CompTIA PenTest+ (PT0-003) — All Questions
3 questions
After compromising one internal host, a tester uses it as a foothold to reach and attack other systems on the internal network. What is this technique called?
- a.Scoping
- b.Lateral movement (pivoting)✓
- c.Vulnerability scanning of the internet
- d.Passive reconnaissance
Lateral movement, or pivoting, uses a compromised host as a foothold to reach other systems that were not directly accessible, expanding access across the network. It is a post-exploitation activity, distinct from scoping or initial reconnaissance.
In a post-exploitation context, what does establishing persistence refer to?
- a.Encrypting the tester's report for delivery
- b.Maintaining continued access to a compromised system across reboots or credential changes✓
- c.Scoping the next engagement with the client
- d.Permanently improving the client's password policy
Persistence is the ability to retain access to a compromised system over time, for example surviving reboots, which demonstrates the potential impact of a breach. Testers document any persistence mechanisms used so they can be fully removed during cleanup.
Why is cleanup and restoration an important part of the post-exploitation phase of an authorized penetration test?
- a.It replaces the need for a final report
- b.It automatically patches all discovered vulnerabilities
- c.It removes tester-created artifacts and accounts so the environment is returned to its original state✓
- d.It increases the CVSS score of every finding
Cleanup removes tools, accounts, and other artifacts the tester introduced, returning the environment to its pre-test state and avoiding leaving new weaknesses behind. It does not alter scores, replace the report, or remediate the client's underlying vulnerabilities, which the client must fix.