PT0-002 Attacks and Exploits Practice Question
A penetration tester is asked to assess whether an organization's employees can be tricked into revealing credentials. The client approves an assessment in which the tester registers a look-alike domain and sends emails directing staff to a fake login page. Which type of assessment is the tester conducting?
⚠ Common exam trap
The trap here is overcomplicating the classification when the described activity of a spoofed domain plus fake login page is straightforwardly phishing, not a technical infrastructure or wireless assessment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A phishing simulation targeting credential harvesting
The engagement uses a spoofed domain and a counterfeit login page delivered through email to induce employees to surrender credentials. That combination of social engineering and credential capture defines a phishing simulation. Its purpose is to quantify human risk and test the effectiveness of awareness training and email controls, which aligns exactly with the client's approved objective.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A wireless assessment targeting rogue access points
Why it's wrong here
A wireless assessment evaluates the security of Wi-Fi networks, including rogue access point detection and encryption strength. The scenario involves a look-alike domain and a fraudulent login page delivered by email, which has nothing to do with radio-frequency attacks or wireless infrastructure. The tester is not interacting with any wireless network here.
- ✗
A vulnerability scan of the external attack surface
Why it's wrong here
An external vulnerability scan probes internet-facing hosts and services for known weaknesses using automated tooling. It does not involve social engineering, spoofed domains, or deceiving employees. The scenario explicitly centers on tricking staff into entering credentials on a fake page, which is a human-focused technique rather than an automated infrastructure scan.
- ✓
A phishing simulation targeting credential harvesting
Why this is correct
Registering a look-alike domain and luring employees to a counterfeit login page to capture credentials is the defining pattern of a phishing simulation focused on credential harvesting. The objective is to measure human susceptibility and the effectiveness of awareness controls, which matches the approved scenario of tricking staff into revealing their login details.
- ✗
A physical intrusion test using tailgating techniques
Why it's wrong here
Physical intrusion testing involves bypassing doors, badge readers, or guards to gain unauthorized physical access to a facility. The scenario describes email lures and a spoofed web page, which operate entirely in the digital and social-engineering domain. No on-site access or physical control is being defeated, so this does not describe the engagement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PT0-003 question from scratch — 777 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.