Be able to read a code snippet or scenario and name the exact flaw, library, or tool. The most important thing is matching the tool to the task: Scapy for packet crafting, Pacu for AWS post-exploitation, and correct vulnerability classification for injection flaws.
Start practicing
Vulnerability Discovery and Analysis — choose a session length
Free · No account required
Domain overview
This domain covers finding and validating weaknesses before exploitation: source code review, packet crafting, cloud and web misconfigurations, and tool-assisted discovery. Questions present short scenarios—a PHP snippet, an AWS audit, a Python script—and ask you to name the vulnerability, the right library, or the appropriate tool for the target environment.
Exam objectives
Crafting and inspecting packets with Scapy, including TCP flags, in Python scripts
Source code review for hardcoded credentials, injection flaws, and missing input validation
Identifying SQL injection in PHP string-concatenated queries using $_POST input
Using cloud exploitation tools such as Pacu for AWS privilege escalation and persistence
Choosing requests or socket for raw packet crafting when Scapy is the intended low-level manipulation library.
Reading a concatenated SQL query as XSS or command injection instead of recognizing SQL injection.
Confusing general cloud audit tools with AWS-specific exploitation frameworks like Pacu.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A penetration tester wants to exploit a vulnerable service on a target using a known module. Which framework provides a large database of exploit modules, payloads, and post-exploitation tools?
2After gaining initial access to a Windows domain controller, a tester wants to extract password hashes from the SAM database and domain account hashes. Which Impacket tool is designed for this purpose?
3A penetration tester has captured a WPA2 handshake. Which tool from the Aircrack-ng suite is used to crack the pre-shared key?
4During a code review of a PHP web application, you encounter the following code: $result = mysql_query("SELECT * FROM users WHERE username='" . $_GET['user'] . "'");. Which vulnerability does this represent?
5A tester needs to brute-force SSH credentials on a target. Which tool is most appropriate for this task?
6In a Python script for a penetration test, you need to craft a custom TCP packet with specific flags. Which library is best suited for low-level packet manipulation?
7During a reverse engineering task on a .NET binary, which tool would allow you to decompile the code into readable C# source code?
8A tester wants to perform an evil twin attack to capture WPA handshakes. Which tool from the Aircrack-ng suite is used to deauthenticate clients from a legitimate AP to force reconnection to the rogue AP?
9Which PowerShell script is commonly used for post-exploitation enumeration of Active Directory, such as querying user accounts and group memberships?
10During a cloud security assessment of AWS, a tester wants to identify misconfigurations using automated tools. Which THREE tools are specifically designed for AWS security auditing?
11A tester is reviewing source code for security vulnerabilities. Which TWO of the following are examples of insecure coding practices that often lead to critical vulnerabilities?
12During a web application test, a penetration tester needs to intercept and modify HTTP requests before forwarding them to the server. Which tool is best suited for this task?
13A penetration tester is performing a password cracking task against a dump of NTLM hashes obtained from a Windows domain controller. Which tool would be the most efficient for this task?
14A tester wants to perform a Kerberoasting attack against an Active Directory environment. Which Impacket tool would be most appropriate?
15A penetration tester is reviewing a Python script used for a custom exploit. Which of the following code snippets contains a dangerous function that could lead to remote code execution?
16A tester needs to enumerate Windows domain users and groups from a compromised system. Which PowerShell script would be most useful?
17Which tool would be best for capturing and analyzing network packets to troubleshoot a web application?
18A penetration tester wants to exploit a Windows system using a known vulnerability and gain a meterpreter session. Which tool is most appropriate?
19During a source code review of a PHP application, the tester finds the following line: $query = "SELECT * FROM users WHERE username = '" . $_POST['username'] . "'"; Which vulnerability is present?
20A tester needs to perform an online brute-force attack against an SSH service. Which tool is most suitable?
21A penetration tester has been given a target IP address and needs to quickly determine which services are running on the target. Which Nmap option should the tester use to perform a SYN scan with service version detection and default NSE scripts?
22During a web application penetration test, the tester captures a login request in Burp Suite and wants to automate a brute-force attack against the password field. Which Burp Suite tool is specifically designed for this purpose?
23A penetration tester needs to perform a Kerberoasting attack against a Windows Active Directory environment. Which tool from the Impacket suite should the tester use to request service tickets and extract TGS hashes for offline cracking?
24A penetration tester is conducting a wireless security assessment. The target network uses WPA2-PSK. The tester has captured the four-way handshake. Which tool from the Aircrack-ng suite can be used to attempt to recover the pre-shared key by performing a dictionary attack?
25During code review, a penetration tester identifies the following line in a PHP web application: $sql = "SELECT * FROM users WHERE username='" . $_GET['user'] . "'"; Which type of vulnerability is most likely present?
26A penetration tester is analyzing a Linux binary and wants to decompile it to understand its logic. Which open-source tool is specifically designed for reverse engineering and can generate C-like pseudocode from compiled binaries?
27A penetration tester needs to perform a dictionary attack against an SSH service. Which of the following tools is best suited for this task?
28During a penetration test, the tester wants to capture network traffic for later analysis. Which tool is most appropriate for capturing packets and saving them to a pcap file?
29A penetration tester has obtained a set of NTLM password hashes from a Windows domain controller. The tester wants to perform an offline cracking attack using GPU acceleration. Which tool is best suited for this purpose?
30A penetration tester is performing a cloud security audit of an AWS environment. Which tool is specifically designed for AWS exploitation and post-exploitation, including privilege escalation and persistence?
31A penetration tester is writing a Python script to send a crafted TCP packet to a target. Which Python library should the tester use for low-level packet crafting and injection?
32A penetration tester needs to enumerate Active Directory users and groups from a Windows domain. Which PowerShell tool is specifically designed for AD enumeration and is commonly used in post-exploitation?
33A penetration tester is reviewing a Java application for insecure deserialization vulnerabilities. Which of the following should the tester look for? (Choose TWO.)
34A penetration tester is performing a wireless assessment and wants to set up an evil twin attack. Which of the following steps are necessary? (Choose THREE.)
35A penetration tester is conducting a post-exploitation phase on a Windows target and wants to dump credentials. Which of the following tools can be used? (Choose TWO.)
36A penetration tester needs to identify live hosts and open ports on a target network. Which tool is most appropriate for this task?
37During a web application test, a penetration tester intercepts requests between the browser and server and modifies them in real time. Which Burp Suite tool is designed for this purpose?
38After gaining initial access to a Windows system, a penetration tester wants to extract password hashes from the local SAM database. Which Impacket tool should be used?
39A penetration tester is conducting a wireless assessment and needs to capture the four-way handshake to perform offline WPA cracking. Which tool is best suited for capturing the handshake?
40A penetration tester needs to perform an online brute-force attack against an SSH service. Which tool is most appropriate?
41During a code review, a penetration tester identifies a PHP function that executes arbitrary shell commands. Which function poses the greatest security risk if user input is not sanitized?
42A penetration tester is analyzing a Java application and finds the following code snippet: Object obj = ois.readObject(); where ois is an ObjectInputStream. What vulnerability is most likely present if the input is untrusted?
43A penetration tester has captured network traffic and wants to analyze it using Wireshark. Which two actions can the tester perform to focus on specific types of communication? (Choose TWO.)
44During a penetration test, a tester needs to perform a deauthentication attack to force a client to reconnect and capture the WPA handshake. Which two tools from the Aircrack-ng suite are required? (Choose TWO.)
45A penetration tester is reverse-engineering a .NET binary to understand its authentication logic. Which three tools are suitable for decompiling .NET assemblies? (Choose THREE.)
46A penetration tester is writing a Bash script to automate scanning of multiple subnets with Nmap and parse the output. Which three features are commonly used in such a script? (Choose THREE.)
47A penetration tester is reviewing source code and wants to identify common hardcoded credentials and input validation gaps. Which three checks should the tester perform? (Choose THREE.)
48A penetration tester is analyzing a compiled Linux binary that appears to validate license keys. The tester wants to understand the validation logic without access to source code. The binary is stripped of symbols and uses anti-debugging techniques. Which approach is most effective for discovering the validation algorithm?
49A penetration tester is analyzing a web application and discovers that it uses a JSON Web Token (JWT) for session management. The tester captures a token and notices that the signature algorithm is 'none'. The application accepts tokens with the 'none' algorithm. Which type of vulnerability does this represent, and what is the immediate impact?
50A penetration tester is conducting a vulnerability assessment of a Linux web server. The tester runs a scan with Nikto and receives a finding indicating that the server is potentially vulnerable to a cross-site scripting (XSS) attack on a specific parameter. To confirm the finding, the tester wants to manually verify the XSS vulnerability. Which action should the tester take?
51A penetration tester is analyzing a suspicious executable found on a compromised Windows host. The tester wants to identify if the executable is packed or obfuscated, which might indicate malware. Which tool is specifically designed for detecting packers and providing information about the executable's structure?
52A penetration tester is performing a vulnerability assessment of a web application. The tester wants to identify input validation vulnerabilities that could lead to injection attacks. Which two techniques are most effective for discovering injection flaws such as SQL injection and command injection? (Choose two.)
Be able to read a code snippet or scenario and name the exact flaw, library, or tool. The most important thing is matching the tool to the task: Scapy for packet crafting, Pacu for AWS post-exploitation, and correct vulnerability classification for injection flaws.
The Courseiva PT0-003 question bank contains 52 questions in the Vulnerability Discovery and Analysis domain, covering the 17% of the exam attributed to this domain in the official CompTIA blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Vulnerability Discovery and Analysis domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included