Step2Study
IT & TechnologyPT0-003100% Free

CompTIA PenTest+ (PT0-003)

Practice bank
242 Qs
Real exam
90 Qs
Time limit
165 min
Passing
750 on a 100–900 scale

Exam blueprint

Engagement Management
13%
Reconnaissance and Enumeration
21%
Vulnerability Discovery and Analysis
17%
Attacks and Exploits
35%
Post-exploitation and Lateral Movement
14%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 165 min · pass 83% · 242 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Part of a learning path

Study with friends

Challenge a friend to beat your score.

CompTIA PenTest+ (PT0-003) practice test questions

Sample questions from the 242-question bank, with answers and explanations.

All questions
  1. 1. A penetration tester is performing OSINT against a client organization. They want to find email addresses associated with the target domain. Which tool is specifically designed to harvest email addresses, employee names, and subdomains from public sources like search engines, PGP key servers, and SHODAN?

    Reconnaissance and Enumeration

    • A. theHarvester
    • B. Recon-ng
    • C. SpiderFoot
    • D. Maltego
    Show answer

    A. theHarvester

    theHarvester is a dedicated OSINT tool specifically designed to gather email addresses, subdomains, hostnames, employee names, and open ports from various public sources, including search engines and PGP key servers.

  2. 2. A penetration tester discovers a web application that allows users to upload profile pictures. Upon uploading a file named `image.php.jpg`, the server processes it and saves it as `image.php.jpg` in a publicly accessible directory. When the tester navigates to the URL of the uploaded file, a 'PHP code execution' error is displayed. Which web application attack is MOST likely indicated by this behavior?

    Attacks and Exploits

    • A. Server-Side Request Forgery (SSRF)
    • B. File Upload Vulnerability
    • C. SQL Injection
    • D. Cross-Site Scripting (XSS)
    Show answer

    B. File Upload Vulnerability

    The ability to upload a file with a `.php` extension (even if disguised with `.jpg`) and then trigger PHP code execution (indicated by the error) is a clear sign of a file upload vulnerability. This allows an attacker to bypass file type restrictions and execute arbitrary code on the server.

  3. 3. A penetration tester's initial exploitation attempts using a staged Meterpreter payload consistently fail because the target network's firewall terminates outbound connections before the second stage can be downloaded. Which type of payload should the tester select to overcome this issue?

    Vulnerability Discovery and Analysis

    • A. A staged payload such as windows/meterpreter/reverse_tcp
    • B. A NOP generator payload
    • C. A stageless payload such as windows/meterpreter_reverse_tcp
    • D. An auxiliary scanner module
    Show answer

    C. A stageless payload such as windows/meterpreter_reverse_tcp

    Stageless (single) payloads, denoted with an underscore in Metasploit naming (e.g., windows/meterpreter_reverse_tcp), embed the entire payload in one package so no second-stage download is required, making them resilient to firewalls that block staged transfers. Staged payloads rely on downloading a second component, which fails under this restriction; auxiliary modules and NOP generators are unrelated to this problem.

  4. 4. A password policy requires exactly 8 characters formatted as one uppercase letter, followed by five lowercase letters, followed by two digits. Using a hashcat mask attack with the mask ?u?l?l?l?l?l?d?d, how many total password combinations must be tested?

    Attacks and Exploits

    • A. 26^8 ≈ 2.09 × 10^11
    • B. 95^8 ≈ 6.63 × 10^15
    • C. 62^8 ≈ 2.18 × 10^14
    • D. 26 × 26^5 × 10^2 ≈ 3.09 × 10^10
    Show answer

    D. 26 × 26^5 × 10^2 ≈ 3.09 × 10^10

    The mask ?u?l?l?l?l?l?d?d specifies one uppercase (26 options), five lowercase (26 options each), and two digits (10 options each): 26 × 26^5 × 10^2 = 26 × 11,881,376 × 100 = 30,891,577,600 ≈ 3.09 × 10^10. The other options represent brute-forcing the full printable set (95^8), all alphanumeric characters (62^8), or all uppercase-only (26^8), none of which match the known character-position structure exploited by the mask.

  5. 5. A penetration tester wants to quickly determine which ports are open on a target network while completing as few full TCP handshakes as possible to reduce log noise. Which Nmap scan type should the tester use?

    Vulnerability Discovery and Analysis

    • A. -sU (UDP scan)
    • B. -sT (TCP connect scan)
    • C. -sS (SYN scan)
    • D. -sA (ACK scan)
    Show answer

    C. -sS (SYN scan)

    A SYN scan (-sS) sends a SYN packet and, upon receiving a SYN/ACK, immediately sends a RST instead of completing the handshake with an ACK, making it faster and stealthier than a full connect scan.

  6. 6. A penetration tester is performing initial reconnaissance against a target organization. They want to identify publicly accessible subdomains associated with the main domain without directly interacting with the target's servers. Which of the following techniques would be most effective for this purpose?

    Reconnaissance and Enumeration

    • A. Querying Certificate Transparency logs.
    • B. Running a Metasploit auxiliary scanner module for subdomain enumeration.
    • C. Using 'dig axfr' against the target's DNS server.
    • D. Performing a full TCP connect scan on common web ports.
    Show answer

    A. Querying Certificate Transparency logs.

    Querying Certificate Transparency logs is a passive method to discover subdomains. These logs record all SSL/TLS certificates issued, which often include subdomains, without directly interacting with the target's infrastructure.

  7. 7. A penetration tester is evaluating a wireless network. They observe that the network uses WPA2-PSK encryption and has Wi-Fi Protected Setup (WPS) enabled. The tester wants to exploit a known vulnerability in WPS to gain access to the network without needing to capture a full WPA2 handshake. Which tool and attack method would be most effective for this scenario?

    Attacks and Exploits

    • A. Kismet to identify hidden SSIDs and then deauthenticate clients.
    • B. Hashcat with a rule-based attack on a PMKID.
    • C. Aircrack-ng with a dictionary attack against a captured WPA2 handshake.
    • D. Reaver to brute-force the WPS PIN.
    Show answer

    D. Reaver to brute-force the WPS PIN.

    WPS has a known design flaw that allows for the brute-forcing of its PIN in two halves, significantly reducing the keyspace. Reaver is a tool specifically designed to exploit this vulnerability, making it the most effective choice for gaining access to a WPA2-PSK network with WPS enabled without needing to capture a full handshake.

  8. 8. During contract negotiation, a client's legal team requests a clause specifying that the client will assume responsibility for legal costs and damages if a third party sues the penetration testing firm as a direct result of testing activities that were explicitly authorized within the agreed scope. Which type of clause is being requested?

    Engagement Management

    • A. Indemnification clause
    • B. Non-disclosure clause
    • C. Limitation of liability clause
    • D. Force majeure clause
    Show answer

    A. Indemnification clause

    An indemnification clause obligates one party (here, the client) to cover the other party's (the testing firm's) legal costs and damages arising from claims tied to authorized actions performed under the contract. A limitation of liability clause instead caps the testing firm's own financial exposure rather than shifting third-party claim costs to the client, an NDA governs confidentiality, and a force majeure clause addresses performance excuses due to uncontrollable events like natural disasters.

  9. 9. A penetration tester is evaluating a web application that allows users to submit support tickets. The application includes a file upload feature for attachments. The tester attempts to upload a file named `shell.php` containing a simple PHP web shell. However, the application rejects the upload with an error message: 'Invalid file type.' The tester then renames the file to `shell.php.jpg` and uploads it successfully. When attempting to access the uploaded file via a direct URL, the web server executes the PHP code, granting the tester remote code execution. Which web application vulnerability did the tester exploit?

    Attacks and Exploits

    • A. SQL Injection
    • B. File Upload Vulnerability
    • C. Cross-Site Scripting (XSS)
    • D. Server-Side Request Forgery (SSRF)
    Show answer

    B. File Upload Vulnerability

    The tester exploited a file upload vulnerability where the application's file type validation was bypassed by simply changing the file extension. This allowed the malicious PHP code to be uploaded and executed by the web server.

  10. 10. A penetration tester is performing reconnaissance on a target company and wants to identify publicly exposed Git repositories that might contain sensitive information. Which specialized OSINT tool is designed to search GitHub and other code hosting platforms for specific keywords or patterns to uncover such repositories?

    Reconnaissance and Enumeration

    • A. TruffleHog
    • B. Sublist3r
    • C. Maltego
    • D. Shodan
    Show answer

    A. TruffleHog

    TruffleHog is specifically designed to scan Git repositories (and other sources) for high-entropy strings and patterns indicative of sensitive data like API keys, credentials, or configuration files, making it ideal for finding publicly exposed secrets in code.

  11. 11. A pentester is performing cloud discovery against a client's AWS environment as part of the reconnaissance phase. The client is concerned about publicly exposed object storage containing sensitive data. Which approach would MOST effectively identify misconfigured or publicly accessible storage buckets?

    Vulnerability Discovery and Analysis

    • A. Launching a Burp Suite active scan against the AWS Management Console login page
    • B. Running hashcat against exported IAM access keys
    • C. Running an Nmap version scan against known AWS IP ranges
    • D. Using a purpose-built enumeration tool such as S3Scanner to identify bucket names and permissions
    Show answer

    D. Using a purpose-built enumeration tool such as S3Scanner to identify bucket names and permissions

    Tools like S3Scanner are designed specifically to enumerate S3 bucket names (via naming conventions, DNS, or brute force) and check their permissions/ACLs for public exposure. Nmap version scanning, hashcat, and Burp active scanning are not suited to identifying misconfigured object storage.

  12. 12. A tester needs to quickly determine which hosts are online across a 254-address subnet before running detailed service scans, without sending any TCP/UDP port probes to the targets. Which nmap command should the tester run?

    Attacks and Exploits

    • A. nmap -sn 192.168.1.0/24
    • B. nmap -sV 192.168.1.0/24
    • C. nmap -A 192.168.1.0/24
    • D. nmap -sS 192.168.1.0/24
    Show answer

    A. nmap -sn 192.168.1.0/24

    The -sn flag performs a host discovery (ping) scan and disables port scanning entirely, making it ideal for quickly identifying live hosts. -sS, -sV, and -A all involve port scanning and are slower/more intrusive.

  13. 13. A tester attempting to compromise a WPA2-PSK wireless network notices the target access point has WPS enabled. The tester uses the reaver tool to systematically try PIN combinations against the AP's WPS interface. What is the primary weakness in the WPS protocol that this attack exploits?

    Attacks and Exploits

    • A. WPS uses the same encryption key for all connected clients
    • B. The 8-digit WPS PIN is validated in two separate halves, reducing the effective keyspace
    • C. WPS transmits the passphrase in cleartext during association
    • D. WPS PINs are stored unencrypted in the access point's firmware
    Show answer

    B. The 8-digit WPS PIN is validated in two separate halves, reducing the effective keyspace

    WPS validates the 8-digit PIN in two halves (the first 4 digits and the last 3 digits, since the 8th digit is a checksum), and the AP confirms each half separately, drastically reducing the brute-force keyspace from 10^8 to roughly 11,000 combinations, which is the core flaw tools like reaver exploit.

  14. 14. A penetration tester has successfully gained access to a Windows server within a client's internal network. During the post-exploitation phase, the tester aims to maintain persistent access. Which of the following methods, when implemented, would provide the MOST covert and resilient form of persistence?

    Post-exploitation and Lateral Movement

    • A. Injecting a malicious DLL into a legitimate system process that re-establishes C2.
    • B. Establishing a scheduled task that executes a reverse shell payload every hour.
    • C. Creating a new administrator account with a generic username and password.
    • D. Modifying the 'Run' registry key to launch a backdoor upon user login.
    Show answer

    A. Injecting a malicious DLL into a legitimate system process that re-establishes C2.

    Injecting a malicious DLL into a legitimate system process is highly covert as it blends with normal operations and is resilient because it can be re-established even if the initial process is terminated. It's less likely to be detected by standard monitoring tools compared to other methods.

  15. 15. A penetration tester is performing a web application assessment and encounters a login form. The tester suspects the application might be vulnerable to command injection. Which of the following inputs, when entered into a username field, would be the MOST indicative of a successful command injection vulnerability on a Linux-based server?

    Attacks and Exploits

    • A. admin' OR 1=1--
    • B. <script>alert('XSS')</script>
    • C. admin; cat /etc/passwd
    • D. admin' UNION SELECT NULL,NULL,NULL--
    Show answer

    C. admin; cat /etc/passwd

    The input `admin; cat /etc/passwd` attempts to terminate the 'admin' string with a semicolon (;) and then execute the `cat /etc/passwd` command. If successful, this would display the contents of the password file, which is a clear indicator of a command injection vulnerability on a Linux system.

  16. 16. A penetration tester has obtained a password hash from a compromised system and needs to crack it using a wordlist. The hash is identified as an NTLM hash. Which hashcat mode would be used to perform this cracking operation?

    Reconnaissance and Enumeration

    • A. hashcat -m 1000 -a 0 <hash_file> <wordlist>
    • B. hashcat -m 500 -a 0 <hash_file> <wordlist>
    • C. hashcat -m 1800 -a 0 <hash_file> <wordlist>
    • D. hashcat -m 0 -a 0 <hash_file> <wordlist>
    Show answer

    A. hashcat -m 1000 -a 0 <hash_file> <wordlist>

    Hashcat mode 1000 is specifically designated for NTLM hashes. The '-a 0' flag specifies a dictionary (wordlist) attack, which is appropriate for cracking hashes with a given wordlist.

  17. 17. A penetration tester has gained a low-privileged shell on a Linux server. During the post-exploitation phase, the tester identifies that the 'find' command is installed with the SUID bit set for the 'root' user. Which of the following commands would allow the tester to escalate privileges to root?

    Post-exploitation and Lateral Movement

    • A. find / -exec chmod +s /bin/bash \;
    • B. find . -exec cp /bin/bash /tmp/shell \;
    • C. find . -exec /bin/sh -p \; -quit
    • D. find / -exec sudo /bin/bash \;
    Show answer

    C. find . -exec /bin/sh -p \; -quit

    When a command like 'find' has the SUID bit set for root, it runs with root privileges. Using '-exec' allows arbitrary commands to be executed within the context of 'find'. Executing '/bin/sh -p' with the SUID bit preserves the effective user ID, providing a root shell.

  18. 18. According to the Penetration Testing Execution Standard (PTES), during which phase do the tester and client formally agree on scope, objectives, and rules of engagement before any technical activity begins?

    Engagement Management

    • A. Intelligence gathering
    • B. Pre-engagement interactions
    • C. Post-exploitation
    • D. Threat modeling
    Show answer

    B. Pre-engagement interactions

    PTES's first phase, pre-engagement interactions, is where scope, goals, RoE, and legal documents are established before any scanning or exploitation occurs.

  19. 19. A penetration tester is analyzing a web application using Burp Suite and observes that a specific parameter in a GET request, `?id=123`, consistently returns data from a database. When attempting to manipulate this parameter to `?id=123 AND 1=1` and `?id=123 AND 1=2`, the application behaves identically, but when a single quote is introduced, `?id=123'`, the application returns a generic error page. The tester suspects a SQL injection vulnerability. Which of the following Burp Suite tools would be most effective for systematically identifying the specific database type and extracting data?

    Vulnerability Discovery and Analysis

    • A. Burp Scanner's active scan for SQL injection.
    • B. Burp Sequencer to analyze randomness of session tokens.
    • C. Burp Repeater with manual payload modification.
    • D. Burp Intruder with a 'Sniper' attack type and SQLi payloads.
    Show answer

    D. Burp Intruder with a 'Sniper' attack type and SQLi payloads.

    Burp Intruder, configured with a 'Sniper' attack type, is ideal for systematically testing a single injection point with a large set of SQL injection payloads. This allows for observing subtle differences in responses (e.g., error messages, content length, timing) that indicate the database type and can be used for data extraction.

  20. 20. During an authorized physical security assessment, a tester wants to covertly capture the RF signal from an employee's proximity access card while standing nearby, then write that data to a blank card to test the badge reader's access controls. Which tool is best suited for this task?

    Vulnerability Discovery and Analysis

    • A. Lock pick set
    • B. Proxmark3
    • C. Kismet
    • D. Wireshark
    Show answer

    B. Proxmark3

    Proxmark3 is a specialized RFID research device capable of sniffing, reading, and cloning proximity card credentials, making it the appropriate tool for covertly capturing and duplicating badge data.

  21. 21. A tester extracted a large set of NTLM password hashes from a compromised domain controller during vulnerability validation. To efficiently crack as many hashes as possible by leveraging known corporate password patterns (e.g., 'Company2024!'), which hashcat attack configuration would be MOST effective as a first pass?

    Vulnerability Discovery and Analysis

    • A. A combinator attack merging two large generic wordlists (-a 1)
    • B. A pure brute-force attack across the full character set (-a 3)
    • C. A straight dictionary attack with a rule file (-a 0 -r rules.rule)
    • D. An association attack tied to username fields (-a 9)
    Show answer

    C. A straight dictionary attack with a rule file (-a 0 -r rules.rule)

    A dictionary attack combined with rule-based mangling (-a 0 -r) efficiently generates common variations (capitalization, appended numbers/symbols) of known password patterns, making it far faster and more targeted than brute-forcing the entire keyspace. Combinator and association attacks serve different, less efficient purposes for this specific goal.

  22. 22. A penetration tester is performing reconnaissance against a client's web application. They discover a login form and suspect it might be vulnerable to username enumeration. They want to systematically test common usernames against the form to see if the application responds differently to valid versus invalid usernames. Which Burp Suite tool is best suited for this task?

    Reconnaissance and Enumeration

    • A. Burp Repeater
    • B. Burp Sequencer
    • C. Burp Intruder
    • D. Burp Decoder
    Show answer

    C. Burp Intruder

    Burp Intruder is specifically designed for automating repetitive tasks, such as iterating through a list of payloads (like usernames) and analyzing the application's responses. This makes it ideal for username enumeration attacks.

  23. 23. A penetration tester has compromised a web server and established a Meterpreter session. The tester identifies that the server is running an outdated version of Apache Tomcat. To establish persistence, the tester plans to deploy a malicious WAR file. Which Metasploit module is best suited for this task?

    Post-exploitation and Lateral Movement

    • A. exploit/multi/script/web_delivery
    • B. auxiliary/scanner/http/tomcat_mgr_login
    • C. exploit/multi/http/tomcat_mgr_deploy
    • D. post/multi/manage/shell_to_meterpreter
    Show answer

    C. exploit/multi/http/tomcat_mgr_deploy

    The `exploit/multi/http/tomcat_mgr_deploy` module is specifically designed to exploit weak credentials or vulnerabilities in the Tomcat Manager application to deploy a malicious WAR file, which can then be used to establish persistence.

  24. 24. During a web application assessment, a tester submits a product ID value of 5' UNION SELECT null,null,null-- - and observes the page display three columns of data that match the number of columns in the original query. Which type of SQL injection technique is the tester using?

    Attacks and Exploits

    • A. Union-based SQL injection
    • B. Boolean-based blind SQL injection
    • C. Stored cross-site scripting
    • D. Time-based blind SQL injection
    Show answer

    A. Union-based SQL injection

    Union-based SQL injection appends a UNION SELECT statement to combine the results of an injected query with the original query, requiring the attacker to match the column count and often use NULL placeholders to discover it, exactly as described.

  25. 25. A tester compromises a domain controller and uses Mimikatz to extract the krbtgt account's NTLM hash via a DCSync attack. The tester then forges a Kerberos ticket-granting ticket with arbitrary group memberships and a ten-year expiration, allowing continued domain admin access even after all user passwords are reset. Which attack technique does this describe?

    Attacks and Exploits

    • A. Kerberoasting
    • B. Pass-the-hash attack
    • C. Golden ticket attack
    • D. Silver ticket attack
    Show answer

    C. Golden ticket attack

    Forging a TGT using the krbtgt account's hash creates a golden ticket, granting near-unlimited, long-lived access to any resource in the domain regardless of subsequent password changes, since the krbtgt key controls the entire Kerberos trust.

CompTIA PenTest+ (PT0-003) flashcards

Tap a card to flip it. 192 flashcards in the full deck.

  • theHarvester

    Flip card

    An OSINT tool used to gather public information (emails, subdomains, hostnames, employee names, banners, open ports) from various public sources for a given target domain or company name.

    • Automates collection of email addresses and subdomains.
    • Leverages search engines (Google, Bing, Baidu), PGP key servers, LinkedIn, etc.
    • Useful for initial reconnaissance to build a target profile.
    Study this card →
  • File Upload Vulnerability

    Flip card

    A security flaw in a web application that allows an attacker to upload malicious files (e.g., web shells, scripts) to the server, potentially leading to remote code execution, defacement, or other compromise.

    • Occurs due to insufficient validation of file types, content, or size.
    • Can be exploited by uploading files with double extensions (e.g., .php.jpg) or content type manipulation.
    • Often leads to Remote Code Execution (RCE) if the uploaded file is executed by the server.
    Study this card →
  • Staged vs. Stageless Metasploit Payloads

    Flip card

    Staged payloads send a small stager that downloads the full payload afterward (slash notation), while stageless payloads deliver the entire payload in a single package (underscore notation).

    • Staged: windows/meterpreter/reverse_tcp
    • Stageless: windows/meterpreter_reverse_tcp
    • Stageless payloads are larger but more firewall-resilient
    Study this card →
  • Hashcat Mask Attack

    Flip card

    A targeted brute-force technique that defines the character set for each position in a password based on a known or suspected pattern, drastically reducing keyspace versus full brute force.

    • ?u = uppercase, ?l = lowercase, ?d = digit, ?s = special
    • Keyspace = product of charset sizes per position
    • Far more efficient than full charset brute force when policy/pattern is known
    Study this card →
  • Nmap SYN Scan (-sS)

    Flip card

    A half-open TCP scan that sends SYN packets and resets the connection before completion, providing fast, low-footprint port discovery.

    • Also called a 'half-open' scan
    • Requires raw socket privileges (root/admin)
    • Default scan type when running Nmap with elevated privileges
    Study this card →
  • Certificate Transparency (CT) Logs

    Flip card

    Publicly auditable logs that record all SSL/TLS certificates issued by Certificate Authorities. They are a valuable resource for passive subdomain enumeration.

    • Maintains a public record of all issued SSL/TLS certificates.
    • Can reveal subdomains associated with an organization's primary domain.
    • A passive reconnaissance technique as it doesn't interact with the target.
    Study this card →
  • WPS PIN Brute-Force (Reaver)

    Flip card

    An attack exploiting a design flaw in Wi-Fi Protected Setup (WPS) that allows for the brute-forcing of the 8-digit PIN in two halves, significantly reducing the time required to recover the WPA2-PSK passphrase.

    • Exploits a weak authentication mechanism in WPS.
    • Typically uses the tool Reaver or similar.
    • Can recover the WPA2-PSK passphrase within hours, even with strong passwords.
    Study this card →
  • Indemnification Clause

    Flip card

    A contract provision where one party agrees to compensate the other for losses, damages, or legal costs arising from claims related to actions performed under the agreement.

    • Often shields the testing firm from third-party lawsuits stemming from authorized testing
    • Differs from limitation of liability, which caps the tester's own exposure
    • Commonly paired with authorization letters and NDAs in the SOW/MSA
    Study this card →
  • TruffleHog

    Flip card

    A tool designed to search through Git repositories, commit history, and other data sources to find high-entropy strings, patterns, or sensitive data like API keys, credentials, and configuration files.

    • Scans Git repositories (GitHub, GitLab, Bitbucket, local).
    • Identifies sensitive data based on entropy and predefined patterns.
    • Useful for discovering accidentally exposed secrets in code.
    Study this card →
  • Cloud Storage Enumeration

    Flip card

    The process of discovering and assessing cloud object storage (e.g., AWS S3, Azure Blob) for public exposure or misconfigured access controls.

    • Tools: S3Scanner, Bucket Finder, ScoutSuite, CloudBrute
    • Checks bucket naming, DNS entries, and ACL/policy settings
    • Common finding: publicly readable/writable buckets exposing sensitive data
    Study this card →
  • nmap Host Discovery (-sn)

    Flip card

    An nmap scan mode that identifies live hosts on a network using ICMP, ARP, or TCP/UDP probes without scanning any ports.

    • -sn = 'no port scan', formerly called -sP
    • Useful for fast network sweeps before deeper scans
    • Falls back to ARP requests on local subnets for speed
    Study this card →
  • WPS PIN Brute-Force Vulnerability

    Flip card

    A design flaw in WPS where the 8-digit PIN is verified in two separate halves, allowing attackers like reaver to brute-force the PIN in roughly 11,000 attempts instead of 100 million.

    • 8th PIN digit is a checksum, leaving 7 unknown digits
    • AP validates first 4 digits and last 3 digits separately
    • Reduces brute-force keyspace from 10^8 to about 11,000 combinations
    Study this card →
  • DLL Injection for Persistence

    Flip card

    A technique to maintain persistence on a compromised system by forcing a legitimate process to load and execute a malicious Dynamic Link Library (DLL).

    • Malicious code runs within a trusted process's memory space.
    • Difficult to detect as it mimics legitimate system behavior.
    • Can re-establish command and control (C2) even if parent process terminates.
    Study this card →
  • Command Injection

    Flip card

    A web vulnerability that allows an attacker to execute arbitrary operating system commands on the server running a web application, typically by injecting commands into user-supplied input.

    • Occurs when an application passes unsanitized user input to a system shell.
    • Attackers can use various shell metacharacters (e.g., ;, &&, ||, |, `) to chain commands.
    • Can lead to full system compromise if executed with sufficient privileges.
    Study this card →
  • Hashcat NTLM Cracking

    Flip card

    Using Hashcat, a powerful password cracking utility, to break NTLM (NT LAN Manager) password hashes, typically through dictionary attacks, brute-force, or hybrid attacks.

    • NTLM hashes are commonly found in Windows environments.
    • Hashcat mode '1000' is used for NTLM hashes.
    • The '-a 0' flag specifies a dictionary attack.
    Study this card →
  • SUID Binary Exploitation

    Flip card

    Exploiting legitimate binaries with the SUID bit set to gain elevated privileges, typically by executing a shell or another privileged command.

    • SUID bit allows a program to run with the permissions of its owner.
    • If a root-owned SUID binary can execute arbitrary commands, it can lead to privilege escalation.
    • Common SUID binaries to check include 'find', 'nmap', 'vi', 'more', 'less'.
    Study this card →
  • PTES Pre-engagement Interactions

    Flip card

    The first phase of PTES where scope, objectives, legal agreements, and RoE are established between tester and client.

    • Occurs before any technical testing
    • Includes defining scope and success criteria
    • Sets legal groundwork (contracts, NDA, RoE)
    Study this card →
  • SQL Injection (SQLi)

    Flip card

    A web security vulnerability that allows an attacker to interfere with the queries that an application makes to its database, potentially leading to unauthorized data access, modification, or deletion.

    • Occurs when user-supplied input is insecurely incorporated into SQL queries.
    • Can be detected by injecting special characters (e.g., single quote, double dash).
    • Blind SQLi relies on timing or boolean responses; error-based SQLi returns database errors.
    Study this card →
  • Proxmark3

    Flip card

    A portable RFID research tool capable of reading, sniffing, and cloning low- and high-frequency proximity card credentials.

    • Supports both 125kHz (low-freq) and 13.56MHz (high-freq) cards
    • Used in physical penetration tests to clone employee badges
    • Requires proximity to the target card to capture signal
    Study this card →
  • Hashcat Attack Modes

    Flip card

    Hashcat supports multiple attack modes (-a) that define how candidate passwords are generated to match hashes, ranging from dictionary-based to brute-force approaches.

    • -a 0: straight dictionary attack
    • -a 3: brute-force/mask attack
    • -a 0 -r applies rule files to mutate dictionary words efficiently
    Study this card →
  • Burp Intruder

    Flip card

    Burp Intruder is a powerful tool within Burp Suite used for automating customized attacks against web applications, such as brute-force attacks, dictionary attacks, and username enumeration.

    • Automates repetitive requests
    • Supports various attack types (e.g., Sniper, Battering Ram)
    • Analyzes response differences for enumeration/vulnerability discovery
    Study this card →
  • Tomcat WAR File Deployment for Persistence

    Flip card

    Deploying a malicious Web Application Archive (WAR) file to a vulnerable Apache Tomcat server to maintain access or establish a backdoor.

    • Requires access to Tomcat Manager or a vulnerability to upload WAR files.
    • A WAR file can contain a web shell or a reverse shell payload.
    • Metasploit provides modules for automating this process.
    Study this card →
  • Union-Based SQL Injection

    Flip card

    An injection technique that appends a UNION SELECT statement to an existing query so attacker-chosen data is returned in the application's output.

    • Requires matching the number of columns in the original query
    • NULL is often used as a placeholder for unknown data types
    • Effective when application output is directly visible to the tester
    Study this card →
  • Golden Ticket Attack

    Flip card

    A Kerberos attack where an adversary uses the krbtgt account's NTLM hash to forge a Ticket Granting Ticket, granting persistent, domain-wide access that survives password resets.

    • Requires the krbtgt hash, often obtained via DCSync
    • Grants access to any service in the domain as any user
    • Remediated by resetting the krbtgt password twice
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.