CompTIA PT0-001 - CompTIA PenTest+ Certification Exam Exam

Question #11 (Topic: Topic 1)
Which of the following is the reason why a penetration tester would run the chkconfig --del servicename command at the end of an engagement?
A. To remove the persistence B. To enable persistence C. To report persistence D. To check for persistence
Answer: A
Question #12 (Topic: Topic 1)
A penetration tester wants to target NETBIOS name service. Which of the following is the MOST likely command to exploit the NETBIOS name service?
A. arpspoof B. nmap C. responder D. burpsuite
Answer: B
Question #13 (Topic: Topic 1)
A security consultant receives a document outlining the scope of an upcoming penetration test. This document contains IP addresses and times that each can be
scanned. Which of the following would contain this information?
A. Rules of engagement B. Request for proposal C. Master service agreement D. Business impact analysis
Answer: A
Question #14 (Topic: Topic 1)
A penetration tester executes the following commands:
[CompTIA-PT0-001-1.0/xmlfile-9_1.png]
Which of the following is a local host vulnerability that the attacker is exploiting?
A. Insecure file permissions B. Application whitelisting C. Shell escape D. Writable service
Answer: A
Question #15 (Topic: Topic 1)
A penetration tester reviews the scan results of a web application. Which of the following vulnerabilities is MOST critical and should be prioritized for exploitation?
A. Stored XSS B. Fill path disclosure C. Expired certificate D. Clickjacking
Answer: A
Download Exam
Page: 3 / 40
Total 196 questions