COMPTIA PENTEST+ (PT0-003) COMPLETE 2026-2027 EXAM PAPER-
REVISION QUESTIONS & SOLUTIONS
A payload type that requires the attacker be able to directly connect to the back door.
Reverse shell
A payload type in which the target connects back to the attacker.
msfvenom
A tool for creating your own dropper payloads.
mimikatz
A tool for dumping all manner of credentials from a target's memory.
LOLbins
Executables that are a normal part of an operating system, but used for malicious purpose.
supply chain attack
An attack type that exploits vulnerabilities in third-party software dependencies.
WiFi Pumpkin
An example of a software-based evil twin.
URL hijacking
An attack type that uses typographical errors to direct users to a fake website.
PsExec
A tool that is part of the Sysinternals Suite, and executes commands on remote Windows
machines.
Cross-site Scripting (XSS)
An attack in which malicious code is read by a browser and executed in the background.
aircrack-ng
A suite of tools that can sniff, capture, and crack Wi-Fi passwords.
CAN bus attack
An attack type that attempts to gain control of a motor vehicle.
, rooting/jailbreaking
Statement of Work (SOW)
Document that outlines the pentest deliverables
PowerShell
A scripting tool that is native to Windows
MITRE ATT&CK
A framework is based on actual observations of real adversary tactics and techniques.
Active
Type of reconnaissance that directly interacts with the target.
Origin address
The name of the webserver's actual IP address.
OSINTFramework.com
A website for researching OSINT tools based on investigative need.
False positive
The test result type in which a discovered vulnerability is not really exploitable.
credentialed scan
The type of scan in which the scanning tool logs onto the target.
Static Application Security Testing (SAST)
A scan type that examines non-running source code.
Exploit Prediction Scoring System (EPSS)
A scoring system that estimates the probability of exploitation activity being observed over the
next 30 days.
Web Application Scan
A scan type that focuses on the OWASP Top 10 vulnerabilities list.
On-path attack (aka MITM)
An attack type in which the attacker injects themselves in between two communicating hosts.
REVISION QUESTIONS & SOLUTIONS
A payload type that requires the attacker be able to directly connect to the back door.
Reverse shell
A payload type in which the target connects back to the attacker.
msfvenom
A tool for creating your own dropper payloads.
mimikatz
A tool for dumping all manner of credentials from a target's memory.
LOLbins
Executables that are a normal part of an operating system, but used for malicious purpose.
supply chain attack
An attack type that exploits vulnerabilities in third-party software dependencies.
WiFi Pumpkin
An example of a software-based evil twin.
URL hijacking
An attack type that uses typographical errors to direct users to a fake website.
PsExec
A tool that is part of the Sysinternals Suite, and executes commands on remote Windows
machines.
Cross-site Scripting (XSS)
An attack in which malicious code is read by a browser and executed in the background.
aircrack-ng
A suite of tools that can sniff, capture, and crack Wi-Fi passwords.
CAN bus attack
An attack type that attempts to gain control of a motor vehicle.
, rooting/jailbreaking
Statement of Work (SOW)
Document that outlines the pentest deliverables
PowerShell
A scripting tool that is native to Windows
MITRE ATT&CK
A framework is based on actual observations of real adversary tactics and techniques.
Active
Type of reconnaissance that directly interacts with the target.
Origin address
The name of the webserver's actual IP address.
OSINTFramework.com
A website for researching OSINT tools based on investigative need.
False positive
The test result type in which a discovered vulnerability is not really exploitable.
credentialed scan
The type of scan in which the scanning tool logs onto the target.
Static Application Security Testing (SAST)
A scan type that examines non-running source code.
Exploit Prediction Scoring System (EPSS)
A scoring system that estimates the probability of exploitation activity being observed over the
next 30 days.
Web Application Scan
A scan type that focuses on the OWASP Top 10 vulnerabilities list.
On-path attack (aka MITM)
An attack type in which the attacker injects themselves in between two communicating hosts.