Courseiva

PT0-003 · topic practice

Vulnerability Discovery and Analysis practice questions

This domain covers finding and validating weaknesses before exploitation: source code review, packet crafting, cloud and web misconfigurations, and tool-assisted discovery. Questions present short scenarios—a PHP snippet, an AWS audit, a Python script—and ask you to name the vulnerability, the right library, or the appropriate tool for the target environment.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Vulnerability Discovery and Analysis

What the exam tests

What to know about Vulnerability Discovery and Analysis

Be able to read a code snippet or scenario and name the exact flaw, library, or tool. The most important thing is matching the tool to the task: Scapy for packet crafting, Pacu for AWS post-exploitation, and correct vulnerability classification for injection flaws.

Crafting and inspecting packets with Scapy, including TCP flags, in Python scripts

Source code review for hardcoded credentials, injection flaws, and missing input validation

Identifying SQL injection in PHP string-concatenated queries using $_POST input

Using cloud exploitation tools such as Pacu for AWS privilege escalation and persistence

Watch out for

Common Vulnerability Discovery and Analysis exam traps

  • ▸Choosing requests or socket for raw packet crafting when Scapy is the intended low-level manipulation library.
  • ▸Reading a concatenated SQL query as XSS or command injection instead of recognizing SQL injection.
  • ▸Confusing general cloud audit tools with AWS-specific exploitation frameworks like Pacu.

Practice set

Vulnerability Discovery and Analysis questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Review the full subnetting walkthrough →

During a penetration test, you are asked to identify all live hosts on a subnet. Which Nmap scan type is most likely to evade firewalls and determine if a host is up without completing the TCP handshake?

During a web application test, a penetration tester needs to modify an HTTP request in real-time, send it repeatedly with different parameter values, and analyze the responses. Which Burp Suite tool is best suited for this task?

Which tool is used for security auditing of AWS environments and can enumerate misconfigurations in IAM, S3, and other services?

A penetration tester is analyzing a network capture with Wireshark. Which TWO of the following are common uses of Wireshark in a pentest?

A penetration tester wants to identify all live hosts and open ports on a network segment. Which Nmap scan type is most efficient for this purpose?

Question 6hardmultiple choice
Read the full wireless explanation →

During a wireless penetration test, a tester captures WPA2 handshakes but finds they are unable to crack the password using a dictionary attack. Which technique could improve the likelihood of cracking the password?

Question 7hardmultiple choice
Read the full DNS explanation →

A tester decompiles a .NET application using dnSpy and finds a function that loads a serialized object from a file. Which vulnerability is most likely present?

Question 8mediummulti select
Read the full wireless explanation →

A penetration tester is conducting a wireless assessment and wants to capture WPA handshakes for offline cracking. Which two tools from the Aircrack-ng suite would be used? (Choose two.)

A tester has compromised a Linux server and wants to maintain persistence. Which three actions would be typical for post-exploitation? (Choose three.)

A penetration tester is reviewing code for insecure deserialization vulnerabilities. Which two languages are commonly associated with this vulnerability? (Choose two.)

Which cloud security auditing tool is designed specifically for assessing AWS environments and can perform enumeration of misconfigurations?

A penetration tester is performing post-exploitation on a Windows domain controller and wants to extract Kerberos tickets for offline cracking. Which two Impacket tools can be used to obtain ticket-granting service (TGS) tickets? (Choose TWO.)

A penetration tester is assessing a web application that reflects user input into HTML responses without sanitization. The tester needs to determine whether a reflected cross-site scripting payload can execute JavaScript in a victim's browser. The application sets a strict Content Security Policy header but does not block inline event handlers. Which tool should the tester use to craft and verify the payload's execution in a controlled browser environment?

A penetration tester is performing an authenticated vulnerability scan against a Windows Server 2022 host using Tenable Nessus. The scan policy is configured with 'Perform thorough tests' and 'Enable plugin families for Windows'. After the scan completes, the report shows several vulnerabilities with a severity of Critical. However, the tester notices that some of these findings are false positives because the vulnerable software is not actually installed. Which Nessus feature should the tester use to verify the findings and reduce false positives?

A penetration tester wants to exploit a vulnerable service on a target using a known module. Which framework provides a large database of exploit modules, payloads, and post-exploitation tools?

After gaining initial access to a Windows domain controller, a tester wants to extract password hashes from the SAM database and domain account hashes. Which Impacket tool is designed for this purpose?

Question 17mediummultiple choice
Read the full wireless explanation →

A penetration tester has captured a WPA2 handshake. Which tool from the Aircrack-ng suite is used to crack the pre-shared key?

During a code review of a PHP web application, you encounter the following code: $result = mysql_query("SELECT * FROM users WHERE username='" . $_GET['user'] . "'");. Which vulnerability does this represent?

A tester needs to brute-force SSH credentials on a target. Which tool is most appropriate for this task?

Question 20mediummultiple choice
Study the full Python automation breakdown →

In a Python script for a penetration test, you need to craft a custom TCP packet with specific flags. Which library is best suited for low-level packet manipulation?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Vulnerability Discovery and Analysis sessions

Start a Vulnerability Discovery and Analysis only practice session

Every question in these sessions is drawn from the Vulnerability Discovery and Analysis domain — nothing else.

Related practice questions

Related PT0-003 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the PT0-003 exam test about Vulnerability Discovery and Analysis?
Be able to read a code snippet or scenario and name the exact flaw, library, or tool. The most important thing is matching the tool to the task: Scapy for packet crafting, Pacu for AWS post-exploitation, and correct vulnerability classification for injection flaws.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Vulnerability Discovery and Analysis questions in a focused session?
Yes — the session launcher on this page draws every question from the Vulnerability Discovery and Analysis domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other PT0-003 topics?
Use the topic links above to move to related areas, or go back to the PT0-003 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the PT0-003 exam covers. They are not copied from any real exam or dump site.