PT0-003 — CompTIA PenTest+
CompTIA

CompTIA PenTest+ (PT0-003) Practice Questions

4.8 100 verified reviews
120 questions
June 14, 2026 updated
Online quiz simulator

Domain coverage

  • Engagement Management (13%)
  • Reconnaissance and Enumeration (21%)
  • Vulnerability Discovery and Analysis (17%)
  • Attacks and Exploits (35%)
  • Post-Exploitation and Lateral Movement (14%)

Sample Questions (12 of 120 shown)

Q1 Engagement Management
A penetration tester is preparing a proposal for a client that requires testing of a web application handling PCI DSS data. Which compliance requirement must be explicitly addressed in the Rules of Engagement?
  1. SOX compliance for financial reporting
  2. PCI DSS scoping and segmentation validation requirements
  3. HIPAA breach notification procedures
  4. GDPR data subject consent documentation
✓ Correct Answer: B
When testing environments that process payment card data, the Rules of Engagement must address PCI DSS requirements. This includes validating network segmentation that isolates cardholder data environments and ensuring testing does not violate PCI DSS restrictions. SOX applies to financial reporting, HIPAA to healthcare, and GDPR to EU personal data.
Q2 Engagement Management
During a penetration test, the tester discovers evidence of an active insider threat. According to standard engagement protocols, what is the appropriate immediate action?
  1. Document the finding and continue testing without alerting the client
  2. Immediately stop all testing activities and contact law enforcement
  3. Notify the client's designated point of contact through the established escalation channel
  4. Exploit the insider's access to gather more evidence
✓ Correct Answer: C
The Rules of Engagement should define escalation procedures for critical findings. When discovering active criminal activity or insider threats, the tester must notify the designated client contact through agreed-upon channels. Stopping all testing or contacting law enforcement without client direction typically violates engagement terms.
Q3 Engagement Management
A client requests a penetration test but cannot provide written authorization for three weeks. The project timeline is urgent. What is the appropriate response?
  1. Begin passive reconnaissance only while waiting for authorization
  2. Proceed with the test using verbal authorization from the IT manager
  3. Decline to begin any testing activities until written authorization is received
  4. Start with non-invasive scanning that won't affect production systems
✓ Correct Answer: C
Written authorization is mandatory before any penetration testing activities. Testing without proper authorization is illegal and may violate computer fraud laws. Even passive reconnaissance without written consent can create legal liability. The tester must wait for documented authorization regardless of timeline pressures.
Q4 Engagement Management
Which document specifies the technical boundaries of a penetration test, including approved IP ranges, excluded systems, and testing timeframes?
  1. Master Service Agreement (MSA)
  2. Statement of Work (SOW)
  3. Rules of Engagement (ROE)
  4. Non-Disclosure Agreement (NDA)
✓ Correct Answer: C
The Rules of Engagement (ROE) defines the technical boundaries and operational parameters of the penetration test. It includes specific IP ranges, excluded systems, testing windows, authorized techniques, and emergency contacts. The SOW covers business terms, while the ROE covers technical testing boundaries.
Q5 Engagement Management
A penetration testing firm is assessing the risk of testing a client's critical production environment. Which factor represents the highest potential business impact risk?
  1. Testing during off-peak hours
  2. Testing systems without a proper backup plan in place
  3. Using automated scanning tools with safe checks enabled
  4. Testing with read-only access credentials
✓ Correct Answer: B
Testing production systems without verified backups represents the highest business impact risk. If testing causes system failure or data corruption without recovery options, the business could suffer significant downtime and financial loss. Testing during off-peak hours and using safe scan options actually reduces risk.
Q6 Engagement Management
In a penetration test proposal, which component best helps the client understand the value and expected outcomes of the engagement?
  1. Detailed CVs of all assigned testers
  2. A clear statement of objectives and deliverables including risk ratings
  3. The history of similar tests performed by the firm
  4. Technical specifications of testing tools to be used
✓ Correct Answer: B
A clear statement of objectives and deliverables helps clients understand what they will receive and how it addresses their security concerns. Including risk rating methodologies demonstrates how findings will be prioritized.
Q7 Engagement Management
A bank hires a penetration tester who must ensure sensitive information remains confidential throughout the engagement. Which contract document enforces this requirement?
  1. Non-Disclosure Agreement (NDA)
  2. Master Service Agreement (MSA)
  3. Statement of Work (SoW)
  4. Service Level Agreement (SLA)
✓ Correct Answer: A
A Non-Disclosure Agreement (NDA) is a legal contract that binds parties to keep sensitive information confidential. In penetration testing, the NDA ensures the tester does not disclose client confidential data encountered during the assessment.
Q8 Engagement Management
A penetration tester is developing the rules of engagement for a potential client. Which of the following should be included in the ROE? (Select TWO)
  1. Billing rates for testers
  2. Testing window and authorized hours
  3. Detailed resumes of the testing team
  4. Escalation procedures and emergency contacts
  5. Marketing materials for the testing firm
✓ Correct Answer: B, D
The Rules of Engagement document defines the operational parameters of the test. Testing windows specify when testing can occur, and escalation procedures define how to handle critical findings or emergencies. Billing, resumes, and marketing materials belong in separate business documents.
Q9 Engagement Management
A penetration tester is getting ready to conduct a vulnerability scan to evaluate an environment. Which of the following should the tester confirm before beginning the scan?
  1. The client has backed up critical systems
  2. The tester has completed their security training
  3. The scanning tool has been purchased
  4. The client's IT staff have been dismissed for the day
✓ Correct Answer: A
Before conducting vulnerability scans, the tester should confirm that the client has current, verified backups of critical systems. This ensures that if scanning causes instability or outages, systems can be restored. This is a standard pre-engagement safety measure.
Q10 Engagement Management
An external legal firm is conducting a penetration test of a large corporation. Which of the following would be most appropriate for the legal firm to use in the subject line of a weekly email update?
  1. Action Required Status Update
  2. Urgent Status Update
  3. Important Weekly Status Update
  4. Privileged & Confidential Status Update
✓ Correct Answer: D
When a legal firm is conducting the penetration test, communications should be marked as "Privileged & Confidential" to maintain attorney-client privilege and protect sensitive findings from disclosure. This helps ensure the test results are protected under legal professional privilege.
Q11 Engagement Management
Which of the following explains why a tester would choose DREAD over PTES during the planning phase of a penetration test?
  1. The tester is performing a web application test
  2. The tester is evaluating a mobile application
  3. The tester is assessing a fat client application
  4. The tester is creating a threat model
✓ Correct Answer: D
DREAD is a risk assessment model used for ranking and classifying threats (threat modeling). PTES (Penetration Testing Execution Standard) is a methodology for how to perform penetration tests, not for creating threat models. DREAD helps prioritize threats based on Damage, Reproducibility, Exploitability, Affected users, and Discoverability.
Q12 Engagement Management
A company hires a penetration tester to perform an external attack surface review as part of a pre-engagement activity. The tester looks for assets to test. Which of the following is an example of a target that can be used for testing?
  1. API
  2. HTTP
  3. IPA
  4. ICMP
✓ Correct Answer: A
An API (Application Programming Interface) is a common target for penetration testing, especially in modern web and mobile applications. APIs can be entry points for injection attacks, authentication bypasses, and data leakage. HTTP, IPA, and ICMP are protocols, not target types.

You've viewed 3 of 120 questions. Start the free practice exam to answer all questions with instant feedback.

Exam overview

The CompTIA PenTest+ (PT0-003) certification is the only penetration testing exam that includes all stages of ethical hacking — from planning and scoping to vulnerability discovery, exploitation, and post-exploitation. Unlike CEH which is theory-heavy, PenTest+ validates your ability to perform actual penetration tests using industry-standard tools like Nmap, Metasploit, Burp Suite, and Wireshark.

As cyberattacks grow more sophisticated, organizations need skilled penetration testers who can think like attackers and identify vulnerabilities before they're exploited. The V3 exam (launched December 2024) adds critical new content on cloud penetration testing (container escapes, metadata service attacks, IAM misconfigurations) and AI attacks (prompt injection, model manipulation) — skills that directly map to real-world offensive security roles.

Our PT0-003 practice test engine mirrors the actual exam with performance-based questions that simulate real penetration testing scenarios. Every question is mapped to the five exam domains, so you can focus your study on high-weight areas like Attacks and Exploits (35%). With detailed explanations that teach offensive security principles — not just test answers — you'll build the hands-on skills needed to pass the exam and excel in penetration testing jobs.

Official Exam Domains & Weighting

To successfully pass the PT0-003 exam, candidates must master penetration testing methodologies across the following five core domains:
  • Domain 1: Engagement Management (13%)
Plan and scope penetration tests while ensuring legal/ethical compliance, develop detailed reports with remediation recommendations, and manage stakeholder communication throughout the engagement.
  • Domain 2: Reconnaissance and Enumeration (21%)
Perform active and passive reconnaissance using OSINT, network sniffing, and protocol scanning. Conduct enumeration (DNS, services, directories) and customize Python/PowerShell/Bash scripts for information gathering.
  • Domain 3: Vulnerability Discovery and Analysis (17%)
Conduct vulnerability scans (authenticated, unauthenticated, SAST, DAST), analyze results to identify false positives, and use tools like Nessus, Nikto, and OpenVAS for vulnerability discovery.
  • Domain 4: Attacks and Exploits (35%)
Execute network attacks (VLAN hopping, on-path attacks), authentication attacks (brute-force, pass-the-hash, credential stuffing), host-based attacks (privilege escalation, process injection), web application attacks (SQL injection, XSS, directory traversal), cloud-based attacks (container escapes, IAM misconfigurations), and AI attacks (prompt injection, model manipulation).
  • Domain 5: Post-Exploitation and Lateral Movement (14%)
Maintain persistence, perform lateral movement, document findings, create attack narratives, and provide remediation recommendations during post-exploitation activities.

What Our Customers Say 100 verified reviews

4.8 Based on 100 reviews
The progress tracking feature for PT0-003 really motivated me. Seeing my improvement over time was incredibly satisfying.
— Daniel H.
My boss asked me to get the PT0-003 cert for work. This was the best study tool I found. Passed in three weeks.
— Austin P.
Comprehensive coverage for PT0-003. Every domain is represented and the question difficulty ramps up nicely.
— Emma J.
I work full time and study at night. The PT0-003 question bank allowed me to learn efficiently without wasting precious time.
— Harper S.
Couldn’t have passed the PT0-003 exam without this. The questions are challenging, the explanations are thorough, and the value is unbeatable.
— Hannah L.
Passed PT0-003 with 912/1000. The practice questions cover the exam objectives thoroughly and the explanations are clear.
— Ella M.

Log in to rate this exam and leave a review.

Submitted for moderation before publishing. Keep it helpful and respectful.

Frequently Asked Questions

PenTest+ is more hands-on than CEH (which is theory-heavy) but less advanced than OSCP (which requires deep exploit development). It's the perfect middle-ground for IT pros transitioning into offensive security. Our practice tests include PBQs that simulate real pentesting scenarios — scan, exploit, and report.

V3 (launched Dec 2024) adds cloud penetration testing (container escapes, metadata service attacks, IAM misconfigurations) and AI attacks (prompt injection, model manipulation). It also strengthens coverage of lateral movement and persistence techniques. If you're studying for the current exam, make sure your materials are V3-specific — our question bank is fully updated for PT0-003.

CompTIA doesn't publish the exact number, but candidates report 4-6 PBQs alongside multiple-choice questions. PBQs require you to use tools (Nmap, Metasploit, Burp Suite) in a simulated environment. Our practice engine includes PBQ simulators so you won't be surprised on exam day.

CompTIA recommends 3-4 years in a penetration tester job role, with Network+ and Security+ (or equivalent) knowledge. If you're new to pentesting, start with Security+ first, then transition to PenTest+. Our study planner adapts to your experience level and tracks progress across all five domains.

Yes, PenTest+ is recognized by employers and government agencies (including U.S. DoD) for offensive security roles. It prepares you for roles like Penetration Tester, Vulnerability Assessor, Security Consultant, and Red Team Operator. Our customers report an average salary increase of $18,000 after certification.

Most candidates need 8-12 weeks of consistent study (1.5-2 hours/day) with prior Security+ and networking experience. If you're new to pentesting, allow 4-6 months. Our personalized study planner adapts to your schedule and focuses on the heavy-weight Domain 4 (35%).

PenTest+ is a great foundation that proves you can perform real pentests. OSCP is more advanced and valued by elite red teams. Many professionals earn PenTest+ first to build foundational skills, then pursue OSCP for advanced exploit development. Our practice tests prepare you for both paths and include a career roadmap guide.