CompTIA PenTest+ PT1-002 Dumps in PDF

Free CompTIA PT1-002 Real Questions (page: 20)

A security professional wants to test an IoT device by sending an invalid packet to a proprietary service listening on TCP port 3011.
Which of the following would allow the security professional to easily and programmatically manipulate the TCP header length and checksum using arbitrary numbers and to observe how the proprietary service responds?

  1. Nmap
  2. tcpdump
  3. Scapy
  4. hping3

Answer(s): A


Reference:

https://www.mn.uio.no/i /english/research/groups/psy/completedmasters/2017/Kim_Jonatan_Wessel_Bjorneset/ kim_jonatan_wessel_bjorneset_testing_security_for_internet_of_things_a_survey_on_vulnerabilities_in_ip_cameras.pdf (24)



A penetration tester is reviewing the following SOW prior to engaging with a client:
`Network diagrams, logical and physical asset inventory, and employees' names are to be treated as client con dential. Upon completion of the engagement, the penetration tester will submit ndings to the client's Chief Information Security O cer (CISO) via encrypted protocols and subsequently dispose of all ndings by erasing them in a secure manner.`
Based on the information in the SOW, which of the following behaviors would be considered unethical? (Choose two.)

  1. Utilizing proprietary penetration-testing tools that are not available to the public or to the client for auditing and inspection
  2. Utilizing public-key cryptography to ensure ndings are delivered to the CISO upon completion of the engagement
  3. Failing to share with the client critical vulnerabilities that exist within the client architecture to appease the client's senior leadership team
  4. Seeking help with the engagement in underground hacker forums by sharing the client's public IP address
  5. Using a software-based erase tool to wipe the client's ndings from the penetration tester's laptop
  6. Retaining the SOW within the penetration tester's company for future use so the sales team can plan future engagements

Answer(s): C,E



A company recruited a penetration tester to con gure wireless IDS over the network.
Which of the following tools would BEST test the effectiveness of the wireless
IDS solutions?

  1. Aircrack-ng
  2. Wireshark
  3. Wi te
  4. Kismet

Answer(s): A


Reference:

https://purplesec.us/perform-wireless-penetration-test/



A penetration tester gains access to a system and establishes persistence, and then runs the following commands: cat /dev/null > temp touch `"r .bash_history temp mv temp .bash_history
Which of the following actions is the tester MOST likely performing?

  1. Redirecting Bash history to /dev/null
  2. Making a copy of the user's Bash history for further enumeration
  3. Covering tracks by clearing the Bash history
  4. Making decoy les on the system to confuse incident responders

Answer(s): C


Reference:

https://null-byte.wonderhowto.com/how-to/clear-logs-bash-history-hacked-linux-systems-cover-your-tracks-remain-undetected-0244768/



Which of the following web-application security risks are part of the OWASP Top 10 v2017? (Choose two.)

  1. Buffer over ows
  2. Cross-site scripting
  3. Race-condition attacks
  4. Zero-day attacks
  5. Injection aws
  6. Ransomware attacks

Answer(s): A,B


Reference:

https://owasp.org/www-pdf-archive/OWASP_Top_10_2017_RC2_Final.pdf



Share your comments for CompTIA PT1-002 exam with other users:

A
akminocha
9/28/2023 10:36:00 AM

please help us with 1z0-1107-2 dumps

J
Jefi
9/4/2023 8:15:00 AM

please upload the practice questions

T
Thembelani
5/30/2023 2:45:00 AM

need this dumps

A
Abduraimov
4/19/2023 12:43:00 AM

preparing for this exam is overwhelming. you cannot pass without the help of these exam dumps.

P
Puneeth
10/5/2023 2:06:00 AM

new to this site but i feel it is good

A
Ashok Kumar
1/2/2024 6:53:00 AM

the correct answer to q8 is b. explanation since the mule app has a dependency, it is necessary to include project modules and dependencies to make sure the app will run successfully on the runtime on any other machine. source code of the component that the mule app is dependent of does not need to be included in the exported jar file, because the source code is not being used while executing an app. compiled code is being used instead.

M
Merry
7/30/2023 6:57:00 AM

good questions

V
VoiceofMidnight
12/17/2023 4:07:00 PM

Delayed the exam until December 29th.

U
Umar Ali
8/29/2023 2:59:00 PM

A and D are True

V
vel
8/28/2023 9:17:09 AM

good one with explanation

G
Gurdeep
1/18/2024 4:00:15 PM

This is one of the most useful study guides I have ever used.

AI Tutor 👋 I’m here to help!