Courseiva

CompTIA PenTest+ (PT0-003) (PT0-003) — Questions 526–600

777 questions total · 11pages · All types, answers revealed

Page 7

Page 8 of 11

Page 9
526
Multi-Selecthard

A penetration tester has gained a foothold on a Windows host and wants to escalate privileges by abusing a misconfigured Windows service. Which TWO conditions would allow the tester to escalate privileges by replacing a service binary? (Choose two.)

Select 2 answers
A.The service is configured with a delayed automatic start type on a domain-joined host
B.The service runs under the NetworkService account with SeShutdownPrivilege enabled
C.The service's DACL grants the tester SERVICE_STOP and SERVICE_START but not SERVICE_CHANGE_CONFIG
D.The service's executable path points to a directory where the tester has write permissions
E.The service's unquoted path contains a space and an earlier directory in the path is writable
AnswersD, E

If the binary a service launches resides in a folder writable by the low-privilege user, the tester can replace or overwrite it with malicious code. When the service restarts, Windows executes the attacker-controlled binary in the service's security context, typically SYSTEM, yielding privilege escalation. The writable path is the core enabling condition for binary replacement.

Why this answer

Binary-replacement escalation requires the tester to influence which executable the service runs. That happens either when the service binary sits in a directory the tester can write to, or when an unquoted path with spaces lets Windows resolve a planted file from a writable earlier directory. Both conditions let attacker code execute in the service's privileged context, while the other options concern unrelated permissions or start settings.

Exam trap

The trap here is assuming any service-related permission or start configuration enables escalation, when binary replacement strictly requires control over the executable file or its path resolution.

527
MCQmedium

A penetration tester is attempting a pass-the-hash (PtH) attack against a Windows domain-joined machine. The tester has obtained the NTLM hash of a local administrator account. Which tool can be used directly to authenticate using the hash to gain remote command execution?

A.John the Ripper
B.Metasploit's psexec module
C.Mimikatz
D.Nmap
AnswerB

Metasploit's psexec module is correct because it accepts an NTLM hash as the credential and uses it to authenticate to a Windows machine via SMB, then creates a remote service to execute an arbitrary payload. This is a direct implementation of pass-the-hash: the hash is supplied to the server in the NTLM challenge/response exchange, and no plaintext password is needed. It provides full remote code execution, making it an ideal fit for a pass-the-hash attack.

Why this answer

Metasploit's psexec module (exploit/windows/smb/psexec) directly accepts an NTLM hash via the 'SMBPass' option and uses it to authenticate over SMB, then creates a service on the target to execute commands. This is a classic pass-the-hash technique against Windows systems, as the module leverages the SMB protocol and Windows service control manager without needing the plaintext password.

Exam trap

The trap here is that candidates confuse Mimikatz's ability to perform pass-the-hash locally (spawning a cmd.exe with the hash) with the ability to directly execute commands remotely, but Mimikatz requires additional tools like PsExec or WinRM to achieve remote execution, whereas Metasploit's psexec module is a single-step solution.

How to eliminate wrong answers

Option A is wrong because John the Ripper is a password cracking tool that attempts to recover plaintext passwords from hashes, not a tool that can directly authenticate using a hash for remote command execution. Option C is wrong because Mimikatz is primarily a credential extraction and manipulation tool that can perform pass-the-hash locally (e.g., via sekurlsa::pth) to spawn a process with the hash, but it does not directly provide remote command execution against a domain-joined machine without additional steps like scheduling a remote task or using PsExec.

528
MCQmedium

A Python proof-of-concept sends repeated login attempts but does not preserve cookies between requests. The application sets a CSRF token in a session cookie. What change is most likely required for accurate testing?

A.Use a requests.Session object and refresh the CSRF token before each attempt.
B.Remove all headers from the requests.
C.Increase the payload length only.
D.Disable TLS certificate verification as the main fix.
AnswerA

A Session object persists cookies, including the session cookie, across all requests, which is essential for CSRF token validation because many frameworks bind the token to the session. Merely sending repeated POST requests without refreshing the CSRF token will cause the server to reject each attempt as the token expires or rotates after a single use. You must first GET the login form, extract the updated hidden token (e.g., with a regex or BeautifulSoup), include it in the POST body, and repeat that cycle for every attempt.

Why this answer

The proof-of-concept fails to maintain session state across requests, which is essential for handling CSRF tokens that are typically tied to a session. Using a `requests.Session` object automatically persists cookies (including the session cookie containing the CSRF token) across requests, and refreshing the CSRF token before each attempt ensures the token is valid for each login attempt, mimicking real browser behavior.

Exam trap

The trap here is that candidates may think the issue is about request headers or payload size, when the real problem is the lack of session state management (cookie persistence) and CSRF token synchronization across requests.

How to eliminate wrong answers

Option B is wrong because removing all headers would likely break the application's request handling (e.g., missing Content-Type or User-Agent), and does not address the core issue of cookie persistence or CSRF token management. Option C is wrong because increasing payload length only affects the data sent in the request body, but does not solve the problem of missing session cookies or invalid CSRF tokens, which are handled via headers and cookies, not payload size.

529
MCQmedium

A penetration tester has been given access to a network tap on a client's internal network. The tester wants to perform initial reconnaissance by identifying all live hosts and their operating systems without sending any packets that could be detected. Which technique is most appropriate?

A.Perform an ARP scan using arp-scan from a connected workstation.
B.Run Wireshark to capture traffic and analyze source IP addresses and TCP/IP stack signatures.
C.Use Nmap with the -sn flag to perform a ping sweep of the subnet.
D.Initiate a DNS zone transfer request to the internal DNS servers.
AnswerB

Wireshark placed on a network tap in promiscuous mode simply observes frames already flowing across the wire, injecting zero packets and therefore remaining invisible to detection mechanisms. By examining source IP addresses in captured traffic, the tester builds a list of live hosts that are actively communicating. Passive TCP/IP stack fingerprinting then infers the OS of each host by analyzing fields such as initial TTL, TCP window size, DF flag, and option ordering, without generating any traffic. This fully satisfies the goal of stealthy network discovery.

Why this answer

Capturing traffic with Wireshark from a network tap is entirely passive—it never injects packets into the network. By analyzing source IP addresses and TCP/IP stack signatures (e.g., TTL values, window sizes, and IP ID patterns), the tester can identify live hosts and infer their operating systems without sending any detectable traffic. This aligns perfectly with the requirement to avoid sending any packets.

Exam trap

The trap here is that candidates often assume passive techniques like packet capture cannot identify operating systems, or they mistakenly think that ARP scans and ping sweeps are 'quiet' because they use low-level protocols, forgetting that any packet injection is detectable.

How to eliminate wrong answers

Option A is wrong because an ARP scan using arp-send sends ARP request packets onto the network, which can be detected by network monitoring tools or intrusion detection systems, violating the 'no packets sent' constraint. Option C is wrong because Nmap with the -sn flag performs a ping sweep that sends ICMP echo requests, TCP SYN packets to port 443, or ARP probes (depending on privileges), all of which generate detectable network traffic.

530
MCQmedium

A penetration tester needs to perform a Kerberoasting attack against a Windows Active Directory environment. Which tool from the Impacket suite should the tester use to request service tickets and extract TGS hashes for offline cracking?

A.wmiexec.py
B.secretsdump.py
C.GetUserSPNs.py
D.psexec.py
AnswerC

GetUserSPNs.py (from Impacket) is the correct choice because it specifically enumerates user accounts registered as Service Principal Names (SPNs) and requests Kerberos service tickets for those SPNs, which are encrypted with the target user account's password-derived key. It outputs a John-the-Ripper/hashcat-ready hash that can be cracked offline to recover the plaintext password. This tool automates the full Kerberoasting workflow—querying for SPNs, requesting TGS tickets, and formatting the output—making it the canonical tool for this attack.

Why this answer

GetUserSPNs.py in the Impacket suite is used to find and request service principal names (SPNs) and retrieve TGS hashes for Kerberoasting.

531
MCQmedium

A penetration tester analyzes a PowerShell script that uses the 'Invoke-Command' cmdlet to run a command on multiple remote Windows systems. The script checks if the local Administrator account is using a default password. Which phase of the penetration test is this script most directly supporting?

A.Lateral movement
B.Credential dumping
C.Enumeration of misconfigurations
D.Privilege escalation
AnswerC

This script performs a systematic check across remote systems to determine whether the default Administrator password is still configured. That is a form of enumeration focusing on misconfigurations, specifically insecure default credentials. In the penetration testing methodology, enumeration is the active discovery of weaknesses, and verifying that a default password remains enabled is a classic example of identifying a configuration flaw without yet exploiting it for access or lateral movement.

Why this answer

The script uses Invoke-Command to check if the local Administrator account on multiple remote Windows systems uses a default password. This directly supports the enumeration of misconfigurations phase, as it identifies a common security weakness (default credentials) that could be exploited. It does not involve moving between systems (lateral movement) or extracting stored credentials (credential dumping).

Exam trap

The trap here is confusing the act of checking for default credentials (enumeration of misconfigurations) with the subsequent exploitation step (lateral movement) or the method of extracting stored credentials (credential dumping).

How to eliminate wrong answers

Option A is wrong because lateral movement involves using compromised credentials or techniques to access additional systems, not simply checking for default passwords across remote hosts. Option B is wrong because credential dumping refers to extracting password hashes or plaintext credentials from memory (e.g., using Mimikatz) or from SAM/registry hives, not testing if a known default password is still in use.

532
MCQeasy

A penetration tester has submitted the final report to the client. The client's legal team requests a separate document that describes the methodology used, but does not include any actual findings or sensitive data. Which type of document should the tester provide?

A.A new executive summary that omits the findings
B.A copy of the technical findings with redacted details
C.A document describing the testing methodology and scope
D.The remediation plan without the exploit steps
AnswerC

A methodology and scope document describes the engagement's rules of engagement, such as the approved testing techniques (e.g., credentialed network scanning, web application testing, social engineering), the target IP ranges and domains, the testing schedule, and the authorization constraints. It contains no vulnerability details, exploit paths, or compromised asset information, making it safe for legal counsel to review for contractual compliance. This document demonstrates that the tester operated within the agreed boundaries while keeping all sensitive findings separate from the legal review package.

Why this answer

The client's legal team specifically requested a document describing the methodology used without any actual findings or sensitive data. Option C, a document describing the testing methodology and scope, directly fulfills this requirement by providing a high-level overview of the penetration testing approach, tools, and boundaries, while excluding all findings, evidence, and sensitive client data. This type of document is often called a 'Methodology Statement' or 'Scope of Work' and is commonly used for legal or compliance purposes to demonstrate due diligence without exposing risk details.

Exam trap

The trap here is that candidates confuse the purpose of an executive summary (which summarizes findings) with a methodology-only document, leading them to choose Option A, but the legal team explicitly wants no findings or sensitive data, making a pure methodology document the only correct choice.

How to eliminate wrong answers

Option A is wrong because an executive summary, by definition, includes a high-level overview of the findings and risk ratings, which the legal team explicitly asked to omit. Option B is wrong because a copy of the technical findings with redacted details still contains sensitive data (even if redacted, the underlying structure and context of findings remain), and the legal team requested a document that does not include any actual findings or sensitive data at all.

533
MCQmedium

A penetration tester discovers a web application that deserializes user-controlled data without validation. The application uses Java serialization. The tester creates a malicious serialized object that executes a system command. Which of the following conditions is required for this exploit to succeed?

A.The application must be running with root privileges
B.The application must use a custom ClassLoader
C.The Java runtime must have a gadget chain available in its classpath
D.The application must be running on a Windows operating system
AnswerC

The correct precondition for a successful Java deserialization attack is the presence of one or more gadget chains—sequences of existing classes with methods that, when invoked through crafted serialized objects, perform dangerous operations like executing commands. These chains are typically found in popular third-party libraries such as Apache Commons Collections, Commons Beanutils, or Spring, which are on the application's classpath (including nested JARs or dependency directories). The runtime must be able to resolve these classes when the serialized stream triggers their methods; without them, the deserializer may only throw exceptions or create benign objects. This is why the classpath composition is the decisive factor, not OS-specific behavior, and why penetration testers aggressively enumerate dependencies to identify exploitable gadget libraries.

Why this answer

Java deserialization exploits rely on the presence of specific classes (gadget chains) in the application's classpath that can be chained together to achieve arbitrary code execution. The attacker crafts a serialized object that, when deserialized, triggers a sequence of method calls (gadget chain) that ultimately executes a system command. Without a suitable gadget chain available in the classpath, the deserialization of a malicious object will not lead to code execution.

Exam trap

CompTIA often tests the misconception that privilege escalation (root) or custom class loading is required, when in fact the core requirement is the availability of gadget chains in the classpath.

How to eliminate wrong answers

Option A is wrong because the exploit does not require root privileges; it relies on the application's own permissions and the presence of gadget chains, not on the operating system user. Option B is wrong because a custom ClassLoader is not a prerequisite for Java deserialization attacks; the exploit works with the default class loading mechanism as long as the necessary gadget classes are in the classpath.

534
MCQmedium

During a web application test, a tester discovers that the application uses JSON Web Tokens (JWT) for authentication. The tester attempts to modify the 'alg' header to 'none' and sends the token. The server accepts the forged token. Which vulnerability is being exploited?

A.kid injection
B.alg:none attack
C.Algorithm confusion
D.Weak signing secret
AnswerB

By changing the JWT header's alg parameter to 'none' (or variants like 'None' or 'NONE'), the tester instructs the server that no signing algorithm is used. If the server's token-handling logic does not strictly enforce an allowlisted set of algorithms, it may accept the token with an empty signature, effectively bypassing signature verification. This is the classic JWT 'alg none' attack, which directly manipulates the algorithm field rather than the key or secret.

Why this answer

The 'alg:none' attack exploits JWT libraries that accept tokens without verifying signatures. This allows an attacker to forge tokens. Weak secret brute-force would crack the signing key; kid injection manipulates the key ID.

535
MCQmedium

A penetration tester is exploiting a SQL injection vulnerability in a web application. They want to extract data from the database without displaying it on the page. Which SQL injection technique should they use?

A.Blind time-based SQL injection
B.Stacked queries
C.UNION-based SQL injection
D.Error-based SQL injection
AnswerA

This attack works by injecting a conditional clause that pauses the database response only when a predicate evaluates true, such as `IF(ASCII(SUBSTR((SELECT database()),1,1))>100, SLEEP(5), 0)`. Since the application never directly prints the query output, the tester infers each character by measuring response-delay differences, extracting data one bit or one character at a time without needing visible rows or error messages. It is the only technique among the choices that succeeds when the application suppresses both output and errors, which matches the scenario described.

Why this answer

Blind SQL injection techniques like time-based or boolean-based are used when data is not returned directly in the response. Time-based uses delays to infer information.

536
MCQmedium

A penetration tester is writing a Bash script to enumerate network shares on multiple Windows hosts. The script uses smbclient to list shares. Which command should be used within the script to attempt to connect to a host with a known username and password?

A.smbclient -L //host -U username%password
B.smbclient //host/share -U username%password
C.smbmap -H host -u username -p password
D.net use \\host\share /user:username password
AnswerA

The -L flag in smbclient instructs the client to list all available SMB shares on the specified server, rather than mounting a particular share. Supplying credentials with -U username%password is necessary on modern Windows systems where guest or anonymous access to the share list is typically disabled. This command is ideal for a bash enumeration script because it produces parseable output of share names, types, and comments, and it works across SMB dialects supported by the target. It is the canonical smbclient way to enumerate shares.

Why this answer

The `smbclient -L //host` command lists available shares on a remote SMB/CIFS host, and appending `-U username%password` provides the credentials for authentication. This matches the requirement to enumerate network shares on multiple Windows hosts using a known username and password within a Bash script.

Exam trap

The trap here is that candidates confuse the `-L` (list shares) option with the direct share connection syntax (`//host/share`), or they mistakenly select a different tool like `smbmap` when the question explicitly specifies using `smbclient` in the script.

How to eliminate wrong answers

Option B is wrong because `smbclient //host/share -U username%password` attempts to connect directly to a specific share (e.g., `//host/share`) rather than listing all shares, which is not the goal of enumeration. Option C is wrong because `smbmap` is a different tool (not `smbclient`) and is not the command specified in the question's context of using `smbclient` within a Bash script.

537
Multi-Selectmedium

During a web application penetration test, a tester wants to identify vulnerabilities that allow unauthorized access to internal resources. Which TWO of the following are commonly exploited to access internal services?

Select 2 answers
A.Server-side request forgery (SSRF)
B.Cross-site scripting (XSS)
C.SQL injection (SQLi)
D.Command injection
E.XML external entity (XXE) injection
AnswersA, E

SSRF is the correct answer because it directly exploits the server's ability to fetch URLs. An attacker can manipulate server-side requests to target internal addresses (127.0.0.1, 10.0.0.0/8) or cloud metadata endpoints, thus accessing resources that are not exposed to the internet. This makes SSRF the primary technique for reaching internal services from a vulnerable web application.

Why this answer

SSRF can be used to access internal services by making the server request internal IPs. XXE can also be used for SSRF by using external entities to make HTTP requests. XSS is client-side, SQLi is database, command injection is OS commands.

538
MCQmedium

A penetration tester is performing DNS reconnaissance and wants to enumerate all subdomains of a target domain by querying DNS servers in an attempt to transfer the entire zone file. Which technique is the tester using?

A.DNS zone transfer
B.DNS reverse lookup
C.DNS cache snooping
D.DNS tunneling
AnswerA

A DNS zone transfer (AXFR) is a legitimate replication mechanism that copies the entire zone file from a primary to a secondary DNS server. When misconfigured to allow unrestricted AXFR, it exposes every record in the zone, including internal host names, IP addresses, and service records, giving an attacker a complete map of the target's network. This makes it the definitive enumeration technique because it returns the full data set in one query.

Why this answer

DNS zone transfer (AXFR) is a mechanism that allows a secondary DNS server to replicate the entire zone file from a primary server. If misconfigured, anyone can request it.

539
Multi-Selecteasy

A penetration tester needs to perform initial reconnaissance on a target domain. Which of the following tools are specifically designed for domain enumeration? (Select TWO).

Select 2 answers
A.Wireshark
B.Metasploit
C.theHarvester
D.Netcat
E.recon-ng
AnswersC, E

theHarvester harvests emails, subdomains, hosts and employee names from public sources such as search engines and certificate transparency logs, performing passive OSINT against a target domain. It requires no prior credentials, matching the initial reconnaissance constraint of enumerating domain assets without touching the target directly.

Why this answer

theHarvester (C) is specifically designed for domain enumeration, as it gathers emails, subdomains, hosts, employee names, open ports, and banners from public sources like search engines and PGP key servers. recon-ng (E) is a full-featured web reconnaissance framework whose modules perform domain enumeration tasks such as subdomain discovery, DNS lookups, and contact harvesting. Wireshark (A) is a packet capture and protocol analyzer used for traffic inspection, not domain enumeration. Metasploit (B) is an exploitation framework, and while it has auxiliary scanning modules, it is not specifically designed for domain enumeration.

Netcat (D) is a general-purpose networking utility for reading/writing TCP/UDP connections, not a domain enumeration tool.

540
MCQmedium

During a penetration test, a tester gains shell access on a Linux server as a low-privileged user. The user is identified to be a member of the 'docker' group. Which technique is most effective for escalating privileges to root?

A.Use docker to mount the entire host filesystem and modify the root password.
B.Use docker to run a container with network host mode to access internal services.
C.Use docker to pull a malicious image from the internet to compromise other containers.
D.Use docker to create a new user with root privileges inside a container.
AnswerA

Running 'docker run -v /:/mnt -it ubuntu bash' mounts the host root filesystem. From inside the container, the attacker can chroot to /mnt and modify /etc/shadow or add an SSH authorized key, gaining full root access.

Why this answer

Membership in the 'docker' group grants the user effective root-equivalent access because the Docker daemon runs as root and allows any member of the 'docker' group to issue commands that can mount arbitrary host paths. By running a container with the host filesystem mounted (e.g., `docker run -v /:/mnt --privileged -it alpine chroot /mnt`), the tester can directly modify the `/etc/shadow` file or the root password, thereby escalating privileges to root without needing any additional exploit.

Exam trap

The trap here is that candidates may think Docker group membership only allows container management or network manipulation, overlooking the fact that the Docker socket grants full root-equivalent file system access via volume mounts.

How to eliminate wrong answers

Option B is wrong because using network host mode (`--network host`) only gives the container access to the host's network stack, which might help with lateral movement or service discovery but does not provide a mechanism to escalate privileges to root on the host itself. Option C is wrong because pulling a malicious image from the internet could compromise other containers or the host if the image exploits a vulnerability, but it is not a reliable or direct method for privilege escalation; the most effective and immediate technique is to mount the host filesystem and modify authentication files.

541
MCQhard

A penetration tester is compiling evidence for a critical-severity SQL injection vulnerability. Which of the following is the most important piece of evidence to include in the report to demonstrate exploitability while remaining responsible?

A.A video of the full exploitation process, including data extraction.
B.A screenshot of the database table with all user credentials.
C.Raw network captures showing SQL injection attempts.
D.A proof-of-concept script that retrieves the current database user (e.g., 'SELECT user()').
AnswerD

A proof-of-concept that executes `SELECT user()` and prints the returned value is the gold standard because it demonstrates full control of the SQL query with a single, non-sensitive result. This proves the injection is exploitable without exposing any business data, keeping the evidence safe for the report and compliant with the rules of engagement. The concise output is easy to validate and provides a direct, repeatable demonstration for the client.

Why this answer

Proof-of-concept code should demonstrate the vulnerability without causing harm or exposing sensitive data.

542
MCQmedium

A penetration tester is using Nmap to identify the operating system of a target host. Which Nmap option should be used to enable OS detection?

A.-sV
B.-O
C.-sC
D.-A
AnswerB

-O is the correct answer because it is the dedicated Nmap flag for operating system detection. This option works by sending specially crafted TCP and UDP probes to the target and comparing the responses against Nmap's large database of OS fingerprints, thereby identifying the likely operating system. It is the precise, purpose-built switch for this task, unlike broader or unrelated flags.

Why this answer

The -O option enables OS detection in Nmap.

543
MCQmedium

A penetration tester is analyzing a Python script used during a test. The script contains the following code: 'import requests; r = requests.get('http://target', headers={'User-Agent': 'Mozilla/5.0'}); print(r.text)'. What is the primary purpose of setting the User-Agent header in this script?

A.To bypass IP-based rate limiting.
B.To mimic a legitimate browser to evade detection by web application firewalls.
C.To authenticate to the web server.
D.To enable SSL/TLS encryption.
AnswerB

The User-Agent header sets the client string sent with the HTTP request; using a Mozilla/5.0 value makes requests appear to originate from a standard browser rather than the requests library. This satisfies the stem's purpose of evading web application firewall detection.

Why this answer

Setting the User-Agent header to 'Mozilla/5.0' makes the HTTP request appear to originate from a standard web browser rather than a Python script. This helps evade detection by web application firewalls (WAFs) and other security controls that may block or flag requests with non-browser User-Agent strings, which are common indicators of automated or malicious traffic.

Exam trap

The trap here is that candidates may confuse the User-Agent header with mechanisms that affect rate limiting or authentication, when in fact it is purely a client identification field used for evasion and content negotiation.

How to eliminate wrong answers

Option A is wrong because the User-Agent header does not affect IP-based rate limiting, which is enforced by the server based on the source IP address, not the User-Agent string. Option C is wrong because authentication to a web server typically requires credentials (e.g., via HTTP Basic Auth, tokens, or cookies), not a User-Agent header; the User-Agent is merely a client identification string defined in RFC 7231.

544
MCQmedium

A tester finds that a web application is vulnerable to Server-Side Request Forgery (SSRF). The tester wants to access the cloud metadata endpoint to obtain instance credentials. Which IP address is commonly used for the cloud metadata service?

A.127.0.0.1
B.10.0.0.1
C.192.168.1.1
D.169.254.169.254
AnswerD

169.254.169.254 is the well-known link-local address used by major cloud providers (AWS, GCP, Azure, and others) to expose instance metadata, such as credentials, userdata, and network configuration. The address falls within the 169.254.0.0/16 APIPA block, making it non-routable and automatically reachable only from the instance itself. Because many cloud configurations historically permitted unauthenticated HTTP requests to this endpoint, it is the classic target for SSRF attacks, prompting cloud providers to introduce IMDSv2 with mandatory token-based access.

Why this answer

The cloud metadata endpoint is typically at 169.254.169.254 for AWS, GCP, and Azure.

545
MCQeasy

A penetration tester is analyzing a Python script that uses the 'socket' module to create a TCP connection to a target IP and port. The script then sends a payload (e.g., 'GET / HTTP/1.0\r\n\r\n') and waits for a response. Which tool function is this script most likely performing?

A.Port scanning
B.Banner grabbing
C.Vulnerability scanning
D.Password cracking
AnswerB

Banner grabbing is the active retrieval of a service's identity by sending a connection or request and observing the returned greeting or header, such as an HTTP Server header. In this script, sending a crafted payload and reading the subsequent response is precisely the mechanism used to capture the service banner, which reveals the software and version. This is a foundational reconnaissance step for later vulnerability research, but the single request-response exchange itself performs banner grabbing.

Why this answer

The script creates a TCP connection, sends an HTTP GET request, and waits for a response. This is the classic behavior of banner grabbing, where the goal is to retrieve the service banner (e.g., HTTP server version) from the target. The 'socket' module is used to manually craft the connection and payload, which is a low-level technique for service identification, not for scanning multiple ports or assessing vulnerabilities.

Exam trap

The trap here is that candidates may confuse banner grabbing with port scanning because both involve connecting to a port, but banner grabbing focuses on service identification from a single connection, not enumeration of open ports.

How to eliminate wrong answers

Option A is wrong because port scanning involves iterating over multiple ports to discover open ones, whereas this script targets a single IP and port. Option C is wrong because vulnerability scanning requires checking for known weaknesses (e.g., via a database of CVEs) and often uses automated tools like Nessus, not a simple socket connection sending a static HTTP request.

546
MCQmedium

A penetration tester wants to perform a directory brute-force attack against a web server to discover hidden files and directories. Which tool is best suited for this task?

A.WPScan
B.Nikto
C.Gobuster
D.Nmap
AnswerC

Gobuster is a purpose-built content discovery tool for brute-forcing directories, files, DNS subdomains, and virtual hosts. It loads a wordlist and sends HTTP requests to the target, distinguishing valid resources by filterable response status codes (e.g., 200, 301, 403) and configurable patterns. Its multi-threading, support for file extensions, wildcard detection, and performance make it the standard choice for directory brute-forcing in penetration tests.

Why this answer

Gobuster is a popular tool for directory and file brute-forcing using wordlists, making it ideal for discovering hidden resources on web servers.

547
MCQmedium

A penetration tester is about to start an engagement. Which document outlines the IP ranges that are in scope, the testing window, and the emergency stop criteria?

A.Non-Disclosure Agreement (NDA)
B.Statement of Work (SOW)
C.Rules of Engagement (RoE)
D.Get-out-of-jail letter
AnswerC

The RoE is the authoritative operational document that directly defines the technical constraints and legal boundaries of the penetration test. It includes the exact authorized IP ranges/networks, permitted testing times (including any blackout windows), allowed test types (e.g., active exploitation, social engineering), handling of sensitive data, and specific stop conditions or escalation paths if critical systems fail. Unlike the NDA or SOW, the RoE is the document testers must consult minute-to-minute to ensure every action is authorized and safe.

Why this answer

The rules of engagement (RoE) specify technical and procedural boundaries for the test.

548
MCQmedium

A client requests a penetration test of their internal network. During scoping, the tester learns that the client uses a managed security service provider (MSSP) that monitors all network traffic. The client does not want the MSSP to be informed about the test. What is the most appropriate action for the tester to take?

A.Proceed with the test without informing the MSSP, as the client has requested confidentiality
B.Include a clause in the rules of engagement that holds the tester harmless for any disruptions caused by the MSSP's monitoring
C.Advise the client to inform the MSSP about the scheduled test and coordinate a maintenance window or exclusion list
D.Perform the test only after hours to minimize the chance of the MSSP detecting the test activity
AnswerC

Advising the client to inform the MSSP and coordinate a maintenance window or exclusion list is the correct approach because it allows the MSSP to create a temporary allow list for the test's source IPs, domains, and tool signatures. This suppresses expected alerts, prevents unnecessary incident response, and ensures the SOC can distinguish legitimate test traffic from true threats. It also establishes a deconfliction contact so both parties can respond quickly if unexpected activity arises, aligning with standard scoping and rules of engagement practices.

Why this answer

Failing to inform the MSSP could trigger automated incident response actions (e.g., IPS blocking, SIEM alerting, or even network isolation) that disrupt the test and potentially cause false-positive security incidents. Coordinating a maintenance window or exclusion list ensures the MSSP's monitoring tools (like Snort, Suricata, or proprietary NDR) do not interfere with legitimate test traffic, preserving both test integrity and the client's operational security.

Exam trap

The trap here is that candidates assume client confidentiality overrides all other considerations, but the PT0-002 exam emphasizes that penetration testing must not cause unintended operational disruptions or violate third-party agreements, making coordination with the MSSP a mandatory scoping step.

How to eliminate wrong answers

Option A is wrong because proceeding without informing the MSSP violates standard penetration testing best practices and could cause the MSSP's monitoring systems (e.g., IDS/IPS, SIEM correlation rules) to flag the test traffic as malicious, leading to automated blocking, alert fatigue, or unnecessary escalation to the client's security team. Option B is wrong because a hold-harmless clause does not prevent the MSSP from actively blocking or alerting on test traffic; it only shifts liability after disruption occurs, which still compromises the test's accuracy and may violate the MSSP's own terms of service or SLAs.

549
MCQmedium

A penetration tester is conducting a vulnerability scan of a network segment that contains several legacy servers. The tester uses a commercial vulnerability scanner with default settings. The scan completes and reports a critical vulnerability on a server running an outdated version of Apache with known remote code execution. However, the tester suspects this might be a false positive because the server is behind an application-layer firewall that blocks the specific exploit. Which of the following steps should the tester take to confirm the vulnerability?

A.Rerun the scan with increased intensity to ensure the vulnerability is real
B.Ignore the finding because the vulnerability is protected by the firewall
C.Manually test the vulnerability by sending a crafted exploit payload to the server
D.Check the firewall logs to see if the scanner's traffic was blocked
AnswerC

The application-layer firewall may block the exploit, so scanner output alone is inconclusive. Sending a crafted payload manually tests whether the remote code execution actually succeeds through the filtering, confirming or disproving the reported vulnerability.

Why this answer

The correct option is C: manually test the vulnerability by sending a crafted exploit payload to the server. This is the only way to confirm whether the reported Apache RCE is actually exploitable in this scenario, since a vulnerability scanner's default settings can produce false positives and an application-layer firewall may block the exploit even if the underlying service is vulnerable. Manual exploitation validates the finding end-to-end rather than relying on scanner signatures or assumptions.

Option A is wrong because increasing scan intensity does not prove exploitability and may still be blocked or produce the same signature-based result. Option B is wrong because a firewall blocking one exploit path does not mean the vulnerability is absent or unexploitable via other vectors. Option D is wrong because firewall logs only show whether the scanner's traffic was blocked, not whether the vulnerability itself is real or exploitable.

550
MCQhard

A penetration tester is analyzing the output of a Nessus vulnerability scan and notices a critical vulnerability reported against a web server that is actually a false positive due to outdated plugin data. What is the best course of action for the tester?

A.Accept the finding as accurate and include it in the report
B.Remove the finding from the report entirely
C.Manually verify the vulnerability by testing it
D.Ignore the finding because it's a false positive
AnswerC

Manual verification entails actively reproducing the vulnerability—e.g., sending a crafted HTTP request to confirm a SQL injection, or checking if a specific CVE applies by reviewing patch levels and exploiting the target in a controlled manner. This step distinguishes real security gaps from false positives generated by the scanner, and also collects proof-of-concept evidence necessary for a credible, actionable penetration test report.

Why this answer

A false positive due to outdated plugin data must be manually verified before any action is taken. The tester should use a tool like `curl` or a browser to send the exact request that Nessus simulated (e.g., an HTTP GET to a specific endpoint) and inspect the response headers or body to confirm whether the vulnerability actually exists. Only after manual validation can the tester decide to include, exclude, or note the finding in the report.

Exam trap

The trap here is that candidates may think a false positive should be removed or ignored outright, but the correct approach is to manually verify the finding to ensure the vulnerability is truly absent before making any reporting decision.

How to eliminate wrong answers

Option A is wrong because blindly accepting a known false positive would introduce inaccurate risk into the report, potentially causing unnecessary remediation efforts. Option B is wrong because removing the finding entirely without documentation violates reporting integrity; the tester should note the false positive and the manual verification steps taken. Option D is wrong because ignoring the finding without verification could miss a real vulnerability if the plugin data was outdated but the vulnerability still exists in a different form.

551
MCQhard

A penetration tester is conducting a wireless security assessment. The target network uses WPA2-PSK. The tester has captured the four-way handshake. Which tool from the Aircrack-ng suite can be used to attempt to recover the pre-shared key by performing a dictionary attack?

A.airtun-ng
B.aircrack-ng
C.airodump-ng
D.aireplay-ng
AnswerB

aircrack-ng is the core cryptanalysis tool that takes captured 802.11 traffic and recovers wireless encryption keys. For WEP, it applies the PTW or KoreK/FMS attacks once enough IVs have been collected; for WPA/WPA2, it performs a dictionary or brute-force attempt against the MIC computed during the 4-way EAPOL handshake. It validates the correct key by matching the passphrase-specific PMK to the handshake's MIC, making it the exact utility needed to complete the cracking objective.

Why this answer

Aircrack-ng is the tool within the suite that performs dictionary or brute-force attacks on captured WPA/WPA2 handshakes to recover the PSK.

552
MCQmedium

A tester wants to identify the technologies used by a web application before conducting a deeper assessment. Which tool would be most appropriate for passive technology fingerprinting?

A.Nmap
B.Wappalyzer
C.OpenVAS
D.Nikto
AnswerB

Wappalyzer is a browser extension and library that performs passive technology fingerprinting by inspecting HTTP response headers (e.g., X-Powered-By, Set-Cookie), HTML meta tags, script sources, and other client-side content returned by the web application. It does not send a single request to the target beyond what the browser itself makes, so it identifies frameworks, CMSs, analytics tools, and server software entirely from normal page loads. This makes it the correct tool for passive identification in this scenario.

Why this answer

Wappalyzer is a browser extension or online tool that identifies web technologies (CMS, frameworks, analytics) by analyzing page content and headers without sending probes.

553
Multi-Selecthard

During a cloud security assessment of AWS, a tester wants to identify misconfigurations using automated tools. Which THREE tools are specifically designed for AWS security auditing?

Select 3 answers
A.Hashcat
B.Pacu
C.Prowler
D.CrackMapExec
E.ScoutSuite
AnswersB, C, E

Correct: AWS exploitation framework.

Why this answer

Pacu is an open-source AWS exploitation framework designed for offensive security testing. It automates the identification of misconfigurations, such as overly permissive IAM policies, exposed S3 buckets, and vulnerable Lambda functions, making it a correct choice for cloud security auditing.

Exam trap

CompTIA often tests candidates' ability to distinguish between general-purpose security tools (like Hashcat for cracking) and cloud-specific auditing tools (like Pacu, Prowler, and ScoutSuite), leading to confusion when tools have overlapping names or functions.

554
MCQeasy

A penetration tester is preparing the final report. The client's IT director wants a high-level overview of the test results, including the number of findings and the overall risk rating. Which section of the report should the tester point to?

A.Executive summary
B.Technical findings
C.Methodology
D.Recommendations
AnswerA

The executive summary is intentionally crafted as a concise, high-level overview for management, translating technical vulnerabilities into business risk and strategic impact. It highlights the most critical findings, overall risk posture, and key remediation priorities without technical jargon or raw data. This ensures decision-makers can quickly grasp the urgency and allocate resources appropriately, making it the correct section for the client's request.

Why this answer

The executive summary is specifically designed to provide a high-level overview for management and non-technical stakeholders, such as the IT director. It summarizes the number of findings, overall risk rating, and key business impacts without delving into technical details, making it the correct section for this request.

Exam trap

The trap here is that candidates often confuse the 'executive summary' with the 'technical findings' section, mistakenly thinking a high-level overview belongs in the detailed technical results, but the exam expects you to recognize that management-focused summaries are always in the executive summary.

How to eliminate wrong answers

Option B is wrong because the technical findings section contains detailed vulnerability descriptions, proof-of-concept code, and remediation steps, which is too granular for a high-level overview. Option C is wrong because the methodology section describes the testing approach, tools, and scope, not the summary of results or risk ratings.

555
MCQeasy

A client wants to conduct a penetration test of their e-commerce website. They are concerned about impacting live transactions. Which clause should be included in the Rules of Engagement to address this?

A.Exclusion of network stress testing and availability testing.
B.Out-of-scope systems list.
C.In-scope IP addresses.
D.Authorization for testing.
AnswerA

An exclusion of network stress testing and availability testing directly protects the live e-commerce infrastructure by prohibiting load simulation, distributed denial-of-service (DDoS) emulation, resource-exhaustion attempts, and any technique designed to consume bandwidth, CPU, memory, or connection state. This clause constrains the testing methodology itself, ensuring the tester still can evaluate injection flaws, auth issues, and business logic while leaving transactional capacity unscathed. It is the only option that specifically addresses the client's concern about service impact rather than merely defining targets.

Why this answer

The client's primary concern is avoiding disruption to live transactions. A clause excluding network stress testing and availability testing (e.g., DoS attacks, resource exhaustion, or high-volume scanning) directly addresses this by prohibiting any action that could degrade performance or cause downtime. This is a standard Rules of Engagement (RoE) safeguard for production e-commerce environments where transaction integrity and uptime are critical.

Exam trap

The trap here is that candidates often confuse 'out-of-scope systems' with operational restrictions, failing to realize that even in-scope systems can be disrupted by stress testing, so a specific exclusion clause is required.

How to eliminate wrong answers

Option B is wrong because an out-of-scope systems list defines which hosts or networks are off-limits, but it does not specifically prohibit stress or availability testing on in-scope systems; the client's concern is about impacting live transactions on the target e-commerce site, not about accessing unrelated systems. Option C is wrong because listing in-scope IP addresses merely identifies the targets for testing, but it does not include any operational restrictions; without an explicit clause against stress testing, the tester could still perform disruptive actions on those IPs, violating the client's requirement.

556
MCQeasy

Which of the following is the most appropriate evidence to include in a penetration testing report for a SQL injection vulnerability?

A.A verbal description of the exploit
B.Screenshots of the successful injection with timestamps
C.A link to a public exploit database
D.Raw source code of the application
AnswerB

Timestamped screenshots constitute definitive proof of exploitability because they capture the exact injection payload, the targeted parameter, and the resulting application response or database error, demonstrating the impact in real time. The timestamp establishes a verifiable audit trail, and the visual record allows the client to confirm the finding, prioritize remediation, and satisfy evidence requirements for regulatory compliance or insurance claims.

Why this answer

Screenshots with timestamps provide clear visual evidence of the exploitation and help validate the finding.

557
MCQhard

You are conducting a penetration test on a web application that uses a JavaScript challenge-response authentication mechanism. During testing, you notice that the client-side JavaScript code is heavily obfuscated and includes a function that seems to compute a token based on user input and a server-provided nonce. Your goal is to bypass the authentication by generating valid tokens without interacting with the server's intended logic. You have extracted the obfuscated JavaScript and used a beautifier to make it more readable, but the logic is still complex. Which of the following approaches is most likely to succeed in bypassing the authentication?

A.Capture a valid token and replay it with a new nonce
B.Use a JavaScript debugger to dynamically analyze the obfuscated function and replicate its token generation
C.Send random tokens to the server and rely on statistical guessing
D.Use a brute-force script to try all possible token values based on the nonce
AnswerB

Using a JavaScript debugger lets you set breakpoints inside the obfuscated token-generation function to inspect its runtime state, step through the algorithm, and extract the exact logic and any embedded secrets. By walking the call stack and examining variable values, you can determine how the token is derived from the nonce and other inputs. Once the algorithm is understood, you can write a standalone script that produces valid tokens on demand, effectively defeating the client-side obfuscation.

Why this answer

Option B is correct because dynamic analysis with a JavaScript debugger lets you set breakpoints, inspect runtime variables, and step through the obfuscated token-generation function, revealing the exact algorithm and inputs needed to replicate valid tokens offline without invoking the server's intended logic. This is the most reliable approach against obfuscated client-side challenge-response code, since static beautification alone often leaves control flow and string transformations unclear. Option A fails because a token is typically bound to a specific nonce, so replaying it with a new nonce will not validate.

Option C is impractical because token entropy makes random guessing statistically infeasible. Option D is also infeasible because brute-forcing all token values based on the nonce is computationally prohibitive for any reasonably sized token space.

558
MCQeasy

Which PowerShell script is commonly used for post-exploitation enumeration of Active Directory, such as querying user accounts and group memberships?

A.Nishang
B.Empire
C.Invoke-Mimikatz
D.PowerView
AnswerD

PowerView is a PowerShell script—part of the PowerSploit project—that provides a suite of cmdlets for Active Directory reconnaissance, including Get-DomainUser, Get-DomainGroup, Find-DomainAdmin, and Get-DomainACL. It queries LDAP (and sometimes other AD services) to map the domain, identify privileged accounts, and reveal relationships that aid lateral movement. This makes it the standard tool for AD enumeration during post-exploitation, matching the question's intent.

Why this answer

PowerView (option D) is a PowerShell script within the PowerSploit framework specifically designed for post-exploitation enumeration of Active Directory. It provides cmdlets like Get-NetUser, Get-NetGroup, and Get-NetComputer to query user accounts, group memberships, and domain trust relationships via LDAP queries, making it the correct choice for this task.

Exam trap

The trap here is that candidates confuse post-exploitation frameworks (Empire) or credential-dumping tools (Invoke-Mimikatz) with the specific script designed for AD enumeration, or they assume Nishang's broad toolkit includes dedicated AD enumeration, when PowerView is the precise answer for querying user accounts and group memberships.

How to eliminate wrong answers

Option A (Nishang) is wrong because it is a collection of PowerShell scripts for penetration testing and offensive security, but it focuses on broader tasks like reverse shells, keylogging, and data exfiltration, not specifically on Active Directory enumeration. Option B (Empire) is wrong because it is a post-exploitation framework that uses PowerShell agents for command and control, but it is not a single script; it relies on modules like PowerView for AD enumeration, so it is not the script itself. Option C (Invoke-Mimikatz) is wrong because it is a PowerShell wrapper for Mimikatz, which extracts credentials (e.g., plaintext passwords, Kerberos tickets) from memory, not for querying AD user accounts or group memberships.

559
MCQmedium

Refer to the exhibit. A penetration tester obtains this output from a Linux server. The tester notes that port 3389 is typically used for RDP on Windows. Which of the following is the MOST likely explanation?

A.The server has been compromised and is used as a jump box
B.The server is running a honeypot mimicking RDP
C.The server is running a Windows virtual machine using RDP
D.The server is running a service that mimics RDP using xrdp
AnswerD

xrdp is an open-source RDP server for Linux that listens on TCP 3389, letting the Linux host accept RDP clients. Its presence explains an RDP-typical port on a non-Windows system, matching the exhibit's Linux output.

Why this answer

The correct answer is D: the server is running a service that mimics RDP using xrdp. xrdp is an open-source RDP server for Linux that listens on TCP port 3389, so seeing 3389 open on a Linux host is most likely explained by xrdp providing an RDP-compatible remote desktop service. Option A is speculative and not supported merely by an open port, option B is unlikely without honeypot-specific evidence, and option C is inconsistent because a Windows VM would not make the underlying Linux server itself expose RDP on 3389.

560
MCQmedium

A penetration tester is reviewing a Bash script that uses 'nmap' with the '-sC' and '-sV' flags. The script runs the scan and saves the output to a text file. Later, the tester uses 'grep' to extract lines containing 'open'. What is the primary purpose of this script?

A.Identify all open ports and services running on them
B.Perform a vulnerability scan using NSE scripts
C.Detect the operating system of the target
D.Perform a stealthy SYN scan
AnswerA

The command combines `-sC` (default NSE scripts) with `-sV` (service/version detection), and the pipeline's grep step filters the output for open ports and associated service banners. This is a standard reconnaissance technique to enumerate listening TCP services, which is exactly what the correct answer describes. Default scripts augment version data with service-specific details, but the primary goal is mapping the attack surface, not deep vulnerability assessment.

Why this answer

The '-sC' flag runs default NSE scripts (which perform service enumeration and basic checks), and '-sV' enables version detection. Together, they identify open ports and the services/versions running on them. The subsequent 'grep' for 'open' extracts lines showing open ports, confirming the primary purpose is to enumerate open ports and their associated services.

Exam trap

CompTIA often tests the distinction between default NSE scripts (service enumeration) and vulnerability-specific scripts (e.g., 'vuln'), leading candidates to mistakenly think '-sC' implies vulnerability scanning.

How to eliminate wrong answers

Option B is wrong because '-sC' runs default NSE scripts, not a full vulnerability scan; vulnerability scanning typically requires specific NSE scripts like 'vuln' or '-sV' with '--script vuln'. Option C is wrong because OS detection requires the '-O' flag, which is not used in this script; '-sC' and '-sV' do not perform OS fingerprinting.

561
MCQmedium

After completing a penetration test, the tester must deliver a report. According to standard practices, which of the following is a required component of the deliverables?

A.Executive summary, technical findings, and remediation guidance
B.Remediation guidance and a list of all tested IPs
C.Only technical findings and proof-of-concept code
D.Executive summary and raw data logs
AnswerA

A penetration test report must communicate risk to both business and technical audiences. The executive summary conveys impact to leadership, technical findings document exploited vulnerabilities with evidence, and remediation guidance tells the client how to fix them, satisfying the deliverable's dual-audience requirement.

Why this answer

A typical penetration test report includes an executive summary, technical findings, and remediation guidance.

562
MCQeasy

A penetration tester runs the following command: `hashcat -m 1000 -a 0 hashes.txt rockyou.txt`. What type of attack is being performed?

A.Brute-force attack
B.Hybrid attack
C.Rule-based attack
D.Dictionary attack
AnswerD

This is correct because Hashcat's -a 0 attack mode is the dictionary attack, where each word from a wordlist is tried as a password candidate. The -m parameter specifies the hash type (e.g., -m 0 for MD5), and the command relies solely on the supplied wordlist rather than generating combinations. Dictionary attacks are often the first choice in penetration testing because they exploit common and weak passwords efficiently.

Why this answer

The command uses mode 1000 (NTLM) and attack mode 0 (dictionary) with rockyou.txt wordlist. This is a dictionary attack.

563
Multi-Selecthard

A penetration tester discovers a critical vulnerability that cannot be fully remediated immediately. The client asks for recommendations. Which THREE of the following should the tester include?

Select 3 answers
A.Implement compensating controls to reduce risk.
B.Prioritize remediation of this vulnerability first.
C.Delete the finding from the report.
D.Offer to retest after remediation is applied.
E.Ignore the vulnerability until the next test.
AnswersA, B, D

When a critical vulnerability cannot be patched immediately, implementing compensating controls—such as a web application firewall (WAF) rule to block exploit payloads, network segmentation to limit lateral movement, or additional authentication requirements—provides an interim layer of risk reduction. These controls do not remove the underlying flaw but reduce the likelihood of successful exploitation while a permanent fix is developed. This is a proactive and accepted practice in vulnerability management, as it buys time without leaving the asset fully exposed.

Why this answer

When full remediation is not possible, recommend compensating controls, prioritize critical fixes, and offer retesting.

564
MCQmedium

During a penetration test, the tester wants to discover publicly exposed IoT devices related to the target organization. Which OSINT tool is specifically designed for searching devices connected to the internet?

A.Censys
B.Shodan
C.Maltego
D.theHarvester
AnswerB

Shodan is the correct answer because it is a dedicated search engine for internet-connected devices. It works by scanning the entire IPv4 (and IPv6) address space and indexing the banners returned by services like HTTP, SSH, FTP, and Telnet. Penetration testers use Shodan to quickly identify public-facing devices, exposed industrial control systems, and services running on unusual ports, making it the industry-standard tool for internet-facing device discovery.

Why this answer

Shodan is a search engine that indexes banners from internet-connected devices, including IoT, webcams, routers, and industrial control systems.

565
Multi-Selecthard

A penetration tester is performing active reconnaissance on a web application and needs to discover parameters that the application accepts. Which TWO tools are most commonly used for parameter discovery? (Select TWO.)

Select 2 answers
A.ffuf
B.theHarvester
C.WPScan
D.Nikto
E.Arjun
AnswersA, E

ffuf performs fuzzing by substituting wordlist entries into request positions, detecting accepted parameters through response differences in status codes, length or reflection. This directly satisfies the stem's requirement to discover parameters the application accepts during active reconnaissance, using its `-w` wordlist and filter flags to isolate valid hits.

Why this answer

ffuf (A) is correct because it is a fast web fuzzer that can brute-force URL parameters, directories, and POST data using wordlists, making it a standard tool for parameter discovery during active reconnaissance. Arjun (E) is correct because it is purpose-built for HTTP parameter discovery, using a large built-in wordlist and heuristics to find hidden GET/POST parameters efficiently. theHarvester (B) is not correct because it focuses on OSINT gathering of emails, subdomains, and hosts from public sources rather than discovering application parameters. WPScan (C) is not correct because it targets WordPress-specific vulnerabilities and enumeration, not generic parameter discovery.

Nikto (D) is not correct because it is a web server scanner for misconfigurations and known issues, not a parameter brute-forcing tool.

Exam trap

In the CompTIA Pentest+ context, the trap is that candidates often confuse general-purpose web scanners (like Nikto) or CMS-specific tools (like WPScan) with dedicated parameter discovery tools, leading them to select options that perform different reconnaissance tasks.

566
MCQeasy

A penetration tester is preparing for a social engineering engagement. The client has requested that the tester attempt to gain access to the building by impersonating a delivery person. Which of the following should the tester obtain from the client before conducting the test?

A.A copy of the client's security policy
B.A non-disclosure agreement (NDA)
C.A list of employee names and phone numbers
D.A get-out-of-jail letter
AnswerD

The get-out-of-jail letter is essential for physical social engineering engagements. It authorizes the tester to be on the premises and protects them from legal action if they are caught impersonating a delivery person. It should be signed by an authorized client representative and kept on the tester's person during the engagement. This document is critical for legal protection and proof of authorization.

Why this answer

For physical social engineering engagements, the tester must obtain a get-out-of-jail letter from the client. This document authorizes the tester to be on the premises and protects them from legal action if they are caught. It is essential for legal protection and should be carried at all times during the engagement.

Other documents like NDAs or security policies do not provide this authorization.

Exam trap

The trap here is thinking that an NDA or security policy is sufficient, but only the get-out-of-jail letter authorizes physical entry and protects against trespassing charges.

567
MCQeasy

A penetration tester wants to identify all publicly accessible Amazon S3 buckets that belong to a specific organization. Which technique is most effective for passive reconnaissance?

A.Use Google dorks to search for bucket names and URLs.
B.Send DNS queries for common bucket name prefixes.
C.Use nmap to scan all AWS IP ranges for open ports.
D.Perform a DNS zone transfer on the target organization's domain.
AnswerA

Google dorking is a passive reconnaissance technique that leverages search engines' indexed data to find publicly exposed S3 bucket names embedded in URLs (e.g., site:s3.amazonaws.com combined with company keywords). Because it queries Google's cache rather than accessing AWS or the target's infrastructure directly, it leaves no trace in target logs and is ideal for stealthy initial enumeration.

Why this answer

Google dorks (e.g., site:s3.amazonaws.com "companyname") allow a penetration tester to passively discover publicly accessible S3 bucket names and URLs indexed by search engines without sending any traffic to the target organization. This technique leverages existing search engine caches, making it purely passive and highly effective for identifying misconfigured buckets that have been crawled.

Exam trap

CompTIA often tests the distinction between passive and active reconnaissance, and the trap here is that candidates confuse DNS queries (which are active) with passive techniques like search engine dorking, or assume that scanning IP ranges is a valid way to discover S3 buckets when in reality S3 buckets are identified by their DNS names, not by port scanning.

How to eliminate wrong answers

Option B is wrong because sending DNS queries for common bucket name prefixes (e.g., companyname-bucket.s3.amazonaws.com) is an active reconnaissance technique that generates DNS traffic and can be logged by the organization's DNS servers or AWS, violating the passive nature required. Option C is wrong because nmap scanning of AWS IP ranges is active reconnaissance that sends packets to AWS infrastructure, potentially triggering alerts, and S3 buckets are accessed via HTTPS on port 443, not by scanning for open ports on arbitrary IPs.

568
MCQeasy

A penetration testing firm is contracted to test a multi-tenant SaaS application. During scoping, the client needs to ensure that testing does not affect other tenants' data. Which scoping control is most important to implement?

A.Isolated testing environment
B.Data anonymization
C.Signed waiver from all tenants
D.Limit test to read-only operations
AnswerA

An isolated testing environment is the correct technical control for multi-tenant engagements because it establishes a hard boundary between the test scope and production tenants. By using separate VLANs, dedicated cloud accounts, or physically separate infrastructure, the penetration tester can safely perform resource-intensive or destructive tests (e.g., DoS, exploitation) without risking cross-tenant data exposure or availability degradation. This isolation is a preventive technical measure that directly addresses the inherent risk of shared multi-tenant infrastructure, unlike legal or procedural safeguards.

Why this answer

An isolated testing environment is the most important scoping control because it ensures that the penetration testing activities, including any potentially disruptive scans or exploits, are contained within a dedicated instance of the SaaS application. This prevents any cross-tenant data leakage or service degradation, as the tester's actions are restricted to a logically or physically separate environment that does not share databases or compute resources with production tenants. Without isolation, even read-only testing could inadvertently access or modify data belonging to other tenants due to shared multi-tenant architecture.

Exam trap

The trap here is that candidates may confuse data anonymization as a sufficient control for multi-tenant isolation, overlooking that anonymization does not prevent cross-tenant data access or service disruption in a shared environment.

How to eliminate wrong answers

Option B (Data anonymization) is wrong because data anonymization is a data protection technique applied to production data to remove personally identifiable information (PII), but it does not prevent the tester's actions from affecting other tenants' data or the application's shared infrastructure; it only reduces the risk of exposing sensitive data if accessed. Option C (Signed waiver from all tenants) is wrong because a signed waiver is a legal document that releases the testing firm from liability, but it does not technically prevent the testing from affecting other tenants' data; it merely shifts responsibility after a breach occurs, which is not a proactive scoping control.

569
MCQmedium

During a web application penetration test, the tester captures a login request in Burp Suite and wants to automate a brute-force attack against the password field. Which Burp Suite tool is specifically designed for this purpose?

A.Intruder
B.Scanner
C.Sequencer
D.Repeater
AnswerA

Intruder is Burp Suite's dedicated automated fuzzing and brute-force engine. It enables you to define a request template, mark payload positions, and cycle through large wordlists using attack types like Sniper, Pitchfork, and Cluster Bomb. With features like payload processing, request throttling, and session handling macros, Intruder is purpose-built for credential guessing and dictionary attacks against authentication endpoints. That is why it is the correct tool for this task.

Why this answer

Intruder is the correct tool because it is specifically designed for automated customized attacks, including brute-force attacks, against web application parameters. It allows the tester to define a payload position (e.g., the password field in a login request) and iterate through a list of candidate passwords, automatically resending the request with each payload value and analyzing the responses.

Exam trap

The trap here is that candidates often confuse Repeater (which is for manual, single-request testing) with Intruder (which is for automated, multi-request attacks), leading them to choose Repeater because they think it can be used for brute-forcing by manually sending requests one by one.

How to eliminate wrong answers

Option B (Scanner) is wrong because Burp Scanner is an automated vulnerability detection tool that identifies security flaws (e.g., SQL injection, XSS) by passively and actively scanning requests, not for performing brute-force attacks against a specific field. Option C (Sequencer) is wrong because it analyzes the randomness of session tokens or other data to assess cryptographic strength, not for automating password guessing. Option D (Repeater) is wrong because it allows manual resending and modification of a single request for testing, but it lacks the ability to automate multiple requests with varying payloads, which is essential for a brute-force attack.

570
Multi-Selectmedium

A penetration tester is writing remediation recommendations. Which THREE practices should the tester follow? (Select THREE.)

Select 3 answers
A.Recommend updates with specific version numbers
B.Suggest compensating controls if full remediation is not immediate
C.Recommend only one fix for each vulnerability
D.Avoid mentioning retesting to reduce client concern
E.Prioritize critical and high-severity findings first
AnswersA, B, E

Providing exact vendor-released patch version numbers (e.g., 'upgrade to Apache 2.4.58') removes guesswork from the remediation process. It ties the recommendation to the specific CVE or vulnerability disclosed, enabling the client's patch management team to verify the fix and avoid deploying an outdated or incomplete patch. Specific versions also help track compliance against the report during retesting, preventing partial or ineffective remediation.

Why this answer

Good remediation recommendations are specific, prioritized, and offer alternatives if full fixes are impossible.

571
Multi-Selecthard

During a web application penetration test, the tester wants to discover hidden parameters that the application accepts. Which THREE tools are BEST suited for parameter bruteforcing? (Select THREE.)

Select 3 answers
A.WPScan
B.Arjun
C.Nikto
D.ffuf
E.Burp Suite Intruder
AnswersB, D, E

Arjun is a dedicated parameter discovery tool that tries thousands of common parameter names against a target endpoint and detects hidden parameters by analyzing response differences such as reflected values, status code or content-length changes, and timing anomalies. It uses a built-in curated wordlist and supports heuristics, making it far more specialized and efficient for this task than general-purpose scanners. This purpose-built design is why it is the correct answer here.

Why this answer

Arjun (B) is purpose-built for hidden parameter discovery, sending large wordlists of parameter names and analyzing response differences (length, status, reflection) to identify accepted parameters. ffuf (D) is a fast web fuzzer that can brute-force parameter names by fuzzing the query string or POST body with the FUZZ keyword and filtering responses by size, words, or status code. Burp Suite Intruder (E) supports parameter bruteforcing by placing payload positions on parameter names and using sniper/cluster-bomb attacks with wordlists, then reviewing response length or status changes. WPScan (A) is a WordPress vulnerability scanner focused on plugins, themes, and users, not generic parameter discovery.

Nikto (C) is a web server scanner that checks for misconfigurations and known files, but it does not perform parameter-name bruteforcing.

Exam trap

The trap here is that candidates may confuse general web vulnerability scanners (like Nikto or WPScan) with tools that are purpose-built for parameter bruteforcing, leading them to select tools that lack the specific functionality for discovering hidden parameters.

572
MCQeasy

After a penetration test, the client requests a document that includes the methodology used, a list of all vulnerabilities found along with their CVSS scores, and detailed steps for remediation. Which type of report section is this?

A.Executive summary
B.Technical report
C.Rules of engagement
D.Scope of work
AnswerB

A technical report delivers exactly the depth the client requested: penetration-testing methodology, every identified vulnerability with its CVSS score, and step-by-step remediation guidance. This satisfies the stem's requirement for granular technical detail, unlike an executive summary, which omits methodology and remediation specifics in favour of business risk.

Why this answer

The client's request for methodology, vulnerability list with CVSS scores, and remediation steps describes the detailed, technical findings of the penetration test. This content is characteristic of the Technical Report section, which provides in-depth analysis and actionable data for technical stakeholders, as opposed to high-level summaries or contractual documents.

Exam trap

The trap here is confusing the Executive Summary's high-level risk ratings with the Technical Report's detailed CVSS scores and remediation steps, leading candidates to incorrectly select the Executive Summary when the question explicitly lists granular technical details.

How to eliminate wrong answers

Option A is wrong because the Executive Summary provides a high-level overview for non-technical management, not the detailed methodology, CVSS scores, and step-by-step remediation instructions. Option C is wrong because the Rules of Engagement (RoE) is a pre-engagement document defining scope, boundaries, and legal terms, not a post-test deliverable containing findings and remediation.

573
MCQmedium

A penetration tester is preparing a proposal for a client. The client wants a test that includes a detailed technical report with remediation steps and an executive summary for management. Which standard or framework is most commonly used to structure the testing process from pre-engagement through post-engagement?

A.OWASP Testing Guide
B.OSSTMM
C.PTES
D.NIST SP 800-115
AnswerC

PTES (Penetration Testing Execution Standard) is the correct choice because it defines a comprehensive, industry-recognized framework covering all seven phases of a penetration test: pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting. This structure is specifically designed for professional penetration testing engagements, ensuring that legal boundaries are established, scoping is thorough, and deliverables are actionable and client-focused. Its widespread adoption and practical focus make it the most suitable methodology to cite in a proposal promising a full, end-to-end penetration test.

Why this answer

The Penetration Testing Execution Standard (PTES) provides a comprehensive framework covering all phases from pre-engagement to post-engagement.

574
MCQmedium

A penetration tester has gained access to a Windows domain controller and wants to extract Kerberos tickets from memory to perform a pass-the-ticket attack. Which tool and command should the tester use to list and export all Kerberos tickets from the current session?

A.mimikatz # sekurlsa::tickets /export
B.mimikatz # lsadump::dcsync /user:krbtgt
C.mimikatz # sekurlsa::logonpasswords
D.mimikatz # kerberos::golden /user:Administrator /domain:example.com /sid:S-1-5-21-... /krbtgt:... /ticket:golden.kirbi
AnswerA

The sekurlsa::tickets command in Mimikatz lists all Kerberos tickets in memory for the current session, and the /export option exports them to .kirbi files. These files can then be used with kerberos::ptt to inject the tickets into a new session, enabling pass-the-ticket. This is the standard method for extracting and reusing Kerberos tickets during post-exploitation.

Why this answer

To perform pass-the-ticket, the tester needs to extract Kerberos tickets from memory. Mimikatz's sekurlsa::tickets module lists all tickets in the current session and can export them with /export. The exported .kirbi files can then be injected using kerberos::ptt.

Other commands like kerberos::golden forge new tickets, lsadump::dcsync retrieves the KRBTGT hash, and sekurlsa::logonpasswords extracts passwords but not tickets.

Exam trap

The trap here is confusing pass-the-ticket with golden ticket creation, leading to the selection of commands that forge tickets rather than export existing ones.

575
MCQeasy

A penetration tester is conducting a network attack and wants to intercept traffic between two hosts on the same local network by spoofing ARP responses. Which tool is specifically designed for this purpose?

A.Bettercap
B.Responder
C.Hashcat
D.John the Ripper
AnswerA

Bettercap is a modular network attack framework with a built-in ARP spoofer module. By sending forged ARP replies, it can redirect traffic between a target host and the gateway, placing the tester in the middle of the conversation. This enables passive sniffing, session hijacking, and content injection, making it the correct choice for ARP-based MITM attacks.

Why this answer

Bettercap is a powerful tool that includes ARP spoofing capabilities for man-in-the-middle attacks on local networks.

576
MCQhard

A penetration tester gains a foothold on a Linux system with ASLR and NX enabled. The tester identifies a stack buffer overflow in a SUID binary. The binary has no PIE (Position Independent Executable) and is compiled without stack canaries. The tester wants to execute a shell. Which technique should be used?

A.Return-to-libc attack
B.Heap spraying
C.ROP chain
D.Buffer overflow with NOP sled
AnswerC

The binary is not compiled with PIE, so its own code segment resides at a fixed base address even when ASLR is enabled. An attacker can identify small instruction sequences (gadgets) ending in ret within that executable region and chain them together to call existing functions such as mprotect or system, thereby executing arbitrary logic without ever injecting shellcode. Because the execution never branches to the stack or heap, NX is bypassed, and because the gadgets live at static addresses in the binary, ASLR does not randomize their locations.

Why this answer

Since the binary has no PIE and lacks stack canaries, the attacker can predict the address of the return address on the stack. However, with ASLR and NX enabled, the stack is non-executable and system library addresses are randomized. A ROP chain allows the tester to bypass both protections by chaining small instruction sequences (gadgets) already present in the binary or loaded libraries to achieve arbitrary code execution, such as calling execve to spawn a shell.

Exam trap

CompTIA often tests the misconception that return-to-libc alone bypasses ASLR, but without a leak, the randomized libc base makes the attack fail; the trap here is that candidates may overlook the need for an information leak or assume that a non-PIE binary eliminates ASLR entirely.

How to eliminate wrong answers

Option A is wrong because a return-to-libc attack relies on knowing the address of a libc function like system(), but ASLR randomizes the base address of libc, making the address unpredictable without an information leak. Option B is wrong because heap spraying is used to exploit heap-based vulnerabilities or to bypass ASLR by filling the heap with shellcode, but here the vulnerability is a stack buffer overflow and NX prevents execution of shellcode placed on the stack or heap.

577
MCQmedium

During a reconnaissance phase, a penetration tester is using a tool to enumerate NetBIOS names on a target internal network. The tester issues the command 'nbtstat -A 192.168.1.100' on a Windows machine. What type of information is the tester most likely trying to obtain?

A.The operating system version and patch level
B.A list of currently open TCP ports on the remote system
C.The MAC address of the remote network interface
D.The NetBIOS name table including computer name, logged-in users, and domain
AnswerD

nbtstat -A with a remote IP performs an adapter status query, returning the NetBIOS name table that encodes the computer name as <00> UNIQUE, the logged-in user as <03> UNIQUE when the messenger service is active, and the domain or workgroup as <1C> or <00> GROUP entries. Decoding these suffix bytes yields identities that can be used for later phishing or credential attacks. This makes the name table—not OS details, port inventory, or a lone MAC—the authoritative output for a penetration tester during reconnaissance.

Why this answer

The `nbtstat -A` command queries the NetBIOS name table of a remote system using its IP address. This table contains the computer name, logged-in users, and domain/workgroup information, which are critical for identifying targets and potential trust relationships during internal reconnaissance.

Exam trap

The trap here is that candidates confuse `nbtstat -A` with `nbtstat -a` (which uses a NetBIOS name instead of an IP) or assume it returns OS details, when in fact it only returns the NetBIOS name table entries.

How to eliminate wrong answers

Option A is wrong because `nbtstat -A` does not reveal OS version or patch level; that information is typically obtained via tools like `nmap` OS fingerprinting or SMB version queries. Option B is wrong because `nbtstat` operates at the NetBIOS layer (port 137-139) and does not enumerate open TCP ports; port scanning requires tools like `nmap` or `netstat`. Option C is wrong because while NetBIOS can sometimes reveal MAC addresses via the <00> or <03> entries in the name table, the primary purpose of `nbtstat -A` is to retrieve the full NetBIOS name table, not specifically the MAC address; ARP or `getmac` would be more direct for MAC address enumeration.

578
MCQhard

During a web application test, a tester discovers a parameter that appears to be vulnerable to SQL injection. They want to extract data from a database using a technique that does not rely on visible output. Which type of SQL injection is most appropriate?

A.UNION-based SQL injection
B.Blind time-based SQL injection
C.Out-of-band SQL injection
D.Error-based SQL injection
AnswerB

Blind time-based SQL injection is the correct answer because it exfiltrates data without requiring any visible output, error message, or outbound network interaction. The attacker injects a conditional expression that triggers a database delay function, such as SLEEP(5) in MySQL, WAITFOR DELAY '0:0:5' in SQL Server, or pg_sleep(5) in PostgreSQL, when the condition evaluates true. By comparing the response time of true versus false conditions, the tester can pose boolean questions (e.g., 'Is the first character of the username A?') and iteratively reconstruct data. This works even when the application always returns the same generic page, making it the most reliable blind technique in a bandwidth-constrained test.

Why this answer

Blind SQL injection, specifically time-based, is used when no error or data is returned, allowing inference via time delays.

579
MCQeasy

Which of the following is the most important factor when determining the scope of a penetration test?

A.Tester's available tools
B.Business objectives
C.Latest vulnerabilities
D.Number of testing team members
AnswerB

Business objectives are the most important scoping factor because they define why the test is conducted—such as regulatory compliance, security posture improvement, or protecting high-value assets—and thus which systems, data, and activities fall in scope. Without clear objectives, a penetration test lacks clear targets, success criteria, and boundaries, making results less meaningful to the organization. These objectives align the engagement with management's risk tolerance and business priorities.

Why this answer

The client's business objectives drive the scope to ensure the test addresses what the client needs to protect. Tools, vulnerabilities, and team size are secondary considerations.

580
MCQhard

A penetration tester is targeting a web application that uses parameterized queries for all database interactions. Which attack vector is most likely to succeed?

A.Cross-site request forgery
B.SQL injection
C.Cross-site scripting
D.Business logic flaws
AnswerD

Business logic flaws involve abusing an application's intended features and workflows, such as modifying a price field, bypassing a mandatory step, or escalating privileges by tampering with state. Parameterized queries only ensure that database input is treated as data, but they do not enforce any business rules, authorization checks, or transactional invariants. An attacker can exploit these logical weaknesses through otherwise legitimate requests, even when all SQL access is safe. This is the correct answer because query parameterization offers no protection at the application logic layer, and the tester is likely hunting for such flaws.

Why this answer

Parameterized queries prevent SQL injection by separating SQL code from user input, making option B ineffective. Business logic flaws (D) are vulnerabilities in the application's design or workflow that are not mitigated by secure coding practices like parameterized queries, so they remain exploitable. This attack vector targets the intended functionality of the application, such as manipulating pricing or bypassing authentication steps, which parameterized queries do not protect against.

Exam trap

The trap here is that candidates assume parameterized queries eliminate all database-related attacks, overlooking that business logic flaws are independent of query construction and remain a viable attack vector.

How to eliminate wrong answers

Option A is wrong because cross-site request forgery exploits the trust a site has in a user's browser, not database query construction, and parameterized queries have no impact on CSRF defenses. Option B is wrong because parameterized queries are specifically designed to prevent SQL injection by ensuring user input is treated as data, not executable code, so this attack vector will fail. Option C is wrong because cross-site scripting exploits client-side script injection in web pages, not database interactions, and parameterized queries do not affect XSS vulnerabilities.

581
MCQmedium

During a penetration test, a tester discovers a critical vulnerability that could allow remote code execution on an internet-facing server. According to best practices, what is the most appropriate immediate action?

A.Keep the finding confidential until retesting.
B.Notify the client immediately about the critical finding.
C.Exploit the vulnerability to demonstrate impact.
D.Wait until the final report to disclose the finding.
AnswerB

Notifying the client immediately about a critical finding is correct because critical vulnerabilities—such as remote code execution, authentication bypass, or SQL injection with data access—represent an imminent and material risk to the organization. Prompt communication enables the client to initiate emergency incident response, apply temporary mitigations, or patch the affected system before the final report is delivered. This practice is usually mandated by the rules of engagement and aligns with professional standards that prioritize minimizing exposure over adhering to a rigid reporting schedule.

Why this answer

Critical findings should be communicated immediately so the client can take urgent action.

582
MCQmedium

A penetration tester is analyzing a Bash script that uses the tool 'curl' to send HTTP requests. The script contains the following line: curl -X POST -d "username=admin&password[$ne]=a" http://target/login. Which type of attack is this script most likely attempting?

A.Cross-Site Scripting (XSS)
B.SQL Injection
C.NoSQL Injection
D.Directory Traversal
AnswerC

NoSQL Injection is the correct answer: the $ne operator is a MongoDB comparison operator meaning 'not equal to.' By injecting a JSON object like {"password": {"$ne": null}} into the password field, the attacker causes the authentication query to return true for any non-null password value, effectively bypassing login. This occurs because the application naively concatenates unsanitized user input into the NoSQL query structure, allowing operator injection into the query logic.

Why this answer

The payload `password[$ne]=a` uses MongoDB's `$ne` (not equal) operator, which is a NoSQL query operator. When the backend parses this as a MongoDB query, it will match any document where the password is not equal to 'a', effectively bypassing authentication. This is a classic NoSQL injection attack, not SQL injection, because the syntax targets NoSQL databases like MongoDB.

Exam trap

The trap here is that candidates see a POST request with parameters and immediately think SQL injection, but the square bracket syntax `[$ne]` is a dead giveaway for NoSQL injection, which is a distinct attack vector targeting document-based databases.

How to eliminate wrong answers

Option A is wrong because Cross-Site Scripting (XSS) involves injecting client-side scripts into web pages, not manipulating database query operators via HTTP parameters. Option B is wrong because SQL injection uses SQL-specific syntax (e.g., `' OR 1=1 --`) to manipulate relational databases, whereas `[$ne]` is a MongoDB operator and does not work against SQL databases.

583
MCQmedium

After completing a penetration test, the tester prepares the final report. According to best practices, which of the following should be included in the executive summary?

A.Detailed list of vulnerabilities and CVSS scores
B.Step-by-step exploitation procedures
C.The tester's personal opinions about the security posture
D.High-level findings, risk ratings, and strategic recommendations
AnswerD

High-level findings, risk ratings, and strategic recommendations form the core of an executive summary because they directly address the business impact and remediation priorities that executives care about. Risk ratings, often derived from CVSS or a customized likelihood/impact matrix, condense technical vulnerabilities into a language that non-technical stakeholders can use for resource allocation and risk acceptance. Strategic recommendations provide a roadmap for improving the organization's security posture, linking specific findings to actionable, cost-effective measures that align with the enterprise's risk appetite.

Why this answer

The executive summary should provide high-level findings, risk ratings, and strategic recommendations. Option A is wrong because detailed vulnerability lists belong in the technical section. Option B is wrong because exploitation procedures are too detailed.

Option C is wrong because personal opinions are unprofessional and subjective.

584
Multi-Selecteasy

A penetration tester is gathering information using passive reconnaissance techniques. Which of the following are considered passive reconnaissance methods? (Choose two.)

Select 2 answers
A.Using nmap to scan for open ports
B.Performing a DNS brute force attack
C.Conducting a vulnerability scan with Nessus
D.Reviewing the target's social media profiles
E.Analyzing job postings for technology stack clues
AnswersD, E

Reviewing social media profiles involves no direct interaction with target systems, so no packets reach the organisation's infrastructure. This satisfies passive reconnaissance, which relies solely on publicly available information and remains undetectable by the target's monitoring tools.

Why this answer

Options D and E are correct because passive reconnaissance relies on publicly available information gathered without directly interacting with the target's systems. Reviewing the target's social media profiles (D) is passive since it only involves reading publicly posted content, which can reveal employee names, roles, and organizational details useful for social engineering or OSINT. Analyzing job postings for technology stack clues (E) is also passive because job ads are public documents that may disclose specific tools, platforms, and versions in use, without sending any traffic to the target.

In contrast, using nmap to scan for open ports (A) actively sends packets to the target and is therefore active reconnaissance. Performing a DNS brute force attack (B) actively queries DNS servers with many candidate names, making it active. Conducting a vulnerability scan with Nessus (C) directly probes the target's systems for weaknesses, which is also active reconnaissance.

585
Multi-Selecteasy

A company is planning a social engineering engagement. Which TWO items should be included in the pre-engagement documentation?

Select 2 answers
A.List of all employee passwords
B.Network topology diagrams
C.Source code of all applications
D.Emergency contact list
E.Rules of engagement
AnswersD, E

An emergency contact list is a mandatory deliverable for social engineering engagements because any deployed scenario could accidentally trigger a real security incident or expose a worker to harm. The lead tester needs named individuals with the authority to approve an immediate abort, making this list as operationally important as the RoE itself. Without these contacts, a seemingly harmless test could spiral out of control with no rapid way to stop it.

Why this answer

Pre-engagement documentation should include the rules of engagement (RoE) and emergency contacts to handle incidents during social engineering.

586
MCQeasy

A penetration tester discovers a critical vulnerability in a client's production environment. What is the BEST immediate course of action before including this finding in the final report?

A.Immediately communicate the finding to the client's point of contact.
B.Wait until the final report is complete to include all findings together.
C.Include the finding only in the technical appendix of the final report.
D.Stop the penetration test and wait for further instructions.
AnswerA

Critical production vulnerabilities demand immediate verbal or written disclosure to the client's point of contact, enabling urgent remediation before the report is finalised. Delaying notification until report delivery breaches the tester's duty to warn and could expose the client to active exploitation.

Why this answer

The correct option is A: immediately communicate the finding to the client's point of contact. For a critical vulnerability in a production environment, prompt notification lets the client begin containment and remediation before the issue is exploited, and it aligns with standard penetration-testing ethics and rules of engagement that require timely disclosure of high-risk findings. Waiting until the final report (B) or burying the finding in a technical appendix (C) delays the client's ability to respond and could leave production systems exposed.

Stopping the test entirely (D) is not required and may not be the best action, since the tester can still report the finding while following the agreed scope and escalation procedures.

587
MCQmedium

During a penetration test, a client asks the tester to clarify the scope of the test. Which of the following is the best approach for the tester?

A.Make a decision based on previous tests.
B.Clarify with the client via email or documented communication.
C.Include the scope in the report after testing.
D.Ignore the question and continue testing.
AnswerB

Clarifying via email or documented communication is the correct action because it creates an auditable trail of the scope decision, which is essential for legal and compliance purposes. The written confirmation should specify the exact IP ranges, domain names, or testing techniques in question, along with the client's approval, to serve as a formal amendment to the rules of engagement. This approach also protects both parties and ensures that any subsequent testing activities are fully authorized and defensible.

Why this answer

Clarifying scope questions helps ensure the test stays within agreed boundaries and avoids misunderstandings.

588
MCQmedium

A penetration tester is reviewing a Python script that attempts to exploit a command injection vulnerability. The script uses the 'subprocess' module with the 'shell=True' argument. Which of the following code changes would be MOST effective to reduce the risk of unintended consequences when executing system commands?

A.Replace subprocess with os.system()
B.Use the 'shlex.quote()' function to sanitize user input before passing to subprocess
C.Avoid using shell=True and pass the command as a list of arguments
D.Use the 'exec()' function to run the command
AnswerC

Passing the command as a list of arguments while omitting shell=True is the correct mitigation because subprocess then executes the executable directly via execve or similar system calls without invoking a shell. With shell=False, the shell's metacharacter interpretation is completely bypassed; characters like ;, |, and $ are passed as literal arguments to the command, not interpreted. This eliminates shell injection by design, because user-controlled values are always treated as data, never as code. This is the recommended approach per Python's official subprocess documentation for security-sensitive applications.

Why this answer

Setting `shell=True` in Python's `subprocess` module causes the command string to be interpreted by the system shell, which introduces command injection risks if any part of the string is user-controlled. By passing the command as a list of arguments (e.g., `['ls', '-l', filename]`) and omitting `shell=True`, the subprocess module directly executes the binary without shell interpretation, eliminating shell metacharacter injection. This is the most effective mitigation as it avoids shell parsing entirely, which is the root cause of the vulnerability.

Exam trap

CompTIA often tests the misconception that input sanitization (like quoting) is sufficient to prevent command injection, when in fact the most secure approach is to avoid shell invocation altogether by using a list of arguments with `shell=False`.

How to eliminate wrong answers

Option A is wrong because replacing `subprocess` with `os.system()` still invokes the system shell to execute the command, inheriting the same command injection risks and providing no improvement; in fact, `os.system()` offers even less control over execution. Option B is wrong because while `shlex.quote()` can help sanitize input for shell use, it is not foolproof—edge cases like null bytes or certain locale-dependent characters can bypass quoting, and relying on quoting still leaves the command exposed to shell parsing, making it less robust than removing shell involvement entirely.

589
MCQmedium

During a web application penetration test, the tester wants to discover hidden directories and files on the target web server. Which tool is best suited for this task, and what technique does it use?

A.Curl - manual HTTP requests
B.Whatweb - web server identification
C.Wappalyzer - technology fingerprinting
D.Gobuster - directory brute forcing
AnswerD

Gobuster is a tool specifically designed for brute-forcing URIs (directories and files) by systematically sending HTTP requests for each entry in a wordlist against the target web server. It is highly efficient, supporting multi-threading, status-code filtering, and extensions, making it ideal for discovering hidden or unlisted resources. Because it automates the iterative request-response cycle and parses responses for valid HTTP status codes, it is the appropriate choice for directory brute forcing in a penetration test. Unlike the other tools, it directly addresses the task of enumerating directory structure.

Why this answer

Directory enumeration tools like gobuster, dirbuster, and dirsearch use wordlist-based brute force to discover hidden directories and files. Gobuster is a common choice. Wappalyzer is for technology fingerprinting, whatweb is for web server identification, and curl is for HTTP requests but lacks directory brute force functionality.

590
MCQeasy

During a penetration test, a tester uses Responder to capture NTLM hashes from a Windows network. Which of the following protocols is MOST commonly targeted by Responder for poisoning?

A.LLMNR
B.DNS
C.ICMP
D.HTTP
AnswerA

LLMNR, or Link-Local Multicast Name Resolution, is a protocol that Windows systems use to resolve hostnames on the local network when DNS queries fail. Responder works by listening for these multicast LLMNR queries and then spoofing a response, claiming to be the host the client is looking for. The client then attempts to authenticate to the attacker's machine, sending an NTLMv2 hash that the tester captures and can later crack or relay. This makes LLMNR the primary and correct protocol that Responder targets for hash capture in a penetration test.

Why this answer

Responder poisons LLMNR, NBT-NS, and mDNS to capture NTLM hashes. The other options are not primary targets.

591
Multi-Selecthard

A penetration tester is performing lateral movement in a Windows domain after compromising a workstation. Which THREE techniques can be used to move to another machine?

Select 3 answers
A.ARP spoofing
B.Evil-WinRM
C.WMIExec
D.SSH with captured credentials
E.PsExec
AnswersB, C, E

Evil-WinRM is a purpose-built post-exploitation and lateral movement tool that wraps the WinRM protocol (Windows Remote Management), typically operating over ports 5985/5986, to provide an interactive PowerShell session on a remote Windows host. It authenticates with valid credentials (often obtained via hash, LM, or NTLM pass-the-hash) and is optimized for penetration testing, supporting local and SMB upload/download, script execution, and memory injection. This strongly aligns with lateral movement because it allows an attacker to move from a compromised host to another using standard Windows remote management services, making it a correct answer.

Why this answer

PsExec, WMIExec, and Evil-WinRM are common tools for lateral movement in Windows environments.

592
MCQmedium

A client requires a penetration test of their web application that uses Single Sign-On (SSO) with a third-party identity provider. The client is concerned that testing could lock out real user accounts and disrupt operations. Which of the following should be included in the rules of engagement to address this concern?

A.Prohibit all testing of the authentication mechanism
B.Provide test accounts that are excluded from lockout policies
C.Only perform testing during business hours
D.Require the tester to use only passive reconnaissance techniques
AnswerB

Supplying test accounts excluded from lockout policies lets the tester simulate brute-force or password-spraying attempts on a dedicated account without the risk of locking out real production users. Since lockout thresholds are typically enforced after a small number of failed attempts, using these accounts allows repeated authentication attempts while preserving the availability and reputation of the client's legitimate user base. The accounts must be clearly segregated from production data and have restrictions on permissions to avoid unintended impact.

Why this answer

Providing test accounts that are excluded from lockout policies allows the penetration tester to thoroughly assess the SSO authentication mechanism—including the SAML or OIDC flows—without risking the lockout of real user accounts. This directly addresses the client's operational concern while still enabling comprehensive testing of the identity provider integration.

Exam trap

The trap here is that candidates may assume restricting testing to business hours (Option C) is sufficient to mitigate account lockout risks, but they fail to recognize that lockout policies operate independently of time and that real user accounts remain vulnerable to disruption regardless of when testing occurs.

How to eliminate wrong answers

Option A is wrong because prohibiting all testing of the authentication mechanism would leave critical SSO vulnerabilities (e.g., SAML assertion injection, OIDC token replay) unexamined, violating the core objective of a penetration test. Option C is wrong because performing testing only during business hours does not prevent account lockouts; lockout policies apply regardless of time, and real user accounts could still be disabled during testing, causing operational disruption.

593
Multi-Selectmedium

During a Linux privilege escalation attempt, a tester checks for misconfigurations that could allow running commands as root. Which of the following are potential vectors? (Select THREE.)

Select 3 answers
A.Unquoted service paths
B.Sudo misconfigurations
C.Writable scripts in cron jobs
D.DLL hijacking
E.SUID/SGID binaries
AnswersB, C, E

Sudo misconfigurations are a critical Linux privilege escalation vector because a user's sudo rights may allow running a command that can be leveraged to obtain a root shell, such as `sudo vim` or `sudo python -c 'import pty; pty.spawn("/bin/bash")'`. Misconfigurations include NOPASSWD entries, unsafe wildcard rules, or binary paths that can be replaced, and they directly expose unintended root-level execution. An attacker enumerates `sudo -l` to find such permissive entries.

Why this answer

SUID/SGID binaries, sudo misconfigurations, and writable cron scripts are common escalation vectors.

594
MCQhard

A penetration tester is using OpenVAS to perform an authenticated vulnerability scan of a Linux server. The tester has provided valid SSH credentials. Which of the following is a primary benefit of performing an authenticated scan over an unauthenticated scan?

A.Ability to detect vulnerabilities that require local access
B.Reduced network bandwidth usage
C.Faster scan completion time
D.Elimination of all false positives
AnswerA

Authenticated scanning leverages valid credentials to log into the target OS and perform local checks, such as inspecting file permissions, registry keys, installed software versions, and missing security patches. These truly local vulnerabilities are invisible to unauthenticated network-based scans, which can only observe remotely reachable services and banners. This credential-based access is the primary technical justification for choosing an authenticated scan.

Why this answer

Authenticated scans have deeper access to the system, allowing the scanner to check configuration files, patch levels, and local vulnerabilities that are not visible externally.

595
MCQmedium

A penetration tester is presenting findings to a group of IT administrators. One administrator questions the validity of a finding, claiming it is not exploitable. How should the tester respond?

A.Insist that the finding is valid based on the tester's experience.
B.Escalate the issue to the project manager.
C.Present the proof-of-concept code and screenshots that demonstrate the exploit.
D.Agree to remove the finding from the report.
AnswerC

Presenting the proof-of-concept code and screenshots directly addresses the administrator's skepticism by demonstrating a deterministic, repeatable procedure that produces the stated compromise. Screenshots provide visual attestation of pre-conditions, executed commands, and post-conditions, while the PoC code allows the client to independently reproduce the attack in a controlled environment. This transforms the finding from an assertion into an evidence-backed, reproducible vulnerability, which is the professional standard for validating pen-test results and building trust.

Why this answer

The tester should provide evidence to support the finding rather than being defensive or dismissive.

596
Multi-Selecthard

A penetration testing company is planning a social engineering engagement for a client. The engagement includes phishing and physical tailgating. Which THREE of the following should be clearly defined in the Rules of Engagement? (Select THREE.)

Select 3 answers
A.The format of the final report
B.The specific vulnerabilities to be exploited
C.The conditions under which the test must be stopped immediately
D.The types of social engineering attacks allowed (e.g., phishing, vishing, tailgating)
E.The list of employees and contractors who are in scope for social engineering
AnswersC, D, E

Emergency stop criteria, often called 'cease-and-desist' or 'safety stop' conditions, are an indispensable RoE section that enumerates triggering events such as evidence of life-threatening incidents, unexpected system catastrophic failures, or unauthorized access to protected health/financial data. This clause clarifies that the tester's authority to act is revocable in real time and defines the chain of communication for immediate shutdown. Absent this, the client retains no operational control over a live, rolling attack scenario, which is both a legal and safety hazard.

Why this answer

RoE should address personnel scope, emergency stop conditions, and specific techniques allowed; vulnerabilities and deliverables are part of SOW.

597
MCQeasy

A penetration tester wants to enumerate SMB shares, user lists, and operating system information from a Windows target without authenticating. Which of the following tools is BEST suited for this task?

A.enum4linux
B.smbclient
C.nmblookup
D.nbtscan
AnswerA

enum4linux is a comprehensive Perl wrapper that automates null-session queries via rpcclient, net, and smbclient to extract a wide range of SMB/NetBIOS data, including user lists, share names, group memberships, password policies, and OS information. It is considered the go-to tool for unauthenticated enumeration of Windows and Samba targets because it consolidates dozens of RPC calls into one script, making it far more thorough than individual utilities.

Why this answer

enum4linux is a Perl wrapper around tools like smbclient, nmblookup, and nbtscan, specifically designed to extract SMB shares, user lists, and OS information from Windows targets without authentication by leveraging null sessions and SMB RPC calls (e.g., via MSRPC over SMB). It automates the enumeration of these details using the Server Message Block (SMB) protocol, making it the best choice for unauthenticated reconnaissance.

Exam trap

The trap here is that candidates often confuse nmblookup or nbtscan as tools for SMB enumeration, but they only handle NetBIOS name resolution, not the deeper SMB share or user enumeration that enum4linux automates.

How to eliminate wrong answers

Option B (smbclient) is wrong because it requires authentication to list shares or access files; without credentials, it can only attempt a null session but lacks the automated enumeration of user lists and OS details that enum4linux provides. Option C (nmblookup) is wrong because it only performs NetBIOS name resolution via NBNS queries, not SMB share or user enumeration. Option D (nbtscan) is wrong because it scans for NetBIOS name services (port 137) to retrieve hostnames and MAC addresses, but it does not enumerate SMB shares or user lists.

598
MCQeasy

A penetration tester is preparing a report for a client's CISO who is not technical. The CISO needs to understand the overall risk posture and the business impact of the findings. Which section of the report should be tailored for this audience?

A.Executive summary
B.Technical findings
C.Appendices with raw scan data
D.Remediation details
AnswerA

The executive summary is crafted specifically for decision-makers like the CISO, translating technical vulnerability data into clear business risk. It highlights the overall security posture, key threats that could impact operations or revenue, and suggested prioritization—all in non-technical language. This section enables the CISO to communicate findings to the board and justify resource allocation without needing to parse exploits or raw logs.

Why this answer

The executive summary is designed for non-technical stakeholders like a CISO to quickly grasp the overall risk posture and business impact without needing to interpret raw data or technical jargon. It synthesizes findings into high-level business risks, such as potential financial loss or regulatory exposure, rather than detailing specific vulnerabilities or exploit chains. This section ensures the audience can make informed decisions about resource allocation and risk acceptance.

Exam trap

The trap here is that candidates confuse 'executive summary' with 'remediation details' or 'technical findings,' assuming the CISO needs operational specifics, when in fact the exam tests the principle that non-technical audiences require a distilled, business-focused overview of risk posture and impact.

How to eliminate wrong answers

Option B is wrong because technical findings contain detailed vulnerability descriptions, exploit steps, and proof-of-concept code that require technical expertise to understand, making it unsuitable for a non-technical CISO. Option C is wrong because appendices with raw scan data (e.g., Nmap XML, Nessus .nessus files) are dense, unprocessed outputs that overwhelm non-technical readers and obscure business impact. Option D is wrong because remediation details focus on specific patches, configuration changes, or code fixes, which are operational instructions for technical teams, not a high-level risk summary for executive decision-making.

599
MCQmedium

A penetration tester is testing a web application and discovers an endpoint that returns XML data. The tester attempts to read /etc/passwd by injecting an external entity. Which type of attack is this?

A.XXE injection
B.Command injection
C.SSRF
D.SQL injection
AnswerA

XXE injection is correct because the vulnerability arises from the XML parser processing an external entity defined in the DOCTYPE declaration. An attacker can use a crafted XML payload with an entity like <!ENTITY xxe SYSTEM "file:///etc/passwd"> to read sensitive files, perform internal port scans, or trigger network requests. The root cause is the application's insecure handling of XML external entities, which is the defining characteristic of XXE.

Why this answer

XML External Entity (XXE) injection allows reading files or performing SSRF via XML processing.

600
MCQmedium

During a penetration test, a tester wants to discover all live hosts on a subnet without performing a full port scan. Which Nmap command is most appropriate for this purpose?

A.nmap -sS 192.168.1.0/24
B.nmap -sn 192.168.1.0/24
C.nmap -O 192.168.1.0/24
D.nmap -A 192.168.1.0/24
AnswerB

-sn instructs Nmap to skip port scanning entirely and perform host discovery only, sending a blend of ICMP echo requests, TCP SYN to port 443, TCP ACK to port 80, and ICMP timestamp requests to see if targets respond. This quickly identifies live hosts on the 192.168.1.0/24 subnet without enumerating services, reducing time, noise, and the risk of a false negative from a single probe type. It is the correct, purpose-built flag for this task.

Why this answer

The -sn flag performs a ping sweep (host discovery) without port scanning, which is the standard method to discover live hosts on a subnet efficiently.

Page 7

Page 8 of 11

Page 9

All pages