CompTIA PT0-002 - Questions & Answers
Free preview · every answer includes a full explanation
Product page: https://prepkeys.com/pt0-002.html
A penetration tester is conducting an authorized, physical penetration test to attempt to enter a client's
building during non-business hours.
Which of the following are MOST important for the penetration tester to have during the test? (Choose two.)
A penetration tester who is conducting a web-application test discovers a clickjacking vulnerability associated with a login page to financial data.
Which of the following should the tester do with this information to make this a successful exploit?
Which of the following tools would BEST allow a penetration tester to capture wireless handshakes to reveal a Wi-Fi password from a Windows machine?
A compliance-based penetration test is primarily concerned with:
A penetration tester is evaluating a company's network perimeter. The tester has received limited information about defensive controls or countermeasures, and limited internal knowledge of the testing exists.
Which of the following should be the FIRST step to plan the reconnaissance activities?
A penetration tester captured the following traffic during a web-application test:

Which of the following methods should the tester use to visualize the authorization information being transmitted?
A penetration tester is scanning a corporate lab network for potentially vulnerable services.
Which of the following Nmap commands will return vulnerable ports that might be interesting to a potential attacker?
A penetration tester received a 16-bit network block that was scoped for an assessment. During the assessment, the tester realized no hosts were active in the provided block of IPs and reported this to the company. The company then provided an updated block of IPs to the tester.
Which of the following would be the most appropriate NEXT step?
Within a Python script, a line that states print (var) outputs the following:
[{'1' : 'CentOS', '2' : 'Ubuntu'), {'1' : 'Windows 10', '2' : 'Windows Server 2016'}]Which of the following objects or data structures is var ?
A penetration tester is assessing a wireless network. Although monitoring the correct channel and SSID, the tester is unable to capture a handshake between the clients and the AP.
Which of the following attacks is the MOST effective to allow the penetration tester to capture a handshake?