Free practice testPT0-003

Free CompTIA PenTest+ practice test

10 real PenTest+ questions, playable right now. No account, no card, no email gate. Every answer opens the full explanation: the concept, why the right option is right, and why each wrong option is wrong, cited to the authoritative documentation behind it.

Sample question 1 of 10

Specialized and embedded systemsAttacks and ExploitsModerate

You assess an IP camera and log in with admin/admin, a credential the firmware ships with that users cannot change. Which IoT Top 10 weakness is this?

Sample question 2 of 10

Reconnaissance scriptingReconnaissance and EnumerationModerate

A script has:

nmap -Pn 10.0.0.5 || echo "scan failed" >> errors.log

Under what condition is the failure logged?

Sample question 3 of 10

Vulnerability scanning types and configurationVulnerability Discovery and AnalysisHard

You must scan a fragile production network and cannot risk taking services down. Which choice most reduces that risk?

Sample question 4 of 10

Persistence mechanismsPost-exploitation and Lateral MovementEasy

You have shell access on a Linux host and append your public key to a user's ~/.ssh/authorized_keys. What have you set up?

Sample question 5 of 10

Testing frameworks and methodologiesEngagement ManagementModerate

An analyst reviewing a report sees the test WSTG-INFO-02. What does that identifier denote?

Sample question 6 of 10

Other web application attacksAttacks and ExploitsModerate

An image is served via ?filename=. On an authorized test you request:

?filename=../../../../etc/passwd

and receive the file. Which vulnerability is this?

Sample question 7 of 10

Web and application enumerationReconnaissance and EnumerationModerate

An automated crawler fetches one page during application mapping. How does it reach further pages of the site?

Sample question 8 of 10

Scanner tools and output interpretationVulnerability Discovery and AnalysisEasy

A scanner report lists cpe:/a:apache:http_server:2.4.49 beside a finding. What does a CPE string identify?

Sample question 9 of 10

Data staging and exfiltrationPost-exploitation and Lateral MovementModerate

You have collected files from several hosts and copy them all into C:\Windows\Temp\loot on one machine. What is this step?

Sample question 10 of 10

Scope and rules of engagementEngagement ManagementModerate

A client is concerned about service availability and approves stress testing. Where should that stress testing run?

Full PenTest+ question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

What this test covers

These 10 questions are drawn across the published exam blueprint rather than from one chapter: this set touches Attacks and Exploits, Reconnaissance and Enumeration, Vulnerability Discovery and Analysis, Post-exploitation and Lateral Movement, Engagement Management. Every question is original, written from the official objectives, and verified against a cited vendor page before it serves. None are recalled exam content, which is why the explanations can cite their sources.

A ten-question sample tells you where you stand, not whether you are ready. The full experience is numbered practice exams: 90 questions apportioned to the official domain weightings, sat under the real 165-minute clock and scored against the published cut score.

Keep reading

Every guide and cost breakdown, by vendor