最新的CompTIA PenTest+ - PT0-003免費考試真題
The following file was obtained during reconnaissance:

Which of the following is most likely to be successful if a penetration tester achieves non- privileged user access?

Which of the following is most likely to be successful if a penetration tester achieves non- privileged user access?
正確答案: D
說明:(僅 Fast2test 成員可見)
Which of the following is necessary during preengagement activities to proceed with an engagement?
正確答案: B
說明:(僅 Fast2test 成員可見)
A client warns the assessment team that an ICS application is maintained by the manufacturer.
Any tampering of the host could void the enterprise support terms of use. Which of the following techniques would be most effective to validate whether the application encrypts communications in transit?
Any tampering of the host could void the enterprise support terms of use. Which of the following techniques would be most effective to validate whether the application encrypts communications in transit?
正確答案: C
說明:(僅 Fast2test 成員可見)
A penetration tester writes a Bash script to automate the execution of a ping command on a Class C network:

Which of the following pieces of code should the penetration tester use in place of the -- MISSING-TEXT--placeholder?

Which of the following pieces of code should the penetration tester use in place of the -- MISSING-TEXT--placeholder?
正確答案: D
說明:(僅 Fast2test 成員可見)
A penetration tester finds an unauthenticated RCE vulnerability on a web server and wants to use it to enumerate other servers on the local network. The web server is behind a firewall that allows only an incoming connection to TCP ports 443 and 53 and unrestricted outbound TCP connections. The target web server is https://target.comptia.org. Which of the following should the tester use to perform the task with the fewest web requests?
正確答案: B
說明:(僅 Fast2test 成員可見)
During an assessment, a penetration tester wants to extend the vulnerability search to include the use of dynamic testing. Which of the following tools should the tester use?
正確答案: A
說明:(僅 Fast2test 成員可見)
During an assessment, a penetration tester obtains a low-privilege shell and then runs the following command:
findstr /SIM /C:"pass" *.txt *.cfg *.xml
Which of the following is the penetration tester trying to enumerate?
findstr /SIM /C:"pass" *.txt *.cfg *.xml
Which of the following is the penetration tester trying to enumerate?
正確答案: C
說明:(僅 Fast2test 成員可見)
Which of the following is most important when communicating the need for vulnerability remediation to a client at the conclusion of a penetration test?
正確答案: A
說明:(僅 Fast2test 成員可見)
Which of the following implements the "five whys" methodology during the execution phase of a penetration testing engagement?
正確答案: B
說明:(僅 Fast2test 成員可見)
A penetration tester is performing an assessment focused on attacking the authentication identity provider hosted within a cloud provider. During the reconnaissance phase, the tester finds that the system is using OpenID Connect with OAuth and has dynamic registration enabled. Which of the following attacks should the tester try first?
正確答案: A
說明:(僅 Fast2test 成員可見)