Be able to match each scenario to the correct technique and tool: time-based SQLi for delay inference, CrackMapExec or Impacket for SMB, pass-the-hash for NTLM authentication, and Responder for LLMNR spoofing. The key is identifying the protocol and credential type before picking a tool.
Start practicing
Attacks and Exploits — choose a session length
Free · No account required
Domain overview
Domain 4 of PT0-003 covers exploiting hosts, services, and credentials during engagements. You are tested on recognizing attack techniques, selecting the right tool for a scenario, and interpreting output, with emphasis on SQL injection variants, SMB enumeration and remote execution, pass-the-hash, and LLMNR/NBT-NS spoofing to capture NTLMv2 hashes.
Exam objectives
Blind SQL injection variants, including time-based inference using database delay functions like SLEEP or WAITFOR DELAY.
SMB enumeration and remote command execution with tools such as CrackMapExec, Impacket psexec, and smbclient.
Pass-the-hash authentication to Windows using captured NTLM hashes with Impacket or CrackMapExec.
LLMNR/NBT-NS spoofing with Responder to capture NTLMv2 hashes and relay or crack them.
Confusing time-based blind SQL injection with boolean-based or error-based, when the question specifically mentions response delay as the inference channel.
Choosing a general port scanner or vulnerability scanner for SMB share enumeration and remote execution instead of a dedicated SMB/Impacket tool.
Attempting to crack an NTLM hash before recognizing that pass-the-hash allows authentication without recovering the plaintext password.
Practice questions for the Attacks and Exploits domain are being added. Check back soon.
← Back to all PT0-003 domainsBe able to match each scenario to the correct technique and tool: time-based SQLi for delay inference, CrackMapExec or Impacket for SMB, pass-the-hash for NTLM authentication, and Responder for LLMNR spoofing. The key is identifying the protocol and credential type before picking a tool.
The Courseiva PT0-003 question bank contains 0 questions in the Attacks and Exploits domain, covering the 35% of the exam attributed to this domain in the official CompTIA blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Attacks and Exploits domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included