CompTIA PenTest+ PT0-003 (V3) Practice Question

As part of a penetration test, you are evaluating a dashboard that lets employees paste any URL into a form to generate a live preview. The application sends the URL to the server, which fetches the content and returns it to the user's browser. You want to prove that this functionality can be abused to reach non-public resources inside the corporate network. Which action would provide the clearest evidence that the preview feature can actually contact an internal service?

  • Provide a URL that targets an internal-only endpoint (for example, http://127.0.0.1:8080/admin) and verify that the application returns the protected content

  • Measure how long the server takes to respond to extremely slow external sites and infer back-end behavior from any delay

  • Capture response headers during a normal login request and look for internal hostnames or odd header values

  • Run a dictionary attack against subdomains of the public site to discover names that are not listed in public DNS

CompTIA PenTest+ PT0-003 (V3)
Attacks and Exploits
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $51
$425.00 $374.00
SAVE $57
CompTIA PenTest+ Voucher with Retake
v3 / PT0-003
Includes Retake
$474.00 $417.00
Bash, the Crucial Exams Chat Bot
AI Bot