Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA PenTest+ PT0-003 Questions and answers with CertsForce

Viewing page 2 out of 10 pages
Viewing questions 11-20 out of questions
Questions # 11:

While conducting OSINT, a penetration tester discovers the client ' s administrator posted part of an unsanitized firewall configuration to a troubleshooting message board. Which of the following did the penetration tester most likely use?

Options:

A.

HTML scraping


B.

Public code repository scanning


C.

Wayback Machine


D.

Search engine enumeration


Expert Solution
Questions # 12:

During a testing engagement, a penetration tester compromises a host and locates data for exfiltration. Which of the following are the best options to move the data without triggering a data loss prevention tool? (Select two).

Options:

A.

Move the data using a USB flash drive.


B.

Compress and encrypt the data.


C.

Rename the file name extensions.


D.

Use FTP for exfiltration.


E.

Encode the data as Base64.


F.

Send the data to a commonly trusted service.


Expert Solution
Questions # 13:

A penetration tester is performing a network security assessment. The tester wants to intercept communication between two users and then view and potentially modify transmitted data. Which of the following types of on-path attacks would be best to allow the penetration tester to achieve this result?

Options:

A.

DNS spoofing


B.

ARP poisoning


C.

VLAN hopping


D.

SYN flooding


Expert Solution
Questions # 14:

A penetration tester needs to obtain sensitive data from several executives who regularly work while commuting by train. Which of the following methods should the tester use for this task?

Options:

A.

Shoulder surfing


B.

Credential harvesting


C.

Bluetooth spamming


D.

MFA fatigue


Expert Solution
Questions # 15:

During a routine penetration test, the client’s security team observes logging alerts that indicate several ID badges were reprinted after working hours without authorization. Which of the following is the penetration tester most likely trying to do?

Options:

A.

Obtain long-term, valid access to the facility


B.

Disrupt the availability of facility access systems


C.

Change access to the facility for valid users


D.

Revoke access to the facility for valid users


Expert Solution
Questions # 16:

A penetration tester writes a Bash script to automate the execution of a ping command on a Class C network:

bash

for var in —MISSING TEXT—

do

ping -c 1 192.168.10.$var

done

Which of the following pieces of code should the penetration tester use in place of the —MISSING TEXT— placeholder?

Options:

A.

crunch 1 254 loop


B.

seq 1 254


C.

echo 1-254


D.

{1.-254}


Expert Solution
Questions # 17:

Which of the following frameworks can be used to classify threats?

Options:

A.

PTES


B.

STRIDE


C.

OSSTMM


D.

OCTAVE


Expert Solution
Questions # 18:

A penetration tester discovers data to stage and exfiltrate. The client has authorized movement to the tester ' s attacking hosts only. Which of the following would be most appropriate to avoid alerting the SOC?

Options:

A.

Apply UTF-8 to the data and send over a tunnel to TCP port 25.


B.

Apply Base64 to the data and send over a tunnel to TCP port 80.


C.

Apply 3DES to the data and send over a tunnel UDP port 53.


D.

Apply AES-256 to the data and send over a tunnel to TCP port 443.


Expert Solution
Questions # 19:

A tester is working on an engagement that has evasion and stealth requirements. Which of the following enumeration methods is the least likely to be detected by the IDS?

Options:

A.

curl https://api.shodan.io/shodan/host/search?key= < API_KEY > & query=hostname: < target >


B.

proxychains nmap -sV -T2 < target >


C.

for i in < target > ; do curl -k $i; done


D.

nmap -sV -T2 < target >


Expert Solution
Questions # 20:

A penetration tester has just started a new engagement. The tester is using a framework that breaks the life cycle into 14 components. Which of the following frameworks is the tester using?

Options:

A.

OWASP MASVS


B.

OSSTMM


C.

MITRE ATT & CK


D.

CREST


Expert Solution
Viewing page 2 out of 10 pages
Viewing questions 11-20 out of questions