
CompTIAPenTest+
Domain 4Objective 3
Host-Based Attacks PT0-003 Practice Questions (Page 1)
Part of the Attacks and exploits domain, which accounts for 35% of the PT0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~23–39 in this domain), expect 4–7 from this objective — we provide 29 practice questions to prepare you well beyond it. (estimate)
29questions here
6free pages
8concepts
35%of the exam
Questions 1–5
- 1
A penetration tester has gained local administrator access to a Windows server. The tester wants to extract password hashes from the Local Security Authority Subsystem Service (LSASS) process memory to perform pass-the-hash attacks. Which tool would be most appropriate for this task?
Select an answer first - 2
A penetration tester is performing process injection on a Windows host and wants to avoid detection by antivirus. The tester plans to use a technique that does not create a new thread in the target process. Which technique would be most appropriate?
Select an answer first - 3
A penetration tester is performing DLL injection on a Windows host and wants to avoid creating a new thread in the target process. Which technique would be most appropriate?
Select an answer first - 4
A penetration tester is assessing a Windows host and finds that the 'Secondary Logon' service is running. The tester wants to escalate privileges using a known vulnerability in this service. Which tool would be most appropriate to automate the exploitation?
Select an answer first - 5
Which process injection method involves creating a remote thread in a target process to execute malicious code?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “PT0-003” is a trademark of its owner, used for identification only.