Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free CompTIA PT0-003 Practice Exam with Questions & Answers | Set: 7

Questions 61

A penetration tester obtains password dumps associated with the target and identifies strict lockout policies. The tester does not want to lock out accounts when attempting access. Which of the following techniques should the tester use?

Options:
A.

Credential stuffing

B.

MFA fatigue

C.

Dictionary attack

D.

Brute-force attack

CompTIA PT0-003 Premium Access
Questions 62

Which of the following protocols would a penetration tester most likely utilize to exfiltrate data covertly and evade detection?

Options:
A.

FTP

B.

HTTPS

C.

SMTP

D.

DNS

Questions 63

A penetration tester gains access to the target network and observes a running SSH server.

Which of the following techniques should the tester use to obtain the version of SSH running on the target server?

Options:
A.

Network sniffing

B.

IP scanning

C.

Banner grabbing

D.

DNS enumeration

Questions 64

Which of the following could be used to enhance the quality and reliability of a vulnerability scan report?

Options:
A.

Risk analysis

B.

Peer review

C.

Root cause analysis

D.

Client acceptance

Questions 65

While conducting a peer review for a recent assessment, a penetration tester finds the debugging mode is still enabled for the production system. Which of the following is most likely responsible for this observation?

Options:
A.

Configuration changes were not reverted.

B.

A full backup restoration is required for the server.

C.

The penetration test was not completed on time.

D.

The penetration tester was locked out of the system.

Questions 66

A penetration tester sets up a C2 (Command and Control) server to manage and control payloads deployed in the target network. Which of the following tools is the most suitable for establishing a robust and stealthy connection?

Options:
A.

ProxyChains

B.

Covenant

C.

PsExec

D.

sshuttle