CompTIA PenTest+ Practice Questions (Free Sample)

These 15 free questions give you a real feel for the PenTest+ exam, the same scenario style and difficulty you get inside Certifym, with an instant score the moment you submit and a full explanation for every answer once you enter your email. They span Engagement Management, Reconnaissance and Enumeration, Attacks and Exploits, and Post-exploitation and Reporting.

Ready for the real thing? Members get ten full-length PenTest+ practice exams with full explanations, study mode, and domain drills. New practice content is added every week, and your progress is saved when you join.

CompTIA PenTest+ (PT0-003) — Free Sample Questions

  1. Question 1 of 15Engagement Management

    Which document defines the systems, methods, and boundaries a penetration tester is authorized to test?

  2. Question 2 of 15Engagement Management

    Why must a penetration tester obtain written authorization before testing begins?

  3. Question 3 of 15Reconnaissance and Enumeration

    A tester gathers employee names and email formats from a company website and LinkedIn without sending any packets to target systems. What is this called?

  4. Question 4 of 15Reconnaissance and Enumeration

    Which tool is most commonly used to discover live hosts and open ports during network enumeration?

  5. Question 5 of 15Attacks and Exploits

    A tester finds a web input that returns database errors when a single quote is submitted. Which vulnerability should be investigated?

  6. Question 6 of 15Attacks and Exploits

    After gaining a low-privilege shell on a Linux host, a tester searches for misconfigured SUID binaries and weak sudo rules. What is the goal of this activity?

  7. Question 7 of 15Attacks and Exploits

    Which attack captures and reuses a valid authentication hash to access a system without cracking the password?

  8. Question 8 of 15Attacks and Exploits

    A social engineering test sends employees a crafted email hoping they click a malicious link. Which technique is this?

  9. Question 9 of 15Post-exploitation and Reporting

    Which section of a penetration test report is written for executives who need to understand business impact without technical detail?

  10. Question 10 of 15Post-exploitation and Reporting

    After finishing an engagement, why should a tester remove any accounts, tools, and backdoors they created?

  11. Question 11 of 15Post-exploitation and Reporting

    Which finding should typically be prioritized first for remediation in a penetration test report?

  12. Question 12 of 15Engagement Management

    What is the main purpose of maintaining detailed notes and timestamps throughout an engagement?

  13. Question 13 of 15Engagement Management

    A client asks the tester to also assess a subsidiary domain that was not listed in the agreed scope. What is the correct action?

  14. Question 14 of 15Engagement Management

    Which practice reduces the risk that an active exploit will disrupt production systems during a test?

  15. Question 15 of 15Reconnaissance and Enumeration

    A penetration tester gathers information about a target using only publicly available sources such as search engines and social media. What is this technique called?

Untimed, no account needed. Your score appears instantly. Add your email afterwards if you want the explanation for every question and a copy of your results.