Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 57 pages
Exam (elaborations)

COMPTIA PENTEST+ PT0-003 CERTIFICATION EXAM WITH QUESTIONS AND VERIFIED ANSWERS, PLUS DETAILED RATIONALES/EXPERT VERIFIED FOR GUARANTEED PASS 2026/LATEST UPDATE/INSTANT DOWNLOAD PDF

Document preview thumbnail
Preview 4 out of 57 pages

COMPTIA PENTEST+ PT0-003 CERTIFICATION EXAM WITH QUESTIONS AND VERIFIED ANSWERS, PLUS DETAILED RATIONALES/EXPERT VERIFIED FOR GUARANTEED PASS 2026/LATEST UPDATE/INSTANT DOWNLOAD PDFCOMPTIA PENTEST+ PT0-003 CERTIFICATION EXAM WITH QUESTIONS AND VERIFIED ANSWERS, PLUS DETAILED RATIONALES/EXPERT VERIFIED FOR GUARANTEED PASS 2026/LATEST UPDATE/INSTANT DOWNLOAD PDF

Content preview

COMPTIA PENTEST+ PT0-003
CERTIFICATION EXAM WITH QUESTIONS
AND VERIFIED ANSWERS, PLUS DETAILED
RATIONALES/EXPERT VERIFIED FOR
GUARANTEED PASS 2026/LATEST
UPDATE/INSTANT DOWNLOAD PDF
1.
A penetration tester is performing reconnaissance against a client-
approved external web application. The tester wants to identify
technologies, frameworks, server software, and potentially exposed
metadata without directly exploiting the application. Which technique is
MOST appropriate?
A. Password spraying
B. Passive reconnaissance
C. Privilege escalation
D. SQL injection
Answer: B. Passive reconnaissance
Rationale: Passive reconnaissance gathers information without
directly interacting with the target in a way that would typically
generate traffic to the target infrastructure. Sources can include public
DNS records, search engines, certificate transparency data,
WHOIS/RDAP information, job postings, public code repositories, and
other OSINT sources. This is particularly valuable during the early
reconnaissance stage because it helps establish the target's attack
surface while minimizing detection and operational impact.


2.


1

,A penetration tester discovers that vpn.example.com resolves to an IP
address belonging to the client's organization. The tester wants to
determine whether other hosts exist within the same network range.
Which activity would BEST support this objective?
A. Network enumeration
B. Credential stuffing
C. Data destruction
D. Social engineering
Answer: A. Network enumeration
Rationale: Network enumeration identifies systems, services, ports,
protocols, and other network resources associated with a target
environment. Once an authorized IP range has been established, a
tester can use host discovery and port-scanning techniques to identify
additional attack-surface components. Credential stuffing and social
engineering address different attack vectors, while data destruction is
not an enumeration activity.


3.
During a penetration test, an analyst identifies TCP port 22 open on a
server. Which service is MOST commonly associated with this port?
A. DNS
B. SSH
C. HTTPS
D. SMB
Answer: B. SSH
Rationale: TCP port 22 is conventionally associated with Secure Shell
(SSH). SSH provides encrypted remote administration and can become
an attack vector when weak credentials, vulnerable implementations,
exposed keys, poor access controls, or configuration weaknesses exist.
2

,Port numbers alone should not be treated as definitive proof of a
service, however, because services can be configured to use
nonstandard ports.


4.
A tester wants to determine whether a web application is vulnerable to
SQL injection. Which input would be MOST relevant to testing?
A. An SQL metacharacter inserted into an application parameter
B. A malformed Ethernet frame
C. A UDP broadcast packet
D. A forged ARP response
Answer: A. An SQL metacharacter inserted into an application
parameter
Rationale: SQL injection occurs when untrusted application input is
incorporated into SQL statements without appropriate
parameterization or validation. Testing parameters with controlled
SQL syntax or metacharacters can reveal whether application input
reaches the database query interpreter in an unsafe manner. ARP
manipulation and malformed Ethernet frames address network-layer
or link-layer attack scenarios rather than SQL injection.


5.
A tester discovers that an application accepts a parameter such as
file=report.pdf and appears to retrieve files from the server filesystem.
Which vulnerability should the tester investigate?
A. Local file inclusion
B. Cross-site request forgery


3

, C. VLAN hopping
D. DNS poisoning
Answer: A. Local file inclusion
Rationale: Local file inclusion (LFI) occurs when an application
allows an attacker to influence which local files are loaded or
processed. Improperly controlled file parameters may allow access to
sensitive files or, in some circumstances, contribute to code execution
when combined with another weakness. CSRF involves unauthorized
actions performed through a user's authenticated browser, while
VLAN hopping and DNS poisoning involve different network attack
surfaces.


6.
A web application reflects user-supplied input into an HTML response
without proper output encoding. The tester demonstrates that JavaScript
executes in another user's browser. What vulnerability has been
demonstrated?
A. XSS
B. SSRF
C. XXE
D. LDAP injection
Answer: A. XSS
Rationale: Cross-site scripting (XSS) occurs when attacker-controlled
content is interpreted as executable script in a victim's browser.
Reflected XSS commonly involves malicious input being returned
immediately in an application response, whereas stored XSS involves
persistent malicious content being saved by the application. SSRF
targets server-side requests, while XXE involves XML parsers and
external entities.

4

Document information

Uploaded on
August 23, 2026
Number of pages
57
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$24.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
6
Followers
0
Items
721
Last sold
5 days ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions