CompTIA PT0-001 Exam Practice Questions (P. 5)
- Full Access (196 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #21
A penetration tester is able to move laterally throughout a domain with minimal roadblocks after compromising a single workstation. Which of the following mitigation strategies would be BEST to recommend in the report? (Select THREE).
- ARandomize local administrator credentials for each machine.Most Voted
- BDisable remote logons for local administrators.
- CRequire multifactor authentication for all logins.Most Voted
- DIncrease minimum password complexity requirements.
- EApply additional network access control.Most Voted
- FEnable full-disk encryption on every workstation.
- GSegment each host into its own VLAN.
Correct Answer:
CDE
CDE
send
light_mode
delete
Question #22
A security consultant is trying to attack a device with a previously identified user account.

Which of the following types of attacks is being executed?

Which of the following types of attacks is being executed?
- ACredential dump attack
- BDLL injection attack
- CReverse shell attack
- DPass the hash attackMost Voted
Correct Answer:
D
D
send
light_mode
delete
Question #23
A malicious user wants to perform an MITM attack on a computer. The computer network configuration is given below:
IP: 192.168.1.20 -
NETMASK: 255.255.255.0 -
DEFAULT GATEWAY: 192.168.1.254 -
DHCP: 192.168.1.253 -
DNS: 192.168.10.10, 192.168.20.10
Which of the following commands should the malicious user execute to perform the MITM attack?
IP: 192.168.1.20 -
NETMASK: 255.255.255.0 -
DEFAULT GATEWAY: 192.168.1.254 -
DHCP: 192.168.1.253 -
DNS: 192.168.10.10, 192.168.20.10
Which of the following commands should the malicious user execute to perform the MITM attack?
- Aarpspoof -c both -r -t 192.168.1.1 192.168.1.20
- Barpspoof -t 192.168.1.20 192.168.1.254Most Voted
- Carpspoof -c both -t 192.168.1.20 192.168.1.253
- Darpspoof -r -t 192.168.1.253 192.168.1.20
Correct Answer:
B
Reference:
https://www.hackers-arise.com/single-post/2017/07/25/Man-the-Middle-MiTM-Attack-with-ARPspoofing
B
Reference:
https://www.hackers-arise.com/single-post/2017/07/25/Man-the-Middle-MiTM-Attack-with-ARPspoofing
send
light_mode
delete
Question #24
A client has requested an external network penetration test for compliance purposes. During discussion between the client and the penetration tester, the client expresses unwillingness to add the penetration tester's source IP addresses to the client's IPS whitelist for the duration of the test. Which of the following is the
BEST argument as to why the penetration tester's source IP addresses should be whitelisted?
BEST argument as to why the penetration tester's source IP addresses should be whitelisted?
- AWhitelisting prevents a possible inadvertent DoS attack against the IPS and supporting log-monitoring systems.
- BPenetration testing of third-party IPS systems often requires additional documentation and authorizations; potentially delaying the time-sensitive test.
- CIPS whitelisting rules require frequent updates to stay current, constantly developing vulnerabilities and newly discovered weaknesses.
- DTesting should focus on the discovery of possible security issues across all in-scope systems, not on determining the relative effectiveness of active defenses such as an IPS.Most Voted
Correct Answer:
D
D
send
light_mode
delete
Question #25
An energy company contracted a security firm to perform a penetration test of a power plant, which employs ICS to manage power generation and cooling. Which of the following is a consideration unique to such an environment that must be made by the firm when preparing for the assessment?
- ASelection of the appropriate set of security testing tools
- BCurrent and load ratings of the ICS components
- CPotential operational and safety hazardsMost Voted
- DElectrical certification of hardware used in the test
Correct Answer:
A
A
send
light_mode
delete
All Pages