[Jan-2022] Verified PT0-002 dumps Q&As - PT0-002 dumps with Correct Answers
The Best CompTIA PenTest+ Study Guide for the PT0-002 Exam
NEW QUESTION 11
A penetration tester is testing input validation on a search form that was discovered on a website. Which of the following characters is the BEST option to test the website for vulnerabilities?
- A. Double dash
- B. Comma
- C. Semicolon
- D. Single quote
Answer: D
NEW QUESTION 12
Which of the following should a penetration tester consider FIRST when engaging in a penetration test in a cloud environment?
- A. Whether the specific cloud services are being used by the application
- B. Whether the cloud service provider allows the penetration tester to test the environment
- C. Whether the country where the cloud service is based has any impeding laws
- D. The geographical location where the cloud services are running
Answer: D
Explanation:
Section: (none)
Explanation
NEW QUESTION 13
Performing a penetration test against an environment with SCADA devices brings additional safety risk because the:
- A. devices are obsolete and are no longer available for replacement.
- B. devices produce more heat and consume more power.
- C. protocols are more difficult to understand.
- D. devices may cause physical world effects.
Answer: C
NEW QUESTION 14
User credentials were captured from a database during an assessment and cracked using rainbow tables. Based on the ease of compromise, which of the following algorithms was MOST likely used to store the passwords in the database?
- A. bcrypt
- B. PBKDF2
- C. MD5
- D. SHA-1
Answer: C
NEW QUESTION 15
A penetration tester wants to scan a target network without being detected by the client's IDS. Which of the following scans is MOST likely to avoid detection?
- A. nmap -p0 -T0 -sS 192.168.1.10
- B. nmap -A -n 192.168.1.10
- C. nmap -f --badsum 192.168.1.10
- D. nmap -sA -sV --host-timeout 60 192.168.1.10
Answer: D
NEW QUESTION 16
A penetration tester runs the unshadow command on a machine. Which of the following tools will the tester most likely use NEXT?
- A. Mimikatz
- B. John the Ripper
- C. Hydra
- D. Cain and Abel
Answer: B
NEW QUESTION 17
A security engineer identified a new server on the network and wants to scan the host to determine if it is running an approved version of Linux and a patched version of Apache. Which of the following commands will accomplish this task?
- A. nmap -A -T4 -p80 192.168.1.20
- B. nmap -O -v -p80 192.168.1.20
- C. nmap -sS -sL -p80 192.168.1.20
- D. nmap -f -sV -p80 192.168.1.20
Answer: A
NEW QUESTION 18
A new security firm is onboarding its first client. The client only allowed testing over the weekend and needed the results Monday morning. However, the assessment team was not able to access the environment as expected until Monday. Which of the following should the security company have acquired BEFORE the start of the assessment?
- A. A signed statement of work
- B. The correct user accounts and associated passwords
- C. The expected time frame of the assessment
- D. The proper emergency contacts for the client
Answer: C
NEW QUESTION 19
A penetration tester who is doing a company-requested assessment would like to send traffic to another system using double tagging. Which of the following techniques would BEST accomplish this goal?
- A. RFID tagging
- B. RFID cloning
- C. Tag nesting
- D. Meta tagging
Answer: D
NEW QUESTION 20
During a penetration-testing engagement, a consultant performs reconnaissance of a client to identify potential targets for a phishing campaign. Which of the following would allow the consultant to retrieve email addresses for technical and billing contacts quickly, without triggering any of the client's cybersecurity tools? (Choose two.)
- A. Conducting wardriving near the client facility
- B. Utilizing DNS lookup tools
- C. Phishing company employees
- D. Crawling the client's website
- E. Using the WHOIS lookup tool
- F. Scraping social media sites
Answer: D,E
NEW QUESTION 21
A penetration tester writes the following script:
Which of the following objectives is the tester attempting to achieve?
- A. Set the TTL of ping packets for stealth.
- B. Determine active hosts on the network.
- C. Fill the ARP table of the networked devices.
- D. Scan the system on the most used ports.
Answer: B
NEW QUESTION 22
A penetration-testing team is conducting a physical penetration test to gain entry to a building. Which of the following is the reason why the penetration testers should carry copies of the engagement documents with them?
- A. As proof in case they are discovered
- B. To guide them through the building entrances
- C. To validate the billing information with the client
- D. As backup in case the original documents are lost
Answer: A
NEW QUESTION 23
You are a security analyst tasked with hardening a web server.
You have been given a list of HTTP payloads that were flagged as malicious.
INSTRUCTIONS
Given the following attack signatures, determine the attack type, and then identify the associated remediation to prevent the attack in the future.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.
Answer:
Explanation:
NEW QUESTION 24
Which of the following should a penetration tester attack to gain control of the state in the HTTP protocol after the user is logged in?
- A. Sessions and cookies
- B. HTTPS communication
- C. Password encryption
- D. Public and private keys
Answer: A
NEW QUESTION 25
Which of the following documents describes specific activities, deliverables, and schedules for a penetration tester?
- A. MOU
- B. NDA
- C. MSA
- D. SOW
Answer: D
NEW QUESTION 26
A penetration tester wants to identify CVEs that can be leveraged to gain execution on a Linux server that has an SSHD running. Which of the following would BEST support this task?
- A. Run nmap with the -sA option set against the target
- B. Run nmap with the -sV and -p22 options set against the target
- C. Run nmap with the -o, -p22, and -sC options set against the target
- D. Run nmap with the --script vulners option set against the target
Answer: A
NEW QUESTION 27
A tester who is performing a penetration test on a website receives the following output:
Warning: mysql_fetch_array() expects parameter 1 to be resource, boolean given in /var/www/search.php on line 62 Which of the following commands can be used to further attack the website?
- A. 1 UNION SELECT 1, DATABASE(),3--
- B. /var/www/html/index.php;whoami
- C. <script>var adr= '../evil.php?test=' + escape(document.cookie);</script>
- D. ../../../../../../../../../../etc/passwd
Answer: B
NEW QUESTION 28
A software development team is concerned that a new product's 64-bit Windows binaries can be deconstructed to the underlying code. Which of the following tools can a penetration tester utilize to help the team gauge what an attacker might see in the binaries?
- A. Immunity Debugger
- B. OllyDbg
- C. GDB
- D. Drozer
Answer: B
NEW QUESTION 29
Which of the following are the MOST important items to include in the final report for a penetration test? (Choose two.)
- A. The vulnerability identifier
- B. The client acceptance form
- C. The network location of the vulnerable device
- D. The tool used to find the issue
- E. The name of the person who found the flaw
- F. The CVSS score of the finding
Answer: A,D
NEW QUESTION 30
Running a vulnerability scanner on a hybrid network segment that includes general IT servers and industrial control systems:
- A. will create a denial-of-service condition on the IP networks.
- B. will reveal vulnerabilities in the Modbus protocol.
- C. may cause unintended failures in control systems.
- D. may reduce the true positive rate of findings.
Answer: C
NEW QUESTION 31
A penetration tester conducted a discovery scan that generated the following:
Which of the following commands generated the results above and will transform them into a list of active hosts for further analysis?
- A. nmap -sn 192.168.0.1-254 , grep "Nmap scan" | awk '{print S5}'
- B. nmap -oG list.txt 192.168.0.1-254 , sort
- C. nmap --open 192.168.0.1-254, uniq
- D. nmap -o 192.168.0.1-254, cut -f 2
Answer: D
NEW QUESTION 32
A penetration tester runs a scan against a server and obtains the following output:
21/tcp open ftp Microsoft ftpd
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
| 03-12-20 09:23AM 331 index.aspx
| ftp-syst:
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
445/tcp open microsoft-ds Microsoft Windows Server 2012 Std
3389/tcp open ssl/ms-wbt-server
| rdp-ntlm-info:
| Target Name: WEB3
| NetBIOS_Computer_Name: WEB3
| Product_Version: 6.3.9600
|_ System_Time: 2021-01-15T11:32:06+00:00
8443/tcp open http Microsoft IIS httpd 8.5
| http-methods:
|_ Potentially risky methods: TRACE
|_http-server-header: Microsoft-IIS/8.5
|_http-title: IIS Windows Server
Which of the following command sequences should the penetration tester try NEXT?
- A. ftp 192.168.53.23
- B. nmap --script vuln -sV 192.168.53.23
- C. smbclient \\\\WEB3\\IPC$ -I 192.168.53.23 -U guest
- D. curl -X TRACE https://192.168.53.23:8443/index.aspx
- E. ncrack -u Administrator -P 15worst_passwords.txt -p rdp 192.168.53.23
Answer: A
NEW QUESTION 33
Which of the following provides a matrix of common tactics and techniques used by attackers along with recommended mitigations?
- A. PTES technical guidelines
- B. MITRE ATT&CK framework
- C. NIST SP 800-53
- D. OWASP Top 10
Answer: B
NEW QUESTION 34
Given the following output:
User-agent:*
Disallow: /author/
Disallow: /xmlrpc.php
Disallow: /wp-admin
Disallow: /page/
During which of the following activities was this output MOST likely obtained?
- A. URL enumeration
- B. Website scraping
- C. Website cloning
- D. Domain enumeration
Answer: B
NEW QUESTION 35
......
PT0-002 certification guide Q&A from Training Expert DumpsMaterials: https://www.dumpsmaterials.com/PT0-002-real-torrent.html
PT0-002 Certification Overview Latest PT0-002 PDF Dumps: https://drive.google.com/open?id=1jBof2E2ffh6MvrvPxuhS8Xz4NPgiAUO9
