CompTIA PT0-003 Exam Practice Questions (P. 1)
- Full Access (344 questions)
- One Year of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #1
A penetration tester wants to send a specific network packet with custom flags and sequence numbers to a vulnerable target. Which of the following should the tester use?
send
light_mode
delete
Question #2
Which of the following explains the reason a tester would opt to use DREAD over PTES during the planning phase of a penetration test?
- AThe tester is conducting a web application test.
- BThe tester is assessing a mobile application.
- CThe tester is evaluating a thick client application.
- DThe tester is creating a threat model.
send
light_mode
delete
Question #3
A penetration tester is performing a security review of a web application. Which of the following should the tester leverage to identify the presence of vulnerable open-source libraries?
send
light_mode
delete
Question #4
A penetration tester finds that an application responds with the contents of the /etc/passwd file when the following payload is sent:

Which of the following should the tester recommend in the report to best prevent this type of vulnerability?

Which of the following should the tester recommend in the report to best prevent this type of vulnerability?
- ADrop all excessive file permissions with chmod o-rwx.
- BEnsure the requests application access logs are reviewed frequently.
- CDisable the use of external entities.
- DImplement a WAF to filter all incoming requests.
send
light_mode
delete
Question #5
A penetration tester is conducting reconnaissance for an upcoming assessment of a large corporate client. The client authorized spear phishing in the rules of engagement. Which of the following should the tester do first when developing the phishing campaign?
send
light_mode
delete
Question #6
A penetration tester needs to test a very large number of URLs for public access. Given the following code snippet:

Which of the following changes is required?

Which of the following changes is required?
- AThe condition on line 6
- BThe method on line 5
- CThe import on line 1
- DThe delimiter in line 3
send
light_mode
delete
Question #7
During a penetration test, a tester captures information about an SPN account. Which of the following attacks requires this information as a prerequisite to proceed?
send
light_mode
delete
Question #8
While performing an internal assessment, a tester uses the following command: crackmapexec smb 192.168.1.0/24 -u user.txt -p Summer123@
Which of the following is the main purpose of the command?
Which of the following is the main purpose of the command?
- ATo perform a pass-the-hash attack over multiple endpoints within the internal network
- BTo perform common protocol scanning within the internal network
- CTo perform password spraying on internal systems
- DTo execute a command in multiple endpoints at the same time
send
light_mode
delete
Question #9
A penetration testing team needs to determine whether it is possible to disrupt the wireless communications for PCs deployed in the client's offices. Which of the following techniques should the penetration tester leverage?
send
light_mode
delete
Question #10
Which of the following tasks would ensure the key outputs from a penetration test are not lost as part of the cleanup and restoration activities?
- APreserving artifacts
- BReverting configuration changes
- CKeeping chain of custody
- DExporting credential data
send
light_mode
delete
All Pages
