Pass the CompTIA PenTest+ PT0-002 Questions and answers with CertsForce

Viewing page 4 out of 14 pages
Viewing questions 31-40 out of questions
Questions # 31:

A penetration tester is conducting a penetration test and discovers a vulnerability on a web server that is owned by the client. Exploiting the vulnerability allows the tester to open a reverse shell. Enumerating the server for privilege escalation, the tester discovers the following:

Question # 31

Which of the following should the penetration tester do NEXT?

Options:

A.

Close the reverse shell the tester is using.


B.

Note this finding for inclusion in the final report.


C.

Investigate the high numbered port connections.


D.

Contact the client immediately.


Expert Solution
Questions # 32:

A penetration tester is conducting a penetration test. The tester obtains a root-level shell on a Linux server and discovers the following data in a file named password.txt in the /home/svsacct directory:

U3VQZXIkM2NyZXQhCg==

Which of the following commands should the tester use NEXT to decode the contents of the file?

Options:

A.

echo U3VQZXIkM2NyZXQhCg== | base64 ג€"d


B.

tar zxvf password.txt


C.

hydra ג€"l svsacct ג€"p U3VQZXIkM2NyZXQhCg== ssh://192.168.1.0/24


D.

john --wordlist /usr/share/seclists/rockyou.txt password.txt


Expert Solution
Questions # 33:

The following output is from reconnaissance on a public-facing banking website:

Question # 33

Based on these results, which of the following attacks is MOST likely to succeed?

Options:

A.

A birthday attack on 64-bit ciphers (Sweet32)


B.

An attack that breaks RC4 encryption


C.

An attack on a session ticket extension (Ticketbleed)


D.

A Heartbleed attack


Expert Solution
Questions # 34:

A penetration tester finds a PHP script used by a web application in an unprotected internal source code repository. After reviewing the code, the tester identifies the following:

Question # 34

Which of the following combinations of tools would the penetration tester use to exploit this script?

Options:

A.

Hydra and crunch


B.

Netcat and cURL


C.

Burp Suite and DIRB


D.

Nmap and OWASP ZAP


Expert Solution
Questions # 35:

A client would like to have a penetration test performed that leverages a continuously updated TTPs framework and covers a wide variety of enterprise systems and networks. Which of the following methodologies should be used to BEST meet the client's expectations?

Options:

A.

OWASP Top 10


B.

MITRE ATT&CK framework


C.

NIST Cybersecurity Framework


D.

The Diamond Model of Intrusion Analysis


Expert Solution
Questions # 36:

Given the following code:

Question # 36

Which of the following data structures is systems?

Options:

A.

A tuple


B.

A tree


C.

An array


D.

A dictionary


Expert Solution
Questions # 37:

Which of the following is the BEST resource for obtaining payloads against specific network infrastructure products?

Options:

A.

Exploit-DB


B.

Metasploit


C.

Shodan


D.

Retina


Expert Solution
Questions # 38:

Which of the following tools would be BEST suited to perform a manual web application security assessment? (Choose two.)

Options:

A.

OWASP ZAP


B.

Nmap


C.

Nessus


D.

BeEF


E.

Hydra


F.

Burp Suite


Expert Solution
Questions # 39:

During a penetration test, a tester is able to change values in the URL from example.com/login.php?id=5 to example.com/login.php?id=10 and gain access to a web application. Which of the following vulnerabilities has the penetration tester exploited?

Options:

A.

Command injection


B.

Broken authentication


C.

Direct object reference


D.

Cross-site scripting


Expert Solution
Questions # 40:

A penetration tester is conducting an engagement against an internet-facing web application and planning a phishing campaign. Which of the following is the BEST passive method of obtaining the technical contacts for the website?

Options:

A.

WHOIS domain lookup


B.

Job listing and recruitment ads


C.

SSL certificate information


D.

Public data breach dumps


Expert Solution
Viewing page 4 out of 14 pages
Viewing questions 31-40 out of questions