CompTIA certification preparation
PT0-003 Practice Questions
Practice exam-style questions, check your answers, and review explanations and source references where they are available.
- Exam
- PT0-003
- Provider
- CompTIA
- Full set
- 329 questions
- Last Update Check
[Attacks and Exploits] A penetration tester is trying to get unauthorized access to a web application and executes the following command:
GET /foo/images/file?id=2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fetc%2fpasswd
Which of the following web application attacks is the tester performing?
Question 1 discussion
Question 2 discussion
[Attacks and Exploits] During an assessment, a penetration tester gains a low-privilege shell and then runs the following command:
findstr /SIM /C:"pass" *.txt *.cfg *.xml
Which of the following is the penetration tester trying to enumerate?
Question 3 discussion
Question 4 discussion
Question 5 discussion
Question 6 discussion
[Attacks and Exploits] A penetration tester finds that an application responds with the contents of the /etc/passwd file when the following payload is sent:
xml Copy code ]> &foo;
Which of the following should the tester recommend in the report to best prevent this type of vulnerability?
Question 7 discussion
Question 8 discussion
Question 9 discussion
During an assessment, a penetration tester sends the following request:
POST /services/v1/users/create HTTP/1.1
Host: target-application.com Content-Type:
application/json Content-Length: [dynamic]
Authorization: Bearer (FUZZ)
Which of the following attacks is the penetration tester performing?
Question 10 discussion
Source context
How this practice set is maintained
Maintained by the CertMage content team, this page loads questions from the exam dataset connected to its preparation resource. When an answer includes a supporting reference, it is shown with that answer so you can review the underlying vendor documentation.
Certification objectives, interfaces, and vendor services can change. Verify important details against the provider's current exam guide and documentation before your exam.
