Courseiva

CompTIA PenTest+ (PT0-003) (PT0-003) — Questions 76–150

777 questions total · 11pages · All types, answers revealed

Page 1

Page 2 of 11

Page 3
76
MCQhard

A penetration tester is presenting findings to a mixed audience of technical staff and executives. The executives seem confused about the risk ratings. How should the tester adjust the presentation?

A.Ask the executives to leave and schedule a separate meeting with them later.
B.Explain the risk ratings in terms of business impact and likelihood, avoiding technical jargon.
C.Provide the executives with a separate written report and continue the technical presentation.
D.Skip the technical details and focus only on the executive summary.
AnswerB

Translating risk ratings into business impact and likelihood removes jargon and makes findings actionable for executives, who are ultimately responsible for accepting or funding remediation. For example, describing a server vulnerability as a 0.4 likelihood of a $500,000 data breach is clearer than citing a CVSS score. This approach aligns technical findings with enterprise risk tolerance and enables informed, timely decisions.

Why this answer

When communicating to a mixed audience, the tester should tailor the message to each group's needs, focusing on risk and business impact for executives.

77
MCQeasy

In a penetration test report, the executive summary is primarily intended for which audience?

A.IT system administrators
B.Senior management (e.g., CISO, board of directors)
C.Software developers
D.External compliance auditors
AnswerB

The executive summary is purpose-built for senior management, such as the CISO and board of directors, who need a concise, non-technical articulation of overall security posture, business risk, financial or reputational impact, and high-level strategic recommendations. It frames the assessment in terms of risk tolerance and investment priorities, not raw technical findings.

Why this answer

The executive summary is designed for senior management (e.g., CISO, board of directors) because it provides a high-level overview of the penetration test's objectives, key findings, risk impact, and recommended strategic actions. It avoids technical jargon and detailed exploit steps, focusing instead on business risk and remediation priorities that inform decision-making and resource allocation.

Exam trap

The trap here is that candidates confuse the audience for the executive summary with the audience for the technical report, mistakenly thinking that all stakeholders need the same level of detail, when in fact senior management requires a non-technical, risk-focused summary while technical teams need the full exploit details.

How to eliminate wrong answers

Option A is wrong because IT system administrators need detailed technical findings, including specific vulnerabilities, exploitation steps, and remediation commands (e.g., patch versions, configuration changes), which are found in the technical report, not the executive summary. Option C is wrong because software developers require code-level details such as vulnerable functions, input validation flaws, and proof-of-concept exploits to fix application bugs, which are not included in the executive summary. Option D is wrong because external compliance auditors need evidence of specific control failures and adherence to standards (e.g., PCI DSS, ISO 27001), which are documented in the technical findings and compliance mapping sections, not the executive summary.

78
MCQmedium

While performing vulnerability scanning, a penetration tester runs a Nessus scan against a web server. The report shows a 'critical' finding, but after manual verification, the tester determines the service is not actually vulnerable. This scenario best describes:

A.A false negative
B.A configuration error
C.A false positive
D.A true positive
AnswerC

A false positive is an alert that a vulnerability scanner generates for a condition that, upon manual verification, does not actually exist. This is precisely what happened here: the scanner flagged a weakness, but penetration testing proved it was not present. Such alerts require triage to filter noise and avoid wasting remediation effort.

Why this answer

A false positive is when a scanner reports a vulnerability that does not actually exist. Penetration testers must verify scanner findings to avoid reporting false positives.

79
Multi-Selecthard

A penetration tester is conducting active reconnaissance on a target network and wants to enumerate SNMP information. Which TWO of the following tools or commands can be used to query SNMP data from network devices? (Select TWO.)

Select 2 answers
A.WPScan
B.snmpwalk
C.nmap with snmp scripts
D.dig
E.tcpdump
AnswersB, C

snmpwalk is the canonical command-line utility for actively enumerating SNMP-enabled devices, sending a sequence of GETNEXT requests to traverse the entire Management Information Base (MIB) tree. By default, it uses the community string 'public' via SNMPv2c, and a successful walk quickly reveals system name, interfaces, contacts, and even process tables—data that is extremely valuable during active reconnaissance. Unlike generic scanners, snmpwalk specifically implements the SNMP protocol and is designed to extract the full OID hierarchy in one pass.

Why this answer

snmpwalk is a standard SNMP tool to retrieve a subtree of MIB data, and nmap can be used with SNMP scripts to enumerate information.

80
MCQhard

During a penetration test, a tester gains initial access to a Linux server and wants to pivot to an internal network that is not directly accessible. Which of the following tools is specifically designed for creating SOCKS proxies for pivoting?

A.chisel
B.netcat
C.nmap
D.hydra
AnswerA

Chisel is a high-performance tunneling tool that creates encrypted channels over HTTP/HTTPS, allowing an attacker to pivot into internal networks. It supports both TCP port forwarding and SOCKS5 proxy mode, enabling dynamic routing of traffic from tools like Nmap or proxychains through the compromised host. Its design specifically addresses the need for stealthy and flexible post-exploitation access, making it the appropriate choice for establishing a proxy-based pivot.

Why this answer

Chisel is a tool that creates tunnels and SOCKS proxies over HTTP, ideal for pivoting through restrictive networks.

81
MCQmedium

A penetration tester is analyzing a Python script that uses the 'requests' library to send HTTP POST requests to a target URL with different payloads. The script also implements a retry mechanism with exponential backoff. What is the most likely purpose of this script?

A.Directory brute-forcing
B.Password spraying
C.SQL injection testing
D.Session hijacking
AnswerB

Password spraying is correct because the script sends POST requests to a single endpoint (likely a login form) with different password payloads, while the username remains constant or cycles slowly. The retry logic with exponential backoff is specifically designed to evade account lockout policies and rate limiting, allowing the attacker to try multiple passwords across accounts without triggering defenses. This behavior—iterating passwords slowly against one URL—is the signature of password spraying, which uses a few common passwords against many accounts rather than a brute-force of many passwords per account.

Why this answer

The script sends HTTP POST requests with different payloads and implements a retry mechanism with exponential backoff. This behavior is characteristic of password spraying, where an attacker attempts a small number of common passwords against many usernames to avoid account lockouts. The exponential backoff helps evade rate-limiting and intrusion detection systems by gradually increasing delays between attempts.

Exam trap

The trap here is that candidates may confuse password spraying with brute-force attacks, but the key distinction is that password spraying uses a small set of passwords across many accounts, while brute-force focuses on many passwords for a single account.

How to eliminate wrong answers

Option A is wrong because directory brute-forcing typically uses HTTP GET requests to discover hidden paths, not POST requests with payloads. Option C is wrong because SQL injection testing usually involves sending crafted payloads in GET parameters or POST data, but the retry mechanism with exponential backoff is not a standard technique for SQLi; it is more aligned with authentication bypass attempts. Option D is wrong because session hijacking involves stealing or predicting session tokens (e.g., cookies or JWTs), not sending POST requests with different payloads and retries.

82
MCQeasy

A company hires a penetration testing firm to simulate the tactics, techniques, and procedures of a real adversary. The engagement includes attempting to achieve specific objectives without being detected. This type of engagement is best described as:

A.Network penetration test
B.Web application penetration test
C.Social engineering engagement
D.Red team exercise
AnswerD

A red team exercise is an objective-based, adversarial simulation that mimics the tactics, techniques, and procedures (TTPs) of a specific real-world threat actor, with rules of engagement allowing stealth, creativity, and a kill-chain approach. It tests not just the existence of vulnerabilities but also the blue team's detection, response, and recovery capabilities by conducting a realistic attack lifecycle—reconnaissance, initial compromise, lateral movement, privilege escalation, and impact or exfiltration. Unlike a standard pen test, a red team engagement is often conducted without the defensive team being forewarned, and it succeeds only if it achieves a predefined business objective without being caught, making it the closest simulation of a genuine attack.

Why this answer

A red team exercise is an adversary simulation that aims to test detection and response capabilities.

83
MCQmedium

A tester is exploiting a web application and identifies a parameter that reflects user input in the response without sanitization. The tester wants to steal session cookies from other users. Which type of cross-site scripting (XSS) attack should the tester use?

A.Stored XSS
B.Blind XSS
C.Reflected XSS
D.DOM-based XSS
AnswerC

Reflected XSS is correct because the injected script is included in a request (commonly a URL parameter) and the server immediately echoes it back in the response without proper sanitization, causing the browser to execute it. The attacker can craft a malicious link containing the payload and trick the victim into clicking it; when the victim's browser sends the request, the reflected payload executes in the victim's session. This matches the scenario where the tester exploits the web application and sees the payload reflected directly in the response, making a crafted link the natural delivery vector.

Why this answer

Reflected XSS occurs when input is immediately reflected in the response. Stored XSS persists on the server. DOM-based XSS occurs client-side.

For stealing cookies, reflected XSS can be crafted into a link sent to the victim.

84
MCQmedium

A penetration tester is conducting an internal network assessment and wants to capture NTLMv2 hashes from Windows hosts without sending any authentication traffic. Which tool and attack technique should the tester use?

A.Responder with LLMNR/NBT-NS/mDNS poisoning
B.Metasploit's hashdump module
C.Hashcat with a wordlist attack
D.Bettercap with ARP spoofing
AnswerA

Responder is the correct tool because it actively listens for LLMNR, NBT-NS, and mDNS name-resolution queries broadcast by Windows hosts when DNS lookups fail. By replying with a spoofed response that claims to be the requested host, Responder forces the victim to initiate an SMB authentication handshake to the attacker, sending an NTLMv2 hash in the process. This hash can then be cracked offline with hashcat or relayed with ntlmrelayx, and the attack works without any prior credentials or access to the target system.

Why this answer

Responder poisons LLMNR/NBT-NS/mDNS to trick hosts into sending NTLM hashes to the attacker, capturing them without the attacker needing to authenticate.

85
Multi-Selectmedium

A penetration tester is preparing a presentation for both technical and executive audiences. Which TWO of the following are effective strategies for communicating findings to an executive audience?

Select 2 answers
A.Discuss each vulnerability's CVSS vector string.
B.Focus on business risk and financial impact.
C.Use technical jargon and detailed exploit steps.
D.Provide a high-level summary with visual aids.
E.Include raw command-line output in slides.
AnswersB, D

Focusing on business risk and financial impact is correct because executives are responsible for risk acceptance, budget allocation, and strategic planning. Presenting findings as likely financial losses, regulatory penalties, or reputational damage connects technical vulnerabilities to the organization's bottom line. This approach enables informed risk management decisions rather than technical discussion.

Why this answer

Executives need high-level overviews and business impact, not technical details.

86
MCQhard

During a penetration test, the tester runs an Nmap scan with the -sV option and gets a result showing 'Apache httpd 2.4.49'. This version is known to be vulnerable to a path traversal attack. Which of the following best describes the next step the tester should take?

A.Ignore it because Nmap version detection is unreliable.
B.Attempt to exploit the vulnerability using a known exploit.
C.Report the vulnerability immediately.
D.Move on to other targets since the vulnerability is well-known.
AnswerB

Attempting to exploit the identified vulnerability using a known, publicly available exploit (e.g., a Metasploit module or a PoC from Exploit-DB) is the definitive validation step in penetration testing. It transforms a potential false positive into demonstrated proof by showing that the service is actually vulnerable and the exploit path yields a controlled outcome. This must be executed with explicit authorization and caution, as a failed or unstable exploit could crash the target service, and the tester should gain approval for any exploit that may have a destructive impact. The successful execution provides concrete evidence, including command output and system access, that is far more persuasive to the client than a simple version-match.

Why this answer

After identifying a potentially vulnerable service, the tester should verify the vulnerability by attempting exploitation in a controlled manner to avoid false positives.

87
MCQhard

You are performing a vulnerability scan on a web application and notice that the scanner reports a high-severity SQL injection vulnerability. However, manual testing confirms that the input is properly sanitized. Which term best describes this situation?

A.False negative
B.True positive
C.Inconclusive
D.False positive
AnswerD

A false positive is an incorrect alert in which the scanner reports a vulnerability that does not actually exist in the web application, such as flagging a sanitized input parameter as SQL injectable. This often occurs due to heuristic detection misfires, outdated signature databases, or responses that imitate vulnerability patterns without the underlying weakness. It consumes security team time and resources on investigating and remediating non-existent issues, highlighting why every automated finding should be validated before being acted upon.

Why this answer

A false positive occurs when a scanner incorrectly identifies a vulnerability that does not exist. This is common in automated vulnerability scanning and requires manual verification.

88
MCQmedium

A penetration tester needs to crack NTLM hashes obtained from a Windows domain. The hashes are in the format used by Windows. Which hashcat mode should the tester use?

A.-m 22000
B.-m 1000
C.-m 0
D.-m 13100
AnswerB

Mode 1000 is exactly the Hashcat identifier for NTLM hashes, the raw MD4 digest of a UTF-16LE encoded password. Because NTLM hashes are unsalted, cracking them with mode 1000 allows direct dictionary, rule-based, and brute-force attacks at very high speeds on GPUs. This mode correctly parses the 32-character hexadecimal NTLM hash and compares candidate passwords using the same MD4 algorithm that Windows uses internally.

Why this answer

Hashcat mode 1000 is for NTLM hashes.

89
Multi-Selectmedium

A tester is reviewing source code for security vulnerabilities. Which TWO of the following are examples of insecure coding practices that often lead to critical vulnerabilities?

Select 2 answers
A.Validating input with allowlists
B.Concatenating user input directly into SQL queries
C.Using parameterized queries for database operations
D.Storing plaintext credentials in configuration files
E.Using prepared statements in SQL
AnswersB, D

Building SQL statements by directly concatenating unsanitized user input into query strings is the classic SQL injection flaw. An attacker can craft input that alters the query's structure, such as injecting a tautology or a stacked query, to bypass authentication, exfiltrate data, or execute arbitrary database commands. This violates the principle of separating code from data and is a critical vulnerability under OWASP Top 10 injection risks.

Why this answer

Option B is correct because concatenating user input directly into SQL queries builds the query string from untrusted data, allowing SQL injection (e.g., ' OR '1'='1) to alter query logic and potentially read, modify, or delete database contents. Option D is correct because storing plaintext credentials in configuration files exposes secrets to anyone with file or repository access, leading to credential theft, lateral movement, and full account compromise. Options A and C are secure practices: allowlist validation restricts input to known-good values, and parameterized queries separate code from data to prevent injection.

Option E is also secure: prepared statements precompile the SQL structure so bound parameters cannot change query semantics.

Exam trap

The trap here is that candidates may confuse secure practices (like parameterized queries or allowlists) with insecure ones, or fail to recognize that storing plaintext credentials is a critical vulnerability because it exposes secrets if the configuration file is accessed.

90
MCQmedium

A penetration tester is performing a web application test and wants to exploit a SQL injection vulnerability to extract data from a database. The tester knows that the application returns results in the HTTP response. Which type of SQL injection is being used?

A.Blind boolean-based
B.Blind time-based
C.Out-of-band
D.UNION-based
AnswerD

UNION-based SQL injection directly concatenates the attacker's injected SELECT statement to the original query using the UNION operator, so the modified result set is rendered in the HTTP response. The tester determines the exact number of columns and then selects the wanted columns from arbitrary tables (e.g., usernames and passwords) which appear as rows in the page. Because the data is returned in-band, this is the fastest and simplest method, and it also aids in retrieving system metadata like the DBMS version for further attacks.

Why this answer

UNION-based SQL injection returns results directly in the application's output.

91
MCQhard

A tester is using Hashcat to crack NTLM hashes. They want to try all possible passwords consisting of exactly 8 lowercase letters. Which attack mode and mask should they use?

A.-a 6 -m 1000 ?l?l?l?l?l?l?l?l
B.-a 3 -m 0 ?l?l?l?l?l?l?l?l
C.-a 3 -m 1000 ?l?l?l?l?l?l?l?l
D.-a 0 -m 1000 dictionary.txt
AnswerC

The correct answer combines attack mode 3 with NTLM hash mode 1000. Hashcat's attack mode 3 is a pure brute-force or mask attack, and the mask ?l?l?l?l?l?l?l?l systematically generates every 8-character string consisting of lowercase letters a through z. Any NTLM hash whose password matches that pattern will be recovered because the entire keyspace of 26^8 is exhaustively searched.

Why this answer

Brute-force mode (-a 3) with mask ?l?l?l?l?l?l?l?l tries all 8-letter lowercase combinations.

92
MCQeasy

The client's development team needs to reproduce a cross-site scripting vulnerability found in the login form. They require the exact payload and steps. Which deliverable should the penetration tester provide to meet this need?

A.An executive summary
B.A proof of concept code or walkthrough in the report appendix
C.A spreadsheet of findings with CVSS scores
D.A verbal explanation during the readout
AnswerB

Proof of concept code or a step-by-step walkthrough in the report appendix is the standard mechanism for providing developers with actionable reproduction details. This section can contain the exact URL, crafted input, browser context, and screenshots showing the XSS triggering, allowing the team to replicate the issue in a controlled environment and validate the fix afterward.

Why this answer

The correct deliverable is a proof of concept (PoC) code or walkthrough in the report appendix because the client's development team needs the exact payload and step-by-step instructions to reproduce the cross-site scripting (XSS) vulnerability. This allows them to validate the finding and implement a fix by injecting a crafted script (e.g., <script>alert('XSS')</script>) into the login form's input fields, demonstrating how user input is not properly sanitized or encoded. Including this in the appendix ensures the technical details are documented for replication without cluttering the main report.

Exam trap

The trap here is that candidates often choose the executive summary or CVSS spreadsheet because they focus on reporting severity rather than the technical reproduction details required by the development team, confusing the purpose of different report sections.

How to eliminate wrong answers

Option A is wrong because an executive summary provides a high-level overview for management, not the precise payload and reproduction steps needed by the development team. Option C is wrong because a spreadsheet of findings with CVSS scores only lists severity ratings and basic descriptions, lacking the exact payload and step-by-step walkthrough required to reproduce the XSS vulnerability. Option D is wrong because a verbal explanation during the readout is not a documented deliverable; the development team needs written, reproducible instructions that can be referenced later, not an ephemeral conversation.

93
MCQeasy

A penetration tester is conducting an external network assessment for a client. During the reconnaissance phase, the tester identifies an IP address range that is not listed in the rules of engagement (ROE). The client had initially provided a list of authorized target IPs. What should the tester do next?

A.Stop testing and notify the client to update the ROE.
B.Include the new IPs in the test scope and proceed.
C.Perform a quick scan of the new IPs to gather more information.
D.Ignore the new IPs and only test the provided range.
AnswerA

When an external assessment reveals IP addresses that are not listed in the Rules of Engagement (ROE), the only compliant action is to halt all testing and immediately notify the client. Continuing against those IPs—even if they belong to the client—would exceed the written authorization, potentially constituting unauthorized access under statutes like the Computer Fraud and Abuse Act (CFAA) and breaching the contract. The client must formally update the ROE to add the new addresses, after verifying ownership and confirming the testing window, before any activity against those targets can legally begin.

Why this answer

Testing outside the defined scope is unauthorized and could breach contract or legal boundaries. The correct course is to pause and seek clarification, updating the ROE before proceeding.

94
MCQmedium

A penetration tester is prioritizing remediation recommendations. Which approach is most aligned with industry best practices?

A.Recommend fixing all vulnerabilities simultaneously.
B.Prioritize by ease of remediation regardless of severity.
C.List all findings in alphabetical order.
D.Address critical vulnerabilities first, then high, then medium, with quick wins highlighted.
AnswerD

This is the correct approach because it aligns remediation with risk: critical vulnerabilities are actively exploitable or could cause major compromise, so they must be handled first; high and medium follow based on likelihood and impact. Highlighting quick wins — fixes that are low effort but reduce risk — lets the client show immediate progress while tackling heavier items. This mirrors standard frameworks like CVSS-based prioritization and PTES reporting, and it gives security teams a clear, defensible roadmap.

Why this answer

Prioritization should address critical/high vulnerabilities first, including quick wins that can be implemented rapidly.

95
MCQmedium

A client requests that the penetration test report include raw output from the scanning tools used. Where should this output be placed in the report?

A.In the appendices.
B.As a separate deliverable not included in the report.
C.In the executive summary.
D.In the technical findings section, alongside each vulnerability.
AnswerA

Appendices are the standard location for raw tool output and other verbatim evidence because they provide a structured, supplementary space that supports the main narrative without interrupting its readability. This placement preserves the chain of evidence for downstream auditors or remediation teams to verify the raw data against each finding, which is a practice encouraged by reporting standards such as PTES and NIST SP 800-115. Since the client explicitly requested that this data be included in the report, placing it in an appendix satisfies that requirement while keeping the core document focused on analysis and recommendations.

Why this answer

Raw tool output is typically included in appendices to avoid cluttering the main findings.

96
MCQmedium

A penetration tester needs to crack a large number of NTLM hashes. They have a wordlist and want to apply common password mutations. Which hashcat option enables the use of a rule file to mutate words?

A.-r
B.-a 0
C.-a 6
D.-m 1000
AnswerA

-r specifies a rule file for rule-based attack, enabling mutation of dictionary words such as appending digits or substituting characters to efficiently crack many hashes. In hashcat, -r loads a file containing rule functions like l (lowercase), u (uppercase), $ (append), s (substitute), applied to each word from a wordlist, generating candidate passwords without storing them all. For a large NTLM hash set, rule-based attacks greatly expand coverage while keeping disk usage minimal, so -r is the correct flag.

Why this answer

Hashcat's -r option specifies a rule file that defines transformations (mutation) on dictionary words.

97
MCQmedium

A penetration tester wants to enumerate user accounts and SMB shares from a Windows machine without authenticating. Which tool is specifically designed for this purpose and is commonly used in Linux penetration testing distributions?

A.nmap
B.enum4linux
C.smbclient
D.hydra
AnswerB

enum4linux is a dedicated wrapper around Samba tools (rpcclient, net, nmblookup) and is purpose-built for enumerating Windows/Samba hosts via the SMB and RPC protocols. It can list users, groups, shares, password policy, and OS information without credentials by abusing null sessions or guest access, making it the ideal choice for this task. Its automated scripts (enumusers, enumshares, enumpolicy) provide a comprehensive picture of the target's SMB exposure.

Why this answer

enum4linux is specifically designed to enumerate user accounts, SMB shares, and other information from Windows machines via the SMB protocol without requiring authentication. It leverages the SMB null session vulnerability (CVE-1999-0504) to query the remote system for data such as user lists, share lists, and OS details, making it a standard tool in Linux penetration testing distributions like Kali Linux.

Exam trap

The trap here is that candidates often confuse enum4linux with smbclient or nmap, thinking that any SMB-related tool can perform null session enumeration, but enum4linux is the only one specifically built to automate this process without authentication.

How to eliminate wrong answers

Option A is wrong because nmap is a general-purpose network scanner that can discover open ports and services, but it is not specifically designed for enumerating SMB user accounts and shares without authentication; it requires scripts like smb-enum-users.nse to perform such tasks, and even then it is not the dedicated tool for this purpose. Option C is wrong because smbclient is an interactive SMB client used to access shared resources after authentication or with a null session, but it is not primarily designed for enumeration of user accounts and shares without authentication; it requires manual interaction and does not automate the enumeration process. Option D is wrong because hydra is a password brute-forcing tool used for attacking authentication services, not for enumerating user accounts or SMB shares without authentication; it requires valid credentials or a list of usernames to attempt logins.

98
MCQhard

A penetration tester discovers a web application that uses client-side JavaScript to validate user input before form submission. The input is then sent to the server and used directly in a SQL query without server-side validation. Which attack would most effectively exploit this vulnerability?

A.SQL injection
B.Cross-site scripting (XSS)
C.Command injection
D.Parameter pollution
AnswerA

Client-side validation is only a convenience for users; a penetration tester can intercept or bypass it and submit raw HTTP requests containing malicious SQL payloads directly to the server. If the application concatenates unsanitized input into dynamic SQL queries, the tester can manipulate the query structure, for example by using UNION-based or boolean-based payloads to extract data. This directly exploits the database back end, whereas the other listed attacks do not.

Why this answer

The vulnerability described—client-side JavaScript validation with no server-side sanitization, followed by direct use of input in a SQL query—is the classic precondition for SQL injection. An attacker can bypass client-side controls (e.g., by disabling JavaScript or using a proxy like Burp Suite) and submit crafted SQL syntax (e.g., `' OR 1=1 --`) to manipulate the query, extract data, or execute arbitrary SQL commands on the database server.

Exam trap

The trap here is that candidates may confuse client-side validation bypass with XSS, thinking that JavaScript injection is the primary risk, but the key is that the input flows directly into a SQL query, making SQL injection the most effective and direct attack.

How to eliminate wrong answers

Option B is wrong because cross-site scripting (XSS) exploits the injection of client-side scripts into web pages viewed by other users, not the manipulation of SQL queries on the server; the described scenario involves direct server-side SQL execution, not reflected or stored output in a browser. Option C is wrong because command injection targets operating system commands via shell execution (e.g., through `exec()` or `system()` calls), not SQL queries; the input is used in a SQL query, not a system command. Option D is wrong because parameter pollution involves manipulating HTTP parameters (e.g., duplicate `id` parameters) to override or confuse server-side logic, but it does not directly exploit SQL query construction from unsanitized input.

99
MCQmedium

A penetration tester is analyzing a web application's JavaScript files to discover hidden API endpoints and potential client-side vulnerabilities. Which tool is specifically designed to extract URLs and endpoints from JavaScript files?

A.Wireshark
B.Burp Suite's Target scope
C.LinkFinder
D.Nmap
AnswerC

LinkFinder is a dedicated open-source Python tool designed specifically for parsing JavaScript files and extracting URLs, paths, and fully qualified endpoints using regex patterns and lightweight parsing. It accepts a URL, local file, or Burp session data and outputs both relative and absolute links, making it purpose-built for this exact reconnaissance task. This is why it is the correct answer when analyzing a web application's JavaScript to locate endpoints.

Why this answer

LinkFinder is a Python-based tool specifically designed to extract URLs and endpoints from JavaScript files by using regular expressions and parsing techniques. It analyzes JS files for patterns like API routes, relative paths, and hardcoded URLs, making it ideal for discovering hidden endpoints during web application penetration testing.

Exam trap

The trap here is that candidates may confuse network analysis tools (Wireshark) or general-purpose scanners (Nmap) with specialized JavaScript endpoint extractors, or assume Burp Suite's scope management is a discovery tool rather than a filtering mechanism.

How to eliminate wrong answers

Option A is wrong because Wireshark is a network protocol analyzer that captures and inspects packets at the OSI layers 2-7, not a tool for parsing JavaScript files or extracting URLs from code. Option B is wrong because Burp Suite's Target scope defines which hosts and URLs Burp will intercept or scan, but it does not extract endpoints from JavaScript files; that requires a dedicated JS parser like LinkFinder or Burp's built-in Engagement tools. Option D is wrong because Nmap is a network scanning tool used for host discovery, port scanning, and service enumeration, and it has no capability to parse JavaScript files or extract API endpoints.

100
MCQeasy

A client asks a penetration tester to perform a test on an e-commerce website. The website experiences high traffic during weekdays and major sales events. To minimize business disruption, when should the tester schedule the active scanning and exploitation activities?

A.During peak business hours on weekdays
B.During a major holiday sale event
C.During weekends outside of any special promotions
D.Anytime, as long as the tester does not perform denial-of-service attacks
AnswerC

Weekends outside any special promotions provide an ideal compromise because the application is still in a production-like state with realistic data, but active user traffic is low enough that scanning and exploitation phases have a negligible effect on end users. This window also allows the tester to perform noisy or invasive activities, such as password spraying or fuzzing, without overwhelming a high-concurrency environment. However, it requires planning to ensure operations staff are available to monitor web application firewall (WAF) logs and roll back changes if the test generates an unexpected outage.

Why this answer

Scheduling active scanning and exploitation during weekends outside of special promotions aligns with the requirement to minimize business disruption. High-traffic periods like weekdays and major sales events increase the risk of performance degradation or service interruption from scanning tools, which could impact revenue and user experience. By choosing low-traffic windows, the tester reduces the likelihood of overwhelming the web server or triggering rate-limiting mechanisms.

Exam trap

The trap here is that candidates assume 'no denial-of-service attacks' means no disruption, overlooking that active scanning itself can degrade performance and cause business impact during peak periods.

How to eliminate wrong answers

Option A is wrong because peak business hours on weekdays coincide with high user traffic, making active scanning likely to degrade website performance or trigger security controls like WAF rate limits, causing business disruption. Option B is wrong because a major holiday sale event is a critical revenue period where any disruption from scanning could lead to significant financial loss and violate the client's requirement to minimize business impact. Option D is wrong because even without denial-of-service attacks, active scanning can still cause resource exhaustion, latency spikes, or trigger IPS/IDS blocks, which disrupts normal operations during high-traffic periods.

101
MCQhard

A tester is analyzing a piece of malware and needs to identify the original entry point after unpacking. Which technique is most appropriate?

A.Original Entry Point (OEP) finding
B.Hash analysis
C.Import hash matching
D.Code signing verification
AnswerA

Finding the Original Entry Point (OEP) is essential when analyzing packed or encrypted malware. The packer begins execution in an unpacking stub that decompresses the payload in memory and then jumps to the OEP, where the true program logic starts. Locating the OEP enables an analyst to dump the unpacked process and statically analyze the deobfuscated code, using breakpoints on common OEP heuristics or tools like Scylla and OllyDump.

Why this answer

Finding the Original Entry Point (OEP) is a standard step after unpacking to resume analysis. Option B is wrong because hash analysis identifies known malware. Option C is wrong because import hash matching identifies library versions.

Option D is wrong because code signing verification checks authenticity.

102
MCQhard

A penetration tester is tasked with performing an authenticated vulnerability scan of a Windows network. The tester has domain admin credentials. Which tool is most appropriate for this task?

A.Nikto
B.Nmap
C.theHarvester
D.Nessus
AnswerD

Nessus is a commercial vulnerability scanner that supports credentialed scans via protocols like SSH, WinRM, or SMB, enabling deep assessment of Windows patch levels, service configurations, and custom software. It uses a comprehensive plugin database (e.g., via Nessus or the free Nessus Essentials) to map system state to known vulnerabilities, including missing patches, weak permissions, and policy violations. For authenticated Windows scanning, it connects with provided credentials (local or domain) to query WMI and the registry, making it the correct tool for this task.

Why this answer

Nessus supports authenticated scanning using credentials (e.g., domain admin) to perform deep vulnerability assessment of Windows systems, including missing patches and insecure configurations.

103
MCQmedium

During a penetration test, a tester captures NTLMv2 hashes using Responder. The tester then uses ntlmrelayx to relay the captured hashes to a target server. Which of the following best describes this attack technique?

A.Kerberoasting attack
B.NTLM relay attack
C.SMB relay attack
D.Pass-the-hash attack
AnswerB

In an NTLM relay attack, the tester uses tools like Impacket's ntlmrelayx to capture an NTLMv2 challenge/response and immediately forward it to a target service, making the remote server believe the authentication came from the legitimate user. The attacker never needs the password or to crack the hash; the relayed exchange is accepted as valid proof of identity, enabling unauthorized access to services like SMB, HTTP, or LDAP.

Why this answer

NTLM relay attacks forward captured authentication attempts to other servers, allowing the attacker to authenticate without cracking the hash. This is distinct from pass-the-hash, which requires a hash of the target account for local authentication.

104
Multi-Selecthard

During a penetration test, the tester encounters a situation where the scope of the test is ambiguous. Which TWO actions should the tester take to clarify the situation?

Select 2 answers
A.Document the ambiguity and the agreed-upon resolution in the test plan.
B.Proceed with the test based on the tester's best guess.
C.Test all systems within the network to ensure thoroughness.
D.Ignore the ambiguity and continue testing the original scope.
E.Contact the client to clarify the scope before proceeding.
AnswersA, E

Documenting the ambiguity and its agreed-upon resolution in the test plan creates an auditable record that prevents disputes over authorization, aligns the engagement with the rules of the contract, and ensures the final report accurately reflects the tested boundaries. This change-control step is essential for legal defensibility and professional accountability.

Why this answer

When scope is unclear, the tester should communicate with the client and document the assumptions to avoid misunderstandings.

105
MCQeasy

A penetration tester has compromised a Linux server and gained a low-privilege shell. The tester discovers that the /etc/shadow file is readable by the tester's user. Which attack is most directly enabled by this finding?

A.Pass-the-hash
B.Password cracking offline
C.LLMNR poisoning
D.Kerberoasting
AnswerB

Reading /etc/shadow is effectively game over for the compromised account's password: the file stores salted, one-way hashes of every local user's password, and an attacker can copy those hash strings directly to a cracking tool. John the Ripper's 'unshadow' utility combines /etc/passwd and /etc/shadow entries, or Hashcat can ingest the raw hash lines, enabling dictionary, rule-based, hybrid, or brute-force attacks at billions of guesses per second on GPU hardware. Even strong passwords fall to hybrid or mask attacks if the password policy is weak, and reused credentials often appear in prior breach data. Because the hashes are fully in hand, this offline cracking approach is the primary and most practical path after obtaining /etc/shadow.

Why this answer

The /etc/shadow file contains the hashed passwords for all users on the system. If a low-privilege user can read this file, they can copy the password hashes and attempt to crack them offline using tools like John the Ripper or Hashcat. This directly enables an offline password cracking attack, as the tester can brute-force or use dictionary attacks against the hashes without needing to interact with the live system.

Exam trap

The trap here is that candidates may confuse the ability to read a password hash file with a pass-the-hash attack, but pass-the-hash is a Windows-specific technique that requires NTLM hashes and a network authentication context, not a local file read on Linux.

How to eliminate wrong answers

Option A is wrong because pass-the-hash is an attack that uses captured NTLM hashes to authenticate to Windows systems, not Linux systems; it requires a Windows environment and does not apply to reading /etc/shadow. Option C is wrong because LLMNR poisoning is a Windows-specific network attack that exploits the Link-Local Multicast Name Resolution protocol to capture NetNTLMv2 hashes, and it is not related to reading a local file on a Linux server. Option D is wrong because Kerberoasting targets Kerberos service tickets in Active Directory environments to crack service account passwords; it is a Windows domain attack and does not involve the /etc/shadow file on a Linux server.

106
MCQmedium

A penetration testing firm has been hired to test the internal network of a large enterprise. During the scoping meeting, the client states that they want to include all IP ranges, including those used by the HR department's sensitive systems. The tester should recommend which of the following to minimize business impact and avoid disruption?

A.Exclude the HR department's IP range from the test
B.Perform the test during off-peak hours and provide prior notification
C.Use only passive reconnaissance techniques on the HR systems
D.Include the HR systems but require written authorization from HR management
AnswerB

Scheduling the engagement during off-peak hours, such as nights or weekends, reduces the risk of operational disruption to critical HR processes like payroll runs, benefits processing, and employee self-service transactions. Providing prior notification to HR allows their IT and security teams to review planned test activities, adjust monitoring thresholds to avoid false positives, and ensure that any system failures can be distinguished from test-induced incidents. This approach aligns with proper change management and deconfliction procedures, ensuring that valid business activities are not mistaken for intrusions while maintaining full coverage of the assigned scope.

Why this answer

Performing the test during off-peak hours and providing prior notification minimizes business impact by reducing the likelihood of disrupting critical HR operations during normal business hours. This approach aligns with the scoping requirement to include all IP ranges while allowing the client to prepare for potential service interruptions, such as those caused by active scanning techniques like TCP SYN scans or service enumeration. Prior notification ensures that HR staff can take precautions, such as backing up sensitive data or pausing batch jobs, thereby avoiding data corruption or system unavailability.

Exam trap

The trap here is that candidates often choose Option C (passive reconnaissance) thinking it avoids disruption entirely, but they overlook that passive techniques cannot fulfill the test's objective of identifying exploitable vulnerabilities, which requires active interaction with the target systems.

How to eliminate wrong answers

Option A is wrong because excluding the HR department's IP range directly contradicts the client's explicit request to include all IP ranges, including sensitive HR systems, and would leave a critical attack surface untested, potentially missing vulnerabilities like weak authentication on HR databases or exposed SMB shares. Option C is wrong because using only passive reconnaissance techniques on the HR systems is insufficient for a thorough penetration test; passive techniques (e.g., sniffing network traffic or analyzing DNS records) cannot identify active vulnerabilities such as unpatched services, default credentials, or misconfigured firewall rules that require active probing like Nmap version scans or vulnerability scanning with tools like OpenVAS.

107
Multi-Selecthard

A penetration tester has compromised a Windows host and wants to perform lateral movement using WMI. The tester has obtained local administrator credentials for the target host but wants to avoid writing files to disk. Which two methods can be used to execute commands remotely via WMI without creating files on the target? (Choose two.)

Select 2 answers
A.Using wmic /node:target process call create "cmd.exe /c ..."
B.Using winrs -r:target cmd.exe
C.Using schtasks /create /s target /tn ... /tr ... /sc once /st ...
D.Using Invoke-WmiMethod -Class Win32_Process -Name Create -ComputerName target -ArgumentList "cmd.exe /c ..."
E.Using psexec.exe \\target -accepteula cmd.exe
AnswersA, D

The wmic command-line tool can execute processes on a remote host via WMI. When using process call create, it creates a new process on the target, which runs the specified command. This does not require writing a file to disk on the target, as the command is executed directly. However, it may create temporary files depending on the command, but the WMI mechanism itself does not write a payload to disk. This is a common fileless lateral movement technique.

Why this answer

Two WMI-based methods for remote command execution without writing files to disk are using the wmic command-line tool with process call create, and using PowerShell's Invoke-WmiMethod to call Win32_Process Create. Both leverage WMI to spawn processes on the target. PsExec writes a service binary to disk, schtasks creates a scheduled task on disk, and WinRS uses WinRM, not WMI.

Exam trap

The trap here is assuming that any remote execution method is fileless or WMI-based; tools like PsExec and schtasks write to disk, and WinRS uses a different protocol.

108
MCQeasy

A penetration tester has completed the technical portion of a test and is now writing the executive summary. Which of the following is most important to include in this section to effectively communicate with senior management?

A.A detailed list of all tools and commands used during the test
B.The total number of vulnerabilities found and their risk ratings, with a focus on business impact
C.Step-by-step instructions on how to reproduce the most critical vulnerability
D.The names of the penetration testers and their certifications
AnswerB

The executive summary's core purpose is to translate complex penetration test results into a concise risk picture that business leaders can act upon. Stating the total number of vulnerabilities and their risk ratings (e.g., Critical, High, Medium, Low) directly supports decisions about resource allocation, and framing those ratings with the likely business impact—such as unauthorized access to sensitive data or potential regulatory fines—makes the urgency concrete for executives.

Why this answer

The executive summary is intended for senior management, who need to understand the business impact of findings rather than technical details. Option B focuses on the total number of vulnerabilities, their risk ratings, and business impact, which directly aligns with management's decision-making needs. This ensures the report communicates risk in terms of potential financial or operational consequences, not just technical severity.

Exam trap

The trap here is that candidates mistake technical completeness for executive communication, choosing options like A or C because they focus on the tester's work rather than the audience's needs, but the exam specifically tests the distinction between technical reporting and management reporting.

How to eliminate wrong answers

Option A is wrong because a detailed list of all tools and commands used during the test is too technical for senior management; this level of detail belongs in the technical report or appendices, not the executive summary. Option C is wrong because step-by-step instructions on how to reproduce the most critical vulnerability are operational details meant for the technical team, not for high-level management who require a summary of risks and remediation priorities.

109
MCQeasy

A penetration tester is analyzing a suspicious executable found on a compromised Windows host. The tester wants to identify if the executable is packed or obfuscated, which might indicate malware. Which tool is specifically designed for detecting packers and providing information about the executable's structure?

A.Nmap
B.PEiD
C.Metasploit
D.Wireshark
AnswerB

PEiD is a tool that detects most common packers, cryptors, and compilers for PE executables. It analyzes the executable's signatures to identify if it is packed and often provides the packer name. In this scenario, the tester can use PEiD to quickly determine if the executable is packed, which is a common characteristic of malware. This helps in deciding the next steps for analysis.

Why this answer

PEiD is a classic tool for detecting packers and identifying the compiler used to build a PE executable. It works by scanning for known signatures in the executable's entry point and other sections. If the executable is packed, PEiD will often display the packer's name, which is valuable information for malware analysis.

This helps the tester understand if the executable is obfuscated and may need to be unpacked before further analysis.

Exam trap

The trap here is selecting a network or exploitation tool for binary analysis, when the task specifically requires static inspection of a PE file for packing.

110
MCQmedium

During a penetration test, a penetration tester discovers a critical vulnerability that allows unauthenticated remote code execution on a public-facing web server. According to best practices for communication during a penetration test, what should the tester do next?

A.Immediately notify the client of the critical finding and provide initial remediation steps.
B.Document the finding and inform the client only after verifying with a second tester.
C.Wait until the end of the test to include it in the final report.
D.Exploit the vulnerability to demonstrate the full impact before notifying the client.
AnswerA

Critical unauthenticated RCE on a public-facing server poses immediate business risk, so the tester should promptly notify the client contact and supply initial remediation guidance. This satisfies the stem's best-practise communication requirement: escalate critical findings immediately rather than waiting for the final report.

Why this answer

Penetration testing best practices and most rules of engagement require immediate notification of the client when a critical vulnerability — especially unauthenticated RCE on a public-facing system — is discovered, because it represents an active, exploitable risk. Providing initial remediation guidance at the same time helps the client mitigate before the finding is weaponized. This balances the tester's duty to the client with the goal of the engagement.

Exam trap

PT0-003 often tests the misconception that testers should fully exploit or verify findings before reporting — the correct behavior is immediate escalation of critical findings per the rules of engagement.

How to eliminate wrong answers

Option B is wrong because waiting to verify with a second tester delays notification of a critical, actively exploitable vulnerability — the tester should confirm enough to be confident but not delay urgent communication. Option C is wrong because withholding a critical finding until the final report violates the standard practice of immediate escalation for high-severity issues and could expose the client to real harm. Option D is wrong because exploiting the vulnerability further to 'demonstrate impact' without notifying the client is unethical, may violate the rules of engagement, and could cause unintended damage or data loss.

111
MCQeasy

A penetration tester wants to perform a pass-the-hash attack on a Windows target. Which tools can be used for this purpose? (Choose the best answer.)

A.sqlmap
B.pth-winexe
C.John the Ripper
D.Hashcat
AnswerB

pth-winexe is part of the Samba suite and is a utility specifically designed to execute commands on a remote Windows system using an NTLM hash in place of a password. It embeds the hash into the authentication handshake (e.g., SMB/Netlogon remote procedure call) to authenticate without needing the plaintext password. This makes it a direct implementation of the Pass-the-Hash technique for interactive command execution.

Why this answer

pth-winexe is a common tool for pass-the-hash attacks on Windows.

112
Multi-Selecteasy

A penetration tester wants to perform passive reconnaissance on a target organization. Which two activities are considered passive reconnaissance? (Choose TWO.)

Select 2 answers
A.Searching Pastebin for leaked credentials
B.Sending SNMP queries to a network device
C.Scanning ports with Nmap
D.Performing a DNS zone transfer attempt
E.Using crt.sh to view SSL certificates
AnswersA, E

Searching Pastebin for leaked credentials involves querying a third-party data-sharing site rather than touching the target's infrastructure, so no packets reach the organisation's systems. This satisfies the stem's passive reconnaissance constraint, since the tester gathers intelligence without directly interacting with the target's hosts, domains, or network ranges.

Why this answer

Option A is correct because searching Pastebin for leaked credentials involves only reviewing publicly available third-party data without ever touching the target's systems, which is the definition of passive reconnaissance. Option E is correct because crt.sh queries public Certificate Transparency logs to enumerate SSL/TLS certificates and associated subdomains, again relying on externally published data rather than interacting with the target. Option B is not passive because sending SNMP queries directly contacts the target device and can be logged.

Option C is not passive because Nmap port scanning actively probes the target's hosts and services. Option D is not passive because attempting a DNS zone transfer sends a direct AXFR request to the target's name server.

Exam trap

The trap here is that candidates often confuse 'publicly available information' with 'active probing'—for example, assuming that querying crt.sh or Pastebin is active because it involves a web request, when in fact it is passive because the request goes to a third-party service, not the target's own systems.

113
MCQhard

After compromising a Linux host, you want to escalate privileges by exploiting a cron job that runs a script with root privileges. The script references an executable using a relative path. Which attack technique is most appropriate?

A.PATH manipulation
B.SUID binary exploitation
C.Kernel exploit
D.DLL hijacking
AnswerA

PATH manipulation is the correct privilege escalation vector in this scenario because cron jobs often run with a minimal PATH such as /usr/bin:/bin. If a scheduled task invokes a command without an absolute path (e.g., 'tar' instead of '/usr/bin/tar'), an attacker who can place a malicious executable named 'tar' in any directory that appears earlier in the resolved search order—for instance, a world-writable directory like /tmp—can hijack execution. The cron daemon then executes the attacker's binary with the target user's privileges, enabling arbitrary command execution and potential root compromise if the job runs as root.

Why this answer

PATH manipulation works by modifying the PATH environment variable so that when the script calls the executable (by name only, no full path), the attacker's malicious version runs with the privileges of the script.

114
MCQeasy

During a penetration test report review, the client's IT manager asks for a 'quick reference' that lists each vulnerability, its severity, and the affected system, without detailed exploit steps. Which section of the report should the tester point to?

A.Executive summary
B.Technical findings section
C.Appendix with raw scan results
D.Remediation recommendations
AnswerB

The technical findings section is the core of a penetration test report and typically opens with a summary table that lists every identified vulnerability along with its risk severity (e.g., Critical, High, Medium, Low), affected host or asset, and a reference identifier. This table is designed for quick scanning, allowing an IT manager to immediately grasp the full scope of vulnerabilities without reading verbose raw output. The section also provides supporting technical detail, evidence, and code snippets for each finding, but the summary table alone is the perfect quick-reference artifact.

Why this answer

The technical findings section is the correct place because it provides a structured list of each vulnerability, its severity rating (e.g., CVSS score), and the affected system, while intentionally omitting detailed exploit steps. This directly satisfies the IT manager's request for a 'quick reference' without the operational risk of exposing attack procedures. The executive summary is too high-level, and the appendix with raw scan results lacks the curated, severity-ranked format needed for a quick reference.

Exam trap

The trap here is that candidates confuse the 'quick reference' request with the executive summary, assuming any summary must be in the executive section, but the executive summary lacks the per-vulnerability detail and system mapping that the technical findings section provides.

How to eliminate wrong answers

Option A is wrong because the executive summary is a high-level overview for non-technical stakeholders, focusing on business risk and strategic recommendations, not a per-vulnerability list with severity and affected systems. Option C is wrong because the appendix with raw scan results contains unprocessed, often voluminous output from tools like Nmap or Nessus, which lacks the curated, severity-ranked format and clear mapping of each vulnerability to a specific system that the IT manager needs.

115
MCQmedium

During a code review, a penetration tester identifies a PHP function that executes arbitrary shell commands. Which function poses the greatest security risk if user input is not sanitized?

A.echo
B.strlen
C.system
D.array_pop
AnswerC

system() is a PHP function that schedules an external command for execution by the system shell and displays its output. When user-controlled input is concatenated into the command string without proper escaping, an attacker can inject shell metacharacters such as ; or && to chain arbitrary commands (e.g., system('ping ' . $_GET['ip'])). This direct OS interaction makes system() a classic command injection sink and the correct dangerous function in the review.

Why this answer

system() executes commands and returns output, allowing arbitrary command execution if input is unsanitized.

116
MCQmedium

During a web application test, a penetration tester discovers that the application exposes internal object references (e.g., user ID in a URL) and does not properly authorize access. The tester can view other users' private data by simply changing the ID parameter. Which type of vulnerability does this represent?

A.Cross-Site Request Forgery (CSRF)
B.Insecure Direct Object Reference (IDOR)
C.SQL Injection
D.Cross-Site Scripting (XSS)
AnswerB

Insecure Direct Object Reference occurs when an application exposes a reference to an internal implementation object—most commonly a database key or numeric ID—in a URL or form parameter, and fails to verify the authenticated subject is authorized for that object. By simply changing the user ID in the request, the tester was able to retrieve another user's profile, demonstrating a missing object-level access control check. This is a classic IDOR finding and a type of broken access control.

Why this answer

The vulnerability is Insecure Direct Object Reference (IDOR) because the application exposes internal object references (e.g., user ID in a URL) and fails to enforce proper authorization checks. By simply changing the ID parameter, the tester can access other users' private data without authentication or permission validation, which is the hallmark of IDOR.

Exam trap

CompTIA often tests IDOR by presenting a scenario where a parameter is manipulated to access another user's data, and the trap is confusing it with CSRF (which involves state-changing actions via forged requests) or SQL injection (which involves database query manipulation), rather than recognizing the core issue as missing authorization on direct object references.

How to eliminate wrong answers

Option A is wrong because Cross-Site Request Forgery (CSRF) involves tricking a user into executing unwanted actions on a web application where they are authenticated, not directly manipulating object references to access unauthorized data. Option C is wrong because SQL Injection is a code injection technique that exploits insecure database queries by inserting malicious SQL statements, not by manipulating exposed object references in URLs or parameters.

117
Multi-Selectmedium

A penetration tester is scoping a web application penetration test. The client wants to include a third-party API that processes payments. Which TWO are appropriate considerations?

Select 2 answers
A.Assume the API is secure because it is a well-known provider
B.Test only the client's code and ignore the API entirely
C.Obtain written permission from the third-party provider before testing
D.Include the API in scope without permission because it is critical to the application
E.Document the API as out-of-scope if permission is not granted
AnswersC, E

Written permission from the third-party provider is the only legally defensible basis for actively testing their API, as it establishes an authorization boundary that protects both the tester and the client from claims of unauthorized access under laws like the Computer Fraud and Abuse Act (CFAA) and similar regulations. This permission should explicitly define the testing scope, allowed techniques, and time windows, and it should ideally be obtained through the provider's official pen-testing authorization process or by adding the tester to the client's contract with the provider. Without such written authorization, even well-intentioned security testing can be construed as malicious activity, so obtaining this document is a non-negotiable prerequisite before any API testing begins.

Why this answer

Option C is correct because testing a third-party payment API without the provider's explicit written authorization is unauthorized access, regardless of the client's ownership of the application; the tester must obtain permission from the API provider (or verify the client has it) before sending any test traffic to that API. Option E is correct because if the provider does not grant permission, the API must be formally documented as out-of-scope in the rules of engagement and scope statement, so the tester avoids any unauthorized testing while still delivering a clear, defensible report. Option A is wrong because assuming a well-known provider is secure is an unfounded trust assumption that ignores the need for verification and authorization.

Option B is wrong because ignoring the API entirely may leave critical integration risks (authentication, data flow, error handling) untested and unassessed. Option D is wrong because criticality to the application never overrides the legal and ethical requirement for explicit permission before testing third-party systems.

Exam trap

The trap here is that candidates may assume a well-known API is inherently secure (Option A) or that testing only the client's code is sufficient (Option B), overlooking the legal necessity of permission and the risk of integration flaws.

118
MCQhard

A penetration tester is conducting a grey box test on a web application. During the test, the tester discovers that the application is hosted on a cloud infrastructure that belongs to a third-party provider. The client did not mention this provider in the scope. What is the best course of action regarding testing this infrastructure?

A.Add the cloud provider to the scope without notifying the client
B.Stop testing the cloud infrastructure and notify the client
C.Continue testing because the application is owned by the client
D.Obtain verbal permission from the cloud provider and proceed
AnswerB

The correct action is to immediately halt all testing against the cloud-infrastructure components that fall outside the client-authorized scope. Because the infrastructure is owned and operated by the cloud provider as a third party, continuing against it without authorization could constitute unauthorized access under laws like the CFAA or the Computer Misuse Act, and the tester must notify the client so the client can formally amend the scope or obtain written permission from the provider.

Why this answer

Testing third-party infrastructure without permission is illegal and violates the rules of engagement. The tester should stop testing that part and inform the client.

119
MCQmedium

A penetration tester has completed the test and is preparing the final report. The client asks the tester to include a section that describes the scope, methodology, and tools used. In which section should this information be placed?

A.Appendices
B.Remediation section
C.Technical findings
D.Executive summary
AnswerA

Appendices are the designated repository for supporting details in a penetration test report, such as raw scan output, command history, screenshots, and proof-of-concept exploit code. These artifacts validate the technical findings without interrupting the narrative flow of the main report. The question's context indicates the tester is organizing supplementary evidence, which explicitly belongs in an appendix section that can be referenced from the body.

Why this answer

Appendices are the appropriate place for supplementary information such as scope, methodology, and tools used.

120
MCQeasy

A client requests a penetration test that simulates an external attacker with no prior knowledge of the internal network. The tester is not provided with any credentials, network diagrams, or source code. Which type of test does this describe?

A.White-box test
B.Black-box test
C.Gray-box test
D.Covert test
AnswerB

A black-box test accurately simulates an external attacker with no prior knowledge, forcing the tester to perform open-source intelligence (OSINT), port scanning, and service enumeration to identify entry points. Because the client requested an 'external' test, this aligns perfectly: the tester starts from the outside with only public information and any active exploitation must be done from external network boundaries. This approach mirrors a real-world attack and minimizes bias about where vulnerabilities exist.

Why this answer

This is a black-box test because the tester simulates an external attacker with no prior knowledge of the internal network, no credentials, no network diagrams, and no source code. In black-box testing, the tester must discover all vulnerabilities from an outsider's perspective, relying solely on publicly available information and active reconnaissance techniques such as port scanning, service enumeration, and vulnerability scanning. This approach aligns with the client's requirement to mimic a real-world attacker who has zero insider knowledge.

Exam trap

The trap here is that candidates often confuse black-box testing with gray-box testing, mistakenly thinking that 'no credentials' automatically implies gray-box, but gray-box testing still provides some internal knowledge (e.g., network diagrams or low-privilege access), which is explicitly absent in this scenario.

How to eliminate wrong answers

Option A is wrong because a white-box test provides the tester with full knowledge of the internal network, including credentials, network diagrams, and source code, which contradicts the scenario where no such information is given. Option C is wrong because a gray-box test offers partial knowledge, such as limited credentials or network topology, whereas the scenario explicitly states no prior knowledge or credentials are provided.

121
MCQhard

A penetration tester is analyzing a PowerShell script that uses the 'Invoke-Command' cmdlet to execute commands on remote machines, and 'Set-Service' to change service startup types. What attack is this script most likely performing?

A.Remote service modification for persistence.
B.Lateral movement via PsExec.
C.Credential dumping.
D.Data exfiltration.
AnswerA

Invoke-Command with Set-Service is a classic persistence technique: it remotely alters a service's StartType (e.g., to Automatic) or recovery actions so that a malicious payload or backdoor survives reboots. The script does not show any new service creation, but modification of an existing service's configuration is sufficient for persistence because the service will launch automatically at system startup.

Why this answer

The script uses Invoke-Command to execute commands on remote machines and Set-Service to change service startup types. This combination is commonly used to modify a service to start automatically or to create a new service that runs malicious code, establishing persistence on a remote system. The attack does not involve lateral movement via PsExec (which uses SMB and service control manager differently) nor credential dumping (which requires tools like Mimikatz or direct memory access).

Exam trap

The trap here is that candidates confuse the use of Invoke-Command (PowerShell Remoting) with PsExec, but PsExec is a distinct tool that does not use the Invoke-Command cmdlet, and the focus on service modification points to persistence rather than lateral movement or credential theft.

How to eliminate wrong answers

Option B is wrong because PsExec is a separate tool that uses SMB and the Windows Service Control Manager to execute processes remotely, not the Invoke-Command cmdlet which relies on WinRM (WS-Management). Option C is wrong because credential dumping involves extracting password hashes or plaintext credentials from memory (e.g., LSASS) or registry, not modifying service startup types with Set-Service.

122
MCQmedium

A client hires a penetration testing firm to assess a web application. The client uses a third-party content delivery network (CDN) for static assets and explicitly wants to exclude the CDN infrastructure from testing. In which document should this restriction be formally documented?

A.Statement of Work (SOW)
B.Non-Disclosure Agreement (NDA)
C.Master Services Agreement (MSA)
D.Rules of Engagement (ROE)
AnswerD

The Rules of Engagement is the document that explicitly authorizes and constrains the technical execution of the assessment, including in-scope IP addresses, allowed testing times, emergency contacts, and specific exclusions like the CDN. It bridges the gap between contractual scope and the actual commands and techniques used, and it is the document the tester consults to determine exactly what may or may not be touched.

Why this answer

The Rules of Engagement (ROE) document is the correct place to formally document restrictions such as excluding the CDN infrastructure from testing. The ROE defines the scope, boundaries, and specific constraints for the penetration test, including which IP ranges, domains, or systems are off-limits. This ensures the testing team does not inadvertently target the third-party CDN, which could violate contractual agreements or cause unintended disruptions.

Exam trap

The trap here is that candidates confuse the ROE with the SOW, assuming the SOW is the catch-all document for all restrictions, but the ROE is specifically designed for operational boundaries and constraints in penetration testing engagements.

How to eliminate wrong answers

Option A is wrong because the Statement of Work (SOW) describes the high-level objectives, deliverables, and timeline of the engagement, but it does not typically contain granular operational constraints like excluding specific infrastructure components. Option B is wrong because the Non-Disclosure Agreement (NDA) is a legal contract protecting confidential information, not a document for defining testing boundaries or restrictions. Option C is wrong because the Master Services Agreement (MSA) establishes the overarching legal and business terms between parties, but it does not detail per-engagement technical limitations such as CDN exclusion.

123
MCQmedium

A company wants to simulate a real-world attack scenario where the penetration tester has no prior knowledge of the environment and must act as an external threat actor. However, the tester is allowed to use social engineering to gain initial access. Which type of engagement is most appropriate?

A.Red team exercise
B.Network penetration test
C.Wireless penetration test
D.Web application penetration test
AnswerA

A red team exercise is a full-scope, objective-based simulation that mimics a real adversary's tactics, techniques, and procedures (TTPs), including social engineering, physical access, email phishing, and exploitation. Unlike a single-vector assessment, it is designed to test the organization's overall security posture — people, processes, and technology — by stealthily moving toward a defined goal, such as data exfiltration or domain compromise. Social engineering is a core component because it validates whether employee awareness and security policies can resist real-world manipulation.

Why this answer

A red team exercise is a full-scope adversary simulation that can include social engineering and black box testing.

124
MCQeasy

Which SQL injection technique involves injecting a query that causes a delay in response, allowing the attacker to infer information based on response time?

A.Error-based SQL injection
B.UNION-based SQL injection
C.Boolean-blind SQL injection
D.Blind time-based SQL injection
AnswerD

Blind time-based SQL injection infers information by injecting a query that forces the database to sleep for a set interval only when a certain condition is true, then measuring the response time. For example, in MySQL an attacker can append 'AND SLEEP(5)' to make the query pause 5 seconds if the condition holds, allowing them to extract data character by character. This technique directly matches the description of injecting a query that leverages a temporal delay to infer database contents, so it is the correct answer.

Why this answer

Blind time-based SQL injection uses delays (e.g., WAITFOR DELAY) to infer true/false conditions.

125
Multi-Selecteasy

Which two tools are commonly used for password cracking in penetration testing?

Select 2 answers
A.Metasploit
B.Nmap
C.Hashcat
D.John the Ripper
E.Wireshark
AnswersC, D

Hashcat is a high-speed password recovery tool that offloads attacks to GPUs, enabling extremely fast brute-force, dictionary, combinator, mask, and rule-based attacks. It supports hundreds of hash types, including NTLM, Kerberos 5, bcrypt, and md5crypt, making it a preferred choice for cracking hashes captured during penetration tests. Its performance and attack flexibility make it one of the de facto standards for offline password cracking.

Why this answer

Hashcat (C) is a GPU-accelerated password recovery tool that supports hundreds of hash types (MD5, NTLM, bcrypt, WPA-PBKDF2, etc.) and attack modes like dictionary, brute-force, mask, and rule-based, making it a standard choice for cracking captured password hashes during penetration tests. John the Ripper (D) is another dedicated password cracker that auto-detects many hash formats, supports wordlist and incremental modes, and is widely used to crack /etc/shadow, NTLM, and other credential stores. The other options are not password-cracking tools: Metasploit (A) is an exploitation framework that may invoke crackers but is not itself one, Nmap (B) is a port scanner and service/OS fingerprinting tool, and Wireshark (E) is a packet capture and protocol analyzer.

126
MCQmedium

A penetration testing firm is hired to assess a client's hybrid infrastructure with on-premises and cloud servers in multiple regions. The client specifies testing only the on-premises systems due to budget and compliance. Which of the following should the tester emphasize in the rules of engagement (ROE)?

A.Detailed network diagrams of the cloud environment
B.Explicit exclusion of all cloud-based assets
C.Approval from the cloud service provider
D.A list of all cloud API endpoints
AnswerB

The Rules of Engagement must unambiguously delineate the authorized testing surface. Explicitly excluding cloud-based assets prevents the tester from inadvertently probing systems that are outside the contracted scope, which could constitute unauthorized access and violate cloud provider terms of service or data protection regulations. This clarity also aligns expectations between the client and tester, mitigating the risk of scope creep and ensuring that any findings are confined to the intended on-premises environment.

Why this answer

The client explicitly restricted testing to on-premises systems due to budget and compliance. The rules of engagement (ROE) must clearly define the authorized scope to prevent accidental testing of cloud assets, which could violate the contract and potentially breach the cloud provider's terms of service. Option B is correct because explicitly excluding all cloud-based assets ensures the tester does not touch any cloud resources, aligning with the client's constraints.

Exam trap

The trap here is that candidates may think they need cloud provider approval or network diagrams to understand the environment, but the key is respecting the client's explicit scope limitation by excluding cloud assets in the ROE.

How to eliminate wrong answers

Option A is wrong because detailed network diagrams of the cloud environment are irrelevant and out of scope; the tester is not authorized to test cloud systems, and requesting such diagrams could imply intent to test them, violating the client's restrictions. Option C is wrong because approval from the cloud service provider is not required when the cloud assets are explicitly excluded from testing; the tester has no need to interact with the cloud provider's infrastructure, and seeking such approval could create unnecessary legal or contractual complications.

127
Multi-Selectmedium

A penetration tester is conducting a web application reconnaissance and wants to discover API endpoints and hidden parameters. Which three tools are most appropriate for this task? (Choose THREE.)

Select 3 answers
A.ffuf
B.Wappalyzer
C.Arjun
D.Gobuster
E.Whatweb
AnswersA, C, D

ffuf brute-forces web paths and parameter names using wordlists, directly satisfying the requirement to discover hidden API endpoints and parameters during reconnaissance. Its fuzzing engine substitutes payloads into URL paths or query strings, revealing resources that normal browsing misses, making it appropriate alongside other content-discovery tools.

Why this answer

ffuf (A) is correct because it is a fast web fuzzer that can brute-force directories, files, and API endpoint paths using wordlists, making it ideal for discovering hidden API routes. Arjun (C) is correct because it is specifically designed to discover hidden HTTP parameters by sending requests with common parameter names and analyzing response differences, which directly addresses the hidden-parameter discovery goal. Gobuster (D) is correct because its dir and vhost modes perform dictionary-based brute-forcing of web paths and subdomains, effectively enumerating API endpoints and hidden directories.

Wappalyzer (B) is not appropriate because it only fingerprints technologies (CMS, frameworks, libraries) from page content and headers, not endpoints or parameters. Whatweb (E) is also a fingerprinting tool that identifies web technologies and server banners, so it does not enumerate endpoints or hidden parameters.

Exam trap

The trap here is that candidates may confuse technology fingerprinting tools (Wappalyzer, Whatweb) with active discovery tools, or forget that Gobuster's directory brute-force mode is valid for API endpoint discovery, not just web directories.

128
MCQhard

During a web application test, you find a feature that allows users to export data as PDF. The PDF generation uses user input without sanitization. You inject an XML external entity that reads /etc/passwd and the content appears in the PDF. Which vulnerability is present?

A.Server-Side Request Forgery (SSRF)
B.XML External Entity (XXE)
C.Command injection
D.Cross-Site Scripting (XSS)
AnswerB

XXE uses external entities to read files.

Why this answer

The vulnerability is XML External Entity (XXE) because the PDF generator parses user-supplied XML and resolves external entity references, allowing the attacker to read local files like /etc/passwd. The defining signature is the injection of a DOCTYPE declaration with an ENTITY that references a file:// or similar URI, and the content appearing in the output. This is the textbook XXE file-disclosure scenario.

Exam trap

The trap is that the payload travels through a PDF export feature, so candidates assume the bug is in the PDF library or is an SSRF — but the root cause is XML entity resolution, and the exam tests whether you recognize the DOCTYPE/ENTITY signature as XXE regardless of the output channel.

How to eliminate wrong answers

Option A is wrong because SSRF causes the server to make HTTP requests to internal or external resources — the attacker retrieves responses from other services, not local files via XML entity resolution. Option C is wrong because command injection executes OS commands through shell metacharacters in input; here the payload is an XML entity, not a shell command, and the output is file content, not command output. Option D is wrong because XSS executes JavaScript in a victim's browser; the payload here is server-side XML parsed by the PDF engine, and the impact is server-side file disclosure, not client-side script execution.

129
MCQeasy

During the reconnaissance phase, a penetration tester wants to identify subdomains of a target domain without making direct requests to the target's own DNS servers. Which technique would be BEST for this purpose?

A.Using the 'nslookup' command interactively
B.Performing a zone transfer
C.Using search engines and public certificate transparency logs
D.Using the 'host' command
AnswerC

Search engines and public certificate transparency logs are external, third-party aggregators that collect data from the target without any interaction from the tester. CT logs, like crt.sh, are append-only ledgers of issued TLS certificates, compelling certificate authorities to publish them; querying these logs reveals subdomains and other infrastructure. Since this method sends no packets to the target's servers and generates no target-side logs, it is a textbook passive reconnaissance technique.

Why this answer

Search engines (e.g., Google dorking) and public certificate transparency logs (e.g., crt.sh) allow a tester to discover subdomains by querying aggregated historical DNS and TLS certificate data, without sending any queries to the target's authoritative DNS servers. This passive reconnaissance technique avoids alerting the target's infrastructure and complies with the requirement of no direct requests to the target's DNS servers.

Exam trap

CompTIA often tests the distinction between active and passive reconnaissance, and the trap here is that candidates may choose zone transfer (Option B) because it is a well-known DNS enumeration technique, but they overlook that it requires direct contact with the target's DNS server and is typically blocked, whereas certificate transparency logs provide a passive alternative that avoids direct interaction.

How to eliminate wrong answers

Option A is wrong because using 'nslookup' interactively sends DNS queries directly to the target's DNS servers (or configured resolvers), which violates the requirement of not making direct requests to the target's own DNS servers. Option B is wrong because performing a zone transfer (AXFR) requires a direct TCP connection to the target's authoritative DNS server on port 53, and most modern DNS servers are configured to deny zone transfers except to authorized secondary servers, making it both a direct request and often unsuccessful.

130
MCQeasy

A tester wants to enumerate SMB shares and execute commands remotely on a Windows target using captured credentials. Which tool is most appropriate?

A.Hashcat
B.Responder
C.CrackMapExec
D.Bettercap
AnswerC

CrackMapExec is a post-exploitation tool that natively supports SMB share enumeration and remote command execution. It authenticates over SMB and can list shares, access files, and run arbitrary commands via named pipes or WMI. This makes it the correct choice for a tester who needs to enumerate SMB shares and execute commands in an Active Directory environment.

Why this answer

CrackMapExec is a versatile tool for SMB enumeration, command execution, and lateral movement with credentials.

131
MCQhard

A penetration tester has gained access to a Linux server and wants to move laterally to a Windows server. The tester captured a hash of a domain user. Which tool can be used to authenticate to the Windows server using the hash?

A.evil-winrm
B.Ligolo-ng
C.SSH
D.Chisel
AnswerA

evil-winrm is the correct choice because it natively supports pass-the-hash authentication against the WinRM service. Using the --hash flag, an attacker can authenticate with an NTLM hash (LM:NT) directly, circumventing the need for a cleartext password. This tool also provides an interactive PowerShell shell, making it a standard lateral-movement utility for post-exploitation on Windows servers.

Why this answer

evil-winrm supports pass-the-hash authentication over WinRM, allowing lateral movement.

132
MCQeasy

Which penetration testing standard provides a structured methodology for conducting penetration tests, including pre-engagement, reconnaissance, and reporting phases?

A.NIST SP 800-115
B.OWASP Testing Guide
C.PTES
D.OSSTMM
AnswerC

PTES, the Penetration Testing Execution Standard, offers a comprehensive, structured methodology that explicitly defines seven phases: pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting. It standardizes both technical execution and communication, including rules of engagement, data handling, and report templates. This makes it a complete, industry-recognized standard for penetration testing, clearly surpassing the narrower guides.

Why this answer

The Penetration Testing Execution Standard (PTES) covers the entire testing lifecycle.

133
MCQeasy

A penetration tester is preparing the executive summary for a client's board of directors. Which of the following is the most appropriate content for this section?

A.Detailed step-by-step reproduction steps for each vulnerability
B.A list of all discovered IP addresses and open ports
C.A high-level overview of risks, business impact, and recommended strategic improvements
D.The raw output of automated scanning tools used during the test
AnswerC

The executive summary must translate the findings into a high-level narrative that shows how vulnerabilities affect core business objectives, legal obligations, and risk tolerance, allowing the board to act without needing deep technical expertise. It should aggregate risk into qualitative ratings, articulate probable business impact (such as revenue, reputation, or compliance penalties), and propose strategic remediation investments, which is precisely the decision-support content this option describes.

Why this answer

The executive summary is intended for the board of directors, who require a high-level understanding of risks, business impact, and strategic recommendations rather than technical details. Option C aligns with the PT0-002 objective of tailoring communication to the audience, focusing on risk posture and remediation priorities that inform executive decision-making.

Exam trap

CompTIA often tests the candidate's ability to distinguish between audience-appropriate content, trapping those who confuse the executive summary with the technical report by including granular technical data like reproduction steps or raw scan results.

How to eliminate wrong answers

Option A is wrong because detailed step-by-step reproduction steps belong in the technical report or findings appendix, not the executive summary, which must avoid overwhelming non-technical stakeholders with procedural minutiae. Option B is wrong because a raw list of IP addresses and open ports is operational data for the technical team; the executive summary should synthesize this into risk context and business impact, not present unprocessed reconnaissance output.

134
MCQmedium

You are performing a network scan and need to identify live hosts on a subnet without triggering firewalls that block ICMP. Which technique should you use?

A.ARP scan with arp-scan
B.Ping sweep with nmap -sn
C.TCP SYN ping with nmap -PS
D.UDP scan with nmap -sU
AnswerA

ARP scan with arp-scan is the correct choice because ARP requests operate at Layer 2, directly querying each host on the local broadcast domain. Since ARP traffic is encapsulated in Ethernet frames, IP-based firewalls and host-based packet filters cannot intercept or block these probes, making ARP the most reliable method for discovering live hosts on the same subnet. Additionally, arp-scan sends gratuitous ARP requests and parses replies, efficiently mapping all active MAC and IP addresses without relying on higher-layer protocols.

Why this answer

Using ARP scan (arp-scan) works on local networks and does not rely on ICMP, making it effective even when ICMP is blocked. It sends ARP requests and listens for replies.

135
MCQeasy

A penetration tester is conducting information gathering on a target organization. The tester discovers a public code repository that contains configuration files with embedded credentials. Which of the following is the BEST next step?

A.Notify the organization's security team of the exposed credentials.
B.Attempt to crack the passwords to gain further access.
C.Document the findings and proceed with passive reconnaissance.
D.Use the credentials to log into the target system immediately.
AnswerA

Exposed credentials are an active risk indicator, not merely a data point for the report. By notifying the organization's security team immediately, the pentester enables them to rotate affected accounts, investigate potential prior misuse, and harden authentication controls before a real attacker exploits them. This action aligns with responsible-disclosure obligations and the rules of engagement that prioritize minimizing harm to the client.

Why this answer

The tester has discovered exposed credentials in a public code repository, which is a critical security finding that requires immediate disclosure to the organization's security team. Ethical penetration testing mandates that any discovered vulnerabilities, especially those involving credential exposure, be reported promptly to prevent unauthorized access and potential data breaches. Proceeding with further exploitation without authorization violates the rules of engagement and could cause legal or operational harm.

Exam trap

The trap here is that candidates may confuse passive reconnaissance with active exploitation, thinking that documenting and moving on is sufficient, when in fact exposed credentials demand immediate action to prevent real-world compromise.

How to eliminate wrong answers

Option B is wrong because attempting to crack the passwords is an active exploitation step that goes beyond passive information gathering and violates the scope of engagement without prior authorization. Option C is wrong because documenting the findings and proceeding with passive reconnaissance ignores the urgency of exposed credentials, which could be exploited by malicious actors in the meantime. Option D is wrong because using the credentials to log into the target system immediately constitutes unauthorized access and is a violation of ethical hacking principles and legal boundaries.

136
MCQmedium

A tester is targeting a web application that makes server-side requests to internal resources based on user input. The tester attempts to access the AWS metadata endpoint at http://169.254.169.254/latest/meta-data/. The request returns sensitive cloud credentials. Which vulnerability is being exploited?

A.IDOR
B.SSRF
C.XXE
D.CSRF
AnswerB

SSRF (Server-Side Request Forgery) occurs when a web application makes HTTP requests to a destination chosen by an attacker without properly validating the URL or host. The attacker can pivot the server into requesting internal-only endpoints, such as cloud instance metadata (e.g., http://169.254.169.254/latest/meta-data/) or internal admin panels. Because the request originates from the server itself, firewalls and network segmentation may be bypassed, making SSRF a direct and high-impact match for the scenario where the tester targets server-side request behavior.

Why this answer

SSRF (Server-Side Request Forgery) allows the attacker to make the server send requests to internal resources. The metadata endpoint is a classic SSRF target. XXE can also access files but typically via entity injection, not direct URL.

137
MCQhard

A penetration tester is writing a report and needs to classify vulnerabilities by risk level. The client has a formal risk acceptance process. Which of the following best describes the purpose of including a risk acceptance section in the report?

A.To provide step-by-step remediation instructions
B.To record vulnerabilities the client has decided not to fix, with justification
C.To justify why the tester did not exploit certain vulnerabilities
D.To document all vulnerabilities found during the test
AnswerB

The risk acceptance section documents findings the client formally chooses not to remediate, capturing the justification and accepting party. This satisfies their risk acceptance process and protects the tester from liability for known, accepted issues.

Why this answer

Option B is correct because a risk acceptance section formally records vulnerabilities that the client has consciously chosen not to remediate, along with the business justification and any compensating controls, which aligns with the client's formal risk acceptance process. This section documents the client's informed decision to retain the residual risk rather than fix it. Option A is wrong because remediation instructions belong in the findings/remediation guidance, not the risk acceptance section.

Option C is wrong because a tester's decision not to exploit a vulnerability relates to testing scope or methodology, not risk acceptance. Option D is wrong because documenting all vulnerabilities is the purpose of the findings section, not the risk acceptance section.

138
MCQmedium

You are conducting a penetration test and need to identify subdomains of a target domain using a passive approach that does not generate traffic to the target's servers. Which technique should you use?

A.Certificate transparency logs
B.DNS cache snooping
C.Subdomain bruteforce with gobuster
D.DNS zone transfer
AnswerA

Certificate transparency logs are a passive discovery resource because they are publicly available, append-only ledgers maintained by independent log operators, and querying them does not involve sending any packets to the target organization's own servers or infrastructure. Services like crt.sh or Censys provide APIs that return certificates issued for a domain, often revealing subdomains, wildcard entries, and even expired certificates that were previously in use. This method leaves no trace on the target's DNS logs, web servers, or intrusion detection systems, making it a classic OSINT/ passive-recon technique. For a penetration tester, it provides a high-yield, low-risk baseline for expanding the attack surface before active testing begins.

Why this answer

Certificate transparency logs (e.g., crt.sh) are public logs of SSL/TLS certificates, often containing subdomain names. Querying them is passive and does not interact with the target.

139
MCQhard

A penetration tester is analyzing a web application and discovers that it uses a JSON Web Token (JWT) for session management. The tester captures a token and notices that the signature algorithm is 'none'. The application accepts tokens with the 'none' algorithm. Which type of vulnerability does this represent, and what is the immediate impact?

A.Weak signing key vulnerability, allowing brute-force of the HMAC secret
B.Token replay attack due to lack of expiration validation
C.JWT signature bypass due to 'none' algorithm acceptance, enabling token forgery
D.Algorithm confusion attack, allowing token forgery with arbitrary claims
AnswerC

When a JWT is signed with the 'none' algorithm, it has no signature. If the application accepts such tokens, an attacker can modify the payload (e.g., change the username or role) and set the algorithm to 'none', and the token will be considered valid. This allows privilege escalation or impersonation. The immediate impact is that the tester can forge tokens with arbitrary claims, bypassing authentication and authorization.

Why this answer

Accepting JWTs with the 'none' algorithm means the application does not verify the token's integrity. An attacker can craft a token with any claims and set the algorithm to 'none', and the server will trust it. This is a critical authentication bypass.

The immediate impact is that the tester can impersonate any user or escalate privileges by modifying the token payload. Proper validation should reject tokens with 'none' unless explicitly intended and secured.

Exam trap

The trap here is confusing the 'none' algorithm vulnerability with algorithm confusion or weak key attacks, when in fact it is a straightforward signature bypass that allows arbitrary token forgery.

140
MCQeasy

A penetration tester is compiling the final report. The client's compliance officer requires a section that maps each finding to specific regulatory requirements (e.g., PCI DSS, HIPAA). Which section of the report is best suited for this mapping?

A.Executive Summary
B.Technical Findings
C.Compliance Mapping
D.Appendices
AnswerC

The compliance mapping section is purpose-built to translate technical vulnerabilities into a regulatory context, directly addressing the compliance officer's need for a clear correlation. It typically uses a matrix that maps each finding to applicable standards—such as PCI DSS requirements, HIPAA administrative/technical safeguards, or SOC 2 criteria—including the failed control, evidence of non-compliance, and recommended remediation actions. This section provides a direct, defensible audit trail and demonstrates the organization's compliance posture, enabling stakeholders to prioritize remediation based on both technical risk and legal/regulatory obligations.

Why this answer

The Compliance Mapping section is specifically designed to cross-reference each technical finding with relevant regulatory frameworks such as PCI DSS, HIPAA, or GDPR. This allows the compliance officer to quickly verify that all required controls are addressed and that the report meets audit or legal standards. The other sections focus on summarizing or detailing technical issues, not on mapping findings to specific regulations.

Exam trap

The trap here is that candidates often confuse the Technical Findings section as the place for all detailed information, including compliance references, but the exam expects a dedicated Compliance Mapping section to satisfy audit and regulatory requirements separately.

How to eliminate wrong answers

Option A is wrong because the Executive Summary provides a high-level overview of the engagement's objectives, scope, and critical risks for management, not a detailed mapping to regulatory requirements. Option B is wrong because the Technical Findings section describes vulnerabilities, exploitation steps, and remediation in depth, but does not explicitly correlate each finding with specific compliance standards like PCI DSS or HIPAA.

141
MCQeasy

A penetration tester wants to discover email addresses associated with a target domain (example.com) without sending any network packets to the target's systems. Which technique is BEST suited for this?

A.Google dorking
B.DNS brute forcing
C.WHOIS lookup
D.SMB enumeration
AnswerA

Google dorking leverages search engine indexes to find publicly available emails embedded in documents, web pages, or mailing lists. Using operators such as filetype:pdf, intext:@domain.com, or site:target.com, a tester can systematically extract addresses without sending a single packet to the target. This passive approach makes it ideal for initial reconnaissance, as the target's logs remain unaware of the activity.

Why this answer

Google dorking uses advanced search operators (e.g., site:example.com intext:@example.com) to index publicly available information from Google's cached pages, allowing discovery of email addresses without sending any packets to the target's infrastructure. This passive reconnaissance technique relies solely on pre-existing search engine data, making it ideal for avoiding direct interaction with the target.

Exam trap

The trap here is that candidates often confuse passive reconnaissance with techniques like DNS brute forcing or WHOIS lookups, but DNS brute forcing is active (sends packets) and WHOIS lookups only yield limited administrative contacts, not the broad email discovery that Google dorking provides.

How to eliminate wrong answers

Option B (DNS brute forcing) is wrong because it involves sending DNS queries to the target's name servers to enumerate subdomains, which generates network packets and active interaction with the target's systems. Option C (WHOIS lookup) is wrong because while it is passive, it typically returns administrative and technical contact emails (e.g., admin@example.com) rather than a broad set of user email addresses associated with the domain, and it queries public WHOIS databases, not the target's own systems.

142
MCQhard

A penetration tester is performing a wireless penetration test. The RoE states that testing is only allowed between 8 PM and 6 AM. At 7:30 PM, the tester begins active scanning. At 8:15 PM, a client employee calls emergency contact to report suspicious activity. According to the RoE, which of the following is the most likely reason for the call?

A.The tester used an unauthorized tool
B.The tester started testing outside the agreed time window
C.The tester targeted an out-of-scope access point
D.The tester exceeded the allowed signal strength
AnswerB

Active scanning began at 7:30 PM, thirty minutes before the 8 PM window opened, so the tester breached the RoE's permitted testing hours. The employee's 8:15 PM call follows that unauthorised activity, making the early start the most likely trigger. The constraint satisfied is the agreed time window itself.

Why this answer

The RoE explicitly restricts testing to 8 PM – 6 AM, but the tester began active scanning at 7:30 PM — 30 minutes before the allowed window. Active scanning generates detectable wireless traffic (probe requests, deauth frames, association attempts) that a client employee could notice and report. The call at 8:15 PM is most likely a delayed report of the activity that started at 7:30 PM, outside the agreed window.

Exam trap

PT0-003 often tests whether candidates correctly attribute an incident to the specific RoE clause violated (timing, scope, tooling) rather than assuming the most dramatic cause like out-of-scope targeting.

How to eliminate wrong answers

Option A is wrong because the scenario provides no information about unauthorized tools; the RoE violation described is temporal, not tool-related. Option C is wrong because there is no indication the tester targeted an out-of-scope access point — the scenario only mentions timing. Option D is wrong because signal strength limits are not mentioned in the RoE excerpt provided, and the question focuses on the time-window violation.

143
MCQeasy

A penetration tester discovers a critical vulnerability during an assessment. According to best practices, when should the tester communicate this finding to the client?

A.Only in the final report
B.After the test is complete
C.Immediately upon discovery
D.At the next scheduled status meeting
AnswerC

Communicating the vulnerability as soon as it is verified is the only approach that aligns with the primary goal of penetration testing: to reduce client risk, not simply to produce a report. Immediate notification enables the client to initiate emergency change-management, quarantine affected systems, or apply compensating controls while the test is still running, and it also allows the tester to document the exact proof-of-concept and evidence while it is fresh. This direct, real-time dialogue is typically required by organizational policies, insurance policies, or industry frameworks like PTES, which emphasize timely handling of critical issues to minimize exploitation risk.

Why this answer

Critical findings should be reported immediately to allow the client to take urgent action.

144
MCQhard

During a penetration test, a tester uses the Wayback Machine to review historical versions of the target's website. What is the primary benefit of this activity?

A.It reveals old web pages that may contain sensitive information or forgotten endpoints
B.It bypasses the target's WAF
C.It provides real-time vulnerability data
D.It performs a live vulnerability scan
AnswerA

Historical snapshots stored by the Internet Archive capture the target's web pages at various points in time. Penetration testers can mine these archives to locate old URLs, deprecated backup files, configuration snippets, or even credentials that were inadvertently posted before being removed from the live site. This passive intelligence gathering expands the attack surface by exposing forgotten endpoints that no longer appear in current site maps.

Why this answer

The Wayback Machine archives historical snapshots of web pages, which can reveal old files, endpoints, or sensitive information that may have been removed but are still accessible on the live site.

145
MCQeasy

A penetration tester wants to discover all subdomains of a target domain without directly querying the target's DNS servers to avoid detection. Which technique is most appropriate?

A.DNS zone transfer
B.Brute-force subdomain enumeration using a wordlist
C.Passive DNS enumeration using public data sources
D.SNMP community string enumeration
AnswerC

Passive DNS enumeration leverages publicly available data sources such as certificate transparency logs, historical DNS records, search engine caches, and third-party passive DNS databases. It does not send any packets directly to the target's own servers, so the target cannot detect or log the reconnaissance activity. This makes it a truly stealthy method for discovering externally visible subdomains, though it may not find internal-only hostnames.

Why this answer

Passive DNS enumeration leverages public data sources such as certificate transparency logs, search engine caches, and passive DNS databases (e.g., VirusTotal, SecurityTrails) to discover subdomains without sending any queries to the target's authoritative DNS servers. This approach avoids generating DNS traffic that could be logged or detected by the target's monitoring systems, making it ideal for stealthy reconnaissance.

Exam trap

The trap here is that candidates may confuse passive enumeration with brute-force or zone transfer techniques, overlooking the explicit requirement to avoid direct DNS queries and detection, which only passive methods satisfy.

How to eliminate wrong answers

Option A is wrong because DNS zone transfer (AXFR) requires the target's DNS server to be misconfigured to allow unrestricted zone transfers, and it directly queries the target's DNS server, which would be detected. Option B is wrong because brute-force subdomain enumeration using a wordlist involves sending numerous DNS queries to the target's DNS servers to test each subdomain, generating detectable traffic and defeating the requirement to avoid direct queries.

146
MCQmedium

A penetration tester is using Burp Suite to test a web application. The tester notices that the application relies on client-side JavaScript validation to restrict input. To bypass this validation and test for server-side vulnerabilities, which Burp Suite feature is MOST useful for automatically modifying requests before they are sent to the server?

A.Proxy (with Match and Replace rules)
B.Intruder
C.Repeater
D.Decoder
AnswerA

The Proxy module sits between the browser and the web server, capturing every HTTP/S request and response. Match and Replace rules allow you to define regular expression-based conditions that automatically rewrite headers, body fields, or even entire requests in real time, effectively overriding client-side restrictions such as maxlength attributes, hidden form values, or JavaScript-based checks. This means the tester can alter traffic without manual interaction, making it the correct tool for this scenario.

Why this answer

The Proxy's Match and Replace rules allow the tester to automatically modify HTTP requests in transit, such as stripping or altering client-side validation parameters (e.g., maxlength, pattern attributes) before they reach the server. This bypasses client-side JavaScript restrictions because the modifications occur after the browser's validation but before the request is forwarded to the server, enabling direct testing of server-side input handling.

Exam trap

The trap here is that candidates often confuse Intruder's ability to send many requests with automatic modification of live traffic, not realizing that Intruder requires manual payload configuration and does not intercept browser-generated requests in real-time like Proxy Match and Replace does.

How to eliminate wrong answers

Option B (Intruder) is wrong because Intruder is designed for automated brute-force attacks, fuzzing, or parameter enumeration by sending many crafted requests, but it does not automatically modify requests as they pass through a proxy; it requires manual configuration of payload positions and does not intercept live browser traffic. Option C (Repeater) is wrong because Repeater is used for manually resending and tweaking individual requests after they have been captured, but it does not automatically modify requests in real-time before they are sent to the server; it operates on already-captured requests and lacks the automatic, on-the-fly substitution capability of Match and Replace rules.

147
MCQmedium

A penetration tester wants to identify all subdomains for a target domain using only public records. Which technique is most effective for this purpose?

A.Searching crt.sh (Certificate Transparency logs).
B.DNS zone transfer.
C.Using Nmap to brute-force subdomains.
D.Querying the domain's MX records.
AnswerA

Certificate Transparency logs are public, append-only ledgers that record every TLS certificate issued by a trusted CA, including the Subject Alternative Name (SAN) entries. By querying crt.sh for the target domain, you retrieve a historical list of all certificates that referenced the domain or any of its subdomains. Because this data comes from third-party CT log servers rather than the target's own infrastructure, it constitutes passive reconnaissance that generates zero direct traffic to the target.

Why this answer

Certificate Transparency logs, accessible via crt.sh, are a public record of all SSL/TLS certificates issued for a domain. Since certificates often include Subject Alternative Names (SANs) listing subdomains, querying crt.sh reveals subdomains without any interaction with the target's infrastructure. This technique is passive, requires no authorization, and leverages mandatory logging per RFC 6962, making it highly effective for enumeration from public records.

Exam trap

The trap here is that candidates confuse 'public records' with 'active DNS queries' and choose DNS zone transfer (B) or brute-forcing (C), failing to recognize that Certificate Transparency logs are the only passive, public-record-based option listed.

How to eliminate wrong answers

Option B is wrong because DNS zone transfer (AXFR) is not a public record technique; it requires explicit server configuration to allow transfers, and modern DNS servers almost always restrict it to authorized secondary nameservers, making it a high-risk, active technique that rarely succeeds against hardened targets. Option C is wrong because using Nmap to brute-force subdomains is an active scanning technique that generates network traffic to the target's DNS servers, which is not 'using only public records' and can be detected or blocked, unlike passive methods.

148
MCQeasy

A penetration tester is writing the executive summary of a report for a client. The client's executive team needs to understand the overall risk posture. Which of the following should be included in the executive summary?

A.Detailed step-by-step replication steps for each vulnerability
B.A list of all CVSS scores for each finding
C.A high-level overview of the test's objectives, scope, and key findings with business impact
D.Raw scan output from vulnerability scanners
AnswerC

The executive summary must translate the penetration test's outcomes into strategic language that non-technical decision-makers can act upon. By clearly stating the objectives, scope, and key findings together with their business impact, it provides a defensible basis for prioritizing remediation investments and accepting residual risk. This format aligns with common reporting standards such as the PTES and the PenTest+ reporting guidance, where executive summaries emphasize risk posture over technical mechanics.

Why this answer

The executive summary is intended for non-technical leadership who need to grasp the overall risk posture quickly. Option C provides a high-level overview of objectives, scope, and key findings with business impact, which aligns with the PT0-002 objective of tailoring communication to the audience. Detailed technical data like replication steps or raw CVSS scores belong in the technical report, not the executive summary.

Exam trap

The trap here is that candidates confuse the executive summary with the technical report, thinking that including raw data like CVSS scores or replication steps makes the summary more 'complete,' when in fact it overwhelms the intended audience with irrelevant detail.

How to eliminate wrong answers

Option A is wrong because detailed step-by-step replication steps are operational details meant for the technical report or remediation team, not for executives who need a strategic risk overview. Option B is wrong because a list of all CVSS scores is too granular and lacks business context; executives need interpreted risk levels (e.g., critical, high) tied to business impact, not raw numerical scores.

149
MCQmedium

A penetration tester has gained initial access to a Linux server through a vulnerable web application. The server has a restrictive outbound firewall that only allows traffic on ports 80, 443, and 53. The tester wants to establish a reverse shell that is likely to bypass the firewall. Which of the following techniques would be most effective?

A.Use a reverse shell listener on TCP port 3389 and connect from the target
B.Use a bind shell on the target's port 4444 and connect directly
C.Use a reverse shell over DNS by encoding commands in DNS queries
D.Use a reverse shell on TCP port 8080 and hope it is not blocked
AnswerC

A DNS reverse shell works by encoding command output and input inside DNS queries and responses, using tools like dnscat2 or iodine. Because UDP/TCP port 53 is typically allowed outbound for name resolution, this tunnel bypasses the firewall's egress restrictions without raising immediate alarms. The DNS protocol is often not deeply inspected by firewalls, allowing the attacker to encapsulate arbitrary data in query names and response records. This makes it a reliable and stealthy method when the only allowed ports are 80, 443, and 53.

Why this answer

DNS traffic on port 53 is typically allowed through restrictive outbound firewalls, and encoding reverse shell commands within DNS queries allows the tester to tunnel traffic over DNS, bypassing the firewall's port restrictions. Tools like dnscat2 or iodine can encapsulate TCP data in DNS requests, making the reverse shell appear as legitimate DNS traffic.

Exam trap

The trap here is that candidates may assume a reverse shell on a non-standard port (like 3389) will work because it's a common service port, but the firewall's explicit allow list (80, 443, 53) makes any other port blocked, and DNS tunneling is the only technique that leverages an allowed protocol for covert communication.

How to eliminate wrong answers

Option A is wrong because TCP port 3389 is used for RDP (Remote Desktop Protocol), which is not a standard outbound port allowed by the firewall (only ports 80, 443, and 53 are allowed), and even if it were, a reverse shell listener on that port would still be blocked by the firewall. Option B is wrong because a bind shell opens a listening port on the target (port 4444), but the restrictive outbound firewall does not block inbound connections; the issue is that the tester cannot initiate a direct connection to the target from outside due to the firewall's outbound rules, and the bind shell requires the tester to connect to the target, which is not possible if the target is behind NAT or has no direct route.

150
MCQmedium

In a Python script for a penetration test, you need to craft a custom TCP packet with specific flags. Which library is best suited for low-level packet manipulation?

A.requests
B.scapy
C.socket
D.impacket
AnswerB

Scapy is purpose-built for packet crafting and manipulation. It provides a declarative, layer-by-layer API where you can compose packets like `IP(src='10.0.0.1')/TCP(dport=80, flags='S')`, then send them with functions such as `send()`, `sendp()`, or `sr()`. Scapy also handles checksum calculation, fragmentation, retransmissions, and dissection of responses, making it the de facto standard for network exploration, fuzzing, and custom TCP flag testing in penetration tests.

Why this answer

Scapy allows crafting, sending, and sniffing network packets at a low level, supporting custom TCP flags.

Page 1

Page 2 of 11

Page 3

All pages