
CompTIAPenTest+
Domain 3Objective 2
Result Analysis PT0-003 Practice Questions (Page 3)
Part of the Vulnerability discovery and analysis domain, which accounts for 17% of the PT0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~11–19 in this domain), expect 4–6 from this objective — we provide 12 practice questions to prepare you well beyond it. (estimate)
12questions here
3free pages
3concepts
17%of the exam
Questions 11–12
- 11
A tester is performing a scan of a web application and the scanner reports that the application is vulnerable to XML external entity (XXE) injection. The tester manually sends a payload with an external entity and the application returns the contents of a local file. However, the client states that the application is behind a web application firewall (WAF) that should block XXE attacks. What is the most likely explanation?
Select an answer first - 12
A tester is conducting a scan of a network and notices that the scanner is reporting a host as 'up' but is not detecting any open ports. The tester manually connects to the host on port 22 (SSH) and the connection is successful. What is the most likely cause of the scan issue?
Select an answer first
Finished these 2 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to PT0-003
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “PT0-003” is a trademark of its owner, used for identification only.