20+ practice questions focused on Attacks and Exploits — one of the most tested topics on the CompTIA PenTest+ (PT0-003) exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Attacks and Exploits PracticeA penetration tester has successfully compromised a Windows machine and wants to perform lateral movement to another machine using captured NTLM hashes. Which tool would allow the tester to pass the hash and execute commands remotely?
Explanation: CrackMapExec is a popular tool for pass-the-hash and executing commands via SMB or other protocols.
During a penetration test, a tester identifies that a web application is vulnerable to Server-Side Request Forgery (SSRF). The tester attempts to access the AWS metadata endpoint to retrieve temporary credentials. Which IP address is commonly used for the cloud metadata endpoint?
Explanation: The AWS metadata endpoint is available at 169.254.169.254 for all cloud providers.
A penetration tester is exploiting a SQL injection vulnerability in a login page. The tester wants to extract data from another table without returning data in the original query. Which SQL injection technique should the tester use?
Explanation: Blind time-based SQL injection is the correct technique because it allows data extraction without returning data in the original query output. The tester injects conditional time delays (e.g., IF condition WAIT FOR DELAY) to infer information bit by bit based on response timing. UNION-based SQL injection combines query results into the original output, violating the requirement. Error-based SQL injection returns data in error messages, which is a form of output. Out-of-band SQL injection uses a separate channel, but the stem implies no output at all, making time-based the best fit.
A penetration tester is assessing a web application that uses JSON Web Tokens (JWT) for authentication. The tester discovers that the server does not validate the signature algorithm properly. Which attack should the tester attempt to forge a valid token?
Explanation: If the server accepts 'none' algorithm, the token can be forged without a signature.
Which Metasploit command is used to interact with an established session on a compromised host?
Explanation: The sessions command lists and interacts with active sessions.
+15 more Attacks and Exploits questions available
Practice all Attacks and Exploits questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Attacks and Exploits. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Attacks and Exploits questions on the PT0-003 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Attacks and Exploits is tested as part of the CompTIA PenTest+ (PT0-003) blueprint. Practicing with targeted Attacks and Exploits questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free PT0-003 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Attacks and Exploits is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Attacks and Exploits practice session with instant scoring and detailed explanations.
Start Attacks and Exploits Practice →