PT1002 CompTIA PenTest+ Certification Exam Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

Anya, a penetration tester, is engaged to assess a client\'s e-commerce platform. The client has stipulated that all testing must occur during non-business hours and explicitly forbids any data exfiltration or actions that could compromise the availability of the live site. Anya discovers a potential SQL injection vulnerability in the product search functionality. To effectively demonstrate the severity of this flaw without violating the client\'s directives, which of the following actions would be the most appropriate and ethical approach?

Employ a time-based blind SQL injection technique to confirm the vulnerability by observing differential response times without extracting any data.
Proceed with a full SQL dump of the customer database to provide irrefutable proof of the vulnerability's impact.
Immediately cease all testing related to the identified vulnerability and only document its presence in the final report.
Utilize an automated SQL injection tool that attempts to bypass client-imposed restrictions to fully exploit the vulnerability.

About the PT1002 CompTIA PenTest+ Certification Exam Certification

These free practice questions are designed to help you assess your readiness for the PT1002 CompTIA PenTest+ Certification Exam exam by Other. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.