{"id":17041,"date":"2026-09-21T06:09:06","date_gmt":"2026-09-21T06:09:06","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17041"},"modified":"2026-09-21T06:09:06","modified_gmt":"2026-09-21T06:09:06","slug":"comptia-pentest-pt0-003-practice-test-questions-and-exam-dumps-part11-q201-220","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-pentest-pt0-003-practice-test-questions-and-exam-dumps-part11-q201-220\/","title":{"rendered":"CompTIA Pentest+ PT0-003 Practice Test Questions and Exam Dumps Part11 Q201-220"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/pt0-003-exam-dumps\"><b>CompTIA PT0-003 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 201<\/b><\/h3>\n<p><b>Which tool is commonly used to analyze relationships between users, groups, computers, and permissions in an Active Directory environment?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Nikto<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Gobuster<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BloodHound<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashcat<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">BloodHound is designed to visualize relationships and permissions within Active Directory environments. During an authorized penetration test, it can help identify relationships between users, groups, computers, sessions, and delegated permissions that may create potential attack paths. Its value comes from showing how existing privileges and relationships connect rather than simply listing individual vulnerabilities. Testers should use the tool only against approved environments and handle collected directory information securely because it may contain sensitive organizational details.<\/span><\/p>\n<h3><b>Question 202<\/b><\/h3>\n<p><b>Which protocol is commonly associated with Windows file and printer sharing?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SMB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SMTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Server Message Block (SMB) is commonly used for file and printer sharing in Windows environments. During authorized penetration testing, SMB services can be assessed for exposed shares, authentication configuration, protocol versions, permissions, and other security weaknesses. Improperly configured shares may expose sensitive files or provide unnecessary access to users. Organizations can reduce risk by restricting SMB exposure, applying appropriate permissions, disabling obsolete protocol versions, and segmenting systems. SMB assessment should remain within clearly authorized hosts and networks.<\/span><\/p>\n<h3><b>Question 203<\/b><\/h3>\n<p><b>A tester identifies a domain that appears related to the target organization but is hosted by an unrelated provider. What should the tester do before scanning it?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Scan it immediately<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Confirm whether it is within scope<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Attempt credential attacks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Add it to the report as compromised<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A discovered domain should be verified against the engagement scope before active testing begins. Organizations frequently use third-party hosting providers, marketing platforms, SaaS services, subsidiaries, and external partners. Ownership or association with a target organization does not automatically authorize penetration testing against the system. Scope verification prevents accidental testing of systems belonging to another party and reduces legal and operational risks. If authorization is unclear, the tester should consult the designated engagement contact rather than assuming that the asset is included.<\/span><\/p>\n<h3><b>Question 204<\/b><\/h3>\n<p><b>Which attack attempts to trick a system into resolving a legitimate hostname to an attacker-controlled address?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS spoofing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Directory traversal<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DNS spoofing involves providing falsified DNS information so that a hostname resolves to an unintended address. Depending on the environment, manipulated DNS responses can redirect users or applications toward attacker-controlled infrastructure. During an authorized assessment, testers can evaluate whether DNS security controls and monitoring detect unexpected resolution behavior. Secure DNS configuration, protected DNS infrastructure, appropriate validation mechanisms, and DNSSEC where suitable can reduce certain risks. DNS spoofing differs from SQL injection and directory traversal because it targets name resolution rather than application input or filesystem paths.<\/span><\/p>\n<h3><b>Question 205<\/b><\/h3>\n<p><b>Which scan type attempts to complete the TCP connection rather than stopping after the SYN response?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">UDP scan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">TCP connect scan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Idle scan<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP scan<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A TCP connect scan completes the TCP connection process when testing a port, allowing the tester to determine whether a TCP service is accepting connections. This differs from a SYN scan, which generally stops before completing the connection. TCP connect scans can be useful when the tester lacks the privileges required for certain lower-level scanning techniques or when a complete connection is appropriate. During authorized testing, scan selection should consider network impact, detection requirements, and the rules of engagement.<\/span><\/p>\n<h3><b>Question 206<\/b><\/h3>\n<p><b>Which web security issue occurs when an application allows a user to submit content that is later executed in another user&#8217;s browser?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Stored XSS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CSRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IDOR<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Stored cross-site scripting occurs when malicious or otherwise untrusted content is stored by an application and later delivered to other users in a context where the browser interprets it as executable content. Common locations can include comments, profiles, messages, or other user-generated content. During authorized testing, testers should validate the issue carefully and avoid exposing unnecessary users or data. Proper output encoding, input handling, content security policies, and safe application design can reduce the likelihood and impact of stored XSS vulnerabilities.<\/span><\/p>\n<h3><b>Question 207<\/b><\/h3>\n<p><b>Which technology is commonly used to securely authenticate users over an enterprise wireless network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WPA3-Personal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WPA3-Enterprise<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">WEP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open Wi-Fi<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">WPA3-Enterprise is designed for enterprise wireless environments and can use stronger authentication mechanisms through an authentication server infrastructure. It is appropriate for organizations that require centralized identity-based wireless access rather than relying on a shared password. During an authorized wireless assessment, testers can review authentication methods, encryption settings, certificate validation, and network segmentation. WEP is obsolete, while open Wi-Fi provides no comparable wireless encryption. Enterprise wireless security should also include appropriate monitoring and access-control policies.<\/span><\/p>\n<h3><b>Question 208<\/b><\/h3>\n<p><b>What does a false positive from a vulnerability scanner mean?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A vulnerability exists but was missed<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">A vulnerability is reported even though it is not actually present<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The system has been successfully compromised<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The scan was never started<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A false positive occurs when an automated scanner reports a vulnerability that is not actually present on the target. This can happen because of inaccurate version detection, generic signatures, unusual configurations, backported patches, or incomplete application context. During penetration testing, important findings should be validated before being treated as confirmed vulnerabilities. Reducing false positives improves report quality and prevents organizations from spending resources on issues that do not represent actual risk. Manual validation is particularly valuable for high-impact findings.<\/span><\/p>\n<h3><b>Question 209<\/b><\/h3>\n<p><b>Which protocol is commonly used to send email between mail servers?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SMTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LDAP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SMB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RDP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Simple Mail Transfer Protocol (SMTP) is commonly used for sending and relaying email between mail systems. During authorized assessments, SMTP services may be reviewed for configuration weaknesses, unnecessary information disclosure, authentication issues, or inappropriate relay behavior. Secure mail infrastructure should restrict unauthorized relay and use appropriate authentication and transport protections. LDAP is primarily associated with directory services, SMB with file and printer sharing, and RDP with remote desktop access. Mail-service testing should follow the engagement&#8217;s approved scope and communication rules.<\/span><\/p>\n<h3><b>Question 210<\/b><\/h3>\n<p><b>A vulnerability is technically serious but a compensating control significantly limits exposure. What should the tester consider?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Ignore the vulnerability completely<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Consider both the underlying weakness and the compensating control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automatically classify it as informational<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Delete the evidence<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A vulnerability should be assessed in the context of the target&#8217;s actual security controls. A compensating control may reduce exploitability or limit potential impact without removing the underlying weakness. The tester should document both the vulnerability and the control that mitigates it, explaining how the control affects practical risk. This provides stakeholders with a more accurate assessment than ignoring either factor. Severity should be supported by evidence and appropriate methodology rather than determined solely from the vulnerability&#8217;s theoretical impact.<\/span><\/p>\n<h3><b>Question 211<\/b><\/h3>\n<p><b>Which technique attempts to use a captured authentication hash without recovering the original password?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pass-the-hash<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential stuffing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open redirect<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Pass-the-hash involves using a captured password hash or equivalent authentication material to authenticate to certain services without first recovering the plaintext password. In an authorized assessment, this can demonstrate the impact of credential exposure and weaknesses in authentication architecture. The technique differs from password cracking because the tester does not necessarily need to recover the original password. Organizations can reduce risk through protections for privileged credentials, credential isolation, appropriate authentication controls, network segmentation, and monitoring for unusual authentication activity.<\/span><\/p>\n<h3><b>Question 212<\/b><\/h3>\n<p><b>Which reconnaissance method can identify historical versions of a website or previously published content?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web archives<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ARP scanning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Port knocking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Packet fragmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Web archives preserve historical copies or records of publicly accessible websites and can reveal information that is no longer visible on the current site. During authorized reconnaissance, historical content may expose old subdomains, documentation, technologies, employee references, or previously published files. Such information can help testers understand changes in the target&#8217;s external footprint. Because archived information may reference infrastructure that is no longer owned or authorized by the organization, testers should verify current scope before performing active testing against any discovered assets.<\/span><\/p>\n<h3><b>Question 213<\/b><\/h3>\n<p><b>Which vulnerability allows an attacker to influence a server into processing an external entity or resource referenced by submitted data?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">XXE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CSRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">IDOR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open redirect<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">XML External Entity (XXE) vulnerabilities can occur when an application processes XML input with unsafe external-entity functionality enabled. Depending on the parser and application design, this may expose sensitive resources or cause the server to interact with unintended destinations. During authorized testing, testers should determine whether external entity processing is enabled and whether appropriate parser protections are applied. Secure XML parsers should disable unnecessary external entities and related features. Modern applications should also minimize XML functionality when it is not required.<\/span><\/p>\n<h3><b>Question 214<\/b><\/h3>\n<p><b>What is the purpose of an API authentication token?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identify and authorize a client or user<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase DNS speed<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Detect wireless channels<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Compress HTTP responses<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An API authentication token is commonly used to represent an authenticated client, user, or service when making requests to an API. Depending on the authentication design, the token may contain or reference identity and authorization information. During authorized testing, testers can evaluate token expiration, storage, transmission, scope, and authorization enforcement. A valid token should not automatically grant unrestricted access; the server must still verify whether the requested operation is permitted. Secure token management reduces the impact of token theft or misuse.<\/span><\/p>\n<h3><b>Question 215<\/b><\/h3>\n<p><b>Which network attack can intercept traffic by placing a malicious system between two communicating parties?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Man-in-the-middle<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dictionary attack<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Directory traversal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A man-in-the-middle attack occurs when an attacker positions themselves between communicating systems and potentially intercepts or alters traffic. The feasibility of such an attack depends on network architecture, encryption, authentication, and other controls. During an authorized assessment, testers may evaluate whether communications are properly protected against interception and whether users or systems validate the identity of communication endpoints. Strong encryption, certificate validation, secure protocols, network segmentation, and monitoring can reduce the risk of successful interception.<\/span><\/p>\n<h3><b>Question 216<\/b><\/h3>\n<p><b>Which assessment activity determines whether a discovered vulnerability can actually be reproduced under controlled conditions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Validation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Asset disposal<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data archiving<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network provisioning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Vulnerability validation confirms that a suspected security issue is genuinely present and reproducible under controlled conditions. Automated tools may identify potential vulnerabilities, but manual validation can establish whether the reported condition applies to the specific target configuration. During authorized testing, validation should be performed carefully and with minimal impact. Testers should record relevant evidence, affected components, limitations, and environmental factors. Confirmed findings provide stronger support for remediation decisions than unverified scanner alerts.<\/span><\/p>\n<h3><b>Question 217<\/b><\/h3>\n<p><b>Which tool is commonly used to recover passwords from captured password hashes during authorized testing?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Wireshark<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hashcat<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Nmap<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Nikto<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Hashcat is a password-recovery tool commonly used to assess the strength of password hashes in authorized security engagements. Testers can use appropriate wordlists, rules, or computational approaches to determine whether weak passwords can be recovered from captured hashes. The objective is to evaluate password security rather than unnecessarily access unrelated accounts. Hashcat should only be used with credentials or hashes that are explicitly authorized for testing. Strong password policies, MFA, secure hashing algorithms, and appropriate credential management reduce the risk associated with password compromise.<\/span><\/p>\n<h3><b>Question 218<\/b><\/h3>\n<p><b>Which security header instructs browsers to prefer HTTPS connections for a website?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Strict-Transport-Security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Content-Type<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Accept<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Location<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Strict-Transport-Security, commonly known as HSTS, instructs compatible browsers to use HTTPS for future connections to a domain for a specified period. This helps reduce certain downgrade and protocol-stripping risks by discouraging insecure HTTP communication. During authorized web assessments, testers can review whether HSTS is present and whether its configuration is appropriate for the application and domain. HSTS does not replace valid TLS certificates or secure server configuration. It works as an additional control that reinforces secure transport.<\/span><\/p>\n<h3><b>Question 219<\/b><\/h3>\n<p><b>Which activity involves identifying operating-system and application versions from service responses?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Banner grabbing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data destruction<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential rotation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Banner grabbing involves examining information returned by services to identify software names, versions, or other characteristics. This can help testers understand the technology running on a target and determine which vulnerabilities or configuration issues may be relevant. Service banners can be manually provided, automatically detected, or intentionally hidden by administrators. Because banners can be inaccurate or misleading, testers should validate important version information before reporting a vulnerability. Reducing unnecessary banner information can also limit passive information disclosure.<\/span><\/p>\n<h3><b>Question 220<\/b><\/h3>\n<p><b>What is the primary purpose of a vulnerability remediation plan?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Define actions for reducing or eliminating identified security weaknesses<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increase the number of discovered vulnerabilities<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Replace penetration-testing authorization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hide unresolved findings<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A vulnerability remediation plan defines actions needed to reduce or eliminate identified security weaknesses. Depending on the finding, actions may include patching software, changing configurations, improving access controls, implementing MFA, modifying application code, or applying compensating controls. A good plan identifies responsible teams, priorities, and expected completion timelines where appropriate. During penetration testing, remediation recommendations should be practical and tied to the evidence collected. After remediation, a retest can determine whether the original security issue has been effectively addressed.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA PT0-003 Exam Dumps and Practice Test Dumps. &nbsp; Question 201 Which tool is commonly used to analyze relationships between users, groups, computers, and permissions in an Active Directory environment? Nikto Gobuster BloodHound Hashcat Correct Answer: 3 Explanation BloodHound is designed to visualize relationships and permissions within Active Directory environments. During an authorized [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17041"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17041"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17041\/revisions"}],"predecessor-version":[{"id":17042,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17041\/revisions\/17042"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17041"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17041"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17041"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}