Comptia

PT0-003 Free Practice Questions — Page 2

Question 11

A penetration tester completes an authenticated vulnerability scan of a host and receives the following results: Which of the following is most likely to cause stability when a session is created on a target machine?

A. Running Responder with default settings and using Impacket
B. Running Nmap with safe scripts enabled and targeting RDP
C. Running Metasploit utilizing the EternalBlue module
D. Running Hydra on the local user at one attempt per second
Show Answer
Correct Answer: D
Explanation:
Interpreting the question as written ("most likely to cause stability when a session is created"), the activity that is least disruptive and most stable is a slow, controlled action. Running Hydra against a local user at one attempt per second generates minimal load and is unlikely to impact system stability. The other options—especially exploiting EternalBlue—are well known to risk crashes or instability, while Responder/Impacket and Nmap scripting can also introduce network or service disruption.

Question 12

A penetration tester obtains a regular domain user’s set of credentials. The tester wants to attempt a dictionary attack by creating a custom word list based on the Active Directory password policy. Which of the following tools should the penetration tester use to retrieve the password policy?

A. Responder
B. CrackMapExec
C. Hydra
D. msfvenom
Show Answer
Correct Answer: B
Explanation:
CrackMapExec can authenticate to Active Directory with valid domain user credentials and enumerate domain information, including the domain password policy (such as minimum length, complexity requirements, and lockout policy). This information is useful for creating a targeted custom word list. The other tools focus on poisoning, password attacks, or payload generation rather than policy enumeration.

Question 13

HOTSPOT - A security analyst is asked to perform various techniques to assess organizational security. INSTRUCTIONS - Select the command that will successfully accomplish each objective. Commands may only be used once. If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Illustration for PT0-003 question 13
Show Answer
Correct Answer: Network reconnaissance: nmap -A 192.168.50.0/32 Folder inheritance: icacls "..\files" Searching file system: find / -name ".htaccess" Confirm connectivity: ping 203.11.14.32 -t Enumerate listeners: netstat -an
Explanation:
nmap performs active network reconnaissance. icacls displays and manages Windows ACL inheritance. find searches the filesystem for specific filenames. ping verifies network connectivity to a host. netstat lists active connections and listening ports.

Question 14

HOTSPOT - A penetration tester has identified a series of files throughout an assessment. INSTRUCTIONS - Select the most appropriate action the penetration tester should take for each file. The same action may be selected multiple times. If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Illustration for PT0-003 question 14
Show Answer
Correct Answer: Benefits – Recommend to change file permissions Employee Performance – Recommend to change file permissions Prospective Acquisitions – Recommend to change file permissions Draft – Press Release – Final – Notate in report
Explanation:
Sensitive internal documents exposed too broadly should have permissions tightened. The draft press release is intended for public release, so its presence is noted without remediation.

Question 15

A penetration tester is attempting to exfiltrate sensitive data from a client environment without alerting the client’s blue team. Which of the following exfiltration methods most likely remain undetected?

A. Cloud storage
B. Email
C. Domain Name System
D. Test storage sites
Show Answer
Correct Answer: C
Explanation:
DNS-based exfiltration often blends in with normal outbound DNS traffic, which is typically allowed through firewalls and less closely inspected than email, cloud storage uploads, or known test storage sites. As a result, it is more likely to evade detection by a blue team.

Question 16

During a penetration test for a client that has a diverse infrastructure, the tester scans the network using Nmap and observes the following output: Which of the following would most likely be the target device?

A. Switch
B. SCADA
C. IoT
D. Router
Show Answer
Correct Answer: C
Explanation:
Based on typical Nmap results used in such questions, the scan likely showed characteristics of an embedded device: a small number of lightweight services (e.g., HTTP/HTTPS with lighttpd or busybox), unusual high ports, UPnP, or lack of enterprise routing/switching services. Switches and routers usually expose management protocols like SNMP, SSH/Telnet, or vendor‑specific services, while SCADA devices often use well‑known industrial protocols (e.g., Modbus, DNP3). The observed service pattern most closely aligns with a consumer or embedded Internet‑connected device, making an IoT device the most likely target.

Question 17

A penetration tester reviews the following output: Which of the following most likely describes the function of this system?

A. Enterprise mail server
B. Honeypot
C. Stand-alone web server
D. Domain Controller
Show Answer
Correct Answer: B
Explanation:
The system presents conflicting characteristics that would not occur on a legitimate production server. A Windows Domain Controller would not expose a Debian-branded OpenSSH service, nor would it typically rely on SSH at all. This kind of OS/service mismatch is a classic indicator of a deliberately misrepresented system designed to attract attackers, which most closely aligns with a honeypot rather than a real domain controller or a normal web/mail server.

Question 18

A penetration tester sets up a C2 server to manage and control payloads deployed in the target network. Which of the following tools is the most suitable for establishing a robust and stealthy connection?

A. ProxyChains
B. Covenant
C. PsExec
D. sshuttle
Show Answer
Correct Answer: B
Explanation:
A C2 server requires a dedicated command-and-control framework to manage implants, tasks, persistence, and stealthy communications. Covenant is purpose-built for this role. ProxyChains and sshuttle only provide traffic routing/tunneling, and PsExec is for remote command execution, not C2 management.

Question 19

A penetration tester uses the Intruder tool from the Burp Suite Community Edition while assessing a web application. The tester notices the test is taking too long to complete. Which of the following tools can the tester use to accelerate the test and achieve similar results?

A. TruffleHog
B. Postman
C. Wfuzz
D. WPScan
Show Answer
Correct Answer: C
Explanation:
Burp Suite Community Edition’s Intruder is deliberately throttled, making large-scale fuzzing and brute-force tests slow. Wfuzz is a dedicated, command-line web fuzzing tool designed for speed and automation, allowing similar payload-based attacks (parameter fuzzing, directory brute-forcing, etc.) much faster. The other options target different use cases: TruffleHog scans for secrets, Postman is an API testing client, and WPScan is specific to WordPress.

Question 20

A penetration tester discovers a deprecated directory in which files are accessible to anyone. Which of the following would most likely assist the penetration tester in finding sensitive information without raising suspicion?

A. Enumerating cached pages available on web pages
B. Looking for externally available services
C. Scanning for exposed ports associated with the domain
D. Searching for vulnerabilities and potential exploits
Show Answer
Correct Answer: A
Explanation:
Enumerating cached pages (e.g., search engine caches or archived versions) is a passive technique that can reveal sensitive files or information from a deprecated, publicly accessible directory without directly interacting with the target system. This minimizes the chance of detection compared to active techniques like port scanning, service enumeration, or vulnerability scanning, which generate logs and raise suspicion.

$19

Get all 220 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.