Question 1
Q1A penetration tester wants to send a specific network packet with custom flags and sequence numbers to a vulnerable target. Which of the following should the tester use?
Show answer & explanation
Correct answer: C
Create a free account to browse all 20 sample questions. The full practice test includes 305 questions. Use the simulator for timed and flashcard mode. Or, view 138 more questions in the alternate version PT0-001 138 Questions.
A penetration tester wants to send a specific network packet with custom flags and sequence numbers to a vulnerable target. Which of the following should the tester use?
Correct answer: C
Which of the following explains the reason a tester would opt to use DREAD over PTES during the planning phase of a penetration test?
Correct answer: D
A penetration tester is performing a security review of a web application. Which of the following should the tester leverage to identify the presence of vulnerable open-source libraries?
Correct answer: C
A penetration tester finds that an application responds with the contents of the /etc/passwd file when the following payload is sent:Which of the following should the tester recommend in the report to best prevent this type of vulnerability?

Correct answer: C
A penetration tester is assessing a financial technology company's cloud-native application, which is built on a Kubernetes cluster hosted in AWS. The engagement's goal is to simulate a full-chain attack starting from an external vulnerability.
The tester first identifies a Server-Side Request Forgery (SSRF) vulnerability in a public-facing GraphQL endpoint running on a pod. This endpoint is used for generating PDF reports from user-supplied URLs. The pod is running in a default namespace on a worker node and does not have a specific IAM role attached.
After exploiting the SSRF, the tester successfully queries the EC2 Instance Metadata Service (IMDSv1). The credentials retrieved belong to the worker node's instance profile, which has limited permissions, primarily for EC2 and ECR access. However, the tester discovers that the Kubelet API (port 10250) on the worker node allows anonymous authentication.
Given this scenario, what is the MOST effective next step for the tester to escalate privileges from pod access to full control over the worker node?
Correct answer: C
The most effective escalation path is to abuse the anonymously accessible Kubelet API. The /run endpoint of this API can be used to execute commands within pods or even create new pods on the worker node. By sending a crafted POST request via the SSRF vulnerability to http:// :10250/run/ / / , the tester can execute commands. To achieve full node compromise, the tester can instruct the Kubelet to create a new, privileged pod with the host's root filesystem mounted (e.g., using hostPath). This allows the tester to escape the container sandbox and gain a root shell directly on the worker node. This technique is highly effective as it abuses a common Kubernetes misconfiguration (anonymous Kubelet auth) and doesn't rely on less reliable kernel exploits or limited IAM permissions.
A penetration tester is evaluating an AI-powered image recognition system used for physical access control at a secure data center. The system is designed to grant access only to authorized personnel. The tester's objective is to cause the model to misclassify a photo of an unauthorized individual as an authorized employee, thereby gaining entry. The tester has black-box access to the system's API but no knowledge of the model's architecture or training data. Which type of adversarial machine learning attack is the tester attempting to perform?
Correct answer: C
The tester is attempting an adversarial evasion attack. This type of attack involves creating a malicious input (an adversarial example) by making small, often imperceptible, perturbations to a legitimate input. The goal is to cause a deployed and trained machine learning model to misclassify it during the inference phase. In this scenario, the tester would modify the image of the unauthorized person in a specific way to trick the AI model into classifying it as an authorized employee. This is a black-box attack, as the tester interacts with the model's API to observe outputs and iteratively craft the malicious input without needing access to the model's internal workings. Data poisoning occurs during training, while model inversion and membership inference aim to extract information about the model or its data.
A DevOps team is building a CI/CD pipeline and wants to automate the process of identifying known vulnerabilities within the open-source libraries and third-party dependencies used in their containerized application. The goal is to fail the build if a dependency with a critical CVE is detected. Which of the following security testing methodologies should be integrated into the pipeline to achieve this specific goal?
Correct answer: C
Software Composition Analysis (SCA) is the specific methodology designed to identify and manage vulnerabilities in third-party and open-source components. SCA tools scan an application's dependencies (e.g., from package.json, requirements.txt, or container layers) and compare them against a database of known vulnerabilities (CVEs). This allows the CI/CD pipeline to automatically detect and flag insecure dependencies. SAST analyzes first-party source code for coding flaws, DAST tests the running application from the outside, and IAST works at runtime, but only SCA focuses specifically on the security of the software supply chain and third-party libraries.
A penetration tester is assessing a web application with a strict Content Security Policy (CSP). The tester finds a reflected XSS vulnerability but cannot execute inline scripts. The application's CSP header is as follows:
Content-Security-Policy: default-src 'self'; script-src 'self' https://trusted.cdn.com; object-src 'none'; style-src 'self' 'unsafe-inline';
Which TWO of the following techniques could be used to bypass this CSP and execute arbitrary JavaScript? (Select TWO).
Correct answers: B, E
Since script-src allows 'self', any script loaded from the application's own origin is trusted. A JSONP endpoint on the same domain that reflects user input in a callback function (e.g., /api/jsonp?callback=alert(1)) can be abused to execute arbitrary JavaScript. The injected payload would be , which is permitted by the CSP.
The CSP explicitly trusts scripts from https://trusted.cdn.com. If any JavaScript library hosted on this CDN has a vulnerability (such as an insecure callback, DOM-based XSS sink, or a gadget for prototype pollution), it can be used as a vector to execute arbitrary code. The attacker's payload would call the vulnerable function from the trusted library.
While conducting a scheduled penetration test against a client's external network, a consultant discovers evidence of an active, ongoing compromise by an unknown threat actor. The consultant identifies a live command-and-control (C2) beaconing out from a critical web server. According to the rules of engagement, all critical findings must be reported within 24 hours. What is the MOST appropriate immediate action for the consultant to take?
Correct answer: B
Discovering an active compromise by a real threat actor changes the engagement from a test to a live incident. The consultant's primary responsibility is to immediately stop all testing activities to avoid interfering with forensic evidence or alerting the attacker. The next step is to contact the client via the designated emergency escalation path, which should be defined in the rules of engagement. This allows the client to initiate their incident response plan immediately. Continuing the test or attempting containment could corrupt evidence and is outside the scope of a standard penetration test.
An automated vulnerability scan reports a high-severity 'Unquoted Service Path' vulnerability on a Windows Server. The finding indicates that the service 'CustomSvc' has the path C:\Program Files\Custom App\service.exe. Before confirming this as an exploitable vulnerability, what is the MOST critical next step for the penetration tester to perform for manual validation?
Correct answer: C
An unquoted service path vulnerability is only exploitable if the user has write permissions in one of the directories in the path. The service path C:\Program Files\Custom App\service.exe will cause Windows to look for C:\Program.exe, then C:\Program Files\Custom.exe, and finally the correct path. The MOST critical validation step is to check if the current user (or a low-privileged user) can write a malicious executable into C:\ or C:\Program Files\. The icacls command is used to check the Access Control Lists (ACLs) on these folders. If write permissions exist, the tester can place a malicious Custom.exe in C:\Program Files\ to achieve privilege escalation when the service restarts. Without write permissions, the vulnerability is not exploitable.
Register free to unlock 10 more sample questions
Create a free account to continue with the rest of the PT0-003 sample set.
Own this practice test forever.
Any 2 exams per month.
Any 4 exams per month.
Any 12 exams over 3 months.