Courseiva
hardMultiple Choice

PT0-002 Practice Question: A penetration tester is analyzing a Bash script…

A penetration tester is analyzing a Bash script that automates a password spraying attack. The script contains the following loop: 'for user in $(cat users.txt); do for pass in $(cat passwords.txt); do curl -s -o /dev/null -w "%{http_code}" --data "user=$user&pass=$pass" http://target/login; done; done'. The script runs but the output is a continuous stream of HTTP status codes that are hard to interpret. Which improvement would most effectively help the tester identify a successful login?

⚠ Common exam trap

Candidates often assume filtering out 200 codes (Option B) will reveal successes, but they overlook that many real-world login flows use a 302 redirect for success, making 'grep -v 200' ineffective or misleading.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a conditional statement that checks if the HTTP status code is 302 (redirect) or 200, and if so, prints the successful credentials.

The script currently outputs a raw stream of HTTP status codes with no context. Adding a conditional to check for 302 (redirect, often indicating a successful login) or 200 (OK) and printing the corresponding credentials allows the tester to immediately identify which user/password pair succeeded, turning an unreadable output into actionable intelligence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add a delay with 'sleep 1' between requests to avoid rate limiting.

    Why it's wrong here

    Adding 'sleep 1' between requests inserts a delay to throttle the request rate and avoid triggering rate limiting or IP bans, but this does nothing to interpret the responses. The script still produces raw output for every attempt, so the attacker must manually identify which response indicates a successful login. Rate limiting control is a pre-processing tactic, not a post-processing analysis of status codes or content.

  • ✗

    Pipe the output to 'grep -v 200' to exclude any responses that are not 200 OK.

    Why it's wrong here

    Using 'grep -v 200' removes every line that contains the substring '200', which would delete all successful 200 OK responses and leave only failures and redirects. This is the inverse of the desired behavior, and because many login success responses are 302 redirects to a dashboard, those would remain but not be automatically flagged as successes. Additionally, grep operates on text lines, not structured HTTP status codes, so it may miss multi-line responses or status codes embedded in other output.

  • ✓

    Add a conditional statement that checks if the HTTP status code is 302 (redirect) or 200, and if so, prints the successful credentials.

    Why this is correct

    Adding a conditional in the bash script to check for HTTP 302 or 200 and then printing the credentials directly automates the success detection. In web applications, a login form often responds with a 302 redirect to the authenticated user's dashboard upon success, or 200 with the post-login page; unsuccessful attempts typically return 401, 403, or 200 with an error message in the body. By capturing the status code with curl -w '%{http_code}' and comparing it in an if statement, the script can immediately isolate valid credential pairs from the noise, turning raw output into actionable findings.

  • ✗

    Use 'curl -v' to see the full response headers.

    Why it's wrong here

    Running curl with the -v flag provides verbose output that includes request headers, response headers, and TLS handshake details, which is helpful for manual debugging of a single request. However, it outputs every request and response in full, making it even harder to parse through hundreds of attempts, and it does not apply any conditional logic to identify successful logins. The pentester would still have to visually scan each response, defeating the purpose of an automated script, and it certainly does not print the successful credentials by itself.

About these practice questions

This PT0-003 question is part of Courseiva's 777-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.