Courseiva

PT0-003 · domain

Vulnerability Discovery and Analysis

This domain covers finding and validating weaknesses before exploitation: source code review, packet crafting, cloud and web misconfigurations, and tool-assisted discovery. Questions present short scenarios—a PHP snippet, an AWS audit, a Python script—and ask you to name the vulnerability, the right library, or the appropriate tool for the target environment.

52 questions11 easy27 medium14 hard

Focused practice

Practice Vulnerability Discovery and Analysis questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Vulnerability Discovery and Analysis

Be able to read a code snippet or scenario and name the exact flaw, library, or tool. The most important thing is matching the tool to the task: Scapy for packet crafting, Pacu for AWS post-exploitation, and correct vulnerability classification for injection flaws.

Crafting and inspecting packets with Scapy, including TCP flags, in Python scripts

Source code review for hardcoded credentials, injection flaws, and missing input validation

Identifying SQL injection in PHP string-concatenated queries using $_POST input

Using cloud exploitation tools such as Pacu for AWS privilege escalation and persistence

Watch out for

Common Vulnerability Discovery and Analysis exam traps

  • ▸Choosing requests or socket for raw packet crafting when Scapy is the intended low-level manipulation library.
  • ▸Reading a concatenated SQL query as XSS or command injection instead of recognizing SQL injection.
  • ▸Confusing general cloud audit tools with AWS-specific exploitation frameworks like Pacu.

Question index

All Vulnerability Discovery and Analysis questions (52)

Click any question to see the full explanation, or start a practice session above.

1

A penetration tester needs to identify live hosts and open ports on a target network. Which tool is most appropriate for this task?

Easy
2

A penetration tester wants to exploit a vulnerable service on a target using a known module. Which framework provides a large database of exploit modules, payloads, and post-exploitation tools?

Easy
3

A penetration tester has been given a target IP address and needs to quickly determine which services are running on the target. Which Nmap option should the tester use to perform a SYN scan with service version detection and default NSE scripts?

Easy
4

During code review, a penetration tester identifies the following line in a PHP web application: $sql = "SELECT * FROM users WHERE username='" . $_GET['user'] . "'"; Which type of vulnerability is most likely present?

Medium
5

A penetration tester is analyzing a Java application and finds the following code snippet: Object obj = ois.readObject(); where ois is an ObjectInputStream. What vulnerability is most likely present if the input is untrusted?

Hard
6

A tester is reviewing source code for security vulnerabilities. Which TWO of the following are examples of insecure coding practices that often lead to critical vulnerabilities?

Medium
7

A penetration tester is analyzing a suspicious executable found on a compromised Windows host. The tester wants to identify if the executable is packed or obfuscated, which might indicate malware. Which tool is specifically designed for detecting packers and providing information about the executable's structure?

Easy
8

During a code review, a penetration tester identifies a PHP function that executes arbitrary shell commands. Which function poses the greatest security risk if user input is not sanitized?

Medium
9

A penetration tester is analyzing a web application and discovers that it uses a JSON Web Token (JWT) for session management. The tester captures a token and notices that the signature algorithm is 'none'. The application accepts tokens with the 'none' algorithm. Which type of vulnerability does this represent, and what is the immediate impact?

Hard
10

In a Python script for a penetration test, you need to craft a custom TCP packet with specific flags. Which library is best suited for low-level packet manipulation?

Medium
11

A penetration tester is reviewing source code and wants to identify common hardcoded credentials and input validation gaps. Which three checks should the tester perform? (Choose THREE.)

Easy
12

A tester needs to enumerate Windows domain users and groups from a compromised system. Which PowerShell script would be most useful?

Medium
13

A penetration tester is reviewing a Python script used for a custom exploit. Which of the following code snippets contains a dangerous function that could lead to remote code execution?

Medium
14

A penetration tester needs to perform an online brute-force attack against an SSH service. Which tool is most appropriate?

Easy
15

A penetration tester has captured a WPA2 handshake. Which tool from the Aircrack-ng suite is used to crack the pre-shared key?

Medium
16

A penetration tester wants to exploit a Windows system using a known vulnerability and gain a meterpreter session. Which tool is most appropriate?

Medium
17

During a penetration test, the tester wants to capture network traffic for later analysis. Which tool is most appropriate for capturing packets and saving them to a pcap file?

Easy
18

A penetration tester has obtained a set of NTLM password hashes from a Windows domain controller. The tester wants to perform an offline cracking attack using GPU acceleration. Which tool is best suited for this purpose?

Medium
19

A penetration tester has captured network traffic and wants to analyze it using Wireshark. Which two actions can the tester perform to focus on specific types of communication? (Choose TWO.)

Medium
20

A tester needs to perform an online brute-force attack against an SSH service. Which tool is most suitable?

Medium
21

During a source code review of a PHP application, the tester finds the following line: $query = "SELECT * FROM users WHERE username = '" . $_POST['username'] . "'"; Which vulnerability is present?

Hard
22

A penetration tester is analyzing a compiled Linux binary that appears to validate license keys. The tester wants to understand the validation logic without access to source code. The binary is stripped of symbols and uses anti-debugging techniques. Which approach is most effective for discovering the validation algorithm?

Hard
23

A penetration tester is performing a cloud security audit of an AWS environment. Which tool is specifically designed for AWS exploitation and post-exploitation, including privilege escalation and persistence?

Hard
24

During a penetration test, a tester needs to perform a deauthentication attack to force a client to reconnect and capture the WPA handshake. Which two tools from the Aircrack-ng suite are required? (Choose TWO.)

Medium
25

During a reverse engineering task on a .NET binary, which tool would allow you to decompile the code into readable C# source code?

Hard
26

Which tool would be best for capturing and analyzing network packets to troubleshoot a web application?

Easy
27

After gaining initial access to a Windows domain controller, a tester wants to extract password hashes from the SAM database and domain account hashes. Which Impacket tool is designed for this purpose?

Medium
28

After gaining initial access to a Windows system, a penetration tester wants to extract password hashes from the local SAM database. Which Impacket tool should be used?

Medium
29

A tester needs to brute-force SSH credentials on a target. Which tool is most appropriate for this task?

Medium
30

A penetration tester is writing a Bash script to automate scanning of multiple subnets with Nmap and parse the output. Which three features are commonly used in such a script? (Choose THREE.)

Medium
31

A tester wants to perform an evil twin attack to capture WPA handshakes. Which tool from the Aircrack-ng suite is used to deauthenticate clients from a legitimate AP to force reconnection to the rogue AP?

Medium
32

A tester wants to perform a Kerberoasting attack against an Active Directory environment. Which Impacket tool would be most appropriate?

Medium
33

During a web application test, a penetration tester needs to intercept and modify HTTP requests before forwarding them to the server. Which tool is best suited for this task?

Easy
34

A penetration tester is writing a Python script to send a crafted TCP packet to a target. Which Python library should the tester use for low-level packet crafting and injection?

Medium
35

A penetration tester is conducting a wireless assessment and needs to capture the four-way handshake to perform offline WPA cracking. Which tool is best suited for capturing the handshake?

Hard
36

A penetration tester is conducting a vulnerability assessment of a Linux web server. The tester runs a scan with Nikto and receives a finding indicating that the server is potentially vulnerable to a cross-site scripting (XSS) attack on a specific parameter. To confirm the finding, the tester wants to manually verify the XSS vulnerability. Which action should the tester take?

Medium
37

During a web application test, a penetration tester intercepts requests between the browser and server and modifies them in real time. Which Burp Suite tool is designed for this purpose?

Medium
38

A penetration tester needs to perform a Kerberoasting attack against a Windows Active Directory environment. Which tool from the Impacket suite should the tester use to request service tickets and extract TGS hashes for offline cracking?

Medium
39

A penetration tester is conducting a wireless security assessment. The target network uses WPA2-PSK. The tester has captured the four-way handshake. Which tool from the Aircrack-ng suite can be used to attempt to recover the pre-shared key by performing a dictionary attack?

Hard
40

During a cloud security assessment of AWS, a tester wants to identify misconfigurations using automated tools. Which THREE tools are specifically designed for AWS security auditing?

Hard
41

Which PowerShell script is commonly used for post-exploitation enumeration of Active Directory, such as querying user accounts and group memberships?

Easy
42

During a web application penetration test, the tester captures a login request in Burp Suite and wants to automate a brute-force attack against the password field. Which Burp Suite tool is specifically designed for this purpose?

Medium
43

A penetration tester needs to enumerate Active Directory users and groups from a Windows domain. Which PowerShell tool is specifically designed for AD enumeration and is commonly used in post-exploitation?

Easy
44

A penetration tester is performing a password cracking task against a dump of NTLM hashes obtained from a Windows domain controller. Which tool would be the most efficient for this task?

Medium
45

A penetration tester is conducting a post-exploitation phase on a Windows target and wants to dump credentials. Which of the following tools can be used? (Choose TWO.)

Medium
46

A penetration tester needs to perform a dictionary attack against an SSH service. Which of the following tools is best suited for this task?

Medium
47

A penetration tester is reviewing a Java application for insecure deserialization vulnerabilities. Which of the following should the tester look for? (Choose TWO.)

Medium
48

During a code review of a PHP web application, you encounter the following code: $result = mysql_query("SELECT * FROM users WHERE username='" . $_GET['user'] . "'");. Which vulnerability does this represent?

Hard
49

A penetration tester is performing a vulnerability assessment of a web application. The tester wants to identify input validation vulnerabilities that could lead to injection attacks. Which two techniques are most effective for discovering injection flaws such as SQL injection and command injection? (Choose two.)

Hard
50

A penetration tester is reverse-engineering a .NET binary to understand its authentication logic. Which three tools are suitable for decompiling .NET assemblies? (Choose THREE.)

Hard
51

A penetration tester is analyzing a Linux binary and wants to decompile it to understand its logic. Which open-source tool is specifically designed for reverse engineering and can generate C-like pseudocode from compiled binaries?

Hard
52

A penetration tester is performing a wireless assessment and wants to set up an evil twin attack. Which of the following steps are necessary? (Choose THREE.)

Hard

Frequently asked questions

What does the Vulnerability Discovery and Analysis domain cover on the PT0-003 exam?
Be able to read a code snippet or scenario and name the exact flaw, library, or tool. The most important thing is matching the tool to the task: Scapy for packet crafting, Pacu for AWS post-exploitation, and correct vulnerability classification for injection flaws.
How many questions are in this domain?
This page lists all 52 Vulnerability Discovery and Analysis questions in the PT0-003 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Vulnerability Discovery and Analysis questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
pentest-plus PENTEST-PLUS ptp tools code Practice Questions