Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the CompTIA PenTest+ PT0-003 Questions and answers with CertsForce

Viewing page 8 out of 10 pages
Viewing questions 71-80 out of questions
Questions # 71:

A penetration tester cannot complete a full vulnerability scan because the client ' s WAF is blocking communications. During which of the following activities should the penetration tester discuss this issue with the client?

Options:

A.

Goal reprioritization


B.

Peer review


C.

Client acceptance


D.

Stakeholder alignment


Expert Solution
Questions # 72:

Which of the following explains the reason a tester would opt to use DREAD over PTES during the planning phase of a penetration test?

Options:

A.

The tester is conducting a web application test.


B.

The tester is assessing a mobile application.


C.

The tester is evaluating a thick client application.


D.

The tester is creating a threat model.


Expert Solution
Questions # 73:

During a security audit, a penetration tester wants to exploit a vulnerability in a common network protocol. The protocol allows encrypted communications to be intercepted and manipulated. Which of the following vulnerabilities should the tester exploit?

Options:

A.

CVE-202W-ZZZZ: Cisco ASA IKEv2/IPSec Fragmentation Vulnerability


B.

CVE-202Y-XXXX: Wireshark SSL/TLS Decryption Vulnerability


C.

CVE-202X-YYYY: OpenSSL DROWN Attack


D.

CVE-202Z-WWWW: Microsoft SMBv1 EternalBlue Exploit


Expert Solution
Questions # 74:

Which of the following elements of a penetration test report can be used to most effectively prioritize the remediation efforts for all the findings?

Options:

A.

Methodology


B.

Detailed findings list


C.

Risk score


D.

Executive summary


Expert Solution
Questions # 75:

A penetration tester receives the following output when enumerating a local user:

User compromised_user may run the following commands on localhost:

root (NO PASSWD): /bin/vim

The tester suspects that another host on the same subnet is also vulnerable. Which of the following is the best method to validate whether the other host is vulnerable?

Options:

A.

ssh compromised_user@victimhost " vim; echo $? "


B.

ssh compromised_user@victimhost " sudo -l "


C.

ssh compromised_user@victimhost " bash -c vim "


D.

ssh compromised_user@victimhost " ls -lah /bin/vim "


Expert Solution
Questions # 76:

A penetration tester gains initial access to a target system by exploiting a recent RCE vulnerability. The patch for the vulnerability will be deployed at the end of the week. Which of the following utilities would allow the tester to reenter the system remotely after the patch has been deployed? (Select two).

Options:

A.

schtasks.exe


B.

rundll.exe


C.

cmd.exe


D.

chgusr.exe


E.

sc.exe


F.

netsh.exe


Expert Solution
Questions # 77:

A penetration tester wants to verify whether passwords from a leaked password list can be used to access an SSH server as a legitimate user. Which of the following is the most appropriate tool for this task?

Options:

A.

BloodHound


B.

Responder


C.

Burp Suite


D.

Hydra


Expert Solution
Questions # 78:

A penetration tester identifies the following open ports during a network enumeration scan:

PORT STATE SERVICE

22/tcp open ssh

80/tcp open http

111/tcp open rpcbind

443/tcp open https

27017/tcp open mongodb

50123/tcp open ms-rpc

Which of the following commands did the tester use to get this output?

Options:

A.

nmap -Pn -A 10.10.10.10


B.

nmap -sV 10.10.10.10


C.

nmap -Pn -w 10.10.10.10


D.

nmap -sV -Pn -p- 10.10.10.10


Expert Solution
Questions # 79:

A penetration tester wants to create a malicious QR code to assist with a physical security assessment. Which of the following tools has the built-in functionality most likely needed for this task?

Options:

A.

BeEF


B.

John the Ripper


C.

ZAP


D.

Evilginx


Expert Solution
Questions # 80:

A penetration tester identifies an exposed corporate directory containing first and last names and phone numbers for employees. Which of the following attack techniques would be the most effective to pursue if the penetration tester wants to compromise user accounts?

Options:

A.

Smishing


B.

Impersonation


C.

Tailgating


D.

Whaling


Expert Solution
Viewing page 8 out of 10 pages
Viewing questions 71-80 out of questions