Download CompTIA PenTest+ Certification Exam.PT0-002.ExamTopics.2026-09-25.455q.vcex

Vendor: CompTIA
Exam Code: PT0-002
Exam Name: CompTIA PenTest+ Certification Exam
Date: Sep 25, 2026
File Size: 7 MB

How to open VCEX files?

Files with VCEX extension can be opened by ProfExam Simulator.

ProfExam Discount

Demo Questions

Question 1
Which of the following is the MOST secure method for sending the penetration test report to the client?
  1. Host it on an online storage system.
  2. Put it inside a password-protected ZIP file.
  3. Transfer it via webmail using an HTTPS connection.
  4. Use the client's public key.
Correct answer: D
Question 2
A penetration tester learned that when users request password resets, help desk analysts change users' passwords to 123change. The penetration tester decides to brute force an internet-facing webmail to check which users are still using the temporary password. The tester configures the brute-force tool to test usernames found on a text file and the password 123change.
Which of the following techniques is the penetration tester using?
  1. Brute-force attack
  2. LDAP injection
  3. Password spraying
  4. Kerberoasting
Correct answer: C
Question 3
A penetration tester is validating whether input validation mechanisms have been implemented in a web application.
Which of the following should the tester use to determine whether the application is vulnerable to path traversal attacks?
  1. GET /image?filename-..%2f..%2f..%2f..%2f..%2f..%2fetc%2fhosts
  2. GET /image?filename=lefitfe;pwd
  3. POST /image?filename -
  4. POST /image?filename =yhtak;ncat --ssl 192.168.0.1 2222
Correct answer: A
Question 4
Which of the following best describes why a client would hold a lessons-learned meeting with the penetration-testing team?
  1. To provide feedback on the report structure and recommend improvements
  2. To discuss the findings and dispute any false positives
  3. To determine any processes that failed to meet expectations during the assessment
  4. To ensure the penetration-testing team destroys all company data that was gathered during the test
Correct answer: C
Question 5
Within a Python script, a line that states print (var) outputs the following:
[{'1' : 'CentOS', '2' : 'Ubuntu'}, {'1' : 'Windows 10', '2' : 'Windows Server 2016'}]
Which of the following objects or data structures is var?
  1. An array
  2. A class
  3. A dictionary
  4. A list
Correct answer: D
Question 6
During a code review assessment, a penetration tester finds the following vulnerable code inside one of the web application files:
<% String id = request.getParameter("id"); %>
Employee ID: <%= id %>
Which of the following is the BEST remediation to prevent a vulnerability from being exploited, based on this code?
  1. Parameterized queries
  2. Patch application
  3. Output encoding
  4. HTML sanitization
Correct answer: C
Question 7
A penetration tester wrote the following comment in the final report: "Eighty-five percent of the systems tested were found to be prone to unauthorized access from the internet."
Which of the following audiences was this message intended?
  1. Systems administrators
  2. C-suite executives
  3. Data privacy ombudsman
  4. Regulatory officials
Correct answer: B
Question 8
During a vulnerability scanning phase, a penetration tester wants to execute an Nmap scan using custom NSE scripts stored in the following folder:
/home/user/scripts
Which of the following commands should the penetration tester use to perform this scan?
  1. nmap --resume "not intrusive"
  2. nmap --script default,safe
  3. nmap --script /home/user/scripts
  4. nmap --load /home/user/scripts
Correct answer: C
Question 9
A company recruited a penetration tester to configure intrusion detection over the wireless network. Which of the following tools would BEST resolve this issue?
  1. Aircrack-ng
  2. Wireshark
  3. Cowpatty
  4. Kismet
Correct answer: D
Question 10
A security analyst is conducting an unknown environment test from 192.168.3.3. The analyst wants to limit observation of the penetration tester's activities and lower the probability of detection by intrusion protection and detection systems.
Which of the following Nmap commands should the analyst use to achieve this objective?
  1. nmap -F 192.168.5.5
  2. nmap -datalength 2 192.168.5.5
  3. nmap -D 0.5.2.2 192.168.5.5
  4. nmap -scanflags SYNFIN 192.168.5.5
Correct answer: D
HOW TO OPEN VCE FILES

Use VCE Exam Simulator to open VCE files
Avanaset

HOW TO OPEN VCEX AND EXAM FILES

Use ProfExam Simulator to open VCEX and EXAM files
ProfExam Screen

ProfExam
ProfExam at a 20% markdown

You have the opportunity to purchase ProfExam at a 20% reduced price

Get Now!