CompTIA PenTest+ Exam PT0-003 Practice Questions

Page: 1 / 14
Total 365 questions
Question 1

As part of a security audit, a penetration tester finds an internal application that accepts unexpected user inputs, leading to the execution of arbitrary commands. Which of the following techniques would the penetration tester most likely use to access the sensitive data?



Answer : B

SQL injection (SQLi) is a technique that allows attackers to manipulate SQL queries to execute arbitrary commands on a database. It is one of the most common and effective methods for accessing sensitive data in internal applications that accept unexpected user inputs. Here's why option B is the most likely technique:

Arbitrary Command Execution: The question specifies that the internal application accepts unexpected user inputs leading to arbitrary command execution. SQL injection fits this description as it exploits vulnerabilities in the application's input handling to execute unintended SQL commands on the database.

Data Access: SQL injection can be used to extract sensitive data from the database, modify or delete records, and perform administrative operations on the database server. This makes it a powerful technique for accessing sensitive information.

Common Vulnerability: SQL injection is a well-known and frequently exploited vulnerability in web applications, making it a likely technique that a penetration tester would use to exploit input handling issues in an internal application.

Reference from Pentest:

Luke HTB: This write-up demonstrates how SQL injection was used to exploit an internal application and access sensitive data. It highlights the process of identifying and leveraging SQL injection vulnerabilities to achieve data extraction.

Writeup HTB: Describes how SQL injection was utilized to gain access to user credentials and further exploit the application. This example aligns with the scenario of using SQL injection to execute arbitrary commands and access sensitive data.

Conclusion:

Given the nature of the vulnerability described (accepting unexpected user inputs leading to arbitrary command execution), SQL injection is the most appropriate and likely technique that the penetration tester would use to access sensitive data. This method directly targets the input handling mechanism to manipulate SQL queries, making it the best choice.

======


Question 2

A penetration tester currently conducts phishing reconnaissance using various tools and accounts for multiple intelligence-gathering platforms. The tester wants to consolidate some of the tools and accounts into one solution to analyze the output from the intelligence-gathering tools. Which of the following is the best tool for the penetration tester to use?



Answer : C

Penetration testers use OSINT (Open-Source Intelligence) tools to collect and analyze reconnaissance data.

Maltego (Option C):

Maltego is a powerful graph-based OSINT tool that integrates data from multiple sources (e.g., social media, DNS records, leaked credentials).

It automates data correlation and helps visualize connections.


Incorrect options:

Option A (Caldera): Used for adversary emulation, not OSINT.

Option B (SpiderFoot): A reconnaissance tool but lacks data correlation capabilities.

Option D (WIGLE.net): A wireless network database, not an OSINT analysis tool.

Question 3

A penetration tester modifies a web application's URL by inserting malformed data into input parameters. The web application returns the error message below:

Internal Server Error

NumberFormatException: For input string ...

Source file: /home/www/htmldoc/app001/140612/main

Which of the following actions will the tester most likely take?



Answer : A

The returned error indicates that the application is processing user-controlled input dynamically and failing to handle malformed input properly. A NumberFormatException typically occurs when the application expects a numeric value but receives a string or unexpected format. The error also leaks internal implementation details, including exception type and server-side file path information. The most appropriate next action is dynamic application security testing, because the tester is interacting with the running application, manipulating parameters, observing responses, and identifying weaknesses in input validation, error handling, and information disclosure. This is not evidence of log tampering, since the tester is not modifying or deleting logs. It also does not indicate a memory corruption condition; managed exceptions such as number-format parsing errors are usually logic or validation issues rather than remote buffer overflows. SQL injection is possible in many parameterized web contexts, but this specific error points more directly to improper type handling and verbose error disclosure. This maps to study-guide topics covering DAST, web application testing, input validation, fuzzing, error handling, and secure coding weaknesses.


Question 4

A penetration tester uses a Python script to scan web servers. The script loops through ports including 443, 80, and 8080, but constructs every request using http://. The script fails during execution. Which of the following should the tester do?



Answer : D

Port 443 normally provides HTTPS rather than unencrypted HTTP. A request constructed as http://host:443 can fail because the client initiates an unencrypted HTTP exchange while the service expects a TLS handshake.

The script should select the scheme according to the port, for example:

scheme = 'https' if port == '443' else 'http'

The nesting order of the loops is not the underlying problem. response.status_code can be printed directly. Changing GET to POST does not correct the protocol mismatch.

Reference status: PT0-003-aligned code-analysis concepts involving Python requests, URL construction, HTTP, HTTPS, ports, and error correction.

===========


Question 5

A penetration tester reviews a SAST vulnerability scan report. The following lines of code have been reported as vulnerable:

Issue 40 of 126

Language: Java

Severity: Medium

Call:

try {

// ...

} catch (SomeException e) {

e.printStackTrace();

}

Which of the following is the best method to remediate this vulnerability?



Answer : A

The correct answer is A. Implementing a logging framework

The vulnerable code uses:

e.printStackTrace();

In Java applications, printStackTrace() can expose sensitive internal details, such as class names, file paths, line numbers, application logic, database errors, and other implementation information. If this output is displayed to users or written insecurely, it can help an attacker understand the application and craft further attacks.

The best remediation is to replace direct stack trace printing with a proper logging framework, such as Log4j, SLF4J, or java.util.logging, configured with appropriate log levels and secure log handling. A logging framework allows developers to record useful diagnostic information while controlling where logs are stored, what level of detail is included, and whether sensitive data is exposed.

B is incorrect because simply removing the reported code lines may break exception handling and does not provide a proper secure error-handling solution.

C is incorrect because secure coding awareness is useful as a long-term improvement, but it does not directly remediate this specific vulnerable code.

D is incorrect because this is not a false positive. Direct use of printStackTrace() is commonly flagged by SAST tools because it can result in information disclosure.

In PenTest+ terms, this falls under Tools and Code Analysis, specifically SAST findings, insecure error handling, information disclosure, and secure coding remediation.


Question 6

A tester conducts a web application penetration test and discovers a hidden diagnostics page. The hidden diagnostics page allows a user to ping other systems and test connectivity. Which of the following payloads is best suited to test this function?



Answer : A

The correct answer is A. ; whoami ; ps aux

A diagnostics page that allows users to ping other systems commonly passes user input to an operating system command such as ping. If the application does not properly validate or sanitize input, an attacker may be able to inject additional operating system commands.

The semicolon ; is a command separator on Unix/Linux systems. A payload such as:

; whoami ; ps aux

attempts to terminate or extend the original ping command and execute additional commands. whoami identifies the user context running the command, and ps aux lists running processes. This makes it an appropriate payload for testing command injection.

B is incorrect because <script>alert(1)</script> is used to test cross-site scripting.

C is incorrect because ' SELECT @@version -- is used to test SQL injection.

D is incorrect because ../../../../../../etc/passwd is used to test path traversal or local file inclusion.

In PenTest+ terms, this falls under Attacks and Exploits, specifically web application command injection testing.


Question 7

A penetration tester needs to help create a threat model of a custom application. Which of the following is the most likely framework the tester will use?



Answer : D

The DREAD model is a risk assessment framework used to evaluate and prioritize the security risks of an application. It stands for Damage potential, Reproducibility, Exploitability, Affected users, and Discoverability.

Understanding DREAD:

Purpose: Provides a structured way to assess and prioritize risks based on their potential impact and likelihood.

Components:

Damage Potential: The extent of harm that an exploit could cause.

Reproducibility: How easily the exploit can be reproduced.

Exploitability: The ease with which the vulnerability can be exploited.

Affected Users: The number of users affected by the exploit.

Discoverability: The likelihood that the vulnerability will be discovered.

Usage in Threat Modeling:

Evaluation: Assign scores to each DREAD component to assess the overall risk.

Prioritization: Higher scores indicate higher risks, helping prioritize remediation efforts.

Process:

Identify Threats: Enumerate potential threats to the application.

Assess Risks: Use the DREAD model to evaluate each threat.

Prioritize: Focus on addressing the highest-scoring threats first.

Reference from Pentesting Literature:

The DREAD model is widely discussed in threat modeling and risk assessment sections of penetration testing guides.

HTB write-ups often include references to DREAD when explaining how to assess and prioritize vulnerabilities in applications.

Step-by-Step ExplanationReference:

Penetration Testing - A Hands-on Introduction to Hacking

HTB Official Writeups

======


Page:    1 / 14   
Total 365 questions