{"id":17060,"date":"2026-09-21T06:13:47","date_gmt":"2026-09-21T06:13:47","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17060"},"modified":"2026-09-21T06:13:47","modified_gmt":"2026-09-21T06:13:47","slug":"comptia-pentest-pt0-003-practice-test-questions-and-exam-dumps-part20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-pentest-pt0-003-practice-test-questions-and-exam-dumps-part20-q381-400\/","title":{"rendered":"CompTIA Pentest+ PT0-003 Practice Test Questions and Exam Dumps Part20 Q381-400"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/pt0-003-exam-dumps\"><b>CompTIA PT0-003 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 381<\/b><\/h3>\n<p><b>Before testing a production application that restricts access by source IP address, what should the penetration tester confirm?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The application&#8217;s logo<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The authorized testing source IP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The database table names<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The server&#8217;s screen resolution<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Source-IP restrictions can prevent legitimate testing traffic from reaching an application or can cause unexpected security events if testing originates from an unauthorized location. Before beginning the assessment, the penetration tester should confirm which source IP addresses, VPN connections, or approved jump hosts are authorized by the engagement documentation. This ensures that testing traffic follows the agreed network path and remains within scope. Verifying the testing source also helps the client distinguish authorized penetration-testing activity from potentially suspicious external traffic.<\/span><\/p>\n<h3><b>Question 382<\/b><\/h3>\n<p><b>Which DNS record creates an alias that points one domain name to another canonical hostname?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CNAME<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">AAAA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PTR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MX<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A CNAME, or Canonical Name, record creates an alias from one DNS name to another hostname. It is commonly used when multiple names should resolve through a shared canonical destination. An AAAA record maps a hostname to an IPv6 address, a PTR record supports reverse DNS lookups, and an MX record identifies mail servers responsible for receiving email. During authorized reconnaissance, identifying CNAME relationships can help testers understand how different publicly accessible names are connected to shared infrastructure or external service providers.<\/span><\/p>\n<h3><b>Question 383<\/b><\/h3>\n<p><b>A security assessment identifies a public DNS zone containing internal hostnames that should not be exposed externally. Which issue should the tester document?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS information exposure<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session fixation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Container escape<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Publicly accessible DNS information can reveal internal naming conventions, infrastructure roles, development systems, management hosts, or other details that were not intended for external disclosure. During an authorized assessment, testers should document the exposed information and explain how it could assist reconnaissance without assuming that disclosure automatically represents a critical vulnerability. The appropriate severity depends on the sensitivity of the information and the organization&#8217;s architecture. Session fixation, password spraying, and container escape are unrelated security issues.<\/span><\/p>\n<h3><b>Question 384<\/b><\/h3>\n<p><b>Which DNS security mechanism uses cryptographic signatures to provide authenticity and integrity for DNS responses?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SNMP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DNSSEC, or Domain Name System Security Extensions, uses digital signatures to help validate the authenticity and integrity of DNS data. It is designed to reduce certain DNS manipulation risks by allowing validating resolvers to verify that responses originate from an authorized DNS hierarchy and have not been altered. DHCP assigns network configuration, SNMP is used for network management, and FTP transfers files. During an authorized assessment, reviewing DNSSEC configuration can help identify weaknesses in an organization&#8217;s DNS security architecture.<\/span><\/p>\n<h3><b>Question 385<\/b><\/h3>\n<p><b>A tester discovers that a web application processes serialized objects received from users without adequately validating their contents. Which vulnerability class may be involved?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Insecure deserialization<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Network segmentation failure<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate expiration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Insecure deserialization occurs when an application reconstructs serialized objects from untrusted or insufficiently validated input. Depending on the technology and implementation, unsafe deserialization can lead to unauthorized actions, data manipulation, or other serious security consequences. During an authorized assessment, testers should determine whether serialized data is trusted, whether integrity controls exist, and whether the application restricts accepted object types. Network segmentation, password spraying, and certificate expiration address different security areas and do not describe unsafe object reconstruction.<\/span><\/p>\n<h3><b>Question 386<\/b><\/h3>\n<p><b>Which web security weakness occurs when a server uses a user-controlled URL to make requests to another resource without adequately restricting the destination?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CORS misconfiguration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SSRF<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Clickjacking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session fixation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Server-Side Request Forgery, or SSRF, occurs when an application causes its server to make requests based on attacker-controlled or insufficiently restricted input. The security concern is that the server may have network access or privileges that the external requester does not possess. During an authorized assessment, testers should evaluate whether destination controls, network segmentation, and request validation are properly implemented. CORS misconfiguration concerns browser-origin policies, clickjacking involves deceptive framing, and session fixation concerns session identifiers.<\/span><\/p>\n<h3><b>Question 387<\/b><\/h3>\n<p><b>An API accepts requests from arbitrary websites and exposes sensitive authenticated data through browser-based requests. Which configuration should the tester investigate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CORS policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS TTL<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SMTP banner<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP configuration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cross-Origin Resource Sharing, or CORS, controls which web origins are permitted to interact with resources through browser-based cross-origin requests. An overly permissive CORS configuration can expose sensitive API responses when combined with authentication and other conditions. During an authorized assessment, testers should review allowed origins, credential handling, and whether sensitive endpoints are unnecessarily accessible cross-origin. DNS TTL controls caching duration, SMTP banners identify mail services, and NTP configuration concerns time synchronization. CORS should be evaluated in the context of the application&#8217;s actual authentication model.<\/span><\/p>\n<h3><b>Question 388<\/b><\/h3>\n<p><b>Which web vulnerability can occur when an application includes a local server file based on insufficiently validated user input?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN hopping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Local file inclusion<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS poisoning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Local File Inclusion, or LFI, occurs when an application incorporates or processes files from the local server based on user-controlled input without adequate validation. Depending on the application and server configuration, this can expose sensitive files or affect application behavior. During an authorized assessment, testers should determine whether file paths are constrained to intended resources and whether strong allowlisting is used. VLAN hopping affects network segmentation, password spraying targets authentication systems, and DNS poisoning manipulates name resolution.<\/span><\/p>\n<h3><b>Question 389<\/b><\/h3>\n<p><b>A web application redirects users after login based on a URL supplied by the client. What should the tester verify to reduce OAuth-related redirect abuse?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether the redirect URI is strictly validated<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether DNS uses short TTL values<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether the server supports IPv6<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Whether SMTP uses encryption<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">OAuth implementations should carefully validate redirect URIs so authorization responses are returned only to approved destinations. Weak or overly flexible redirect validation can create opportunities for authorization information to be sent to an unintended location. During an authorized assessment, testers should review whether registered redirect URIs are exact or appropriately constrained and whether wildcard behavior introduces unnecessary risk. DNS TTL, IPv6 support, and SMTP encryption do not directly address OAuth redirect validation. Proper redirect handling is an important part of secure authorization-flow design.<\/span><\/p>\n<h3><b>Question 390<\/b><\/h3>\n<p><b>Which network attack can exploit insufficient separation between VLANs by causing traffic from one VLAN to reach another?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Session fixation<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">XXE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN hopping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Credential stuffing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">VLAN hopping refers to techniques that can allow network traffic to cross VLAN boundaries when switch configuration or trunking controls are improperly implemented. This can weaken intended network segmentation and potentially expose systems that should be isolated from one another. During an authorized internal assessment, testers should evaluate VLAN configuration and segmentation controls according to the engagement&#8217;s scope. Session fixation affects web sessions, XXE concerns XML processing, and credential stuffing involves reused credentials. Proper switch configuration and segmentation reduce the risk of unintended VLAN traversal.<\/span><\/p>\n<h3><b>Question 391<\/b><\/h3>\n<p><b>Which protocol is commonly associated with authentication in enterprise wireless networks using centralized identity services?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">802.1X<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">FTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Telnet<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">POP3<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IEEE 802.1X provides port-based network access control and is commonly used with enterprise wireless authentication. It can work with an authentication server to validate users or devices before granting network access. During an authorized wireless assessment, testers may review whether enterprise authentication is properly configured and whether appropriate authentication methods and certificate validation are used. FTP and Telnet are older application-layer protocols, while POP3 is primarily used for retrieving email. Enterprise wireless security generally benefits from centralized authentication rather than shared credentials.<\/span><\/p>\n<h3><b>Question 392<\/b><\/h3>\n<p><b>A tester observes that Windows hosts are resolving names through a legacy local-name-resolution protocol that could expose authentication information. Which protocol should receive attention?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">HTTPS<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">LLMNR<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SFTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNSSEC<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Link-Local Multicast Name Resolution, or LLMNR, is a legacy name-resolution mechanism used in some Windows environments. If improperly configured, name-resolution behavior can create opportunities for credential-related information exposure during an authorized internal assessment. Organizations can reduce unnecessary exposure by disabling legacy protocols where they are not required and using appropriately secured name-resolution services. HTTPS protects web communications, SFTP provides secure file transfer, and DNSSEC adds integrity protections to DNS. The exact risk should be evaluated against the organization&#8217;s configuration and security controls.<\/span><\/p>\n<h3><b>Question 393<\/b><\/h3>\n<p><b>Which attack technique attempts to use captured NTLM authentication material against another service without requiring the original password?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTLM relay<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Clickjacking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open redirect<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">NTLM relay involves forwarding captured NTLM authentication exchanges to another service that accepts NTLM authentication. The security concern is that an attacker may potentially authenticate to a service using relayed authentication material without knowing the user&#8217;s plaintext password. During authorized testing, organizations can assess whether protections such as SMB signing, appropriate authentication configurations, and network segmentation reduce this risk. Clickjacking, SQL injection, and open redirects involve different application-layer weaknesses and do not describe authentication relay behavior.<\/span><\/p>\n<h3><b>Question 394<\/b><\/h3>\n<p><b>A tester identifies an Active Directory service account associated with a service principal name and wants to assess whether its password is susceptible to offline cracking. Which technique is relevant?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Kerberoasting<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VLAN hopping<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS tunneling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Clickjacking<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Kerberoasting is an Active Directory attack technique involving service accounts associated with service principal names. Authentication-related material can be obtained in a form that may permit offline password-strength assessment. During an authorized penetration test, the objective is to determine whether service-account passwords are sufficiently strong and whether unnecessary service-account privileges increase risk. VLAN hopping concerns network segmentation, DNS tunneling concerns use of DNS communications for data transfer, and clickjacking targets web interfaces. Service accounts should use strong credentials and appropriate privilege restrictions.<\/span><\/p>\n<h3><b>Question 395<\/b><\/h3>\n<p><b>During an authorized wireless assessment, which technique can test whether clients properly respond to unexpected wireless management-frame activity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password spraying<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Wireless deauthentication testing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL injection<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Local file inclusion<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Wireless deauthentication testing can be used in an authorized assessment to evaluate how wireless clients and infrastructure respond to deauthentication-related management traffic. The purpose may include determining whether protections such as Protected Management Frames are properly implemented and whether clients reconnect securely. Because wireless testing can disrupt connectivity, it must be explicitly authorized and carefully controlled. Password spraying targets authentication systems, SQL injection targets database-driven applications, and local file inclusion concerns server-side file handling.<\/span><\/p>\n<h3><b>Question 396<\/b><\/h3>\n<p><b>A cloud-hosted virtual machine can access a metadata service that exposes sensitive temporary credentials because application access is not restricted. What should the tester investigate?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud metadata service exposure<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Email forwarding rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS zone expiration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Browser cache settings<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud metadata services can provide information about the workload environment and, depending on the platform and configuration, temporary credentials or other sensitive data. If applications can access metadata unnecessarily, a compromised workload may potentially obtain information beyond what it requires. During an authorized cloud assessment, testers should review metadata-service protections, workload identity permissions, and network access controls. Email forwarding, DNS expiration, and browser caching do not directly address this cloud-specific risk. Restricting unnecessary metadata access can reduce credential exposure.<\/span><\/p>\n<h3><b>Question 397<\/b><\/h3>\n<p><b>Which practice helps ensure that software packages used in a penetration-testing environment or client application originate from a trusted source?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Image or package provenance verification<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Disabling all logging<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Sharing administrator credentials<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Removing version information<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Package and image provenance verification helps establish that software originates from an expected and trusted source. This can involve signed packages, trusted repositories, verified container images, or other integrity mechanisms. During security assessments, supply-chain controls are relevant because malicious or tampered components can introduce vulnerabilities before software reaches production. Disabling logging, sharing administrator credentials, and removing version information do not establish software authenticity. Organizations should maintain trusted sources and verify integrity where practical, particularly for security-sensitive workloads.<\/span><\/p>\n<h3><b>Question 398<\/b><\/h3>\n<p><b>A container platform permits a workload to run with unnecessary administrative privileges. Which security concern should the tester prioritize?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Container escape risk<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS record expiration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Email spoofing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Browser history exposure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Excessive container privileges can increase the consequences of a compromised workload and may weaken isolation from the host environment. A container escape risk becomes particularly important when privileged configurations, excessive capabilities, or dangerous host access are present. During an authorized assessment, testers should review runtime privileges and isolation controls without performing disruptive actions outside the agreed scope. DNS expiration, email spoofing, and browser history exposure are separate security concerns. Strong container isolation and minimal runtime privileges reduce the potential impact of workload compromise.<\/span><\/p>\n<h3><b>Question 399<\/b><\/h3>\n<p><b>A penetration tester is given authorization to assess a partner-owned application. What additional documentation should the tester verify before testing the partner&#8217;s systems?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The tester&#8217;s preferred operating system<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Explicit authorization from the partner or system owner<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The application&#8217;s programming language<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">The office printer configuration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Testing a third-party or partner-owned system requires explicit authorization from the organization that owns or controls the relevant infrastructure. The tester should verify that the authorization clearly identifies the systems, testing activities, timing, and applicable restrictions. A client&#8217;s permission alone may not automatically authorize actions against infrastructure owned by another organization. Operating-system preferences, programming languages, and printer configurations do not establish legal or operational authorization. Confirming third-party approval protects both the tester and participating organizations from unauthorized activity.<\/span><\/p>\n<h3><b>Question 400<\/b><\/h3>\n<p><b>After completing an engagement, what is the most appropriate approach to sensitive evidence collected during the penetration test?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Keep every file indefinitely<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Publish interesting findings publicly<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Protect, retain, and securely dispose of evidence according to the engagement requirements<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Send all evidence to unrelated employees<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Penetration-testing evidence can contain credentials, personal information, configuration details, screenshots, logs, and other sensitive material. Testers should protect this evidence throughout the engagement and retain it only for the period and purposes authorized by the client or applicable requirements. When retention is no longer necessary, evidence should be securely disposed of according to the agreed procedures. Indefinite retention, public disclosure, or distribution to unrelated personnel increases confidentiality and privacy risks and is inconsistent with responsible evidence handling.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA PT0-003 Exam Dumps and Practice Test Dumps. &nbsp; Question 381 Before testing a production application that restricts access by source IP address, what should the penetration tester confirm? The application&#8217;s logo The authorized testing source IP The database table names The server&#8217;s screen resolution Correct Answer: 2 Explanation Source-IP restrictions can prevent [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17060"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17060"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17060\/revisions"}],"predecessor-version":[{"id":17061,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17060\/revisions\/17061"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17060"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17060"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17060"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}