
CompTIAPenTest+
Domain 4Objective 2
Authentication Attacks PT0-003 Practice Questions (Page 3)
Part of the Attacks and exploits domain, which accounts for 35% of the PT0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~23–39 in this domain), expect 4–7 from this objective — we provide 26 practice questions to prepare you well beyond it. (estimate)
26questions here
6free pages
9concepts
35%of the exam
Questions 11–15
- 11
A company has experienced a credential stuffing attack where attackers used breached credentials to access user accounts. The security team wants to implement a control that will prevent attackers from using stolen credentials even if they have them. Which control is most effective?
Select an answer first - 12
Which tool is specifically known for automating credential stuffing attacks?
Select an answer first - 13
A company's web application has been experiencing brute-force attacks against its admin login page. The security team wants to implement a control that blocks an attacker after a set number of failed attempts but also allows legitimate users who mistype their password to retry without being locked out permanently. Which control best meets this requirement?
Select an answer first - 14
Which condition is necessary for a pass-the-hash attack to succeed?
Select an answer first - 15
A penetration tester needs to automate a credential stuffing attack against a web application that uses a standard login form. The tester has a list of 5,000 username/password pairs and needs to test them efficiently. Which tool is best suited for this task?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “PT0-003” is a trademark of its owner, used for identification only.