PT0-003 · domain
Vulnerability Discovery and Analysis
This domain covers finding and validating weaknesses before exploitation: source code review, packet crafting, cloud and web misconfigurations, and tool-assisted discovery. Questions present short scenarios—a PHP snippet, an AWS audit, a Python script—and ask you to name the vulnerability, the right library, or the appropriate tool for the target environment.
Focused practice
Practice Vulnerability Discovery and Analysis questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Vulnerability Discovery and Analysis
Be able to read a code snippet or scenario and name the exact flaw, library, or tool. The most important thing is matching the tool to the task: Scapy for packet crafting, Pacu for AWS post-exploitation, and correct vulnerability classification for injection flaws.
Crafting and inspecting packets with Scapy, including TCP flags, in Python scripts
Source code review for hardcoded credentials, injection flaws, and missing input validation
Identifying SQL injection in PHP string-concatenated queries using $_POST input
Using cloud exploitation tools such as Pacu for AWS privilege escalation and persistence
Watch out for
Common Vulnerability Discovery and Analysis exam traps
- ▸Choosing requests or socket for raw packet crafting when Scapy is the intended low-level manipulation library.
- ▸Reading a concatenated SQL query as XSS or command injection instead of recognizing SQL injection.
- ▸Confusing general cloud audit tools with AWS-specific exploitation frameworks like Pacu.
Question index
All Vulnerability Discovery and Analysis questions (52)
Click any question to see the full explanation, or start a practice session above.
A penetration tester needs to identify live hosts and open ports on a target network. Which tool is most appropriate for this task?
Easy2A penetration tester wants to exploit a vulnerable service on a target using a known module. Which framework provides a large database of exploit modules, payloads, and post-exploitation tools?
Easy3A penetration tester has been given a target IP address and needs to quickly determine which services are running on the target. Which Nmap option should the tester use to perform a SYN scan with service version detection and default NSE scripts?
Easy4During code review, a penetration tester identifies the following line in a PHP web application: $sql = "SELECT * FROM users WHERE username='" . $_GET['user'] . "'"; Which type of vulnerability is most likely present?
Medium5A penetration tester is analyzing a Java application and finds the following code snippet: Object obj = ois.readObject(); where ois is an ObjectInputStream. What vulnerability is most likely present if the input is untrusted?
Hard6A tester is reviewing source code for security vulnerabilities. Which TWO of the following are examples of insecure coding practices that often lead to critical vulnerabilities?
Medium7A penetration tester is analyzing a suspicious executable found on a compromised Windows host. The tester wants to identify if the executable is packed or obfuscated, which might indicate malware. Which tool is specifically designed for detecting packers and providing information about the executable's structure?
Easy8During a code review, a penetration tester identifies a PHP function that executes arbitrary shell commands. Which function poses the greatest security risk if user input is not sanitized?
Medium9A penetration tester is analyzing a web application and discovers that it uses a JSON Web Token (JWT) for session management. The tester captures a token and notices that the signature algorithm is 'none'. The application accepts tokens with the 'none' algorithm. Which type of vulnerability does this represent, and what is the immediate impact?
Hard10In a Python script for a penetration test, you need to craft a custom TCP packet with specific flags. Which library is best suited for low-level packet manipulation?
Medium11A penetration tester is reviewing source code and wants to identify common hardcoded credentials and input validation gaps. Which three checks should the tester perform? (Choose THREE.)
Easy12A tester needs to enumerate Windows domain users and groups from a compromised system. Which PowerShell script would be most useful?
Medium13A penetration tester is reviewing a Python script used for a custom exploit. Which of the following code snippets contains a dangerous function that could lead to remote code execution?
Medium14A penetration tester needs to perform an online brute-force attack against an SSH service. Which tool is most appropriate?
Easy15A penetration tester has captured a WPA2 handshake. Which tool from the Aircrack-ng suite is used to crack the pre-shared key?
Medium16A penetration tester wants to exploit a Windows system using a known vulnerability and gain a meterpreter session. Which tool is most appropriate?
Medium17During a penetration test, the tester wants to capture network traffic for later analysis. Which tool is most appropriate for capturing packets and saving them to a pcap file?
Easy18A penetration tester has obtained a set of NTLM password hashes from a Windows domain controller. The tester wants to perform an offline cracking attack using GPU acceleration. Which tool is best suited for this purpose?
Medium19A penetration tester has captured network traffic and wants to analyze it using Wireshark. Which two actions can the tester perform to focus on specific types of communication? (Choose TWO.)
Medium20A tester needs to perform an online brute-force attack against an SSH service. Which tool is most suitable?
Medium21During a source code review of a PHP application, the tester finds the following line: $query = "SELECT * FROM users WHERE username = '" . $_POST['username'] . "'"; Which vulnerability is present?
Hard22A penetration tester is analyzing a compiled Linux binary that appears to validate license keys. The tester wants to understand the validation logic without access to source code. The binary is stripped of symbols and uses anti-debugging techniques. Which approach is most effective for discovering the validation algorithm?
Hard23A penetration tester is performing a cloud security audit of an AWS environment. Which tool is specifically designed for AWS exploitation and post-exploitation, including privilege escalation and persistence?
Hard24During a penetration test, a tester needs to perform a deauthentication attack to force a client to reconnect and capture the WPA handshake. Which two tools from the Aircrack-ng suite are required? (Choose TWO.)
Medium25During a reverse engineering task on a .NET binary, which tool would allow you to decompile the code into readable C# source code?
Hard26Which tool would be best for capturing and analyzing network packets to troubleshoot a web application?
Easy27After gaining initial access to a Windows domain controller, a tester wants to extract password hashes from the SAM database and domain account hashes. Which Impacket tool is designed for this purpose?
Medium28After gaining initial access to a Windows system, a penetration tester wants to extract password hashes from the local SAM database. Which Impacket tool should be used?
Medium29A tester needs to brute-force SSH credentials on a target. Which tool is most appropriate for this task?
Medium30A penetration tester is writing a Bash script to automate scanning of multiple subnets with Nmap and parse the output. Which three features are commonly used in such a script? (Choose THREE.)
Medium31A tester wants to perform an evil twin attack to capture WPA handshakes. Which tool from the Aircrack-ng suite is used to deauthenticate clients from a legitimate AP to force reconnection to the rogue AP?
Medium32A tester wants to perform a Kerberoasting attack against an Active Directory environment. Which Impacket tool would be most appropriate?
Medium33During a web application test, a penetration tester needs to intercept and modify HTTP requests before forwarding them to the server. Which tool is best suited for this task?
Easy34A penetration tester is writing a Python script to send a crafted TCP packet to a target. Which Python library should the tester use for low-level packet crafting and injection?
Medium35A penetration tester is conducting a wireless assessment and needs to capture the four-way handshake to perform offline WPA cracking. Which tool is best suited for capturing the handshake?
Hard36A penetration tester is conducting a vulnerability assessment of a Linux web server. The tester runs a scan with Nikto and receives a finding indicating that the server is potentially vulnerable to a cross-site scripting (XSS) attack on a specific parameter. To confirm the finding, the tester wants to manually verify the XSS vulnerability. Which action should the tester take?
Medium37During a web application test, a penetration tester intercepts requests between the browser and server and modifies them in real time. Which Burp Suite tool is designed for this purpose?
Medium38A penetration tester needs to perform a Kerberoasting attack against a Windows Active Directory environment. Which tool from the Impacket suite should the tester use to request service tickets and extract TGS hashes for offline cracking?
Medium39A penetration tester is conducting a wireless security assessment. The target network uses WPA2-PSK. The tester has captured the four-way handshake. Which tool from the Aircrack-ng suite can be used to attempt to recover the pre-shared key by performing a dictionary attack?
Hard40During a cloud security assessment of AWS, a tester wants to identify misconfigurations using automated tools. Which THREE tools are specifically designed for AWS security auditing?
Hard41Which PowerShell script is commonly used for post-exploitation enumeration of Active Directory, such as querying user accounts and group memberships?
Easy42During a web application penetration test, the tester captures a login request in Burp Suite and wants to automate a brute-force attack against the password field. Which Burp Suite tool is specifically designed for this purpose?
Medium43A penetration tester needs to enumerate Active Directory users and groups from a Windows domain. Which PowerShell tool is specifically designed for AD enumeration and is commonly used in post-exploitation?
Easy44A penetration tester is performing a password cracking task against a dump of NTLM hashes obtained from a Windows domain controller. Which tool would be the most efficient for this task?
Medium45A penetration tester is conducting a post-exploitation phase on a Windows target and wants to dump credentials. Which of the following tools can be used? (Choose TWO.)
Medium46A penetration tester needs to perform a dictionary attack against an SSH service. Which of the following tools is best suited for this task?
Medium47A penetration tester is reviewing a Java application for insecure deserialization vulnerabilities. Which of the following should the tester look for? (Choose TWO.)
Medium48During a code review of a PHP web application, you encounter the following code: $result = mysql_query("SELECT * FROM users WHERE username='" . $_GET['user'] . "'");. Which vulnerability does this represent?
Hard49A penetration tester is performing a vulnerability assessment of a web application. The tester wants to identify input validation vulnerabilities that could lead to injection attacks. Which two techniques are most effective for discovering injection flaws such as SQL injection and command injection? (Choose two.)
Hard50A penetration tester is reverse-engineering a .NET binary to understand its authentication logic. Which three tools are suitable for decompiling .NET assemblies? (Choose THREE.)
Hard51A penetration tester is analyzing a Linux binary and wants to decompile it to understand its logic. Which open-source tool is specifically designed for reverse engineering and can generate C-like pseudocode from compiled binaries?
Hard52A penetration tester is performing a wireless assessment and wants to set up an evil twin attack. Which of the following steps are necessary? (Choose THREE.)
HardOther domains
All PT0-003 exam domains
Frequently asked questions
- What does the Vulnerability Discovery and Analysis domain cover on the PT0-003 exam?
- Be able to read a code snippet or scenario and name the exact flaw, library, or tool. The most important thing is matching the tool to the task: Scapy for packet crafting, Pacu for AWS post-exploitation, and correct vulnerability classification for injection flaws.
- How many questions are in this domain?
- This page lists all 52 Vulnerability Discovery and Analysis questions in the PT0-003 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Vulnerability Discovery and Analysis questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.