the following techniques would be most effective for this scenario?Attacks and Exploits
- 180.A penetration tester is conducting a passive reconnaissance phase against a target organization. They are focusing on identifying subdomains without directly interacting with the target's servers. Which of the following techniques would be most effective for this purpose?Reconnaissance and Enumeration
- 181.A penetration tester has compromised an internal Linux server and wants to move laterally to another machine on the same segment. The tester discovers that SSH is running on the target machine, but direct SSH access is restricted by firewall rules. However, the compromised server has outbound access to the internet. Which technique would be MOST effective for reaching the target machine?Post-exploitation and Lateral Movement
- 182.A tester is attempting to capture a WPA2 four-way handshake, but the target client has been idle for over an hour with no new authentication traffic. Which technique should the tester use to force a new handshake capture?Attacks and Exploits
- 183.A penetration tester is performing internal network reconnaissance. They have compromised a low-privilege user account on a Windows domain and want to identify other active hosts on the network segment. They are restricted from installing new tools and prefer a method that leverages built-in Windows commands. Which of the following commands would be most effective for discovering other active hosts?Reconnaissance and Enumeration
- 184.A tester obtains a list of 500,000 username/password pairs leaked from an unrelated third-party website breach and uses an automated tool to try each exact pair against a corporate web portal's login page, succeeding on accounts where employees reused the same password. Which attack technique is this?Attacks and Exploits
- 185.A penetration tester has compromised an endpoint and wants to establish a reverse shell to their C2 server. The target network has strict egress filtering that only allows outbound traffic on ports 80, 443, and 53. To maximize the chances of success while blending in with legitimate traffic, which port should the tester configure their C2 listener to use?Post-exploitation and Lateral Movement
- 186.A tester uses Metasploit to gain a shell on a compromised host, then dumps credentials, escalates privileges, and pivots to reach internal systems that were not directly exposed to the internet. According to the Penetration Testing Execution Standard (PTES), which phase does this activity belong to?Engagement Management
- 187.During a physical security assessment, an attacker dressed as a delivery courier and carrying several large boxes approaches a badge-secured entrance behind an employee. The attacker asks the employee to hold the door open, claiming their hands are full and they cannot access their badge. The employee complies, and the attacker enters without ever presenting credentials. Which social engineering technique is illustrated?Attacks and Exploits
- 188.A tester on an internal network wants to intercept traffic between a target workstation and the default gateway. The tester runs arpspoof to send forged ARP replies to both devices, causing each to update its ARP cache with the attacker's MAC address. Which type of attack is being performed?Attacks and Exploits
- 189.A penetration tester is evaluating a web application that uses a search function. They notice that when they input `<script>alert('XSS')</script>` into the search box and submit, a pop-up window appears with 'XSS', and the malicious script is directly displayed in the browser's response without being stored on the server. Which type of attack has the tester identified?Attacks and Exploits
- 190.A tester crafts a URL such as http://shop.example.com/search?q=<script>alert(1)</script> and sends it to a victim. When the victim clicks the link, the search results page reflects the query string back into the HTML without encoding, and the script executes in the victim's browser. Which type of vulnerability is this?Attacks and Exploits
- 191.A penetration tester is performing an internal network assessment. They identify a critical server that uses NetBIOS Name Service (NBT-NS) for name resolution. The tester observes that when the server attempts to resolve a non-existent host, it broadcasts LLMNR and NBT-NS queries. Which tool and technique should the tester use to capture these requests and potentially obtain credentials?Attacks and Exploits
- 192.A tester runs `nmap -sU -p 53,161,500 10.10.10.5` and the scan reports all three ports as open|filtered. Which statement best explains this result and the appropriate next step?Vulnerability Discovery and Analysis
- 193.A penetration testing firm's SOW requires the final report to include both an executive summary and a prioritized remediation roadmap. During the engagement, the tester recovers several weak password hashes using hashcat that map to service accounts with domain administrator privileges. Which recommendation is MOST appropriate to include in the remediation section for this finding?Engagement Management
- 194.A penetration tester has successfully gained a foothold on a Linux web server. During post-exploitation, the tester discovers that the server has multiple network interfaces, one connected to the internal corporate network and another to a highly restricted DMZ segment. The tester wants to scan the DMZ segment from the compromised web server. Which of the following Nmap commands, when executed on the compromised server, would be MOST effective for this task while attempting to avoid detection by common IDS/IPS rules looking for full TCP connects?Post-exploitation and Lateral Movement
- 195.A penetration tester wants to test the strength of an organization's Active Directory credentials without triggering account lockout policies. The tester decides to try a small number of common passwords, such as 'Winter2024!', against every enabled user account in the domain. Which technique is the tester performing?Attacks and Exploits
- 196.A security firm has an ongoing five-year contract with a client that establishes payment terms, liability limits, and confidentiality obligations applicable to all future work. For each individual assessment, a separate document is created specifying the exact scope, deliverables, and schedule. What is the document that establishes the long-term overarching terms called?Engagement Management
- 197.A penetration tester has compromised a Windows domain controller and wants to exfiltrate sensitive files, but direct outbound connections are heavily monitored. The tester notices that the domain controller can resolve external DNS queries. To avoid detection, the tester decides to use DNS exfiltration. Which of the following tools or techniques is best suited for encoding and sending data via DNS queries?Post-exploitation and Lateral Movement
- 198.A penetration tester is performing reconnaissance against a target organization. They have identified several public-facing web servers and want to gather information about their SSL/TLS certificates, such as issuer, expiration dates, and supported cipher suites. Which Nmap script would be MOST effective for automatically extracting this type of information?Reconnaissance and Enumeration
- 199.A penetration tester is performing reconnaissance against a target organization's web infrastructure. They have identified the main domain and want to find as many associated subdomains as possible without directly interacting with the target's DNS servers. They need a tool that can leverage various public data sources to achieve this passively. Which tool is best suited for this purpose?Reconnaissance and Enumeration
- 200.A penetration tester is performing an internal network assessment. They have compromised a Linux workstation and want to identify other active hosts on the local subnet without generating excessive network traffic that might alert administrators. Which command-line tool and option combination is most appropriate for a quick and relatively quiet host discovery on a Linux system?Reconnaissance and Enumeration