Courseiva

CompTIA PenTest+ (PT0-003) (PT0-003) — Questions 751–777

777 questions total · 11pages · All types, answers revealed

Page 10

Page 11 of 11

751
MCQmedium

You are tasked with identifying the technologies used by a web application (e.g., web server, frameworks, libraries) during the reconnaissance phase. Which tool would you use?

A.Gobuster
B.theHarvester
C.Nmap
D.WhatWeb
AnswerD

WhatWeb is a dedicated web technology identification tool that queries the target and analyzes a vast range of indicators, including HTTP headers, meta tags, cookie names, HTML source, and JavaScript variables. Its plugin-based architecture matches thousands of known signatures and reports technologies with confidence levels, covering CMS, frameworks, libraries, and server software. This makes it the correct choice for the stated task of identifying technologies used by a website.

Why this answer

WhatWeb is a tool for fingerprinting web technologies. It identifies software, frameworks, and other components by analyzing HTTP responses and page content. Wappalyzer is a browser extension but WhatWeb is command-line and scriptable.

752
MCQhard

A penetration tester has successfully exploited a buffer overflow vulnerability in a Linux binary. However, the binary has Data Execution Prevention (DEP) enabled and Address Space Layout Randomization (ASLR) disabled. Which exploitation technique is MOST appropriate to achieve code execution in this environment?

A.Return-oriented programming (ROP) to bypass DEP
B.Simple shellcode injection on the stack
C.ASLR bypass techniques
D.Heap spraying
AnswerA

ROP is a technique that defeats DEP by chaining together short instruction sequences—called gadgets—that already exist in executable memory, such as in the C runtime library. Since DEP only prohibits execution from non-executable pages like the stack and heap, ROP never injects or executes new code on those pages; instead, it uses the CPU's ret instruction to jump between gadgets, building arbitrary behavior like calling VirtualProtect or system(). This makes it the correct approach when the stack is non-executable.

Why this answer

Return-oriented programming (ROP) is the most appropriate technique because DEP marks the stack and heap as non-executable, preventing direct shellcode injection. With ASLR disabled, the attacker can reliably locate and chain small instruction sequences (gadgets) from the binary or loaded libraries to achieve arbitrary code execution without needing executable memory regions.

Exam trap

CompTIA often tests the misconception that DEP can be bypassed by simply injecting shellcode onto the stack, ignoring that DEP explicitly prevents execution from non-executable pages, making ROP or similar code-reuse techniques mandatory.

How to eliminate wrong answers

Option B is wrong because simple shellcode injection on the stack fails when DEP is enabled, as the CPU will raise an access violation when trying to execute code from a non-executable memory region. Option C is wrong because ASLR bypass techniques (such as information leaks or brute-forcing) are unnecessary when ASLR is already disabled; the core challenge here is DEP, not address randomization.

753
MCQmedium

During a network penetration test, the tester identifies that a web server is vulnerable to a buffer overflow. The server is running on a Windows system with DEP enabled. Which technique should the tester use to bypass DEP?

A.Return-to-libc attack
B.Return-Oriented Programming (ROP)
C.Use a NOP sled and shellcode injection
D.Stack pivoting
AnswerB

Return-Oriented Programming (ROP) defeats DEP because it never places or executes new code in non-executable data pages. Instead, the attacker overwrites the return address chain on the stack to sequentially invoke existing instructions, known as gadgets, each ending with a `ret` instruction. By carefully selecting and chaining gadgets, the attacker can perform arbitrary computations and call APIs, all within executable memory regions, thus evading DEP's instruction execution blocking.

Why this answer

Return-Oriented Programming (ROP) is the correct technique to bypass Data Execution Prevention (DEP) on Windows. DEP marks memory pages (like the stack and heap) as non-executable, preventing direct shellcode execution. ROP chains together small instruction sequences (gadgets) already present in executable memory (e.g., in loaded DLLs) to achieve arbitrary behavior without injecting or executing new code.

Exam trap

The trap here is that candidates often confuse DEP bypass with simple shellcode injection (Option C) or assume stack pivoting alone bypasses DEP, when in fact ROP is the standard technique to execute code without relying on executable stack memory.

How to eliminate wrong answers

Option A is wrong because a return-to-libc attack typically calls a single libc function (e.g., system()) to execute a command, but on Windows with DEP, the stack is non-executable and the attack still relies on calling existing functions; however, ROP is more flexible and is the standard modern bypass for DEP, while return-to-libc is more associated with Linux and does not fully address the need for chaining multiple calls. Option C is wrong because a NOP sled and shellcode injection rely on executing code on the stack, which is blocked by DEP (non-executable stack). Option D is wrong because stack pivoting is a technique to redirect the stack pointer to a controlled memory region (e.g., heap) to facilitate ROP or other attacks, but it is not itself a method to bypass DEP; it is often used in conjunction with ROP, not as a standalone bypass.

754
MCQmedium

You are contracted to perform a penetration test for a healthcare organization. During the testing, you discover a critical SQL injection vulnerability that exposes patient health information. The deadline for the final report is one week away. The client's IT manager asks you to exclude this finding from the report because they are already aware of it and are working on a fix. The IT manager claims that including it would cause panic among stakeholders. What is the BEST course of action?

A.Agree to exclude it but note it verbally
B.Explain that findings must be included in the report regardless of awareness, and offer to present the finding in a controlled manner to management
C.Report the issue to the client's compliance officer without informing the IT manager
D.Include it only in the technical appendix
AnswerB

A penetration test report is an objective record of observed vulnerabilities, and filtering out a known issue misrepresents the client's security posture and may misdirect remediation resources. You should explain that all findings must remain in the report regardless of the client's awareness, while offering to present the finding in a controlled manner—such as framing it with mitigation context for management. This maintains integrity while addressing the IT manager's concern about stakeholder reaction, and it upholds the professional standards outlined in the PT0-003 scope.

Why this answer

Option B is correct because a penetration tester has an ethical and professional obligation to report all discovered vulnerabilities, especially a critical SQL injection exposing patient health information, which may also trigger HIPAA breach-notification duties; the tester should refuse to omit it while offering a controlled, confidential briefing to management to reduce panic. This preserves report integrity and the client's ability to remediate and meet regulatory obligations. Option A is wrong because agreeing to exclude the finding, even with a verbal note, still suppresses a material risk from the official record.

Option C is wrong because bypassing the IT manager to notify the compliance officer unilaterally breaks the agreed communication channel and may not be the proper escalation path. Option D is wrong because relegating a critical finding to a technical appendix still hides it from the executive summary and key decision-makers who need to act on it.

755
Multi-Selectmedium

A penetration tester is preparing to perform an authenticated vulnerability scan of a network. Which THREE of the following are important considerations before starting the scan? (Select THREE.)

Select 3 answers
A.Using default community strings for SNMP
B.Configuring the scanner to use the appropriate credentials
C.Ensuring the scan will not disrupt production services
D.Selecting a random scan time to avoid detection
E.Obtaining written authorization from the target organization
AnswersB, C, E

Configuring the scanner with valid, appropriately privileged credentials is what makes the scan authenticated and is the single most important technical setup step. Without the correct credentials, the scanner reverts to an unauthenticated posture, producing incomplete results that overlook missing patches, insecure registry entries, local privilege escalation paths, and other authentication-dependent vulnerabilities. The credentials must be stored securely, scoped to the engagement, and granted only the permissions needed to enumerate software versions and system configuration without causing unintended changes.

Why this answer

Authenticated scans require valid credentials to log into systems for deeper assessment. It's important to understand the risk of service disruption, ensure credentials have appropriate privileges, and obtain written authorization to avoid legal issues.

756
MCQmedium

A penetration tester has gained a low-privilege shell on a Windows server and discovers the user has the SeImpersonatePrivilege. Which tool could the tester use to escalate privileges to SYSTEM?

A.Mimikatz
B.SharpHound
C.PowerUp
D.PrintSpoofer
AnswerD

PrintSpoofer is a token impersonation exploit that specifically leverages SeImpersonatePrivilege by creating a malicious named pipe server and then coercing a privileged process—commonly the Print Spooler service—to connect to it. The tool captures the resulting SYSTEM token and uses ImpersonateNamedPipeClient to execute a command with elevated privileges, giving the attacker a SYSTEM shell. It is designed as a modern replacement for JuicyPotato, working reliably on fully patched Windows 10 and Server 2019 builds where older Potato exploits often fail, making it the correct choice.

Why this answer

PrintSpoofer exploits SeImpersonatePrivilege to escalate privileges on Windows.

757
MCQeasy

A penetration tester is hired to perform a test with no prior knowledge of the target environment. The tester is given only the company name and must gather all necessary information from public sources. Which type of penetration test is this?

A.Grey box
B.Black box
C.Red team
D.White box
AnswerB

A black box penetration test supplies the tester with no internal knowledge, only the public-facing scope (e.g., a domain or IP address), requiring full reconnaissance through OSINT and active scanning. This directly matches the stated condition of 'no prior knowledge' because all network topology, application behavior, and potential vulnerabilities must be uncovered from scratch, replicating an external attacker's perspective.

Why this answer

In a black box test, the tester has no prior knowledge or credentials, simulating an external attacker.

758
MCQmedium

While performing web application reconnaissance, a tester wants to enumerate hidden directories and files on a web server. Which of the following tools is specifically designed for directory brute-forcing?

A.Nikto
B.Gobuster
C.WPScan
D.Nmap
AnswerB

Gobuster is a specialized tool for brute-forcing directories, files, and DNS subdomains using user-supplied wordlists. It generates HTTP requests and evaluates response codes to identify valid paths, making it highly efficient for web application reconnaissance. The tool supports multiple modes (dir, dns, vhost), custom extensions, and threading options, giving testers precise control over enumeration depth and speed. This dedicated focus on resource discovery is exactly what the scenario requires.

Why this answer

Gobuster is specifically designed for directory brute-forcing by using a wordlist to discover hidden directories and files on a web server. It sends HTTP GET requests to the target and reports valid responses (e.g., 200, 301, 403), making it the correct tool for this task.

Exam trap

The trap here is that candidates may confuse Nikto's web scanning capabilities with directory brute-forcing, but Nikto's focus is on vulnerability detection rather than enumerating hidden paths via wordlists.

How to eliminate wrong answers

Option A is wrong because Nikto is a web server vulnerability scanner that checks for known vulnerabilities, outdated software, and misconfigurations, not a directory brute-forcer. Option C is wrong because WPScan is a specialized scanner for WordPress sites, focusing on themes, plugins, and user enumeration, not generic directory brute-forcing. Option D is wrong because Nmap is a network port scanner and host discovery tool, not designed for HTTP-based directory enumeration.

759
MCQmedium

A penetration tester is performing passive reconnaissance on a target organization. The tester wants to gather information about the target's technology stack, including web server software and frameworks, without directly interacting with the target systems. Which technique is most effective?

A.Running Nmap with the -A flag against the target's public IP range
B.Using theHarvester to search for email addresses and subdomains
C.Querying public records with BuiltWith
D.Performing a DNS zone transfer
AnswerC

BuiltWith is a technology-profile lookup service that aggregates data from its own web crawlers, DNS records, and other public repositories. By querying BuiltWith's API or website, the tester retrieves detailed information about a target's web server, JavaScript frameworks, content management system, analytics tools, and other technology components without sending any packets to the target's infrastructure. This makes it a passive reconnaissance technique because the target never sees direct traffic from the tester, even though a third party (BuiltWith) may have actively scanned the site previously.

Why this answer

BuiltWith is a passive reconnaissance tool that queries public web data and DNS records to identify a target's technology stack, such as web server software (e.g., Apache, Nginx) and frameworks (e.g., React, Django), without sending any packets to the target's systems. This makes it ideal for passive information gathering, as it relies on third-party databases and cached information rather than direct interaction.

Exam trap

The trap here is that candidates often confuse passive reconnaissance with low-interaction active tools like Nmap's -A flag, failing to recognize that any direct network probing constitutes active reconnaissance, even if it's just a single scan.

How to eliminate wrong answers

Option A is wrong because running Nmap with the -A flag performs active reconnaissance by sending probes directly to the target's IP range, which can be detected by intrusion detection systems and violates the passive requirement. Option B is wrong because theHarvester focuses on gathering email addresses and subdomains from search engines and public sources, not on identifying the technology stack like web server software or frameworks.

760
MCQmedium

A penetration tester is analyzing the results of a vulnerability scan against a web application. The scanner reports a potential SQL injection vulnerability in a login form parameter. However, manual testing with the same payload does not produce any error messages or changes in behavior. Which of the following is the most likely reason for the false positive?

A.The scanner used a payload that was not URL-encoded
B.The web application is using a parameterized query that sanitizes input
C.The scanning engine is outdated and does not support the latest SQL syntax
D.The login form is protected by a CAPTCHA that blocks automated scanning
AnswerB

Parameterized queries (also known as prepared statements) separate the SQL query structure from the user-supplied data by pre-compiling the SQL statement and then binding parameters as values, never as executable code. When the scanner sends an injection payload such as ' OR 1=1 --, the database treats the entire string as a literal value, not as SQL logic, so the query executes safely and returns no error or behavioral difference. The scanner may still flag the entry point because it detects the presence of the payload in the request or a generic reflection, but the application's response remains benign, producing a false positive. This is precisely the most common reason why automated vulnerability scanners report SQL injection on modern, well-coded applications.

Why this answer

The use of parameterized queries (prepared statements) separates SQL logic from user input, preventing SQL injection even if the input contains malicious payloads. The scanner's payload triggered a false positive because the application's database layer safely handles the input, so no error or behavioral change occurs during manual testing.

Exam trap

The trap here is that candidates often assume a vulnerability scanner's report is always accurate and overlook the possibility of false positives due to input handling mechanisms like parameterized queries, instead focusing on payload encoding or scanner version issues.

How to eliminate wrong answers

Option A is wrong because URL-encoding is a standard practice for transmitting special characters in HTTP requests; if the scanner's payload were not URL-encoded, the web server would likely reject or truncate the request, not produce a false positive. Option C is wrong because an outdated scanning engine might miss new SQL syntax or produce false negatives, but it would not cause a false positive; the scanner reported a vulnerability that manual testing disproves, which is a false positive, not a false negative.

761
MCQhard

A penetration tester is analyzing a Linux binary and wants to decompile it to understand its logic. Which open-source tool is specifically designed for reverse engineering and can generate C-like pseudocode from compiled binaries?

A.IDA Pro Free
B.dnSpy
C.Ghidra
D.jadx
AnswerC

Ghidra is a free, open-source reverse-engineering suite developed by the NSA and includes a built-in decompiler that converts machine code into approximate C pseudocode. It supports a broad range of architectures and runs natively on Linux, making it ideal for analyzing ELF binaries. The decompiler output, though not perfect, dramatically accelerates understanding of program flow and logic, which is exactly what a penetration tester needs.

Why this answer

Ghidra, developed by the NSA, is a reverse engineering framework that can decompile binaries into C-like pseudocode.

762
MCQmedium

During a Windows privilege escalation attempt, the tester finds that the current user has the SeImpersonatePrivilege enabled. Which tool is commonly used to exploit this privilege to gain SYSTEM?

A.PrintSpoofer
B.SharpUp
C.Mimikatz
D.PowerUp
AnswerA

PrintSpoofer exploits SeImpersonatePrivilege by coercing a privileged process to authenticate against a named pipe it controls, then impersonating the resulting token to obtain SYSTEM. It targets Windows 10 and Server 2019+, where Rotten Potato techniques fail, satisfying the scenario's requirement for a working SeImpersonate escalation path.

Why this answer

PrintSpoofer exploits SeImpersonatePrivilege to impersonate SYSTEM and spawn a shell.

763
MCQmedium

During a Linux privilege escalation attempt, a tester finds a binary with the SUID bit set that is not on the GTFOBins list. The binary executes /bin/bash with the effective UID of root. What is the most likely way to exploit this?

A.Use GTFOBins to find a suitable exploit
B.Perform a buffer overflow on the binary
C.Run the binary with the -p flag
D.Modify the PATH to include a fake binary
AnswerC

When a SUID root binary executes /bin/bash, the kernel sets the effective UID to 0, but Bash normally resets the effective UID to the real UID to prevent privilege abuse. Running the binary with the -p flag forces Bash into privileged mode, preventing that reset and keeping the effective UID at 0. This yields a root shell with the user's real UID unchanged, making it the standard and direct privilege-escalation technique for SUID binaries that invoke a shell. The -p option is therefore the intended method to preserve the elevated privileges.

Why this answer

When an SUID binary executes /bin/bash, bash will drop the effective UID unless the -p (privileged) flag is used. Running the binary with '-p' preserves the effective UID, granting a root shell. Simply running the binary may result in a shell with the original user's privileges.

Exam trap

The -p flag is required to prevent bash from dropping the elevated privileges. Without it, the shell reverts to the real UID.

764
MCQeasy

A tester is attempting to crack WPA2 handshakes captured from a wireless network. Which hashcat mode should be used?

A.-m 13100
B.-m 1000
C.-m 0
D.-m 22000
AnswerD

Mode 22000 is the dedicated Hashcat format for WPA/WPA2, accepting both EAPOL and PMKID data from the four-way handshake. It replaces the older 2500 and 16800 modes and handles the PBKDF2-SHA1 key derivation to test passwords offline. When converting a .cap file with hcxpcapngtool, the resulting .hc22000 file is fed into Hashcat with -m 22000. This is the correct mode for cracking WPA2 handshakes.

Why this answer

Hashcat mode 22000 is used for WPA-PBKDF2-PMKID+EAPOL (WPA/WPA2) handshakes.

765
MCQmedium

A penetration tester wants to fuzz a network protocol to find buffer overflows. Which tool is most appropriate?

A.John the Ripper
B.Peach Fuzzer
C.Nessus
D.Wireshark
AnswerB

Peach Fuzzer is a dedicated fuzzing framework that generates and mutates inputs against network protocol definitions, making it suited to discovering buffer overflows in protocol parsers. General-purpose scanners lack the stateful, protocol-aware mutation needed for this testing.

Why this answer

Peach Fuzzer (option B) is the correct choice because it is a dedicated fuzzing framework designed to generate malformed inputs for network protocols and file formats, making it well suited to discovering buffer overflows. It supports protocol modeling and mutation-based generation, which aligns directly with the penetration tester's goal of fuzzing a network protocol. John the Ripper (A) is a password-cracking tool, not a fuzzer, so it cannot generate malformed protocol data.

Nessus (C) is a vulnerability scanner that checks for known issues rather than performing dynamic input fuzzing, and Wireshark (D) is a packet capture and analysis tool that inspects traffic but does not fuzz protocols.

766
Drag & Dropmedium

Drag and drop the steps to perform privilege escalation on a Linux system using kernel exploit enumeration into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Privilege escalation requires system info gathering, exploit search, compilation, execution, and verification.

767
Multi-Selecthard

A penetration tester is performing a wireless assessment and wants to set up an evil twin attack. Which of the following steps are necessary? (Choose THREE.)

Select 3 answers
A.Create a rogue access point with the same SSID as the target network
B.Configure WPA3 encryption on the rogue AP
C.Use Wireshark to decrypt the traffic
D.Capture the WPA handshake when clients attempt to connect
E.Send deauthentication frames to disconnect clients from the genuine AP
AnswersA, D, E

Cloning the target network's SSID is the essence of an evil twin attack because clients authenticate to networks by name and apparent signal strength rather than by verifying the AP's true identity. The attacker configures a rogue access point to broadcast the exact same SSID as the legitimate network, often also cloning the security type and any captive portal, so that a victim's device will associate with the attacker. Without this SSID masquerade, there is no evil twin with which to perform the subsequent steps of deauthentication and handshake capture.

Why this answer

An evil twin attack involves creating a rogue access point with the same SSID as a legitimate network, deauthenticating clients, and capturing the handshake.

768
MCQmedium

A penetration tester is evaluating the security of a WordPress site. Which tool is specifically designed to scan WordPress installations for vulnerabilities?

A.Nessus
B.WPScan
C.OpenVAS
D.Nikto
AnswerB

WPScan is an open-source security scanner purpose-built for WordPress, included by default in distributions like Kali Linux. It enumerates the WordPress core version, installed themes and plugins, user accounts, and backup or configuration files, then cross-references findings against the WPScan API vulnerability database. This allows it to identify known vulnerabilities in plugins and themes that generic scanners often miss. Because the question asks for a tool specifically for evaluating WordPress security, WPScan is the correct answer.

Why this answer

WPScan is a dedicated WordPress vulnerability scanner that checks for known vulnerabilities in WordPress core, plugins, and themes.

769
MCQeasy

A penetration tester wants to identify live hosts on a large internal network. Which Nmap option would be the FASTEST for initial host discovery?

A.-sV (Version detection)
B.-sS (SYN stealth scan)
C.-sn (Ping sweep)
D.-A (Aggressive scan)
AnswerC

-sn (Ping sweep) is the correct option because it performs host discovery only, sending minimal probes such as ICMP echo requests, TCP SYN to port 443, TCP ACK to port 80, and ICMP timestamp requests (depending on Nmap version and privileges) to determine which hosts respond without scanning any open ports. This makes it the fastest and most efficient method for identifying live hosts across a large subnet, as it does not wait for service banners or full port scans. The -sn flag is designed exactly for this purpose, replacing the old -sP behavior in Nmap.

Why this answer

The -sn option performs a ping sweep, sending ICMP echo requests, TCP SYN to port 443, TCP ACK to port 80, and ICMP timestamp requests by default. It does not perform port scanning, making it the fastest method for initial host discovery on a large internal network because it only checks for host availability without enumerating services.

Exam trap

The trap here is that candidates often confuse host discovery with port scanning, assuming that a SYN scan (-sS) is the fastest because it is stealthy, but they overlook that -sn is designed specifically for host discovery and avoids the overhead of port scanning entirely.

How to eliminate wrong answers

Option A is wrong because -sV performs version detection, which requires an open port to be found first and then sends additional probes to determine service versions, making it significantly slower and not suitable for initial host discovery. Option B is wrong because -sS performs a SYN stealth scan, which scans for open ports on each host, requiring multiple packet exchanges per port and per host, which is much slower than a simple ping sweep for just identifying live hosts.

770
MCQhard

A penetration testing firm is engaged to assess a cloud infrastructure hosted in multiple AWS regions. The client specifies that only systems in US-based regions should be tested due to data sovereignty concerns. Which of the following is the MOST critical documentation to include in the rules of engagement (ROE) to ensure compliance?

A.Statement of Work (SOW)
B.List of allowed AWS regions and associated VPC CIDR ranges
C.Data Processing Agreement (DPA)
D.Penetration testing methodology document
AnswerB

Listing permitted AWS regions alongside their VPC CIDR ranges directly enforces the US-only data sovereignty constraint, giving testers an unambiguous boundary for scoping. Region names alone cannot identify which subnets fall inside authorised testing limits, so pairing each approved region with its CIDR blocks prevents accidental testing of out-of-scope workloads in other territories.

Why this answer

The rules of engagement (ROE) must explicitly define the authorized scope to prevent testing outside US-based regions, which could violate data sovereignty laws. Listing allowed AWS regions and their associated VPC CIDR ranges provides a precise technical boundary for the penetration test, ensuring that only in-scope systems are targeted. Without this, the testing team might inadvertently access resources in non-US regions, leading to legal and compliance breaches.

Exam trap

The trap here is that candidates often confuse the SOW (which defines high-level scope) with the ROE (which requires specific technical boundaries like region and CIDR lists), leading them to select Option A instead of the more precise Option B.

How to eliminate wrong answers

Option A is wrong because a Statement of Work (SOW) describes the overall project objectives, deliverables, and timelines, but it does not provide the granular technical scope (e.g., specific AWS regions and IP ranges) required to enforce data sovereignty restrictions during testing. Option C is wrong because a Data Processing Agreement (DPA) governs how personal data is processed and protected between parties, but it does not define the operational boundaries (e.g., which AWS regions or VPCs are permitted) for a penetration test; it is a legal document, not a scoping control.

771
Multi-Selecthard

Which TWO of the following actions are appropriate when handling personally identifiable information (PII) discovered during a penetration test?

Select 2 answers
A.Include raw PII in the report as proof of access
B.Transfer PII to the client's secure storage for inclusion in the report
C.Securely delete any PII that is not required for reporting
D.Redact or mask PII in screenshots and logs before inclusion
E.Anonymize PII by replacing with fake data in the report
AnswersC, D

Securely deleting PII not needed for reporting enforces data minimisation, reducing the retention footprint and breach risk after the engagement. Retaining only what the report requires limits the tester's liability and aligns with privacy regulations governing personal data handling.

Why this answer

Option C is correct because data minimization is a core PII-handling principle: any PII collected during testing that is not strictly needed to demonstrate the finding should be securely deleted (e.g., using secure wipe or cryptographic erasure) rather than retained, reducing the client's breach exposure and legal liability. Option D is correct because when evidence must be shown, PII should be redacted or masked (e.g., replacing characters with asterisks or blurring fields in screenshots) so the report proves access without exposing the actual data subjects' identities. Option A is wrong because embedding raw PII in a report unnecessarily propagates sensitive data to additional systems and readers, violating minimization and confidentiality obligations.

Option B is wrong because transferring PII to another storage location still retains and duplicates the data beyond what reporting requires, expanding the attack surface. Option E is wrong because replacing real PII with fabricated data alters the evidence and can misrepresent what was actually found, undermining the report's integrity.

772
MCQmedium

During a penetration test, the tester discovers active ransomware on a critical server. Which communication should the tester perform FIRST according to standard rules of engagement?

A.Include it in the final report
B.Immediately notify the client's emergency contact
C.Attempt to contain the ransomware
D.Log the finding and continue testing
AnswerB

The emergency contact is the predefined channel for urgent, time-sensitive findings, and notifying them immediately triggers their incident-response process, enables isolation of affected systems, and starts preservation of forensic evidence. This aligns with the core pen-test rule: you are to report, not remediate, and you should never assume you have the client's authority to take active defensive action. Acting promptly also covers your legal and ethical duty to prevent further harm, which is the primary reason this is the only correct choice.

Why this answer

The standard rules of engagement (ROE) for penetration testing require immediate notification of the client's emergency contact upon discovery of active ransomware. This is because ransomware represents an active, ongoing security incident that demands urgent response to prevent data loss and further spread, overriding the normal testing timeline. The tester must not attempt containment or continue testing, as those actions could interfere with incident response or violate legal boundaries.

Exam trap

CompTIA often tests the misconception that a penetration tester should attempt to contain or remediate active threats, but the correct action is always to notify the client's emergency contact immediately, as testers are observers, not incident responders.

How to eliminate wrong answers

Option A is wrong because including ransomware in the final report delays critical notification, potentially allowing the ransomware to encrypt more data or spread laterally, which violates the ROE requirement for immediate incident reporting. Option C is wrong because the tester lacks authorization and expertise to contain ransomware; attempting containment could destroy forensic evidence, trigger further encryption, or breach legal agreements. Option D is wrong because logging and continuing testing ignores the active threat, risking catastrophic data loss and violating the ethical duty to report imminent harm under the ROE.

773
MCQmedium

A penetration tester is preparing the final report. The client's legal team requests a document that outlines the scope, limitations, and any data handling procedures to comply with regulatory requirements. Which section of the report should include this information?

A.Executive Summary
B.Methodology
C.Scope and Rules of Engagement
D.Technical Findings
AnswerC

The Scope and Rules of Engagement section is the formal, legally binding part of the report that enumerates authorized assets, allowed testing windows, exclusion lists, and prohibited techniques. It also specifies data handling and retention procedures to satisfy legal and compliance mandates such as GDPR or PCI-DSS. This makes it the correct section for documenting the engagement's constraints and authorization.

Why this answer

The Scope and Rules of Engagement section is the correct location for documenting the scope, limitations, and data handling procedures because it formally defines the boundaries of the penetration test, including authorized targets, testing windows, and legal constraints. This section ensures compliance with regulatory requirements by specifying how data is collected, stored, and disposed of, which is critical for audits and legal review.

Exam trap

The trap here is that candidates confuse the Executive Summary with a catch-all for legal disclaimers, but the exam expects the precise placement of contractual and compliance details in the Scope and Rules of Engagement section.

How to eliminate wrong answers

Option A is wrong because the Executive Summary provides a high-level overview of findings and risk posture for management, not the detailed legal and procedural boundaries of the engagement. Option B is wrong because the Methodology section describes the technical approach, tools, and techniques used (e.g., NIST SP 800-115 phases), not the contractual scope or data handling policies.

774
MCQmedium

A penetration tester is attempting to exploit a Linux system that has ASLR and DEP enabled. The tester has identified a buffer overflow vulnerability in a network service compiled without stack canaries and with a non-executable stack (NX). The binary is statically linked and not PIE. Which exploitation technique is most likely to succeed under these conditions?

A.Heap spraying to place shellcode in the heap and then overwrite a function pointer to execute the shellcode
B.Return-to-libc attack using libc functions
C.Return-Oriented Programming (ROP) to call mprotect and then execute shellcode on the stack
D.Ret2plt to call system() via the PLT
AnswerC

ROP allows the attacker to chain gadgets to call mprotect and change memory permissions on the stack to executable, then jump to shellcode placed on the stack. This bypasses NX while leveraging the known addresses from the statically linked, non-PIE binary.

Why this answer

The binary is statically linked (no libc to return to) and has a non-executable stack (NX), so shellcode cannot execute directly on the stack. Return-Oriented Programming (ROP) allows the attacker to chain gadgets from the binary itself to call mprotect() and change the stack region to executable, then pivot to shellcode placed on the stack. Since ASLR is enabled but the binary is not PIE, its code base address is fixed, making ROP gadgets reliably addressable.

Exam trap

The trap here is that candidates assume return-to-libc is always viable, forgetting that a statically linked binary has no libc to return to, making ROP the only way to call mprotect and bypass NX.

How to eliminate wrong answers

Option A is wrong because heap spraying is typically used to increase the predictability of heap layout for a use-after-free or similar vulnerability, but here the vulnerability is a stack-based buffer overflow; overwriting a function pointer would require a separate write primitive and does not bypass NX on the stack. Option B is wrong because return-to-libc relies on libc functions being present at a known address, but the binary is statically linked, meaning no shared libc is loaded, and ASLR would randomize libc's base address even if it were dynamically linked.

775
MCQmedium

A penetration tester wants to identify hosts on a network that are running web servers on any TCP port, including non-standard ports. Which Nmap command is most efficient for this task?

A.nmap -sV -p- target
B.nmap -sC -p 80,443 target
C.nmap -O -p- target
D.nmap -sT -p 8000,8080 target
AnswerA

The -p- flag directs Nmap to scan all 65,535 TCP ports, not just a default list, ensuring that web servers listening on unusual or non-standard ports are discovered. Coupled with -sV, Nmap performs service version detection by probing open ports and analyzing responses to identify the application and version, such as HTTP servers. This combination is the most thorough approach for the goal of identifying hosts running web services across the entire port range. Unlike OS detection or limited port scans, this directly reveals the service type.

Why this answer

`-sV` enables version detection to identify web server software, and `-p-` scans all 65535 TCP ports, including non-standard ones. This combination efficiently discovers web servers on any port without unnecessary overhead like OS detection or default script scanning.

Exam trap

The trap here is that candidates often choose `-sC` (default scripts) thinking it checks for web servers, but it only runs on the specified ports and doesn't detect services on non-standard ports.

How to eliminate wrong answers

Option B is wrong because `-sC` runs default scripts but only scans ports 80 and 443, missing non-standard ports. Option C is wrong because `-O` performs OS detection, which is irrelevant for identifying web servers, and `-p-` alone doesn't enable service detection. Option D is wrong because `-sT` is a full TCP connect scan limited to ports 8000 and 8080, ignoring the vast majority of potential web server ports.

776
MCQeasy

In the context of OSINT, which resource would you use to find historical versions of a company's website that may reveal outdated information or hidden directories?

A.crt.sh
B.Censys
C.Shodan
D.Wayback Machine
AnswerD

The Wayback Machine is an archival service operated by the Internet Archive that crawls the web and stores full snapshots of websites over time, including HTML, CSS, JavaScript, and images. It allows OSINT researchers to query a URL and retrieve the exact version of a page as it appeared on a chosen date, making it the definitive resource for historical website content. Unlike certificate or network-focused search engines, it preserves the actual user-facing content rather than infrastructure metadata.

Why this answer

The Wayback Machine (archive.org) is the correct resource because it archives historical snapshots of websites, allowing you to view past versions that may contain outdated information, hidden directories, or old configurations no longer present on the live site. This is a core OSINT technique for discovering legacy content or forgotten endpoints.

Exam trap

The trap here is that candidates confuse OSINT tools focused on current infrastructure (Shodan, Censys) or certificate data (crt.sh) with the only tool that provides historical web content snapshots, the Wayback Machine.

How to eliminate wrong answers

Option A is wrong because crt.sh is a certificate transparency log search tool that retrieves SSL/TLS certificates issued for domains, not historical website content or directory structures. Option B is wrong because Censys is a search engine for internet-connected devices and certificates, focusing on current network exposure and services, not archived web pages. Option C is wrong because Shodan is a search engine for internet-connected devices (e.g., IoT, servers, routers) and their banners, not for browsing historical versions of a website.

777
Multi-Selectmedium

A penetration tester is preparing the executive summary. Which THREE elements should be included? (Choose three.)

Select 3 answers
A.Key findings summary
B.Detailed exploit steps for each vulnerability
C.Strategic recommendations
D.Overall risk rating
E.Description of the testing methodology
AnswersA, C, D

The executive summary is intended for executives and stakeholders who need a concise, non-technical overview of the assessment's most critical outcomes. A key findings summary distills the most impactful vulnerabilities, their potential business impact, and overall security posture into a format that supports rapid understanding and decision-making. It highlights issues requiring immediate executive attention without overwhelming the audience with technical jargon or exhaustive detail.

Why this answer

Executive summary should include overall risk rating, key findings, and strategic recommendations. Technical details and methodology are not appropriate for this section.

Page 10

Page 11 of 11

All pages