Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 103 pages
Exam (elaborations)

CompTIA PenTest+ (PT0-003) Comprehensive Practice Exam 2026: 200 Questions & Verified Answers with Detailed Rationales – Complete Study Guide

Document preview thumbnail
Preview 4 out of 103 pages

CompTIA PenTest+ (PT0-003) Comprehensive Practice Exam 2026: 200 Questions & Verified Answers with Detailed Rationales – Complete Study Guide CompTIA PenTest+ (PT0-003) Comprehensive Practice Exam 2026: 200 Questions & Verified Answers with Detailed Rationales – Complete Study Guide CompTIA PenTest+ (PT0-003) Comprehensive Practice Exam 2026: 200 Questions & Verified Answers with Detailed Rationales – Complete Study Guide CompTIA PenTest+ (PT0-003) Comprehensive Practice Exam 2026: 200 Questions & Verified Answers with Detailed Rationales – Complete Study Guide

Content preview

CompTIA PenTest+ (PT0-003) Comprehensive
Practice Exam 2026: 200 Questions & Verified
Answers with Detailed Rationales – Complete Study
Guide


1. Mikaruns the following Nmap scan: nmap -sU -sT -p 1-65535 example.com.
What information will she receive?
A. Only UDP scan results
B. Only TCP connect scan results
C. Vulnerability scanner results, UDP scan, TCP connect/full connect scan, and
results for ports 1-65535
D. Only open port results


Answer: C
Rationale: The command uses -sU for UDP scan and -sT for TCP connect scan.
The -p 1-65535 specifies all ports. The TCP connect scan (-sT) is used when the
user can't create raw packets for a SYN scan or is scanning an IPv6 network.
This combination provides comprehensive results including UDP and TCP
connect scan results for all ports. Option A is incomplete because it ignores
the TCP scan. Option B is incomplete because it ignores the UDP scan. Option
D is too vague.

,2. What technique is being used in the following command: host -t axfr
domain.com dns1.domain.com?
A. DNS cache poisoning
B. Zone transfer
C. DNS spoofing
D. Reverse DNS lookup


Answer: B
Rationale: The axfr flag indicates a zone transfer in both dig and host utilities.
A zone transfer (AXFR) is a DNS query that replicates DNS records between
DNS servers. If misconfigured, it can reveal all DNS records for a domain. DNS
cache poisoning (A) involves corrupting DNS cache. DNS spoofing (C) involves
forging DNS responses. Reverse DNS lookup (D) resolves IP addresses to
domain names.


3. After running an Nmap scan of a system, Lauren discovers that TCP ports
139, 443, and 3389 are open. What operating system is she most likely to
discover running on the system?
A. Linux
B. Windows
C. macOS
D. Unix
Answer: B
Rationale: Port 3389 is Remote Desktop Protocol (RDP), which is commonly
associated with Windows systems. Port 139 is NetBIOS Session Service, also
commonly associated with Windows. Port 443 is HTTPS, which is cross-
platform. While Linux (A), macOS (C), and Unix (D) can run services on these
ports, the combination of 139 and 3389 strongly suggests Windows.

,4. Charles runs an Nmap scan using the following command: nmap -sT -sV -T2 -
p 1-65535 example.com. After watching the scan run for over two hours, he
realizes that he needs to optimize the scan. Which of the following is not a
useful way to speed up his scan?
A. Setting the scan to faster timing (T3 or faster)
B. Changing from a TCP connect scan to a TCP SYN scan
C. Limiting the number of ports tested
D. Only scanning via UDP will not miss any TCP connections


Answer: D
Rationale: Only scanning via UDP will miss all TCP connections, which is not a
useful way to speed up the scan while maintaining comprehensive results.
Options A, B, and C are all valid ways to speed up the scan: faster timing (A),
using SYN scan instead of connect scan (B), and limiting ports (C).
5. Karen identifies TCP ports 8080 and 8443 open on a remote system during a
port scan. What tool is her best option to manually validate the services
running on these ports?
A. A web browser
B. Wireshark
C. Metasploit
D. Nmap
Answer: A
Rationale: Ports 8080 and 8443 are likely alternate HTTP (TCP 80) and HTTPS
(TCP 443) server ports. A web browser is the best tool to connect to these
ports and manually validate the services. Wireshark (B) is a packet analyzer.
Metasploit (C) is an exploitation framework. Nmap (D) is a port scanner.

, 6. Angela recovered a PNG image during the early intelligence-gathering phase
of a penetration test and wants to examine it for useful metadata. What tool
could she most successfully use to do this?
A. ExifTool
B. Wireshark
C. Nmap
D. Metasploit


Answer: A
Rationale: ExifTool is designed to pull metadata from images and other files. It
can extract EXIF data, GPS coordinates, camera information, and other
metadata that may be useful during intelligence gathering. Wireshark (B) is a
packet analyzer. Nmap (C) is a port scanner. Metasploit (D) is an exploitation
framework.
7. During an Nmap scan, Casey uses the -O flag. The scan identifies the host as
follows: Running Linux 2.6.X, OS CPE: cpe:/o:linux:linux_kernel:2.6, OS details:
Linux 2.6.9 - 2.6.33. What can she determine from this information?**
A. The exact kernel version is 2.6.9
B. Nmap's best guess is that the remote host is running a Linux 2.6.9-2.6.33
kernel
C. The system is running Windows
D. The system is running macOS
Answer: B
Rationale: OS identification in Nmap is based on a variety of response
attributes. In this case, Nmap's best guess is that the remote host is running a
Linux 2.6.9-2.6.33 kernel, but it cannot be more specific. Option A is incorrect
because Nmap provides a range, not an exact version. Options C and D are
incorrect because the output clearly indicates Linux.

Document information

Uploaded on
September 18, 2026
Number of pages
103
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$23.53

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
NURSEGENLPN
3.7
(23)
Sold
162
Followers
4
Items
10892
Last sold
7 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their exams and reviewed by others who've used these revision notes.

Didn't get what you expected? Choose another document

No problem! You can straightaway pick a different document that better suits what you're after.

Pay as you like, start learning straight away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and smashed it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions