Free PT0-002 Exam Braindumps (page: 9)

Page 8 of 93

A consulting company is completing the ROE during scoping.
Which of the following should be included in the ROE?

  1. Cost of the assessment
  2. Report distribution
  3. Testing restrictions
  4. Liability

Answer(s): C



A new client hired a penetration-testing company for a month-long contract for various security assessments against the client's new service. The client is expecting to make the new service publicly available shortly after the assessment is complete and is planning to fix any findings, except for critical issues, after the service is made public. The client wants a simple report structure and does not want to receive daily findings.
Which of the following is most important for the penetration tester to define FIRST?

  1. Establish the format required by the client.
  2. Establish the threshold of risk to escalate to the client immediately.
  3. Establish the method of potential false positives.
  4. Establish the preferred day of the week for reporting.

Answer(s): B



A penetration tester logs in as a user in the cloud environment of a company.
Which of the following Pacu modules will enable the tester to determine the level of access of the existing user?

  1. iam_enum_permissions
  2. iam_prive_sc_scan
  3. iam_backdoor_assume_role
  4. iam_bruteforce_permissions

Answer(s): A



A company becomes concerned when the security alarms are triggered during a penetration test.
Which of the following should the company do NEXT?

  1. Halt the penetration test.
  2. Conduct an incident response.
  3. Deconflict with the penetration tester.
  4. Assume the alert is from the penetration test.

Answer(s): C






Post your Comments and Discuss CompTIA PT0-002 exam with other Community members:

PT0-002 Discussions & Posts