TEST BANK
COMPTIA
PenTest+ PT0-
FOR MORE AFFORDABLE FILES CHECK OUT: WWW.MEDTESTBANKS.COM
001
M
EMAIL US ON MEDTESTBANKS@GMAIL.COM
EDITION: 1st Edition
ED
AUTHORS: Omar Santos, Ron Taylor
CO
NN
OI
◊ PDF DOWNLOAD
SS
◊ ORIGINAL FROM PUBLISHER
EU
◊ALL CHAPTERS; COMPLETE GUIDE
R
◊ IMMEDIATE DOWNLOD AFTER ORDER
WWW.MEDTESTBANK.COM
,CompTIA® PenTest+ Cert Guide
Chapter 1 Introduction to Ethical Hacking and Penetration Testing
1) Which of these describes a scenario in which the tester starts with credentials but not full
documentation of the network infrastructure?
A) Black-box test
B) White-box test
C) Gray-box test
D) Blue-box test
Answer: C
2) Which of the following would an ethical hacker not participate in?
A) Unauthorized access
M
B) Responsible disclosure
C) Documentation
D) Black-box testing
ED
Answer: A
3) Which of these attack types involves tricking the user into disclosing information or taking
CO
action?
A) DDoS
B) Ransomware
NN
C) Social engineering
D) Botnet
Answer: C
OI
4) What type of attacker is most likely to be motivated purely by financial profit?
A) Hacktivist
B) Nation-state
SS
C) Insider threat
D) Organized crime
EU
Answer: D
5) What type of attack encrypts user files until the victim pays a fee?
A) Ransomware
R
B) Denial of Service attack
C) Hacktivism
D) Shoulder surfing
Answer: A
6) IoT devices are most susceptible to being used for what type of attack?
A) Ransomware
B) DDoS
C) Man-in-the-Middle
D) Social engineering
Answer: B
,7) What type of attacker steals sensitive data and then reveals it to the public in order to
embarrass the target?
A) Kidnapper
B) Nation state
C) Organized crime
D) Hacktivist
Answer: D
8) What type of tests would be most important to conduct to find out whether hackers could use
the Internet to compromise your client’s online ordering system?
A) Web application tests
B) Network infrastructure tests
C) Wireless network tests
M
D) Physical facility tests
Answer: A
ED
9) What type of tests would be most important to conduct to find out whether the client’s WAPs
are properly secured?
A) Web application tests
CO
B) Network infrastructure tests
C) Wireless network tests
D) Physical facility tests
NN
Answer: C
10) What type of tests would be most important to conduct to find out whether unauthorized
people can reach the company’s server rooms?
OI
A) Web application tests
B) Network infrastructure tests
C) Wireless network tests
SS
D) Physical facility tests
Answer: D
EU
11) What type of tests would be most important to conduct to find out whether there are any
poorly secured firewalls, routers, and switches on a LAN?
A) Web application tests
R
B) Network infrastructure tests
C) Wireless network tests
D) Physical facility tests
Answer: B
, 13) Which testing methodology has key sections including Operational Security Metrics, Trust
Analysis, Work Flow, and Human Security Testing?
A) PTES
B) PCI DSS
C) Penetration Testing Framework
D) OSSTMM
Answer: D
14) Which testing methodology pertains to the specific needs of credit card processing systems?
A) PTES
B) PCI DSS
C) Penetration Testing Framework
D) OSSTMM
M
Answer: B
15) Which testing methodology focuses on the hands-on aspects of penetration testing and
ED
provides links to many tools in an HTML format?
A) PTES
B) PCI DSS
CO
C) Penetration Testing Framework
D) OSSTMM
Answer: C
NN
16) What document created by the National Institute of Standards and Technology provides
organizations with guidelines on planning and conducting information security testing?
A) Special Publication (SP) 800-115
OI
B) General Publication (GP) 2006-110
C) Special Publication (SP) 2018-01
D) International Publication (IP) 2016-330
SS
Answer: A
EU
17) Which of these is not a requirement for a typical penetration testing environment?
A) Closed network
B) Virtualized computing environment
C) Sign-in credentials for the systems to be tested
R
D) Practice targets
Answer: C
18) Which of these can help protect the client in the event that you break something during a
test?
A) Social engineering
B) WPA
C) Open network
D) Virtual environment
Answer: D
Voordelen van het kopen van samenvattingen bij Stuvia op een rij:
√ Verzekerd van kwaliteit door reviews
Stuvia-klanten hebben meer dan 700.000 samenvattingen beoordeeld. Zo weet je zeker dat je de beste documenten koopt!
Snel en makkelijk kopen
Je betaalt supersnel en eenmalig met iDeal, Bancontact of creditcard voor de samenvatting. Zonder lidmaatschap.
Focus op de essentie
Samenvattingen worden geschreven voor en door anderen. Daarom zijn de samenvattingen altijd betrouwbaar en actueel. Zo kom je snel tot de kern!
Veelgestelde vragen
Wat krijg ik als ik dit document koop?
Je krijgt een PDF, die direct beschikbaar is na je aankoop. Het gekochte document is altijd, overal en oneindig toegankelijk via je profiel.
Tevredenheidsgarantie: hoe werkt dat?
Onze tevredenheidsgarantie zorgt ervoor dat je altijd een studiedocument vindt dat goed bij je past. Je vult een formulier in en onze klantenservice regelt de rest.
Van wie koop ik deze samenvatting?
Stuvia is een marktplaats, je koop dit document dus niet van ons, maar van verkoper MedConnoisseur. Stuvia faciliteert de betaling aan de verkoper.
Zit ik meteen vast aan een abonnement?
Nee, je koopt alleen deze samenvatting voor €19,49. Je zit daarna nergens aan vast.