CompTIA PT0-002 - CompTIA PenTest+ Certification Exam Exam

Question #11 (Topic: Single Topic)
SIMULATION
You are a penetration tester reviewing a client's website through a web browser.
INSTRUCTIONS
Review all components of the website through the browser to determine if vulnerabilities are present.
Remediate ONLY the highest vulnerability from either the certificate, source, or cookies.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.







Answer: See explanation below.
Question #12 (Topic: Single Topic)
A Chief Information Security Officer wants a penetration tester to evaluate the security awareness level of the company's employees.
Which of the following tools can help the tester achieve this goal?
A. Metasploit B. Hydra C. SET D. WPScan
Answer: C
Question #13 (Topic: Single Topic)
Which of the following is the MOST common vulnerability associated with IoT devices that are directly connected to the Internet?
A. Unsupported operating systems B. Susceptibility to DDoS attacks C. Inability to network D. The existence of default passwords
Answer: D
Question #14 (Topic: Single Topic)
Which of the following describes the reason why a penetration tester would run the command sdelete mimikatz. * on a Windows server that the tester
compromised?
A. To remove hash-cracking registry entries B. To remove the tester-created Mimikatz account C. To remove tools from the server D. To remove a reverse shell from the system
Answer: C
Question #15 (Topic: Single Topic)
A penetration tester is scanning a corporate lab network for potentially vulnerable services.
Which of the following Nmap commands will return vulnerable ports that might be interesting to a potential attacker?
A. nmap 192.168.1.1-5 -PU22-25,80 B. nmap 192.168.1.1-5 -PA22-25,80 C. nmap 192.168.1.1-5 -PS22-25,80 D. nmap 192.168.1.1-5 -Ss22-25,80
Answer: C
Download Exam
Page: 3 / 106
Total 530 questions