Vulnerability Discovery and Analysis PT0-003 Practice Quiz

196 exam-style questions covering 17% of the PT0-003 exam. Instant feedback on every answer, progress tracking, no signup required.

This domain is part of the CompTIA PenTest+ practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.

Sample Questions

Which description best matches Container scans in PenTest+ Objective 3.0 Vulnerability Discovery and Analysis?
  • A. Container scans assess container images, runtimes, configurations, and dependencies for vulnerabilities and insecure settings.
  • B. Sidecar scans use a sidecar component or companion process to observe or assess containerized workloads without changing the main application container.
  • C. Scan-type selection matches the assessment technique to the target technology, credential availability, safety constraints, and evidence needed.
  • D. Application scans assess applications for security weaknesses in code, runtime behavior, dependencies, configuration, and input handling.

Container scans assess container images, runtimes, configurations, and dependencies for vulnerabilities and insecure settings. This is the correct answer.

Which option correctly defines Sidecar scans?
  • A. Infrastructure as Code scanning reviews infrastructure definitions for insecure configurations before deployment.
  • B. Sidecar scans use a sidecar component or companion process to observe or assess containerized workloads without changing the main application container.
  • C. Source code analysis reviews application code to identify flaws, insecure patterns, and implementation weaknesses.
  • D. A mobile scan assesses mobile applications or mobile environments for insecure storage, communication, permissions, and platform-specific weaknesses.

Sidecar scans use a sidecar component or companion process to observe or assess containerized workloads without changing the main application container. This is the correct answer.

A tester is choosing a vulnerability discovery technique involving Container scans. Which choice best describes it?
  • A. Host-based scans should be selected when the vulnerability discovery or analysis scenario matches this purpose: Host-based scans assess vulnerabilities, patch state, configuration, and software from the perspective of a specific host.
  • B. Container scans should be selected when the vulnerability discovery or analysis scenario matches this purpose: Container scans assess container images, runtimes, configurations, and dependencies for vulnerabilities and insecure settings.
  • C. Authenticated scans should be selected when the vulnerability discovery or analysis scenario matches this purpose: Authenticated scans use valid credentials to inspect systems more deeply for patches, configuration, and local vulnerabilities.
  • D. Unauthenticated scans should be selected when the vulnerability discovery or analysis scenario matches this purpose: Unauthenticated scans assess targets without credentials and are limited to externally visible information and service responses.

Container scans assess container images, runtimes, configurations, and dependencies for vulnerabilities and insecure settings. This matches the vulnerability discovery or analysis scenario without shifting to a related but different scan, tool, validation, or physical security concept. This is the correct answer.

A tester is choosing a vulnerability discovery technique involving Sidecar scans. Which choice best describes it?
  • A. Signal strength scanning should be selected when the vulnerability discovery or analysis scenario matches this purpose: Signal strength scanning measures wireless signal power to understand range, coverage, proximity, or possible rogue access point location.
  • B. ICS vulnerability assessment should be selected when the vulnerability discovery or analysis scenario matches this purpose: Industrial control systems vulnerability assessment evaluates OT and control-system environments with extra care for safety and operational stability.
  • C. Sidecar scans should be selected when the vulnerability discovery or analysis scenario matches this purpose: Sidecar scans use a sidecar component or companion process to observe or assess containerized workloads without changing the main application container.
  • D. Manual ICS assessment should be selected when the vulnerability discovery or analysis scenario matches this purpose: Manual ICS assessment uses carefully controlled review and testing methods to avoid disrupting fragile industrial control systems.

Sidecar scans use a sidecar component or companion process to observe or assess containerized workloads without changing the main application container. This matches the vulnerability discovery or analysis scenario without shifting to a related but different scan, tool, validation, or physical security concept. This is the correct answer.

A tester is choosing a vulnerability discovery technique involving Application scans. Which choice best describes it?
  • A. Tenable Nessus should be selected when the vulnerability discovery or analysis scenario matches this purpose: Tenable Nessus is a vulnerability scanner used to identify vulnerabilities, missing patches, and configuration issues.
  • B. PowerSploit should be selected when the vulnerability discovery or analysis scenario matches this purpose: PowerSploit is a PowerShell-based post-exploitation and security assessment framework often used to identify Windows attack paths.
  • C. Grype should be selected when the vulnerability discovery or analysis scenario matches this purpose: Grype scans container images and filesystems for known vulnerabilities in packages and dependencies.
  • D. Application scans should be selected when the vulnerability discovery or analysis scenario matches this purpose: Application scans assess applications for security weaknesses in code, runtime behavior, dependencies, configuration, and input handling.

Application scans assess applications for security weaknesses in code, runtime behavior, dependencies, configuration, and input handling. This matches the vulnerability discovery or analysis scenario without shifting to a related but different scan, tool, validation, or physical security concept. This is the correct answer.

An assessment must use the right scan type without disrupting the target or collecting the wrong evidence. Which scenario best matches Container scans?
  • A. A scenario matches TruffleHog when the tester needs this distinction: TruffleHog scans repositories and files for exposed secrets such as keys, tokens, and credentials.
  • B. A scenario matches BloodHound when the tester needs this distinction: BloodHound maps Active Directory relationships and attack paths to identify privilege escalation and lateral movement opportunities.
  • C. A scenario matches Container scans when the tester needs this distinction: Container scans assess container images, runtimes, configurations, and dependencies for vulnerabilities and insecure settings.
  • D. A scenario matches Tenable Nessus when the tester needs this distinction: Tenable Nessus is a vulnerability scanner used to identify vulnerabilities, missing patches, and configuration issues.

Container scans assess container images, runtimes, configurations, and dependencies for vulnerabilities and insecure settings. This distinction matters because choosing a nearby concept would change the scan type, evidence source, validation result, tool selection, or physical testing approach. This is the correct answer.

An assessment must use the right scan type without disrupting the target or collecting the wrong evidence. Which scenario best matches Sidecar scans?
  • A. A scenario matches Validate scan results when the tester needs this distinction: Validating scan results confirms that reconnaissance, scanning, and enumeration findings are accurate and useful before they drive attack planning or reporting.
  • B. A scenario matches False positives when the tester needs this distinction: False positives are findings reported as vulnerabilities or exposures that are not actually present or exploitable as stated.
  • C. A scenario matches False negatives when the tester needs this distinction: False negatives are real vulnerabilities or exposures that a scan or process failed to detect.
  • D. A scenario matches Sidecar scans when the tester needs this distinction: Sidecar scans use a sidecar component or companion process to observe or assess containerized workloads without changing the main application container.

Sidecar scans use a sidecar component or companion process to observe or assess containerized workloads without changing the main application container. This distinction matters because choosing a nearby concept would change the scan type, evidence source, validation result, tool selection, or physical testing approach. This is the correct answer.

A senior tester must select the safest discovery method that still proves the weakness. Which answer applies Container scans most accurately?
  • A. Public exploit selection is the best answer when the discovery, validation, or physical testing decision depends on this exact meaning: Public exploit selection chooses an appropriate known exploit or proof of concept for validating or demonstrating a vulnerability within scope.
  • B. Scripting to validate results is the best answer when the discovery, validation, or physical testing decision depends on this exact meaning: Scripting to validate results uses custom or modified scripts to confirm findings, reproduce evidence, or reduce false assumptions.
  • C. Tailgating is the best answer when the discovery, validation, or physical testing decision depends on this exact meaning: Tailgating occurs when an unauthorized person follows an authorized person into a restricted area without proper authentication.
  • D. Container scans is the best answer when the discovery, validation, or physical testing decision depends on this exact meaning: Container scans assess container images, runtimes, configurations, and dependencies for vulnerabilities and insecure settings.

Container scans assess container images, runtimes, configurations, and dependencies for vulnerabilities and insecure settings. This applies the concept at the decision point where the wrong term would create incomplete discovery, unsafe testing, unsupported exploit selection, or inaccurate reporting. This is the correct answer.

Link to this quiz

Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:

https://quizbuffet.com/comptia-pentest-plus/vulnerability-discovery-and-analysis/

<a href="https://quizbuffet.com/comptia-pentest-plus/vulnerability-discovery-and-analysis/">CompTIA PenTest+ Vulnerability Discovery and Analysis practice quiz on QuizBuffet</a>

Other PT0-003 Domains

← Back to PT0-003 practice test overview

Questions are written against the published PT0-003 objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.