Practice questions · Cybersecurity

CompTIA PenTest+ (PT0-003): Practice Questions

intermediate 45 questions

Original, syllabus-based practice questions for CompTIA PenTest+ (PT0-003). Each answer is explained, including why the other options are wrong. Filter by domain or difficulty. These are original concept checks to test understanding - not questions taken from any live exam, and they describe techniques at a conceptual level only.

By The Exam Atlas Editorial Team · Verified 2026-08-05 · ~56 min

  1. Engagement Management easy

    Which document defines what may be tested, when, from where, and what is off-limits?

  2. Engagement Management medium

    During a test you discover a live host that is clearly outside the agreed target list. What is the correct response?

  3. Engagement Management medium

    A client's web application is hosted on a third-party cloud platform. Before testing it, what is usually also required?

  4. Engagement Management easy

    What is the main purpose of the executive summary in a penetration test report?

  5. Engagement Management hard

    A client asks for a short signed document confirming a test happened, its scope and dates, to send to their auditor. What is this?

  6. Engagement Management medium

    What does de-confliction refer to during an engagement?

  7. Engagement Management hard

    Which testing model gives the tester full information about the environment in advance?

  8. Reconnaissance and Enumeration easy

    Which of the following activities counts as passive reconnaissance?

  9. Reconnaissance and Enumeration easy

    What best describes the difference between passive and active reconnaissance?

  10. Reconnaissance and Enumeration medium

    What is the main value of enumeration after a host has been discovered?

  11. Reconnaissance and Enumeration medium

    Why is open-source intelligence usually gathered before active scanning?

  12. Reconnaissance and Enumeration medium

    A tester compiles exposed services, endpoints and interfaces into a single picture of everything an attacker could interact with. What is this called?

  13. Reconnaissance and Enumeration hard

    What level of scripting knowledge does the reconnaissance domain expect for PT0-003?

  14. Reconnaissance and Enumeration medium

    Which enumeration result most directly suggests where credential attacks might be relevant?

  15. Reconnaissance and Enumeration easy

    Which of these is information typically obtained through open-source intelligence?

  16. Reconnaissance and Enumeration hard

    A tester wants to map an organisation's externally reachable hostnames without sending traffic to them. Which source fits?

  17. Vulnerability Discovery and Analysis easy

    What advantage does a credentialed scan have over a non-credentialed scan?

  18. Vulnerability Discovery and Analysis medium

    A scanner reports a critical vulnerability, but the tester confirms the affected feature is disabled. This finding is a:

  19. Vulnerability Discovery and Analysis medium

    Why should findings be prioritised using more than the CVSS score alone?

  20. Vulnerability Discovery and Analysis hard

    A real, exploitable weakness exists but the scan did not report it. This is a:

  21. Vulnerability Discovery and Analysis medium

    What does validation add to a raw scanner finding?

  22. Vulnerability Discovery and Analysis easy

    Which scan type sees only what an unauthenticated outsider would see?

  23. Vulnerability Discovery and Analysis hard

    A tester compares a system's settings against a hardening baseline instead of running a scanner. This is best described as:

  24. Vulnerability Discovery and Analysis medium

    What does a CVE identifier represent?

  25. Attacks and Exploits medium

    A described attack intercepts communication between two parties to read or alter it. Which category is this?

  26. Attacks and Exploits medium

    An API returns records belonging to other users when an object identifier is changed. Which weakness category is this?

  27. Attacks and Exploits easy

    Which category best fits a rogue wireless access point that imitates a legitimate one?

  28. Attacks and Exploits medium

    A web flaw lets an attacker make the server send requests to internal systems it should not reach. Which category is this?

  29. Attacks and Exploits medium

    Which category describes untrusted input being processed by an application as a command?

  30. Attacks and Exploits easy

    A tester follows an employee through a badge-controlled door without authenticating. Which concept is this?

  31. Attacks and Exploits hard

    In an authorised test, what must be true before any social-engineering activity begins?

  32. Attacks and Exploits medium

    Which category best fits an attack that abuses over-permissive identity policies in a cloud tenant?

  33. Attacks and Exploits easy

    A web flaw lets an attacker run script in another user's browser session. Which category is this?

  34. Attacks and Exploits medium

    Two techniques would both prove a finding, but one risks an outage. What guides the choice in a professional test?

  35. Attacks and Exploits hard

    A described IoT device ships with the same fixed login on every unit. Which weakness category is this?

  36. Attacks and Exploits medium

    Which category fits an attack that captures and re-sends valid authentication material to gain access?

  37. Attacks and Exploits hard

    During the attacks phase, why is knowing how a technique is detected part of the objective?

  38. Attacks and Exploits medium

    A described attack uses fake messages to trick staff into revealing credentials. Which category is this?

  39. Post-exploitation and Lateral Movement easy

    What is the difference between vertical and horizontal privilege escalation?

  40. Post-exploitation and Lateral Movement medium

    A tester routes through a compromised host to reach a network segment they could not touch directly. What is this called?

  41. Post-exploitation and Lateral Movement medium

    Why must any persistence mechanism used in a test be documented and removed?

  42. Post-exploitation and Lateral Movement easy

    What does lateral movement describe?

  43. Post-exploitation and Lateral Movement hard

    During post-exploitation, how should data handling be approached in an authorised test?

  44. Post-exploitation and Lateral Movement medium

    Why does a professional test include a cleanup phase at the end?

  45. Post-exploitation and Lateral Movement hard

    Why is understanding detection avoidance useful to the client, not just the tester?

Practice questions FAQ

Are these real PT0-003 exam questions?
No. These are original study questions written to test understanding. They are not real exam questions, exam dumps, or copied from any provider.
How should I use these practice questions?
Answer each one, read the explanation (including why the wrong options are wrong), and use the per-domain score below to focus your revision on weak areas. Revisit before exam day.
How many questions should I do before the exam?
Enough to score consistently across every domain, alongside full-length practice from official or reputable providers. Understanding why each answer is right matters more than raw volume.
What score means I am ready?
A good signal is consistently scoring around 80% or higher across all domains on questions you have not seen before, and being able to explain why the wrong options are wrong.
Should I use exam dumps?
No. Dumps (real or leaked questions) breach provider policy, can void your certification, and do not build the understanding the exam actually tests.

Sources