CompTIA PenTest+ PT0-003 (V3) Practice Question

A penetration tester is in the final phase of an engagement and needs to remove all artifacts from a compromised Windows server. For persistence, a malicious service named TrueSystemMonitor was installed. The tester has already stopped the active process. To ensure this persistence mechanism is fully eradicated and will not launch again upon system restart, which of the following commands should the tester execute next?

  • reg add "HKLM\SYSTEM\CurrentControlSet\Services\TrueSystemMonitor" /v Start /t REG_DWORD /d 4 /f

  • taskkill /F /IM TrueSystemMonitor.exe

  • del C:\Windows\System32\TrueSystemMonitor.exe

  • sc.exe delete TrueSystemMonitor

CompTIA PenTest+ PT0-003 (V3)
Post-exploitation and Lateral Movement
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $51
$425.00 $374.00
SAVE $57
CompTIA PenTest+ Voucher with Retake
v3 / PT0-003
Includes Retake
$474.00 $417.00
Bash, the Crucial Exams Chat Bot
AI Bot