Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA PenTest+ PT0-003 Questions and answers with CertsForce

Viewing page 3 out of 10 pages
Viewing questions 21-30 out of questions
Questions # 21:

During an internal penetration test, the tester uses the following command:

C:\ Invoke-mimikatz.ps1 " kerberos::golden /domain:test.local /sid:S-1-5-21-3234... /target: dc01.test.local /service:CIFS /RC4:237749d82... /user:support.test.local /ptt "

Which of the following best describes the tester’s goal when executing this command?

Options:

A.

Bypassing normal authentication


B.

Enumerating shares


C.

Obtaining current user credentials


D.

Using password spraying


Expert Solution
Questions # 22:

A penetration tester has adversely affected a critical system during an engagement, which could have a material impact on the organization. Which of the following should the penetration tester do to address this issue?

Options:

A.

Restore the configuration.


B.

Perform a BIA.


C.

Follow the escalation process.


D.

Select the target.


Expert Solution
Questions # 23:

A penetration tester is trying to execute a post-exploitation activity and creates the follow script:

Question # 23

Which of the following best describes the tester ' s objective?

Options:

A.

To download data from an API endpoint


B.

To download data from a cloud storage


C.

To exfiltrate data over alternate data streams


D.

To exfiltrate data to cloud storage


Expert Solution
Questions # 24:

Which of the following activities should be performed to prevent uploaded web shells from being exploited by others?

Options:

A.

Remove the persistence mechanisms.


B.

Spin down the infrastructure.


C.

Preserve artifacts.


D.

Perform secure data destruction.


Expert Solution
Questions # 25:

A penetration tester discovers exposed cloud storage buckets and needs to access the contents. Which of the following should the tester do?

Options:

A.

Protocol fingerprinting


B.

Credential brute forcing


C.

Service discovery


D.

Secrets enumeration


Expert Solution
Questions # 26:

Which of the following techniques is the best way to avoid detection by Data Loss Prevention (DLP) tools?

Options:

A.

Encoding


B.

Compression


C.

Encryption


D.

Obfuscation


Expert Solution
Questions # 27:

During a vulnerability assessment, a penetration tester finds the following information:

KRBTGT account with more than 1250 days without password change.

Which of the following tools could an attacker use to exploit this vulnerability?

Options:

A.

Mimikatz


B.

John the Ripper


C.

Hashcat


D.

Hydra


Expert Solution
Questions # 28:

A penetration tester completes an authenticated vulnerability scan of a host and receives the following results:

Line 1: 10.1.10.127 resolves to comptia.foo.local

Line 2: FOUND ports 445, 3389 TCP open

Line 3: OS Fingerprint 70% confidence Windows 7 SP0

Line 4: SMB signing is disabled

Line 5: Scan Complete.

Which of the following is most likely to cause stability issues when a session is created on a target machine?

Options:

A.

Running Responder with default settings and using Impacket


B.

Running Nmap with safe scripts enabled and targeting RDP


C.

Running Metasploit utilizing the EternalBlue module


D.

Running Hydra on the local user at one attempt per second


Expert Solution
Questions # 29:

Which of the following activities should be performed to prevent uploaded web shells from being exploited by others?

Options:

A.

Removing persistence mechanisms


B.

Uninstalling tools


C.

Preserving artifacts


D.

Reverting configuration changes


Expert Solution
Questions # 30:

Which of the following components of a penetration test report most directly contributes to prioritizing remediations?

Options:

A.

Proof of concept


B.

Risk scoring


C.

Attack narrative


D.

Executive summary


Expert Solution
Viewing page 3 out of 10 pages
Viewing questions 21-30 out of questions