Official Bank 0/331

CompTIA PenTest+ Exam (PT0-003) - CompTIA Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
331 Total Questions
1
Question
A penetration tester identifies an exposed corporate directory containing first and last names and phone numbers for employees. Which of the following attack techniques would be the most effective to pursue if the penetration tester wants to compromise user accounts?
Options
A Tailgating
B Whaling
C Smishing
D Impersonation
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
A penetration tester finishes an initial discovery scan for hosts on a /24 customer subnet. The customer states that the production network is composed of Windows servers but no container clusters. The following are the last several lines from the scan log: Line 1: 112 hosts found... trying ports Line 2: FOUND 22 with OpenSSH 1.2p2 open on 99 hosts Line 3: FOUND 161 with UNKNOWN banner open on 110 hosts Line 4: TCP RST received on ports 21, 3389, 80 Line 5: Scan complete.

Which of the following is the most likely reason for the results?
Options
A Windows is using WSL
B IPS is blocking the ports
C The wrong subnet was scanned
D Multiple honeypots were encountered
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
As part of an engagement, a penetration tester wants to maintain access to a compromised system after rebooting. Which of the following techniques would be best for the tester to use?
Options
A Creating a scheduled task
B Performing a credential-dumping attack
C Establishing a reverse shell
D Executing a process injection attack
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
A penetration tester executes multiple enumeration commands to find a path to escalate privileges.

Given the following command:
find / -user root -perm -4000 -exec ls -ldb {} \; 2>/dev/null

Which of the following is the penetration tester attempting to enumerate?
Options
A Passwords
B Permission
C API keys
D Attack path mapping
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
A penetration tester finished a security scan and uncovered numerous vulnerabilities on several hosts. Based on the targets’ EPSS and CVSS scores, which of the following targets is the most likely to get attacked?
Options
A Target 3: EPSS Score = 0.6 and CVSS Score = 1
B Target 4: EPSS Score = 0.4 and CVSS Score = 4.5
C Target 1: EPSS Score = 0.6 and CVSS Score = 4
D Target 2: EPSS Score = 0.3 and CVSS Score = 2
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.