Latest PT0-001 Actual Free Exam Questions Updated 250 Questions
Free PT0-001 Exam Braindumps certification guide Q&A
PT0-001 Prerequisites
Notably, CompTIA suggests a certain level of experience and knowledge before one can take PT0-001. During the exam, candidates have to prove skills in determining a network's strength and security from malicious attack activities. They should be equipped with an intermediate understanding of how to customize evaluation frameworks for adequate work progress and be aware of the best procedures to communicate and recommend new ideas to improve the general state of IT security. In addition, having Security+, Network+ or equivalent knowledge is recommended, along with a minimum of 3 to 4 years' experience in IT security or any related area.
NEW QUESTION 146
A penetration tester is assessing the security of a web form for a client and enters ";id" in one of the fields.
The penetration tester observes the following response:
Based on the response, which of the following vulnerabilities exists?
- A. SQL injection
- B. XSS/XSRF
- C. Command injection
- D. Session hijacking
Answer: C
NEW QUESTION 147
The following command is run on a Linux file system:
Chmod 4111 /usr/bin/sudo
Which of the following issues may be exploited now?
- A. Unquoted service path
- B. Kernel vulnerabilities
- C. Misconfigured sudo
- D. Sticky bits
Answer: D
NEW QUESTION 148
Which of the following commands will allow a tester to enumerate potential unquoted service paths on a host?
wmic environment get name, variablevalue, username | findstr /i "Path" |
- A. findstr /i /v "c:\windows\\" |findstr /i /v """
- B. v /i "%"
wmic service get name, displayname, pathname, startmode |findstr /i "auto" | - C. findstr /i "Service"
wmic service get /format:hform > c:\temp\services.html - D. wmic startup get caption, location, command |findstr /i "service" |findstr /
Answer: A
Explanation:
Explanation/Reference: https://medium.com/@SumitVerma101/windows-privilege-escalation-part-1-unquoted-service- path-c7a011a8d8ae
NEW QUESTION 149
A client requests that a penetration tester emulate a help desk technician who was recently laid off. Which of the following BEST describes the abilities of the threat actor?
- A. Script kiddie
- B. Advanced persistent threat
- C. Hacktivist
- D. Organized crime
Answer: A
Explanation:
Reference https://www.sciencedirect.com/topics/computer-science/disgruntled-employee
NEW QUESTION 150
A recently concluded penetration test revealed that a legacy web application is vulnerable to SQL injection.
Research indicates that completely remediating the vulnerability would require an architectural change, and the stakeholders are not in a position to risk the availability on the application. Under such circumstances, which of the following controls are low-effort, short-term solutions to minimize the SQL injection risk? (Choose two.)
- A. Identify and sanitize all user inputs.
- B. Use a whitelist approach for SQL statements.
- C. Identify the source of malicious input and block the IP address.
- D. Identify and eliminate dynamic SQL from stored procedures.
- E. Use a blacklist approach for SQL statements.
- F. Identity and eliminate inline SQL statements from the code.
Answer: A,B
Explanation:
Explanation
NEW QUESTION 151
A technician is reviewing the following report. Given this information, identify which vulnerability can be definitively confirmed to be a false positive by dragging the "false positive" token to the "Confirmed" column for each vulnerability that is a false positive.
Answer:
Explanation:
NEW QUESTION 152
A penetration tester has compromised a host. Which of the following would be the correct syntax to create a Netcat listener on the device?
- A. nc -p 4444 /bin/bash
- B. nc -vp 4444 /bin/bash
- C. nc -l -p 4444 /bin/bash
- D. nc -lp 4444 /bin/bash
Answer: C
Explanation:
Explanation/Reference: https://null-byte.wonderhowto.com/how-to/hack-like-pro-use-netcat-swiss-army-knife-hacking-tools-
0148657/
NEW QUESTION 153
A vulnerability scan report shows what appears to be evidence of a memory disclosure vulnerability on one of the target hosts. The administrator claims the system is patched and the evidence is a false positive.
Which of the following is the BEST method for a tester to confirm the vulnerability exists?
- A. Run the vulnerability scanner again.
- B. Manually run publicly available exploit code.
- C. Perform dynamic analysis on the vulnerable service.
- D. Confirm via evidence of the updated version number.
Answer: A
NEW QUESTION 154
While trying to maintain persistence on a Windows system with limited privileges, which of the following registry keys should the tester use?
- A. HKEY_CURRENT_USER
- B. HKEY_CLASSES_ROOT
- C. HKEY_LOCAL_MACHINE
- D. HKEY_CURRENT_CONFIG
Answer: A
Explanation:
Explanation/Reference: https://www.redcanary.com/blog/windows-registry-attacks-threat-detection/
NEW QUESTION 155
A penetration tester used an ASP.NET web shell to gain access to a web application, which allowed the tester to pivot in the corporate network. Which of the following is the MOST important follow-up activity to complete after the tester delivers the report?
- A. Documenting lessons learned
- B. Presenting attestation of findings
- C. Removing tester-created credentials
- D. Removing shells
- E. Obtaining client acceptance
Answer: B
NEW QUESTION 156
A penetration tester has successfully deployed an evil twin and is starting to see some victim traffic. The next step the penetration tester wants to take is to capture all the victim web traffic unencrypted. Which of the following would BEST meet this goal?
- A. Implement a CA attack by impersonating trusted CAs.
- B. Harvest the user credentials to decrypt traffic.
- C. Perform an MITM attack.
- D. Perform an HTTP downgrade attack.
Answer: D
NEW QUESTION 157
While engaging clients for a penetration test from highly regulated industries, which of the following is usually the MOST important to the clients from a business perspective?
- A. Letter of engagement and attestation of findings
- B. SOW and final report
- C. NDA and MSA
- D. Risk summary and executive summary
Answer: B
NEW QUESTION 158
While reviewing logs, a web developer notices the following user input string in a field:
Which of the following types of attacks was done to the website?
- A. Blind XSS
- B. XSS injection
- C. Reflected XSS
- D. Persistent XSS
Answer: B
NEW QUESTION 159
A company performed an annual penetration test of its environment. In addition to several new findings, all of the previously identified findings persisted on the latest report. Which of the following is the MOST likely reason?
- A. The penetration testing tools were misconfigured.
- B. The organization is not taking action to remediate identified findings.
- C. Systems administrators are applying the wrong patches.
- D. Infrastructure is being replaced with similar hardware and software.
Answer: B
NEW QUESTION 160
A penetration tester calls human resources and begins asking open-ended questions Which of the following social engineering techniques is the penetration tester using?
- A. Interrogation
- B. Elicitation
- C. Impersonation
- D. Spear phishing
Answer: B
NEW QUESTION 161
......
PT0-001 Certification Overview Latest PT0-001 PDF Dumps: https://www.validvce.com/PT0-001-exam-collection.html
Top CompTIA PT0-001 Exam Audio Study Guide! Practice Questions Edition: https://drive.google.com/open?id=1-Cs7dlDwXkEpEe00yHQw9R64k8FipVfn
