Attacks and Exploits PT0-003 Practice Quiz
884 exam-style questions covering 35% of the PT0-003 exam. Instant feedback on every answer, progress tracking, no signup required.
This domain is part of the CompTIA PenTest+ practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.
Sample Questions
Which description best matches Attack preparation analysis in PenTest+ Objective 4.0 Attacks and Exploits?
- A. Attack preparation analysis interprets reconnaissance, scanning, and enumeration output to select targets, capabilities, constraints, and documentation before exploitation.
- B. Target prioritization ranks potential targets based on value, exposure, vulnerability, exploitability, scope, and testing goals.
- C. High-value asset identification determines which systems, data, accounts, or services would create the most impact if compromised.
- D. Exploit readiness decision confirms the target, scope, capability, dependencies, and evidence are ready before launching an attack.
Attack preparation analysis interprets reconnaissance, scanning, and enumeration output to select targets, capabilities, constraints, and documentation before exploitation. This is the correct answer.
Which option correctly defines Target prioritization?
- A. Common Weakness Enumeration classifies common software and hardware weakness types that can lead to vulnerabilities.
- B. Target prioritization ranks potential targets based on value, exposure, vulnerability, exploitability, scope, and testing goals.
- C. The Exploit Prediction Scoring System estimates the likelihood that a vulnerability will be exploited in the wild.
- D. End-of-life software or systems no longer receive normal vendor support or security updates, increasing exploitation risk.
Target prioritization ranks potential targets based on value, exposure, vulnerability, exploitability, scope, and testing goals. This is the correct answer.
A tester is prioritizing or preparing an attack with Attack preparation analysis in mind. Which choice best describes the concept?
- A. Defensive capabilities should be selected when the attack scenario matches this purpose: Defensive capabilities are security controls, monitoring, segmentation, filtering, or response mechanisms that affect exploit planning.
- B. Attack preparation analysis should be selected when the attack scenario matches this purpose: Attack preparation analysis interprets reconnaissance, scanning, and enumeration output to select targets, capabilities, constraints, and documentation before exploitation.
- C. Capability selection should be selected when the attack scenario matches this purpose: Capability selection chooses tools, exploits, payloads, techniques, and supporting material that fit the target and scope.
- D. Tool selection should be selected when the attack scenario matches this purpose: Tool selection chooses the software or utility that best fits the target, protocol, attack type, evidence needed, and authorization limits.
Attack preparation analysis interprets reconnaissance, scanning, and enumeration output to select targets, capabilities, constraints, and documentation before exploitation. This matches the attacks-and-exploits scenario without shifting to a related but different attack type, tool, target-preparation step, or automation method. This is the correct answer.
A tester is prioritizing or preparing an attack with Target prioritization in mind. Which choice best describes the concept?
- A. Low-level diagram creation should be selected when the attack scenario matches this purpose: Low-level diagram creation documents detailed technical relationships, paths, systems, flows, and dependencies used in attack planning.
- B. Storyboard should be selected when the attack scenario matches this purpose: A storyboard outlines the sequence of attack steps, evidence, screenshots, and narrative flow for planning or reporting.
- C. Target prioritization should be selected when the attack scenario matches this purpose: Target prioritization ranks potential targets based on value, exposure, vulnerability, exploitability, scope, and testing goals.
- D. Dependencies should be selected when the attack scenario matches this purpose: Dependencies are tools, credentials, access, conditions, libraries, services, or assumptions required for an attack to work.
Target prioritization ranks potential targets based on value, exposure, vulnerability, exploitability, scope, and testing goals. This matches the attacks-and-exploits scenario without shifting to a related but different attack type, tool, target-preparation step, or automation method. This is the correct answer.
A tester is prioritizing or preparing an attack with High-value asset identification in mind. Which choice best describes the concept?
- A. On-path attack should be selected when the attack scenario matches this purpose: An on-path attack intercepts, observes, or manipulates communication between parties that believe they are communicating directly.
- B. Certificate services attack should be selected when the attack scenario matches this purpose: A certificate services attack abuses certificate authority, enrollment, template, or trust misconfigurations to gain access or escalate privileges.
- C. Misconfigured services exploitation should be selected when the attack scenario matches this purpose: Misconfigured services exploitation abuses insecure service settings, permissions, exposure, or authentication weaknesses.
- D. High-value asset identification should be selected when the attack scenario matches this purpose: High-value asset identification determines which systems, data, accounts, or services would create the most impact if compromised.
High-value asset identification determines which systems, data, accounts, or services would create the most impact if compromised. This matches the attacks-and-exploits scenario without shifting to a related but different attack type, tool, target-preparation step, or automation method. This is the correct answer.
Attack planning must balance value, exploitability, scope, dependencies, and evidence. Which scenario best matches Attack preparation analysis?
- A. A scenario matches Default credentials when the tester needs this distinction: Default credentials attack systems where vendor or initial usernames and passwords were not changed.
- B. A scenario matches On-path attack when the tester needs this distinction: An on-path attack intercepts, observes, or manipulates communication between parties that believe they are communicating directly.
- C. A scenario matches Attack preparation analysis when the tester needs this distinction: Attack preparation analysis interprets reconnaissance, scanning, and enumeration output to select targets, capabilities, constraints, and documentation before exploitation.
- D. A scenario matches Certificate services attack when the tester needs this distinction: A certificate services attack abuses certificate authority, enrollment, template, or trust misconfigurations to gain access or escalate privileges.
Attack preparation analysis interprets reconnaissance, scanning, and enumeration output to select targets, capabilities, constraints, and documentation before exploitation. This distinction matters because choosing a nearby concept would change the target, exploit path, credential method, cloud or web technique, tool choice, or safety boundary. This is the correct answer.
Attack planning must balance value, exploitability, scope, dependencies, and evidence. Which scenario best matches Target prioritization?
- A. A scenario matches Network share enumeration when the tester needs this distinction: Network share enumeration identifies accessible shares, permissions, files, and exposed resources across networked systems.
- B. A scenario matches Packet crafting when the tester needs this distinction: Packet crafting creates custom packets to test protocols, evade controls, exploit behavior, or validate network assumptions.
- C. A scenario matches Metasploit when the tester needs this distinction: Metasploit is an exploitation framework used to select, configure, launch, and manage exploits and payloads.
- D. A scenario matches Target prioritization when the tester needs this distinction: Target prioritization ranks potential targets based on value, exposure, vulnerability, exploitability, scope, and testing goals.
Target prioritization ranks potential targets based on value, exposure, vulnerability, exploitability, scope, and testing goals. This distinction matters because choosing a nearby concept would change the target, exploit path, credential method, cloud or web technique, tool choice, or safety boundary. This is the correct answer.
A lead tester must prepare the attack path without violating scope or choosing unsupported capabilities. Which answer applies Attack preparation analysis most accurately?
- A. Impacket is the best answer when the exploit or attack decision depends on this exact meaning: Impacket is a collection of Python tools and libraries for working with network protocols, especially Windows and Active Directory protocols.
- B. CrackMapExec is the best answer when the exploit or attack decision depends on this exact meaning: CrackMapExec is a post-exploitation and network assessment tool often used to assess SMB, credentials, and Active Directory exposure.
- C. Wireshark/tcpdump attack usage is the best answer when the exploit or attack decision depends on this exact meaning: Wireshark and tcpdump capture and analyze packets to support attack preparation, validation, and troubleshooting.
- D. Attack preparation analysis is the best answer when the exploit or attack decision depends on this exact meaning: Attack preparation analysis interprets reconnaissance, scanning, and enumeration output to select targets, capabilities, constraints, and documentation before exploitation.
Attack preparation analysis interprets reconnaissance, scanning, and enumeration output to select targets, capabilities, constraints, and documentation before exploitation. This applies the concept at the decision point where the wrong term would create an ineffective attack path, unsafe execution, out-of-scope activity, or unsupported evidence. This is the correct answer.
Link to this quiz
Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:
https://quizbuffet.com/comptia-pentest-plus/attacks-and-exploits/
<a href="https://quizbuffet.com/comptia-pentest-plus/attacks-and-exploits/">CompTIA PenTest+ Attacks and Exploits practice quiz on QuizBuffet</a>
Other PT0-003 Domains
- Engagement Management
- Reconnaissance and Enumeration
- Vulnerability Discovery and Analysis
- Post-exploitation and Lateral Movement
← Back to PT0-003 practice test overview
Questions are written against the published PT0-003 objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.