CompTIA PenTest+ PT0-003 (V3) Practice Question

A security consultant reviewing web server logs for an online banking portal notices a tester sending a series of GET requests such as /view.aspx?account=200, /view.aspx?account=201, and /view.aspx?account=202. Each response returns full JSON objects containing account balances, names, and mailing addresses that do not belong to the authenticated user whose session cookie appears in the request headers. No additional tokens or access-control checks are observed in the responses, and the tester is able to iterate through more than 1,000 consecutive IDs in a short period. Based on the activity, which type of vulnerability is being exercised to pull sensitive data from records the user does not own?

  • Shared default credentials have been left active for all user accounts

  • Public share enumeration has been enabled by default for the application

  • Numeric references are used with no proper verification, allowing access to other records

  • Sensitive content is transferred without encryption during transit

CompTIA PenTest+ PT0-003 (V3)
Attacks and Exploits
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $51
$425.00 $374.00
SAVE $57
CompTIA PenTest+ Voucher with Retake
v3 / PT0-003
Includes Retake
$474.00 $417.00
Bash, the Crucial Exams Chat Bot
AI Bot