COMPTIA PENTES 3 UPDATED ACTUAL EXAM QUESTIONS CORRECT ANSWERS GRADED A
PLUS
Question:
PowerShell.
Answer:
A scripting tool that is native to Windows
Question:
MITRE ATT&CK.
Answer:
A framework is based on actual observations of real adversary tactics and techniques.
Question:
Active.
Answer:
Type of reconnaissance that directly interacts with the target.
Question:
Origin address.
Answer:
The name of the webserver's actual IP address.
Question:
OSINTFramework.com.
Answer:
, A website for researching OSINT tools based on investigative need.
Question:
False positive.
Answer:
The test result type in which a discovered vulnerability is not really exploitable.
Question:
credentialed scan.
Answer:
The type of scan in which the scanning tool logs onto the target.
Question:
Static Application Security Testing (SAST).
Answer:
A scan type that examines non-running source code.
Question:
Exploit Prediction Scoring System (EPSS).
Answer:
A scoring system that estimates the probability of exploitation activity being observed over the next
30 days.
Question:
Web Application Scan.
Answer:
A scan type that focuses on the OWASP Top 10 vulnerabilities list.
PLUS
Question:
PowerShell.
Answer:
A scripting tool that is native to Windows
Question:
MITRE ATT&CK.
Answer:
A framework is based on actual observations of real adversary tactics and techniques.
Question:
Active.
Answer:
Type of reconnaissance that directly interacts with the target.
Question:
Origin address.
Answer:
The name of the webserver's actual IP address.
Question:
OSINTFramework.com.
Answer:
, A website for researching OSINT tools based on investigative need.
Question:
False positive.
Answer:
The test result type in which a discovered vulnerability is not really exploitable.
Question:
credentialed scan.
Answer:
The type of scan in which the scanning tool logs onto the target.
Question:
Static Application Security Testing (SAST).
Answer:
A scan type that examines non-running source code.
Question:
Exploit Prediction Scoring System (EPSS).
Answer:
A scoring system that estimates the probability of exploitation activity being observed over the next
30 days.
Question:
Web Application Scan.
Answer:
A scan type that focuses on the OWASP Top 10 vulnerabilities list.