CompTIA PenTest+ Practice Test 2

CompTIA PenTest+ Practice Test

1 / 10

A pen test must avoid disrupting a healthcare provider’s patient systems. Which scoping factor ensures this?

2 / 10

You’re reviewing a Ruby script with user input. Which line indicates a potential command injection risk?

3 / 10

A client needs evidence of a successful exploit for compliance. Which deliverable should you provide?

4 / 10

You’re exploiting a Windows host vulnerable to MS08-067. Which Metasploit module should you use?

5 / 10

A target has an open port 22. Which command tests for weak SSH credentials?

6 / 10

You’re analyzing a PHP script for vulnerabilities. Which tool detects insecure deserialization flaws?

7 / 10

After exploiting a system, you must document the attack path. Which report section should include this?

8 / 10

A web app is susceptible to directory traversal. Which payload tests for this vulnerability?

9 / 10

You need to enumerate subdomains for a target passively. Which tool leverages public certificate transparency logs?

10 / 10

A client requires a pen test but restricts access to production systems. Which document should you consult to clarify permissible targets?

Your score is

The average score is 0%

0%