CompTIAAdvancedCompTIAPenTest+Penetration TestingVulnerability Assessment
CompTIA PenTest+ (PT0-003)
PT0-003
The CompTIA PenTest+ (PT0-003) exam validates practical penetration testing skills across engagement management, reconnaissance, vulnerability discovery, attacks, post-exploitation, reporting, and remediation.
Take a timed, 90-question mock exam that simulates the real test — or browse every question with answers and explanations at your own pace.
Questions
View all →- 1A penetration tester wants to send a specific network packet with custom flags and sequence numbers to a vulnerable target. Which of the following should the tester use?
- 2Which of the following explains the reason a tester would opt to use DREAD over PTES during the planning phase of a penetration test?
- 3A penetration tester is performing a security review of a web application. Which of the following should the tester leverage to identify the presence of vulnerable open-source libraries?
- 4A penetration tester finds that an application responds with the contents of the /etc/passwd file when the following payload is sent: Which of the following should the tester recommend in the report to best prevent this type of vulnerability?
- 5A penetration tester is conducting reconnaissance for an upcoming assessment of a large corporate client. The client authorized spear phishing in the rules of engagement. Which of the following should the tester do first when developing the phishing campaign?
- 6A penetration tester needs to test a very large number of URLs for public access. Given the following code snippet: Which of the following changes is required?
- 7During a penetration test, a tester captures information about an SPN account. Which of the following attacks requires this information as a prerequisite to proceed?
- 8While performing an internal assessment, a tester uses the following command: crackmapexec smb 192.168.1.0/24 -u user.txt -p Summer123@ Which of the following is the main purpose of the command?
- 9A penetration testing team needs to determine whether it is possible to disrupt the wireless communications for PCs deployed in the client's offices. Which of the following techniques should the penetration tester leverage?
- 10Which of the following tasks would ensure the key outputs from a penetration test are not lost as part of the cleanup and restoration activities?