PT0-003 · domain
Vulnerability Discovery and Analysis
Practise CompTIA PenTest+ (PT0-003) Vulnerability Discovery and Analysis practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Vulnerability Discovery and Analysis questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Vulnerability Discovery and Analysis
Vulnerability Discovery and Analysis questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Vulnerability Discovery and Analysis exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Vulnerability Discovery and Analysis questions (8)
Click any question to see the full explanation, or start a practice session above.
During code review, a penetration tester identifies the following line in a PHP web application: $sql = "SELECT * FROM users WHERE username='" . $_GET['user'] . "'"; Which type of vulnerability is most likely present?
Medium2A penetration tester has captured a WPA2 handshake. Which tool from the Aircrack-ng suite is used to crack the pre-shared key?
Medium3A penetration tester has obtained a set of NTLM password hashes from a Windows domain controller. The tester wants to perform an offline cracking attack using GPU acceleration. Which tool is best suited for this purpose?
Medium4A penetration tester has captured network traffic and wants to analyze it using Wireshark. Which two actions can the tester perform to focus on specific types of communication? (Choose TWO.)
Medium5A penetration tester is writing a Python script to send a crafted TCP packet to a target. Which Python library should the tester use for low-level packet crafting and injection?
Medium6During a cloud security assessment of AWS, a tester wants to identify misconfigurations using automated tools. Which THREE tools are specifically designed for AWS security auditing?
Hard7Which tool is used for security auditing of AWS environments and can enumerate misconfigurations in IAM, S3, and other services?
Easy8A penetration tester needs to enumerate Active Directory users and groups from a Windows domain. Which PowerShell tool is specifically designed for AD enumeration and is commonly used in post-exploitation?
EasyOther domains
All PT0-003 exam domains
Frequently asked questions
- What does the Vulnerability Discovery and Analysis domain cover on the PT0-003 exam?
- Vulnerability Discovery and Analysis questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 8 Vulnerability Discovery and Analysis questions in the PT0-003 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Vulnerability Discovery and Analysis questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.