TechNuggets Academy
PT0-003

Free CompTIA PenTest+ Practice Test

12 exam-style questions with full explanations — no sign-up. Score yourself, then close your gaps with the full course.

Exam fee ~$4045 exam domainsLevel Intermediate2 timed practice tests in the course
✅ Free practice — no sign-up📝 Real exam-style questions💡 Detailed explanations💸 30-day money-back via Udemy
Question 1 of 12 · Engagement Management
During an active external penetration test, a tester notices unusual login activity from an unfamiliar foreign IP address against the target's VPN concentrator that appears unrelated to the authorized testing activity. The tester has not generated any traffic toward that system. Which action should the tester take FIRST?
Suspected real-world compromise discovered during testing is a critical escalation event. The rules of engagement (RoE) define emergency contacts and escalation procedures precisely for this scenario, and the tester must notify the client immediately so the client can respond to a potential active incident.
Question 2 of 12 · Reconnaissance and Enumeration
During a scoped external engagement, the client requires that testers avoid any direct interaction with in-scope hosts during the initial subdomain discovery phase. Which technique BEST meets this requirement while still identifying subdomains associated with the target's SSL/TLS certificates?
Certificate Transparency log searches (e.g., via crt.sh) are purely passive — they query a third-party public log of issued certificates and never touch the target's infrastructure, satisfying the no-direct-interaction requirement while still revealing subdomains from SAN entries.
Question 3 of 12 · Vulnerability Discovery and Analysis
A penetration tester's automated scanner flags a Windows server as critically vulnerable to MS17-010 (EternalBlue). The tester attempts exploitation with a known Metasploit module, but it fails, and manual SMB banner analysis confirms the security patch has been applied. Which of the following is the BEST action for the tester to take?
Manual verification (failed exploit attempt plus banner analysis) confirms the vulnerability is not actually present, so the scanner result should be documented as a false positive with supporting evidence — this is core to the validation/analysis phase of vulnerability assessment.
Question 4 of 12 · Attacks and Exploits
During an authorized internal Active Directory engagement, a tester has valid low-privilege domain credentials but no administrative rights. The goal is privilege escalation by targeting service accounts that may have weak passwords. Which technique BEST accomplishes this within scope?
Any authenticated domain user can request TGS service tickets for accounts with SPNs and attempt to crack the encrypted ticket offline, requiring no elevated privileges — ideal for a low-privilege starting position.
Question 5 of 12 · Post-exploitation and Lateral Movement
During an authorized internal penetration test, you compromise a dual-homed Linux server that has an interface on the 10.10.20.0/24 segment, which is not directly reachable from your attack workstation. You need to run Nmap and other tools against hosts in that segment through the compromised server. Which approach BEST accomplishes this within the rules of engagement?
SSH dynamic port forwarding creates a SOCKS proxy on the compromised host; combined with proxychains, this allows arbitrary tools (like Nmap) to route traffic into the otherwise unreachable segment with minimal footprint and easy teardown.
Question 6 of 12 · Engagement Management
A penetration testing firm is engaged to test a client's web application. Two weeks into the engagement, the client's project manager verbally asks the test team to also assess a newly acquired subsidiary's network that was not included in the original scope. What should the test team do?
Any change to engagement scope, including new targets, requires formal written authorization amending the SOW/RoE. Verbal approval is not sufficient legal protection for the tester or evidence of authorized access for the new target.
Question 7 of 12 · Reconnaissance and Enumeration
The rules of engagement explicitly prohibit OS fingerprinting and traceroute activity, but service version detection and default NSE scripts are approved. The target's firewall blocks ICMP echo requests. Which Nmap command satisfies all of these constraints against host 10.10.10.5?
-Pn skips host discovery (needed since ICMP is blocked and the host would otherwise appear down), -sV performs service version detection, and -sC runs the default safe NSE script set — none of which perform OS fingerprinting or traceroute.
Question 8 of 12 · Vulnerability Discovery and Analysis
A tester needs to identify known CVEs affecting the third-party open-source libraries bundled inside a client's Java application, without executing the application. Which technique is BEST suited for this task?
SCA tools inventory third-party and open-source dependencies and cross-reference them against known CVE databases without needing to run or fuzz the application.
Question 9 of 12 · Attacks and Exploits
A tester is authorized to assess wireless security. Employees are known to connect to a WPA2-Enterprise SSID named 'Corp-Secure' from a nearby office building. Which attack technique BEST allows the tester to capture wireless client credentials in this authorized engagement?
An evil twin AP paired with a rogue RADIUS server tricks clients into sending EAP credentials to the attacker, which is the standard method for harvesting credentials against WPA2-Enterprise.
Question 10 of 12 · Post-exploitation and Lateral Movement
During a multi-day authorized internal assessment, you need to maintain access to a compromised Windows workstation. The client's rules of engagement require that any persistence mechanism be easily identifiable and fully removable at the end of testing. Which method BEST satisfies this requirement?
A clearly named, documented scheduled task provides straightforward persistence and can be trivially located and deleted at engagement close, satisfying the requirement for identifiability and clean removal.
Question 11 of 12 · Engagement Management
What is the primary purpose of establishing a deconfliction point of contact before a penetration test begins?
The deconfliction contact is a designated individual (often on the blue team or IT security staff) who can be reached to verify that alerts triggered during the engagement are the result of authorized testing, avoiding wasted incident response effort or accidental law enforcement involvement.
Question 12 of 12 · Reconnaissance and Enumeration
A tester has valid low-privilege domain credentials in scope and needs to quickly enumerate accessible SMB shares across an entire /24 subnet of Windows hosts. Which command is BEST suited for this task?
CrackMapExec (CME) is designed to authenticate with supplied credentials across an entire subnet in a single command and enumerate SMB shares on every reachable host, making it the efficient choice for this scenario.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →

PT0-003 exam — quick answers

How much does the PT0-003 exam cost?

The exam fee is approximately $404 and varies by region — confirm current pricing with the certification vendor before you book.

What topics are on the exam?

It covers 5 domains: Engagement Management (13%), Reconnaissance and Enumeration (21%), Vulnerability Discovery and Analysis (17%), Attacks and Exploits (35%), Post-exploitation and Lateral Movement (14%). The full course has a dedicated chapter, lab and practice-test coverage for each.

Is this practice test really free?

Yes — all questions on this page are free with explanations and no sign-up. The paid Udemy course adds two full-length timed exams, video lessons and hands-on labs.

Will this prepare me for the real exam?

The questions mirror the real exam's style and are mapped to the official domains. This is exam-focused preparation — combine the free test with the full course's timed simulations to gauge your readiness.

More free practice by exam domain:
Engagement Management →Reconnaissance and Enumeration →Vulnerability Discovery and Analysis →Attacks and Exploits →