CompTIA PenTest+ - PT0-003 Exam Practice Test

A penetration tester wants to verify whether passwords from a leaked password list can be used to access an SSH server as a legitimate user.
Which of the following is the most appropriate tool for this task?
Correct Answer: C
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
Which of the following protocols would a penetration tester most likely utilize to exfiltrate data covertly and evade detection?
Correct Answer: B
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
An external legal firm is conducting a penetration test of a large corporation. Which of the following would be most appropriate for the legal firm to use in the subject line of a weekly email update?
Correct Answer: B
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
A penetration tester is getting ready to conduct a vulnerability scan as part of the testing process.
The tester will evaluate an environment that consists of a container orchestration cluster. Which of the following tools should the tester use to evaluate the cluster?
Correct Answer: A
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
A penetration tester scans for services to exploit and finds that a web server is running on TCP port 443 on IP telephony devices. Which of the following attack techniques should the tester try first?
Correct Answer: D
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
A consultant starts a network penetration test. The consultant uses a laptop that is hardwired to the network to try to assess the network with the appropriate tools. Which of the following should the consultant engage first?
Correct Answer: B
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
A penetration tester is attempting to discover vulnerabilities in a company's web application.
Which of the following tools would most likely assist with testing the security of the web application?
Correct Answer: D
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
A penetration tester gains shell access to a Windows host. The tester needs to permanently turn off protections in order to install additional payload. Which of the following commands is most appropriate?
Correct Answer: A
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
A penetration tester gains access to a chrooted environment and runs service --status-all on a target host. The tester reviews the following output:
[ + ] cron
[ + ] dhcp
[ - ] tomcat
[ - ] xserver
[ + ] ssh
The only other commands that the tester can execute are ps, nc, tcpdump, and crontab.
Which of the following is the best method to maintain persistence?
Correct Answer: D
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
A tester compromises a shared host that is manually audited every week due to the absence of a SIEM.
Which of the following is the best way to reduce the chances of being detected?
Correct Answer: D
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
A penetration testing team has gained access to an organization's data center, but the team requires more time to test the attack strategy. Which of the following wireless attack techniques would be the most successful in preventing unintended interruptions?
Correct Answer: C
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
During an assessment, a penetration tester compromises some machines but finds that none of the accounts have sufficient access to the target HR database server. In order to enumerate accounts with sufficient permissions, the tester wants to model an attack path before taking further action. Which of the following tools should the tester use to meet this objective?
Correct Answer: A
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
A penetration tester conducts reconnaissance and looks for ways to obtain administrator emails to use in a phishing campaign. Which of the following tools should the penetration tester use?
Correct Answer: B
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).
During an engagement, a penetration tester discovers a web application vulnerability that affects multiple devices. The tester creates and runs the following script:

Which of the following best describes what the tester is attempting to do?
Correct Answer: C
Explanation: Only visible for ExamsLabs members. You can sign-up / login (it's free).