PT0-003 Sample Questions

PT0-003 Sample Questions & Answers

Prioritizing and performing network or authentication attacks carries the most weight, alongside analyzing vulnerability discoveries, reconnaissance and enumeration techniques, testing frameworks used during pre-engagement planning, and lateral movement.

Launch the full PT0-003 simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Attacks and Exploits · AI System Attacks

    A penetration tester is evaluating an AI-powered image recognition system used for physical access control at a secure data center. The system is designed to grant access only to authorized personnel. The tester's objective is to cause the model to misclassify a photo of an unauthorized individual as an authorized employee, thereby gaining entry. The tester has black-box access to the system's API but no knowledge of the model's architecture or training data. Which type of adversarial machine learning attack is the tester attempting to perform?

    Show answer & explanation

    Correct answer: C

    The tester is attempting an adversarial evasion attack. This type of attack involves creating a malicious input (an adversarial example) by making small, often imperceptible, perturbations to a legitimate input. The goal is to cause a deployed and trained machine learning model to misclassify it during the inference phase. In this scenario, the tester would modify the image of the unauthorized person in a specific way to trick the AI model into classifying it as an authorized employee. This is a black-box attack, as the tester interacts with the model's API to observe outputs and iteratively craft the malicious input without needing access to the model's internal workings. Data poisoning occurs during training, while model inversion and membership inference aim to extract information about the model or its data.

  2. Question 2Intermediate

    Vulnerability Discovery and Analysis · Software Composition Analysis

    A DevOps team is building a CI/CD pipeline and wants to automate the process of identifying known vulnerabilities within the open-source libraries and third-party dependencies used in their containerized application. The goal is to fail the build if a dependency with a critical CVE is detected. Which of the following security testing methodologies should be integrated into the pipeline to achieve this specific goal?

    Show answer & explanation

    Correct answer: C

    Software Composition Analysis (SCA) is the specific methodology designed to identify and manage vulnerabilities in third-party and open-source components. SCA tools scan an application's dependencies (e.g., from package.json, requirements.txt, or container layers) and compare them against a database of known vulnerabilities (CVEs). This allows the CI/CD pipeline to automatically detect and flag insecure dependencies. SAST analyzes first-party source code for coding flaws, DAST tests the running application from the outside, and IAST works at runtime, but only SCA focuses specifically on the security of the software supply chain and third-party libraries.

  3. Question 3AdvancedSelect 2

    Attacks and Exploits · Web Application Attacks

    A penetration tester is assessing a web application with a strict Content Security Policy (CSP). The tester finds a reflected XSS vulnerability but cannot execute inline scripts. The application's CSP header is as follows:

    Content-Security-Policy: default-src 'self'; script-src 'self' https://trusted.cdn.com; object-src 'none'; style-src 'self' 'unsafe-inline';

    Which TWO of the following techniques could be used to bypass this CSP and execute arbitrary JavaScript? (Select TWO).

    Show answer & explanation

    Correct answers: B, E

    Since script-src allows 'self', any script loaded from the application's own origin is trusted. A JSONP endpoint on the same domain that reflects user input in a callback function (e.g., /api/jsonp?callback=alert(1)) can be abused to execute arbitrary JavaScript. The injected payload would be , which is permitted by the CSP.

    The CSP explicitly trusts scripts from https://trusted.cdn.com. If any JavaScript library hosted on this CDN has a vulnerability (such as an insecure callback, DOM-based XSS sink, or a gadget for prototype pollution), it can be used as a vector to execute arbitrary code. The attacker's payload would call the vulnerable function from the trusted library.

  4. Question 4Beginner

    Engagement Management · Communication and Reporting

    While conducting a scheduled penetration test against a client's external network, a consultant discovers evidence of an active, ongoing compromise by an unknown threat actor. The consultant identifies a live command-and-control (C2) beaconing out from a critical web server. According to the rules of engagement, all critical findings must be reported within 24 hours. What is the MOST appropriate immediate action for the consultant to take?

    Show answer & explanation

    Correct answer: B

    Discovering an active compromise by a real threat actor changes the engagement from a test to a live incident. The consultant's primary responsibility is to immediately stop all testing activities to avoid interfering with forensic evidence or alerting the attacker. The next step is to contact the client via the designated emergency escalation path, which should be defined in the rules of engagement. This allows the client to initiate their incident response plan immediately. Continuing the test or attempting containment could corrupt evidence and is outside the scope of a standard penetration test.

  5. Question 5Intermediate

    Vulnerability Discovery and Analysis · Result Analysis and Validation

    An automated vulnerability scan reports a high-severity 'Unquoted Service Path' vulnerability on a Windows Server. The finding indicates that the service 'CustomSvc' has the path C:\Program Files\Custom App\service.exe. Before confirming this as an exploitable vulnerability, what is the MOST critical next step for the penetration tester to perform for manual validation?

    Show answer & explanation

    Correct answer: C

    An unquoted service path vulnerability is only exploitable if the user has write permissions in one of the directories in the path. The service path C:\Program Files\Custom App\service.exe will cause Windows to look for C:\Program.exe, then C:\Program Files\Custom.exe, and finally the correct path. The MOST critical validation step is to check if the current user (or a low-privileged user) can write a malicious executable into C:\ or C:\Program Files\. The icacls command is used to check the Access Control Lists (ACLs) on these folders. If write permissions exist, the tester can place a malicious Custom.exe in C:\Program Files\ to achieve privilege escalation when the service restarts. Without write permissions, the vulnerability is not exploitable.

  6. Question 6Intermediate

    Attacks and Exploits · Authentication Attacks

    A penetration tester has gained a foothold as a standard, non-privileged user in a Windows Active Directory environment. Their goal is to escalate privileges by targeting service accounts. The tester uses Rubeus to perform a Kerberoasting attack. What is the primary objective of this attack?

    Show answer & explanation

    Correct answer: B

    Kerberoasting is an attack that targets service accounts in Active Directory. Any authenticated user can request a Kerberos service ticket (TGS) for any service by its Service Principal Name (SPN). The TGS is encrypted with the service account's NTLM password hash. The primary objective of a Kerberoasting attack is to request these tickets and extract the encrypted portion. The tester can then take these hashes offline and attempt to crack them using tools like Hashcat. Since service accounts often have weak, non-expiring passwords, cracking them is often feasible and can lead to significant privilege escalation.

  7. Question 7Advanced

    Attacks and Exploits · Cloud and Container Attacks

    A penetration tester is tasked with simulating a software supply chain attack. The target organization heavily relies on public package repositories like npm and PyPI for their development lifecycle. The tester has identified a popular open-source library that the organization uses, named common-utils. Which of the following techniques BEST simulates a supply chain attack in this context?

    Show answer & explanation

    Correct answer: C

    This technique, known as typosquatting or brandjacking, is a classic software supply chain attack. By publishing a malicious package with a name that is a common misspelling of a legitimate package (common-util instead of common-utils), an attacker can trick developers or automated build systems into downloading and executing malicious code. This code could steal credentials, create backdoors, or compromise the entire CI/CD pipeline. This method directly targets the trust developers place in package repositories and represents a direct attack on the software supply chain. Other supply chain attacks include compromising a legitimate package (dependency confusion) or attacking the build tools themselves.

  8. Question 8Beginner

    Vulnerability Discovery and Analysis · Physical security concepts

    During a physical security assessment, a penetration tester needs to clone a low-frequency (125kHz) HID proximity card to gain unauthorized access to a building. Which tool is specifically designed for reading, emulating, and cloning such RFID cards?

    Show answer & explanation

    Correct answer: C

    The Proxmark3 is the industry-standard tool for RFID research and penetration testing. It is specifically designed to interact with both low-frequency (125kHz) and high-frequency (13.56MHz) RFID systems. It can read the data from an original HID Prox card, save it, and then write that data to a blank, cloneable card (like a T5577 card), creating a functional copy. The WiFi Pineapple is for wireless network attacks, the USB Rubber Ducky is a keystroke injection tool, and the HackRF One is a general-purpose Software Defined Radio (SDR).

  9. Question 9Intermediate

    Engagement Management · Compare and contrast testing frameworks and methodologies

    A development team is conducting a threat modeling exercise for a new API gateway. They are focused on identifying threats related to Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. Which of the following threat modeling frameworks directly aligns with this categorization of threats?

    Show answer & explanation

    Correct answer: C

    STRIDE is a threat modeling framework developed by Microsoft that provides a mnemonic for categorizing threats. The acronym stands for Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. It is designed to help developers and security professionals systematically identify and mitigate potential security threats during the design phase of a project. DREAD is for risk rating, OCTAVE is a risk-based assessment methodology, and PTES is a penetration testing execution standard.

  10. Question 10Intermediate

    Engagement Management · Given a scenario, summarize pre-engagement activities.

    A penetration tester is scoping an engagement for a client's serverless application hosted on AWS. The application consists of multiple Lambda functions triggered by API Gateway, S3 events, and DynamoDB Streams. The client is concerned about potential business logic flaws and data exposure. Which of the following should be the PRIMARY focus when defining the scope for this engagement?

    Show answer & explanation

    Correct answer: B

    In a serverless architecture, the primary security boundary and attack surface shifts from the network and OS level to the application and identity level. The most critical aspect to test is the Identity and Access Management (IAM) configuration. Each Lambda function has an execution role with specific permissions. Overly permissive roles are a common and high-impact vulnerability, allowing an attacker who compromises one function to pivot and access other AWS services (like S3 buckets or DynamoDB tables) they shouldn't. Therefore, a thorough review of IAM roles and policies is the primary focus for identifying potential data exposure and lateral movement paths. Network scanning is irrelevant due to the shared responsibility model, and while code review is important, the IAM permissions define the blast radius of any code-level vulnerability.

Ready for the real thing?

The full PT0-003 simulator has every exam-style question, timed mode, and instant scoring.