CompTIA PenTest+ PT0-003 Certification Exam
CompTIA PenTest+ PT0-003
The CompTIA PenTest+ PT0-003 certification validates the skills needed to plan and scope a penetration test, perform reconnaissance and vulnerability discovery, execute attacks and exploits, and report findings with remediation guidance. The exam covers five domains: engagement management, reconnaissance and enumeration, vulnerability discovery and analysis, attacks and exploits, and post-exploitation and lateral movement. Candidates demonstrate hands-on skills with tools such as Nmap, Nikto, Burp Suite and hashcat, analyze scan output and shell sessions, exploit web, network, cloud and host targets, escalate privileges and pivot through segmented networks, and communicate results to stakeholders. The exam has a maximum of 90 questions over 165 minutes.
Certification Overview
- Exam name: PenTest+ PT0-003
- Vendor: CompTIA
- Exam code: PT0-003
- Duration: 165 minutes
- Total questions: 90
- Passing score: 75%
Who Should Take This Exam?
Penetration Tester, Security Consultant, Red Team Operator, Vulnerability Analyst, Application Security Specialist, Network Security Engineer
Prerequisites
No formal prerequisite. CompTIA recommends Network+ and Security+ or equivalent knowledge, plus 3-4 years of hands-on penetration testing or offensive security experience.
Topics Covered
- Engagement Management
- Reconnaissance and Enumeration
- Vulnerability Discovery and Analysis
- Attacks and Exploits
- Post-Exploitation and Lateral Movement
Question Types
- Multiple Choice (Single Answer)
- Multiple Choice (Multiple Answers)
- Drag and Drop
- Scenario-Based
PenTest+ PT0-003 Practice Questions
Our question bank contains 653+ practice questions for this certification. Sample questions from each exam chapter. Expand a question to see the answer choices. With a subscription, you get unlimited practice exams with randomized questions from our full question bank.
Engagement Management
In a penetration test's rules of engagement, what is the testing window primarily used to define?
- The dates and times during which testing activities are authorized to occur
- The list of tools the tester is authorized to install on the network
- The set of employees permitted to observe the test taking place on-site
- The billing rate that was agreed upon for the engagement overall
During scoping, what does target selection determine for a penetration test?
- The billing schedule the client will follow across the engagement
- The formatting template the tester must follow for the report
- The specific systems and networks that are authorized for testing
- The license tier of the vulnerability scanner that will be used
Which document authorizes a tester to perform activities that would otherwise be unauthorized access, and must be signed before testing starts?
- An invoice that estimates the total cost of the engagement
- A vulnerability scan report left over from a prior engagement
- A non-disclosure agreement that covers only the tester's own employer
- The signed rules of engagement or scoping agreement for this test
Reconnaissance and Enumeration
What is the defining characteristic of passive reconnaissance?
- Information is gathered without directly interacting with the target's systems
- Crafted packets are sent to each host on the range to observe how it responds
- The tester connects to the target's VPN using previously stolen credentials
- A vulnerability scanner is pointed directly at the target's open ports
What does the acronym OSINT stand for in the context of reconnaissance?
- Open-source intelligence gathered from publicly available sources
- Outbound session interception performed at the network perimeter
- On-site scanning of internal traffic captured from a switch port
- Operational security incident notification sent to the target's admins
Why would a tester use passive DNS lookups from a third-party historical database instead of querying the target's own authoritative name server?
- It avoids sending queries to the target that could be logged or trigger an alert
- It returns the current live IP address rather than a historical one
- It resolves internal, RFC 1918 addresses that public DNS cannot reach
- It automatically enumerates every subdomain registered under the domain
Vulnerability Discovery and Analysis
What is the key difference between an authenticated and an unauthenticated vulnerability scan?
- An authenticated scan logs in with valid credentials to check internal configuration
- An unauthenticated scan can only be launched from inside the target's own network
- An authenticated scan skips host discovery and jumps straight to exploitation
- An unauthenticated scan requires a signed API token issued by the scanner vendor
What does the acronym SAST stand for in the context of vulnerability discovery?
- System access security tracking performed at the network layer
- Static application security testing performed against source or binaries
- Sequential authentication scanning technique used against login forms
- Session-aware sandboxed testing conducted inside a container runtime
What is the primary difference between SAST and DAST?
- DAST analyzes source code line by line before it is ever compiled
- SAST can only be applied to applications written in a compiled language
- SAST analyzes code without executing it, while DAST tests the running application
- DAST requires read access to the application's version control history
Attacks and Exploits
What is VLAN hopping?
- A technique used to gain access to VLANs other than the attacker's assigned one
- A denial-of-service technique aimed directly at a DHCP relay agent
- A method for cloning the MAC address of a switch's uplink port
- A technique for cracking the passphrase on a WPA2 wireless network
What is the goal of an on-path, or man-in-the-middle, attack?
- To intercept and potentially alter traffic between two communicating parties
- To register a domain name that closely resembles the target's own brand
- To flood a target host with malformed packets until it stops responding
- To brute-force the login page of a target's web application
Which VLAN hopping technique relies on a switch port being left in dynamic trunking negotiation mode?
- Double tagging, which instead relies on a native VLAN mismatch condition
- MAC flooding, which overwhelms the switch's content-addressable memory table
- DHCP starvation, which targets the pool of available lease addresses
- Switch spoofing, where the attacker's host negotiates a trunk link directly
Post-Exploitation and Lateral Movement
What is the primary purpose of establishing persistence on a compromised host?
- To maintain access even after a reboot or if the initial exploit vector closes
- To increase the host's available disk space for later staging of tools
- To automatically patch the vulnerability that was originally exploited
- To register the host with a new, unauthorized DNS domain name
What is lateral movement in the context of a penetration test?
- Moving from an initially compromised host to other systems to expand access
- Migrating a compromised host's workload to a different physical data center
- Rotating the tester's own source IP address between scan attempts
- Renaming a compromised file to avoid matching an antivirus signature
What is the purpose of cleaning up artifacts at the end of a penetration test engagement?
- To remove tools or accounts so the environment returns to its pre-engagement state
- To generate the final invoice covering every hour billed during testing
- To archive the client's production logs for the duration of the engagement
- To reset every user's password across the domain before the report is delivered
Frequently Asked Questions
How many questions are on the exam?
The PenTest+ PT0-003 exam contains 90 questions.
What is the passing score?
You need 75% to pass.
How long is the exam?
You have 165 minutes to complete the exam.
More CompTIA Practice Exams
Practice with realistic mock exams to prepare for your CompTIA certification.