CompTIA PenTest + PT0-003 (V3) Exam (New Version) Practice Test 4

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11371 | Total Attempts: 9,893,164
| Questions: 25 | Updated: Sep 23, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. A tester planning an attack chain notes that exploiting the final target requires first successfully compromising an intermediate jump host, which in turn requires a valid set of credentials the tester does not yet have. Documenting this chain of prerequisites is best described as addressing which capability selection element?

Explanation

Documenting the chain of prerequisites is addressing dependencies within capability selection. Tool selection concerns which tool to use, scope limitations concern boundaries on what can be tested, labeling sensitive systems flags high-risk targets, and exploit customization concerns modifying an exploit for the target.

Submit
Please wait...
About This Quiz
CompTIA PenTest + Pt0-003 (V3) Exam (New Version) Practice Test 4 - Quiz

This quiz evaluates your knowledge and skills related to the CompTIA PenTest + PT0-003 (V3) exam. It covers essential topics such as vulnerability assessment, exploitation techniques, and reporting methodologies. Engaging with this practice material is crucial for those preparing for a career in penetration testing, ensuring you are well-versed in... see morethe latest concepts and practices in the field. see less

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. At the conclusion of an engagement, a tester decommissions the command-and-control server and phishing domain they stood up specifically for this test, ensuring none of their external attack infrastructure remains active. Which cleanup activity does this represent?

Explanation

Decommissioning external attacker-controlled infrastructure like a C2 server or phishing domain is specifically spinning down infrastructure. Removing persistence mechanisms and reverting configuration changes address the client's own systems, preserving artifacts keeps evidence, and secure data destruction concerns properly disposing of collected data.

Submit

3. A tester copies a small amount of sensitive configuration data and pastes it into a public text-sharing website under an obscure, hard-to-guess URL, planning to retrieve it later from outside the client's network. Which exfiltration technique is this?

Explanation

Pasting data into a public text-sharing site for later retrieval is specifically the text storage sites exfiltration technique. Alternate data streams hide data within a file system, virtual drive mounting creates a local encrypted container, cross-account resources move data between cloud accounts, and a covert DNS channel encodes data within DNS traffic.

Submit

4. A tester uses a legitimate, signed Windows utility normally used to run functions from DLL files to instead execute a malicious payload, avoiding the need to drop a separate, potentially flagged executable onto the target system. Complete the sentence: this specific living-off-the-land binary is called ______.

Explanation

rundll32 is a legitimate, signed Windows utility that can be abused to execute malicious code from a DLL, making it a commonly used LOLBin since it avoids dropping a separate flagged executable. Other LOLBins listed in the objectives, such as msbuild or mmc.exe, serve similar purposes through different underlying legitimate functionality.

Submit

5. A tester installs a malicious browser extension on a compromised workstation that silently captures form data, including credentials, every time the user logs into a web application, and continues doing so across browser restarts. Which persistence mechanism is this?

Explanation

A malicious browser extension installed to persistently capture data across sessions is specifically the browser extension persistence mechanism. A rootkit hides malicious software at the OS level, a scheduled task and registry key are other Windows-specific persistence techniques, and a backdoor web shell provides access through a web server.

Submit

6. A tester wants a PowerShell tool specifically built to discover and attack SQL Server instances across a Windows Active Directory environment, including finding instances with weak permissions or excessive privileges. Which tool fits this description?

Explanation

PowerUpSQL is specifically built to discover and attack SQL Server instances within an AD environment. PowerView focuses on broader AD object and trust enumeration, PowerSploit is a general post-exploitation framework, generic AD search scripts are not a specific named tool, and Impacket is a Python library collection.

Submit

7. A tester on an industrial control network sends specially crafted commands over an unencrypted, unauthenticated protocol commonly used to communicate with programmable logic controllers, causing a controller to change its output state. Which protocol-specific attack is this?

Explanation

Modbus is a widely used, often unencrypted and unauthenticated industrial protocol for communicating with PLCs, and crafting commands against it is a Modbus attack. A CAN bus attack targets vehicle and embedded systems, and RFID attacks, NFC attacks, and bluejacking target short-range wireless technologies.

Submit

8. A tester sends text messages to employees' personal phones claiming to be from the company's IT department, including a malicious link disguised as a mandatory password reset portal. Which social engineering attack type is this?

Explanation

Smishing is SMS-based phishing, exactly as described. Vishing uses voice calls, whaling specifically targets executives, spearphishing is a personalized email attack, and a watering hole attack compromises a website the target frequents.

Submit

9. A tester finds that a cloud service account has been granted broad administrative permissions across the entire cloud environment, far beyond what its specific automated function actually requires. Which category of cloud attack surface does this represent?

Explanation

A service account granted excessive permissions beyond what it needs is an IAM misconfiguration, a common and high-impact cloud security weakness. A metadata service attack targets an instance's credential endpoint, container escape breaks out of container isolation, a workload runtime attack targets a running workload's execution, and logging information exposure concerns sensitive data leaking through logs.

Submit

10. A tester notices a web application URL includes a parameter like invoice_id=1024, and by simply changing the number to 1025, the tester can view another customer's invoice without any additional authorization check. Which vulnerability is this?

Explanation

Insecure direct object reference occurs when an application exposes internal references, like a sequential invoice ID, without properly verifying authorization to access that object. Cross-site scripting injects malicious scripts, SSRF tricks the server into making unintended requests, CSRF tricks a victim's browser into unwanted requests, and a deserialization attack exploits unsafe object reconstruction.

Submit

11. A tester disables a host's endpoint detection and response agent by exploiting a flaw that allows termination of the protected process, before deploying further malicious tooling on that host undetected. Which host-based attack category does this represent?

Explanation

Disabling an EDR agent to operate undetected is specifically circumventing security tools. Privilege escalation gains higher-level access, payload obfuscation disguises malicious code's signature, log tampering alters log records, and a shell escape breaks out of a restricted shell environment.

Submit

12. In one test, a tester manipulates a signed assertion used for enterprise single sign-on, exploiting flawed signature validation to alter the asserted identity. In a separate test, another tester exploits a flaw in a different, JSON-token-based identity protocol commonly used by modern web and mobile applications. Which two attack categories are described, respectively?

Explanation

Manipulating a signed assertion for enterprise single sign-on describes a SAML attack, since SAML uses XML-based signed assertions, while exploiting a JSON-token-based identity protocol describes an OIDC attack, since OpenID Connect uses JSON Web Tokens. Kerberos attacks target Windows domain authentication tickets, LDAP injection manipulates directory queries, and pass-the-token reuses a captured token rather than exploiting either protocol's format directly.

Submit

13. A tester captures an authentication attempt intended for one server and forwards it in real time to a second, different server, successfully authenticating to the second server using the victim's credentials without ever knowing the actual password. Which attack is this?

Explanation

A relay attack captures an authentication attempt and forwards it to a different target in real time, authenticating there without knowing the credentials. An on-path attack intercepts traffic without necessarily redirecting authentication elsewhere, VLAN hopping crosses segmentation boundaries, packet crafting builds custom packets, and multihomed host exploitation abuses a dual-connected host.

Submit

14. Match each remediation example to its correct control category.

Explanation

Technical controls are enforced through technology such as MFA, administrative controls are policy-based such as a password complexity requirement, physical controls are tangible barriers such as biometric scanners, and operational controls govern day-to-day personnel practices such as mandatory vacations, which help surface fraud or misuse by rotating trusted personnel out periodically.

Submit

15. A tester briefly stands near an employee in a public coffee shop and uses a handheld RFID reader to capture the data from the employee's proximity access badge without their knowledge, intending to create a duplicate. Which physical security technique is this?

Explanation

Badge cloning captures and duplicates the data from a proximity access card, exactly as described with the RFID reader. Tailgating follows someone through a door, a site survey observes physical controls, a USB drop leaves malicious media for someone to find, and lock picking manipulates a physical lock mechanism.

Submit

16. After running a vulnerability scan, a tester compares the list of scanned hosts against the full asset inventory and discovers that 15 hosts on a remote office subnet were never reached by the scanner due to a network routing issue. Which concept does this comparison assess?

Explanation

Comparing scanned hosts against the full asset inventory to identify gaps in coverage is assessing scan completeness. True and false positive rates concern detection accuracy on hosts actually scanned, public exploit selection concerns choosing an exploit for a confirmed finding, and troubleshooting scan configurations is the subsequent step of fixing the routing issue.

Submit

17. A tester wants to scan a container image for known vulnerabilities in its operating system packages and application dependencies before it is pushed to a production registry. Which tool is well suited to this task?

Explanation

Trivy scans container images for known vulnerabilities in OS packages and application dependencies before deployment. BloodHound maps Active Directory attack paths, Nikto scans web servers, TruffleHog searches for exposed secrets, and PowerSploit is a post-exploitation PowerShell framework.

Submit

18. A tester wants to identify security misconfigurations, such as an overly permissive storage bucket policy, defined within a client's Terraform configuration files before that infrastructure is ever deployed. Complete the sentence: this is an example of static application security testing applied to ______.

Explanation

Extending static application security testing to Infrastructure as Code configuration files, such as Terraform definitions, catches misconfigurations before infrastructure is ever deployed. This differs from scanning a running application or an already-built container image, since IaC scanning happens against the definition files themselves.

Submit

19. A tester wants to quickly find email address naming patterns and specific email addresses associated with a target company's domain, drawn from a database of previously indexed public sources. Which tool is designed for this specific purpose?

Explanation

Hunter.io is specifically designed to find email address naming patterns and specific addresses associated with a domain. Amass focuses on subdomain and attack surface mapping, and Aircrack-ng, Wireshark, and InSSIDer are wireless or packet-analysis tools.

Submit

20. Rather than rewriting HTTP request logic from scratch in every script, a tester imports a pre-built module that provides ready-made functions for sending requests and parsing responses. Which concept does reusing this pre-built module represent?

Explanation

Importing a pre-built module with ready-made functions is exactly the use of libraries, functions, and classes to avoid rewriting common logic. Loops repeat code, conditionals make decisions, and Boolean and arithmetic operators evaluate logic or perform calculations rather than describing code reuse.

Submit

21. A tester runs a scan across an entire subnet specifically to determine which IP addresses have an active, responding host, without yet probing for specific open ports or services. Which enumeration technique is this?

Explanation

Host discovery identifies which IP addresses have an active, responding host, as a precursor to deeper enumeration. Service discovery identifies what is running on already-discovered hosts, protocol enumeration identifies protocols in use, share enumeration identifies accessible shares, and DNS enumeration identifies domain records.

Submit

22. A tester reviews a target company's current job postings and finds a listing that specifies required experience with a particular version of an internal ticketing system and a specific VPN client. Which OSINT technique does this represent?

Explanation

Reviewing job postings for clues about a target's technology stack is job board analysis, a passive OSINT technique. Password dumps refer to leaked credential databases, cached pages refer to archived web content, certificate transparency logs reveal issued TLS certificates, and network sniffing captures live traffic.

Submit

23. A tester wants a tool that automates OSINT collection by querying dozens of different public data sources at once, such as WHOIS records, breach databases, and social media, then compiles the results into a single correlated report. Which tool fits this description?

Explanation

SpiderFoot automates OSINT collection across dozens of public data sources simultaneously, compiling results into a correlated report. Nmap performs network scanning, Wireshark captures packet traffic, and Aircrack-ng and InSSIDer are wireless-focused tools.

Submit

24. After a client disputes a specific finding, claiming a compensating control the tester was unaware of should have prevented the exploit from working, the tester investigates why the finding was reported despite that control supposedly being in place. Which collaboration activity does this investigation represent?

Explanation

Investigating why a finding occurred, including reconciling it against a disputed compensating control, is root cause analysis. Peer review is a quality check by colleagues, goal reprioritization adjusts objectives, business impact analysis assesses organizational consequences, and secure distribution concerns how the report is safely shared.

Submit

25. During a cloud engagement, a tester finds that a client's virtual machine has an unpatched, outdated operating system, but the underlying hypervisor and physical infrastructure are fully patched by the cloud provider. Under the shared responsibility model, whose responsibility was the unpatched OS?

Explanation

Under the shared responsibility model for infrastructure-as-a-service, the customer is responsible for patching the guest OS and anything running on top of it, while the provider handles the underlying infrastructure and hypervisor. The provider's responsibility ends at the infrastructure layer, and a third party or the tester are not responsible for OS patching within this framework.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
A tester planning an attack chain notes that exploiting the final...
At the conclusion of an engagement, a tester decommissions the...
A tester copies a small amount of sensitive configuration data and...
A tester uses a legitimate, signed Windows utility normally used to...
A tester installs a malicious browser extension on a compromised...
A tester wants a PowerShell tool specifically built to discover and...
A tester on an industrial control network sends specially crafted...
A tester sends text messages to employees' personal phones claiming to...
A tester finds that a cloud service account has been granted broad...
A tester notices a web application URL includes a parameter like...
A tester disables a host's endpoint detection and response agent by...
In one test, a tester manipulates a signed assertion used for...
A tester captures an authentication attempt intended for one server...
Match each remediation example to its correct control category.
A tester briefly stands near an employee in a public coffee shop and...
After running a vulnerability scan, a tester compares the list of...
A tester wants to scan a container image for known vulnerabilities in...
A tester wants to identify security misconfigurations, such as an...
A tester wants to quickly find email address naming patterns and...
Rather than rewriting HTTP request logic from scratch in every script,...
A tester runs a scan across an entire subnet specifically to determine...
A tester reviews a target company's current job postings and finds a...
A tester wants a tool that automates OSINT collection by querying...
After a client disputes a specific finding, claiming a compensating...
During a cloud engagement, a tester finds that a client's virtual...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!