Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 47 pages
Exam (elaborations)

COMPTIA PENTEST+ PT0-002 CERTIFICATION EXAM WITH QUESTIONS AND VERIFIED ANSWERS, PLUS DETAILED RATIONALES/EXPERT VERIFIED FOR GUARANTEED PASS 2026/LATEST UPDATE/INSTANT DOWNLOAD PDF

Document preview thumbnail
Preview 4 out of 47 pages

COMPTIA PENTEST+ PT0-002 CERTIFICATION EXAM WITH QUESTIONS AND VERIFIED ANSWERS, PLUS DETAILED RATIONALES/EXPERT VERIFIED FOR GUARANTEED PASS 2026/LATEST UPDATE/INSTANT DOWNLOAD PDF COMPTIA PENTEST+ PT0-002 CERTIFICATION EXAM WITH QUESTIONS AND VERIFIED ANSWERS, PLUS DETAILED RATIONALES/EXPERT VERIFIED FOR GUARANTEED PASS 2026/LATEST UPDATE/INSTANT DOWNLOAD PDF COMPTIA PENTEST+ PT0-002 CERTIFICATION EXAM WITH QUESTIONS AND VERIFIED ANSWERS, PLUS DETAILED RATIONALES/EXPERT VERIFIED FOR GUARANTEED PASS 2026/LATEST UPDATE/INSTANT DOWNLOAD PDF

Content preview

COMPTIA PENTEST+ PT0-002
CERTIFICATION EXAM WITH QUESTIONS
AND VERIFIED ANSWERS, PLUS DETAILED
RATIONALES/EXPERT VERIFIED FOR
GUARANTEED PASS 2026/LATEST
UPDATE/INSTANT DOWNLOAD PDF
1. During a penetration test, an analyst discovers that a web
application accepts user input directly into a database query. Which
vulnerability is MOST likely present?
A. Cross-site request forgery
B. SQL injection
C. XML external entity injection
D. Server-side request forgery
Answer: B. SQL injection
Rationale: SQL injection occurs when untrusted input is incorporated
into SQL statements without proper parameterization or sanitization.
An attacker may manipulate the query structure to retrieve, modify, or
delete database information. Parameterized queries, prepared
statements, and appropriate input validation are common mitigations.


2. A penetration tester has been authorized to assess a company's
external infrastructure. The client provides only the company name
and primary domain. Which testing approach is MOST
appropriate?
A. Black-box testing
B. White-box testing
C. Gray-box testing
D. Credentialed testing
1

,Answer: A. Black-box testing
Rationale: Black-box testing begins with little or no internal
information about the target. The tester must perform reconnaissance
and enumeration much like an external attacker would. White-box
testing provides extensive internal information, while gray-box testing
provides partial information or credentials.


3. Which reconnaissance technique involves examining DNS records
to identify hosts, mail servers, and other infrastructure?
A. WHOIS enumeration
B. DNS enumeration
C. Banner grabbing
D. Packet crafting
Answer: B. DNS enumeration
Rationale: DNS enumeration examines records such as A, AAAA,
MX, NS, CNAME, and TXT records. This can reveal subdomains,
mail infrastructure, authoritative name servers, and other useful
information about the organization's attack surface.


4. A tester discovers the following DNS record:
mail.example.com MX 10 mailserver.example.com
What does the record primarily identify?
A. Web server
B. Mail server
C. DNS resolver
D. Domain registrar
Answer: B. Mail server

2

,Rationale: An MX, or Mail Exchange, record identifies the server
responsible for receiving email for a domain. Enumerating MX
records can help a penetration tester identify the organization's email
infrastructure and potential targets.


5. Which tool is commonly associated with network discovery, port
scanning, service enumeration, and OS detection?
A. Nmap
B. Hashcat
C. John the Ripper
D. sqlmap
Answer: A. Nmap
Rationale: Nmap is a network discovery and security auditing utility
capable of host discovery, TCP and UDP port scanning,
service/version detection, OS detection, and scripting through the
Nmap Scripting Engine.


6. A penetration tester runs a TCP SYN scan against a target. What
does an open TCP port generally indicate when the target responds
with SYN/ACK?
A. The port is filtered
B. The port is closed
C. A service is listening
D. The firewall has blocked the request
Answer: C. A service is listening
Rationale: In a SYN scan, a SYN/ACK response generally indicates
that the port is open and accepting connections. A RST response


3

, generally indicates a closed port, while lack of response or an ICMP
filtering response can indicate filtering.


7. Which phase of a penetration test involves determining the scope,
objectives, rules of engagement, and authorization?
A. Exploitation
B. Planning and reconnaissance
C. Post-exploitation
D. Reporting
Answer: B. Planning and reconnaissance
Rationale: Before technical testing begins, the tester needs
authorization, defined scope, objectives, testing windows,
communication procedures, exclusions, and rules of engagement. This
prevents unauthorized activity and establishes the boundaries of the
assessment.


8. A client states that production systems must never be
intentionally crashed during testing. Where should this restriction
be documented?
A. Vulnerability database
B. Rules of engagement
C. Password policy
D. Incident response plan
Answer: B. Rules of engagement
Rationale: Rules of engagement define exactly what testing activities
are permitted or prohibited. Restrictions such as avoiding denial-of-
service attacks, prohibited IP ranges, testing windows, and emergency
contacts should be documented there.

4

Document information

Uploaded on
August 23, 2026
Number of pages
47
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$26.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
6
Followers
0
Items
721
Last sold
5 days ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions