Winter Special Sale Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 2493360325

Good News !!! PT0-002 CompTIA PenTest+ Certification Exam is now Stable and With Pass Result

PT0-002 Practice Exam Questions and Answers

CompTIA PenTest+ Certification Exam

Last Update 1 day ago
Total Questions : 464

CompTIA PenTest+ Certification Exam is stable now with all latest exam questions are added 1 day ago. Incorporating PT0-002 practice exam questions into your study plan is more than just a preparation strategy.

PT0-002 exam questions often include scenarios and problem-solving exercises that mirror real-world challenges. Working through PT0-002 dumps allows you to practice pacing yourself, ensuring that you can complete all CompTIA PenTest+ Certification Exam practice test within the allotted time frame.

PT0-002 PDF

PT0-002 PDF (Printable)
$50
$124.99

PT0-002 Testing Engine

PT0-002 PDF (Printable)
$58
$144.99

PT0-002 PDF + Testing Engine

PT0-002 PDF (Printable)
$72.8
$181.99
Question # 1

Which of the following are the MOST important items to include in the final report for a penetration test? (Choose two.)

Options:

A.  

The CVSS score of the finding

B.  

The network location of the vulnerable device

C.  

The vulnerability identifier

D.  

The client acceptance form

E.  

The name of the person who found the flaw

F.  

The tool used to find the issue

Discussion 0
Question # 2

A penetration tester was able to gather MD5 hashes from a server and crack the hashes easily with rainbow tables.

Which of the following should be included as a recommendation in the remediation report?

Options:

A.  

Stronger algorithmic requirements

B.  

Access controls on the server

C.  

Encryption on the user passwords

D.  

A patch management program

Discussion 0
Question # 3

A penetration tester conducted a discovery scan that generated the following:

Question # 3

Which of the following commands generated the results above and will transform them into a list of active hosts for further analysis?

Options:

A.  

nmap –oG list.txt 192.168.0.1-254 , sort

B.  

nmap –sn 192.168.0.1-254 , grep “Nmap scan” | awk ‘{print S5}’

C.  

nmap –-open 192.168.0.1-254, uniq

D.  

nmap –o 192.168.0.1-254, cut –f 2

Discussion 0
Question # 4

A penetration tester logs in as a user in the cloud environment of a company. Which of the following Pacu modules will enable the tester to determine the level of access of the existing user?

Options:

A.  

iam_enum_permissions

B.  

iam_privesc_scan

C.  

iam_backdoor_assume_role

D.  

iam_bruteforce_permissions

Discussion 0
Question # 5

A penetration tester completed an assessment, removed all artifacts and accounts created during the test, and presented the findings to the client. Which of the following happens NEXT?

Options:

A.  

The penetration tester conducts a retest.

B.  

The penetration tester deletes all scripts from the client machines.

C.  

The client applies patches to the systems.

D.  

The client clears system logs generated during the test.

Discussion 0
Question # 6

A client has requested that the penetration test scan include the following UDP services: SNMP, NetBIOS, and DNS. Which of the following Nmap commands will perform the scan?

Options:

A.  

nmap –vv sUV –p 53, 123-159 10.10.1.20/24 –oA udpscan

B.  

nmap –vv sUV –p 53,123,161-162 10.10.1.20/24 –oA udpscan

C.  

nmap –vv sUV –p 53,137-139,161-162 10.10.1.20/24 –oA udpscan

D.  

nmap –vv sUV –p 53, 122-123, 160-161 10.10.1.20/24 –oA udpscan

Discussion 0
Question # 7

A security professional wants to test an IoT device by sending an invalid packet to a proprietary service listening on TCP port 3011. Which of the following would allow the security professional to easily and programmatically manipulate the TCP header length and checksum using arbitrary numbers and to observe how the proprietary service responds?

Options:

A.  

Nmap

B.  

tcpdump

C.  

Scapy

D.  

hping3

Discussion 0
Question # 8

The results of an Nmap scan are as follows:

Starting Nmap 7.80 ( https://nmap.org ) at 2021-01-24 01:10 EST

Nmap scan report for ( 10.2.1.22 )

Host is up (0.0102s latency).

Not shown: 998 filtered ports

Port State Service

80/tcp open http

|_http-title: 80F 22% RH 1009.1MB (text/html)

|_http-slowloris-check:

| VULNERABLE:

| Slowloris DoS Attack

| <..>

Device type: bridge|general purpose

Running (JUST GUESSING) : QEMU (95%)

OS CPE: cpe:/a:qemu:qemu

No exact OS matches found for host (test conditions non-ideal).

OS detection performed. Please report any incorrect results at https://nmap.org/submit/.

Nmap done: 1 IP address (1 host up) scanned in 107.45 seconds

Which of the following device types will MOST likely have a similar response? (Choose two.)

Options:

A.  

Network device

B.  

Public-facing web server

C.  

Active Directory domain controller

D.  

IoT/embedded device

E.  

Exposed RDP

F.  

Print queue

Discussion 0
Question # 9

Which of the following should a penetration tester attack to gain control of the state in the HTTP protocol after the user is logged in?

Options:

A.  

HTTPS communication

B.  

Public and private keys

C.  

Password encryption

D.  

Sessions and cookies

Discussion 0
Question # 10

A red team gained access to the internal network of a client during an engagement and used the Responder tool to capture important data. Which of the following was captured by the testing team?

Options:

A.  

Multiple handshakes

B.  

IP addresses

C.  

Encrypted file transfers

D.  

User hashes sent over SMB

Discussion 0
Get PT0-002 dumps and pass your exam in 24 hours!

Free Exams Sample Questions