Official Bank 0/270

CompTIA PenTest+ Exam (PT0-003) - CompTIA Actual Exam Questions

Last updated on April 15, 2026

97% Exam Compliance
270 Total Questions
1
Question

[Tools and Code Analysis] A penetration tester launches an attack against company employees. The tester clones the company's intranet login page and sends the link via email to all employees. Which of the following best describes the objective and tool selected by the tester to perform this activity?

Options
A

Gaining remote access using BeEF

B

Obtaining the list of email addresses using theHarvester

C

Harvesting credentials using SET

D

Launching a phishing campaign using GoPhish

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question

A penetration tester cannot complete a full vulnerability scan because the client's WAF is blocking communications. During which of the following activities should the penetration tester discuss this issue with the client?

Options
A

Goal reprioritization

B

Peer review

C

Client acceptance

D

Stakeholder alignment

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question

During a penetration test, the tester wants to obtain public information that could be used to compromise the organization's cloud infrastructure. Which of the following is the most effective resource for the tester to use for this purpose?

Options
A

Sensitive documents on a public cloud

B

Open ports on the cloud infrastructure

C

Repositories with secret keys

D

SSL certificates on websites

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question

[Information Gathering and Vulnerability Scanning] While conducting a reconnaissance activity, a penetration tester extracts the following information: Emails: - admin@acme.com - sales@acme.com - support@acme.com Which of the following risks should the tester use to leverage an attack as the next step in the security assessment?

Options
A

Unauthorized access to the network

B

Exposure of sensitive servers to the internet

C

Likelihood of SQL injection attacks

D

Indication of a data breach in the company

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question

[Tools and Code Analysis] A company hires a penetration tester to test the security of its wireless networks. The main goal is to intercept and access sensitive data. Which of the following tools should the security professional use to best accomplish this task?

Options
A

Metasploit

B

WiFi-Pumpkin

C

SET

D

theHarvester

E

WiGLE.net

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.