Courseiva

CompTIA PenTest+ (PT0-003) (PT0-003) — Questions 301–375

777 questions total · 11pages · All types, answers revealed

Page 4

Page 5 of 11

Page 6
301
MCQmedium

During a web application test, a tester discovers that the application uses JSON Web Tokens (JWT) for authentication. The tester intercepts a JWT and changes the algorithm header to 'none' with an empty signature. Which attack is being attempted?

A.SQL injection
B.SSRF
C.JWT alg:none attack
D.IDOR
AnswerC

A JWT alg:none attack works by changing the token's `alg` header field to `none`, signaling that the token is unsecured. Vulnerable JWT libraries that accept this value will skip signature verification entirely, allowing an attacker to forge tokens with arbitrary claims, such as elevating privileges, without knowing the secret key. This directly exploits the server's failure to enforce strict algorithm allowlists.

Why this answer

Setting algorithm to 'none' is a JWT algorithm confusion attack where the server accepts unsigned tokens.

302
MCQeasy

Which type of penetration test provides the tester with full knowledge of the target environment, including network diagrams, source code, and administrative credentials?

A.Grey box
B.White box
C.Black box
D.Red team
AnswerB

White box testing grants the assessor complete visibility — network diagrams, source code and administrative credentials — so effort focuses on finding flaws rather than reconnaissance. This contrasts with black box, where no internal knowledge is supplied, and grey box, which provides partial detail.

Why this answer

A white box penetration test gives the tester full knowledge of the target, including network diagrams, source code, and administrative credentials. This full-disclosure approach lets the tester focus on finding vulnerabilities efficiently rather than spending time on reconnaissance.

Exam trap

PT0-003 often tests the distinction between knowledge levels (black/grey/white box) and engagement types (red team, purple team), so candidates who equate 'red team' with 'full knowledge' pick the wrong answer.

How to eliminate wrong answers

Option A is wrong because a grey box test provides partial knowledge — typically some documentation or limited credentials — but not full source code and admin access. Option C is wrong because a black box test provides zero prior knowledge, simulating an external attacker who must perform reconnaissance from scratch. Option D is wrong because red team is a goal-oriented adversarial simulation (often testing detection and response), not a knowledge-disclosure category; a red team engagement can be black, grey, or white box.

303
MCQeasy

After completing a penetration test, a tester needs to dispose of test data securely. Which of the following methods is most appropriate for this purpose?

A.Delete the data using standard operating system commands
B.Use a secure data destruction tool that overwrites data multiple times
C.Format the storage device once
D.Keep the data encrypted for future reference
AnswerB

Overwriting data multiple times with a secure destruction tool renders the original bit patterns unrecoverable, satisfying the requirement to dispose of test data securely. Unlike degaussing, which only works on magnetic media, overwriting suits SSDs and HDDs alike, and it preserves the drive for reuse where the stem does not mandate physical destruction.

Why this answer

Option B is correct because a secure data destruction tool that overwrites the data multiple times (e.g., using multi-pass overwrite algorithms like DoD 5220.22-M or Gutmann) renders the original test data unrecoverable, which is the goal of secure disposal after a penetration test. Standard deletion (A) only removes file system references, leaving data recoverable with forensic tools, and a single format (C) likewise does not guarantee the underlying blocks are wiped. Keeping the data encrypted (D) is not disposal at all and retains sensitive test data, creating ongoing confidentiality and compliance risk.

304
MCQmedium

A penetration tester has gained a low-privileged shell on a Linux server. During enumeration, the tester discovers a binary with the SUID bit set that belongs to root and is known to have a buffer overflow vulnerability. What is the MOST effective next step to escalate privileges?

A.Use the binary to execute a command that changes the root password
B.Develop and execute a buffer overflow exploit against the binary to gain a root shell
C.Modify the binary's permissions to allow execution by any user
D.Use sudo to run the binary as root
AnswerB

The correct approach is to exploit a vulnerability in the SUID binary itself. Because the binary's effective UID is root, a successful buffer overflow exploit that hijacks control flow can execute shellcode with privileges equivalent to root. The shellcode should typically set real/effective/saved UID to 0 and then spawn a shell, yielding an interactive root session without altering any system state or requiring credentials.

Why this answer

The SUID binary owned by root and vulnerable to a buffer overflow allows a low-privileged user to execute it with root privileges. Developing and executing a buffer overflow exploit against the binary will overwrite the return address or function pointer to spawn a root shell, directly escalating privileges to root. This is the most effective method because it leverages the existing vulnerability to gain full control without relying on other misconfigurations.

Exam trap

The trap here is that candidates may confuse SUID with sudo, assuming sudo can be used to run the binary as root, but SUID binaries execute with the owner's privileges automatically without requiring sudoers configuration.

How to eliminate wrong answers

Option A is wrong because changing the root password requires root privileges or the ability to write to /etc/shadow, which the low-privileged shell does not have; the SUID binary does not inherently provide a mechanism to execute arbitrary commands like passwd. Option C is wrong because modifying the binary's permissions (e.g., chmod) is not possible from a low-privileged shell, as the binary is owned by root and the SUID bit is already set; the goal is to exploit the binary, not change its permissions. Option D is wrong because sudo requires the user to be in the sudoers file with appropriate permissions, which a low-privileged user typically does not have; the SUID binary is executed directly, not via sudo.

305
MCQhard

The scope allows only Nmap, but it is ineffective against heavy packet filtering. The tester wants to use an alternate tool. What should the tester do?

A.Request approval from the client to use a different tool
B.Use the alternate tool and note it in the report
C.Abort the scan and report that the network is not testable
D.Use Nmap with different parameters
AnswerA

The scope explicitly permits only Nmap, so introducing another tool breaches the agreed rules of engagement. Requesting client approval first keeps the tester within authorisation; using an unapproved tool, however effective against packet filtering, would be unauthorised testing.

Why this answer

The correct answer is A: Request approval from the client to use a different tool. Since the scope explicitly limits testing to Nmap, using any other tool would violate the agreed rules of engagement, so the tester must obtain written client authorization before substituting a different tool. Options B and D are wrong because they either bypass the scope restriction or continue with the ineffective Nmap approach without addressing the filtering problem.

Option C is also incorrect because the engagement is not necessarily untestable—an approved alternate tool could still accomplish the objectives.

306
MCQmedium

A penetration tester is performing a password attack on a Windows domain and has captured NTLM hashes. Which tool can be used to perform a pass-the-hash attack to gain remote code execution on a target system?

A.Hashcat
B.Responder
C.pth-winexe
D.John the Ripper
AnswerC

pth-winexe is part of the pass-the-hash toolkit that implements the Windows SMB client and authentication stack, allowing you to authenticate to a remote Windows host using only the NTLM hash as the credential. It substitutes the password in the NTLM/SPNEGO exchange with the hash, establishes an authenticated session, and executes a specified command without ever knowing the plaintext password. This directly demonstrates pass-the-hash: the hash itself serves as the proof of knowledge to impersonate the user.

Why this answer

pth-winexe is a tool specifically designed for pass-the-hash attacks to execute commands on remote Windows systems.

307
MCQmedium

A penetration tester is performing reconnaissance against a target organization and must passively collect email addresses, employee names, and document metadata without directly interacting with the target's servers. Which tool or technique is best suited for this requirement?

A.Nmap with the default script set against the target's mail server
B.theHarvester querying public search engines and data sources
C.Metasploit auxiliary scanner modules against the target's domain controller
D.Nikto scanning the target's public web server
AnswerB

theHarvester is built for OSINT gathering and can query search engines, certificate transparency logs, and other public sources without sending traffic to the target. It returns emails, hostnames, and employee names, matching the passive requirement. It does not need credentials or direct target access, so it avoids alerting the target while still producing actionable reconnaissance data.

Why this answer

theHarvester is designed for passive OSINT collection and can query search engines, certificate transparency logs, and public data sources without sending traffic to the target. It aggregates emails, hostnames, and employee names. The other tools listed are active scanners that interact directly with target systems and do not focus on gathering personnel or email data from public sources.

Exam trap

The trap here is assuming any reconnaissance tool satisfies a passive requirement, when tools like Nmap, Nikto, and Metasploit modules actively touch the target and may be logged.

308
MCQeasy

A penetration tester is conducting passive reconnaissance on a target organization. Which technique can be used to discover subdomains of the target's domain without sending any packets to the target's network?

A.Performing a DNS brute-force attack against the target's domain
B.Using the 'site:' operator in a search engine query
C.Sending ICMP echo requests to potential subdomain IP addresses
D.Querying WHOIS databases for domain registration information
AnswerB

Using the 'site:' search engine operator is a purely passive technique because you are querying a third-party search index rather than touching the target's infrastructure. Search engines crawl and recursively list indexed subdomains under 'example.com', revealing them without generating any traffic to the target. This makes it an ideal OSINT method for subdomain discovery.

Why this answer

Using the 'site:' operator in a search engine query (e.g., 'site:example.com') retrieves indexed subdomains from the search engine's cache without sending any packets to the target's network. This is a purely passive technique that leverages publicly available data, aligning with the definition of passive reconnaissance.

Exam trap

The trap here is that candidates often confuse passive reconnaissance with techniques that appear passive but still send packets (like DNS brute-force or ICMP echo requests), or they incorrectly assume WHOIS queries can enumerate subdomains when WHOIS only provides registration metadata.

How to eliminate wrong answers

Option A is wrong because a DNS brute-force attack sends DNS queries to the target's authoritative name servers, which are packets that reach the target's network infrastructure, making it an active technique. Option C is wrong because sending ICMP echo requests (ping) to potential subdomain IP addresses directly transmits packets to the target's network, which is active reconnaissance and violates the 'no packets' constraint. Option D is wrong because querying WHOIS databases retrieves registration information (e.g., registrar, contacts) but does not discover subdomains; WHOIS records typically contain domain ownership details, not subdomain listings.

309
MCQeasy

A tester is reviewing code and sees a function that concatenates user input directly into a SQL query. Which vulnerability is most likely present?

A.Buffer overflow
B.SQL injection
C.Command injection
D.Cross-site scripting (XSS)
AnswerB

SQL injection occurs when untrusted input is concatenated directly into a SQL statement without proper parameterization or escaping, allowing an attacker to alter the query's logic. For example, injecting ' OR '1'='1 modifies a WHERE clause to bypass authentication or retrieve all rows. Since the code review shows concatenation into a database query, this is the correct vulnerability: the attacker can manipulate the SQL command structure.

Why this answer

The correct answer is B, SQL injection, because concatenating untrusted user input directly into a SQL query allows an attacker to alter the query's structure and execute arbitrary SQL statements. This is the classic pattern for SQL injection, where input such as ' OR '1'='1 or UNION SELECT can bypass authentication or extract data. Buffer overflow (A) involves writing beyond allocated memory bounds and is not indicated by string concatenation into a query.

Command injection (C) occurs when input is passed to an OS shell or command interpreter, not a SQL query. Cross-site scripting (D) involves injecting script into web pages rendered to other users, which is a different context from SQL query construction.

310
MCQeasy

A penetration tester wants to perform a slow and stealthy port scan to avoid intrusion detection systems. Which Nmap option should be used?

A.-O
B.-A
C.-T0
D.-sV
AnswerC

-T0 is Nmap's Paranoid timing template, which intentionally introduces extreme delays between successive probes, typically waiting 300 seconds (5 minutes) before sending the next packet. This serialized, near-constant pacing is designed to stay well below the threshold that most real-time intrusion detection systems use for alerting, making it the slowest and most stealthy timing mode available. Its entire purpose is to minimize network footprint and avoid rate-based detection, directly fulfilling the penetration tester's requirement for a slow and stealthy scan, so it is the correct answer.

Why this answer

The -T0 option sets the timing template to Paranoid, which is extremely slow and avoids IDS detection. -O is for OS detection, -sV for version detection, and -A for aggressive scan.

311
MCQhard

A tester uses OllyDbg to step through a binary. The EAX register contains 0x00401234. What does this represent?

A.A system call number
B.A file handle
C.A memory address
D.An ASCII character
AnswerC

EAX holds 0x00401234, a 32-bit value in the typical executable image range, so it is a virtual memory address rather than an instruction opcode or immediate operand. Debuggers display register contents this way when tracing code.

Why this answer

Option C (A memory address) is correct because the value 0x00401234 is a 32-bit hexadecimal value in the typical range of a process's virtual address space, and EAX commonly holds pointers or addresses during execution in OllyDbg. In a Windows PE binary, addresses around 0x00400000 are the default image base, so 0x00401234 likely points into the executable's code or data section. It is not a system call number, which would be a small integer index (e.g., in Linux EAX holds syscall numbers like 1 for write), nor a file handle, which is typically a small opaque integer returned by CreateFile/OpenFile, nor an ASCII character, which would be a single byte value such as 0x41 ('A').

312
Multi-Selectmedium

A penetration tester is performing post-exploitation on a compromised Linux server and wants to maintain persistence. Which TWO of the following methods are commonly used for Linux persistence?

Select 2 answers
A.Modifying registry Run keys
B.Creating scheduled tasks
C.Creating WMI subscriptions
D.Adding SSH authorized_keys
E.Creating cron jobs
AnswersD, E

Appending an attacker-controlled public key to ~/.ssh/authorized_keys on the compromised Linux host enables passwordless SSH authentication for that user at any time. This grants persistent remote access that survives reboots and does not rely on additional commands running at intervals. It is a stealthy and reliable persistence method, especially on servers where SSH is exposed.

Why this answer

Cron jobs and SSH authorized_keys are common persistence techniques. Scheduled tasks are Windows-specific, registry is Windows, WMI is Windows.

313
MCQmedium

Refer to the exhibit. A penetration tester performed an Nmap scan of a target server and received the above output. The tester recalls that one of these services is associated with a well-known remote code execution vulnerability that can be exploited without authentication. Which service is most likely vulnerable?

A.HTTP (port 80)
B.SSH (port 22)
C.Microsoft-DS (port 445)
D.ms-wbt-server (port 3389)
AnswerC

Microsoft-DS on port 445 exposes SMB, historically vulnerable to unauthenticated remote code execution such as EternalBlue (MS17-010). That flaw lets an attacker execute code without credentials, matching the stem's requirement for a well-known no-authentication RCE service.

Why this answer

The correct answer is C, Microsoft-DS on port 445, because SMBv1 (the service typically exposed on TCP 445) is associated with the well-known, unauthenticated remote code execution vulnerability EternalBlue (MS17-010), which was exploited by WannaCry and NotPetya. An Nmap scan showing Microsoft-DS on 445 should immediately raise this concern, since exploitation requires no credentials and can yield SYSTEM-level code execution. HTTP on port 80 (A) may host web vulnerabilities, but it is not tied to a single well-known unauthenticated RCE in the way SMBv1 is.

SSH on port 22 (B) is an encrypted remote-login service that requires authentication and is not associated with an unauthenticated RCE of this kind. ms-wbt-server on port 3389 (D) is RDP, which is normally protected by authentication and credentials, so it does not fit the 'without authentication' criterion.

314
Multi-Selecthard

A tester is conducting a code review of a web application. Which three coding practices can help prevent cross-site scripting (XSS)?

Select 3 answers
A.Parameterized queries
B.Content Security Policy (CSP) headers
C.Disabling JavaScript in the client
D.Output encoding
E.Input validation
AnswersB, D, E

CSP headers instruct the browser to load scripts only from approved sources and block inline execution, providing defence in depth when an injection slips past other controls. This constrains the impact of any reflected or stored XSS payload that reaches the rendered page.

Why this answer

Content Security Policy (CSP) headers (B) are correct because a restrictive CSP, such as one using default-src 'self' and disallowing 'unsafe-inline', prevents the browser from executing injected inline or third-party scripts, which is a primary XSS mitigation. Output encoding (D) is correct because encoding untrusted data for the correct context (HTML entity encoding, JavaScript escaping, URL encoding, CSS escaping) ensures attacker-supplied markup is rendered as inert text rather than executable script. Input validation (E) is correct because validating input against a strict allowlist (for example, expected format, length, and character set) rejects or sanitizes malicious payloads before they can be stored or reflected, reducing XSS attack surface.

Parameterized queries (A) are not correct here because they prevent SQL injection, not XSS. Disabling JavaScript in the client (C) is not a server-side coding practice and is impractical for a web application that depends on JavaScript, so it is not a recommended XSS prevention control.

315
Multi-Selectmedium

Before starting a penetration test, the tester receives permission to test only two public IP ranges and is told not to perform denial-of-service testing. Which two documents or artefacts are most important to confirm before testing begins? (Choose 2.)

Select 2 answers
A.Written authorization to test the specified targets.
B.Rules of engagement describing prohibited techniques such as DoS.
C.A list of exploit payloads from a public GitHub repository.
D.A screenshot of the company home page.
AnswersA, B

Written authorization to test specified targets is the foundational legal document for any penetration test. It establishes explicit permission from the system owner, defines the exact scope of systems and networks in scope, and limits the tester's authority to those targets. Without this signed authorization, even benign security testing could constitute unauthorized access under laws like the CFAA or similar cybercrime statutes, exposing the tester to civil and criminal liability.

Why this answer

Written authorization (A) is the foundational legal document that explicitly grants the tester permission to test the specified public IP ranges, protecting against claims of unauthorized access under laws like the Computer Fraud and Abuse Act. The rules of engagement (B) define the scope boundaries, including the prohibition of denial-of-service testing, which is critical to avoid service disruption and legal liability. Without these two documents, the tester lacks both legal authority and operational constraints, making them the most important artefacts before testing begins.

Exam trap

The trap here is that candidates may mistakenly prioritize technical artefacts like exploit lists or screenshots over the legal and scoping documents that are mandatory before any testing begins, confusing operational tools with authorization requirements.

316
MCQmedium

A penetration tester needs to escalate privileges on a Linux system and finds that the user can run a script with sudo that has a vulnerable argument. Which resource should the tester consult to find exploitation techniques for common sudo misconfigurations?

A.GTFOBins
B.Exploit-DB
C.Metasploit
D.CVE Details
AnswerA

GTFOBins is a curated repository of Unix binary exploitation techniques, specifically cataloging ways to abuse binaries for privilege escalation. For a Linux system, if a penetration tester discovers via 'sudo -l' that a binary can be executed with sudo privileges, GTFOBins provides exact command sequences to leverage that binary to spawn a root shell or read protected files. It is the go-to, command-focused resource for sudo misconfigurations and setuid abuse, making it directly applicable to the scenario.

Why this answer

GTFOBins is a curated list of Unix binaries that can be exploited to bypass local security restrictions, including sudo misconfigurations.

317
MCQhard

A penetration tester is presenting findings to a group of executives. Which of the following is the most effective way to communicate a critical vulnerability?

A.Describe the vulnerability in terms of potential financial and reputational damage.
B.Recommend specific code changes without context.
C.Explain the technical exploit steps in detail.
D.Show raw network captures as evidence.
AnswerA

Executive audiences prioritize fiduciary responsibility; translating a discovered vulnerability into projected financial impact (potential breach cost, legal fines, operational downtime) and reputational damage (customer churn, media exposure, diminished brand trust) makes the finding actionable at a governance level. This framing establishes why remediation deserves budget and executive sponsorship, rather than treating the issue as purely an IT concern. It also aligns the finding with organizational risk appetite and regulatory obligations that executives are accountable for.

Why this answer

Executives need to understand business impact, not technical details. Use business language and focus on risk.

318
MCQeasy

A penetration tester wants to identify the operating system of a remote host without sending any traffic to the target network. Which of the following techniques is most effective for this purpose?

A.Perform an nmap OS fingerprint scan on the host.
B.Use Shodan to search for the host's IP address and examine the service banners.
C.Send a ping sweep to the host's network segment.
D.Use ARP scanning to discover the host's MAC address and look up the vendor.
AnswerB

Shodan's pre-collected banners and service fingerprints let the tester infer the host's operating system from cached scan data, satisfying the passive-only constraint since no packets reach the target network. Active fingerprinting techniques would generate traffic and violate the requirement.

Why this answer

Shodan is a search engine that indexes service banners and metadata from internet-connected devices. By querying Shodan for the target's IP address, the tester can retrieve previously collected OS information without sending any packets to the target, satisfying the 'no traffic' constraint.

Exam trap

The trap here is that candidates assume passive OS identification requires active scanning tools like nmap, overlooking that Shodan provides a passive, historical data source that avoids generating any traffic to the target.

How to eliminate wrong answers

Option A is wrong because nmap OS fingerprint scan actively sends TCP/IP probes (e.g., SYN, FIN, NULL packets) to the target host, generating network traffic. Option C is wrong because a ping sweep sends ICMP Echo Request packets to multiple hosts, which directly generates traffic on the target network. Option D is wrong because ARP scanning sends ARP request broadcasts to the local network segment, which creates traffic and only works for hosts on the same Layer 2 domain, not a remote host.

319
MCQeasy

A penetration tester is scoping an engagement for a client that hosts a public-facing web application and an internal database server. The client wants to ensure that testing does not cause any disruption to the database server. Which of the following should the tester include in the rules of engagement to address this concern?

A.Specify that only passive reconnaissance techniques will be used on the database server.
B.Include a clause that the tester will not attempt to exploit any vulnerabilities on the database server.
C.Define the database server as an out-of-scope target.
D.Require that all testing activities be performed during off-peak hours only.
AnswerC

Explicitly listing the database server as out-of-scope in the rules of engagement is the only contractual and technical guarantee that no tool will send packets to it, as all scanning and testing tools can be configured with exclusion lists. This eliminates any risk of accidental disruption, data corruption, or service outage, and also protects the tester from legal and professional liability. It is the cleanest, most enforceable scoping decision.

Why this answer

Defining the database server as out-of-scope explicitly removes it from all testing activities, ensuring zero disruption as requested. This is the only option that fully prevents any interaction with the database server, including passive reconnaissance or exploitation attempts, which could still cause unintended load or queries.

Exam trap

The trap here is that candidates may think passive reconnaissance or off-peak testing is sufficient to avoid disruption, but the CompTIA PT0-002 exam emphasizes that only explicit out-of-scope designation guarantees no interaction with a target system.

How to eliminate wrong answers

Option A is wrong because passive reconnaissance on the database server (e.g., banner grabbing, DNS enumeration) could still generate traffic or queries that disrupt the server, violating the client's requirement. Option B is wrong because including a clause not to exploit vulnerabilities still allows other testing activities (e.g., scanning, enumeration) that could cause disruption, and the tester might inadvertently trigger a vulnerability during reconnaissance. Option D is wrong because performing tests during off-peak hours does not prevent disruption; it only reduces the impact on users, but the database server could still be affected by scanning or exploitation attempts.

320
MCQeasy

Which penetration testing standard provides a step-by-step methodology from pre-engagement through post-engagement activities, including intelligence gathering, vulnerability analysis, and exploitation?

A.PTES
B.OSSTMM
C.OWASP Testing Guide
D.NIST SP 800-115
AnswerA

The Penetration Testing Execution Standard (PTES) is explicitly designed as a step-by-step methodology for conducting penetration tests. It defines seven distinct phases—pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting—each with detailed technical guidance and deliverables. This lifecycle coverage makes PTES the most complete answer for a standard that walks an assessor through the entire engagement from scoping to final report.

Why this answer

PTES (Penetration Testing Execution Standard) covers the entire lifecycle of a penetration test.

321
MCQhard

A penetration tester gains a low-privileged shell on a Linux server and discovers that the user is a member of the 'docker' group. The tester wants to escalate privileges to root. Which technique is most effective?

A.Use cron job misconfigurations to execute a reverse shell
B.Exploit kernel vulnerabilities using a local exploit suggester
C.Run a Docker container with the host filesystem mounted and access it as root
D.Abuse SETUID binaries to execute commands as root
AnswerC

By running a Docker container with the host filesystem mounted (e.g., `docker run -v /:/mnt -it alpine chroot /mnt`), the user can access all host files as root because Docker effectively runs as root. This bypasses normal privilege restrictions.

Why this answer

Members of the 'docker' group can run Docker containers with the `-v /:/mnt` flag to mount the host filesystem into the container. Inside the container, the user effectively has root privileges (since the container runs as root by default) and can access the host's `/mnt` directory, allowing them to modify files like `/mnt/etc/shadow` or add an SSH key to `/mnt/root/.ssh/authorized_keys` to gain root access on the host.

Exam trap

CompTIA often tests the misconception that kernel exploits are always the fastest path to root, but the trap here is that membership in the 'docker' group is a trivial and reliable escalation vector that bypasses the need for kernel exploitation or other complex techniques.

How to eliminate wrong answers

Option A is wrong because cron job misconfigurations require write access to a cron directory or a user's crontab, which the low-privileged user does not have; the 'docker' group membership does not grant cron-related privileges. Option B is wrong because exploiting kernel vulnerabilities is a valid privilege escalation technique, but it is not the most effective here since the 'docker' group provides a direct, reliable, and less risky path to root without needing to match a specific kernel version or risk system instability. Option D is wrong because abusing SETUID binaries requires finding a binary with the SUID bit set that can be exploited (e.g., via a known vulnerability or misconfiguration), but the 'docker' group membership offers a more straightforward and guaranteed escalation path.

322
MCQeasy

A penetration tester wants to crack NTLM hashes obtained from a Windows domain. Which hashcat mode should the tester use?

A.-m 22000
B.-m 13100
C.-m 0
D.-m 1000
AnswerD

Hashcat mode 1000 is the correct choice for NTLM hashes, which are the standard credential material extracted from Windows SAM files, NTDS.dit, or memory dumps. These hashes are computed by first converting the password to UTF-16LE and then applying the MD4 hash algorithm, a process unique to Windows authentication. Mode 1000 tells Hashcat to treat each hash as a 32-character hexadecimal NTLM digest, enabling efficient dictionary, rule-based, or brute-force attacks specifically tailored to this format, including pass-the-hash and offline cracking scenarios.

Why this answer

Hashcat mode 1000 is for NTLM hashes.

323
MCQmedium

A penetration tester has completed testing and identified several vulnerabilities: a critical SQL injection (CVSS 9.8), a medium stored XSS (CVSS 6.1), and a low self-signed certificate (CVSS 3.7). The client's security manager asks for a simplified way to prioritize remediation. Which of the following is the most effective approach for the tester to present the findings?

A.List all vulnerabilities in descending order of CVSS score only.
B.Provide a risk matrix that maps likelihood and impact for each finding.
C.Present only the critical SQL injection finding because it overshadows the others.
D.Calculate a single overall risk score for the entire engagement by averaging all CVSS scores.
AnswerB

A risk matrix allows the tester to rate each finding based on the likelihood of exploitation and the potential business impact. This gives the client a clear, actionable prioritization that accounts for their specific environment and risk tolerance.

Why this answer

A risk matrix that maps likelihood and impact for each finding provides a more nuanced prioritization than raw CVSS scores alone. CVSS scores reflect intrinsic severity but do not account for the client's specific threat environment, asset criticality, or compensating controls. By presenting a risk matrix, the tester enables the security manager to make informed decisions based on the actual risk to the organization, which is the core goal of the reporting and communication domain in PT0-002.

Exam trap

The trap here is that candidates often assume CVSS scores are the definitive prioritization metric, but PT0-002 emphasizes that risk-based communication (using likelihood and impact) is the most effective approach for client remediation discussions.

How to eliminate wrong answers

Option A is wrong because listing vulnerabilities in descending order of CVSS score only ignores the context of likelihood and business impact, which can lead to misprioritization (e.g., a critical SQL injection on a non-critical server may be less urgent than a medium XSS on a public-facing application with sensitive user data). Option C is wrong because presenting only the critical SQL injection finding disregards the other vulnerabilities, which could be exploited in combination (e.g., chaining XSS with SQL injection) or pose significant risk in the client's specific environment. Option D is wrong because calculating a single overall risk score by averaging CVSS scores is statistically invalid and obscures the distinct severity levels of individual findings; a low-severity issue can dilute the critical finding, giving a false sense of security.

324
MCQhard

A penetration tester has compromised a Linux host and wants to use it as a pivot point to access an internal network that is not directly reachable from the attacker's machine. Which tool can create a SOCKS proxy for routing traffic through the compromised host?

A.Responder
B.chisel
C.nmap
D.netcat
AnswerB

Chisel is a single-binary client/server tunnel program that can establish an outbound reverse tunnel from a compromised Linux host to the attacker's C2 server, then expose a SOCKS5 proxy on the attacking machine at the remote end. For example, the attacker runs `chisel server --reverse --socks5` and the compromised host runs `chisel client <attacker-ip>:8080 R:socks`. Because the client makes the initial outbound connection, this evades most inbound firewall rules, and the resulting SOCKS5 proxy allows any attacker tool to route scans and traffic into the target's internal network through the compromised host.

Why this answer

Chisel is a fast TCP/UDP tunnel over HTTP that can create a SOCKS proxy for pivoting.

325
MCQhard

A penetration tester is performing a cloud security audit of an AWS environment. Which tool is specifically designed for AWS exploitation and post-exploitation, including privilege escalation and persistence?

A.Pacu
B.CrackMapExec
C.ScoutSuite
D.Prowler
AnswerA

Pacu is the correct answer because it is an open-source AWS exploitation framework designed specifically for offensive cloud security testing. It automates attack chains against AWS environments, including privilege escalation, Lambda backdooring, and S3 bucket misconfiguration exploitation, making it the only option that directly performs exploitation rather than just auditing or reconnaissance.

Why this answer

Pacu is an AWS exploitation framework that provides modules for enumeration, privilege escalation, and persistence.

326
MCQeasy

After completing a penetration test, the client requests a one-page document that highlights the most critical vulnerabilities, overall risk level, and recommended next steps for management. Which deliverable should the penetration tester provide?

A.Executive summary
B.Technical report
C.Raw scan data
D.Remediation guide
AnswerA

The executive summary is the standard deliverable for management, condensing the entire engagement into a concise, business-focused narrative. It prioritizes findings by risk and business impact, translating technical vulnerabilities into language that non-technical stakeholders can immediately understand and act upon. For a client requesting a one-page overview, this is the appropriate format because it highlights critical issues and recommended next steps without overwhelming detail.

Why this answer

The executive summary is the correct deliverable because it is specifically designed to provide a high-level overview of the most critical vulnerabilities, overall risk level, and recommended next steps for management. Unlike a technical report, it avoids deep technical jargon and focuses on business impact, aligning with the client's request for a concise one-page document.

Exam trap

The trap here is that candidates often confuse the executive summary with the technical report, thinking management needs detailed evidence, when in fact the exam emphasizes that management requires a concise, risk-focused overview without technical depth.

How to eliminate wrong answers

Option B is wrong because a technical report is a detailed document that includes full attack chains, command outputs, and evidence, which is too lengthy and technical for a one-page management summary. Option C is wrong because raw scan data is unprocessed output from tools like Nmap or Nessus, lacking analysis, risk ratings, or actionable recommendations, and is not suitable for management. Option D is wrong because a remediation guide is a step-by-step technical document for fixing vulnerabilities, not a high-level summary of critical findings and risk levels for executive decision-making.

327
MCQmedium

Which legal framework in the United States prohibits unauthorized access to computer systems and is commonly referenced in penetration testing authorization documents?

A.HIPAA
B.GLBA
C.CFAA
D.SOX
AnswerC

The Computer Fraud and Abuse Act (CFAA), codified at 18 U.S.C. §1030, is the primary U.S. federal statute prohibiting unauthorized access to computers and protected systems. It criminalizes intentionally accessing a computer without authorization, or exceeding authorized access, to obtain information, cause damage, or commit fraud. This makes CFAA the legal framework that directly targets unauthorized computer access, which is why it is the correct answer.

Why this answer

The Computer Fraud and Abuse Act (CFAA) is the primary U.S. law against unauthorized computer access.

328
MCQhard

During an internal penetration test, a tester discovers a Windows server running a custom service that is vulnerable to a stack-based buffer overflow. The binary has Data Execution Prevention (DEP) enabled but Address Space Layout Randomization (ASLR) is disabled. Which exploitation technique would be MOST effective to achieve code execution?

A.Injecting shellcode directly onto the stack and overwriting the return address to jump to it
B.Using a return-to-libc attack to call system() with a command string
C.Constructing a ROP chain using gadgets from loaded DLLs to simulate shellcode execution
D.Enabling the execute bit on the stack via a memory corruption primitive
AnswerC

A ROP chain reuses sequences of existing instructions (gadgets) terminated by a ret, all located in executable modules such as loaded DLLs or system libraries. Because these gadgets reside in executable memory, DEP does not block them; chaining them lets the attacker simulate arbitrary logic or call functions like VirtualProtect to change memory permissions and then execute shellcode. With ASLR disabled, gadget addresses are fixed and predictable, making this a reliable bypass of DEP on Windows.

Why this answer

With DEP enabled, the stack is marked non-executable, so injecting shellcode directly (option A) would fail. ASLR being disabled means the addresses of loaded DLLs are predictable, making it feasible to construct a ROP chain using gadgets from those DLLs to simulate shellcode execution. Option C is correct because ROP chains bypass DEP by reusing existing executable code (gadgets) without needing to execute code on the stack.

Exam trap

The trap here is that candidates assume DEP can be bypassed simply by enabling execution on the stack (option D) without realizing that doing so requires a ROP chain or similar technique to call VirtualProtect, making option C the more direct and effective approach.

How to eliminate wrong answers

Option A is wrong because DEP prevents execution of code on the stack, so overwriting the return address to jump to injected shellcode will cause an access violation. Option B is wrong because a return-to-libc attack typically calls a single function like system() from libc, but on Windows the equivalent (e.g., calling system() from msvcrt) is limited; more importantly, return-to-libc cannot easily chain multiple function calls to achieve arbitrary shellcode behavior, whereas a ROP chain can. Option D is wrong because enabling the execute bit on the stack would require a separate memory corruption primitive to modify page permissions (e.g., via VirtualProtect), which itself would need to be called through ROP or similar; it is not a direct exploitation technique and is less effective than constructing a full ROP chain.

329
MCQmedium

A penetration tester is presenting findings to a mixed audience of executives and technical staff. For the executives, the tester should focus on:

A.Raw tool output and log files
B.Risk ratings, business impact, and high-level remediation strategy
C.Detailed exploit code and proof-of-concept
D.Step-by-step remediation commands
AnswerB

Risk ratings, business impact, and a high-level remediation strategy align security findings directly with the organization's operational and financial goals, which is what executive audiences need to prioritize actions and allocate resources. Ratings such as Critical/High/Medium/Low, derived from likelihood and impact (e.g., CVSS base scores adjusted for business context), translate technical vulnerabilities into decision-ready language. The high-level remediation strategy—such as 'segment the payment network' or 'accelerate patching of internet-facing systems'—gives executives actionable direction without drowning them in implementation minutiae.

Why this answer

Executives are interested in business risk, impact, and strategic recommendations, not technical details.

330
MCQhard

A penetration tester is contracted to perform a grey box test of a company's internal network. The client provides a VPN account for remote access but does not disclose that the account has been used by a former employee. The tester connects and is immediately locked out. Which pre-engagement document should have addressed this scenario?

A.Emergency contact list
B.Data handling agreement
C.Statement of Work (SOW)
D.Rules of Engagement (RoE)
AnswerD

The Rules of Engagement (RoE) is the authoritative document that defines the boundaries, testing windows, legal authorizations, and permissible techniques for a penetration test. In a grey box engagement, the RoE should explicitly list the provided credentials—such as usernames, passwords, API tokens, or SSO accounts—along with their validity period, or state where they will be securely delivered (e.g., an encrypted annex). This ensures the tester only uses authorized accounts and does not exceed the granted access level. Without this, the tester would have no legal proof that using those credentials was permitted.

Why this answer

The rules of engagement (RoE) should specify the accounts and credentials provided, including any limitations or known issues.

331
MCQhard

A penetration tester is conducting active reconnaissance and wants to perform a SYN scan on a target network. During the scan, the tester notices that some ports are reported as filtered. What does a filtered port status typically indicate in Nmap?

A.The port is closed and the target responded with a RST packet.
B.The port is open but no service is listening.
C.The target is not responding to any probes.
D.A firewall is blocking the probe packets.
AnswerD

When Nmap receives no response (or an ICMP unreachable message, such as type 3 code 13, administratively prohibited) to a SYN probe to a specific port, it labels that port 'filtered'. This indicates that a firewall or packet-filtering device is interfering with the probe, either by dropping the packet silently or by sending back a rejection message. Consequently, Nmap cannot definitively determine whether the port is open or closed because it lacks a TCP-level response like SYN/ACK or RST. This is a common result when stateful firewalls inspect and block unsolicited inbound packets during active reconnaissance.

Why this answer

Filtered ports in Nmap indicate that a firewall, packet filter, or other network obstacle is blocking the probe packets, preventing Nmap from determining whether the port is open or closed.

332
MCQmedium

A tester runs the following Metasploit commands: ``` msf6 > use exploit/multi/handler msf6 exploit(multi/handler) > set PAYLOAD windows/meterpreter/reverse_tcp msf6 exploit(multi/handler) > set LHOST 10.0.0.5 msf6 exploit(multi/handler) > set LPORT 4444 msf6 exploit(multi/handler) > run ``` What is the purpose of this configuration?

A.To exploit a remote service directly
B.To receive a reverse shell from a target that already executed the payload
C.To perform a bind shell attack
D.To stage a payload for later execution
AnswerB

This is the correct function: multi/handler acts as a listener that waits for a reverse TCP connection from a target that has already executed a Meterpreter or other reverse payload. In a typical attack workflow, the tester starts this handler on their machine, then delivers a payload to the target via phishing, exploit, or direct execution; once the target runs the payload, it connects back to the handler's listening port. The handler then provides an interactive session (e.g., Meterpreter) for post-exploitation. It is a generic catch-all for reverse shells and is indispensable when using staged payloads, where the initial stager connects back to fetch the full payload.

Why this answer

The multi/handler is a generic handler used to receive reverse connections from payloads that were delivered separately (e.g., via phishing). It waits for the target to connect back.

333
Multi-Selecteasy

Which THREE of the following are example of privilege escalation techniques on Linux systems? (Select THREE.)

Select 3 answers
A.Exploiting kernel vulnerabilities
B.Exploiting SUID binary vulnerabilities
C.Token manipulation
D.Sudo misconfiguration exploitation
E.Pass-the-hash
AnswersA, B, D

Kernel vulnerabilities are a classic local privilege escalation vector because the kernel executes in the most privileged CPU ring (ring 0 on x86). A flaw such as a use-after-free or missing permission check in a syscall handler lets an unprivileged user execute arbitrary code with kernel or root privileges. Exploits like Dirty COW (CVE-2016-5195) and CVE-2022-0847 (Dirty Pipe) demonstrate how a low-privileged attacker can overwrite read-only files or gain root, making this a primary target for post-exploitation.

Why this answer

Option A is correct because exploiting kernel vulnerabilities (e.g., Dirty COW CVE-2016-5195 or Dirty Pipe CVE-2022-0847) lets a local unprivileged user execute code in kernel context and gain root, a classic Linux privilege-escalation technique. Option B is correct because SUID binaries run with the file owner's privileges (often root), so abusing a vulnerable or misconfigured SUID program (e.g., via GTFOBins techniques) elevates a normal user to root. Option D is correct because sudo misconfiguration—such as overly permissive entries in /etc/sudoers (e.g., NOPASSWD or allowed commands like vi, find, or python)—lets a user run commands as root and escalate privileges.

Option C (token manipulation) is a Windows access-token concept (e.g., SeDebugPrivilege/token stealing), not a standard Linux escalation technique. Option E (pass-the-hash) is a Windows/Active Directory credential-reuse attack against NTLM hashes, not applicable to Linux privilege escalation.

Exam trap

CompTIA often tests the distinction between Windows-specific and Linux-specific privilege escalation techniques, so the trap here is that candidates may mistakenly apply Windows concepts like token manipulation or pass-the-hash to Linux environments, where they are not valid.

334
MCQmedium

A wireless network test must not disrupt the network. How can the tester crack WPA2 passwords without disruption?

A.Scan for rogue access points
B.Use passive sniffing to capture traffic and crack offline
C.Perform a deauthentication attack
D.Attempt a brute-force attack against the Wi-Fi password
AnswerB

Passive sniffing captures the WPA2 four-way handshake without transmitting any frames, so the live network remains untouched — satisfying the non-disruptive constraint. Cracking then occurs offline against the captured handshake, meaning no authentication attempts or deauthentication frames ever reach the access point.

Why this answer

Option B is correct because passive sniffing captures the WPA2 4-way handshake (or PMKID) from normal client traffic without sending any frames, and the captured handshake is then cracked offline against a wordlist, so the live network is never disrupted. This satisfies the requirement that the test must not disrupt the network. Option A, scanning for rogue access points, is a discovery activity and does not crack WPA2 passwords.

Option C, a deauthentication attack, forcibly disconnects clients and is inherently disruptive. Option D, an online brute-force attack against the Wi-Fi password, would generate authentication attempts against the AP, which is disruptive and also impractical due to WPA2's key derivation.

335
Multi-Selectmedium

During a penetration test, a tester needs to perform a deauthentication attack to force a client to reconnect and capture the WPA handshake. Which two tools from the Aircrack-ng suite are required? (Choose TWO.)

Select 2 answers
A.airmon-ng
B.aircrack-ng
C.aireplay-ng
D.airodump-ng
E.airolib-ng
AnswersC, D

aireplay-ng is the correct tool because it can inject arbitrary 802.11 frames, including deauthentication packets. The command `aireplay-ng -0 <count> -a <BSSID> <interface>` sends repeated deauth frames to disconnect connected clients, forcing them to reconnect and generate new EAPOL handshakes that airodump-ng can capture. It is the active component of the deauthentication attack.

Why this answer

Airodump-ng captures the handshake, and aireplay-ng sends deauth packets.

336
MCQmedium

A penetration testing engagement requires testing a production environment during business hours. The client is concerned about potential service disruption. Which document should specify the conditions under which the test must be halted?

A.Get-out-of-jail letter
B.Rules of Engagement
C.Communication plan
D.Statement of Work
AnswerB

The Rules of Engagement defines scope, timing, permitted techniques and stop conditions, so it is the document authorising the tester to halt activity if disruption risk appears. It directly satisfies the client's requirement for agreed business-hours testing safeguards.

Why this answer

The Rules of Engagement (RoE) is the definitive document that outlines the scope, authorization, and constraints of a penetration test, including explicit conditions under which testing must be halted to prevent service disruption. Unlike other documents, the RoE is a legally binding agreement that specifies technical boundaries such as IP ranges, testing windows, and stop conditions (e.g., CPU threshold exceeded or application error rate spike). This ensures the client's production environment is protected during business hours.

Exam trap

In CompTIA Pentest+, candidates often confuse the Statement of Work (SOW) with the Rules of Engagement (RoE). The SOW defines what will be done, while the RoE specifies how and under what constraints it will be done, including explicit halt conditions to prevent service disruption.

How to eliminate wrong answers

Option A is wrong because a get-out-of-jail letter (or authorization letter) is a document that provides the tester with emergency contact information and legal authorization to bypass security controls, but it does not define the technical conditions for halting the test. Option C is wrong because a communication plan outlines how and when to report findings and escalate issues, but it does not specify the technical stop conditions for the test itself. Option D is wrong because a Statement of Work (SOW) defines the high-level objectives, deliverables, and timeline of the engagement, but it lacks the granular technical constraints and halt conditions that are detailed in the Rules of Engagement.

337
MCQmedium

A client wants a penetration test of their cloud infrastructure hosted on AWS. The client states that they want to test the security of their EC2 instances, S3 buckets, and IAM configurations. The client's security team is concerned about potential service disruption due to testing. Which of the following should be included in the rules of engagement to address this concern?

A.A clause that the tester will avoid using any automated scanning tools.
B.A clear definition of what constitutes a denial-of-service condition and a requirement to stop testing immediately if such a condition is detected.
C.A requirement that the tester only performs manual testing and no tools.
D.A clause that the tester will test only during business hours.
AnswerB

To protect a cloud client from accidental availability impact, the rules of engagement should define explicit DoS indicators—for example, sustained packet loss, error-rate thresholds, or load-balancer health-check failures—and require the tester to stop immediately when any indicator is seen. Cloud elasticity can mask or amplify failures, so predefined numeric thresholds and a communication plan let both sides distinguish test-induced disruption from real incidents. This clause is superior because it directly manages the highest-risk outcome of penetration testing rather than merely limiting when or how testing may occur.

Why this answer

It directly addresses the client's concern about service disruption by establishing a clear threshold for denial-of-service (DoS) conditions and a mandatory stop action. In AWS, automated scanning or aggressive testing can inadvertently trigger Auto Scaling events, exhaust burst credits on EC2 instances, or saturate S3 request limits, leading to degraded performance. Defining what constitutes a DoS condition (e.g., CPU > 90%, network packet loss > 5%) ensures the tester can halt immediately, protecting the client's cloud infrastructure while still allowing effective security testing.

Exam trap

The trap here is that candidates often choose options A or C, mistakenly believing that avoiding automation or restricting testing hours will prevent service disruption, when in reality the key is having a clear, measurable definition of disruption and a stop condition, as required by the PT0-002 exam's focus on scoping and risk management.

How to eliminate wrong answers

Option A is wrong because completely avoiding automated scanning tools is impractical for a thorough penetration test of AWS EC2, S3, and IAM configurations; tools like Nmap, Burp Suite, or custom scripts are essential for discovering vulnerabilities such as open ports, misconfigured bucket policies, or weak IAM roles. Option C is wrong because requiring only manual testing is overly restrictive and unrealistic for testing cloud-scale environments; automated tools are needed to efficiently enumerate S3 bucket permissions, scan for IAM privilege escalation paths, and test EC2 security group rules. Option D is wrong because testing only during business hours does not mitigate the risk of service disruption; in fact, testing during peak usage could increase the chance of impacting production workloads, and the client's concern is about disruption itself, not timing.

338
MCQmedium

A penetration tester is performing reconnaissance on a target domain. The tester queries the public DNS records and finds an SPF record that includes an 'include' mechanism pointing to a third-party email service. Which technique can the tester use to potentially discover more subdomains or internal infrastructure?

A.Perform a DNS zone transfer
B.Enumerate MX records for the third-party
C.Query the TXT records of the third-party domain
D.Use Google dorks to find exposed email addresses
AnswerC

Querying the TXT records of the third-party domain is correct because the target's SPF record contains an include: directive that tells the receiver to perform a DNS TXT query on that third-party domain to fetch its SPF policy. That third-party's TXT records may themselves include other domains, or list additional authorized sending hosts/subdomains, thereby mapping out the full SPF include chain and expanding the attacker's view of the target's infrastructure. This is a direct, low-noise recon technique that exploits the trust relationship encoded in SPF, which is exactly what the scenario hints at.

Why this answer

The SPF record's 'include' mechanism points to a third-party email service, which itself may have SPF or other TXT records that reveal additional domains or subdomains used for email infrastructure. By querying the TXT records of the third-party domain, the tester can discover these included domains, potentially expanding the attack surface. This technique leverages the recursive nature of SPF includes to map out related infrastructure.

Exam trap

The trap here is that candidates often assume DNS zone transfers (option A) are the go-to method for subdomain discovery, but the question specifically leverages the SPF 'include' mechanism, making TXT record enumeration the correct and targeted technique.

How to eliminate wrong answers

Option A is wrong because DNS zone transfers (AXFR) require explicit server configuration to allow them and are rarely successful against public DNS servers; they are not a reliable method for discovering subdomains from an SPF include. Option B is wrong because enumerating MX records for the third-party domain only reveals mail exchange servers, not necessarily subdomains or internal infrastructure of the target; it does not leverage the SPF include chain. Option D is wrong because Google dorks for exposed email addresses are a passive reconnaissance technique for finding user emails, not for systematically discovering subdomains or internal network infrastructure from an SPF record.

339
MCQhard

A penetration tester is performing internal network scanning and wants to identify live hosts on a local subnet without sending IP packets. Which method is most effective in a switched Ethernet environment?

A.TCP SYN scan to common ports
B.Nmap ping sweep with -sn
C.arp-scan
D.SNMP walk
AnswerC

arp-scan sends ARP requests, which operate at layer 2, so it discovers live hosts on the local subnet without transmitting IP packets. In a switched Ethernet environment this bypasses router boundaries and reliably maps active devices by MAC address.

Why this answer

In a switched Ethernet environment, ARP (Address Resolution Protocol) operates at Layer 2 and does not require IP packets to discover hosts. The `arp-scan` tool sends ARP requests to the local broadcast MAC address, and live hosts respond with their MAC addresses, making it the most effective method for identifying live hosts without sending IP packets.

Exam trap

The trap here is that candidates often assume Nmap's `-sn` ping sweep is the standard for host discovery, overlooking that it relies on IP-layer packets, whereas ARP operates at Layer 2 and is the only method that avoids IP packets entirely on a local subnet.

How to eliminate wrong answers

Option A is wrong because a TCP SYN scan sends IP packets (TCP segments over IP) to common ports, which violates the requirement of not sending IP packets. Option B is wrong because Nmap's `-sn` ping sweep typically uses ICMP echo requests, TCP SYN to port 443, or ICMP timestamp requests—all of which are IP-based packets. Option D is wrong because an SNMP walk uses UDP/IP packets to query SNMP-enabled devices, requiring IP communication and not suitable for discovering all live hosts on a local subnet without IP packets.

340
MCQmedium

A penetration tester is documenting evidence for a finding and takes a screenshot. Which of the following is the most important metadata to include with the screenshot?

A.The tool version used
B.A timestamp
C.The file size of the screenshot
D.The tester's name
AnswerB

A timestamp, ideally with an explicit timezone offset (e.g., 2025-04-11T14:32:07Z), is critical because it binds the evidence to a specific moment in time, proving that the finding was captured during the authorized penetration testing period. It supports the evidentiary chain of custody and enables correlation with external logs (e.g., target authentication logs, network captures) to corroborate that the reported activity actually occurred. Without an accurate timestamp, a screenshot can be challenged as having been taken before, during, or after the engagement, potentially invalidating the entire finding in a compliance or legal review. Therefore, the timestamp is essential for establishing both the validity and the reliability of the evidence.

Why this answer

Timestamps provide context and prove when the evidence was captured.

341
Multi-Selectmedium

A penetration tester is examining a compiled binary obtained during an engagement. The tester wants to identify potential buffer overflow vulnerabilities and understand the control flow. Which TWO tools would be most appropriate for this task?

Select 2 answers
A.Wireshark
B.Nmap
C.OllyDbg
D.Burp Suite
E.Ghidra
AnswersC, E

OllyDbg is a 32-bit user-mode debugger for Windows, well-known for assembling inline patches, analyzing stack imbalances, and stepping through instructions at the assembly level. It lets an analyst execute the binary dynamically, observe EIP/RSP moves, set conditional breakpoints on API calls like strcpy or memcpy, and manipulate memory to prove an overflow. This runtime perspective directly exposes how input affects control flow, making it the preferred tool for validating an exploit's viability within a live process.

Why this answer

OllyDbg is a debugger that allows dynamic analysis to identify overflow vulnerabilities by examining memory and registers. Ghidra is a disassembler and decompiler that provides static analysis of control flow and potential vulnerabilities. Nmap is a network scanner, Wireshark is a packet analyzer, and Burp Suite is a web proxy, none of which are suitable for binary analysis.

342
MCQmedium

During a vulnerability scan, a penetration tester notices that the scanner is repeatedly attempting to exploit a service, causing the service to crash and generating misleading findings. Which of the following scan configurations would BEST help the tester avoid this issue while still identifying potential vulnerabilities?

A.Enable SYN scan instead of full TCP connect scan
B.Adjust the scan timing template to a slower rate
C.Activate the 'safe checks' option in the scanner
D.Increase the port range to include high ports
AnswerC

Activating the 'safe checks' option is the correct solution because it instructs the scanner to suppress all plugins that are flagged as intrusive, disruptive, or destructive, and instead rely on non-invasive methods such as banner grabbing, version fingerprinting, and configuration analysis. This prevents the scanner from actively attempting to exploit a vulnerability to confirm its existence, thereby avoiding service crashes, data corruption, or other unintended side effects. It also reduces false positives that can arise from failed exploit attempts, making the scan results more reliable in a production environment.

Why this answer

The 'safe checks' option in vulnerability scanners (such as Nessus or OpenVAS) disables intrusive plug-ins that attempt to exploit services aggressively, which can cause service crashes. This configuration allows the scanner to identify potential vulnerabilities without disrupting the target service, avoiding misleading findings from crashed services.

Exam trap

The trap here is that candidates confuse scan rate adjustments (timing templates) or stealth techniques (SYN scan) with the ability to prevent service disruption, when in fact only disabling intrusive checks directly addresses the crashing issue.

How to eliminate wrong answers

Option A is wrong because enabling SYN scan (a half-open scan) only changes the TCP handshake method to reduce network noise and avoid connection logging, but it does not prevent the scanner from sending exploit payloads that crash services. Option B is wrong because adjusting the scan timing template to a slower rate reduces packet transmission speed to avoid network congestion or IDS alerts, but it does not disable the intrusive exploit attempts that cause service crashes. Option D is wrong because increasing the port range to include high ports expands the scope of the scan to discover more services, but it does not mitigate the aggressive exploitation behavior that crashes services.

343
MCQmedium

A penetration tester is using Hashcat to crack NTLM hashes obtained from a Windows system. The tester wants to use a rule-based attack to maximize cracking success. Which Hashcat mode should be used for NTLM hashes?

A.-m 1000
B.-m 1100
C.-m 3000
D.-m 5500
AnswerA

Mode 1000 is the correct hashcat mode for pure NTLM hashes, which are the MD4 digest of the user's password encoded in UTF-16LE and stored in the Windows SAM database or NTDS.dit. This mode directly feeds the raw 32-character hexadecimal NTLM hash into hashcat's cracking algorithms, such as dictionary, rule-based, or brute-force attacks. Selecting any other mode will cause hashcat to parse the hash incorrectly, leading to false negatives or incorrect crack attempts.

Why this answer

Hashcat mode -m 1000 is specifically designated for NTLM hashes, which are the Windows NT LAN Manager hash format stored in the SAM database. A rule-based attack with this mode applies transformation rules to wordlists to generate candidate passwords, maximizing cracking success by leveraging common password patterns and mutations.

Exam trap

The trap here is confusing NTLM hashes (mode 1000) with NetNTLMv1 (mode 5500) or other Windows-related hash types, as candidates often mix up local authentication hashes with network authentication challenge-response hashes.

How to eliminate wrong answers

Option B (-m 1100) is wrong because it corresponds to Domain Cached Credentials (DCC), also known as MS Cache Hash, not NTLM. Option C (-m 3000) is wrong because it is used for LM (LAN Manager) hashes, an older and weaker Windows hash format. Option D (-m 5500) is wrong because it is used for NetNTLMv1 hashes, which are challenge-response hashes used in network authentication, not the local NTLM hash stored in the SAM.

344
MCQhard

During a reverse engineering task on a .NET binary, which tool would allow you to decompile the code into readable C# source code?

A.IDA Pro Free
B.Ghidra
C.jadx
D.dnSpy
AnswerD

dnSpy is a purpose-built .NET assembly editor, decompiler, and debugger that can read .NET metadata, decode CIL bytecode, and reconstruct readable C# or VB.NET source code. It also supports editing assemblies in place and debugging managed code, making it the correct choice when the target is a .NET binary.

Why this answer

dnSpy is a .NET decompiler that can produce high-level source code from .NET assemblies.

345
Multi-Selectmedium

A penetration tester is conducting a web application test and discovers an XML External Entity (XXE) vulnerability. Which of the following attacks can the tester perform using XXE? (Choose THREE.)

Select 3 answers
A.Read sensitive files from the server
B.Denial of service via entity expansion (billion laughs)
C.Perform Server-Side Request Forgery (SSRF)
D.SQL injection through entity values
E.Remote code execution
AnswersA, B, C

An XML parser allows an attacker to define an external entity, such as `<!ENTITY xxe SYSTEM "file:///etc/passwd">`. When the application processes the XML and includes the entity in a response or error message, the server reads the local file and returns its contents, disclosing credentials, configuration, or other sensitive data. This requires the parser to resolve external general entities without secure settings, a common misconfiguration in web applications.

Why this answer

XXE can be used to read files, perform SSRF, and cause denial of service via entity expansion.

346
MCQmedium

A penetration tester is conducting passive reconnaissance on a target organization using Google dorking. The tester wants to find PDF documents that may contain usernames and passwords. Which Google search query is most appropriate for this task?

A.site:target.com filetype:pdf password
B.site:target.com username password
C.site:target.com filetype:xls password
D.site:target.com intitle:'index of' password
AnswerA

This query combines the site: operator to restrict the domain to target.com, filetype:pdf to limit results to Portable Document Format files, and the term password to surface documents containing that string. It is the most direct way to locate potential credential disclosures because PDFs are commonly used for reports, manuals, and configuration guides that may embed default or hardcoded passwords. Unlike other queries, it precisely targets the document type specified in the objective, minimizing irrelevant HTML or spreadsheet results.

Why this answer

It uses the `filetype:pdf` operator to specifically target PDF documents, combined with the keyword `password` to find files likely containing credentials. Google dorking with `site:target.com` restricts results to the target domain, making this query efficient for passive reconnaissance of exposed sensitive information in PDFs.

Exam trap

CompTIA often tests the distinction between operators that filter by file type (`filetype:`) versus those that search for directory structures (`intitle:'index of'`), causing candidates to confuse passive reconnaissance techniques for document discovery with those for directory enumeration.

How to eliminate wrong answers

Option B is wrong because it lacks the `filetype:` operator, so it returns general web pages containing the words 'username' and 'password' rather than specific document files. Option C is wrong because it targets `filetype:xls` (Excel files), not PDF documents as specified in the question. Option D is wrong because `intitle:'index of'` is used to find directory listings, not PDF documents, and it does not include `filetype:pdf` to filter for PDFs.

347
MCQmedium

A client requests a penetration test of their production environment, which includes critical financial transaction systems. The client is concerned about potential service disruptions. Which of the following should the tester include in the Rules of Engagement to address this concern?

A.A detailed schedule of every attack method to be used
B.A clause stating that testing will stop immediately if any service degradation is detected
C.A scope that limits testing to off-peak hours and includes a rollback plan for any changes
D.A list of all tools and versions that will be used during the test
AnswerC

Limiting testing to off-peak hours lowers the likelihood that legitimate transactions are interrupted, while a rollback plan ensures that any configuration or data changes made during the test can be undone quickly. This combination reduces both the probability and the impact of a service disruption, which is the core objective of a well-defined rules-of-engagement scope. It also shows the tester is managing operational risk, not just technical risk.

Why this answer

It directly addresses the client's concern about service disruptions by limiting testing to off-peak hours and including a rollback plan. This ensures that any changes made during the test can be reversed quickly, minimizing the risk to critical financial transaction systems. The Rules of Engagement (RoE) must balance thorough testing with operational stability, and this scope provision achieves that.

Exam trap

CompTIA often tests the misconception that immediate stoppage upon any degradation (Option B) is the best safeguard, but the trap is that this lacks measurable criteria and could halt testing unnecessarily, whereas a well-defined scope with off-peak hours and rollback plans is the correct, proactive approach.

How to eliminate wrong answers

Option A is wrong because providing a detailed schedule of every attack method violates operational security (OPSEC) and is impractical; the RoE should specify types of attacks, not a rigid timeline, as testers need flexibility to adapt to findings. Option B is wrong because a clause to stop testing immediately upon any service degradation is too vague and reactive; it lacks predefined thresholds for what constitutes degradation, potentially causing premature termination without proper analysis. Option D is wrong because listing all tools and versions is unnecessary for the RoE; while tool inventory may be part of a separate agreement, the RoE focuses on scope, constraints, and legal boundaries, not granular tool details.

348
MCQhard

A penetration tester is conducting a web application assessment and discovers that the target uses WordPress. The tester wants to identify installed plugins, themes, and potential vulnerabilities. Which of the following tools is best suited for this task?

A.WPScan
B.OpenVAS
C.Nikto
D.Gobuster
AnswerA

WPScan is purpose-built for WordPress security assessments: it queries the WPScan vulnerability database, enumerates installed plugins, themes, and users, and can test for weak credentials against wp-login. Its fingerprinting goes beyond generic HTTP probing, identifying specific core versions and CVEs, making it the correct choice for a WordPress web application assessment.

Why this answer

WPScan is a dedicated WordPress security scanner that enumerates installed plugins, themes, and known vulnerabilities by querying the WordPress API and fingerprinting version-specific files. It is purpose-built for WordPress assessments, making it the best choice for this task.

Exam trap

The trap here is that candidates often confuse Nikto's general web scanning with CMS-specific enumeration, but Nikto cannot identify WordPress plugins or themes without custom rules.

How to eliminate wrong answers

Option B (OpenVAS) is wrong because it is a general-purpose vulnerability scanner that lacks WordPress-specific enumeration capabilities and does not directly identify plugins or themes. Option C (Nikto) is wrong because it is a web server scanner focused on misconfigurations and outdated server software, not on CMS-specific components like WordPress plugins. Option D (Gobuster) is wrong because it is a directory/file brute-forcing tool that does not perform vulnerability scanning or plugin/theme enumeration.

349
MCQmedium

A penetration tester has completed the test and is writing the findings section. For a critical vulnerability, the tester wants to provide a clear and actionable remediation recommendation. Which of the following is the best practice for writing this recommendation?

A.State 'Upgrade the software to the latest version'
B.Provide a step-by-step guide including commands, patches, and configuration changes
C.Recommend applying vendor-supplied patches but do not include specific versions
D.Suggest hiring a third-party consultant to fix the issue
AnswerB

Providing a step-by-step guide with exact commands, patch identifiers, and configuration changes gives the client a clear, repeatable path to close the vulnerability. This specificity reduces the chance of misinterpretation and allows the client to verify the fix via retesting, which is a key requirement of a professional pentest report. It also enables junior staff to execute the remediation with confidence, minimizing errors and downtime.

Why this answer

A penetration test report must provide actionable remediation that the client can implement immediately. A step-by-step guide with specific commands, patch identifiers, and configuration changes ensures the client can verify and apply the fix without ambiguity, which is critical for a high-severity vulnerability.

Exam trap

The trap here is that candidates often choose Option A or C because they seem efficient, but the exam emphasizes that a penetration test report must be actionable and specific, not generic or reliant on external parties.

How to eliminate wrong answers

Option A is wrong because stating 'Upgrade to the latest version' is too vague; it does not specify the exact version number, patch level, or any prerequisite steps, leaving room for misinterpretation or incomplete remediation. Option C is wrong because recommending vendor-supplied patches without specific version numbers fails to address the exact vulnerable component; the client may apply an outdated or incorrect patch, leaving the vulnerability unmitigated. Option D is wrong because suggesting a third-party consultant shifts responsibility without providing any technical guidance; the report should empower the client's own team to act, not defer action to an external party.

350
MCQmedium

A penetration tester wants to perform a pass-the-hash attack against a Windows target. Which tools can be used to authenticate using an NTLM hash without knowing the plaintext password? (Choose the best option.)

A.Nmap
B.Responder
C.Wireshark
D.CrackMapExec
AnswerD

CrackMapExec is a post-exploitation and lateral movement tool that natively supports pass-the-hash by accepting NTLM hashes via the -H or --hash parameter. It actively authenticates to SMB, WinRM, and other services using the supplied hash, enabling command execution, credential dumping, and domain enumeration across multiple hosts. This makes it a direct and effective utility for conducting pass-the-hash attacks in a penetration test.

Why this answer

CrackMapExec is a popular tool for pass-the-hash attacks across many Windows services.

351
MCQeasy

Which tool would be best for capturing and analyzing network packets to troubleshoot a web application?

A.Nmap
B.Wireshark
C.Burp Suite
D.Aircrack-ng
AnswerB

Wireshark is a full-featured packet analyzer that captures frames in promiscuous mode via libpcap/WinPcap and dissects hundreds of protocols across all OSI layers. It supports live capture and offline analysis, with powerful display filters, color coding, TCP stream reassembly, and expert information to identify anomalies. This makes it the standard tool for traffic capture and analysis.

Why this answer

Wireshark is the correct tool because it is designed specifically for deep packet inspection, allowing you to capture live network traffic and analyze individual packets at multiple OSI layers. For troubleshooting a web application, you can filter HTTP/HTTPS requests and responses, examine TCP handshakes, and identify latency or payload issues, which is essential for diagnosing performance or functional problems.

Exam trap

The trap here is that candidates often confuse Burp Suite (a web application proxy) with a packet analyzer, but Burp Suite operates at the application layer and does not capture raw network packets or provide low-level protocol analysis like Wireshark does.

How to eliminate wrong answers

Option A is wrong because Nmap is a network scanning tool used for host discovery and port enumeration, not for capturing and analyzing the contents of network packets. Option C is wrong because Burp Suite is an intercepting proxy focused on web application security testing (e.g., manipulating HTTP requests), not a general-purpose packet capture and analysis tool like Wireshark. Option D is wrong because Aircrack-ng is a suite of tools for wireless network security auditing (e.g., cracking WEP/WPA keys), not for capturing and analyzing packets from a wired or wireless web application traffic stream.

352
MCQmedium

A client with a hybrid infrastructure (on-premises and cloud IaaS) requests a penetration test covering both environments. The cloud provider's terms of service require notification and restrict scanning to specific IP ranges. In which document should these constraints be documented?

A.Non-Disclosure Agreement (NDA)
B.Rules of Engagement (ROE)
C.Penetration Testing Report
D.Scope of Work (SOW)
AnswerB

The Rules of Engagement (ROE) is the authoritative document that defines the terms under which the penetration test is conducted, including explicit authorization for specific IP ranges, allowable testing times, emergency contacts, notification requirements for detected incidents, and any prohibited techniques such as social engineering or denial-of-service. It operationalizes the client's objectives into concrete constraints that testers must follow to stay within legal and ethical boundaries. For a hybrid infrastructure spanning on-premises and cloud IaaS, the ROE also clarifies cloud-specific considerations like consent for third-party testing and data handling.

Why this answer

The Rules of Engagement (ROE) document is the authoritative source for defining the legal and technical boundaries of a penetration test, including provider-mandated constraints such as notification requirements and restricted IP ranges. In a hybrid infrastructure with cloud IaaS, the ROE must explicitly list the allowed source IPs, target CIDR blocks, and any time windows or rate limits imposed by the cloud provider to ensure compliance with their terms of service. This document is signed by both the client and the testing team before any testing begins, making it the correct place to document these operational constraints.

Exam trap

The PT0-002 exam often tests the distinction between the SOW (high-level scope) and the ROE (detailed operational rules), so the trap here is that candidates confuse the SOW's 'what' with the ROE's 'how' and 'under what constraints'.

How to eliminate wrong answers

Option A is wrong because a Non-Disclosure Agreement (NDA) only governs confidentiality of information shared between parties, not the technical or operational boundaries of the test. Option C is wrong because the Penetration Testing Report is a post-engagement deliverable that summarizes findings and remediation steps; it does not define pre-engagement constraints like IP ranges or notification requirements. Option D is wrong because the Scope of Work (SOW) defines the high-level objectives, deliverables, and timelines of the engagement, but it does not contain the granular operational rules (e.g., specific IP ranges, scanning windows, or provider-mandated restrictions) that belong in the ROE.

353
MCQmedium

After the penetration test, the client requests a one-page summary of the test's scope, key findings, and recommended next steps for the board of directors. Which document should the penetration tester provide?

A.Executive Summary
B.Detailed Technical Report
C.Vulnerability Scan Report
D.Remediation Plan
AnswerA

The executive summary is a one-page, non-technical brief designed for C-suite and board-level stakeholders. It condenses the engagement's scope, key findings, and risk exposure into business-oriented language, prioritizing action items and strategic recommendations over raw technical detail. This format enables leadership to quickly grasp the organization's security posture and approve funding or policy changes.

Why this answer

The executive summary is specifically designed to provide a high-level overview of the penetration test's scope, key findings, and recommended next steps for non-technical stakeholders like the board of directors. It distills complex technical details into business-focused language, enabling informed decision-making without requiring deep cybersecurity expertise.

Exam trap

The trap here is that candidates confuse the executive summary with the detailed technical report, assuming the board needs full technical evidence, when in fact the board requires a concise, business-impact-focused narrative that omits exploit details.

How to eliminate wrong answers

Option B is wrong because the detailed technical report contains in-depth exploit chains, raw logs, and system-level data that would overwhelm a board of directors and is intended for technical teams. Option C is wrong because a vulnerability scan report is an automated output listing CVEs and severity scores, lacking the manual exploitation context and business risk analysis required for a penetration test summary. Option D is wrong because a remediation plan focuses solely on step-by-step fix instructions for technical staff, omitting the scope and high-level findings needed for executive review.

354
Multi-Selectmedium

A penetration tester is performing a full-scope engagement and needs to identify potential privilege escalation vectors on a Windows system. Which TWO of the following are valid Windows privilege escalation techniques?

Select 2 answers
A.Unquoted service path exploitation
B.Pass-the-hash
C.AlwaysInstallElevated registry key abuse
D.Kerberoasting
E.SUID/SGID binary exploitation
AnswersA, C

Unquoted service path exploitation occurs when a Windows service binary's path contains spaces but is not enclosed in quotes. When Windows resolves the path, it checks each space-separated segment in turn, so an attacker with write access to an early directory (e.g., C:\Program.exe or C:\Program Files\Sub.exe) can plant a malicious executable that the service will launch with its own high-integrity privileges, typically SYSTEM. This yields arbitrary code execution without needing credentials or exploiting a kernel bug.

Why this answer

Unquoted service paths and AlwaysInstallElevated are both valid Windows privilege escalation techniques. Kerberoasting and pass-the-hash are for credential access, not local escalation; SUID/SGID is Linux.

355
Multi-Selecthard

A tester is performing a post-exploitation phase on a compromised Linux server and wants to establish persistence. Which THREE of the following methods are commonly used for Linux persistence? (Choose THREE.)

Select 3 answers
A.Adding a registry Run key
B.Adding an SSH public key to ~/.ssh/authorized_keys
C.Creating a systemd service to start on boot
D.Creating a scheduled task using schtasks
E.Adding a cron job to execute a reverse shell periodically
AnswersB, C, E

Appending the attacker's public key to ~/.ssh/authorized_keys enables passwordless key-based authentication for the targeted user account. This grants persistent SSH access without needing to re-establish a foothold through a vulnerability, and it remains effective across reboots and user sessions. The private key stays with the attacker, allowing them to authenticate at any time as long as the SSH service is exposed and the user account remains valid.

Why this answer

Common Linux persistence methods include adding cron jobs (crontab), creating a systemd service that starts on boot, and adding SSH authorized keys for backdoor access. Scheduled tasks are Windows-specific; Registry Run keys are also Windows-only.

356
MCQhard

During a penetration test, a tester discovers evidence of an ongoing data exfiltration attack by an unknown third party. Which of the following should the tester do first?

A.Contact law enforcement directly
B.Immediately notify the client point of contact
C.Document the evidence and include it in the final report
D.Attempt to block the exfiltration to protect the client
AnswerB

Immediately notifying the client point of contact fulfills the tester's primary obligation during a suspected active breach. The client can then activate their incident response plan, preserve forensic evidence, and decide on involving law enforcement or other third parties. This aligns with the rules of engagement, contractual duties, and the need for timely mitigation to minimize damage.

Why this answer

Evidence of criminal activity should be reported immediately to the client, who can then involve law enforcement if needed. The tester should not interfere directly.

357
MCQmedium

You have captured an NTLMv2 hash from a LLMNR poisoning attack using Responder. Which tool and mode would you use to attempt to crack the hash using a dictionary attack?

A.Hashcat -m 5600 -a 0
B.John the Ripper --format=LM --wordlist
C.Hashcat -m 1000 -a 0
D.John the Ripper --format=NT --wordlist
AnswerA

Hashcat's -m 5600 specifically targets NetNTLMv2 hashes, the exact challenge-response format captured via LLMNR/NBNS poisoning tools like Responder. The -a 0 flag designates a straight dictionary attack, allowing you to feed a wordlist of candidate passwords. This is the correct and complete command for cracking the captured NTLMv2 hash, as it selects both the right hash type and the appropriate attack mode.

Why this answer

Hashcat mode 5600 is for NTLMv2 hashes; -a 0 is dictionary attack.

358
MCQmedium

A penetration tester is using theHarvester tool to gather information about a target domain. The tester wants to collect email addresses and subdomains from public search engines and PGP key servers. Which source is theHarvester commonly configured to use for this passive reconnaissance?

A.Direct DNS zone transfer
B.Shodan
C.Baidu
D.Google and Bing search engines
AnswerD

TheHarvester correctly uses public search engines like Google and Bing to passively discover email addresses, subdomains, and hostnames that are publicly indexed. It queries these search engines by crafting targeted search queries, scrapes the search result pages for patterns matching email addresses and domain names, and does not interact directly with the target's infrastructure. This passive approach reduces the likelihood of detection and aligns with the OSINT phase of a penetration test, making Google and Bing the default and most commonly used sources.

Why this answer

TheHarvester is specifically designed to perform passive reconnaissance by querying public search engines (like Google and Bing) and PGP key servers to collect email addresses, subdomains, and other open-source intelligence (OSINT). It does not initiate direct connections to the target's infrastructure, making it a passive tool. The default configuration often includes Google and Bing as primary sources for this data.

Exam trap

The trap here is that candidates may confuse passive reconnaissance with active techniques like DNS zone transfers (Option A) or assume Shodan (Option B) is a default source for theHarvester, when in fact theHarvester's core functionality relies on traditional search engines and PGP key servers for email and subdomain discovery.

How to eliminate wrong answers

Option A is wrong because a direct DNS zone transfer is an active reconnaissance technique that requires a misconfigured DNS server to allow AXFR requests, whereas theHarvester performs passive reconnaissance without interacting with the target's DNS servers. Option B is wrong because Shodan is a search engine for internet-connected devices and services, but theHarvester does not natively integrate Shodan as a source for email and subdomain collection; it focuses on search engines and PGP key servers. Option C is wrong because while Baidu is a search engine, theHarvester's common configurations prioritize Google and Bing due to their broader coverage and API accessibility for passive OSINT gathering.

359
MCQeasy

A penetration tester has discovered a critical SQL injection vulnerability in a web application. The developer team will fix the issue. Which level of detail is most appropriate for this audience?

A.Provide the CVSS score and a brief description.
B.Include the full proof-of-concept code and the exact HTTP requests used.
C.Describe the business impact in financial terms.
D.List all findings in a bullet-point summary without additional context.
AnswerB

Including the full proof-of-concept code and the exact HTTP requests (method, URL, headers, body, and parameter) gives developers a step-by-step reproduction recipe. They can run the same request locally under a debugger to trace the data flow from input to the SQL query, confirm the vulnerable code path, and then verify the fix by re-executing the identical payload. This level of detail also eliminates guesswork about which parameter is injectable and demonstrates the actual impact, such as data extraction, without requiring the developer to craft a payload from scratch.

Why this answer

The developer team needs the exact technical details to reproduce and fix the vulnerability. Providing the full proof-of-concept code and exact HTTP requests allows developers to understand the injection point, the payload structure, and the vulnerable parameter, enabling them to implement a precise fix such as parameterized queries or input validation.

Exam trap

The trap here is that candidates may choose a high-level summary (like CVSS score or business impact) thinking it is sufficient for all audiences, but the PT0-002 exam emphasizes tailoring the level of detail to the recipient's role—developers need technical specifics to remediate, not just risk scores or financial context.

How to eliminate wrong answers

Option A is wrong because a CVSS score and brief description provide only a severity rating and high-level summary, which lacks the technical specifics (e.g., vulnerable parameter, injection syntax) developers need to remediate the SQL injection. Option C is wrong because describing business impact in financial terms is relevant for management or stakeholders, not for developers who require technical details to fix the code. Option D is wrong because a bullet-point summary without context omits critical information like the exact HTTP requests, payloads, and vulnerable endpoints, leaving developers without enough detail to reproduce or patch the vulnerability.

360
Multi-Selectmedium

A web application test must cover OWASP Top 10. Which THREE should be explicitly included? (Choose three.)

Select 3 answers
A.SQL injection testing
B.Directory traversal testing
C.Cross-site scripting (XSS) testing
D.Buffer overflow testing
E.Broken authentication testing
AnswersA, C, E

SQL injection maps to A03: Injection in the OWASP Top 10, so testing must attempt payloads through input fields, parameters and headers to confirm parameterised queries prevent database compromise. This directly satisfies the stem's OWASP Top 10 coverage requirement.

Why this answer

SQL injection testing (A) is explicitly required because injection flaws, including SQL injection, are a core OWASP Top 10 category (A03:2021 Injection) and must be tested by manipulating input fields and parameters to confirm the application safely handles untrusted data. Cross-site scripting (XSS) testing (C) is also explicitly required because XSS falls under the OWASP Top 10 injection category and involves verifying that user-supplied input is properly encoded or escaped in HTML, JavaScript, and attribute contexts. Broken authentication testing (E) is explicitly required because broken authentication is its own OWASP Top 10 category (A07:2021 Identification and Authentication Failures) and covers weak credential handling, session management flaws, and missing multi-factor authentication.

Directory traversal testing (B) is not one of the OWASP Top 10 categories, although it may be tested as part of broader access control or misconfiguration checks. Buffer overflow testing (D) is not an OWASP Top 10 category either; it is primarily a memory-safety concern more relevant to native applications than typical web application testing.

361
MCQeasy

Which of the following is an example of a custom severity rating based on business context?

A.DREAD score of 7
B.High/Medium/Low based on CVSS
C.CVSS score of 9.0
D.Risk rating of 'Critical' based on high business impact and likelihood
AnswerD

A risk rating of 'Critical' that is explicitly predicated on high business impact and high likelihood is a bespoke severity assessment, because those factors are derived from the organization's own risk context and priorities. Unlike standard CVSS or DREAD scores, this rating maps technical severity to business consequences, which is exactly what a custom severity rating is intended to do. It reflects an informed risk decision, not merely a formulaic score.

Why this answer

Custom severity often uses impact and likelihood to determine risk, as not all vulnerabilities affect the business equally.

362
MCQhard

A penetration tester is preparing a remediation recommendation for a SQL injection vulnerability found in a legacy application. The development team cannot immediately update the framework due to compatibility issues. What should the tester recommend as a compensating control?

A.Disable the affected functionality until the framework can be updated.
B.Conduct manual code reviews to identify and fix the vulnerability immediately.
C.Upgrade the database to a newer version to prevent SQL injection.
D.Implement a web application firewall (WAF) with rules to block SQL injection attempts.
AnswerD

A WAF deployed in front of the application can inspect request parameters, headers, and cookies for SQL injection signatures and block malicious traffic in real time, acting as a virtual patch. This provides immediate containment while the development team corrects the underlying code, and rules can be tuned to reduce false positives. It is not a permanent solution—attackers can bypass poorly tuned rules with obfuscation—so it must be paired with an eventual framework update.

Why this answer

When a full fix is not immediately possible, compensating controls such as a WAF can provide temporary protection.

363
Multi-Selecthard

Which TWO of the following are benefits of using a fuzzing tool during the code analysis phase of a penetration test? (Select TWO.)

Select 2 answers
A.Replaces the need for static code analysis
B.Identifies input validation vulnerabilities
C.Validates authentication mechanisms
D.Reveals crashes or error conditions that may indicate exploitable bugs
E.Guarantees 100% code coverage
AnswersB, D

Fuzzing automatically generates and sends unexpected, malformed, or boundary-case inputs to a program, which exposes weaknesses such as missing length checks, improper encoding, or inadequate sanitization. When a fuzzer triggers an assertion, buffer overflow, or unexpected state transition, it typically indicates that the program trusted user input without proper validation. This makes fuzzing particularly effective at uncovering input-validation flaws across parsers, protocol handlers, and file-format libraries.

Why this answer

Option B is correct because fuzzing feeds malformed, unexpected, or boundary-value inputs to an application and observes how it handles them, which is exactly how input validation weaknesses (e.g., missing length checks, improper sanitization) are surfaced. Option D is correct because a core benefit of fuzzing is detecting crashes, hangs, assertion failures, and error conditions such as segmentation faults or unhandled exceptions, which often point to memory corruption or other exploitable bugs. Option A is incorrect because fuzzing is dynamic and complements, rather than replaces, static code analysis, which inspects source or bytecode without executing it.

Option C is incorrect because validating authentication mechanisms requires logic-aware testing of credential handling, session management, and access control, not random input generation. Option E is incorrect because fuzzing cannot guarantee 100% code coverage; reaching every path depends on input space, corpus quality, and time, and coverage is typically partial.

364
Multi-Selecthard

Which THREE of the following are best practices for writing a penetration test report?

Select 3 answers
A.Organize findings by severity and likelihood
B.Include a glossary of terms for non-technical readers
C.Use technical jargon to demonstrate expertise
D.Provide clear remediation steps for each finding
E.Include all vulnerabilities discovered even if they are duplicates or false positives
AnswersA, B, D

Grouping findings by severity and likelihood lets stakeholders triage remediation by actual risk, satisfying the report's need to prioritise action. This ordering maps directly to the risk rating assigned to each vulnerability, ensuring critical, easily exploitable issues are addressed before low-impact ones.

Why this answer

Option A is correct because organizing findings by severity and likelihood (e.g., using a risk matrix combining CVSS base scores with exploitability and business impact) lets stakeholders prioritize remediation of the highest-risk issues first. Option B is correct because a glossary of terms makes the report accessible to non-technical readers such as executives and managers, who often approve budgets and remediation efforts but lack security vocabulary. Option D is correct because each finding should include clear, actionable remediation steps (specific patches, configuration changes, or compensating controls) so the client can actually fix the issue rather than just knowing it exists.

Option C is not a best practice because excessive technical jargon obscures meaning and alienates non-technical stakeholders; reports should be precise but audience-appropriate. Option E is not a best practice because including duplicates and false positives dilutes the report, wastes client time, and undermines credibility; findings should be validated and deduplicated before inclusion.

365
MCQhard

During a penetration test for a financial institution, the tester discovers that a third-party vendor's system is vulnerable and could expose customer PII. The tester is unsure if the vendor is within scope. How should the tester proceed?

A.Perform additional testing on the vendor system to confirm the vulnerability
B.Ignore the finding since it is out of scope
C.Include the vulnerability in the final report as a high-risk finding
D.Communicate with the client to clarify whether the vendor is in scope
AnswerD

Scope is defined solely by the client's authorisation. Testing a third-party vendor without confirmed permission risks legal exposure, so the tester must pause and obtain written clarification from the client before touching the vendor's system.

Why this answer

When a penetration tester discovers a vulnerability on a system whose scope status is unclear, the correct professional and ethical action is to stop and clarify scope with the client before doing anything else. Testing an out-of-scope third-party vendor system without authorization could be illegal and violate the rules of engagement. Communicating with the client to confirm scope is the safe, compliant step.

Exam trap

PT0-003 often tests the misconception that confirming a vulnerability justifies out-of-scope testing, when the correct action is always to clarify scope with the client before proceeding.

How to eliminate wrong answers

Option A is wrong because performing additional testing on a potentially out-of-scope vendor system without authorization is unauthorized access and could be a criminal offense, regardless of intent. Option B is wrong because ignoring a finding that could expose customer PII is unprofessional and may leave the client exposed; the finding should at least be discussed with the client. Option C is wrong because including it as a high-risk finding without confirming scope or authorization could misrepresent the engagement and expose the tester to liability; the client must first confirm whether the vendor is in scope.

366
MCQmedium

A tester is exploiting a SQL injection vulnerability in a login form. The application returns different responses for valid and invalid queries. However, the tester cannot see the database output. Which type of SQL injection is most likely?

A.Out-of-band SQL injection
B.Blind SQL injection
C.UNION-based SQL injection
D.Error-based SQL injection
AnswerB

Blind SQL injection is correct because the tester is exploiting the vulnerability without seeing actual query results or database errors in the application response. Instead, they infer database behavior by observing differences in application responses — either boolean outcomes (e.g., ' AND 1=1 vs ' AND 1=2 causing different page content) or time delays (e.g., SLEEP or WAITFOR DELAY). These indirect signals allow the tester to extract data piece by piece, which aligns with the scenario of exploiting a SQL injection in a low-information environment.

Why this answer

Blind SQL injection occurs when query results are not directly reflected, but the application behavior changes based on truth values.

367
MCQhard

During a penetration test, a tester identifies a buffer overflow vulnerability in a Linux binary that has both ASLR and NX (Non-Executable) enabled. The tester discovers a ROP gadget at a fixed address in a library that is not affected by ASLR. Which technique can be used to exploit this vulnerability and achieve code execution?

A.Heap spraying to predict memory layout and inject shellcode
B.Return-oriented programming (ROP) using the fixed gadgets
C.Stack canary bypass using information leak
D.Format string attack to overwrite GOT entries
AnswerB

Return-oriented programming (ROP) is the direct solution because it reuses machine code gadgets already present in the executable or its libraries, so no new code is injected and NX is never triggered. By chaining gadgets that end in 'ret', an attacker can perform arbitrary computation while maintaining control of the stack. If the binary is non-PIE or ASLR is defeated with a leak, the fixed gadget addresses are known, making the chain deterministic. This elegantly bypasses both NX and ASLR, which is why it is the correct answer.

Why this answer

Return-oriented programming (ROP) is the correct technique because ASLR and NX are both enabled, preventing direct shellcode execution and making memory addresses unpredictable. However, the tester found a ROP gadget at a fixed address in a library not affected by ASLR, allowing the construction of a chain of gadgets to achieve arbitrary code execution without needing to inject or execute shellcode on the stack.

Exam trap

The trap here is that candidates may choose heap spraying (Option A) thinking it bypasses ASLR, but they forget that NX still blocks shellcode execution, making ROP the only viable technique when fixed gadgets are available.

How to eliminate wrong answers

Option A is wrong because heap spraying is used to increase the predictability of heap memory layout for exploiting use-after-free or heap-based vulnerabilities, but it does not bypass NX (which prevents shellcode execution) and does not leverage fixed-address ROP gadgets. Option C is wrong because a stack canary bypass using an information leak addresses stack smashing protection but does not overcome NX or ASLR; it would still require a method to execute code, which ROP provides. Option D is wrong because a format string attack can overwrite GOT entries to redirect execution, but it does not inherently bypass NX or ASLR unless combined with other techniques, and the question specifies that a fixed-address ROP gadget is available, making ROP the direct and intended approach.

368
MCQmedium

A penetration tester gained low-privileged access to a Linux server and found that the user can run a custom script located at /opt/tool/backup.sh with setuid root. The script begins with a hashbang #!/bin/bash and uses an internal variable defined as BASEDIR=$(dirname $0) to determine paths. Which technique is most likely to allow privilege escalation?

A.Modify the $0 variable during execution
B.Create a malicious executable named 'dirname' in a directory earlier in the PATH
C.Overwrite /opt/tool/backup.sh with a reverse shell
D.Exploit a buffer overflow in the Bash interpreter
AnswerB

Since the script uses $(dirname $0) without an absolute path, the system searches PATH for 'dirname'. If the attacker puts a malicious 'dirname' script in a writable directory earlier in PATH, it will be executed as root.

Why this answer

The script uses `BASEDIR=$(dirname $0)` to resolve paths. If the user can place a malicious executable named `dirname` earlier in the PATH than the legitimate `/usr/bin/dirname`, then when the script runs with setuid root, the shell will execute the attacker's `dirname` binary instead, allowing arbitrary code execution as root.

Exam trap

The trap here is that candidates may focus on modifying `$0` (Option A) or overwriting the script (Option C), but the actual vulnerability lies in the insecure use of a relative command (`dirname`) within a setuid script, which allows PATH hijacking.

How to eliminate wrong answers

Option A is wrong because the `$0` variable is set by the shell to the script's path (e.g., `/opt/tool/backup.sh`) and cannot be modified by the user during execution; it is read-only in this context. Option C is wrong because the user has only low-privileged access and cannot overwrite `/opt/tool/backup.sh` (owned by root) without already having root privileges. Option D is wrong because there is no indication of a buffer overflow vulnerability in the Bash interpreter; the script is a simple shell script, and the attack vector is PATH hijacking, not memory corruption.

369
MCQeasy

A penetration tester is preparing the executive summary of a penetration test report. Which of the following BEST describes the primary audience and appropriate level of technical detail?

A.A narrative of the testing methodology for other penetration testers.
B.High-level findings and business impact for management and executives.
C.Detailed technical analysis for system administrators.
D.Step-by-step exploitation procedures for developers.
AnswerB

Executives need business risk and impact, not exploit payloads or command output. Framing findings around likelihood, affected assets and remediation cost lets non-technical decision-makers prioritise spend, satisfying the executive-summary purpose. Technical reproduction steps belong in the detailed findings section instead.

Why this answer

Option B is correct because the executive summary is written for management and executives, who need high-level findings and business impact rather than technical minutiae. This audience typically lacks deep technical background and focuses on risk, cost, and strategic decisions, so the summary should translate technical issues into business consequences. Option A is wrong because a methodology narrative for other penetration testers belongs in the technical body of the report, not the executive summary.

Option C is wrong because detailed technical analysis for system administrators is also part of the technical sections, not the executive-level overview. Option D is wrong because step-by-step exploitation procedures for developers are highly technical content inappropriate for an executive summary.

370
MCQeasy

A penetration tester is analyzing a Python script that uses the 'paramiko' library. The script reads a list of IP addresses from a file and attempts to connect to each host using the same username and a list of common passwords. Which attack technique is the script most likely performing?

A.Brute-force attack against SSH credentials
B.SQL injection attack against a database
C.Cross-site scripting (XSS) attack against a web application
D.ARP spoofing attack to intercept network traffic
AnswerA

The script leverages paramiko, a Python implementation of the SSHv2 protocol, to iterate over hosts and attempt authentication with multiple passwords. Repeating login attempts with different credential pairs against an SSH service is the textbook pattern of a brute-force attack. Unlike a single-target dictionary attack, this exhaustive trial-and-error approach may also cycle through usernames, and a successful connect call indicates valid credentials have been uncovered.

Why this answer

The script uses the 'paramiko' library, which is a Python implementation of the SSHv2 protocol. By reading a list of IP addresses and attempting connections with the same username and a list of common passwords, it is performing a brute-force attack against SSH credentials. This technique systematically tries multiple password guesses to gain unauthorized access to SSH services.

Exam trap

The trap here is that candidates may confuse the paramiko library with general network scripting and incorrectly associate it with web attacks like SQL injection or XSS, rather than recognizing it as an SSH-specific library used for credential brute-forcing.

How to eliminate wrong answers

Option B is wrong because SQL injection targets database queries via input fields, not SSH connections using paramiko. Option C is wrong because cross-site scripting (XSS) injects malicious scripts into web pages viewed by other users, and has no relation to SSH authentication attempts. Option D is wrong because ARP spoofing manipulates the Address Resolution Protocol to intercept network traffic at Layer 2, and does not involve password guessing against SSH services.

371
MCQhard

During a web application test, a tester discovers a JWT token with the following header: {'alg':'HS256','typ':'JWT'}. The token payload contains 'admin':false. The tester attempts to change the algorithm to 'none' and removes the signature. Which vulnerability is being exploited?

A.JWT brute-force
B.JWT algorithm confusion (alg:none)
C.JWT kid injection
D.JWT injection
AnswerB

JWT algorithm confusion (alg:none) occurs when a server accepts a JWT whose header declares the "alg" parameter as "none" (or "None"/"NONE"), which instructs the verifier that the token has no digital signature. An attacker can modify the token's payload, set alg to none, and remove the signature entirely; if the library does not explicitly reject none, the token is trusted as if it were properly signed. This directly bypasses signature verification without the attacker knowing any secret key.

Why this answer

JWT alg:none attack exploits servers that accept unsigned tokens. Other options are different attack types.

372
MCQmedium

In a penetration test report, the tester includes a screenshot of a successful exploit. What metadata should the screenshot include to ensure proper evidence documentation?

A.Only the exploit output without any timestamps or identifiers.
B.A timestamp and the IP address or hostname of the affected system.
C.A diagram of the network architecture instead of the exploit screenshot.
D.The tester's name and the date of the test, but not the system details.
AnswerB

Including a timestamp and the IP address/hostname of the affected system provides verifiable, reproducible proof of the finding. The timestamp lets the client correlate the event with their own logs, while the IP/hostname pinpoints the exact asset that needs remediation. This aligns with penetration test reporting standards that demand objective evidence over subjective summaries.

Why this answer

Screenshots should include timestamps and relevant context such as the affected system to provide clear evidence.

373
MCQeasy

A penetration tester is writing a report and needs to assign a severity rating to a vulnerability. Which of the following scoring systems is specifically designed to consider Damage, Reproducibility, Exploitability, Affected users, and Discoverability?

A.STRIDE
B.OWASP Risk Rating
C.CVSS
D.DREAD
AnswerD

DREAD is a risk-scoring model that ranks threats by scoring each of five categories: Damage (potential loss), Reproducibility (ease of recreating the attack), Exploitability (effort required to exploit), Affected users (number of users impacted), and Discoverability (likelihood the vulnerability is found). Each category is scored on a consistent scale (e.g., 1-10) and the scores are averaged to produce an overall risk rating. Because the question explicitly asks for the model with DREAD categories, DREAD is the correct answer.

Why this answer

The DREAD model is a risk assessment model that uses these five categories.

374
MCQmedium

During a penetration test, the tester discovers evidence of an ongoing data breach that appears to involve criminal activity unrelated to the test scope. What is the tester's primary responsibility regarding this discovery?

A.Continue the test as planned and include the findings in the final report
B.Notify the client's emergency contact and follow the agreed-upon incident response procedures
C.Document the evidence and destroy it after the engagement to protect the client
D.Immediately stop testing and notify law enforcement without client approval
AnswerB

This is the correct action because a penetration test is executed under a contractual RoE that defines an explicit escalation path for exceptional findings. The tester must activate the client's named emergency contact and follow the incident response procedures to preserve evidence, contain the situation, and coordinate any law enforcement referral through the client's legal counsel. This approach balances the tester's legal duty to report criminal activity with the client's ownership of the systems and their authority to control external communications, ensuring the response is both lawful and consistent with the engagement's scope.

Why this answer

The tester should follow the incident response plan and notify the client immediately, as handling criminal activity is a legal and ethical obligation.

375
MCQmedium

A penetration tester is performing an NTLM relay attack against a Windows network. The tester uses ntlmrelayx to relay captured NTLM authentication attempts to a target server. What must be true for this attack to succeed?

A.LLMNR must be enabled
B.The relayed hash must be crackable
C.The target server must have SMB signing enabled
D.SMB signing must be disabled or not enforced
AnswerD

For an NTLM relay attack against SMB to work, the target server must not require SMB signing, meaning signing is disabled or set to 'Not Enforced.' Without mandatory signing, the server accepts SMB packets without verifying their integrity, allowing an attacker to forward a captured NTLM authentication exchange to establish a session. This is why the correct condition is that SMB signing must be disabled or not enforced, as enforced signing blocks the relay entirely.

Why this answer

SMB signing must be disabled or not enforced on the target server, otherwise the relayed authentication will be rejected.

Page 4

Page 5 of 11

Page 6

All pages