Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA PenTest+ PT0-003 Questions and answers with CertsForce

Viewing page 5 out of 10 pages
Viewing questions 41-50 out of questions
Questions # 41:

During an engagement, a penetration tester found some weaknesses that were common across the customer’s entire environment. The weaknesses included the following:

Weaker password settings than the company standard

Systems without the company ' s endpoint security software installed

Operating systems that were not updated by the patch management system

Which of the following recommendations should the penetration tester provide to address the root issue?

Options:

A.

Add all systems to the vulnerability management system.


B.

Implement a configuration management system.


C.

Deploy an endpoint detection and response system.


D.

Patch the out-of-date operating systems.


Expert Solution
Questions # 42:

A penetration tester discovers evidence of an advanced persistent threat on the network that is being tested. Which of the following should the tester do next?

Options:

A.

Report the finding.


B.

Analyze the finding.


C.

Remove the threat.


D.

Document the finding and continue testing.


Expert Solution
Questions # 43:

A penetration tester gains access to a Windows machine and wants to further enumerate users with native operating system credentials. Which of the following should the tester use?

Options:

A.

route.exe print


B.

netstat.exe -ntp


C.

net.exe commands


D.

strings.exe -a


Expert Solution
Questions # 44:

A company hires a penetration tester to perform an external attack surface review as part of a security engagement. The company informs the tester that the main company domain to investigate is comptia.org. Which of the following should the tester do to accomplish the assessment objective?

Options:

A.

Perform information-gathering techniques to review internet-facing assets for the company.


B.

Perform a phishing assessment to try to gain access to more resources and users’ computers.


C.

Perform a physical security review to identify vulnerabilities that could affect the company.


D.

Perform a vulnerability assessment over the main domain address provided by the client.


Expert Solution
Questions # 45:

A penetration tester is evaluating a company’s cybersecurity preparedness. The tester wants to acquire valid credentials using a social engineering campaign. Which of the following tools and techniques are most applicable in this scenario? Select two.

Options:

A.

TruffleHog for collecting credentials


B.

Shodan for identifying potential targets


C.

Gophish for sending phishing emails


D.

Maltego for organizing targets


E.

theHarvester for discovering additional targets


F.

Evilginx for handling legitimate authentication requests through a proxy


Expert Solution
Questions # 46:

A penetration tester writes a Bash script to automate the execution of a ping command on a Class C network:

for var in --MISSING TEXT-- do

ping -c 1 192.168.10.$var

done

Which of the following pieces of code should the penetration tester use in place of —MISSING TEXT—?

Options:

A.

crunch 1 254 loop


B.

seq 1 254


C.

echo 1-254


D.

fl..254


Expert Solution
Questions # 47:

A penetration tester attempts to obtain the preshared key for a client ' s wireless network. Which of the following actions will most likely aid the tester?

Options:

A.

Deploying an evil twin with a WiFi Pineapple


B.

Performing a password spraying attack with Hydra


C.

Setting up a captive portal using SET


D.

Deauthenticating clients using aireplay-ng


Expert Solution
Questions # 48:

A penetration tester is assessing the security of a web application. When the tester attempts to access the application, the tester receives an HTTP 403 response. Which of the following should the penetration tester do to overcome this issue?

Options:

A.

Reset file and folder permissions on the web server.


B.

Obtain a valid X.509 certificate.


C.

Spoof the server’s MAC address.


D.

Use a legacy browser to access the page.


Expert Solution
Questions # 49:

A penetration tester uses Burp Suite to send the following request:

POST /loginPage HTTP/1.1

Host: 10.10.100.1:443

User-Agent: Mozilla/5.0 (X11; Linux;)

Accept: application/json, text/javascript, *

Cookie: as=ausnHsdyh6aBda

Connection: Close

{ " user " : " admin " , " password " : " admin ' or ' " }

Which of the following options best describes what the tester is executing?

Options:

A.

SQL injection


B.

Session hijack


C.

Brute-force attack on usernames or/and password


D.

Cross-site scripting


Expert Solution
Questions # 50:

A penetration tester is getting ready to conduct a vulnerability scan to evaluate an environment that consists of a container orchestration cluster. Which of the following tools would be best to use for this purpose?

Options:

A.

NSE


B.

Nessus


C.

CME


D.

Trivy


Expert Solution
Viewing page 5 out of 10 pages
Viewing questions 41-50 out of questions