
CompTIAPenTest+
Domain 4Objective 2
Authentication Attacks PT0-003 Practice Questions (Page 2)
Part of the Attacks and exploits domain, which accounts for 35% of the PT0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~23–39 in this domain), expect 4–7 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
9concepts
35%of the exam
Questions 6–10
- 6
What is the primary process of a credential stuffing attack?
Select an answer first - 7
A penetration tester has captured NTLM hashes from a Windows domain and wants to use them to authenticate to a remote machine using SMB. Which tool is specifically designed to perform pass-the-hash attacks over SMB?
Select an answer first - 8
Which control is most effective at preventing brute-force attacks on a web application login form?
Select an answer first - 9
A penetration tester is assessing a web application that uses a JSON-based login endpoint. The tester has confirmed that the application does not implement account lockout, but it does throttle requests from a single IP address after 20 failed attempts. The tester needs to attempt passwords for a single known username without triggering the IP-based throttle. Which approach should the tester use?
Select an answer first - 10
Which tool is commonly used to perform brute-force attacks against network services such as SSH and FTP?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “PT0-003” is a trademark of its owner, used for identification only.