COMPTIA PENTEST+ EXAM TEST BANK 1
WITH ACTUAL CORRECT QUESTIONS AND
VERIFIED DETAILED ANSWERS|
FREQUENTLY TESTING VERSION | ALREADY
GRADED A+|NEWEST|EXPERT VERIFIED FOR
GUARANTEED PASS 2026-2027
COMPTIA PENTEST+(PT0-002) EXAM
During a penetration test, it is discovered that a financial institution's systems show
signs of compromise. Upon further investigation, it is found that the intrusion may have
been ongoing for several years, and sensitive data has been gradually exfiltrated. What
type of threat did the penetration tester most likely uncover?
A. Backdoor
B. Bind shell
C. Daemon
D. APT
D. APT
What type of threat involves an unauthorized user gaining access to a system or network
and remaining undetected for an extended period to exfiltrate data?
A. Backdoor
B. Bind shell
C. Daemon
D. Advanced Persistent Threat (APT)
D. Advanced Persistent Threat (APT)
What is a hidden mechanism that provides unauthorized access to a system but does
not necessarily imply a long-term, data-exfiltrating threat?
A. Advanced Persistent Threat (APT)
B. Backdoor
C. Bind shell
D. Daemon
1|Page
,B. Backdoor
Which type of reverse shell involves the target system binding its shell to a local network
port for remote access, but does not imply a long-term, data-exfiltrating threat?
A. Daemon
B. Bind shell
C. Backdoor
D. Advanced Persistent Threat (APT)
B. Bind shell
What term refers to a background process or service on a system, but does not imply a
long-term, data-exfiltrating threat?
A. Advanced Persistent Threat (APT)
B. Bind shell
C. Backdoor
D. Daemon
D. Daemon
A PenTester needs to have continuous persistent access to a Linux system. What
method can the PenTester use to accomplish this?
A. Cron
B. Daemon
C. Service
D. Registry
B. Daemon
What Linux system feature allows a PenTester to maintain long-term, continuous access
by remaining always active and potentially caching its state?
A. Cron job
B. Daemon
C. Service
D. Registry
B. Daemon
Why might a cron job not be suitable for providing continuous, persistent access to a
system?
A. It cannot execute scripts.
2|Page
,B. It runs too frequently.
C. It has a minimum execution interval of one minute.
D. It requires administrator privileges to set up.
C. It has a minimum execution interval of one minute.
Which of the following is a background program in Windows that operates without user
interaction and is similar to a daemon in Linux?
A. Cron job
B. Daemon
C. Service
D. Registry
C. Service
Which Linux system component is always active, available for use, and can sustain long
sessions by caching its state?
A. Cron job
B. Daemon
C. Service
D. Registry
B. Daemon
What limitation does a cron job have that prevents it from providing continuous
persistent access?
A. It cannot execute scripts.
B. It only operates with user interaction.
C. It has a minimum frequency limit of one minute.
D. It lacks the capability to cache its state.
C. It has a minimum frequency limit of one minute.
In the context of Windows, what parallels a daemon in Linux by running in the
background without user interaction?
A. Cron job
B. Daemon
C. Service
D. Registry
C. Service
3|Page
, What mechanism can a PenTester use in Windows to ensure a program automatically
starts upon system boot, leveraging the Registry?
A. Cron
B. Daemon
C. Service manipulation
D. Registry modification
D. Registry modification
A PenTester wants to test how easy it is to obtain passwords with physical access to an
organization's offices. What methods can the PenTester use? (Select all that apply.)
1. Shoulder surfing
2. Fake login websites
3. Meterpreter
4. Hardware-based USB keyloggers
A) 1, 2
B) 2, 3
C) 1, 4
D) 1, 3
C) 1, 4
Which method involves a PenTester watching users as they type passwords to
potentially steal them?
A. Using Meterpreter
B. Shoulder surfing
C. Implementing fake login websites
D. Installing hardware-based keyloggers
B. Shoulder surfing
What is a physical method a PenTester can use that involves recording keystrokes
directly from a device's keyboard?
A. Shoulder surfing
B. Meterpreter
C. Hardware-based USB keyloggers
D. Fake login websites
C. Hardware-based USB keyloggers
4|Page
WITH ACTUAL CORRECT QUESTIONS AND
VERIFIED DETAILED ANSWERS|
FREQUENTLY TESTING VERSION | ALREADY
GRADED A+|NEWEST|EXPERT VERIFIED FOR
GUARANTEED PASS 2026-2027
COMPTIA PENTEST+(PT0-002) EXAM
During a penetration test, it is discovered that a financial institution's systems show
signs of compromise. Upon further investigation, it is found that the intrusion may have
been ongoing for several years, and sensitive data has been gradually exfiltrated. What
type of threat did the penetration tester most likely uncover?
A. Backdoor
B. Bind shell
C. Daemon
D. APT
D. APT
What type of threat involves an unauthorized user gaining access to a system or network
and remaining undetected for an extended period to exfiltrate data?
A. Backdoor
B. Bind shell
C. Daemon
D. Advanced Persistent Threat (APT)
D. Advanced Persistent Threat (APT)
What is a hidden mechanism that provides unauthorized access to a system but does
not necessarily imply a long-term, data-exfiltrating threat?
A. Advanced Persistent Threat (APT)
B. Backdoor
C. Bind shell
D. Daemon
1|Page
,B. Backdoor
Which type of reverse shell involves the target system binding its shell to a local network
port for remote access, but does not imply a long-term, data-exfiltrating threat?
A. Daemon
B. Bind shell
C. Backdoor
D. Advanced Persistent Threat (APT)
B. Bind shell
What term refers to a background process or service on a system, but does not imply a
long-term, data-exfiltrating threat?
A. Advanced Persistent Threat (APT)
B. Bind shell
C. Backdoor
D. Daemon
D. Daemon
A PenTester needs to have continuous persistent access to a Linux system. What
method can the PenTester use to accomplish this?
A. Cron
B. Daemon
C. Service
D. Registry
B. Daemon
What Linux system feature allows a PenTester to maintain long-term, continuous access
by remaining always active and potentially caching its state?
A. Cron job
B. Daemon
C. Service
D. Registry
B. Daemon
Why might a cron job not be suitable for providing continuous, persistent access to a
system?
A. It cannot execute scripts.
2|Page
,B. It runs too frequently.
C. It has a minimum execution interval of one minute.
D. It requires administrator privileges to set up.
C. It has a minimum execution interval of one minute.
Which of the following is a background program in Windows that operates without user
interaction and is similar to a daemon in Linux?
A. Cron job
B. Daemon
C. Service
D. Registry
C. Service
Which Linux system component is always active, available for use, and can sustain long
sessions by caching its state?
A. Cron job
B. Daemon
C. Service
D. Registry
B. Daemon
What limitation does a cron job have that prevents it from providing continuous
persistent access?
A. It cannot execute scripts.
B. It only operates with user interaction.
C. It has a minimum frequency limit of one minute.
D. It lacks the capability to cache its state.
C. It has a minimum frequency limit of one minute.
In the context of Windows, what parallels a daemon in Linux by running in the
background without user interaction?
A. Cron job
B. Daemon
C. Service
D. Registry
C. Service
3|Page
, What mechanism can a PenTester use in Windows to ensure a program automatically
starts upon system boot, leveraging the Registry?
A. Cron
B. Daemon
C. Service manipulation
D. Registry modification
D. Registry modification
A PenTester wants to test how easy it is to obtain passwords with physical access to an
organization's offices. What methods can the PenTester use? (Select all that apply.)
1. Shoulder surfing
2. Fake login websites
3. Meterpreter
4. Hardware-based USB keyloggers
A) 1, 2
B) 2, 3
C) 1, 4
D) 1, 3
C) 1, 4
Which method involves a PenTester watching users as they type passwords to
potentially steal them?
A. Using Meterpreter
B. Shoulder surfing
C. Implementing fake login websites
D. Installing hardware-based keyloggers
B. Shoulder surfing
What is a physical method a PenTester can use that involves recording keystrokes
directly from a device's keyboard?
A. Shoulder surfing
B. Meterpreter
C. Hardware-based USB keyloggers
D. Fake login websites
C. Hardware-based USB keyloggers
4|Page