Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the CompTIA PenTest+ PT0-003 Questions and answers with CertsForce

Viewing page 8 out of 9 pages
Viewing questions 71-80 out of questions
Questions # 71:

A penetration tester wants to use multiple TTPs to assess the reactions (alerted, blocked, and others) by the client’s current security tools. The threat-modeling team indicates the TTPs in the list might affect their internal systems and servers. Which of the following actions would the tester most likely take?

Options:

A.

Use a BAS tool to test multiple TTPs based on the input from the threat-modeling team.


B.

Perform an internal vulnerability assessment with credentials to review the internal attack surface.


C.

Use a generic vulnerability scanner to test the TTPs and review the results with the threat-modeling team.


D.

Perform a full internal penetration test to review all the possible exploits that could affect the systems.


Expert Solution
Questions # 72:

An external legal firm is conducting a penetration test of a large corporation. Which of the following would be most appropriate for the legal firm to use in the subject line of a weekly email update?

Options:

A.

Privileged & Confidential Status Update


B.

Action Required Status Update


C.

Important Weekly Status Update


D.

Urgent Status Update


Expert Solution
Questions # 73:

A penetration testing team wants to conduct DNS lookups for a set of targets provided by the client. The team crafts a Bash script for this task. However, they find a minor error in one line of the script:

1 #!/bin/bash

2 for i in $(cat example.txt); do

3 curl $i

4 done

Which of the following changes should the team make to line 3 of the script?

Options:

A.

resolvconf $i


B.

rndc $i


C.

systemd-resolve $i


D.

host $i


Expert Solution
Questions # 74:

A penetration tester wants to use PowerView in an AD environment. Which of the following is the most likely reason?

Options:

A.

To collect local hashes


B.

To decrypt stored passwords


C.

To enumerate user groups


D.

To escalate privileges


Expert Solution
Questions # 75:
Options:

A.

A generative AI assistant


B.

The customer's designated contact


C.

A cybersecurity industry peer


D.

A team member


Expert Solution
Questions # 76:

A penetration tester needs to identify all vulnerable input fields on a customer website. Which of the following tools would be best suited to complete this request?

Options:

A.

DAST


B.

SAST


C.

IAST


D.

SCA


Expert Solution
Questions # 77:

During an engagement, a penetration tester runs the following command against the host system:

host -t axfr domain.com dnsl.domain.com

Which of the following techniques best describes what the tester is doing?

Options:

A.

Zone transfer


B.

Host enumeration


C.

DNS poisoning


D.

DNS query


Expert Solution
Questions # 78:

SIMULATION

Using the output, identify potential attack vectors that should be further investigated.

Question # 78

Question # 78

Question # 78

Question # 78

Question # 78


Expert Solution
Questions # 79:

A penetration tester finds that an application responds with the contents of the /etc/passwd file when the following payload is sent:

<!DOCTYPE data [ ]>

&foo;

Which of the following should the tester recommend in the report to best prevent this type of vulnerability?

Options:

A.

Drop all excessive file permissions with chmod o-rwx


B.

Ensure the requests application access logs are reviewed frequently


C.

Disable the use of external entities


D.

Implement a WAF to filter all incoming requests


Expert Solution
Questions # 80:

During a security assessment, a penetration tester captures plaintext login credentials on the communication between a user and an authentication system. The tester wants to use this information for further unauthorized access.

Which of the following tools is the tester using?

Options:

A.

Burp Suite


B.

Wireshark


C.

Zed Attack Proxy (ZAP)


D.

Metasploit


Expert Solution
Viewing page 8 out of 9 pages
Viewing questions 71-80 out of questions