
CompTIAPenTest+
Domain 3Objective 2
Result Analysis PT0-003 Practice Questions (Page 1)
Part of the Vulnerability discovery and analysis domain, which accounts for 17% of the PT0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~11–19 in this domain), expect 4–6 from this objective — we provide 12 practice questions to prepare you well beyond it. (estimate)
12questions here
3free pages
3concepts
17%of the exam
Questions 1–5
- 1
A penetration tester is scanning a network and notices that the scanner is not detecting any open ports on a host that is known to be running a web server. The tester pings the host and receives a response. What is the most likely cause of the scan issue?
Select an answer first - 2
A penetration tester receives a vulnerability scan report listing a critical SQL injection in a web application. Which technique is most appropriate to validate this finding without causing damage?
Select an answer first - 3
A penetration tester is performing an internal assessment. The scanner reports that a critical web server is vulnerable to a remote code execution (RCE) flaw. The tester manually verifies the finding by sending a proof-of-concept payload and successfully executes a command. However, the client's security team insists the server was patched last week. The tester checks the patch level and confirms the patch is installed. What is the most likely explanation?
Select an answer first - 4
During an external penetration test, the tester runs a port scan against a target and finds port 443 open. The tester then runs an SSL/TLS scan and the tool reports that the server supports SSLv3. The tester manually connects with OpenSSL and successfully negotiates SSLv3. However, the client's change management team states that SSLv3 was disabled last month. What is the most likely explanation for this discrepancy?
Select an answer first - 5
A vulnerability scanner reports that a web server is vulnerable to a specific denial-of-service (DoS) vulnerability. Manual testing shows that the server does not crash or become unresponsive when the exploit is attempted. How should this finding be classified?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “PT0-003” is a trademark of its owner, used for identification only.