Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA PenTest+ PT0-003 Questions and answers with CertsForce

Viewing page 1 out of 10 pages
Viewing questions 1-10 out of questions
Questions # 1:

During an assessment, a penetration tester runs the following command:

setspn.exe -Q /

Which of the following attacks is the penetration tester preparing for?

Options:

A.

LDAP injection


B.

Pass-the-hash


C.

Kerberoasting


D.

Dictionary


Expert Solution
Questions # 2:

During a wireless penetration assessment for a small business client, a tester attempts to capture wireless packets. However, whenever the tester sets the capture device to monitor mode, it fails to see the client ' s wireless network, as provided by the scope. Which of the following is the most likely reason for this issue?

Options:

A.

The client ' s network uses 6GHz and not 5GHz/2.4GHz.


B.

The tester misconfigured the capture device.


C.

The client provided the wrong SSID for the network.


D.

The tester is not using Aircrack-ng.


Expert Solution
Questions # 3:

An external legal firm is conducting a penetration test of a large corporation. Which of the following would be most appropriate for the legal firm to use in the subject line of a weekly email update?

Options:

A.

Privileged & Confidential Status Update


B.

Action Required Status Update


C.

Important Weekly Status Update


D.

Urgent Status Update


Expert Solution
Questions # 4:

During a penetration test, the tester wants to obtain public information that could be used to compromise the organization ' s cloud infrastructure. Which of the following is the most effective resource for the tester to use for this purpose?

Options:

A.

Sensitive documents on a public cloud


B.

Open ports on the cloud infrastructure


C.

Repositories with secret keys


D.

SSL certificates on websites


Expert Solution
Questions # 5:

During a penetration test, the tester identifies several unused services that are listening on all targeted internal laptops. Which of the following technical controls should the tester recommend to reduce the risk of compromise?

Question # 5

Options:

A.

Multifactor authentication


B.

Patch management


C.

System hardening


D.

Network segmentation


Expert Solution
Questions # 6:

A penetration tester cannot use Nmap and must perform port discovery and banner grabbing for potential vulnerable SSH services. Given the following script:

#!/usr/bin/bash

ip_address = " 192.168.5. "

...

for i in {1..254}

do

--missing command--

done

...

Which of the following commands will best help the tester achieve this objective?

Options:

A.

ping -c 22 " $ip_address$i "


B.

nc " $ip_address$i " " :22 "


C.

arp " $ip_address$i " " :22 "


D.

curl scp:// " $ip_address$i " " :22 "


Expert Solution
Questions # 7:

A Chief Information Security Officer wants to automate adversarial activities from penetration tests that are relevant to the organization. Which of the following should a penetration tester do first to accomplish this task?

Options:

A.

Deploy a command-and-control server with custom profiles to facilitate execution.


B.

Use Python 3 with added testing libraries and script the relevant action to test.


C.

Utilize the PowerShell PowerView tool with custom scripting additions based on test results.


D.

Implement Atomic Red Team to chain critical TTPs and perform the test.


Expert Solution
Questions # 8:

During an engagement, a penetration tester runs the following command against the host system:

host -t axfr domain.com dnsl.domain.com

Which of the following techniques best describes what the tester is doing?

Options:

A.

Zone transfer


B.

Host enumeration


C.

DNS poisoning


D.

DNS query


Expert Solution
Questions # 9:

A company hires a penetration tester to test the security of its wireless networks. The main goal is to intercept and access sensitive data.

Which of the following tools should the security professional use to best accomplish this task?

Options:

A.

Metasploit


B.

WiFi-Pumpkin


C.

SET


D.

theHarvester


E.

WiGLE.net


Expert Solution
Questions # 10:

A penetration tester conducts OSINT for a client and discovers the robots.txt file explicitly blocks a major search engine. Which of the following would most likely help the penetration tester achieve the objective?

Options:

A.

Modifying the WAF


B.

Utilizing a CSRF attack


C.

Changing the robots.txt file


D.

Leveraging a competing provider


Expert Solution
Viewing page 1 out of 10 pages
Viewing questions 1-10 out of questions