Skip to main content

PenTest+ PT0-003

Free PenTest+ PT0-003 Practice Test

552 practice questions across all 5 exam domains. Premium AI deep dives available. No signup required.

552 questions|25 exams|5 domains
Start Free Practice Test

No signup needed — start immediately

Sign up free to unlock the RPG campaign — battle 210 enemies, collect loot, level up your character. Enter the campaign

Free PT0-003 Sample Questions

PT0-003 sample questions, free, no signup. Work through these 12, then take a full practice exam.

  1. Engagement Management

    Question 1. The signed rules of engagement list only IP ranges the client owns. At kickoff the client also asks you to test app.partner-crm.example, which resolves into a hosting provider's address space. What must happen before you send any traffic to that host?

    1. ANothing further. The client asked in writing, and that written request is the authorization.
    2. BGet written authorization from the hosting provider, then amend the scope document to match.
    3. CLimit yourself to an unauthenticated port scan, since scanning is exempt from computer-misuse law.
    4. DDefer the host to the retest window and record it as a scope gap in the final report.
    Show the answer

    Correct answer: B. Get written authorization from the hosting provider, then amend the scope document to match.

    A client can only authorize testing of systems it controls, so a host in a third party's address space needs that provider's written sign-off and an amended scope document first. Port scanning is not a legal exemption; it is still active traffic aimed at someone else's asset.

  2. Attacks and Exploits

    Question 2. You hold credentials for one standard Active Directory user and have local administrator rights nowhere. You request Kerberos service tickets for every account carrying a registered SPN, export them, and crack them offline. Which technique is this?

    1. AAS-REP roasting
    2. BPass-the-hash
    3. CKerberoasting
    4. DGolden ticket forgery
    Show the answer

    Correct answer: C. Kerberoasting

    Kerberoasting abuses the fact that any authenticated domain user can request a service ticket for an SPN-bearing account, and that ticket is encrypted with the service account's password-derived key, so it can be cracked offline without lockout. AS-REP roasting instead targets accounts with Kerberos pre-authentication disabled and needs no credentials at all.

  3. Engagement Management

    Question 3. Midway through an external engagement you confirm unauthenticated remote code execution on a public web server and discover an unknown party's web shell already planted there. What is the correct next step?

    1. ADelete the web shell and apply the vendor patch so the client stops bleeding data.
    2. BPivot through the existing web shell to map how far the intruder reached, then report both.
    3. CFinish the scheduled testing and rank the finding Critical in the final report.
    4. DTrigger the escalation path in the rules of engagement and notify the client's named contact now.
    Show the answer

    Correct answer: D. Trigger the escalation path in the rules of engagement and notify the client's named contact now.

    Evidence of a prior compromise triggers the escalation process defined in the rules of engagement, so you notify the designated contact immediately and let the client's incident responders take over. Removing the shell or using it yourself would destroy or contaminate evidence the responders need.

  4. Engagement Management

    Question 4. A hospital's board of directors will read your finished report to decide next year's security budget. None of them are technical. Which part of the report is written primarily for this audience?

    1. AExecutive summary describing overall risk posture and business impact
    2. BMethodology section listing each phase and the tools used in it
    3. CTechnical findings with reproduction steps and affected hostnames
    4. DAppendix of raw scan output and screenshots kept as evidence
    Show the answer

    Correct answer: A. Executive summary describing overall risk posture and business impact

    The executive summary translates findings into business risk and strategic recommendations for leadership, without technical detail. Technical findings with reproduction steps are aimed at the engineers who will carry out remediation.

  5. Reconnaissance and Enumeration

    Question 5. The client wants the first week of the engagement to generate zero traffic toward its infrastructure. Which reconnaissance activity fits that restriction?

    1. ASweeping the client's public netblock to see which hosts answer
    2. BConnecting to the client's mail server to confirm valid mailbox names
    3. CRequesting a zone transfer from the client's authoritative name servers
    4. DSearching public certificate transparency logs for the client's subdomains
    Show the answer

    Correct answer: D. Searching public certificate transparency logs for the client's subdomains

    Certificate transparency logs are public third-party records, so reviewing them is passive OSINT that never touches the client's systems. Querying the client's own name servers, even for a single request, is active reconnaissance.

  6. Reconnaissance and Enumeration

    Question 6. Without logging in anywhere, a tester compares the initial TTL and TCP window size in replies from an in-scope host against known stack behaviors to judge whether it runs Windows or Linux. Which enumeration technique is this?

    1. AOS fingerprinting
    2. BBanner grabbing
    3. CARP poisoning
    4. DDNS enumeration
    Show the answer

    Correct answer: A. OS fingerprinting

    OS fingerprinting infers the operating system from how its network stack builds packets, such as default TTL and window size. Banner grabbing is close but relies on text a service announces, not on packet characteristics.

  7. Vulnerability Discovery and Analysis

    Question 7. Your scan of a retail client returns three findings: CVSS 9.8 on a VPN gateway reachable from the internet, CVSS 9.1 on a lab server with no network route outside its VLAN, and CVSS 6.5 on a public brochure site. Which should the report rank as the top remediation priority?

    1. AThe lab server, because its base score is closest to the one on the gateway
    2. BThe VPN gateway, because it pairs a critical score with direct internet exposure
    3. CThe brochure site, because it is the most visible asset to customers
    4. DAll three equally, because every finding above 6.0 is treated as critical
    Show the answer

    Correct answer: B. The VPN gateway, because it pairs a critical score with direct internet exposure

    CVSS-based triage weighs the base score together with exposure and asset context, and the gateway combines a critical score with an internet-facing attack surface. The isolated lab server scores high but its lack of reachability lowers its real-world risk.

  8. Vulnerability Discovery and Analysis

    Question 8. A scanner flags a Linux file server as vulnerable because its package version number predates a fix. Manual review of the vendor changelog shows the distribution backported the security patch into that same version. How should the finding be classified?

    1. ATrue positive
    2. BFalse negative
    3. CFalse positive
    4. DTrue negative
    Show the answer

    Correct answer: C. False positive

    The scanner reported a vulnerability that is not actually present, which makes it a false positive, and it should be documented as validated and excluded. A false negative would be the reverse case: a real flaw the scanner failed to report.

  9. Attacks and Exploits

    Question 9. On an authorized physical assessment, a tester carrying two coffees walks in right behind an employee who badged through the server-room corridor door and holds it open for him. Which control would most directly have stopped this entry?

    1. AAn access control vestibule that admits one person per badge
    2. BA longer retention period for the door's badge access logs
    3. CSecurity awareness posters about phishing emails in the break room
    4. DA camera recording the corridor for later review
    Show the answer

    Correct answer: A. An access control vestibule that admits one person per badge

    Tailgating relies on an authorized person opening the door for someone else, and a vestibule (mantrap) enforces one entry per credential. Cameras and logs are detective controls that record the event but do not prevent it.

  10. Attacks and Exploits

    Question 10. Logged in as a low-privilege customer on an in-scope web portal, a tester notices invoice pages load from a sequential numeric ID. Changing that number displays invoices that belong to other customers. Which vulnerability class does this finding represent?

    1. ACross-site request forgery
    2. BServer-side request forgery
    3. CStored cross-site scripting
    4. DInsecure direct object reference
    Show the answer

    Correct answer: D. Insecure direct object reference

    An insecure direct object reference occurs when the application trusts a user-supplied identifier without checking that the requester is authorized for that object. Cross-site request forgery instead tricks a victim's browser into sending an unwanted request, which is not what happened here.

  11. Post-exploitation and Lateral Movement

    Question 11. Over a two-week engagement, the tester added a local account and a scheduled task on three in-scope workstations so access would survive reboots. The engagement window has now ended. Which close-out action is required?

    1. ALeave the artifacts in place so the client's blue team can practice finding them
    2. BRemove every persistence artifact and account, confirm removal, and document it in the report
    3. CDisable the scheduled tasks but keep the local accounts for the retest
    4. DAsk the client's help desk to reimage the three workstations
    Show the answer

    Correct answer: B. Remove every persistence artifact and account, confirm removal, and document it in the report

    Post-engagement cleanup requires the tester to remove everything created during testing, verify it is gone, and record what was removed so the client can confirm. Leaving any backdoor or account behind creates real risk the client never agreed to carry.

  12. Post-exploitation and Lateral Movement

    Question 12. After gaining a foothold on a dual-homed kiosk PC, the tester notices its second adapter sits on a plant-floor segment unreachable from the tester's laptop. The tester relays further in-scope traffic through the kiosk to reach that segment. Which term fits?

    1. APrivilege escalation
    2. BData exfiltration
    3. CPivoting
    4. DPersistence
    Show the answer

    Correct answer: C. Pivoting

    Pivoting uses a compromised host as a relay to reach networks that are otherwise unreachable from the tester's position. Privilege escalation raises rights on a single system and does not by itself extend network reach.

Start the full free PenTest+ practice exam

3 free practice exams · 552 questions in the PenTest+ bank

PT0-003 Domain Breakdown

13%Engagement Management
21%Reconnaissance and Enumeration
17%Vulnerability Discovery and Analysis
35%Attacks and Exploits
14%Post-exploitation and Lateral Movement

How It Works

Step 1

Start a Free Practice Test

Pick a PenTest+ exam topic and jump into real-format PT0-003 questions. No signup, no paywall.

Step 2

Get Premium AI Deep Dives

Campaign Pass adds AI deep dives with mnemonics. Missed questions auto-generate spaced repetition flashcards.

Step 3

Unlock Battles & Leaderboards

Sign up free to enter the RPG campaign — battle enemies tied to each domain, collect loot, and compete on weekly leaderboards.

Why Prepare with SecuSpark?

Real Exam Format

Single choice, multiple choice, and drag-and-drop questions mirror the actual PT0-003 exam experience.

Premium AI Deep Dives

Get instant explanations with memory mnemonics when you answer incorrectly — learn from mistakes, not just scores.

All 5 Domains Covered

552 questions weighted to match real exam distribution across all five PT0-003 domains.

100% Free, No Tricks

No credit card required for the free tier. Campaign Pass unlocks all exams, RPG battles, and premium AI study tools.

PenTest+ Practice Test FAQ

Are there free PT0-003 sample questions?

Yes. 12 worked PT0-003 sample questions with answers and explanations sit on this page, and 3 full PenTest+ practice exams are free with no signup. The whole bank runs 552 questions across 25 exams.

Is this PenTest+ practice test really free?

Yes — 3 PenTest+ practice exams are included on the free tier. No credit card, no signup wall. Campaign Pass unlocks all 25 exams and 552 questions.

What is the PenTest+ PT0-003 passing score?

The passing score is 750 out of 900. Scoring is scaled, so how many correct answers you need shifts with question difficulty. Aim for 85%+ on practice tests before you book the real exam.

How long is the PenTest+ exam?

You get 165 minutes to complete up to 90 questions, including both multiple-choice and performance-based questions (PBQs). That is under 2 minutes per question, so time management is critical.

Are performance-based questions (PBQs) included?

Our multiple-choice questions cover the same concepts PBQs test — vulnerability scan analysis, exploit techniques, and pen test reporting. That's the groundwork for the PBQs on exam day.

Do I need Security+ before taking PenTest+?

No formal prerequisites. CompTIA recommends Network+, Security+, or 3-4 years of hands-on experience. Security+ is a strong base — PenTest+ builds on a lot of the same ground.

Which PenTest+ domains are covered?

All five PT0-003 domains: Engagement Management (13%), Reconnaissance and Enumeration (21%), Vulnerability Discovery and Analysis (17%), Attacks and Exploits (35%), and Post-exploitation and Lateral Movement (14%).

Start Your PenTest+ Practice Test Now

Every domain, weighted like the real exam. 3 exams free, scored instantly, no signup.

Start Free Practice Test