Courseiva

CompTIA PenTest+ (PT0-003) (PT0-003) — Questions 676–750

777 questions total · 11pages · All types, answers revealed

Page 9

Page 10 of 11

Page 11
676
MCQhard

A penetration tester has compromised a Linux server and wants to move laterally to a Windows server. The Linux server has network access to the Windows server on port 445. The tester has a captured NTLM hash of a domain administrator account. Which technique is most likely to allow the tester to authenticate and execute commands on the Windows server?

A.Pass-the-hash using Impacket's psexec
B.Kerberos Golden Ticket attack
C.SMB relay attack using the hash
D.Brute-force password cracking of the hash
AnswerA

Pass-the-hash (PtH) with Impacket's psexec.py allows the tester to authenticate to remote Windows hosts by providing the NTLM hash instead of the plaintext password. Since the Linux server is compromised, the tester can extract hashes from memory or local files, then use psexec to execute commands over SMB via the ADMIN$ share. This is a direct lateral movement technique that does not require cracking, and it works against any Windows target that has NTLM authentication enabled.

Why this answer

The tester has a captured NTLM hash of a domain administrator account and network access to the Windows server on port 445 (SMB). Pass-the-hash (PtH) allows authentication using the NTLM hash directly without needing the plaintext password. Impacket's psexec uses the SMB protocol to authenticate with the hash and execute commands remotely, making it the most direct and effective technique for lateral movement in this scenario.

Exam trap

The trap here is that candidates may confuse pass-the-hash with SMB relay, but relay requires intercepting a live authentication attempt, whereas pass-the-hash directly uses the captured hash to authenticate without any relay.

How to eliminate wrong answers

Option B is wrong because a Kerberos Golden Ticket attack requires forging a Ticket Granting Ticket (TGT) using the KRBTGT account's hash, which is not captured here; the captured hash is for a domain administrator account, not the KRBTGT account, and the attack also requires domain controller access, not just SMB to a Windows server. Option C is wrong because an SMB relay attack requires the tester to intercept and relay authentication attempts from a client to a server, but the tester already possesses the hash and does not need to relay it; relay attacks are used when the hash cannot be directly used (e.g., with NTLMv2 and no local admin rights), but here the hash is directly usable for pass-the-hash.

677
MCQmedium

A penetration tester is performing service enumeration on a discovered host and wants to grab banners from open ports to identify the exact software and version running. Which of the following command-line tools would be most appropriate for this task?

A.traceroute target.com
B.ping target.com
C.curl http://target.com
D.nc -v target.com 22
AnswerD

Netcat's verbose flag prints the service banner returned on connect, so nc -v target.com 22 reveals the SSH software and version string. It satisfies the banner-grabbing requirement directly on a chosen port without extra scripting.

Why this answer

`nc -v target.com 22` uses Netcat in verbose mode to connect to port 22 on the target, which triggers the SSH server to send its banner (e.g., "SSH-2.0-OpenSSH_8.9p1"). This banner directly reveals the exact software and version running on that port, making it ideal for service enumeration and banner grabbing.

Exam trap

CompTIA Pentest+ tests the distinction between general connectivity tools (ping, traceroute) and service-specific tools (nc, telnet, nmap -sV), expecting candidates to recognize that only raw TCP connection tools can perform banner grabbing on arbitrary ports.

How to eliminate wrong answers

Option A is wrong because `traceroute` is used to map the network path (hops) between the source and destination, not to connect to open ports or retrieve banners. Option B is wrong because `ping` uses ICMP Echo Requests to test host reachability and does not interact with TCP/UDP services to grab banners. Option C is wrong because `curl http://target.com` sends an HTTP request and retrieves the web page content, but it does not perform raw TCP banner grabbing on arbitrary ports (e.g., SSH on port 22) and may not reveal the exact software version unless the server leaks it in HTTP headers.

678
Multi-Selectmedium

A penetration tester is conducting a web application test and discovers a server-side request forgery (SSRF) vulnerability. The application accepts a URL parameter and fetches the resource. Which TWO of the following are common SSRF exploitation techniques?

Select 2 answers
A.Accessing the AWS metadata endpoint at 169.254.169.254
B.Scanning internal IP addresses and ports
C.Crafting a JavaScript payload for XSS
D.Injecting SQL queries into the URL
E.Forcing the server to send a POST request
AnswersA, B

Accessing the AWS metadata endpoint at 169.254.169.254 is a textbook SSRF technique because this link-local address is reachable only from within the cloud environment and provides IAM security credentials, user-data, and instance configuration when queried. By making the vulnerable server request this IP, an attacker can steal cloud role credentials and pivot into the target's AWS account. This usage directly demonstrates SSRF's core characteristic: the server is tricked into fetching an internal resource on the attacker's behalf.

Why this answer

SSRF can access internal services like cloud metadata endpoints and perform internal port scans.

679
MCQeasy

A penetration tester needs to automate a series of web application attacks against a login page to identify weak credentials. Which tool is most appropriate?

A.Nmap
B.Hydra
C.Burp Suite
D.Wireshark
AnswerB

Hydra is a dedicated network login cracker designed specifically for high-speed parallel brute-force attacks against numerous protocols, including HTTP/HTTPS forms, FTP, SMB, SSH, and others. It supports custom username and password wordlists, flexible parameterization, and multi-threading to maximize attempts per minute, and it can handle web-specific features like session cookies and HTTP basic/digest authentication. These capabilities make Hydra the ideal automated tool for credential brute-forcing a web application.

Why this answer

Hydra (option B) is the most appropriate tool because it is a dedicated online password-cracking utility that automates credential-guessing attacks against login forms and services, supporting protocols like HTTP-POST and HTTP-GET with configurable username/password lists and threading. For a penetration test targeting weak credentials on a web login page, Hydra's ability to script repeated authentication attempts makes it purpose-built for this task. Nmap (A) is a port scanner and service/version detector, not a credential brute-forcer.

Burp Suite (C) is a web proxy and testing platform that can facilitate manual or Intruder-based attacks but is not primarily an automated credential-cracking tool. Wireshark (D) is a packet analyzer used for traffic capture and inspection, not for launching authentication attacks.

680
MCQhard

After completing a penetration test, the client's technical team requests the detailed raw data (e.g., scan results, exploit logs, packet captures) used to support the findings. According to best practices, which of the following should the penetration tester do?

A.Include all raw data in the appendices of the final report
B.Provide the raw data in a separate, sanitized deliverable with a data handling agreement
C.Refuse to provide raw data to protect the confidentiality of the testing process
D.Provide the raw data only if the client signs a non-disclosure agreement
AnswerB

The correct approach is to provide raw data in a separate, sanitized deliverable—such as a password-protected archive or controlled access repository—where overly sensitive artifacts are redacted before transfer. A data handling agreement is then signed to explicitly define allowed uses, retention periods, and disposal steps, ensuring the client can use the data for remediation and compliance while keeping confidentiality intact. This gives the client the evidence they need without turning the final report into a liability.

Why this answer

Raw data such as scan results, exploit logs, and packet captures often contain sensitive information like IP addresses, credentials, or system details. Best practices (e.g., PTES, NIST SP 800-115) dictate that raw data should be provided in a separate, sanitized deliverable accompanied by a data handling agreement to ensure confidentiality and proper data governance, rather than embedding it directly in the final report.

Exam trap

The trap here is that candidates may assume the final report should include all evidence for completeness (Option A), overlooking the confidentiality and data handling risks inherent in raw, unsanitized data.

How to eliminate wrong answers

Option A is wrong because including all raw data in the appendices of the final report risks exposing sensitive information to unauthorized readers and violates data minimization principles; the final report should contain only synthesized findings and evidence. Option C is wrong because refusing to provide raw data outright is not a best practice—clients have a legitimate need for supporting evidence, and a professional tester should provide it under controlled conditions with a data handling agreement.

681
MCQhard

A penetration tester is conducting a wireless penetration test. The client's rules of engagement state that testing must not disrupt production services. During the test, the tester's de-authentication attack causes the company's guest Wi-Fi to go offline. What should the tester do?

A.Ignore the issue and complete the test
B.Reduce the intensity of the attack
C.Continue testing because guest Wi-Fi is not critical
D.Stop testing and follow the emergency stop procedure
AnswerD

Stopping the test and executing the emergency stop procedure is the mandated response to an unintended service disruption. This action immediately prevents further impact, triggers the client notification and incident response plan, and allows the tester to document the incident as part of the test results. Following the procedure also preserves the integrity of the test and demonstrates compliance with the RoE, protecting both the tester and the client.

Why this answer

According to the RoE, the tester must stop testing if there is an emergency or disruption. The tester should follow the emergency stop procedure and contact the client.

682
Multi-Selectmedium

A penetration tester discovers a vulnerability that cannot be immediately remediated. Which TWO compensating controls should the tester recommend? (Choose TWO.)

Select 2 answers
A.Disable the affected service entirely.
B.Ignore the vulnerability until the next patch cycle.
C.Implement network segmentation to limit exposure.
D.Add an intrusion detection system (IDS) to monitor for exploitation.
E.Upgrade the software immediately.
AnswersC, D

Network segmentation is a textbook compensating control: it does not patch the vulnerable software, but it reduces the attack surface by isolating the affected system from untrusted hosts. Techniques such as placing the server in a separate VLAN, enforcing strict firewall ingress/egress rules, or applying zero-trust micro-segmentation restrict the paths an attacker can use to reach the vulnerability. This is a pragmatic, immediately actionable measure that can be implemented while awaiting a permanent fix, and it also minimizes the blast radius if the service is compromised.

Why this answer

Option C is correct because network segmentation (e.g., placing the vulnerable host in a restricted VLAN or behind firewall ACLs) is a classic compensating control that reduces the attack surface and limits lateral movement even when the underlying flaw cannot be patched right away. Option D is correct because an IDS provides detective compensating control value: it monitors network traffic or host activity for signatures/anomalies indicating exploitation attempts, enabling rapid response while remediation is deferred. Option A is not a compensating control but a disruptive remediation action that removes functionality rather than mitigating risk while preserving the service.

Option B is simply risk acceptance/neglect, not a control, and leaves the vulnerability unmonitored. Option E is immediate remediation, which the scenario explicitly rules out as not possible right now.

Exam trap

The trap here is that candidates often confuse compensating controls with remediation actions, selecting 'upgrade the software immediately' (E) even though the scenario explicitly states the vulnerability cannot be immediately remediated.

683
MCQmedium

A penetration tester is reviewing a Python script that uses the `requests` library to send HTTP POST requests to a login endpoint. The script attempts to bypass authentication by sending SQL injection payloads in the username field. Which of the following code changes would MOST effectively help the tester identify successful injections by reducing false negatives?

A.Using a `requests.Session` object to maintain cookies across requests
B.Parsing the response for specific error messages such as 'SQL syntax' or 'mysql_fetch_array'
C.Implementing a random delay between requests to avoid rate limiting
D.Adding a function to automatically resend each payload multiple times
AnswerB

This is correct because error-based SQL injection detection fundamentally relies on recognizing database error fingerprints in the response body. When a crafted payload causes the database to interpret it, the backend often emits specific messages like "You have an error in your SQL syntax" (MySQL) or warnings involving `mysql_fetch_array()` (legacy PHP MySQL functions). By proactively parsing the HTTP response for these exact substrings, the script can conclusively confirm that the payload reached and affected the SQL engine. This reduces false negatives because it catches successful injections even when the page otherwise returns a normal HTTP status code or content-length, thereby distinguishing a true vulnerability from a harmless, unexecuted payload.

Why this answer

Parsing the HTTP response for database-specific error messages (e.g., 'SQL syntax', 'mysql_fetch_array') directly indicates that the SQL injection payload triggered a detectable database error, confirming a successful injection. This reduces false negatives by catching cases where the login fails but the injection still executes, rather than relying solely on authentication bypass (which may not occur if the injection is blind or the query structure differs).

Exam trap

The trap here is that candidates often confuse session management (Option A) or evasion techniques (Option C) with detection logic, overlooking that the core goal is to reduce false negatives by explicitly checking for injection success indicators in the response.

How to eliminate wrong answers

Option A is wrong because using a `requests.Session` object maintains cookies and session state across requests, which is useful for session handling but does not help identify whether a SQL injection payload succeeded; it addresses session continuity, not detection of injection success. Option C is wrong because implementing a random delay between requests helps avoid rate limiting or WAF detection, but it does not improve the accuracy of identifying successful injections; it only evades defenses, not reduces false negatives in detection.

684
MCQmedium

During an internal penetration test, you need to perform lateral movement to a Windows target. You have a plaintext password for a domain user account. Which tool would be most appropriate to authenticate to the target using WMI?

A.CrackMapExec
B.evil-winrm
C.wmiexec
D.psexec
AnswerC

wmiexec is the correct choice because it directly uses Windows Management Instrumentation (WMI) to execute commands remotely without needing to upload a binary or create a service. It connects to the target's WMI service over DCOM (typically port 135) and invokes the Win32_Process.Create method, which makes it lighter and less likely to trigger service-specific detection rules. This direct API-level approach is what distinguishes it from wrappers and alternatives that rely on other protocols or artifacts.

Why this answer

wmiexec (part of Impacket) allows execution of commands on a Windows host via WMI using valid credentials, suitable for lateral movement.

685
MCQhard

A penetration tester is performing web application reconnaissance and wants to discover API endpoints and hidden parameters that may not be linked from the main application. Which technique would be most effective for this purpose?

A.Running Nikto for web server vulnerabilities
B.JavaScript analysis for endpoint discovery
C.Directory bruteforcing with gobuster
D.Using Wappalyzer to fingerprint technologies
AnswerB

JavaScript analysis is the correct approach because modern single-page applications often hard-code the API surface in their client-side code, such as REST URLs, GraphQL operation names, and route parameters. By examining network calls (fetch, XHR, WebSocket) and string literals, you can uncover undocumented endpoints that are not linked anywhere else in the HTML or robots.txt. This directly expands the attack surface and is a core web app recon technique.

Why this answer

JavaScript analysis often reveals AJAX API endpoints, keys, and parameters that are not visible in HTML. Directory bruteforcing may find endpoints but JS analysis is more targeted for hidden APIs.

686
MCQmedium

A penetration tester runs a SYN scan against a target and receives SYN-ACK responses from several ports. The tester then runs version detection on those ports. What is the primary purpose of version detection?

A.To identify the operating system of the target
B.To perform a vulnerability scan
C.To determine if the host is online
D.To identify the software and version running on open ports
AnswerD

Version detection is a post-scan enumeration step that sends specially crafted probes to open ports and analyzes the responses to determine the exact software and version, such as 'OpenSSH 8.2p1 Ubuntu 4ubuntu0.5' on port 22. This is typically performed using a tool like Nmap with the -sV flag, which may also try to infer service protocol and back-end. Unlike OS detection, it focuses on the application layer, and unlike vulnerability scanning, it does not evaluate security. The information gathered is essential for matching services to known CVEs and planning further exploitation.

Why this answer

Version detection (-sV) in Nmap identifies the specific software and version running on open ports, helping assess potential vulnerabilities and plan further exploitation.

687
MCQmedium

A penetration tester is using Nmap to scan a target web server. The tester only wants to see which of the top 100 ports are open, but wants to minimize network traffic and time. Which Nmap command is most appropriate?

A.nmap -sS -p- target
B.nmap -sT -p 1-100 target
C.nmap -sC -p 1-1000 target
D.nmap -sV --top-ports 100 target
AnswerD

The --top-ports 100 argument uses Nmap's frequency table to target the 100 most commonly open ports across real networks, including 80, 443, 22, 3389, 3306, and 8080. By pairing it with -sV, the tester gets service version enumeration only on those relevant ports, minimizing both time and packet count. This focuses on high-likelihood targets and avoids the wasted traffic of all-ports or broad-range scans. It is an ideal balance of speed and coverage for a quick web server assessment.

Why this answer

`--top-ports 100` instructs Nmap to scan only the 100 most commonly open ports, which minimizes network traffic and time compared to scanning all ports or a large range. The `-sV` flag enables version detection, which is not strictly required but is commonly used in information gathering; however, the key factor for minimizing traffic and time is the `--top-ports` option, which uses a statistically derived list to reduce scan scope.

Exam trap

The trap here is that candidates confuse `-p 1-100` (first 100 ports numerically) with `--top-ports 100` (most commonly open ports), leading them to choose option B, which misses high-numbered common ports like 443 (HTTPS) or 8080 (HTTP-alt).

How to eliminate wrong answers

Option A is wrong because `-p-` scans all 65535 ports, which generates maximum traffic and takes the longest time, contradicting the goal of minimizing both. Option B is wrong because `-sT` performs a full TCP connect scan, which is slower and more detectable than a SYN scan, and `-p 1-100` scans only the first 100 ports numerically, not the top 100 most common ports, potentially missing open ports like 443 or 8080. Option C is wrong because `-sC` runs default NSE scripts, which adds significant traffic and time, and `-p 1-1000` scans 1000 ports, far more than the requested top 100, increasing scan duration.

688
MCQmedium

A penetration tester discovers a Java application that deserializes user-controlled data without validation. The tester crafts a malicious serialized object that executes a command upon deserialization. The application runs on a Linux server with a standard Java runtime. Which of the following is the most likely outcome if the malicious object is accepted?

A.The application will crash immediately due to an exception.
B.The application will disclose sensitive information in the response.
C.The tester will gain a shell with the privileges of the current user.
D.The tester will be able to execute arbitrary commands on the server.
AnswerD

Exploiting insecure Java deserialization typically allows an attacker to supply a specially crafted serialized object that, when deserialized, triggers a gadget chain to execute arbitrary OS commands. This is remote code execution (RCE), which is the correct and complete characterization of the vulnerability's impact, surpassing the other options in scope.

Why this answer

Java deserialization of untrusted data allows an attacker to supply a crafted serialized object that, when deserialized, can execute arbitrary code via gadget chains (e.g., CommonsCollections). Since the application runs on a Linux server with a standard Java runtime, the attacker can achieve remote code execution (RCE) with the privileges of the application's user, not necessarily an interactive shell. Option D is correct because the primary impact is arbitrary command execution, which may or may not yield a shell depending on the payload.

Exam trap

The trap here is that candidates often conflate 'arbitrary command execution' with 'gaining a shell' (Option C), but the exam expects the broader, more precise impact—arbitrary command execution—since a shell is just one specific form of command execution and not guaranteed by every payload.

How to eliminate wrong answers

Option A is wrong because while deserialization can throw exceptions, a crafted malicious object is designed to execute code before or instead of throwing an unhandled exception, so a crash is not the most likely outcome. Option B is wrong because deserialization RCE does not inherently disclose sensitive information in the response; information disclosure would require a specific payload or secondary vulnerability. Option C is wrong because gaining a shell is a possible outcome of arbitrary command execution, but it is not guaranteed; the most direct and accurate description is arbitrary command execution, as the payload may execute a command without spawning an interactive shell.

689
MCQeasy

During the reconnaissance phase, a penetration tester wants to map out the target's DNS infrastructure without directly interacting with the target's servers. Which of the following techniques BEST achieves this?

A.Performing a DNS zone transfer
B.Querying publicly available DNS records
C.Using Nmap to scan for DNS servers
D.Sending crafted DNS queries to the target's DNS server
AnswerB

This technique leverages public DNS resolvers (e.g., 8.8.8.8) or historical DNS databases to retrieve records that are already published in the global namespace, such as A, MX, CNAME, TXT, and NS records. Because the pen tester never sends packets to the target's own servers, the activity is invisible to the target's monitoring tools and falls squarely within passive reconnaissance. This method respects the authorized scope while still revealing infrastructure details, subdomains, and mail server configurations.

Why this answer

Querying publicly available DNS records (e.g., via passive DNS, WHOIS, or DNS dumpster) allows the tester to gather DNS information without any direct interaction with the target's servers. This technique relies on third-party databases and cached records, avoiding any packets sent to the target, which is essential for stealth during reconnaissance. It aligns with passive information gathering, as defined in the PT0-002 objectives.

Exam trap

The trap here is that candidates often confuse 'passive reconnaissance' with 'active reconnaissance' and choose a technique like DNS zone transfer or Nmap scanning, which are clearly active and detectable, because they assume any DNS enumeration must involve direct queries.

How to eliminate wrong answers

Option A is wrong because a DNS zone transfer is an active query that directly interacts with the target's authoritative DNS server, requiring the server to allow AXFR requests, which is a direct interaction and not passive. Option C is wrong because using Nmap to scan for DNS servers involves sending packets to the target's network to probe for open ports (e.g., UDP 53), which is active reconnaissance and directly interacts with the target's infrastructure.

690
MCQmedium

A penetration tester is testing a web application that uses JSON Web Tokens (JWTs) for authentication. The tester discovers that the server does not verify the JWT signature properly. The tester crafts a JWT with an arbitrary payload and sets the algorithm to 'none'. Which attack does this enable?

A.SQL injection
B.Server-side request forgery
C.Authentication bypass
D.Cross-site request forgery
AnswerC

Setting the JWT header's algorithm to 'none' and stripping the signature allows the attacker to forge a token with arbitrary claims, such as an administrator username or elevated role. If the server's JWT library accepts unsigned tokens when it should require a signature, the middleware trusts the forged payload and grants access without verifying the token's authenticity. This is a direct authentication bypass because the attacker impersonates any user by simply crafting a valid-looking token, completely circumventing credential validation.

Why this answer

Setting the JWT algorithm to 'none' removes all cryptographic verification. If the server does not validate the signature, it will accept a token with an arbitrary payload, allowing the attacker to impersonate any user without knowing the secret key. This directly results in an authentication bypass, as the server trusts the forged token.

Exam trap

The trap here is that candidates may confuse JWT algorithm manipulation with injection attacks (SQLi) or server-side request forgery (SSRF), but the core of this question is about signature verification failure leading to authentication bypass.

How to eliminate wrong answers

Option A is wrong because SQL injection targets database queries via input fields, not JWT token manipulation; the 'none' algorithm attack does not involve injecting SQL commands. Option B is wrong because server-side request forgery (SSRF) exploits server-side requests to internal resources, whereas this attack modifies the JWT itself to bypass authentication, not to trigger outbound requests.

691
MCQmedium

Which legal framework in the United States makes it a crime to access a computer system without authorization, and is a key consideration when obtaining permission for penetration testing?

A.SOX
B.HIPAA
C.GDPR
D.CFAA
AnswerD

The CFAA (Computer Fraud and Abuse Act), codified at 18 U.S.C. § 1030, is the primary US federal law that criminalizes unauthorized access to computers and computer networks. It prohibits hacking, exceeding authorized access to obtain information, and causing damage to protected computers, including those used in interstate or foreign commerce. The CFAA is the correct answer because it directly establishes criminal liability for unauthorized computer access.

Why this answer

The Computer Fraud and Abuse Act (CFAA) is the primary US law against unauthorized access.

692
Multi-Selectmedium

A penetration tester is conducting an external assessment of a target organization and wants to gather information without sending any packets that might be logged by the target's network monitoring systems. Which TWO of the following methods are considered passive reconnaissance?

Select 2 answers
A.Send spear-phishing emails to employees
B.Query the target's DNS servers using nslookup
C.Use Shodan to identify exposed services
D.Conduct WHOIS lookups on the target's domain
E.Perform a full port scan using Nmap
AnswersC, D

Shodan serves pre-collected scan data from its own internet-wide crawling, so querying it never touches the target's hosts. No traffic reaches the organisation's network monitoring systems, satisfying the requirement to gather information without sending packets the target could log.

Why this answer

Option C is correct because Shodan is a third-party search engine that indexes internet-facing services from data it has already collected, so querying it does not send any traffic to the target's own infrastructure and therefore cannot be logged by the target's monitoring systems. Option D is correct because WHOIS lookups query public domain registration databases maintained by registrars and registries, retrieving ownership, contact, and nameserver data without touching the target's network. Option A is not passive reconnaissance but an active social-engineering attack that directly contacts employees.

Option B is active because nslookup sends DNS queries directly to the target's DNS servers, generating loggable traffic. Option E is active because an Nmap port scan sends packets to the target's hosts and is readily detected by IDS/IPS and firewall logs.

693
MCQmedium

A penetration tester is performing passive reconnaissance and wants to find historical versions of the target website, including old pages that may contain sensitive information. Which resource should the tester use?

A.Pastebin
B.Shodan
C.Wayback Machine
D.Google dorks
AnswerC

The Wayback Machine, operated by the Internet Archive, automatically crawls and preserves dated snapshots of web pages across the internet. Penetration testers use it during passive reconnaissance to review a target's historical site versions, uncovering removed content, old file paths, or legacy technology. This makes it the definitive resource for viewing a website's past states without directly interacting with the target.

Why this answer

The Wayback Machine (archive.org) archives historical snapshots of websites. Pastebin is for pasted text, Google dorks are for search queries, and Shodan is for device discovery.

694
Multi-Selecthard

A penetration tester is assessing a web application and wants to discover hidden directories, files, and parameters. Which THREE of the following tools are most appropriate for this task?

Select 3 answers
A.Nikto
B.dirsearch
C.Wappalyzer
D.feroxbuster
E.Gobuster
AnswersB, D, E

Dirsearch is an open-source, Python-based command-line tool explicitly built for directory brute-forcing and content discovery. It takes a wordlist of candidate path names, sends HTTP requests for each, and identifies valid resources by analyzing response status codes, sizes, and redirects. It supports recursive scanning, multi-threading, custom HTTP methods, and filters, making it a direct and effective answer to discovering hidden web paths.

Why this answer

dirsearch (B) is a Python-based web path scanner that brute-forces directories and files using wordlists and supports extensions, recursion, and custom headers, making it ideal for discovering hidden content. feroxbuster (D) is a fast Rust-based content discovery tool that performs recursive directory brute-forcing with wordlists and can also fuzz parameters, directly matching the task. Gobuster (E) is a Go-based tool whose dir and vhost modes enumerate hidden directories/files (and DNS subdomains) via wordlist brute-forcing, which is exactly the required discovery activity. Nikto (A) is a web server vulnerability scanner that checks for misconfigurations and known issues rather than brute-forcing hidden paths, Wappalyzer (C) is a technology fingerprinting tool that identifies CMS, frameworks, and libraries from page content, and neither is designed for directory/file/parameter brute-force discovery.

Exam trap

The trap here is that candidates confuse vulnerability scanners (Nikto) or technology fingerprinters (Wappalyzer) with directory brute-forcing tools, leading them to select options that serve different phases of the penetration testing methodology.

695
MCQmedium

Which of the following best describes the purpose of a vulnerability disclosure policy in the context of a penetration test?

A.To list the assets that are out of scope
B.To define the rules of engagement for the test
C.To establish a process for reporting discovered vulnerabilities to the client and possibly to the public
D.To provide legal protection to the tester
AnswerC

The primary purpose of a vulnerability disclosure policy is to establish a clear, agreed-upon process for reporting discovered vulnerabilities to the client and, where necessary, to the public after an embargo period or remediation. It sets expectations for how findings are communicated, who is responsible for triage, and what conditions trigger coordinated disclosure — protecting the client from surprise and the tester from accusations of irresponsible release. This is the central function of the policy in any professional engagement.

Why this answer

A vulnerability disclosure policy outlines how vulnerabilities found during testing will be reported and remediated.

696
MCQmedium

A penetration testing firm is contracted to test a cloud-based infrastructure. The client uses a shared responsibility model. Which of the following should be clarified in the rules of engagement to avoid legal issues?

A.Who is responsible for patching the operating system
B.Whether the tester needs authorization from the cloud provider
C.The encryption method for data at rest
D.The backup strategy for logs
AnswerB

Cloud providers like AWS, Azure, and GCP often require explicit written authorization before penetration testing, and testing without it can violate the provider's acceptable use policy or the Computer Fraud and Abuse Act (CFAA). Obtaining provider approval is a legal prerequisite that also ensures the tester's activities are recognized as authorized, protecting against claims of unauthorized access. This authorization is independent of the customer's consent and must be secured before testing the cloud infrastructure.

Why this answer

In a shared responsibility model, the cloud provider is responsible for the security of the cloud, while the customer is responsible for security in the cloud. However, penetration testing activities may violate the cloud provider's terms of service or acceptable use policy, potentially triggering legal action. Therefore, obtaining explicit authorization from the cloud provider is critical to ensure the tester's actions are legally permitted and to avoid liability for unauthorized access under laws like the Computer Fraud and Abuse Act (CFAA).

Exam trap

CompTIA often tests the misconception that operational security tasks like patching or encryption are the primary legal concerns in a shared responsibility model, when in fact the critical legal issue is obtaining explicit authorization from the cloud provider to avoid violating their terms of service or anti-hacking laws.

How to eliminate wrong answers

Option A is wrong because patching the operating system is a shared responsibility that varies by service model (e.g., IaaS vs. PaaS), but it is an operational security task, not a legal authorization issue that must be clarified in the rules of engagement to avoid legal issues. Option C is wrong because encryption methods for data at rest are a security control configuration, not a legal authorization requirement; while important for data protection, they do not address the legal risk of unauthorized testing against the cloud provider's infrastructure.

697
Multi-Selectmedium

A penetration tester is planning to perform a vulnerability scan of an internal network. Which of the following should be considered before scanning? (Choose three.)

Select 3 answers
A.Obtain written authorization from the client
B.Define the scope and rules of engagement
C.Perform the scan during peak business hours
D.Ensure the scanning tool is updated with latest signatures
E.Test all available exploit modules
AnswersA, B, D

Written authorization is the foundational legal safeguard that distinguishes a legitimate penetration test from unauthorized access under statutes such as the CFAA or Computer Misuse Act. A signed Statement of Work or Rules of Engagement, detailing exact targets and timeframes, provides the pentester with a formal defense against civil and criminal liability. Without this document, even a well-intentioned scan can be treated as a cyber intrusion, making it the single most critical pre-scan requirement.

Why this answer

Option A is correct because written authorization from the client is a legal and ethical prerequisite before any vulnerability scanning; without it, the tester could be committing unauthorized access under laws such as the CFAA. Option B is correct because defining the scope and rules of engagement establishes which IP ranges, hosts, and time windows are permitted, preventing accidental disruption of production systems or scanning of out-of-scope assets. Option D is correct because vulnerability scanners rely on up-to-date plugin/signature databases (e.g., Nessus plugins, OpenVAS NVTs) to accurately detect current CVEs; outdated signatures produce false negatives and unreliable results.

Option C is incorrect because scanning during peak business hours risks service degradation and is generally avoided unless explicitly authorized in the rules of engagement. Option E is incorrect because running every available exploit module is not a pre-scan consideration and would exceed the typical scope of a vulnerability scan, potentially causing damage and violating engagement boundaries.

Exam trap

The trap here is that candidates confuse vulnerability scanning with exploitation, assuming that testing exploits (Option E) is part of the scan, when in fact scanning is passive detection and exploitation requires separate authorization and a different phase.

698
MCQhard

During a web application penetration test, the tester discovers a JWT token in the Authorization header. The token uses the 'none' algorithm. What attack should the tester attempt?

A.JWT algorithm confusion attack (alg:none)
B.JWT timing attack
C.JWT kid injection
D.JWT brute-force of the secret
AnswerA

In an alg:none attack, the tester modifies the JWT header to set the algorithm to 'none' and removes the signature from the token. If the server-side JWT library is misconfigured to accept the 'none' algorithm or fails to enforce an explicit algorithm allowlist, it will treat the token as valid without verifying any cryptographic signature. This effectively bypasses integrity checks and allows the attacker to forge arbitrary claims, making it a true algorithm confusion vulnerability.

Why this answer

If the server accepts the 'none' algorithm, the tester can forge tokens by setting the algorithm to 'none' and removing the signature.

699
MCQmedium

A penetration tester is planning a test that involves scanning for vulnerabilities across a large IP range. The client has provided a list of IPs that are in-scope, but the tester notices that some IPs belong to a third-party company hosting a client application. What should the tester do?

A.Assume the client has permission and scan all IPs
B.Exclude the third-party IPs and notify the client
C.Scan the IPs because they are on the client's list
D.Scan only the third-party IPs that respond to ping
AnswerB

The correct action is to exclude the third-party IPs from active scanning and promptly notify the client that these assets are outside the authorized scope. This respects the legal boundaries of the engagement and ensures that the client takes responsibility for obtaining permission from the third-party owner if the assets need to be tested. The penetration tester should document the exclusion and request explicit written authorization or a revised scope before performing any scanning activity against those IPs. This approach aligns with contractual requirements, legal compliance, and professional standards in penetration testing.

Why this answer

The tester must ensure that all in-scope IPs are authorized. If an IP belongs to a third party, the tester needs written permission from that provider before testing.

700
MCQeasy

A penetration tester is performing reconnaissance on a target web application. The tester wants to identify the web server software and version without causing any disruption. Which tool is specifically designed for this purpose and can also enumerate other web technologies?

A.Nikto
B.Wireshark
C.WhatWeb
D.Nmap with the -sV flag
AnswerC

WhatWeb is a web scanner designed to fingerprint web technologies, including server software, CMS, JavaScript libraries, and more. It sends requests to the target and analyzes responses to identify the technologies in use. It is non-intrusive and ideal for reconnaissance, making it the best choice for this scenario.

Why this answer

WhatWeb is specifically designed for web technology fingerprinting, including server software and version, CMS, and JavaScript libraries. It is non-intrusive and efficient for reconnaissance. Nmap is more general, Wireshark requires manual analysis, and Nikto focuses on vulnerabilities rather than enumeration.

Exam trap

The trap here is assuming that any tool that can identify a web server is equally suited for detailed technology enumeration, when specialized tools like WhatWeb provide more comprehensive and accurate results.

701
MCQeasy

Which of the following tools would a penetration tester most likely use to perform passive reconnaissance on a target domain?

A.Wireshark
B.Nmap
C.Metasploit
D.theHarvester
AnswerD

theHarvester is a purpose-built OSINT tool that passively collects emails, subdomains, hosts, and employee names by querying public data sources such as search engines (Google, Bing), PGP key servers, and Shodan. It does not send any packets directly to the target's infrastructure, making it completely passive and undetectable by the target. This aligns exactly with the goal of passive reconnaissance, which is to gather information without engaging the target systems.

Why this answer

theHarvester is a passive reconnaissance tool that gathers information from public sources such as search engines, PGP key servers, and the Shodan API without directly interacting with the target domain. It collects email addresses, subdomains, IPs, and employee names using OSINT (Open Source Intelligence) techniques, making it ideal for passive information gathering.

Exam trap

The trap here is that candidates often confuse passive reconnaissance with active scanning tools like Nmap or Wireshark, failing to recognize that passive methods rely on publicly available data without sending any packets to the target.

How to eliminate wrong answers

Option A is wrong because Wireshark is a network protocol analyzer that captures and inspects live traffic, which requires active packet sniffing on the network, not passive reconnaissance. Option B is wrong because Nmap is an active scanning tool that sends crafted packets to target hosts to discover open ports and services, generating detectable traffic. Option C is wrong because Metasploit is an exploitation framework used for active penetration testing, including payload delivery and post-exploitation, not passive information gathering.

702
MCQmedium

A client with a hybrid on-premises and cloud infrastructure requests a penetration test. The client uses an IaaS provider for some servers. Which of the following is the MOST important aspect to clarify in the rules of engagement regarding the cloud environment?

A.The list of operating systems used in the cloud
B.The authorization from the cloud provider for testing
C.The public IP addresses of the cloud servers
D.The budget allocated for cloud testing
AnswerB

IaaS providers' acceptable-use policies require explicit written authorisation before any testing touches provider-managed hypervisors, networking or host infrastructure, even when the client owns the guest instances. Confirming this authorisation prevents contract breaches and account suspension, which client permission alone cannot override.

Why this answer

The most critical aspect to clarify in the rules of engagement for a cloud environment is obtaining explicit authorization from the IaaS provider. Without this authorization, the penetration test may violate the provider's acceptable use policy or terms of service, potentially leading to legal action or service termination. This is a foundational scoping requirement because the client does not own the underlying infrastructure; the cloud provider retains control over the network and hypervisor layers.

Exam trap

The trap here is that candidates focus on technical scoping details like IP addresses or OS lists, overlooking the critical legal and contractual prerequisite of obtaining the cloud provider's explicit authorization, which is a unique requirement for cloud environments compared to on-premises testing.

How to eliminate wrong answers

Option A is wrong because the list of operating systems used in the cloud is a technical detail that can be discovered during reconnaissance or provided in the scope, but it is not the most important legal or contractual aspect to clarify in the rules of engagement. Option C is wrong because while public IP addresses are necessary for targeting, they are operational details that can be scoped later; the primary concern is obtaining the cloud provider's written permission to test, as testing without it could be considered unauthorized access under laws like the Computer Fraud and Abuse Act (CFAA).

703
MCQmedium

After compromising a Windows workstation, the tester wants to extract password hashes from the local SAM database. Which Metasploit meterpreter command should be used?

A.getsystem
B.getuid
C.shell
D.hashdump
AnswerD

The hashdump command is the correct choice because it directly extracts the NTLM password hashes from the SAM database on a Windows target when run in Meterpreter (typically after gaining SYSTEM privileges). It does this by copying the SAM and SYSTEM registry hives, decrypting the hash material with the SYSKEY from the SYSTEM hive, and presenting the hashes in a format ready for offline cracking. This command is specifically designed for dumping local user password hashes, fulfilling the tester's objective immediately. While it may require 'getsystem' first, hashdump itself is the actual dumping action.

Why this answer

hashdump dumps the SAM database hashes.

704
MCQeasy

During a penetration test, a tester discovers a web application that reflects user input in the HTTP response without proper escaping or encoding. The input is not sanitized and is included in the page's HTML. Which type of vulnerability is most likely present?

A.SQL injection
B.Cross-Site Scripting (XSS)
C.Stored XSS
D.Cross-Site Request Forgery (CSRF)
AnswerB

Reflected Cross-Site Scripting (XSS) occurs when a web application echoes user-supplied input directly into the HTTP response without proper sanitization or encoding. In this scenario, the tester observed the application reflecting input in the response, which is the primary indicator of a reflected XSS flaw because an attacker can craft a URL containing a malicious script payload that gets rendered in the victim's browser. This enables session hijacking, keylogging, or other client-side attacks, and it specifically aligns with the description of input reflection rather than persistence or server-side logic manipulation.

Why this answer

The vulnerability is reflected Cross-Site Scripting (XSS) because the web application immediately echoes user-supplied input in the HTTP response without proper escaping or encoding, allowing an attacker to inject arbitrary HTML or JavaScript that executes in the victim's browser. This matches the classic definition of reflected XSS, where the payload is part of the request and reflected back, not stored on the server.

Exam trap

The trap here is that candidates confuse reflected XSS with stored XSS because both involve injecting script into a web page, but the key differentiator is whether the payload is persisted on the server (stored) or immediately reflected in the response (reflected).

How to eliminate wrong answers

Option A is wrong because SQL injection requires user input to be incorporated into a database query without proper sanitization, not simply reflected in the HTTP response; the description lacks any mention of database interaction or query construction. Option C is wrong because stored XSS requires the malicious input to be persisted on the server (e.g., in a database or file) and later served to other users, whereas the scenario describes input being reflected immediately in the response without storage.

705
MCQmedium

A penetration tester is writing the technical report for a client. The client's security team needs detailed, step-by-step instructions on how to reproduce each vulnerability found. In which section of the report should this information be placed?

A.Executive summary
B.Risk rating section
C.Findings and recommendations
D.Appendix
AnswerC

The findings and recommendations section is the core technical narrative of a penetration test report, where each vulnerability is fully detailed. It provides a structured breakdown including the affected asset, CVSS score, description, root cause, step-by-step reproduction instructions, evidence, and prioritized remediation guidance. This is the standard location for reproduction steps because it gives the client's technical staff the precise, contextual information they need to validate and fix the issue, while also linking each step to the associated risk and recommended action.

Why this answer

The 'Findings and recommendations' section is the correct location for detailed, step-by-step reproduction instructions because it provides the technical depth needed for the client's security team to validate and remediate each vulnerability. This section typically includes exact commands, payloads, and sequences used during testing, aligning with the PT0-002 objective of delivering actionable technical details.

Exam trap

The trap here is that candidates confuse the 'Executive summary' (which summarizes findings for management) with the 'Findings and recommendations' section, mistakenly thinking step-by-step instructions belong in the high-level overview due to a misunderstanding of report audience segmentation.

How to eliminate wrong answers

Option A is wrong because the executive summary is a high-level overview for non-technical stakeholders, focusing on business impact and risk posture, not step-by-step technical reproduction steps. Option B is wrong because the risk rating section assigns severity scores (e.g., CVSS v3.1 base scores) and prioritizes findings, but does not contain the granular procedural instructions needed to replicate vulnerabilities.

706
MCQmedium

A client has a highly dynamic cloud environment where resources are frequently spun up and down. What scoping challenge does this present?

A.Compliance issues
B.Lack of logs
C.Insufficient testing time
D.Inconsistent attack surface
AnswerD

Inconsistent attack surface is correct because a highly dynamic cloud environment—with auto-scaling groups, ephemeral containers, serverless functions, and infrastructure-as-code-driven provisioning—means the set of IP addresses, hostnames, subdomains, and services is constantly in flux. Penetration testing requires a defined scope (e.g., a list of assets or an IP range), but when resources are created and destroyed on demand, the scope may be outdated by the time testing begins, leading to missed assets or tests against decommissioned resources. This variability demands a scoping approach that uses cloud provider APIs to snapshot the live inventory at the start of the test, and even then, the tester must account for changes during the engagement. Thus, the inconsistent attack surface is the primary challenge, directly affecting test coverage, reproducibility, and the validity of the final report.

Why this answer

An inconsistent attack surface makes it difficult to define a stable scope of targets. Testing may miss transient resources or encounter resources that change during the engagement. Other options are risks but not specific scoping challenges.

707
MCQhard

During a penetration test, the tester gains a Meterpreter session on a Windows target and wants to escalate privileges to SYSTEM. The current user has the SeImpersonatePrivilege token. Which tool should the tester use to exploit this privilege?

A.PrintSpoofer
B.Windows-Exploit-Suggester
C.whoami /priv
D.Mimikatz
AnswerA

PrintSpoofer directly weaponizes SeImpersonatePrivilege: it creates a named pipe and abuses the Windows Print Spooler service to make a SYSTEM-level client connect and impersonate its token. Meterpreter sessions running as a service account with this privilege can use PrintSpoofer to instantly spawn a SYSTEM shell. Unlike suggestion or enumeration tools, it performs the actual privilege escalation, so it is the correct choice for this scenario.

Why this answer

PrintSpoofer exploits the SeImpersonatePrivilege to impersonate SYSTEM tokens.

708
MCQhard

A penetration tester is evaluating a cloud environment (AWS) and finds an S3 bucket with public write access. Which attack is most likely to succeed if the tester wants to plant malicious files that will be served to users?

A.Exhaust the bucket's storage quota
B.Upload a malicious JavaScript file to the bucket
C.Encrypt all objects in the bucket for ransom
D.Modify the bucket policy to grant further permissions
AnswerB

A bucket with public write (s3:PutObject for all principals) allows anyone to upload objects, including a crafted JavaScript file. If the bucket is used for static website hosting, an attacker can reference the uploaded .js file from a malicious page or inject it into a site that loads resources from that bucket, leading to XSS or malware distribution. This directly achieves the objective of planting malicious code in the cloud environment.

Why this answer

An S3 bucket with public write access allows anyone to upload objects without authentication. A penetration tester can upload a malicious JavaScript file (e.g., for cross-site scripting or drive-by download) that, when accessed by users via the bucket's public URL, executes in their browsers. This directly exploits the misconfiguration to serve malicious content to end users.

Exam trap

The trap here is that candidates may confuse 'public write access' with 'public read access' and assume the goal is to read data, or they may overthink the attack path and choose a privilege escalation option (D) instead of directly exploiting the write permission to plant malicious content.

How to eliminate wrong answers

Option A is wrong because exhausting the bucket's storage quota is a denial-of-service tactic, not a method to plant malicious files served to users; it disrupts availability but does not achieve the goal of serving malicious content. Option C is wrong because encrypting all objects for ransom (e.g., ransomware) requires write access but does not plant files that are served to users; it denies access to existing data and is a different attack vector (data extortion). Option D is wrong because modifying the bucket policy to grant further permissions is a privilege escalation step that could enable other attacks, but it does not directly plant malicious files to be served to users; the tester already has public write access, so changing the policy is unnecessary for the stated goal.

709
MCQmedium

A penetration tester is analyzing a Python script that uses the 'requests' library to send HTTP requests with a custom header that mimics a mobile device. The script also uses 'beautifulsoup4' to parse the response and extract specific data. Which task is this script most likely performing?

A.Web scraping to gather publicly available information.
B.Fuzzing for SQL injection.
C.Performing a brute-force attack on a login form.
D.Testing for directory traversal vulnerabilities.
AnswerA

This combination of requests and BeautifulSoup is the canonical web-scraping stack: requests fetches the raw HTML over HTTP, and BeautifulSoup parses it into a navigable tree to extract elements like links, meta tags, or table rows. The mobile User-Agent mimics a smartphone browser, which helps bypass simple bot-detection rules and retrieve the exact responsive markup a normal visitor would see. Gathering publicly available information this way is a low-risk, passive OSINT technique, and the script's design shows no active attack payloads, making web scraping the only fitting purpose.

Why this answer

The script uses the 'requests' library to send HTTP requests with a custom header mimicking a mobile device, and 'beautifulsoup4' to parse the HTML response and extract data. This combination is specifically designed for web scraping, where the custom header helps avoid bot detection by making the request appear to come from a mobile browser, and BeautifulSoup extracts targeted information from the page structure.

Exam trap

The trap here is that candidates may confuse the use of a custom header with security testing (e.g., fuzzing or brute-forcing), but the presence of BeautifulSoup for HTML parsing clearly indicates data extraction, not injection or authentication bypass.

How to eliminate wrong answers

Option B is wrong because fuzzing for SQL injection typically involves sending malformed input (e.g., special characters, SQL keywords) in parameters or form fields, not setting a custom User-Agent header or parsing HTML with BeautifulSoup; tools like Burp Suite Intruder or custom loops with 'requests' are used, but the focus is on injecting payloads, not extracting data from responses. Option C is wrong because a brute-force attack on a login form requires iterating through username/password combinations and analyzing response status codes or error messages, not simply setting a mobile User-Agent and parsing HTML for data extraction; BeautifulSoup is unnecessary for brute-force logic, which typically checks for login success indicators like redirects or specific text.

710
MCQhard

During a penetration test, a tester identifies a buffer overflow vulnerability in a Linux binary. The system has ASLR and NX (Non-Executable) enabled. The tester finds a ROP gadget at a fixed address in a library that is loaded at a constant address across reboots. Which exploitation method is the most appropriate to achieve code execution?

A.Return-to-libc attack
B.Return-Oriented Programming (ROP) chain
C.Heap spraying
D.SEH overwrite exploit
AnswerB

ROP chains bypass both NX and, when gadget addresses are known (e.g., non-PIE binaries or after an info leak), ASLR by reusing short instruction sequences—gadgets—present in executable memory such as libc. The attacker controls the stack to chain gadgets that each end in a ret, allowing arbitrary operations like setting registers and calling functions without injecting shellcode. This makes ROP the most flexible and reliable code-reuse technique for a modern buffer overflow, far beyond a single function call.

Why this answer

Return-Oriented Programming (ROP) is specifically designed to bypass both ASLR and NX when a fixed-address ROP gadget is available. Since the library is loaded at a constant address across reboots, the tester can chain gadgets from that library to execute arbitrary code without needing to inject executable shellcode.

Exam trap

The trap here is that candidates may confuse return-to-libc with ROP, but return-to-libc is limited to calling a single function and cannot chain multiple gadgets, which is necessary for complex code execution when NX is enabled.

How to eliminate wrong answers

Option A is wrong because a return-to-libc attack typically relies on calling a single function (e.g., system()) and does not provide the flexibility to chain multiple operations; it is less effective when ASLR randomizes the base address of libc, but here the library is at a fixed address, making ROP more appropriate for complex code execution. Option C is wrong because heap spraying is a technique used to increase the predictability of heap layout for exploiting use-after-free or heap overflow vulnerabilities, not for bypassing NX or achieving code execution via a buffer overflow with ROP gadgets.

711
MCQeasy

A client wants a social engineering test focusing on phishing. What should be included in the scope to ensure ethical handling?

A.The rules of engagement for notifying employees after the test
B.The attacker infrastructure details
C.The list of approved sender domains to use
D.The expected number of employees who should fall for the email
AnswerA

Rules of engagement define the authorised scope, timing, and post-test notification process, satisfying the ethical-handling requirement. Specifying how and when employees are informed prevents real-world harm, protects the client's staff, and keeps the phishing simulation within agreed legal and contractual boundaries.

Why this answer

The correct answer is A: the rules of engagement for notifying employees after the test, because a phishing social engineering engagement must define how and when targets are debriefed or notified to avoid causing undue harm, panic, or operational disruption, and to keep the test ethical and authorized. Rules of engagement also establish authorization boundaries, escalation contacts, and handling of any real credentials or sensitive data captured during the phishing simulation. Option B is not appropriate for the scope document because exposing attacker infrastructure details is an operational detail, not an ethical safeguard.

Option C, approved sender domains, is a technical setup item rather than the ethical handling requirement. Option D, the expected number of employees who fall for the email, is a success metric, not a control for ethical conduct.

712
MCQeasy

A penetration tester wants to use Google dorking to find publicly accessible documents containing sensitive information on a target domain 'example.com'. Which Google dork would be MOST appropriate to locate PDF files with the word 'confidential'?

A.site:example.com intitle:confidential pdf
B.filetype:pdf site:example.com password
C.site:example.com filetype:pdf confidential
D.site:example.com inurl:pdf confidential
AnswerC

This is the correct Google dork for the objective. The site:example.com operator confines results to the target domain, filetype:pdf restricts results to PDF files, and the standalone keyword 'confidential' matches pages where that term appears within the indexed text of the PDF. Search engines like Google extract and index text content from PDFs, so this query effectively surfaces PDF documents on example.com that contain the word 'confidential,' which is exactly what a penetration tester would want to find during reconnaissance.

Why this answer

The Google dork 'site:example.com filetype:pdf confidential' combines the site restriction to the target domain, the filetype filter for PDFs, and the keyword 'confidential' to search for PDF documents containing that word. This directly matches the requirement to locate publicly accessible PDF files with the word 'confidential' on example.com.

Exam trap

The trap here is that candidates often confuse 'filetype:pdf' with 'inurl:pdf' or 'intitle:pdf', not realizing that 'filetype' specifically filters by file extension, while 'inurl' and 'intitle' search for text in the URL or title, which may not correspond to actual PDF files.

How to eliminate wrong answers

Option A is wrong because 'intitle:confidential pdf' searches for the word 'confidential' in the page title and the literal word 'pdf' anywhere in the page, not for PDF files containing 'confidential'. Option B is wrong because it searches for PDF files containing the word 'password', not 'confidential'. Option D is wrong because 'inurl:pdf confidential' looks for the string 'pdf' in the URL and the word 'confidential' anywhere on the page, which does not guarantee the file is a PDF and may miss PDFs with 'confidential' in the content.

713
Multi-Selectmedium

A penetration tester is conducting a vulnerability scan of a Linux server using OpenVAS. Which TWO scan configurations would provide the MOST comprehensive results? (Select TWO.)

Select 2 answers
A.Scan using the 'Full and fast' configuration
B.Scan using only the 'Discovery' category
C.Authenticated scan with SSH credentials
D.Scan using the 'Denial of Service' configuration
E.Unauthenticated scan with default settings
AnswersA, C

The 'Full and fast' profile in Nessus is the recommended comprehensive scan policy: it activates all plugins except those tagged as 'Denial of Service' or potentially disruptive, and it enables safe port scanning techniques. This ensures maximum vulnerability coverage across all plugin families (such as Windows, Linux, web applications, and databases) while still avoiding outright service disruption. It is the default starting point for a penetration test's vulnerability assessment phase.

Why this answer

Authenticated scans with credentials allow the scanner to log in and check for missing patches, misconfigurations, and vulnerabilities that are not visible externally. Full and fast scan configurations are typical for comprehensive coverage.

714
MCQmedium

A penetration tester is analyzing a Python script that uses the 'scapy' library to craft custom network packets. The relevant code is: ```python from scapy.all import * packet = IP(dst="192.168.1.1")/TCP(dport=80, flags="S") response = sr1(packet, timeout=2) if response.haslayer(TCP): print(response.getlayer(TCP).flags) ``` What is the primary goal of this script?

A.To perform a TCP connect scan by completing the three-way handshake
B.To perform a SYN scan and determine if port 80 is open
C.To send an HTTP GET request and capture the web page
D.To perform a UDP scan on port 80
AnswerB

This script correctly implements a SYN scan: it crafts a TCP packet with the SYN flag set, sends it to port 80, and then reads the response flags to infer the port's state. If the target replies with a SYN-ACK, the port is open, because the target is willing to begin a handshake; if it replies with an RST, the port is closed or filtered. The script does not send the final ACK, so it never completes the handshake—confirming that it is a half-open SYN scan designed solely to detect open ports such as TCP 80.

Why this answer

The script uses Scapy to craft a TCP SYN packet (flags='S') to port 80 and sends it with sr1(), which waits for a single response. If a TCP layer is present in the reply, it prints the flags. This is the classic behavior of a SYN scan (half-open scan): it sends a SYN and analyzes the response to determine if the port is open (SYN-ACK) or closed (RST), without completing the handshake.

Option B correctly identifies this as a SYN scan to check if port 80 is open.

Exam trap

The trap here is that candidates may confuse a SYN scan with a full connect scan (Option A) because both involve sending a SYN, but the key difference is that a SYN scan never sends the final ACK, making it stealthier and not a full handshake.

How to eliminate wrong answers

Option A is wrong because a TCP connect scan completes the full three-way handshake (SYN, SYN-ACK, ACK), whereas this script only sends a SYN and does not send the final ACK, making it a half-open SYN scan. Option C is wrong because the script sends a raw TCP SYN packet, not an HTTP GET request; it does not include any HTTP payload or application-layer data, so it cannot retrieve a web page.

715
MCQhard

A penetration tester is conducting vulnerability scanning on a web application that uses a Web Application Firewall (WAF). The scanner triggers a WAF block after several requests. Which of the following techniques would be MOST effective to continue scanning while evading the WAF?

A.Increase scan speed
B.Randomize request parameters and headers
C.Use HTTP/2 multiplexing
D.Perform a full TCP connect scan
AnswerB

Varying parameters and headers per request breaks the signature patterns a WAF uses to correlate and block traffic, so the scanner's payloads no longer match known attack fingerprints. This satisfies the stem's constraint of continuing the scan after a block without altering the underlying vulnerability checks.

Why this answer

Randomizing request parameters and headers (option B) is the most effective WAF evasion technique here because it breaks the signature and pattern-matching heuristics WAFs rely on, making each request appear unique and preventing the scanner from being fingerprinted and blocked after repeated identical payloads. Varying parameter order, casing, encoding, and header values (e.g., User-Agent, Referer) also helps slip past rate- and anomaly-based rules. Increasing scan speed (A) would generate more suspicious traffic and trigger the WAF even faster.

HTTP/2 multiplexing (C) only changes transport framing and does not alter the request signatures a WAF inspects. A full TCP connect scan (D) is a port-scanning technique and is irrelevant to evading a WAF at the application layer.

716
MCQeasy

During a penetration test, a tester discovers a web application that reflects user input in the HTTP response without sanitization. Which attack is most likely to be successful?

A.Server-side request forgery
B.SQL injection
C.Reflected cross-site scripting
D.Cross-site request forgery
AnswerC

Reflected cross-site scripting (XSS) occurs when an application immediately includes unvalidated or unencoded user input in its response, allowing an attacker to inject executable JavaScript. This matches the discovered behavior of input being echoed back; the payload runs in the victim's browser under the trust of the origin site. Exploitation usually involves tricking a victim into clicking a crafted URL, and the payload is non-persistent, disappearing after the response is rendered.

Why this answer

Reflected cross-site scripting (XSS) is the correct answer because the vulnerability described—user input reflected in the HTTP response without sanitization—directly enables an attacker to inject malicious scripts (e.g., JavaScript) that execute in the victim's browser. This occurs when the application fails to validate or encode the input before including it in the response, allowing the attacker to craft a URL with a script payload that, when visited, runs in the context of the vulnerable web application's origin.

Exam trap

The trap here is that candidates often confuse reflected XSS with stored XSS or CSRF, but the key differentiator is that the input is immediately reflected in the response without sanitization, not stored on the server or requiring a forged request.

How to eliminate wrong answers

Option A is wrong because server-side request forgery (SSRF) exploits server-side functionality to make requests to internal or external resources, not the reflection of user input in HTTP responses. Option B is wrong because SQL injection targets database queries by injecting SQL commands into input fields, not by reflecting input in HTTP responses without sanitization. Option D is wrong because cross-site request forgery (CSRF) tricks a user into performing unintended actions on a web application where they are authenticated, relying on forged requests rather than reflected input in the response.

717
MCQhard

During a web application test, the tester discovers that the application uses JSON Web Tokens (JWT) for authentication. The tester modifies the JWT header to set the algorithm to 'none' and removes the signature. The server accepts the token. What type of attack is this?

A.JWT algorithm confusion (alg:none)
B.JWT injection
C.JWT session stealing
D.JWT secret brute-force
AnswerA

This is a JWT algorithm confusion attack where the attacker modifies the JWT header to set the `alg` field to `none`, removing the signature entirely. If the server's JWT library naively trusts the header and skips signature verification for `alg:none`, the attacker can forge arbitrary tokens and impersonate any user. Modern libraries should enforce an explicit algorithm allowlist, but misconfigured legacy systems remain vulnerable.

Why this answer

Setting the JWT algorithm to 'none' exploits a misconfiguration where the server does not enforce signature verification, leading to JWT algorithm confusion.

718
MCQmedium

A penetration tester is analyzing a PowerShell script that uses Invoke-WebRequest and Invoke-RestMethod to interact with a target web service. The script parses JSON responses to extract session tokens and then uses those tokens in subsequent requests. Which attack technique is this script most likely performing?

A.Brute-forcing web application login credentials.
B.Exploiting an API by manipulating request parameters and observing responses.
C.Performing a SQL injection attack on a web form.
D.Conducting a directory traversal attack to read arbitrary files.
AnswerB

Exploiting an API by manipulating request parameters and observing responses is the correct interpretation. The script dynamically extracts session tokens from prior responses, then reuses them to make authenticated requests while altering parameters such as resource IDs, role fields, or JSON payloads. By analyzing status codes, response bodies, and error messages, the tester can identify authorization flaws (e.g., IDOR), mass assignment, or business logic issues—without needing to bypass authentication itself.

Why this answer

The script uses Invoke-WebRequest and Invoke-RestMethod to interact with a web service, parsing JSON responses to extract session tokens and reusing them in subsequent requests. This pattern is characteristic of API manipulation, where an attacker modifies request parameters (e.g., headers, query strings, or payload) and observes how the API responds to infer vulnerabilities or escalate privileges, rather than directly attacking authentication or injecting SQL.

Exam trap

The trap here is that candidates confuse the use of Invoke-WebRequest and Invoke-RestMethod with brute-force attacks, but the script's focus on token extraction and reuse points to API parameter manipulation, not credential guessing.

How to eliminate wrong answers

Option A is wrong because brute-forcing login credentials would involve repeatedly submitting different username/password pairs, not parsing JSON session tokens from responses and using them in subsequent requests; the script's focus on token extraction indicates session management exploitation, not credential guessing. Option C is wrong because SQL injection requires injecting SQL syntax into input fields to manipulate database queries, whereas the script uses Invoke-WebRequest and Invoke-RestMethod to handle structured JSON data and tokens, with no mention of SQL payloads or database error responses.

719
Multi-Selectmedium

A penetration tester is performing a Kerberoasting attack. Which TWO steps are required for a successful Kerberoasting attack?

Select 2 answers
A.Enumerate domain admins
B.Request TGS tickets for service accounts
C.Perform a relay attack
D.Crack the TGS tickets offline using Hashcat
E.Capture NTLMv2 hashes using Responder
AnswersB, D

Kerberoasting begins with an authenticated user requesting TGS tickets for accounts that have SPNs registered, typically via tools like Rubeus or GetUserSPNs. The returned ticket is encrypted with the target service account's NTLM hash, so capturing these tickets yields a hash that can be cracked offline without any further network interaction. This step is the core of the attack because it obtains the password hash in an extractable format, and it works with only standard domain credentials.

Why this answer

Kerberoasting involves requesting TGS tickets for service accounts and then cracking the tickets offline.

720
Multi-Selecthard

A penetration tester is handling a client's pushback on a finding. Which THREE approaches are appropriate? (Select THREE.)

Select 3 answers
A.Re-evaluate the finding and adjust if new information is available
B.Provide additional evidence to support the finding
C.Immediately lower the severity to satisfy the client
D.Listen to the client's concerns and discuss them
E.Refuse to change the report under any circumstances
AnswersA, B, D

Re-evaluating a finding when new information is presented aligns with the fundamental principle of evidence-based penetration testing. The tester should treat each finding as a hypothesis that is validated by both technical proof and environmental context; if the client provides new facts—such as a compensating control, a patched system, or an architectural detail that alters exploitability—the severity and validity must be updated accordingly. This is not capitulation but professional diligence, ensuring the report accurately reflects the client's true risk posture.

Why this answer

When handling pushback, the tester should listen, provide evidence, and possibly adjust the report if valid points are made.

721
MCQhard

A penetration tester is evaluating vulnerabilities using the DREAD model. For a specific vulnerability, the tester assigns the following scores: Damage=8, Reproducibility=7, Exploitability=9, Affected users=6, Discoverability=5. Which of the following is the overall DREAD risk rating?

A.9
B.8
C.7
D.6
AnswerC

The average vulnerability score equals 7 because the sum of all CVSS base scores divided by the number of assessed findings yields exactly 7. In CVSS v3.1, 7.0 falls in the High severity band (7.0-8.9), accurately reflecting a set that contains both critical and medium findings. This is the correct mean, and it is the appropriate metric for communicating baseline risk posture across the discovered vulnerabilities.

Why this answer

DREAD scores are averaged across the five categories. Compute (8+7+9+6+5)/5 = 35/5 = 7.

722
MCQmedium

You are testing a web application and notice that it uses JSON Web Tokens (JWT) for authentication. You change the algorithm to 'none' and remove the signature, and the token is accepted. Which JWT vulnerability did you exploit?

A.KID injection
B.Algorithm none attack
C.Weak secret brute-force
D.Token replay
AnswerB

In an algorithm none attack, the attacker modifies the JWT header to set 'alg':'none' and strips the signature segment, causing a vulnerable server to accept the token without cryptographic verification. Many JWT libraries only execute signature verification for asymmetric or HMAC algorithms and skip it entirely when alg is 'none' unless explicitly forbidden. This directly matches the observation of bypassing signature verification, so it is the correct answer.

Why this answer

Alg:none attack exploits weak validation that accepts unsigned tokens.

723
MCQmedium

A tester is performing a privilege escalation on a Windows system and finds that the user has SeImpersonatePrivilege enabled. Which tool could be used to escalate to SYSTEM?

A.PsExec
B.PrintSpoofer
C.evil-winrm
D.pth-winexe
AnswerB

PrintSpoofer is a local privilege escalation tool that exploits SeImpersonatePrivilege, a Windows privilege often held by service accounts. It leverages the Print Spooler service by creating a named pipe and tricking the spooler into connecting to it, allowing the attacker to impersonate a SYSTEM token. This enables command execution as SYSTEM without requiring remote credentials or network services.

Why this answer

SeImpersonatePrivilege can be exploited using tools like PrintSpoofer or Potato attacks to impersonate SYSTEM tokens.

724
MCQhard

You have obtained a NTLM hash of a domain admin account and want to authenticate to a remote server without cracking the password. Which technique enables you to authenticate using the hash?

A.Pass-the-Hash
B.AS-REP roasting
C.Pass-the-Ticket
D.Kerberoasting
AnswerA

Pass-the-Hash (PtH) allows an attacker to authenticate to remote systems by supplying the NTLM hash directly instead of the plaintext password. Because NTLM challenge-response authentication uses the hash as the shared secret, the hash is sufficient to impersonate the user without cracking it. This technique is commonly exploited against SMB and other NTLM-authenticating services, making it the direct and correct use of an obtained NTLM hash.

Why this answer

Pass-the-hash uses the NTLM hash directly to authenticate without needing the plaintext password. Tools like pth-winexe or CrackMapExec can perform this.

725
MCQmedium

A penetration tester is performing active reconnaissance on a target network. The tester wants to identify all live hosts in the 192.168.1.0/24 subnet and determine which ones have port 80 open. Which technique is most efficient for this task?

A.Perform a full TCP connect scan on all 65535 ports for each IP address.
B.Use a ping sweep to identify live hosts, then run a SYN scan on port 80 for those hosts.
C.Run a SYN scan on port 80 for every IP in the subnet without ping probing.
D.Use ARP requests to map the subnet and then check for port 80 on each host.
AnswerB

A ping sweep quickly identifies which IPs in the subnet are responsive, allowing the tester to focus scanning effort on live targets only. A SYN scan sends a single SYN packet and evaluates the response without completing the handshake, making it faster and less likely to be logged than a full connect scan. Running the SYN scan on only port 80 for the discovered live hosts is efficient and directly addresses the objective of finding web servers, minimizing traffic and detection risk.

Why this answer

It combines two efficient steps: first, a ping sweep (ICMP Echo Request or ARP scan) identifies live hosts in the 192.168.1.0/24 subnet, reducing the number of targets; second, a SYN scan on port 80 for only those live hosts is faster and less intrusive than scanning all ports or all IPs without prior host discovery. This approach minimizes network traffic and scan time while accurately identifying hosts with HTTP services.

Exam trap

The trap here is that candidates often choose option C, thinking that skipping ping probing saves time, but they overlook the inefficiency of scanning all 256 IPs (including many dead hosts) versus first identifying live hosts to reduce the scan scope.

How to eliminate wrong answers

Option A is wrong because performing a full TCP connect scan on all 65535 ports for each IP in a /24 subnet is highly inefficient, generating massive traffic and taking excessive time, and it does not focus on the specific goal of identifying hosts with port 80 open. Option C is wrong because running a SYN scan on port 80 for every IP in the subnet without ping probing wastes time and resources scanning inactive or non-existent hosts, and it may also trigger intrusion detection systems more aggressively due to scanning dead IPs.

726
MCQeasy

When performing vulnerability scanning, which of the following best describes a false positive?

A.A vulnerability that is correctly identified and verified.
B.A vulnerability that is exploited during the test.
C.A vulnerability that the scanner reports but does not actually exist.
D.A vulnerability that exists but the scanner fails to detect it.
AnswerC

This is the definition of a false positive: the scanner generates an alert based on a signature, version banner, or service fingerprint, but the claimed vulnerability does not actually exist in the target environment. For example, an automated scanner might flag a TLS configuration or an installed software version as vulnerable because the detection logic matches a generic CVE, even though the vendor has backported security patches or the vulnerable component is disabled. Such erroneous reports consume remediation resources and cause confusion, which is why manual verification is required before acting on scan results.

Why this answer

A false positive in vulnerability scanning occurs when the scanner reports a vulnerability that does not actually exist. This is option C. False positives are caused by factors such as overly aggressive signature matching, misconfigured scan profiles, or incomplete verification of service responses.

They waste resources by prompting unnecessary remediation efforts.

Exam trap

The trap here is confusing false positives with false negatives; candidates often pick option D because they misremember the definition, but false negatives are missed vulnerabilities, not incorrect reports.

How to eliminate wrong answers

Option A is wrong because a vulnerability that is correctly identified and verified is a true positive, not a false positive. Option B is wrong because a vulnerability that is exploited during the test is a confirmed exploit, not a false positive; false positives are not exploitable. Option D is wrong because a vulnerability that exists but the scanner fails to detect it is a false negative, not a false positive.

727
MCQeasy

A penetration tester has completed an internal network test. The client's IT manager requests a document that lists each vulnerability with its CVSS score, risk rating, and a brief description of the impact. Which section of the final report should contain this information?

A.Executive Summary
B.Technical Findings
C.Methodology
D.Remediation Summary
AnswerB

The Technical Findings section is the core repository for detailed vulnerability disclosures, listing each finding with its CVSS score, risk rating, affected systems, and a technical description of the impact and exploitation context. This section is specifically tailored for technical staff—such as system administrators, network engineers, and developers—who need precise data to validate and remediate the issues. It is exactly where a pentester documents the technical details of discovered vulnerabilities.

Why this answer

The Technical Findings section is the correct location because it provides a detailed, itemized list of each discovered vulnerability, including its CVSS score, risk rating, and impact description. This section is intended for technical stakeholders who need granular data to prioritize remediation, unlike the Executive Summary which offers high-level business impact and risk overviews.

Exam trap

The trap here is that candidates confuse the Executive Summary's role as a summary of all findings with the Technical Findings' role of providing detailed, per-vulnerability data, leading them to incorrectly select the Executive Summary for listing CVSS scores and impacts.

How to eliminate wrong answers

Option A is wrong because the Executive Summary is a high-level overview for non-technical management, focusing on business risk, strategic recommendations, and key findings without listing individual CVSS scores or detailed impact descriptions. Option C is wrong because the Methodology section describes the tools, techniques, and procedures used during the test (e.g., Nmap scans, exploitation frameworks), not the specific vulnerabilities found.

728
MCQeasy

In a penetration test report, which section should contain detailed technical information such as affected systems, proof-of-concept code, and remediation steps?

A.Technical findings
B.Appendices
C.Executive summary
D.Methodology
AnswerA

The technical findings section is the core of the report where each vulnerability is described with its technical details, including affected systems, proof-of-concept steps, CVSS scores, and remediation recommendations. It serves as the authoritative reference for technical readers and justifies the risk ratings. Without this section, the report would lack actionable evidence for developers and engineers.

Why this answer

The technical findings section is where detailed vulnerability descriptions, evidence, and remediation steps are documented.

729
MCQeasy

Which Metasploit command is used to display information about the current meterpreter session, including the target OS and user?

A.hashdump
B.getuid
C.getsystem
D.sysinfo
AnswerD

sysinfo is the correct Meterpreter command for system reconnaissance, as it displays the target operating system version, computer name, architecture (e.g., x64 or x86), and sometimes the Meterpreter payload type and domain. This information lets a penetration tester choose compatible exploits, payloads, or enumeration modules, and it is the first logical step after gaining a session.

Why this answer

The 'sysinfo' meterpreter command displays system information such as OS, architecture, and sometimes user context.

730
MCQmedium

Which of the following penetration testing standards includes detailed guidelines for pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting?

A.OSSTMM
B.OWASP Testing Guide
C.NIST SP 800-115
D.PTES
AnswerD

PTES (Penetration Testing Execution Standard) is the only option that expressly defines a complete penetration testing methodology from start to finish. It covers pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting. This makes it a comprehensive standard suitable for guiding all phases of a professional penetration test.

Why this answer

PTES (Penetration Testing Execution Standard) covers the entire testing lifecycle from pre-engagement to reporting.

731
MCQmedium

A multi-tenant SaaS application needs tenant isolation testing. Which type of testing is most appropriate?

A.White-box testing with access to source code
B.Vulnerability scanning of the underlying infrastructure
C.Black-box testing from the internet
D.Gray-box testing with a tenant account
AnswerD

Allows testing from an authenticated perspective.

Why this answer

Gray-box testing with a tenant account (D) is correct because the tester has legitimate authenticated access as one tenant, which is exactly what is needed to attempt cross-tenant access and verify isolation controls such as authorization checks, tenant ID scoping, and data segregation. This partial-knowledge approach lets testers probe APIs, object references, and session handling realistically without needing source code. White-box testing (A) requires source code access and is not necessary or typical for validating runtime tenant isolation.

Vulnerability scanning of infrastructure (B) targets hosts and services, not application-level tenant boundaries, and black-box testing from the internet (C) lacks an authenticated tenant context needed to test cross-tenant access.

732
MCQmedium

A penetration tester is performing reconnaissance on a target organization and uses Shodan to find internet-facing devices. Which of the following is the BEST use case for Shodan in this context?

A.Identifying subdomains through DNS brute-forcing
B.Discovering open ports and services on public IP ranges
C.Enumerating email addresses from corporate websites
D.Extracting metadata from documents found on the target's website
AnswerB

Shodan continuously scans the public IPv4 address space (and some IPv6) and stores the service banners it collects from open ports. A penetration tester can query Shodan for a target organization's public IP ranges using the `net:` filter to instantly discover exposed ports, identify running services and their versions, and detect misconfigurations or unpatched software. This provides a passive, external view of the attack surface before any active scanning is performed, which is both efficient and useful for planning further intrusion attempts.

Why this answer

Shodan is a search engine for internet-connected devices that scans public IP ranges and indexes the banners returned by services. Its primary use in reconnaissance is to discover open ports and running services on target IP ranges, revealing attack surface such as exposed databases, web servers, or industrial control systems. This aligns directly with the information-gathering phase of a penetration test.

Exam trap

The trap here is that candidates confuse Shodan's banner-gathering capability with active DNS enumeration or web scraping, leading them to select options that describe unrelated reconnaissance tasks.

How to eliminate wrong answers

Option A is wrong because Shodan does not perform DNS brute-forcing; that task is accomplished with tools like dnsrecon, subfinder, or Gobuster, which query DNS servers directly. Option C is wrong because Shodan indexes service banners and device metadata, not email addresses from corporate websites; email enumeration is typically done via web scraping, search engines, or tools like theHarvester.

733
Multi-Selecthard

During a penetration test, the tester discovers a critical SQL injection vulnerability. The client cannot deploy the full fix (parameterized queries) immediately due to legacy code. Which THREE actions should the tester recommend as compensating controls? (Choose three.)

Select 3 answers
A.Disable detailed error messages to prevent information disclosure
B.Restrict the database account used by the application to least privilege
C.Patch the database management system to the latest version
D.Implement a web application firewall (WAF) rule to block SQL injection patterns
E.Apply input validation and sanitization on the affected parameters
AnswersB, D, E

Restricting the database account to least privilege ensures that even when SQL injection succeeds, the attacker's actions are limited to the permissions granted to that account, such as SELECT on specific tables. Without this control, a privileged account (e.g., sa or a database owner) could be used to read sensitive data, write files, execute stored procedures, or escalate to operating system access, turning a single injection point into a full database compromise.

Why this answer

Compensating controls reduce risk while the full fix is pending. WAF rules, input validation, and restricted DB privileges are appropriate. Disabling error messages is not a direct compensating control, and patching the DBMS may not address the injection.

734
MCQeasy

Which of the following tools is primarily used for enumerating subdomains via search engine queries?

A.Metasploit
B.Netcat
C.theHarvester
D.Nmap
AnswerC

theHarvester is a dedicated OSINT (open-source intelligence) tool that systematically queries search engines, PGP key servers, and Shodan to collect emails, subdomains, hosts, and employee names. Its passive, API-based data collection is explicitly designed for reconnaissance of a domain without actively sending packets to the target. This makes it the correct choice for enumeration tasks that leverage public information.

Why this answer

theHarvester is specifically designed to gather emails, subdomains, IPs, and URLs from public sources, including search engines like Google, Bing, and Yahoo. It leverages search engine APIs and scraping techniques to enumerate subdomains without directly interacting with the target infrastructure, making it the correct tool for this task.

Exam trap

The trap here is that candidates often confuse Nmap's DNS brute-force scripts (like dns-brute) with passive subdomain enumeration, but Nmap actively queries DNS servers, whereas theHarvester passively collects data from search engines without touching the target's infrastructure.

How to eliminate wrong answers

Option A is wrong because Metasploit is a penetration testing framework focused on exploit development and execution, not passive subdomain enumeration via search engines. Option B is wrong because Netcat is a networking utility for reading/writing data across TCP/UDP connections, lacking any search engine querying capability. Option D is wrong because Nmap is a network scanner that probes live hosts and services using raw packets, not a tool for passive subdomain discovery through search engine queries.

735
MCQhard

A penetration tester is tasked with performing vulnerability scanning on a target organization that uses a web application firewall (WAF) and an intrusion prevention system (IPS). The tester wants to avoid being blocked while still gathering comprehensive data. Which scanning approach is most effective?

A.Use a slow, distributed scan from multiple IP addresses with random delays
B.Perform an aggressive scan with a high thread count to complete before the WAF adapts
C.Only perform passive reconnaissance and avoid active scanning
D.Use known WAF bypass techniques for each request
AnswerA

A slow, distributed scan from multiple IP addresses with random delays evades rate-based and behavioral detection by mimicking organic traffic patterns. Modern IPS/WAF platforms correlate request frequency, source entropy, and timing signatures; spreading the load across a botnet-like source pool with jittered intervals keeps the aggregate request rate under the alert threshold while still enumerating services. This approach is the standard for stealthy active scanning in high-security environments, as it trades speed for reliability and avoids the self-defeating burst that triggers countermeasures.

Why this answer

A slow, distributed scan from multiple IP addresses with random delays is most effective because it evades rate-based detection mechanisms in WAFs and IPSs. By spreading the scan across many sources and introducing jitter, the traffic appears as normal user activity rather than a coordinated attack, allowing comprehensive data collection without triggering blocks.

Exam trap

The trap here is that candidates assume a fast, aggressive scan will 'beat' the WAF/IPS before it adapts, but in reality these systems use real-time rate limiting and signature detection that will block the source IP almost immediately, making the slow distributed approach the only viable option.

How to eliminate wrong answers

Option B is wrong because an aggressive scan with a high thread count will rapidly generate a high volume of requests, which WAFs and IPSs are specifically designed to detect and block as a denial-of-service or scanning pattern, likely resulting in the tester being blocked before completion. Option C is wrong because passive reconnaissance alone cannot gather comprehensive vulnerability data such as open ports, service versions, or missing patches, which require active probing to identify.

736
Multi-Selectmedium

Which TWO of the following should be included in the methodology section of a penetration test report?

Select 2 answers
A.List of vulnerabilities discovered
B.Step-by-step remediation instructions
C.The client's network diagram
D.The specific tools and commands used during testing
E.The testing approach (e.g., black-box, white-box)
AnswersD, E

The specific tools and commands used during testing are a core part of the methodology because they document the exact commands, scripts, and utilities (e.g., Nmap, Burp Suite, SQLmap) that were executed to conduct the assessment. This provides transparency, reproducibility, and allows the client to understand the technical context behind any findings. It also enables peer reviewers to validate that the testing was performed in a safe and effective manner.

Why this answer

Option D is correct because the methodology section must document the specific tools and commands used during testing, such as Nmap, Metasploit, or Burp Suite invocations, so the client can understand exactly how the assessment was performed and reproduce or validate the results. Option E is correct because the testing approach (black-box, white-box, or gray-box) defines the scope, knowledge level, and perspective from which the testers operated, which is essential for interpreting the findings correctly. Options A, B, and C do not belong in the methodology section: discovered vulnerabilities are typically detailed in the findings/results section, remediation instructions belong in the recommendations or remediation section, and the client's network diagram is usually included as an appendix or supporting artifact rather than as part of the methodology narrative.

Exam trap

CompTIA often tests the distinction between the methodology section (which describes the 'how' and 'approach') and the findings/recommendations sections, leading candidates to mistakenly include vulnerability lists or remediation steps in the methodology.

737
MCQmedium

A penetration tester is analyzing a Bash script that uses 'curl' to send HTTP requests with payloads and checks for a specific string in the response. The script contains: 'if echo $response | grep -q "root:x:0:0"'. Which vulnerability is the script most likely testing for?

A.SQL injection
B.Local file inclusion
C.Cross-site scripting
D.Remote code execution
AnswerB

Local File Inclusion (LFI) occurs when a web application uses user-controlled input in file operations such as PHP's include() without proper sanitization. By supplying traversal sequences like ../../../../etc/passwd, an attacker forces the server to read and emit local file contents. The response containing 'root:x:0:0' confirms the server is outputting the /etc/passwd file, making LFI the correct classification for this curl-based test.

Why this answer

The script checks for the string 'root:x:0:0' in the HTTP response, which is the standard format of the root user entry in the /etc/passwd file on Unix-like systems. This indicates the script is testing whether the server is returning the contents of a local file (e.g., /etc/passwd) via a path traversal or file inclusion vulnerability, making Local File Inclusion (LFI) the correct answer.

Exam trap

The trap here is that candidates may confuse the presence of a specific string in the response with SQL injection (e.g., thinking 'root:x:0:0' is a database record), but the format is a direct match for the /etc/passwd file, which is a classic LFI indicator.

How to eliminate wrong answers

Option A is wrong because SQL injection typically involves manipulating SQL queries to extract database contents, not checking for static system file strings like 'root:x:0:0'. Option C is wrong because cross-site scripting (XSS) focuses on injecting client-side scripts into web pages, not on retrieving server-side file contents. Option D is wrong because remote code execution (RCE) would involve executing arbitrary commands on the server, whereas the script only checks for a file content string in the response, not command output or execution indicators.

738
Multi-Selectmedium

A penetration tester is conducting passive reconnaissance using OSINT techniques. Which TWO of the following are examples of passive OSINT sources?

Select 2 answers
A.Social engineering
B.Certificate transparency logs (crt.sh)
C.snmpwalk
D.WHOIS databases
E.Nmap SYN scan
AnswersB, D

Certificate transparency logs are publicly published records of issued TLS certificates, so querying crt.sh never touches the target's infrastructure. This satisfies the stem's passive constraint, unlike active scanning or direct enumeration, which would generate traffic visible to the target's monitoring.

Why this answer

Certificate transparency logs (crt.sh) (B) are a passive OSINT source because they are public, third-party repositories of issued TLS certificates that a tester can query without sending any traffic to the target's infrastructure, revealing subdomains and hostnames. WHOIS databases (D) are also passive OSINT, as registration records for domains and IP ranges are queried from registry/RIR servers rather than the target itself, exposing registrant, contact, and nameserver data. By contrast, social engineering (A) is an active engagement technique that involves direct interaction with people, not passive collection. snmpwalk (C) actively sends SNMP queries to a device, and an Nmap SYN scan (E) actively probes target ports with TCP SYN packets, so both generate traffic toward the target and are not passive.

Exam trap

CompTIA Pentest+ often tests the distinction between passive reconnaissance (no direct interaction with the target) and active reconnaissance (generates traffic or requires interaction), and candidates may mistakenly classify tools like snmpwalk or Nmap scans as passive because they are automated or do not require credentials.

739
MCQhard

A penetration testing firm is contracted to perform an external test of a company's web applications. During the scoping meeting, the client mentions that they use a CDN and WAF provided by a third party. The client wants the test to accurately reflect the security of their backend servers behind these protections. What should the tester recommend?

A.Test the CDN and WAF as part of the scope
B.Obtain the backend server IPs from the client and test them directly
C.Include a plan to bypass the WAF in the rules of engagement
D.Only test the public-facing URLs as they are
AnswerB

Obtaining the backend server IPs from the client allows the tester to directly assess the origin servers the client wants evaluated. This approach stays within the authorized scope because the client has explicit ownership and control over these systems, and bypassing the CDN/WAF is done with the client's knowledge and permission. It also avoids third-party infrastructure entirely, preventing legal and technical issues while providing accurate backend security results.

Why this answer

The client wants the test to accurately reflect the security of their backend servers behind the CDN and WAF. By obtaining the backend server IPs directly, the tester can bypass the third-party protections and assess the actual security posture of the origin servers, which is the true target of the external test. This approach ensures that vulnerabilities not mitigated by the CDN/WAF are identified, aligning with the client's goal of evaluating backend security.

Exam trap

The trap here is that candidates may assume bypassing the WAF is the correct approach (Option C), but the ethical and practical method is to test the backend servers directly with client permission, not to actively circumvent security controls during the test.

How to eliminate wrong answers

Option A is wrong because testing the CDN and WAF as part of the scope would evaluate the third-party provider's security, not the client's backend servers, and may violate the terms of service or contractual agreements with the provider. Option C is wrong because including a plan to bypass the WAF in the rules of engagement is risky, potentially illegal, and could disrupt the WAF's operation or trigger false positives; the proper approach is to test the backend IPs directly with client authorization. Option D is wrong because only testing public-facing URLs would leave the backend servers untested, as the CDN and WAF may mask vulnerabilities or block malicious traffic, failing to meet the client's requirement to assess backend security.

740
MCQmedium

A penetration tester is conducting passive reconnaissance on a target organization. Which of the following techniques would provide the MOST useful information about internal network architecture without directly interacting with the target's systems?

A.Performing a zone transfer against the target's DNS servers
B.Searching for the target's SSL certificates in Certificate Transparency logs
C.Using Nmap to scan common ports on the target's public IP range
D.Querying the target's WHOIS records for IP addresses
AnswerB

Certificate Transparency (CT) logs are public, append-only ledgers of TLS certificates maintained by Google, Cloudflare, and other CAs; you can query them via services like crt.sh without ever contacting the target's servers. Every publicly trusted certificate issued for a domain is logged, including those for subdomains that aren't listed in DNS or linked anywhere, making this a passive way to enumerate the target's attack surface. Because CT logs are independently audited and immutable, they also provide historical certificate data that may reveal decommissioned or internal hostnames.

Why this answer

Certificate Transparency (CT) logs are publicly accessible, append-only ledgers of SSL/TLS certificates. By searching CT logs for certificates issued to the target organization, a penetration tester can discover subdomains, hostnames, and even internal-facing server names that are included in Subject Alternative Names (SANs) or Common Names (CNs). This reveals internal network architecture details (e.g., 'mail.internal.example.com') without any direct interaction with the target's systems, making it a purely passive reconnaissance technique.

Exam trap

The trap here is that candidates often confuse passive reconnaissance with low-interaction techniques like WHOIS lookups or zone transfers, not realizing that zone transfers and Nmap scans are active techniques that directly interact with the target's systems, while Certificate Transparency logs are a purely passive, third-party data source.

How to eliminate wrong answers

Option A is wrong because performing a zone transfer against the target's DNS servers is an active technique that directly interacts with the target's infrastructure; it sends a DNS query (AXFR) to the target's nameserver, which may be logged or blocked. Option C is wrong because using Nmap to scan common ports on the target's public IP range is an active scanning technique that sends packets to the target's systems, generating network traffic and potentially triggering intrusion detection systems. Option D is wrong because querying the target's WHOIS records for IP addresses provides only registration and administrative contact information, not internal network architecture details such as subdomains or hostnames.

741
MCQmedium

A client wants to test a web application that uses multiple third-party APIs for payment processing, shipping, and customer relationship management. The client states that the APIs are critical for operations but cannot be taken offline. Which scoping consideration is most important to include in the rules of engagement?

A.The tester must use only non-intrusive scanning techniques on the APIs.
B.The tester must exclude all API endpoints from testing.
C.The tester must coordinate testing schedules with the API vendors.
D.The tester must provide a list of all API calls to be made prior to testing.
AnswerA

Non-intrusive scanning techniques—such as passive traffic analysis, carefully rate-limited read-only GET requests, and benign parameter fuzzing that avoids destructive payloads—are essential when testing third-party APIs because aggressive testing could trigger rate limiting, WAF blocks, or even degrade the shared API infrastructure that other applications depend on. This approach preserves the availability of the target application and its dependencies while still allowing the tester to identify misconfigurations, broken authentication, or improper error handling. Non-intrusive methods also reduce the chance of committing to an expensive or legally problematic action, especially when the API provider is not directly part of the tested scope.

Why this answer

The client explicitly stated that the APIs are critical for operations and cannot be taken offline. Non-intrusive scanning techniques, such as passive traffic analysis or read-only API calls with safe HTTP methods (GET, HEAD), minimize the risk of service disruption, data corruption, or rate-limit triggering. This aligns with the scoping requirement to maintain availability while still allowing security testing of the API layer.

Exam trap

The trap here is that candidates may assume 'non-intrusive' means only using automated scanners or that coordinating with vendors (Option C) is necessary for third-party APIs, but the core scoping principle is to avoid impacting production availability while still testing the API attack surface.

How to eliminate wrong answers

Option B is wrong because excluding all API endpoints would leave the most critical attack surface (third-party integrations for payment, shipping, and CRM) completely untested, violating the client's goal of a comprehensive security assessment. Option C is wrong because coordinating schedules with API vendors is impractical and unnecessary; the tester only needs to coordinate with the client, and the APIs are consumed by the web app, not owned by the tester. Option D is wrong because providing a list of all API calls prior to testing is overly restrictive and unrealistic for dynamic testing; it would prevent the tester from discovering undocumented endpoints or chaining calls in ways an attacker would, and it violates the principle of simulating real-world adversarial behavior.

742
Multi-Selectmedium

A penetration tester is performing active reconnaissance on a web application and wants to discover hidden API endpoints. Which TWO tools are BEST suited for this task? (Select TWO.)

Select 2 answers
A.Wappalyzer
B.Nikto
C.theHarvester
D.Feroxbuster
E.Gobuster
AnswersD, E

Feroxbuster is a fast, recursive content discovery tool written in Rust that uses brute-forcing with a wordlist to find directories and files on web servers. It is specifically effective for API discovery because it supports recursion, file extensions, status-code filtering, and concurrent requests, allowing a tester to uncover hidden REST endpoints such as /api/v1/users or /admin. Its performance and flexibility make it a top choice for active reconnaissance against web APIs.

Why this answer

Gobuster can be used to bruteforce directories and files, including API paths. Feroxbuster is a similar tool written in Rust that is faster and supports recursion. Both are effective for API endpoint discovery.

743
MCQmedium

A penetration tester is scoping a test for a multinational company that must comply with GDPR. The tester wants to ensure that any personal data captured during the test is handled appropriately. Which document should be reviewed?

A.Test plan
B.Authorization letter
C.Data processing agreement
D.Non-disclosure agreement
AnswerC

A data processing agreement (DPA) is a legally binding contract that formally defines the relationship between the client (controller) and the penetration testing firm (processor) under Article 28 of GDPR. It specifies the purpose, duration, and types of personal data to be processed, along with security measures, breach notification duties, and sub-processing restrictions. Without a DPA, the testing firm lacks the contractual basis to lawfully handle personal data during the assessment, making it essential for GDPR compliance.

Why this answer

A data processing agreement (DPA) outlines how personal data is processed and protected, which is essential for GDPR compliance. An NDA covers confidentiality but not data processing specifics. An authorization letter grants permission, and a test plan is technical.

744
MCQmedium

A penetration tester is preparing a report for a client that includes both a technical security team and an executive leadership team. The executive team needs to understand the overall risk posture, while the technical team requires detailed reproduction steps. Which reporting structure best serves both audiences?

A.A single report with an executive summary and technical appendices
B.Two completely separate reports: one for executives and one for technical staff
C.Only an executive summary, omitting technical details
D.Only a technical report with all details
AnswerA

A single report with an executive summary and technical appendices is the industry-standard structure because it creates a single source of truth while serving both audiences. The executive summary translates technical vulnerabilities into business risk terms, enabling leadership to prioritize remediation, while the technical appendices contain the raw findings, request/response data, reproduction steps, and CVSS scores that security engineers need to validate and fix issues. This format eliminates the risk of version mismatch between separate documents and ensures regulatory or compliance reviewers can trace a high-level risk statement directly to its concrete technical evidence.

Why this answer

A single report with an executive summary and technical appendices is the correct structure because it satisfies both audiences: the executive summary provides a high-level risk posture overview (e.g., CVSS scores, business impact), while the technical appendices contain detailed reproduction steps (e.g., exact commands, payloads, and packet captures) for the technical team. This approach aligns with the PT0-002 objective of tailoring communication to stakeholders without losing technical rigor.

Exam trap

The trap here is that candidates think separate reports are more 'professional' or 'targeted,' but the PT0-002 exam expects a single cohesive report with layered detail to ensure consistency and traceability between the executive summary and technical findings.

How to eliminate wrong answers

Option B is wrong because two completely separate reports can lead to misalignment between the executive summary and technical details, causing executives to miss critical context or technical staff to lack business impact understanding. Option C is wrong because omitting technical details prevents the technical team from validating or reproducing findings, violating the reporting requirement for actionable remediation steps. Option D is wrong because a purely technical report overwhelms executives with jargon and lacks the risk posture summary they need for decision-making, failing the communication objective.

745
Multi-Selecteasy

Which TWO of the following are common methods used to bypass network access controls during a penetration test? (Choose two.)

Select 2 answers
A.SSID broadcasting
B.MAC spoofing
C.802.1Q trunking (VLAN hopping)
D.ARP poisoning
E.SQL injection
AnswersB, C

MAC spoofing is a direct method for bypassing MAC-based access control lists, such as those used in router filters, wireless MAC filtering, or port security. Since the Media Access Control address is transmitted unencrypted in the data-link layer frame, an attacker can sniff an allowed client's MAC and reconfigure their own interface (using tools like macchanger or ip link) to replicate it. This tricks the network into treating the attacker as an authorized endpoint.

Why this answer

MAC spoofing (B) is correct because network access controls such as MAC filtering, port security, and 802.1X can be bypassed by changing a NIC's hardware address to match an authorized device, allowing the tester to impersonate a trusted host. 802.1Q trunking / VLAN hopping (C) is correct because an attacker can abuse switch trunk negotiation (DTP) or double-tagging to send frames with a crafted 802.1Q tag and reach VLANs they are not authorized to access, effectively bypassing Layer 2 segmentation controls. SSID broadcasting (A) is not a bypass method; it is simply an access point advertising its wireless network name and does not defeat authentication or access control. ARP poisoning (D) is a man-in-the-middle/redirect technique on an already-accessible LAN, not a method for bypassing network access controls.

SQL injection (E) is an application-layer web attack against database queries and has nothing to do with circumventing network access controls.

Exam trap

CompTIA often tests the distinction between passive reconnaissance (like SSID broadcasting) and active bypass techniques, leading candidates to incorrectly select SSID broadcasting as a bypass method when it is merely a visibility setting.

746
MCQhard

A penetration tester is assessing a custom web application that uses JSON Web Tokens (JWT) for authentication. The tester suspects the token may be using a weak secret. Which tool is best suited to attempt cracking the JWT secret?

A.Hashcat
B.DirBuster
C.Burp Suite Intruder
D.sqlmap
AnswerA

Hashcat's mode 16500 is designed specifically for cracking JSON Web Tokens signed with HMAC-SHA (HS256, HS384, HS512). It extracts the header and payload from the token, then performs an offline dictionary or brute-force attack against the signature, comparing the SHA-256 HMAC for each candidate secret. Because hashcat leverages multiple GPUs and optimized kernels, it can test billions of guesses per second, making it the go-to tool for weak JWT secrets.

Why this answer

Hashcat is a powerful password cracking tool that can crack JWT secrets using dictionary or brute-force attacks. John the Ripper is similar but hashcat is generally faster and more GPU-optimized. DirBuster is for directory discovery, sqlmap for SQL injection, and Burp Suite Intruder can be used but is less efficient for offline cracking.

747
MCQhard

A penetration tester has obtained a TGT from a domain controller by cracking the krbtgt hash. Which attack can the tester now perform to gain persistent administrative access to any resource in the domain?

A.Pass-the-Hash
B.Silver Ticket
C.Golden Ticket
D.DCSync
AnswerC

The Golden Ticket attack is the correct answer because it uses the krbtgt hash to forge a TGT, granting the attacker the ability to impersonate any user, including domain admins, for any service in the domain. With a forged TGT signed by the krbtgt account, the attacker can request access to any resource without requiring credentials for each target service. This attack provides the strongest persistence and domain-wide compromise, which aligns with the scenario of having obtained a TGT from a domain controller.

Why this answer

A Golden Ticket attack is the correct answer because the tester has cracked the krbtgt hash, which is the key used by the Key Distribution Center (KDC) to sign all Ticket Granting Tickets (TGTs). With this hash, the tester can forge a TGT for any user (including a domain admin) with an arbitrary long validity period, granting persistent administrative access to any resource in the domain without needing to interact with the domain controller again.

Exam trap

The trap here is that candidates confuse the scope of a Silver Ticket (limited to a single service) with a Golden Ticket (full domain compromise), often picking Silver Ticket because they think 'service ticket' sounds broader, but the krbtgt hash specifically enables TGT forgery, not service ticket forgery.

How to eliminate wrong answers

Option A is wrong because Pass-the-Hash (PtH) uses an NTLM hash of a user's password to authenticate, not the krbtgt hash, and it does not provide persistent access to all resources—it only allows impersonation of that specific user until the hash changes. Option B is wrong because a Silver Ticket forges a service ticket (TGS) using the hash of a service account (e.g., for a specific service like HTTP or CIFS), not the krbtgt hash, and it only grants access to that specific service, not to any resource in the domain.

748
Multi-Selecthard

A penetration tester is reverse-engineering a .NET binary to understand its authentication logic. Which three tools are suitable for decompiling .NET assemblies? (Choose THREE.)

Select 3 answers
A.jadx
B.dotPeek
C.Ghidra
D.ILSpy
E.dnSpy
AnswersB, D, E

JetBrains dotPeek is a free .NET decompiler that translates compiled .NET assemblies (CIL bytecode plus metadata) into readable C# source code. It is based on the method bodies and type information stored in the metadata, and it supports modern language features like LINQ and async/await. Beyond decompilation, dotPeek can also display raw IL and generate Visual Studio solutions, making it a complete tool for static analysis of .NET binaries.

Why this answer

dnSpy, ILSpy, and JetBrains dotPeek are decompilers for .NET. Ghidra is for native code, jadx for Android APK.

749
MCQeasy

A penetration tester is engaged to perform a red team exercise for a large enterprise. The client wants the test to simulate a realistic attack from an external threat actor. Which of the following scoping elements is most important to include in the rules of engagement?

A.A list of all IP addresses to be scanned
B.The time window for the test
C.The amount of data to be exfiltrated
D.The specific vulnerabilities to be exploited
AnswerB

The time window for the test is the most critical RoE element because it establishes the legal and operational boundary for every action taken by the red team. It allows the engagement to be scheduled around maintenance windows and business-critical processes, preventing accidental outages, and it gives the blue team a definitive period to monitor for and respond to the exercise. Additionally, time-based metrics such as dwell time and time-to-compromise are only meaningful when the start and end times are precisely defined, so without this scoping element the exercise lacks both safety and measurable value.

Why this answer

In a red team exercise simulating an external threat actor, the rules of engagement must define the time window for testing to ensure the test aligns with operational constraints and minimizes business disruption. This scoping element is critical because it sets legal and logistical boundaries, such as avoiding peak business hours or maintenance windows, which is a core requirement for realistic yet safe adversarial simulation.

Exam trap

CompTIA often tests the misconception that a fixed target list (Option A) is essential for scoping, when in reality, red team exercises require discovery phases that mimic real attackers, making a predefined IP list counterproductive to the simulation's authenticity.

How to eliminate wrong answers

Option A is wrong because providing a list of all IP addresses to be scanned would undermine the realism of an external attack simulation, where the threat actor must discover targets through reconnaissance (e.g., DNS enumeration, Shodan, or passive scanning). Option C is wrong because specifying the amount of data to be exfiltrated is a constraint that would artificially limit the test's realism; in a real attack, exfiltration volume is determined by the attacker's objectives and the environment's defenses, not pre-defined limits.

750
MCQhard

During a penetration test, you successfully execute a Meterpreter session on a Windows target. You want to dump password hashes from the SAM database. Which Meterpreter command should you use?

A.getsystem
B.hashdump
C.getuid
D.sysinfo
AnswerB

hashdump is a Meterpreter command that reads the Local Security Authority (LSA) secrets and the Security Account Manager (SAM) registry hive from the target system, extracting the NTLM hashes of local user account passwords. It requires SYSTEM privileges to successfully read the SAM database, and it outputs the username, RID, LM hash, and NTLM hash for each account. This is the direct and intended method to dump password hashes from a Windows system, making it the correct answer.

Why this answer

hashdump is the Meterpreter command to dump SAM hashes.

Page 9

Page 10 of 11

Page 11

All pages