CompTIA PT1-002 Exam Practice Questions (P. 1)
- Full Access (110 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #1
A client wants a security assessment company to perform a penetration test against its hot site. The purpose of the test is to determine the effectiveness of the defenses that protect against disruptions to business continuity. Which of the following is the MOST important action to take before starting this type of assessment?
- AEnsure the client has signed the SOW.Most Voted
- BVerify the client has granted network access to the hot site.
- CDetermine if the failover environment relies on resources not owned by the client.
- DEstablish communication and escalation procedures with the client.
Correct Answer:
C
C
send
light_mode
delete
Question #2
Performing a penetration test against an environment with SCADA devices brings additional safety risk because the:
- Adevices produce more heat and consume more power.
- Bdevices are obsolete and are no longer available for replacement.
- Cprotocols are more difficult to understand.Most Voted
- Ddevices may cause physical world effects.
Correct Answer:
C
Reference:
https://www.hindawi.com/journals/scn/2018/3794603/
C
Reference:
https://www.hindawi.com/journals/scn/2018/3794603/
send
light_mode
delete
Question #3
Which of the following documents describes specific activities, deliverables, and schedules for a penetration tester?
send
light_mode
delete
Question #4
A company hired a penetration-testing team to review the cyber-physical systems in a manufacturing plant. The team immediately discovered the supervisory systems and PLCs are both connected to the company intranet. Which of the following assumptions, if made by the penetration-testing team, is MOST likely to be valid?
- APLCs will not act upon commands injected over the network.
- BSupervisors and controllers are on a separate virtual network by default.
- CControllers will not validate the origin of commands.Most Voted
- DSupervisory systems will detect a malicious injection of code/commands.
Correct Answer:
C
C
send
light_mode
delete
Question #5
A new security firm is onboarding its first client. The client only allowed testing over the weekend and needed the results Monday morning. However, the assessment team was not able to access the environment as expected until Monday. Which of the following should the security company have acquired BEFORE the start of the assessment?
- AA signed statement of work
- BThe correct user accounts and associated passwords
- CThe expected time frame of the assessment
- DThe proper emergency contacts for the clientMost Voted
Correct Answer:
C
C
send
light_mode
delete
All Pages