CompTIA PenTest+ - PT0-003 FREE EXAM DUMPS QUESTIONS & ANSWERS
A penetration tester observes an employee logging in to their laptop. The penetration tester wants to gain access to information with the least intervention. Which of the following actions should the penetration tester take?
Correct Answer: D
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
Which of the following is the most efficient way to infiltrate a file containing data that could be sensitive?
Correct Answer: D
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
During an assessment, a penetration tester manages to get RDP access via a low-privilege user.
The tester attempts to escalate privileges by running the following commands:
Import-Module .\PrintNightmare.psi
Invoke-Nightmare -NewUser "hacker" -NewPassword "Password123!" -
DriverName "Print"
The tester attempts to further enumerate the host with the new administrative privileges by using the runascommand. However, the access level is still low. Which of the following actions should the penetration tester take next?
The tester attempts to escalate privileges by running the following commands:
Import-Module .\PrintNightmare.psi
Invoke-Nightmare -NewUser "hacker" -NewPassword "Password123!" -
DriverName "Print"
The tester attempts to further enumerate the host with the new administrative privileges by using the runascommand. However, the access level is still low. Which of the following actions should the penetration tester take next?
Correct Answer: C
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
Given the following script:

Which of the following is the penetration tester most likely trying to do?

Which of the following is the penetration tester most likely trying to do?
Correct Answer: A
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
During an internal penetration test, a tester compromises a Windows OS-based endpoint and bypasses the defensive mechanisms. The tester also discovers that the endpoint is part of an Active Directory (AD) local domain.
The tester's main goal is to leverage credentials to authenticate into other systems within the Active Directory environment.
Which of the following steps should the tester take to complete the goal?
The tester's main goal is to leverage credentials to authenticate into other systems within the Active Directory environment.
Which of the following steps should the tester take to complete the goal?
Correct Answer: D
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
A penetration tester writes a Bash script to automate the execution of a ping command on a Class C network:

Which of the following pieces of code should the penetration tester use in place of the -- MISSING-TEXT--placeholder?

Which of the following pieces of code should the penetration tester use in place of the -- MISSING-TEXT--placeholder?
Correct Answer: C
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
A penetration tester needs to test a very large number of URLs for public access. Given the following code snippet:

Which of the following changes is required?

Which of the following changes is required?
Correct Answer: C
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
During an assessment, a penetration tester compromises some machines but finds that none of the accounts have sufficient access to the target HR database server. In order to enumerate accounts with sufficient permissions, the tester wants to model an attack path before taking further action. Which of the following tools should the tester use to meet this objective?
Correct Answer: E
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
Which of the following tasks would ensure the key outputs from a penetration test are not lost as part of the cleanup and restoration activities?
Correct Answer: A
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
During a web application assessment, a penetration tester identifies an input field that allows JavaScript injection. The tester inserts a line of JavaScript that results in a prompt, presenting a text box when browsing to the page going forward. Which of the following types of attacks is this an example of?
Correct Answer: A
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
During a security assessment, a penetration tester gains access to an internal server and manipulates some data to hide its presence. Which of the following is the best way for the penetration tester to hide the activities performed?
Correct Answer: C
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).
Which of the following components of a penetration test report most directly contributes to prioritizing remediations?
Correct Answer: C
Vote an answer
Explanation: Only visible for FreeCram members. You can sign-up / login (it's free).