","comment":{"@type":"Comment","text":"The payload is a classic cross-site scripting (XSS) probe that executes JavaScript in the victim's browser. It does not interact with the server's XML parser, so it cannot detect XML external entity injection. This attack targets client-side rendering and reflected/stored input, not server-side XML processing."}},{"@type":"Answer","text":"'; DROP TABLE users; --","comment":{"@type":"Comment","text":"The input '; DROP TABLE users; -- is a SQL injection attempt that tries to terminate the current SQL statement and execute a destructive command on the database. It is unrelated to XML parsing; it targets the database layer, not the XML parser. Using this payload would not reveal XXE vulnerabilities because it doesn't involve document type declarations or entity resolution."}},{"@type":"Answer","text":"../../etc/passwd","comment":{"@type":"Comment","text":"This payload attempts a path traversal attack by using ../ sequences to navigate outside the web root to access /etc/passwd on the filesystem. It exploits the web server's file handling logic, not the XML parser's entity resolution. It is a different vulnerability class from XXE and would not trigger an external entity fetch."}}]}]
A tester wants to crack NTLM hashes captured from a Windows domain. Which hashcat mode should be used for NTLM hashes?
A.-m 1000
B.-m 13100
C.-m 0
D.-m 22000
AnswerA
Hashcat mode 1000 is the designated mode for cracking NT/NTLM hashes, the MD4-based hash of the UTF-16LE password used by Windows for authentication. When an attacker captures NTLM hashes (e.g., from the SAM database or NTDS.dit), mode 1000 is required because the hash format is not a generic MD5 or another algorithm; it's a specific Windows-specific format. This mode directly processes the raw 32-character hexadecimal NTLM hash and is the correct choice for this scenario.
A penetration tester is writing a report and needs to assign a severity rating to a vulnerability that has a CVSS base score of 7.5. According to CVSS v3.1, which severity level does this score correspond to?
A.Critical
B.Low
C.Medium
D.High
AnswerD
Under CVSS v3.x, a base score of 7.5 falls squarely within the High severity band, which spans 7.0 to 8.9. This score commonly results from a network attack vector, low user interaction, and a significant impact on one or more security objectives, though not enough to reach the near-maximum conditions of Critical. Assigning High is accurate and ensures the vulnerability is prioritized appropriately in remediation planning, in line with widely accepted scoring interpretations.
A penetration tester is analyzing a Bash script used for post-exploitation enumeration. The script contains the line: `cat /etc/shadow | awk -F: '{print $1, $2}'`. What is the primary purpose of this command?
A.Display all usernames and their associated password hashes
B.Show the number of users in the system
C.Extract the usernames and home directories
D.List the account expiration dates
AnswerA
The command parses the /etc/shadow file, which stores user authentication data in colon-delimited fields. The first field is the username and the second is the password hash (or a placeholder like ! or * for locked accounts). By printing these two fields, the script effectively dumps every local user's account name alongside its cryptographic hash, enabling offline password cracking with tools like John the Ripper or Hashcat. This is a classic post-exploitation credential-gathering technique, but it requires root or CAP_DAC_READ_SEARCH privileges to read /etc/shadow.
Why this answer
The command `cat /etc/shadow | awk -F: '{print $1, $2}'` reads the shadow file, which stores user account information including password hashes. The `-F:` sets the field separator to colon, and `{print $1, $2}` outputs the first field (username) and second field (password hash). This is a common post-exploitation technique to extract password hashes for offline cracking.
Exam trap
The trap here is that candidates may confuse `/etc/shadow` with `/etc/passwd`, which stores user metadata like home directories, leading them to incorrectly select option C instead of recognizing the hash extraction purpose.
How to eliminate wrong answers
Option B is wrong because counting users would require a different command, such as `wc -l` to count lines, not printing specific fields. Option C is wrong because home directories are stored in `/etc/passwd` (typically field 6), not in `/etc/shadow`, and this command only accesses the shadow file.
A penetration tester obtains a low-privilege shell on a Linux host during an engagement. While enumerating, the tester finds a cron job that runs a script located in a world-writable directory as root every five minutes. Which action should the tester take to escalate privileges using this finding?
A.Search for SUID binaries and abuse one that permits arbitrary file reads
B.Modify the script in the world-writable directory to execute a reverse shell when the cron job runs
C.Run 'sudo -l' to list permitted commands and find a binary that can be abused for escalation
D.Read /etc/crontab to confirm the schedule and then wait for the job to run unmodified
AnswerB
A root-owned cron job executing a script stored in a world-writable directory is a classic privilege escalation path. Because the tester can overwrite the script's contents, the next scheduled execution runs the modified code with root privileges. Replacing the script body with a command that spawns a root shell directly leverages the misconfiguration found during enumeration.
Why this answer
The exploitable condition is a scheduled task running as root that executes a file the low-privilege user can write. Overwriting that script causes the cron daemon to run attacker-controlled code with root privileges on the next interval. This directly converts the enumerated misconfiguration into elevated access, which is the intended outcome.
Exam trap
The trap here is treating enumeration steps such as checking sudo rights or SUID binaries as the exploit itself, when the scenario already hands the tester a concrete writable-script weakness to abuse.
During a penetration test of a corporate network, you discover a Linux server running a custom Python application that handles authentication for a web portal. The server is configured to allow SSH access only from a specific management subnet. You have obtained a limited shell on a different host within the same VLAN as the target server. From your limited shell, you can reach the target server on TCP port 22, but you do not have valid credentials. The Python authentication script uses a flat file database to store user credentials in the format 'username:hashed_password'. You suspect the script has a vulnerability that allows reading arbitrary files, such as the password file. Which of the following actions should you take to exploit this vulnerability?
A.Use Wireshark on the limited shell to capture SSH traffic and extract credentials
B.Perform a port knocking sequence to open SSH access to the target server
C.Craft an HTTP request to the web portal's authentication script with a path traversal payload to read the password file
D.Use Hydra to brute-force SSH credentials from the limited shell because it is on the same VLAN
AnswerC
The authentication script reads a flat-file credential store and lacks input sanitisation, so a path traversal payload in the HTTP request can escape the intended directory and return the password file contents, yielding credentials for the SSH-only server.
Why this answer
Option C is correct because the scenario describes a custom Python authentication script with a suspected arbitrary file read vulnerability, which is typically exploited by sending a crafted request (e.g., HTTP) containing a path traversal payload such as ../../etc/passwd or the flat-file credential database path to the vulnerable script endpoint. This directly leverages the identified flaw to retrieve the 'username:hashed_password' file rather than attacking SSH itself. Option A is wrong because SSH traffic is encrypted, so Wireshark cannot extract credentials from captured packets.
Option B is wrong because port knocking only manipulates firewall rules to permit SSH connections and does not bypass the lack of valid credentials. Option D is wrong because Hydra brute-forcing SSH is a credential-guessing attack, not exploitation of the arbitrary file read vulnerability, and the same-VLAN position does not make brute-forcing the intended or reliable path.
A penetration tester is presenting findings to a technical audience. Which THREE practices are MOST appropriate for this setting? (Select THREE.)
Select 3 answers
A.Use high-level business language only
B.Demonstrate the exploit steps
C.Show evidence like packet captures
D.Provide detailed remediation commands
E.Focus on strategic recommendations
AnswersB, C, D
Demonstrating the exploit steps is essential for a technical audience because it proves the vulnerability is exploitable and shows the exact commands, tools, and conditions required to achieve the compromise. This hands-on walkthrough allows the defenders to understand the full kill chain—from initial access to privilege escalation—and to map those steps to their own detection and prevention controls. Seeing the exploit in action also removes any ambiguity about whether the finding is a false positive, because the tester can show the actual impact in a controlled environment.
Why this answer
Technical audiences benefit from details about exploitation, technical steps, and evidence.
During a web application test, you discover a parameter that reflects user input in the response without proper encoding. You craft a payload that executes JavaScript in the victim's browser. This vulnerability is best classified as:
A.Stored XSS
B.Server-side request forgery (SSRF)
C.Reflected XSS
D.DOM-based XSS
AnswerC
Reflected XSS occurs when a user-controlled parameter is embedded into the HTTP response without proper encoding or sanitization, and the browser executes the injected script as part of the page. The script is triggered only when the victim clicks a crafted link, making the attack non-persistent. Since the parameter is directly reflected in the response and the server is echoing the input, this matches the classic signature of reflected XSS.
Why this answer
Reflected XSS occurs when user input is immediately reflected back in the response without proper sanitization, allowing script execution.
During a penetration test, the tester wants to capture network traffic for later analysis. Which tool is most appropriate for capturing packets and saving them to a pcap file?
A.Wireshark
B.Metasploit
C.Burp Suite
D.Nmap
AnswerA
Wireshark is a network protocol analyzer that captures live traffic by putting the network interface into promiscuous mode via libpcap (or Npcap on Windows) and decoding frames from the data-link layer through the application layer. It is the standard tool for raw packet capture because it passively observes all packets on a network segment, regardless of transport protocol (TCP/UDP) or application (HTTP, SSH, DNS, etc.). Its dissectors, filters, and follow-stream capability directly support analyzing captured traffic, making it the correct choice for this task.
Why this answer
Wireshark is a network protocol analyzer capable of capturing live traffic and saving it to pcap files.
A penetration tester wants to quickly identify the listening services on a target Linux server without performing a full port scan. The tester has obtained an unauthenticated shell as a low-privileged user. Which built-in command is most likely available on a modern Linux distribution to list all listening TCP sockets?
A.netstat -tlnp
B.ss -tlnp
C.lsof -i
D.ifconfig -a
AnswerB
ss is the standard socket statistics utility in iproute2 and is almost always preinstalled on current Linux systems. The flags -t (TCP), -l (listening), -n (numeric), and -p (process) together precisely list listening TCP ports with numeric addresses and, when permitted, the owning process/PID. Because ss reads kernel socket information via netlink, it returns live results instantly and is the modern replacement for netstat.
Why this answer
`ss -tlnp` is the modern replacement for `netstat` on Linux distributions that have deprecated `netstat` (e.g., RHEL 7+, Ubuntu 16.04+). It uses the `netlink` interface to read socket information directly from the kernel, making it faster and more reliable than parsing `/proc/net/tcp`. The flags `-t` (TCP), `-l` (listening), `-n` (numeric addresses/ports), and `-p` (show process) precisely list all listening TCP sockets without requiring root privileges for basic socket listing.
Exam trap
The trap here is that candidates assume `netstat` is universally available on Linux, but the PT0-002 exam tests awareness of modern tooling deprecation, where `ss` is the default built-in command on distributions like CentOS 7+ and Ubuntu 16.04+.
How to eliminate wrong answers
Option A is wrong because `netstat -tlnp` is not guaranteed to be available on modern Linux distributions; it is often deprecated or requires installation of the `net-tools` package, which is not installed by default on many minimal or containerized environments. Option C is wrong because `lsof -i` is not a built-in command on most Linux distributions; it must be installed separately via the `lsof` package, and it does not filter exclusively to listening TCP sockets without additional flags like `-sTCP:LISTEN`.
A 'no-fail' clause prohibits service outages. How should the tester address high-risk tests like SQL injection?
A.Remove all high-risk tests from the scope
B.Require a staging environment for testing
C.Include a clause that the tester is not liable
D.Proceed with testing and hope no outages occur
AnswerB
Requiring a staging environment is the only option that truly eliminates production risk while preserving test depth. A well-configured staging environment, ideally deployed with the same versions, patches, and security controls as production, allows the tester to execute even destructive or high-impact exploits without violating the no-fail clause. This approach maintains test validity because the attacker's interaction with the system is functionally identical, assuming network segmentation and data fidelity are properly addressed. The key is to validate the staging environment's parity before testing.
Why this answer
Testing in a staging environment prevents real outages. Option A is wrong because it removes important tests. Option C is wrong because it does not prevent outages.
A tester runs a Python script to perform a directory traversal attack. The output shows: 'Error: 403 Forbidden'. What is the most likely cause?
A.The script lacks authentication
B.The file does not exist
C.The request is malformed
D.The web server is patched against traversal attacks
AnswerD
A 403 Forbidden response indicates the server understood the request but refused it, typically because traversal sequences are filtered or the web server is patched against directory traversal. A missing file would return 404, and network failure would not yield an HTTP status.
Why this answer
The correct answer is D: the web server is patched against traversal attacks. A 403 Forbidden response means the server understood the request but is explicitly refusing to authorize it, which is exactly what happens when a web server (or WAF) detects path traversal sequences like ../ and blocks them as a security policy. If the file simply did not exist, the server would typically return 404 Not Found rather than 403, and a malformed request would usually produce 400 Bad Request.
Missing authentication would normally yield 401 Unauthorized (or a redirect to a login page), not 403, so option A does not fit either.
A client is planning a penetration test of their internal network but refuses to provide network diagrams or access to a staging environment. The tester is concerned about causing a denial of service (DoS) on critical systems. Which clause should be included in the rules of engagement to mitigate this risk?
A.A clause requiring the client to provide a complete list of in-scope IP addresses.
B.A waiver stating that any service disruption is the client's responsibility.
C.A rate-limiting clause that restricts scan speed and concurrent connections.
D.An exclusion list for systems that should not be tested.
AnswerC
A rate-limiting clause operationalizes a technical control by constraining packets per second, concurrent connections, or tool-specific throttling such as Nmap's `--max-rate`, `--max-parallelism`, or timing templates. This directly reduces the risk of resource exhaustion on stateful devices like firewalls, load balancers, and application servers that have limited session tables or timeouts. Because the tester often lacks full visibility into the client's device capacities, a conservative rate limit keeps scan traffic within a safe tolerance and prevents self-inflicted DoS, even when network details are unknown.
Why this answer
A rate-limiting clause directly addresses the risk of causing a denial of service (DoS) by controlling the speed and concurrency of the penetration test. By restricting scan rates (e.g., using tools like Nmap with `--max-rate` or `--min-hostgroup`) and limiting concurrent connections, the tester can prevent overwhelming critical systems, even without network diagrams or a staging environment. This clause mitigates the risk without requiring the client to provide additional information or shifting liability.
Exam trap
The trap here is that candidates may choose Option A (list of IPs) thinking it reduces risk by narrowing scope, but they overlook that aggressive scanning of even a small IP list can still cause DoS, while rate-limiting directly controls the traffic intensity.
How to eliminate wrong answers
Option A is wrong because requiring a complete list of in-scope IP addresses does not prevent DoS; it only clarifies the target scope, but the tester could still cause a DoS by scanning those IPs too aggressively. Option B is wrong because a waiver stating that any service disruption is the client's responsibility does not mitigate the risk; it merely transfers liability, which is unethical and may violate the testing agreement, and does not prevent the actual DoS from occurring.
A penetration tester is planning a red team exercise for a client. The client insists that the testing should not disrupt production systems and only target a replicated staging environment. However, the tester believes that testing the production environment is necessary for realistic adversary simulation. What is the MOST appropriate course of action?
A.Negotiate with the client to include some production systems, explaining the value, and document agreed scope
B.Proceed with testing the production environment despite the client's request to ensure realism
C.Cancel the engagement because the scope is too restrictive
D.Test the staging environment and then extrapolate results to production
AnswerA
The client's non-disruption constraint governs the engagement, so the tester cannot unilaterally target production. Requesting a scope amendment through formal negotiation preserves the client relationship and ensures any production testing is authorised and documented, satisfying the realistic-simulation goal without breaching agreed boundaries.
Why this answer
Option A is correct because the tester should negotiate and document any scope changes with the client, ensuring mutual agreement and authorization before including production systems. This respects the client's risk tolerance while addressing the tester's realism concerns through formal change control. Option B is wrong because testing production without explicit authorization is unethical and potentially illegal.
Option C is wrong because canceling is premature when the scope can be renegotiated. Option D is wrong because extrapolating staging results to production is unreliable and does not provide a valid assessment of the production environment.
A penetration tester has obtained a set of NTLM password hashes from a Windows domain controller. The tester wants to perform an offline cracking attack using GPU acceleration. Which tool is best suited for this purpose?
A.Hashcat
B.CrackMapExec
C.John the Ripper
D.Hydra
AnswerA
Hashcat performs offline hash cracking and supports GPU acceleration through OpenCL and CUDA, making it suited to NTLM hashes at high speed. It also handles NTLM format directly, unlike tools built for network capture or online authentication attacks.
Why this answer
Hashcat is purpose-built for offline password cracking and is optimized for GPU acceleration via OpenCL and CUDA, supporting NTLM hashes with modes like '-m 1000'. It scales across multiple GPUs and offers rule-based, mask, and combinator attacks, making it the standard tool for high-speed offline cracking.
Exam trap
PT0-003 often tests the distinction between online brute-force tools (Hydra, Medusa) and offline crackers (Hashcat, John) — candidates pick John for GPU work, but Hashcat is the GPU-optimized choice.
How to eliminate wrong answers
Option B is wrong because CrackMapExec is a post-exploitation and lateral-movement tool for SMB/WinRM, not a GPU-accelerated hash cracker. Option C is wrong because John the Ripper, while capable of offline cracking, is primarily CPU-optimized (Jumbo builds support OpenCL but with less GPU efficiency and fewer GPU-specific optimizations than Hashcat). Option D is wrong because Hydra is an online brute-force tool for network services (SSH, FTP, HTTP), not an offline hash cracker.
During the information gathering phase, a penetration tester uses Google dorks to find exposed documents on a target's website. Which Google dork would be most appropriate to find PDF files containing sensitive information?
A.filetype:pdf
B.inurl:admin
C.site:target.com password
D.intitle:index.of
AnswerA
filetype:pdf restricts Google's index to files with the PDF extension, which is ideal for information gathering because PDFs published on a target domain—such as user guides, annual reports, or internal memos—frequently contain metadata, employee names, and technology stack details that are not visible in ordinary HTML pages. During passive reconnaissance, this operator narrows results to a discrete document format that often escapes normal web crawling and may reveal sensitive or forgotten disclosures.
Why this answer
The filetype:pdf dork restricts results to PDF files. Other dorks target different file types or content.
Which TWO of the following are valid uses of the 'socat' tool during a penetration test? (Select TWO.)
Select 2 answers
A.Extracting files from an FTP server
B.Forwarding TCP ports to pivot through a compromised host
C.Performing a man-in-the-middle attack on HTTPS
D.Creating a reverse shell listener
E.Brute-forcing HTTP form authentication
AnswersB, D
socat relays raw TCP streams between two endpoints, so binding a listener on the compromised host and connecting back to the tester's machine tunnels traffic into the internal network — satisfying the pivot requirement without needing SSH or a full proxy tool.
Why this answer
Option B is correct because socat is a general-purpose relay tool that can forward TCP ports, e.g. 'socat TCP-LISTEN:8080,fork TCP:internal-host:80', which is a standard technique for pivoting through a compromised host to reach otherwise unreachable internal services. Option D is correct because socat can act as a listener for a reverse shell, e.g. 'socat TCP-LISTEN:4444 STDOUT' or 'socat TCP-LISTEN:4444 EXEC:/bin/bash', allowing a target to connect back and deliver an interactive shell. Option A is not a socat use case; FTP file extraction is done with an FTP client such as 'ftp', 'wget', or 'curl'.
Option C is not a socat use case; HTTPS man-in-the-middle requires TLS interception/proxy tooling such as mitmproxy, Burp Suite, or sslstrip, not socat's raw stream relaying. Option E is not a socat use case; HTTP form brute-forcing is performed with tools like Hydra, Burp Intruder, or ffuf.
A penetration tester is asked to assess whether an organization's employees can be tricked into revealing credentials. The client approves an assessment in which the tester registers a look-alike domain and sends emails directing staff to a fake login page. Which type of assessment is the tester conducting?
D.A physical intrusion test using tailgating techniques
AnswerC
Registering a look-alike domain and luring employees to a counterfeit login page to capture credentials is the defining pattern of a phishing simulation focused on credential harvesting. The objective is to measure human susceptibility and the effectiveness of awareness controls, which matches the approved scenario of tricking staff into revealing their login details.
Why this answer
The engagement uses a spoofed domain and a counterfeit login page delivered through email to induce employees to surrender credentials. That combination of social engineering and credential capture defines a phishing simulation. Its purpose is to quantify human risk and test the effectiveness of awareness training and email controls, which aligns exactly with the client's approved objective.
Exam trap
The trap here is overcomplicating the classification when the described activity of a spoofed domain plus fake login page is straightforwardly phishing, not a technical infrastructure or wireless assessment.
A penetration tester is writing the executive summary for the final report. The CEO needs to understand the overall risk level and the business impact of the findings. Which of the following should be included in the executive summary?
A.A high-level overview of the most critical vulnerabilities and their potential business impact.
B.Detailed exploit steps with screenshots.
C.A list of all CVSS scores without context.
D.The exact commands used during testing.
AnswerA
This matches the purpose of the executive summary: concise, business-focused information that allows leadership to make informed decisions without needing technical expertise.
Why this answer
The executive summary is intended for non-technical stakeholders like the CEO, who need to grasp the overall risk posture and business implications without technical jargon. Option A provides a high-level overview of critical vulnerabilities and their potential business impact, directly addressing the CEO's need to understand risk level and business impact, which aligns with the PT0-002 objective for effective reporting and communication.
Exam trap
The trap here is that candidates often confuse the executive summary with a technical summary, choosing options with detailed exploit steps or raw CVSS scores, forgetting that the CEO needs a business-focused, non-technical overview of risk and impact.
How to eliminate wrong answers
Option B is wrong because detailed exploit steps with screenshots are too technical and granular for an executive summary; they belong in the technical findings section of the report, not in a high-level overview for a CEO. Option C is wrong because listing all CVSS scores without context fails to convey the business impact or risk level; CVSS scores alone do not explain how vulnerabilities affect business operations, compliance, or strategic goals, which is essential for executive decision-making.
Refer to the exhibit. A penetration tester sends the request and receives the response shown. Which vulnerability is confirmed?
A.Server-side request forgery
B.Cross-site request forgery
C.SQL injection
D.Reflected cross-site scripting
AnswerD
Reflected cross-site scripting (XSS) is confirmed because the tester's input is echoed back unharmed within the HTML response, and the response contains the script execution—typically the payload becomes part of the DOM and runs in the victim's browser. Unlike stored XSS, this reflected variant requires the user to click a crafted link with the payload in a parameter, and the server does not filter or encode the value before embedding it in the HTML. This direct reflection and subsequent client-side execution are the definitive markers of reflected XSS, not of SSRF, CSRF, or SQLi.
Why this answer
The response includes the parameter value 'John' reflected directly in the HTML body without sanitization or encoding, and the request uses an HTTP GET method. This confirms a reflected cross-site scripting (XSS) vulnerability, as the tester can inject arbitrary JavaScript by modifying the 'name' parameter, which will execute in the victim's browser.
Exam trap
The trap here is that candidates may confuse reflected XSS with stored XSS or CSRF, but the key indicator is that the input appears only in the response to that specific request (reflected), not stored on the server, and the GET method with no state change rules out CSRF.
How to eliminate wrong answers
Option A is wrong because server-side request forgery (SSRF) involves the server making requests to internal resources based on user input, but the response shows the input reflected in the page, not a server-side request. Option B is wrong because cross-site request forgery (CSRF) requires a forged request that changes state (e.g., via POST), but the request shown is a simple GET with no state-changing action, and the response reflects input without requiring a session token. Option C is wrong because SQL injection would cause database errors or altered data in the response, but the response simply echoes the input 'John' without any SQL syntax or error messages.
During a penetration test, a tester wants to crack NTLM hashes captured from a Windows domain. Which hashcat mode should the tester use for NTLM hashes?
A.-m 13100
B.-m 1000
C.-m 22000
D.-m 0
AnswerB
Mode 1000 is the correct Hashcat mode for cracking NTLM hashes, which are the legacy Windows authentication digests stored in SAM and NTDS.dit. Each NTLM hash is specifically a single MD4 hash of the user's password in UTF-16LE encoding, a design that makes these hashes extremely fast to brute-force.
Why this answer
Hashcat mode -m 1000 is specifically designated for NTLM hashes, which are the format stored in Windows SAM and NTDS.dit files and transmitted during NTLM authentication. When a tester captures NTLM challenge-response traffic or extracts hashes from a domain controller, -m 1000 tells hashcat to parse the 32-hex-character NTLM hash correctly. This is the standard mode used in tools like Responder + hashcat workflows during internal Active Directory penetration tests.
Exam trap
PT0-003 often tests the distinction between NTLM (mode 1000), NetNTLMv2 (mode 5600), and Kerberoasting TGS-REP (mode 13100), since candidates frequently memorize one NTLM mode and apply it to every Windows hash scenario.
How to eliminate wrong answers
Option A is wrong because -m 13100 corresponds to Kerberos 5 TGS-REP etype 23 (Kerberoasting), not NTLM. Option C is wrong because -m 22000 is the combined WPA-PBKDF2-PMKID+EAPOL mode for Wi-Fi handshakes, unrelated to Windows authentication. Option D is wrong because -m 0 is raw MD5, which produces a different digest and will never match an NTLM hash.
Refer to the exhibit. A penetration tester performed an initial nmap scan and recorded the above output. The tester wants to include this in the report. What additional information should the tester add to make the finding more useful for remediation?
A.The version of services running on each port.
B.The list of open ports only.
C.The operating system of each host.
D.The result of a UDP scan for these ports.
AnswerA
The version of services running on each port is the critical missing piece because the penetration tester has already identified open ports, but without knowing the exact software release (e.g., Apache 2.4.49 vs. 2.4.50), they cannot map those services to specific CVEs and exploit modules. Banner grabbing or Nmap's -sV flag would supply this data, directly enabling vulnerability research and exploitation planning.
Why this answer
The correct option is A, the version of services running on each port, because knowing the exact service and version (e.g., Apache 2.4.49, OpenSSH 8.2p1) lets defenders map findings to known CVEs and apply targeted patches or upgrades. A raw nmap port list only shows TCP/UDP openness and cannot drive remediation without identifying the vulnerable software behind each port. Option B is insufficient because open ports alone do not reveal exploitable services.
Option C, the OS of each host, is useful context but does not identify the vulnerable application layer. Option D, a UDP scan, expands coverage but still does not provide the service-version detail needed for remediation.
Exam trap
The trap is assuming that OS detection or UDP scan results are more important, but remediation teams need service versions to map findings to known vulnerabilities.
A penetration tester is reviewing a Python script that automates a common network attack. The script imports the 'ftplib' and 'telnetlib' libraries. It reads a list of IP addresses from a file and, for each host, attempts to connect using a predefined username and password. If the connection succeeds, it logs the success. Which attack is the script most likely performing?
A.Brute-force attack against FTP and Telnet services
B.Vulnerability scanning for open ports
C.Password spraying attack against web applications
D.Service enumeration using banner grabbing
AnswerA
The script invokes FTP and Telnet client libraries (e.g., ftplib and telnetlib) to open connections and submit login credentials, iterating through password guesses for an identified account. Successful or failed login responses are monitored to determine valid credentials. This is a classic online brute-force attack: it relies on repeated authentication attempts against a live service rather than probing for vulnerabilities or passively observing banner data.
Why this answer
The script uses 'ftplib' and 'telnetlib' to attempt connections with a predefined username and password against multiple IP addresses. This is characteristic of a brute-force attack, where the attacker tries a single credential pair against many hosts to gain unauthorized access to FTP and Telnet services.
Exam trap
The trap here is confusing a brute-force attack (single credential against many hosts) with a password spraying attack (many usernames against a single host), leading candidates to incorrectly select option C when the script's logic clearly targets multiple hosts with one credential pair.
How to eliminate wrong answers
Option B is wrong because vulnerability scanning for open ports typically uses tools like Nmap or libraries like 'socket' to check for open ports, not 'ftplib' or 'telnetlib' for authenticated login attempts. Option C is wrong because password spraying attacks target web applications (often via HTTP/S) with many usernames and a few common passwords, whereas this script uses a single predefined username/password against multiple hosts, which is a classic brute-force pattern against network services, not web apps.
A client hires a penetration testing firm to assess a web application that integrates with a third-party API for payment processing. The client wants to include the API endpoint in the test scope. What should the penetration tester do FIRST to ensure the test is conducted ethically and legally?
A.Assume the client has already obtained permission from the API provider
B.Obtain written authorization from the third-party API provider
C.Rely on the client's statement that the API is within scope
D.Test only the client's application code and ignore the API
AnswerB
Written authorization from the third-party API provider is the only legally binding endorsement for testing infrastructure you do not own. It must be explicit about the scope, IP ranges, endpoints, methods, and time window to avoid exceeding authorized access. Without it, the tester risks criminal or civil liability regardless of the client's request, because the client lacks legal authority to deputize a tester on the provider's systems. A provider's documented permission also protects the client's future relationship and the tester's professional standing.
Why this answer
The penetration tester must obtain explicit written authorization from the third-party API provider before testing. Without this, testing the API endpoint could violate the Computer Fraud and Abuse Act (CFAA) or similar laws, as the tester would be accessing a system they do not own or have contractual permission to test. The client's scope inclusion does not grant legal access to the third-party's infrastructure.
Exam trap
The trap here is that candidates assume the client's scope definition automatically covers third-party systems, but the exam tests the legal and ethical requirement to obtain explicit permission from the actual owner of the target system.
How to eliminate wrong answers
Option A is wrong because assuming the client has obtained permission is a dangerous assumption that could lead to unauthorized access and legal liability; the tester must independently verify authorization. Option C is wrong because relying solely on the client's statement that the API is in scope ignores the fact that the client cannot grant permission for a third-party system; the tester needs direct authorization from the API provider.
Which tool is best for performing static analysis of Python code to find security vulnerabilities?
A.sqlmap
B.nmap
C.Bandit
D.Metasploit
AnswerC
Bandit parses Python source into an abstract syntax tree and flags insecure patterns such as eval, weak hashing and shell injection without executing the code, satisfying the static analysis requirement. Generic scanners lack this language-specific depth.
Why this answer
Bandit (option C) is the correct tool because it is a purpose-built static application security testing (SAST) tool that parses Python source code into an AST and flags insecure patterns such as use of eval, weak hashing like MD5, hardcoded passwords, and subprocess shell=True. It integrates directly into Python projects and CI pipelines (e.g., via pip install bandit and running bandit -r .), making it ideal for finding vulnerabilities without executing the code. sqlmap (A) is a dynamic SQL injection exploitation tool, nmap (B) is a network port and service scanner, and Metasploit (D) is an exploitation framework — all operate against running systems rather than analyzing Python source statically.
A penetration tester is testing a web application and wants to exploit an XXE vulnerability to read sensitive files. Which TWO payloads could be used?
Select 2 answers
A.<script>alert(1)</script>
B.<!DOCTYPE foo [<!ENTITY xxe SYSTEM 'http://169.254.169.254/latest/meta-data/'>]>
C.<!DOCTYPE foo [<!ENTITY xxe SYSTEM 'file:///etc/passwd'>]>
D.'; DROP TABLE users; --
E.../../etc/passwd
AnswersB, C
This payload defines an external entity named 'xxe' that points to the link-local cloud metadata service at 169.254.169.254. When the vulnerable XML parser resolves the entity, it performs a server-side request to that URL, allowing the tester to access instance metadata like IAM credentials. This is both an XXE and an SSRF, specifically aimed at cloud environments.
Why this answer
XXE can be used to read files via file:// or to perform SSRF to internal resources via http://, including cloud metadata.
A penetration tester is writing the executive summary of a report. Which of the following best describes the appropriate language and content for this section?
A.Detailed technical descriptions of each vulnerability with CVSS scores.
B.Business language, overall risk rating, key findings, and strategic recommendations.
C.A list of all tools used during the penetration test.
D.Step-by-step exploitation procedures for each finding.
AnswerB
This option is correct because an executive summary is engineered for decision-makers who need the outcome and strategic direction, not technical minutiae. Framing findings in business language with an overall risk rating and key findings allows leadership to grasp the organization's security posture quickly. Strategic recommendations tie the findings to actionable priorities, making the summary directly useful for approving budgets, prioritizing remediation, and setting security initiatives.
Why this answer
The executive summary is for non-technical stakeholders, so it should use business language and focus on overall risk, key findings, and strategic recommendations.
A penetration tester is performing active reconnaissance on a target network. The tester sends TCP SYN packets to a range of ports on a target host. Only a few ports respond with SYN-ACK packets. What does this indicate?
A.The host is protected by a firewall that drops all packets.
B.The ports that responded with SYN-ACK are open.
C.The host is running a stealthy IDS.
D.The network is using IPv6.
AnswerB
A SYN-ACK response is the second step in the standard TCP three-way handshake and is generated only by a service that is actively listening on that port. When the target replies with SYN-ACK, it affirms that the port is open and ready to accept a connection. This is the core evidence used in a SYN scan to distinguish open ports from closed or filtered ones.
Why this answer
The TCP three-way handshake begins with a SYN packet; a SYN-ACK response indicates that the target port received the SYN and is willing to establish a connection, meaning the port is open and listening. Only ports that respond with SYN-ACK are confirmed open, while others may be closed or filtered, but the presence of any SYN-ACK replies directly indicates open ports.
Exam trap
The trap here is confusing the absence of a response (filtered) with a firewall dropping all packets, but the presence of any SYN-ACK replies proves that not all packets are dropped, and the correct interpretation is that responding ports are open.
How to eliminate wrong answers
Option A is wrong because a firewall that drops all packets would cause no SYN-ACK responses at all, not just a few; the tester received SYN-ACK replies, so packets are not being universally dropped. Option C is wrong because a stealthy IDS (Intrusion Detection System) monitors traffic and may generate alerts but does not alter TCP handshake responses; the SYN-ACK replies are a network-layer behavior from the target host, not an IDS action.
Which section of a penetration test report contains detailed technical information such as the vulnerability description, evidence, affected systems, and remediation steps?
A.Technical findings section
B.Appendices
C.Executive summary
D.Methodology section
AnswerA
The technical findings section is the authoritative repository for every vulnerability, misconfiguration, or security weakness discovered during the engagement. Each finding is documented with a detailed narrative, proof-of-concept steps, affected assets, severity rating (e.g., CVSS base score), and remediation guidance, enabling technical stakeholders to replicate and fix the issue. This is precisely where the granular evidence and exploit details are recorded, making it the correct place for full technical descriptions.
Why this answer
The technical findings section provides in-depth details for technical teams to understand and remediate vulnerabilities.
A penetration tester is analyzing a Python script used for web application testing. The script imports the 'socket' module and uses it to create a raw socket. Which of the following is the most likely purpose of the script?
A.Creating a reverse shell payload
B.Sending crafted TCP packets to perform a SYN flood
C.Parsing HTTP responses for header injection
D.Automating user-agent rotation for web requests
AnswerB
Raw sockets expose the IP and TCP headers to the application, enabling the attacker to craft arbitrary TCP packets with custom flags such as SYN, spoof source IP addresses, and bypass the kernel's TCP state machine. In a SYN flood, the attacker repeatedly sends SYN packets but never completes the handshake, exhausting the target's SYN backlog queue and denying service to legitimate clients. This requires socket.socket(AF_INET, SOCK_RAW, IPPROTO_TCP) plus IP_HDRINCL, capabilities that normal stream sockets (SOCK_STREAM) cannot offer.
Why this answer
The 'socket' module in Python provides low-level networking interfaces, and creating a raw socket (using `socket.SOCK_RAW`) allows the script to craft and send custom packets at the IP layer. A SYN flood attack involves sending a high volume of TCP SYN packets with spoofed source IP addresses to exhaust a target's resources, which requires raw socket access to manipulate packet headers. Therefore, the most likely purpose of the script is sending crafted TCP packets to perform a SYN flood.
Exam trap
The trap here is that candidates may associate the 'socket' module only with standard TCP/UDP connections (like reverse shells) and overlook that raw sockets are specifically required for crafting custom packets in attacks like SYN floods, which operate at a lower network layer.
How to eliminate wrong answers
Option A is wrong because creating a reverse shell payload typically involves establishing a TCP connection (using `socket.SOCK_STREAM`) to a remote host, not raw sockets, and often uses higher-level libraries like `subprocess` or `pty` for shell interaction. Option C is wrong because parsing HTTP responses for header injection is an application-layer task that can be done with libraries like `requests` or `http.client`, and does not require raw socket manipulation at the network layer.
A penetration tester has captured network traffic and wants to analyze it using Wireshark. Which two actions can the tester perform to focus on specific types of communication? (Choose TWO.)
Select 2 answers
A.Use the Conversations window
B.Decrypt SSL/TLS traffic
C.Apply a display filter
D.Run a port scan
E.Generate a report with Nmap
AnswersA, C
The Conversations window aggregates captured traffic into endpoint pairs, showing byte counts, packet totals and duration per conversation. This satisfies the requirement to focus on specific communication types by revealing which hosts exchanged data and letting the tester drill into a chosen stream.
Why this answer
Option A is correct because Wireshark's Conversations window (Statistics > Conversations) groups captured packets by protocol and endpoint pairs (Ethernet, IPv4, IPv6, TCP, UDP), letting the tester quickly identify and isolate specific communication flows between hosts. Option C is correct because display filters (e.g., tcp.port == 443, ip.addr == 10.0.0.5, http) narrow the visible packet list to only the traffic matching specified protocol fields, which is the primary way to focus on particular types of communication. Option B is not appropriate here because decrypting SSL/TLS requires possessing the private key or session keys and is not a filtering/focusing action Wireshark performs on its own.
Option D is incorrect because a port scan is an active reconnaissance technique that generates new traffic rather than analyzing the already-captured traffic. Option E is incorrect because Nmap is a separate scanning tool and does not produce Wireshark analysis reports.
Exam trap
PT0-003 often tests the difference between passive analysis features in Wireshark (Conversations, display filters) and active techniques (port scanning, decryption setup), causing candidates to select actions that are not native Wireshark analysis steps.
A tester needs to perform an online brute-force attack against an SSH service. Which tool is most suitable?
A.Hashcat
B.Hydra
C.John the Ripper
D.Aircrack-ng
AnswerB
Hydra is a well-known network authentication cracker that performs online brute-force attacks by repeatedly submitting login credentials to a live service over the TCP/IP stack. For SSH specifically, Hydra invokes the SSH protocol handshake, supplies candidate username/password pairs, and inspects the server's authentication response to determine success. Its parallelism and modular protocol support (including the 'ssh' module) make it the appropriate choice for attacking a remote host where the password is guessed at the service itself.
Why this answer
Hydra is a fast online brute-force tool that supports many protocols including SSH.
During a penetration test, a tester captures NTLMv2 hashes by spoofing LLMNR and NBT-NS responses on the internal network. Which tool is most commonly used for this type of attack?
A.ntlmrelayx
B.Bettercap
C.Hashcat
D.Responder
AnswerD
Responder is the de facto tool for poisoning LLMNR, NBT-NS, and mDNS queries by answering them with the attacker's IP address, thereby causing clients to send SMB authentication attempts containing NTLMv2 hashes. It operates in the background, listens to broadcast name resolution requests, and tricks unsuspecting hosts into sending their credential material. Once captured, the hashes can be cracked offline with hashcat or relayed via ntlmrelayx, making Responder the correct initial-phase tool for this goal.
Why this answer
Responder is a widely used tool for LLMNR/NBT-NS/mDNS poisoning to capture NTLM hashes.
A penetration tester has compromised a Linux web server and wants to maintain persistent access by creating a new user account with a known password. The tester has root privileges. Which of the following commands will create a new user named 'support' with a home directory and a bash shell?
A.useradd -m -s /bin/bash support
B.passwd support --create --home /home/support --shell /bin/bash
C.adduser support --shell /bin/bash --home /home/support
D.usermod -aG support -d /home/support -s /bin/bash
AnswerA
The useradd command creates a new user. The -m flag ensures a home directory is created, and -s /bin/bash sets the login shell to bash. This matches the requirement to create a user with a home directory and bash shell. After running this, the tester would set a password with passwd support. This is the standard and correct way to add a user on most Linux distributions.
Why this answer
The useradd command with -m and -s creates a new user with a home directory and specified shell. This is the standard low-level utility available on most Linux distributions. After creating the account, the tester would set a password using passwd.
The other commands either modify existing users, use non-standard syntax, or are for password management only, making them unsuitable for creating a new persistent account.
Exam trap
The trap here is confusing user creation with user modification, or assuming that adduser and useradd are interchangeable across all Linux distributions.
A penetration tester is analyzing a PowerShell script used during an internal test. The script contains the following code block: ```powershell $cred = Get-Credential $session = New-PSSession -ComputerName 'Server01' -Credential $cred Invoke-Command -Session $session -ScriptBlock { Get-ChildItem C:\Secrets.txt } Remove-PSSession $session ``` What is the primary purpose of this script?
A.To perform a local privilege escalation using stored credentials
B.To achieve lateral movement and access a file on a remote server
C.To brute-force the password of the user account via 'Get-Credential'
D.To execute a script from the remote server using the ScriptBlock
AnswerB
The script uses Get-Credential to prompt for valid authentication, then Invoke-Command with a ScriptBlock that runs Get-ChildItem against C:\ on Server01. This is classic lateral movement: authenticating to a remote host over PowerShell Remoting (WinRM) and executing commands to access files. It moves the attacker's foothold from the current machine to Server01, rather than raising privileges on the local system.
Why this answer
The script uses Get-Credential to obtain user credentials, creates a remote PowerShell session (PSSession) to Server01 via New-PSSession, and then executes Get-ChildItem C:\Secrets.txt on that remote server using Invoke-Command. This is the classic pattern for lateral movement: authenticating to a remote host and accessing a file stored there, not performing any local privilege escalation or password brute-forcing.
Exam trap
The trap here is that candidates may confuse the use of Get-Credential with a brute-force attack, or misinterpret the remote file access as a local privilege escalation, when the script's clear intent is lateral movement via PowerShell remoting.
How to eliminate wrong answers
Option A is wrong because the script does not attempt any local privilege escalation; it uses supplied credentials to connect to a remote server, not to elevate privileges on the local machine. Option C is wrong because Get-Credential simply prompts for or retrieves stored credentials; it does not perform any brute-force attack against a user account's password.
A penetration tester is performing a vulnerability scan on a web server using Nikto. After the scan, the tester notices several findings related to outdated software versions and missing security headers. What should the tester do to validate the findings and reduce false positives?
A.Ignore findings related to missing headers as low priority
B.Manually verify a subset of the findings
C.Increase the scan intensity to get more details
D.Accept all findings as true since Nikto is a reliable tool
AnswerB
Manually verifying a subset of the findings is the correct next step after an automated scan, because tools like Nikto rely on signature matching and often produce false positives that don't reflect the actual application behavior. By using techniques such as inspecting raw HTTP responses, confirming server headers, or re-checking vulnerable files with curl, the tester can confirm whether a finding represents a genuine vulnerability, gauge the scanner's accuracy, and prioritize remediation based on validated evidence.
Why this answer
Manually verifying findings is the best practice to confirm if they are real vulnerabilities or false positives. Relying on scanner output alone is insufficient.
A penetration tester is analyzing a Bash script that contains the following line: 'for ip in $(cat ip_list.txt); do nc -zv $ip 22; done'. What is the primary purpose of this script?
A.To perform a banner grab on port 22 for each IP
B.To test if port 22 is open on each IP in the list
C.To establish a remote shell connection to each IP on port 22
D.To scan all 65535 ports on each IP in the list
AnswerB
The -z flag instructs netcat to scan for open ports by completing a TCP handshake and then closing the connection without transmitting payload data. If the handshake succeeds, the port is reported as open; otherwise it is reported as closed or filtered. Therefore the script checks whether each IP has port 22 open, which is a simple port availability test.
Why this answer
The script uses `nc -zv $ip 22` which performs a TCP connection test to port 22 on each IP from the list. The `-z` flag tells netcat to scan without sending any data, and `-v` enables verbose output, so it only reports whether the connection succeeded (port open) or failed (port closed or filtered). This is a classic port connectivity check, not a full banner grab or shell establishment.
Exam trap
The trap here is that candidates confuse `-z` (zero I/O scan) with banner grabbing or interactive shell access, assuming netcat always reads banners or spawns shells, when in fact `-z` explicitly prevents data transfer.
How to eliminate wrong answers
Option A is wrong because `nc -zv` does not perform a banner grab; banner grabbing requires `-v` alone or a timeout with data exchange (e.g., `echo | nc -w 3 $ip 22`), and `-z` explicitly avoids sending data. Option C is wrong because `nc -zv` only tests connectivity; establishing a remote shell would require `-e` (if compiled with GAPING_SECURITY_HOLE) or a reverse shell payload, which is absent. Option D is wrong because the script only targets port 22, not all 65535 ports; a full port scan would require a loop over port numbers or a tool like `nmap -p-`.
A penetration tester is analyzing a web application and wants to discover hidden API endpoints by brute-forcing common paths. Which tool is best suited for this task?
A.WPScan
B.Feroxbuster
C.theHarvester
D.Nikto
AnswerB
Feroxbuster is a Rust-based recursive content discovery tool designed specifically for brute-forcing web directories and files, including API endpoints. It uses dictionary-based wordlists, supports status-code and size filtering, and can recurse into discovered directories, making it effective for mapping undocumented API routes. Its speed and flexibility with custom headers, request methods, and extension fuzzing make it the correct tool for this task.
Why this answer
Feroxbuster is a fast, recursive content discovery tool that supports wordlist-based brute-forcing of directories, files, and API endpoints, with automatic recursion.
During a penetration test, a tester successfully exploits a web application and gains a foothold. The tester needs to pivot to an internal network segment that is not directly accessible. Which THREE tools can the tester use to create a SOCKS proxy or tunnel for pivoting?
Select 3 answers
A.Chisel
B.Netcat
C.Nmap
D.Ligolo-ng
E.SSH with -D flag
AnswersA, D, E
Chisel tunnels TCP over HTTP/WebSocket, creating a SOCKS proxy through the foothold host. This satisfies the requirement to reach the internal segment that is not directly accessible, and works where only HTTP egress is permitted.
Why this answer
Chisel (A) is correct because it is a fast TCP/UDP tunneling tool written in Go that can run a server on the compromised host and a client locally, creating a SOCKS5 proxy for pivoting into internal networks. Ligolo-ng (D) is correct because it provides a TUN-based reverse tunneling agent that establishes a SOCKS proxy and routes traffic to internal segments without needing a full VPN, making it ideal for pivoting during penetration tests. SSH with the -D flag (E) is correct because it opens a dynamic SOCKS proxy on a local port, allowing the tester to tunnel traffic through the compromised host if SSH access is available.
Netcat (B) is not marked correct because, while it can create basic TCP relays, it does not natively provide a SOCKS proxy or full tunneling capability for pivoting. Nmap (C) is not marked correct because it is a port scanner and does not include SOCKS proxy or tunneling features for pivoting.
Exam trap
The trap is assuming that Netcat can easily create a SOCKS proxy; it can only do simple port forwarding, not dynamic proxying.
During a source code review of a PHP application, the tester finds the following line: $query = "SELECT * FROM users WHERE username = '" . $_POST['username'] . "'"; Which vulnerability is present?
A.Cross-site scripting (XSS)
B.Path traversal
C.Command injection
D.SQL injection
AnswerD
SQL injection is the correct answer because the source code concatenates user-supplied input directly into a SQL query without using parameterized prepared statements or proper escaping. For example, a query built as "SELECT * FROM users WHERE username = '" . $_POST['user'] . "'" can be exploited with a payload like ' OR '1'='1 to bypass authentication or with UNION-based queries to extract sensitive data. This flaw allows an attacker to read, modify, or delete database contents, and in some cases execute stored procedures, depending on the database user's privileges. The remediation is to use prepared statements with bound parameters, which separate data from SQL code and prevent the attack.
Why this answer
Concatenating user input directly into an SQL query without sanitization leads to SQL injection.
A penetration tester is using Shodan to identify internet-facing devices associated with a target organization. Which of the following is Shodan's primary function in the context of passive reconnaissance?
A.Analyzing malware samples
B.Exploiting vulnerabilities in IoT devices
C.Searching for devices and services exposed to the internet
D.Performing live port scans on target IPs
AnswerC
Shodan continuously probes public IP ranges and collects response banners, including HTTP headers, SSH keys, and SNMP strings, which it indexes for instant querying. This enables a pen tester to identify specific device types, software versions, and open ports on a global scale, making it an invaluable reconnaissance tool prior to close-in testing. It allows searching by filter such as 'port:22', 'product:Apache', or 'country:US'.
Why this answer
Shodan is a search engine for internet-connected devices, providing information about services and banners. It does not perform active scans itself; it indexes data from active scanning.
During a web application test, the tester discovers a parameter that reflects user input in the response without proper encoding. The tester crafts a payload that executes JavaScript when another user views the page. Which type of XSS is this, and what is a primary risk?
A.Stored XSS; risk of data theft from database
B.Reflected XSS; risk of session hijacking
C.Blind XSS; risk of internal network scanning
D.DOM-based XSS; risk of client-side logic bypass
AnswerB
Reflected XSS occurs when user-supplied input is immediately echoed back in the server's response without proper sanitization or encoding. The attacker crafts a malicious URL containing script payload and lures the victim into clicking it; when the page loads, the script runs in the victim's session. This allows the attacker to steal session cookies via document.cookie and send them off-site, facilitating session hijacking. Because the payload is not persisted on the server, delivery depends on the victim accessing the crafted link.
Why this answer
Reflected XSS executes in the victim's browser when the malicious link is clicked, allowing session hijacking.
A penetration tester is preparing the executive summary for a report. Which of the following metrics would be MOST valuable to include for non-technical stakeholders to understand the overall security posture?
A.A list of all tools used during the penetration test
B.The total number of vulnerabilities discovered and their average CVSS score
C.The number of critical and high-risk findings along with the average time to exploit them
D.A detailed step-by-step exploitation walkthrough of one critical vulnerability
AnswerC
The number of critical and high-risk findings, paired with the average time to exploit them, directly conveys the organization's most urgent exposures in a business-relevant way. This metric tells executives how many vulnerabilities pose an immediate threat and how quickly an attacker could leverage them, which is more actionable than raw severity scores. It frames the summary around exposure and remediation urgency, allowing leadership to prioritize resources and track risk reduction.
Why this answer
Non-technical stakeholders (e.g., executives) need a high-level, risk-focused summary that communicates the severity and urgency of findings. The number of critical/high-risk findings directly indicates the most dangerous exposures, and the average time to exploit them conveys how quickly an attacker could compromise the environment. This metric translates technical risk into business impact, which is the core goal of an executive summary.
Exam trap
The trap here is that candidates often choose Option B (total vulnerabilities and average CVSS score) because CVSS is a familiar metric, but the exam tests the understanding that non-technical stakeholders need actionable, prioritized risk data (critical/high count and exploit time) rather than a statistically averaged score that can obscure severe findings.
How to eliminate wrong answers
Option A is wrong because listing all tools used (e.g., Nmap, Burp Suite, Metasploit) provides no insight into the security posture; it is operational detail irrelevant to non-technical stakeholders. Option B is wrong because the total number of vulnerabilities and their average CVSS score can be misleading—a low average CVSS score may hide many critical findings, and non-technical stakeholders need prioritization, not a diluted average. Option D is wrong because a detailed step-by-step exploitation walkthrough is too technical and granular for an executive summary; it belongs in the technical report, not in a high-level communication for non-technical readers.
A penetration tester needs to escalate privileges on a Linux target after gaining initial shell access. The /etc/passwd file shows a user 'jake' with UID 0. What does this indicate?
A.The user 'jake' is a normal user with UID misconfiguration
B.The user 'jake' is a member of the root group
C.The user 'jake' has the same privileges as root
D.There is a duplicate user 'jake' and 'root'
AnswerC
On Linux, the kernel's access-control checks equate any effective UID of 0 with the superuser, regardless of the username associated with that UID. The account name is just a human-readable label; when jake's UID is 0, the system treats every jake-run process as a root-owned process, granting full control over files, processes, and devices. This is precisely why a UID-0 account is said to have the same privileges as root.
Why this answer
In Linux, a UID (User ID) of 0 is reserved exclusively for the root superuser. When the /etc/passwd file shows a user 'jake' with UID 0, the system treats 'jake' with the same privileges as root, regardless of the username. This is because the kernel checks the UID, not the username, for permission decisions.
Therefore, 'jake' has full root-level access, making option C correct.
Exam trap
The trap here is that candidates confuse UID 0 with group membership (GID 0) or assume it's a misconfiguration, when in fact the UID field in /etc/passwd directly determines superuser status, not the username or group.
How to eliminate wrong answers
Option A is wrong because a UID of 0 is not a misconfiguration; it is the defined superuser identifier per POSIX standards, so 'jake' is not a normal user but has root privileges. Option B is wrong because group membership (e.g., being in the root group with GID 0) does not grant root privileges; only UID 0 confers superuser authority, and the /etc/passwd entry shows UID, not group membership. Option D is wrong because there is no duplicate user; 'jake' and 'root' are separate usernames, but both have UID 0, meaning they share the same superuser identity—this is not a duplicate account but a security concern.
A penetration tester uses Hashcat to crack NTLM hashes captured during a pass-the-hash attack. Which Hashcat mode should the tester use for NTLM hashes?
A.-m 0
B.-m 13100
C.-m 1000
D.-m 22000
AnswerC
Hashcat mode 1000 targets raw NTLM hashes, matching the captured pass-the-hash material exactly. Unlike mode 5500, which expects NetNTLMv1 challenge-response pairs, mode 1000 parses the bare 16-byte NT hash directly, so the tester avoids format errors and cracks the captured credentials efficiently.
Why this answer
Hashcat mode -m 1000 is for NTLM hashes. Other modes correspond to different hash types.
A medium-sized e-commerce company, CyberMart, has contracted your penetration testing firm to assess their security posture. The company operates from three physical locations: headquarters, a data center, and a remote warehouse. They have a flat internal network but separate VLANs for production, development, and guest Wi-Fi. CyberMart's CISO insists that the test must be conducted without causing any disruption to the production environment, especially the payment processing system. The test should simulate an external attacker targeting the public-facing web servers and an internal attacker who has gained initial access to the guest network. The CISO also requests that all testing be done during off-peak hours to minimize impact. You are preparing the rules of engagement. Which of the following is the most appropriate action to include in the ROE to satisfy the client's requirements while maintaining a realistic test scenario?
A.Include all VLANs but with explicit permission to conduct denial-of-service tests only during off-peak hours.
B.Allow testing on all VLANs except the production VLAN containing payment processing, with a rule to immediately stop if any degradation is observed.
C.Focus exclusively on the external web servers and exclude internal network testing due to the risk of disruption.
D.Restrict testing to only the guest network and external IPs, excluding all production VLANs.
AnswerB
This scope correctly balances comprehensive internal testing with business continuity: it includes all network segments to simulate both external and internal attackers, but excludes the payment processing VLAN to protect cardholder data and PCI DSS-scoped systems. The immediate-stop rule serves as a safety kill switch, ensuring any sign of degradation halts testing before impact. This covers internal segmentation testing across VLANs, which is essential for a medium e-commerce company, while respecting the CISO's risk tolerance.
Why this answer
Option B is correct because it satisfies the CISO's requirement of avoiding disruption to the production payment system by explicitly excluding the production VLAN from testing, while still allowing realistic external and internal (guest network) attack simulation and adding a stop condition if degradation occurs. This balances test coverage with the no-disruption constraint during off-peak hours. Option A is wrong because permitting denial-of-service tests, even off-peak, risks disrupting production and violates the no-disruption requirement.
Option C is wrong because excluding all internal testing fails to simulate the internal attacker on the guest network. Option D is wrong because restricting testing to only the guest network and external IPs unnecessarily excludes other non-production VLANs such as development, reducing test scope without a stated need.
A penetration testing firm is hired to perform a test on a multinational company that has offices in Europe and North America. The client wants to test all systems including those in the European office, which is subject to GDPR. Which of the following is the MOST important legal consideration to include in the rules of engagement?
A.A limitation of liability clause
B.Data protection and privacy clauses addressing handling of personal data
C.A non-disclosure agreement
D.A schedule of testing hours
AnswerB
GDPR governs processing of EU residents' personal data, so the rules of engagement must include data protection and privacy clauses specifying lawful handling, storage, and disposal of any personal data encountered during testing across European systems.
Why this answer
The engagement involves testing systems in a European office subject to GDPR, which imposes strict requirements on the processing and protection of personal data. The rules of engagement must include data protection and privacy clauses to define how the penetration tester will handle any personal data encountered during the test, ensuring compliance with GDPR Article 5 (lawfulness, fairness, transparency) and Article 32 (security of processing). Without these clauses, the tester could inadvertently violate GDPR by collecting or storing personal data without a lawful basis, exposing both the client and the testing firm to significant fines.
Exam trap
The trap here is that candidates often choose a non-disclosure agreement (NDA) as the most important legal consideration, confusing general confidentiality with the specific data protection obligations required by GDPR, which are distinct and more prescriptive.
How to eliminate wrong answers
Option A is wrong because a limitation of liability clause is a standard contractual provision that caps financial damages, but it does not address the specific GDPR compliance requirements for handling personal data during the test. Option C is wrong because a non-disclosure agreement (NDA) protects confidentiality of the test results and client information, but it does not define how personal data must be processed, stored, or deleted under GDPR. Option D is wrong because a schedule of testing hours is an operational consideration that avoids business disruption, but it has no direct relevance to GDPR's data protection obligations.
A penetration testing firm is hired to assess a healthcare organization's network. The client has strict regulatory requirements (HIPAA) and wants to ensure that all patient data is protected during testing. Which scoping document should specify the data handling procedures and the destruction of any collected sensitive information?
A.Rules of Engagement
B.Testing Methodology
C.Data Protection Addendum
D.Scope of Work
AnswerC
A Data Protection Addendum (DPA) is a legally binding contract that mandates how sensitive information such as Protected Health Information (PHI) must be guarded, processed, and ultimately destroyed in accordance with regulations like HIPAA/HITECH. In a healthcare penetration test, the DPA requires specific technical safeguards—e.g., AES-256 encryption for data at rest and in transit, role-based access limits, and NIST SP 800-88-compliant wiping before return or disposal. This precision and enforceability make the DPA the correct instrument for defining data handling, unlike broader scoping or authorization documents.
Why this answer
A Data Protection Addendum (DPA) or equivalent data handling agreement is the appropriate document to define how sensitive data will be handled, stored, and destroyed. The Rules of Engagement cover authorization and constraints, but specific data protection clauses are often in a separate addendum or included in the contract. The Methodology and Scope of Work do not typically detail data destruction procedures.
During an internal penetration test, a tester captures a NetNTLMv2 hash via an SMB relay attack. The target network does not enforce SMB signing. What is the most effective next step to gain access to a remote server?
A.Crack the hash offline using a dictionary attack.
B.Relay the captured hash to authenticate to another server.
C.Perform a pass-the-hash attack using the captured hash.
D.Use the hash to perform an LLMNR poisoning attack.
AnswerB
This is the correct approach because the captured NetNTLMv2 challenge-response can be forwarded to a target server as part of an SMB authentication sequence. When SMB signing is not enforced, the target server cannot detect that the relayed response is not associated with the original client, so it accepts the authentication as if it came from the legitimate user. The tester can then gain access to file shares, services, or even remote code execution depending on the privileges of the captured user account, and this bypasses the need to crack the password.
Why this answer
Since SMB signing is not enforced, the tester can relay the captured NetNTLMv2 hash directly to another server without needing to crack it. This works because the relay attack forwards the authentication challenge-response to a target server, allowing the tester to authenticate as the victim user without knowing the plaintext password. This is the most effective step because it provides immediate access without the time and resource cost of offline cracking.
Exam trap
The trap here is that candidates often confuse NetNTLMv2 with NTLM hashes, assuming pass-the-hash works with any hash type, when in fact pass-the-hash requires the raw NTLM hash (from LSASS or a dump) and not the challenge-response variant captured via relay.
How to eliminate wrong answers
Option A is wrong because offline cracking of NetNTLMv2 hashes is computationally expensive and time-consuming, especially for complex passwords, making it less effective than relaying when SMB signing is disabled. Option C is wrong because pass-the-hash requires an NTLM hash (not NetNTLMv2), which is a different format; NetNTLMv2 is a challenge-response hash that cannot be directly used in a pass-the-hash attack. Option D is wrong because LLMNR poisoning is a technique to capture hashes, not a method to use an already-captured hash for authentication; the hash has already been obtained, so poisoning is unnecessary.
A penetration tester wants to identify the web server software and version used by a target organization without sending any packets to the target's infrastructure. Which of the following techniques is most effective for this purpose?
A.Use Shodan to search for the target's IP address or domain and review the gathered banners.
B.Perform a DNS zone transfer to obtain internal server information.
C.Use netcat to connect to port 80 and read the HTTP banner.
D.Use nmap -sV with a delayed scan to avoid detection.
AnswerA
Shodan is a search engine for internet-connected devices that continuously crawls the web and stores service banners, including HTTP Server headers, from historical scans. Querying Shodan by the target's IP address or domain is a purely passive reconnaissance technique because it retrieves already-collected data without sending a single packet to the target. This makes it ideal for stealthy initial fingerprinting, as it reveals the web server software and version without any risk of detection or direct interaction.
Why this answer
Shodan is a search engine that continuously scans the internet and stores service banners from various ports. By querying the target's IP address or domain, the penetration tester can retrieve previously collected HTTP headers and other service banners without sending any packets to the target, thus achieving passive reconnaissance.
Exam trap
The trap here is that candidates often confuse passive reconnaissance with low-and-slow active scanning, mistakenly believing that techniques like delayed nmap scans or netcat connections are passive when they still generate detectable network traffic.
How to eliminate wrong answers
Option B is wrong because a DNS zone transfer is an active query that sends a request to the target's DNS server, and it typically reveals internal hostnames, not web server software or version banners. Option C is wrong because using netcat to connect to port 80 sends a TCP SYN packet to the target, which is an active technique that generates network traffic and can be detected. Option D is wrong because nmap -sV performs active service version detection by sending probes to open ports, even with a delayed scan, it still transmits packets to the target infrastructure.
A penetration tester needs to perform Kerberoasting against an Active Directory domain. Which step is required after requesting TGS tickets?
A.Crack the TGS hashes offline
B.Perform SMB relay
C.Request TGT ticket
D.Extract NTLM hashes from LSASS
AnswerA
Kerberoasting correctly involves requesting service ticket (TGS) hashes for Service Principal Names (SPNs), then transferring them to an offline workstation. Because the TGS is encrypted with the target service account's NTLM hash, an attacker can run hashcat or John the Ripper against it to recover the plaintext password, especially if the password is weak or reused. The offline cracking step is what makes the attack low-risk and highly successful.
Why this answer
After requesting TGS tickets for service accounts, the tester must crack the hashes offline using a tool like Hashcat.
During pre-engagement, a client insists that the penetration testers sign a non-disclosure agreement (NDA). However, the client refuses to provide a 'get-out-of-jail' letter. What risk does this pose to the penetration testers?
A.Increased risk of data breach
B.Higher likelihood of false positives
C.Inability to use certain tools
D.Potential legal liability if the client or third parties perceive the testing as malicious
AnswerD
The primary purpose of the pre-engagement authorization letter is to protect the penetration tester from allegations of unauthorized access. Without it, a client or a third party monitoring network traffic—such as an ISP or law enforcement—could reasonably perceive the scanning and exploitation activity as malicious and pursue criminal or civil charges. The letter documents informed consent, defines the exact scope, and names the responsible parties, thereby converting what might look like an attack into an authorized security assessment.
Why this answer
Without a 'get-out-of-jail' letter (also known as a authorization letter or testing waiver), the penetration testers have no documented legal authorization to perform the agreed-upon attacks. If the client or a third party (e.g., an ISP, law enforcement, or a security monitoring service) detects the test traffic and interprets it as malicious, the testers could face criminal charges or civil lawsuits for unauthorized access, even if the NDA is in place. The NDA only protects confidentiality, not the legality of the actions.
Exam trap
The trap here is that candidates often confuse the NDA (which protects confidentiality) with the get-out-of-jail letter (which provides legal authorization), mistakenly thinking the NDA alone is sufficient to cover liability, when in fact the NDA does not grant permission to perform intrusive testing.
How to eliminate wrong answers
Option A is wrong because the risk of a data breach is not directly increased by the absence of a get-out-of-jail letter; a data breach risk is more related to the scope of testing or data handling practices, not the legal authorization document. Option B is wrong because false positives are a technical issue related to tool configuration, signature tuning, or environmental noise, not a legal or authorization document. Option C is wrong because the inability to use certain tools is typically caused by client restrictions, network controls, or tool licensing, not by the lack of a get-out-of-jail letter; the letter does not affect tool functionality.
Which TWO of the following are typical deliverables of a penetration test?
Select 2 answers
A.Technical findings and remediation guidance
B.User credentials for all accounts
C.Source code of the tested application
D.Video recording of the testing process
E.Executive summary
AnswersA, E
This is the core of a penetration test report, providing detailed descriptions of discovered vulnerabilities, including affected systems, exploitation steps, and impact. It must also include actionable remediation steps, such as patching, configuration changes, or code fixes, so the client can address risks. Without this, the report would not meet the engagement's objective of enabling the client to reduce risk.
Why this answer
Standard deliverables include an executive summary for management and technical findings for remediation.
Which Nmap scan type sends SYN packets to determine open ports without completing the TCP three-way handshake?
A.-sU
B.-sS
C.-sT
D.-sN
AnswerB
The -sS option, Nmap's default SYN scan, transmits a raw TCP packet with only the SYN flag set to each port; an open port replies with a SYN/ACK, a closed port with an RST, and a filtered port drops the packet or returns an ICMP unreachable. Because Nmap aborts the handshake immediately upon receiving SYN/ACK, it determines TCP port state without ever completing a full connection, making it fast and relatively unobtrusive.
Why this answer
The SYN scan (-sS) sends a SYN packet and if a SYN/ACK is received, the port is considered open; it does not complete the handshake, making it stealthier than a full connect scan.
After a penetration test, the client's development team requests that the report include specific, actionable remediation steps for each vulnerability. Where in the report should this information be placed?
A.In the executive summary to emphasize the need for fixing vulnerabilities
B.In the appendix as a separate remediation checklist
C.Within the technical report section, under each vulnerability finding
D.In a separate document attached to the report to avoid cluttering the main report
AnswerC
This is the correct placement because professional penetration test reporting conventions, such as those in PTES and OWASP guidance, require remediation instructions to be embedded within each finding. Each vulnerability finding should include a clear remediation subsection—often with specific code examples, configuration changes, or patches—immediately following the evidence and impact. This inline approach ensures the development team sees the problem and the fix together, reducing ambiguity and preventing loss of context, and it also makes the report a single, self-contained reference for the entire remediation process.
Why this answer
The correct placement for specific, actionable remediation steps is within the technical report section under each vulnerability finding. This aligns with industry best practices (e.g., PTES, OWASP) where each finding includes a description, risk rating, and a dedicated remediation subsection, ensuring developers have immediate context and clear steps without cross-referencing other sections.
Exam trap
The trap here is that candidates may think the executive summary or appendix is sufficient for remediation details, but the exam specifically tests that actionable steps must be embedded within each finding to ensure clear ownership and immediate applicability for the development team.
How to eliminate wrong answers
Option A is wrong because the executive summary is a high-level overview for management, not a place for detailed technical remediation steps; it should focus on business risk and strategic recommendations, not per-vulnerability fixes. Option B is wrong because placing remediation steps only in an appendix separates them from the vulnerability context, forcing developers to flip back and forth, which reduces clarity and increases the risk of misapplication. Option D is wrong because a separate document can be lost or overlooked, and the PT0-002 exam expects remediation to be integrated into the main report for traceability and completeness, not hidden in an attachment.
A penetration tester has exploited a web application and found that the server has an outbound firewall that restricts all outbound traffic except for DNS queries (UDP 53). The tester has a reverse shell payload that connects back on TCP 443. Which technique can the tester use to exfiltrate data or establish a channel?
A.Use netcat to send data over TCP 53
B.Use an SSH tunnel over UDP 53
C.Use dnscat2 or other DNS tunneling tool
D.Use a bind shell listening on TCP 443 internally
AnswerC
DNS tunneling tools like dnscat2, iodine, and dns2tcp encode arbitrary data inside DNS queries and responses, which are allowed outbound on UDP/53 by the firewall. The tester controls an authoritative DNS server for a domain, so every DNS query from the compromised host to that domain carries a payload and the responses carry instructions, establishing a command-and-control channel that blends in with normal DNS traffic.
Why this answer
DNS tunneling tools like dnscat2 encode data within DNS queries and responses, allowing the tester to bypass outbound firewall restrictions that only permit UDP 53 traffic. Since the reverse shell payload uses TCP 443, which is blocked, DNS tunneling provides an alternative covert channel that encapsulates the communication within legitimate DNS lookups, effectively exfiltrating data or establishing a command-and-control channel over the allowed protocol.
Exam trap
The trap here is that candidates may assume any protocol can be tunneled over UDP 53 simply by changing the port, but DNS tunneling requires specialized tools that encapsulate data within DNS message formats, not just raw TCP or SSH over UDP.
How to eliminate wrong answers
Option A is wrong because netcat cannot send data over TCP 53 when the outbound firewall only allows UDP 53; TCP 53 is a different protocol and would be blocked. Option B is wrong because SSH tunnels operate over TCP, not UDP, and UDP 53 is used for DNS queries, not SSH; attempting an SSH tunnel over UDP 53 would fail as SSH does not natively support UDP transport. Option D is wrong because a bind shell listening on TCP 443 internally requires the tester to initiate an inbound connection to that port, but the outbound firewall does not restrict inbound traffic; however, the tester is behind the firewall and needs an outbound channel, and a bind shell does not solve the outbound restriction problem.
Which of the following is the MOST appropriate format for delivering the final penetration test report to the client?
A.HTML file hosted on the tester's website.
B.Plain text file with no formatting.
C.Microsoft Word document with tracked changes.
D.PDF with password protection and digital signature.
AnswerD
Password protection plus a digital signature satisfies the client-delivery constraint: encryption guards report confidentiality in transit, while the signature lets the client verify authenticity and detect tampering. A plain PDF or unprotected archive fails both requirements, so this format is the most appropriate for the final penetration test report.
Why this answer
Option D is correct because a PDF with password protection and digital signature ensures the penetration test report is delivered confidentially, tamper-evident, and verifiably authentic to the client. Password protection restricts access to authorized recipients, while the digital signature provides integrity and non-repudiation, which are critical for sensitive security findings. In contrast, an HTML file hosted on the tester's website (A) exposes the report publicly and lacks access control, a plain text file (B) offers no confidentiality or authenticity protections, and a Word document with tracked changes (C) may inadvertently reveal internal edits, comments, or metadata and is easily altered.
A penetration tester gains access to a web application that uses a MongoDB backend. The tester discovers that the search functionality directly interpolates user input into a NoSQL query without sanitization. Which technique should the tester use to extract data from the database?
A.SQL injection
B.NoSQL injection
C.LDAP injection
D.Command injection
AnswerB
NoSQL injection is the correct technique because MongoDB directly interpolates user-supplied input into its query objects. By submitting input such as username[$ne]=null or password[$gt]=, an attacker can inject MongoDB query operators that alter the intended logic, often bypassing authentication or extracting data. More dangerous is the $where operator, which can execute arbitrary JavaScript expressions, making injection possible without SQL syntax.
Why this answer
The application uses MongoDB, a NoSQL database, and the search functionality directly interpolates user input into a NoSQL query without sanitization. This allows the tester to inject MongoDB operators (e.g., $ne, $regex, $gt) to manipulate the query logic and extract data, which is the core of NoSQL injection. Unlike SQL injection, this technique targets MongoDB's query syntax, such as JSON-based operators, to bypass authentication or retrieve records.
Exam trap
The trap here is that candidates see 'injection' and default to SQL injection (Option A) without recognizing that the backend is MongoDB, a NoSQL database, which requires a different injection technique using JSON operators rather than SQL syntax.
How to eliminate wrong answers
Option A is wrong because SQL injection targets relational databases using SQL syntax (e.g., SELECT, UNION), but MongoDB uses a document-based query language with JSON-like operators, not SQL. Option C is wrong because LDAP injection exploits Lightweight Directory Access Protocol queries (e.g., LDAP filters) to manipulate directory services, not NoSQL databases like MongoDB. Option D is wrong because command injection targets operating system commands (e.g., shell commands) via system calls, not database queries, and the vulnerability here is in the database query layer, not the OS.
A penetration tester has gained a low-privileged command shell on a Windows 10 system. The tester suspects there is a vulnerable service with an unquoted service path that can be exploited for privilege escalation. Which command should the tester use to identify all services with this vulnerability?
C.sc query type= all state= all | findstr "SERVICE_NAME"
D.net start
AnswerB
This command recursively enumerates every subkey under the Services registry key and requests the ImagePath value for each service/driver, producing the full command line or binary path that Windows will execute. Because a standard, low-privileged user can read HKLM\SYSTEM (CurrentControlSet), this is a practical enumeration step. An attacker can then identify entries whose paths contain spaces and lack surrounding quotes, setting up an unquoted-service-path privilege escalation attack by placing a crafted executable in a writable directory earlier in the path.
Why this answer
The `reg query` command with the `/s` switch recursively searches the registry key `HKLM\SYSTEM\CurrentControlSet\Services` for the `ImagePath` value of each service. An unquoted service path vulnerability occurs when the `ImagePath` contains spaces and is not enclosed in quotes, allowing an attacker to execute arbitrary code by placing a malicious executable in a path that Windows interprets as a command with arguments. This command directly retrieves the raw path strings from the registry, making it the most reliable method to identify unquoted paths.
Exam trap
The trap here is that candidates assume `sc query` or `Get-Service` will reveal the raw unquoted path, but these commands may normalize or omit quotation marks, whereas the registry `ImagePath` value stores the exact string used by the service, including missing quotes.
How to eliminate wrong answers
Option A is wrong because `Get-Service | Format-List Name,PathName` only displays the service name and its binary path name as reported by the Service Control Manager, but it does not show the raw registry `ImagePath` value; PowerShell may automatically quote or normalize the path, hiding the unquoted vulnerability. Option C is wrong because `sc query type= all state= all | findstr "SERVICE_NAME"` only lists service names, not their binary paths, so it cannot reveal unquoted service paths. Option D is wrong because `net start` only lists currently running services by display name, not their executable paths, and provides no information about the path format or quotation.
A penetration tester is writing a report that includes a vulnerability with a CVSS score of 9.8. The client's security team argues that the score should be lower due to compensating controls. How should the tester respond in the report?
A.Report the base CVSS score and include a note about the compensating controls
B.Report both scores and let the client decide
C.Remove the CVSS score entirely to avoid disagreement
D.Adjust the CVSS score lower to reflect the client's compensating controls
AnswerA
CVSS base scores assume no environmental mitigations, so the tester must report 9.8 unchanged and add a note describing the compensating controls. Recalculating or lowering the base score would misrepresent the vulnerability; the note preserves accuracy while acknowledging the client's controls.
Why this answer
The correct response is A: report the base CVSS score and include a note about the compensating controls. CVSS base scores are intrinsic to the vulnerability itself and do not account for environmental or compensating controls, so the 9.8 base score should remain unchanged in the report. Compensating controls are instead reflected through the CVSS temporal and environmental metric groups (e.g., Environmental score via modified impact and exploitability metrics), which can be documented separately.
Option B is wrong because the tester should not simply defer the scoring decision to the client, and CVSS scores are not adjusted by client preference. Option C is incorrect because omitting the CVSS score removes valuable, standardized severity information. Option D is incorrect because arbitrarily lowering the base score misrepresents the vulnerability and violates CVSS methodology.
A penetration tester wants to perform a pass-the-hash attack against a Windows system. Which tool can be used to authenticate using the NTLM hash instead of a password?
A.Responder
B.Hashcat
C.CrackMapExec
D.John the Ripper
AnswerC
CrackMapExec accepts an NTLM hash via its -H flag and passes it directly during SMB or WinRM authentication, so no plaintext password is needed. This exploits NTLM's design, where the hash itself is the credential, enabling lateral movement across Windows hosts.
Why this answer
CrackMapExec supports pass-the-hash authentication with NTLM hashes.
Which TWO of the following are key components that should be included in an executive summary of a penetration test report? (Select TWO.)
Select 2 answers
A.Disclaimer of liability for the testing company.
B.Detailed step-by-step exploitation procedures.
C.Overall risk score or security posture rating.
D.High-level summary of findings and risk ratings.
E.Full command-line output from penetration testing tools.
AnswersC, D
Executives need a single comparable measure of exposure rather than technical detail. An overall risk score or posture rating aggregates individual findings into one business-readable metric, letting leadership judge severity and prioritise remediation budget without interpreting CVSS vectors or exploit mechanics.
Why this answer
Option C is correct because an executive summary should convey the overall risk score or security posture rating, giving leadership a single, quantified indicator of how well the organization's security controls performed during the engagement. Option D is correct because the executive summary must present a high-level summary of findings along with their risk ratings, translating technical issues into business-relevant impact without diving into exploit mechanics. Options A, B, and E do not belong: a liability disclaimer is typically placed in the report's introductory or legal section rather than the executive summary, detailed step-by-step exploitation procedures belong in the technical findings/attack narrative section for remediation teams, and full command-line tool output is raw technical evidence that belongs in appendices, not a management-facing summary.
During a post-exploitation phase, a tester needs to establish persistence on a Windows target. Which THREE methods are commonly used for persistence on Windows?
Select 3 answers
A.Pass-the-hash
B.Cron jobs
C.Registry Run keys
D.WMI subscriptions
E.Scheduled tasks
AnswersC, D, E
Registry Run keys are a classic Windows persistence mechanism where an attacker adds a value to a run key such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run or HKLM\Software\Microsoft\Windows\CurrentVersion\Run. Any executable referenced by these keys launches automatically when the designated user logs on, requiring minimal privileges for the HKCU variant and no need for a service or scheduled trigger. This is a straightforward, widely used persistence method that directly survives a reboot and re-authentication of the compromised user account.
Why this answer
Scheduled tasks, registry Run keys, and WMI subscriptions are common persistence mechanisms. Pass-the-hash is lateral movement, and cron jobs are Linux-specific.
You are conducting passive reconnaissance on a target organization. Which of the following are examples of passive reconnaissance techniques? (Select TWO.)
Select 2 answers
A.Querying certificate transparency logs
B.DNS zone transfer
C.Scanning ports with Nmap
D.Sending phishing emails
E.Performing a WHOIS lookup
AnswersA, E
Querying certificate transparency logs is passive because these logs are publicly auditable ledgers of all issued TLS/SSL certificates, maintained by independent log operators like Google and Cloudflare. An attacker can query them via services such as crt.sh or the ct.googleapis.com API to discover subdomains and certificate details without ever sending a packet to the target's own infrastructure, thereby leaving no trace in the target's logs.
Why this answer
Passive reconnaissance involves collecting information without directly interacting with the target's systems. WHOIS lookups and certificate transparency logs are passive. DNS zone transfer and port scanning are active.
A penetration tester wants to quickly identify which of the top 100 common ports are open on a target system, while minimizing network traffic and scan time. Which Nmap command is most appropriate?
A.nmap -p- target
B.nmap -T5 -F target
C.nmap -sn target
D.nmap -sV target
AnswerB
The -T5 flag applies the 'insane' timing template, which aggressively reduces timeouts and increases probe parallelism to maximize scanning speed. The -F flag limits the scan to the top 100 most commonly open ports (per Nmap's services database), ensuring that only high-probability targets are probed. Together, these options provide the fastest method to discover which of the top ports are listening, which matches the penetration tester's objective.
Why this answer
The `-T5` flag sets the fastest timing template (insane), which reduces delays and speeds up the scan, while the `-F` flag (fast mode) limits scanning to only the top 100 most common ports as defined in Nmap's nmap-services file. This combination minimizes network traffic and scan time while quickly identifying open ports among the top 100, aligning with the goal of efficiency.
Exam trap
The trap here is that candidates often confuse `-F` with `-p-` or assume `-T5` alone is sufficient, failing to recognize that `-F` is the specific flag that restricts the scan to the top 100 ports, while `-T5` only accelerates the timing without changing the port list.
How to eliminate wrong answers
Option A is wrong because `-p-` scans all 65535 TCP ports, which generates maximum traffic and takes the longest time, directly contradicting the requirement to minimize network traffic and scan time. Option C is wrong because `-sn` performs a ping sweep (host discovery) using ICMP echo requests, TCP SYN to port 443, TCP ACK to port 80, and ICMP timestamp requests; it does not scan any ports for open/closed status, so it cannot identify open ports. Option D is wrong because `-sV` enables version detection, which probes open ports to determine service versions, but it does not limit the port range to the top 100; without `-F`, it scans the default 1000 ports, and the version probing adds significant traffic and time, making it inefficient for the stated goal.
A penetration tester is analyzing a compiled Linux binary that appears to validate license keys. The tester wants to understand the validation logic without access to source code. The binary is stripped of symbols and uses anti-debugging techniques. Which approach is most effective for discovering the validation algorithm?
A.Perform a differential analysis by running the binary with valid and invalid keys and comparing system calls.
B.Run strings on the binary to extract all printable characters.
C.Use a debugger like GDB with anti-anti-debugging plugins to trace execution and set breakpoints on validation routines.
D.Use a hex editor to search for patterns in the binary that resemble known cryptographic constants.
AnswerC
A debugger such as GDB allows the tester to step through execution, inspect registers and memory, and set breakpoints on functions that handle input. With plugins like peda or gef, anti-debugging techniques can be bypassed or neutralized. This dynamic analysis reveals the actual validation logic as it runs, including comparisons and branching. It is the most effective way to understand a stripped binary's algorithm when static analysis is hindered.
Why this answer
Dynamic analysis with a debugger allows the tester to observe the binary's execution in real time, bypass anti-debugging protections, and identify the exact instructions that validate the license key. By setting breakpoints on input-handling functions and tracing comparisons, the tester can reconstruct the algorithm. Static methods like strings or hex pattern searches are insufficient for complex, stripped binaries.
Exam trap
The trap here is relying on static analysis alone when the binary is stripped and protected, missing the need for dynamic debugging to understand runtime behavior.
A penetration tester is analyzing a Python script that uses the Impacket library to perform an SMB relay attack. The script is failing to capture NTLM hashes from target machines. Which part of the script is MOST likely misconfigured?
A.The target IP address
B.The listener IP address
C.The SMB version negotiation
D.The authentication method (NTLMv1 vs NTLMv2)
AnswerB
The listener IP defines the interface on which the malicious SMB server awaits the victim's connection and must be set to an address owned by the attacker and routable from the victim's network. If it is misconfigured, the victim's SMB client cannot establish the TCP session, so no NTLM handshake occurs and no hash is ever transmitted. Correctly setting this IP is therefore the primary requirement for hash capture.
Why this answer
In an SMB relay attack using Impacket, the listener IP address must be set to the attacker's IP address where the relayed authentication is received. If the listener IP is misconfigured (e.g., set to the target's IP or left as localhost), the relay server will not receive the forwarded NTLM hashes, causing the capture to fail. This is a common configuration error when using Impacket's 'smbrelayx' or similar scripts.
Exam trap
The trap here is that candidates often confuse the listener IP with the target IP, assuming the script needs the target's IP to capture hashes, when in fact the listener IP must be the attacker's own IP to receive the relayed authentication.
How to eliminate wrong answers
Option A is wrong because the target IP address is typically the machine being attacked or relayed to, and while it must be correct for the relay to reach the intended service, an incorrect target IP would cause the relay to fail at a different stage (e.g., connection refused), not specifically prevent hash capture. Option C is wrong because SMB version negotiation is handled automatically by Impacket's SMB connection; misconfiguring it might cause a connection failure but would not prevent hash capture if the relay is set up correctly. Option D is wrong because the authentication method (NTLMv1 vs NTLMv2) affects the hash format captured, but both can be relayed; the script's failure to capture hashes is not due to the NTLM version but rather the relay listener not receiving the authentication attempt.
A penetration tester identifies a Linux binary with the SUID bit set. Which command can find all SUID binaries on a Linux system?
A.ps aux
B.ls -la
C.chmod u+s
D.find / -perm /4000
AnswerD
find / -perm /4000 recursively traverses the entire filesystem and matches files whose mode contains the SUID bit, expressed by the octal value 4000. The leading slash in -perm /4000 tells find to match when any of the specified permission bits are set, which is exactly the SUID bit (the normal execute bits don't need to be checked). This finds every SUID binary, including non-root-owned ones, making it the standard way to enumerate SUID files for privilege escalation.
Why this answer
The find command with -perm /4000 lists files with SUID set.
A small business hires a penetration tester to assess the security of their network. The owner is concerned about employee data breaches and wants to ensure compliance with industry regulations. Which of the following is the MOST critical document to establish before the test begins?
A.Vulnerability scan report
B.Rules of engagement
C.Penetration test report
D.Risk assessment matrix
AnswerB
The Rules of Engagement (RoE) is the core pre-engagement document that formalizes the client's authorization, defining the exact scope of target systems, allowed testing windows, permissible exploitation techniques, and emergency contact procedures. It serves as a legal safeguard for both the tester and the client, ensuring that all activity is explicitly sanctioned and that any deviation from the agreed terms is documented. Without a signed RoE, any penetration testing activity would be considered unauthorized access, exposing both parties to legal liability.
Why this answer
The Rules of Engagement (RoE) is the most critical document because it defines the legal boundaries, scope, and authorization for the penetration test. Without a signed RoE, the tester has no legal protection and the test could be considered unauthorized access, violating laws like the Computer Fraud and Abuse Act (CFAA). It also specifies key constraints such as testing times, target IP ranges, and prohibited actions, ensuring compliance with industry regulations like PCI DSS or HIPAA.
Exam trap
The trap here is that candidates confuse the Rules of Engagement with the penetration test report or vulnerability scan report, thinking that technical outputs are more important than the legal and scoping document that authorizes the entire test.
How to eliminate wrong answers
Option A is wrong because a vulnerability scan report is an output of the testing process, not a pre-engagement document; it would be generated after scanning begins. Option C is wrong because a penetration test report is the final deliverable summarizing findings, not a document that establishes authorization or scope before testing. Option D is wrong because a risk assessment matrix is a tool used during planning to prioritize risks, but it does not provide the legal and operational boundaries required to start the test; it is secondary to the RoE.
A client asks why a medium-severity finding should be remediated before a high-severity finding. The medium finding is internet-facing and actively exploited; the high finding is isolated in a lab subnet. What is the best explanation?
A.Prioritization should account for exposure and active exploitation, not only the scanner severity.
B.Medium findings must always be fixed before high findings.
C.The high finding should be ignored permanently because it is in a lab.
D.Only CVSS base score matters for remediation order.
AnswerA
Scanner severity is only a baseline; the actual remediation priority must combine it with exposure and real-world threat data. For example, a medium-severity flaw on an internet-facing asset that is actively exploited in the wild requires faster action than a high-severity issue isolated in a lab with no reachable attack path. Thus, prioritization is a risk-based decision that weighs likelihood and impact, not just the static CVSS label.
Why this answer
Risk-based prioritization must consider real-world factors like internet exposure and active exploitation, not just the CVSS base score. A medium-severity finding that is internet-facing and actively exploited poses a higher immediate risk to the organization than a high-severity finding isolated in a lab subnet, which has no external attack surface. This aligns with industry frameworks like CVSS environmental metrics and the FIRST CVSS v3.1 specification, which allow adjusting severity based on attack vector, complexity, and environmental context.
Exam trap
The trap here is that candidates often assume CVSS base severity alone dictates remediation order, ignoring the critical role of environmental and temporal metrics, as well as business context like exposure and active exploitation.
How to eliminate wrong answers
Option B is wrong because it incorrectly states that medium findings must always be fixed before high findings, which ignores the context of exposure and active exploitation; remediation priority should be based on risk, not a fixed severity hierarchy. Option C is wrong because it suggests the high finding should be ignored permanently, but even isolated lab findings can be leveraged in lateral movement or indicate systemic weaknesses, and should be remediated based on risk, not ignored. Option D is wrong because it claims only CVSS base score matters, but CVSS provides environmental and temporal metrics that adjust severity for factors like exposure and active exploitation, which are critical for accurate prioritization.
A penetration tester wants to quickly identify known vulnerabilities in a web application without triggering many alarms. Which tool should the tester use?
A.SQLmap
B.Metasploit
C.OpenVAS
D.Nikto
AnswerD
Nikto is a lightweight, open-source web server scanner specifically built to quickly identify known vulnerabilities, outdated server software, and insecure files. It performs fast, signature-based checks without requiring a database setup or extensive configuration, making it ideal for a preliminary assessment. Its speed and focus on web server misconfigurations align directly with the need to 'quickly identify known vulnerabilities.'
Why this answer
Nikto is a web server scanner that performs checks for known vulnerabilities with minimal noise. SQLmap is for SQL injection only, OpenVAS is a comprehensive vulnerability scanner that may be noisy, and Metasploit is for exploitation.
A penetration testing firm is hired to assess the security of a small business's web application. The client has explicitly stated that they do not want any testing that could cause a denial of service. Which section of the rules of engagement should specify this restriction?
A.Scope
B.Limitations
C.Scheduling
D.Legal
AnswerB
Correct. The limitations section, often called constraints or rules of engagement, explicitly documents activities that are excluded from the authorized testing, such as no denial-of-service (DoS) testing, no social engineering, or no physical intrusion. This is a contractual safeguard that clearly defines prohibited actions to prevent accidental service disruption or legal overreach. Without a clear limitations section, the tester might assume an action is permitted simply because it is not prohibited elsewhere, leading to unintended consequences.
Why this answer
The restriction against denial of service testing is a limitation on the types of activities permitted during the engagement. In the rules of engagement (RoE), the Limitations section explicitly defines what is prohibited, such as specific attack vectors, tools, or impacts like DoS, to ensure testing stays within agreed boundaries. This is distinct from the Scope, which defines what is tested (e.g., IP ranges, URLs), not what is forbidden.
Exam trap
The trap here is that candidates confuse 'Scope' (what is tested) with 'Limitations' (how it is tested), leading them to incorrectly select Scope because they think the restriction defines the boundaries of the engagement, when in fact Limitations specifies the prohibited actions within those boundaries.
How to eliminate wrong answers
Option A is wrong because Scope defines the targets (e.g., specific IP addresses, subdomains, or web application URLs) and systems in scope, not the restrictions on testing methods or impacts. Option C is wrong because Scheduling covers the timing and duration of testing (e.g., start/end dates, maintenance windows), not prohibitions on specific attack types. Option D is wrong because Legal covers contractual and regulatory compliance (e.g., data handling, liability, jurisdiction), not the operational constraints like prohibiting DoS attacks.
Which TWO of the following are types of penetration testing based on the level of knowledge provided to the tester? (Select TWO.)
Select 2 answers
A.Social engineering
B.Network penetration test
C.Red team
D.Black box
E.White box
AnswersD, E
Black box is a type of penetration testing where the tester has no prior knowledge of the target's internal structure, architecture, or credentials. This approach simulates an external, unprivileged attacker and forces testers to rely entirely on reconnaissance and vulnerability discovery from the outside. It is one of the three knowledge-based categories, alongside white box and gray box.
Why this answer
Black box and white box are two common types based on knowledge level; grey box is the third.
A penetration tester is performing a vulnerability scan on a web server that uses HTTPS. The tester wants to identify the server's SSL/TLS configuration weaknesses without overwhelming the server. Which Nmap command is most appropriate?
This command is correct because -sV triggers version detection, and --script ssl-enum-ciphers explicitly invokes the Nmap script that enumerates SSL/TLS ciphers, protocols, and known weaknesses such as BEAST, POODLE, or weak key exchange. The script sends probe connections to the HTTPS service on port 443 and reports the strength of each cipher, which is precisely what a vulnerability scan of a web service requires. Restricting the scan to -p 443 focuses it on the SSL/TLS endpoint without extraneous traffic.
Why this answer
The `ssl-enum-ciphers` NSE script enumerates all supported SSL/TLS ciphers and protocols on the target, providing a detailed assessment of cryptographic weaknesses (e.g., weak ciphers, outdated TLS versions). The `-sV` flag enables version detection, and `-p 443` targets the HTTPS port, while the script itself is designed to be lightweight and not overwhelm the server, making it ideal for a non-intrusive vulnerability scan.
Exam trap
The trap here is that candidates often choose `-sC` (default scripts) thinking it covers SSL checks, but it does not run the dedicated cipher enumeration script, which is the only option that specifically and safely identifies SSL/TLS weaknesses without aggressive scanning.
How to eliminate wrong answers
Option B is wrong because `-A` enables aggressive scanning (OS detection, version detection, script scanning, traceroute) and `-T4` sets a faster timing template, which can overwhelm the server and is not focused solely on SSL/TLS configuration weaknesses. Option C is wrong because `-sU` performs a UDP scan, but HTTPS (port 443) uses TCP, so this command would not properly assess the SSL/TLS configuration. Option D is wrong because `-sC` runs default NSE scripts, which may include some SSL-related checks but does not specifically enumerate ciphers and protocols in a targeted, non-overwhelming manner like `ssl-enum-ciphers` does.
A tester wants to exploit a Windows service running with SYSTEM privileges that has an unquoted service path containing spaces. Which technique should be used to escalate privileges?
A.AlwaysInstallElevated
B.Token impersonation
C.Unquoted service path exploitation
D.DLL hijacking
AnswerC
An unquoted service path occurs when the ImagePath registry value for a service contains spaces but is not enclosed in quotes. When Windows starts the service, it attempts to locate the executable by splitting the path at each space and trying the resulting filenames, moving from left to right. If an attacker has write access to a directory earlier in that sequence, they can drop a malicious executable (e.g., C:\Program.exe or C:\Program Files\Vendor.exe) that Windows will execute with the service's SYSTEM privileges. This is the correct exploitation method because it directly abuses the service's own path configuration to achieve code execution as SYSTEM.
Why this answer
An unquoted service path allows placing an executable with the same name as a folder in the path, which Windows will execute with SYSTEM privileges.
An organization has a web application that stores session tokens in a cookie named 'auth_token'. The token is a base64-encoded JSON object containing the username, role, and expiration timestamp. Which attack is most likely to succeed if the encryption is not used?
A.Session replay
B.Cross-site request forgery
C.Cookie tampering
D.Session hijacking
AnswerC
Cookie tampering is the correct classification: the tester captures the session cookie, decodes it (e.g., Base64 or URL-decoded JSON), changes a value such as a role, privilege level, or account identifier, and re-encodes it before sending it back to the server. This attack is successful only when the server fails to encrypt or cryptographically sign the cookie, allowing a client-side alteration to be accepted. The result is privilege escalation through direct manipulation of the session token itself, distinguishing it from attacks that leave the token unchanged.
Why this answer
The session token is a base64-encoded JSON object without encryption, making it trivially easy to decode, modify (e.g., change the role to 'admin' or extend the expiration timestamp), re-encode, and send back to the server. This is a classic cookie tampering attack, as the server trusts the client-provided data without integrity verification.
Exam trap
CompTIA often tests the distinction between encoding and encryption, and the trap here is that candidates confuse base64 encoding with actual security, assuming it protects the token's integrity or confidentiality.
How to eliminate wrong answers
Option A is wrong because session replay involves capturing and reusing a valid token unchanged, but the question focuses on the lack of encryption enabling modification, not reuse. Option B is wrong because cross-site request forgery (CSRF) exploits the user's authenticated session to perform unintended actions, not the ability to tamper with the cookie content itself. Option D is wrong because session hijacking typically involves stealing a valid session token (e.g., via XSS or network sniffing) and using it as-is, whereas the core vulnerability here is the ability to forge or alter the token's contents due to lack of encryption.