dc dotCreds
CompTIA PenTest+ PT0-003 Practice Test

PenTest+ PT0-003 Practice Test

Start today’s free 10-question PenTest+ PT0-003 set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 23, 2026, 8:12 PM CDT

Go Pro - One Time Unlock

Unlock the full PT0-003 bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 PenTest+ PT0-003 questions

Use this PenTest+ PT0-003 practice test to review CompTIA PenTest+ PT0-003. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Select a network discovery method 2. Reconnaissance and Enumeration (21%)

As a penetration tester, you are tasked with discovering hosts on a network segment where standard ICMP echo requests are blocked by firewalls. You have identified that TCP SYN probes are allowed through the firewall but may be rate-limited to avoid detection. What method should you use for host discovery while respecting operational constraints?

Concept tested:
Question 2 of 10
Objective Use the communication and escalation plan 1. Engagement Management (13%)

During a penetration test, an unexpected critical vulnerability is discovered that could potentially compromise user data. The engagement plan includes regular reporting cadence but no immediate escalation path for such findings. What should the tester do?

Concept tested:
Question 3 of 10
Objective Enumerate SMTP without sending abuse 2. Reconnaissance and Enumeration (21%)

An SMTP service advertises several command capabilities. The rules allow banner and capability checks but prohibit authentication attempts and message delivery. What should the tester do next?

Concept tested:
Question 4 of 10
Objective Assess mobile application weaknesses 3. Vulnerability Discovery and Analysis (17%)

During a mobile app test, you find that the application stores sensitive data locally without proper encryption and uses client-side obfuscation to protect API keys. What should be your recommendation for addressing this issue?

Concept tested:
Question 5 of 10
Objective Exploit excessive cloud IAM permission safely 4. Attacks and Exploits (35%)

During a cloud penetration test, you discover that an IAM role allows full access to all resources in the AWS account. To demonstrate excessive permissions without causing unnecessary damage, what is the best course of action?

Concept tested:
Question 6 of 10
Objective Use pivoting and tunneling safely 5. Post-exploitation and Lateral Movement (14%)

You are pivoting through a compromised server to reach another network during a penetration test. To ensure that you do not inadvertently expose additional networks, what is the safest approach?

Concept tested:
Question 7 of 10
Objective Preserve evidence integrity 1. Engagement Management (13%)

During a penetration test, you discover that one of your team members has collected evidence in an unrepeatable manner without proper documentation. This could compromise the integrity of the evidence. What should be done to ensure the evidence remains credible and can support legal or disciplinary actions if necessary?

Concept tested:
Question 8 of 10
Objective Choose passive or active reconnaissance 2. Reconnaissance and Enumeration (21%)

During a penetration test, you need to gather information about a target system without triggering alarms. Which method should you use?

Concept tested:
Question 9 of 10
Objective Review source code for security defects 3. Vulnerability Discovery and Analysis (17%)

While reviewing source code for a web application, you find that input is sanitized before reaching a SQL query, but the sanitizer uses a different interpreter or context from the one executing that query. What should the reviewer conclude?

Concept tested:
Question 10 of 10
Objective Test default and weak service credentials 4. Attacks and Exploits (35%)

While testing a network service, you find that it uses default credentials. You are unsure if these credentials have been changed since deployment or if they represent an unauthenticated state of the service. What should be your next step?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
PT0-003 Pro $4.99 one-time

50 Exam Practice Test $1.99 one-time

A 50-question PT0-003 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

CompTIA Cybersecurity Bundle $9.99 one-time

Unlock all 4 active CompTIA Cybersecurity Bundle practice banks in one permanent purchase.

What’s includedSecurity+, CySA+, PenTest+, SecurityX
All Access $6.99/month

Unlock every active practice exam, bundle and path experience, Pro course and study content, and included downloads.

What’s includedEvery current and future active practice exam, All active bundle and career-path practice content, Pro course lessons, study content, and supported paid downloads

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full PT0-003 bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily PT0-003 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily PenTest+ PT0-003 set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 As a penetration tester, you are tasked with discovering hosts on a network segment where standard ICMP echo requests are blocked by firewalls. You have identified that TCP SYN probes are allowed through the firewall but may be rate-limited to avoid detection. What method should you use for host discovery while respecting operational constraints?

Answer choices

  1. A. Use continuous high-rate ICMP echo requests to overwhelm the firewall.
  2. B. Send a single TCP ACK probe to each IP address on the segment.
  3. C. Ignore the firewall and use UDP probes across all ports for rapid discovery.
  4. D. Implement a slow, staggered TCP SYN scan with appropriate timing intervals.

Correct answer

Implement a slow, staggered TCP SYN scan with appropriate timing intervals.

Host discovery methods vary in their reliability and visibility, and firewalls can selectively block probes. A slow, staggered TCP SYN scan respects operational constraints while still allowing for host identification.

Wrong-answer review

  • A. Use continuous high-rate ICMP echo requests to overwhelm the firewall.: ICMP echo requests are easily blocked by firewalls, making them an unreliable method for host discovery and potentially triggering alerts.
  • B. Send a single TCP ACK probe to each IP address on the segment.: A single TCP ACK probe is not a standard host discovery technique and will likely be ignored or misinterpreted by the target system.
  • C. Ignore the firewall and use UDP probes across all ports for rapid discovery.: UDP probes are often unreliable due to their connectionless nature and can generate a large amount of noise on the network.

Extra learning features

Why candidates miss this

The use of continuous high-rate ICMP echo requests to overwhelm the firewall is tempting because it appears to be a brute-force approach. The decisive clue that eliminates it is the explicit constraint of respecting operational constraints, as this method is highly likely to trigger alerts and cause disruption. Likely wrong answer: Use continuous high-rate ICMP echo requests to overwhelm the firewall. Review focus: Technical Guide to Information Security Testing and Assessment, SP 800-115

Interview question

Q: Host discovery methods vary in their reliability and visibility, and firewalls can block one probe type while the host remains reachable by another permitted method. A lack of response is not definitive proof that a host does not exist. Scan rate and timing should respect operational constraints. What considerations guide the selection of a host discovery method in a constrained environment? Strong answer: The slow, staggered TCP SYN scan respects operational constraints while still allowing for host identification.

  • operational constraints
  • firewall blocking
  • host identification
  • scan rate and timing

Caution: Do not restate the multiple-choice stem or ask the learner merely to name a product, rule, or term.

Why this matters

A slow, staggered TCP SYN scan respects operational constraints while still allowing for host identification. Failure to do so could result in network disruption or detection by intrusion detection systems, leading to immediate service interruption and potential legal repercussions. This is a critical consideration for maintaining operational stability and avoiding negative consequences.

Objective/domain: 2. Reconnaissance and Enumeration (21%)

Source: Technical Guide to Information Security Testing and Assessment, SP 800-115

Question 2 During a penetration test, an unexpected critical vulnerability is discovered that could potentially compromise user data. The engagement plan includes regular reporting cadence but no immediate escalation path for such findings. What should the tester do?

Answer choices

  1. A. Contact the client's designated emergency contact immediately.
  2. B. Wait until the next scheduled report to inform the client.
  3. C. Document the finding and proceed with planned testing activities.
  4. D. Pause all testing activities until a new engagement plan is agreed upon.

Correct answer

Contact the client's designated emergency contact immediately.

Objective/domain: 1. Engagement Management (13%)

Source: Technical Guide to Information Security Testing and Assessment, SP 800-115

Question 3 An SMTP service advertises several command capabilities. The rules allow banner and capability checks but prohibit authentication attempts and message delivery. What should the tester do next?

Answer choices

  1. A. Validate capabilities with safe non-delivery commands; document the surface
  2. B. Send a test message to a known address to prove that the server accepts mail.
  3. C. Try credentials over the advertised AUTH mechanism because the service disclosed it.
  4. D. Treat the capability banner as proof that the server permits unauthenticated relay.

Correct answer

Validate capabilities with safe non-delivery commands; document the surface

Objective/domain: 2. Reconnaissance and Enumeration (21%)

Source: CompTIA PenTest+ PT0-003 Exam Objectives, Version 3.0

Question 4 During a mobile app test, you find that the application stores sensitive data locally without proper encryption and uses client-side obfuscation to protect API keys. What should be your recommendation for addressing this issue?

Answer choices

  1. A. Suggest implementing stronger client-side obfuscation techniques.
  2. B. Propose embedding additional secrets in the application to confuse attackers.
  3. C. Advise the removal of all sensitive data from local storage.
  4. D. Recommend using server-side authorization instead of relying on client-side measures.

Correct answer

Recommend using server-side authorization instead of relying on client-side measures.

Objective/domain: 3. Vulnerability Discovery and Analysis (17%)

Source: Mobile Application Security Verification Standard

Question 5 During a cloud penetration test, you discover that an IAM role allows full access to all resources in the AWS account. To demonstrate excessive permissions without causing unnecessary damage, what is the best course of action?

Answer choices

  1. A. Grant yourself full admin rights and document findings.
  2. B. Use the least impactful method to prove permission excess.
  3. C. Create a new S3 bucket with public read access to test.
  4. D. Ignore the finding as it's not within your authorized scope.

Correct answer

Use the least impactful method to prove permission excess.

Objective/domain: 4. Attacks and Exploits (35%)

Source: Cloud Computing Forensic Reference Architecture, SP 800-201

Question 6 You are pivoting through a compromised server to reach another network during a penetration test. To ensure that you do not inadvertently expose additional networks, what is the safest approach?

Answer choices

  1. A. Establish a tunnel without documenting routes.
  2. B. Use pivot points to control and document routes
  3. C. Transfer all data directly between target systems.
  4. D. Ignore new networks discovered through pivoting.

Correct answer

Use pivot points to control and document routes

Objective/domain: 5. Post-exploitation and Lateral Movement (14%)

Source: MITRE ATT&CK Enterprise Matrix

Question 7 During a penetration test, you discover that one of your team members has collected evidence in an unrepeatable manner without proper documentation. This could compromise the integrity of the evidence. What should be done to ensure the evidence remains credible and can support legal or disciplinary actions if necessary?

Answer choices

  1. A. Ignore the issue as long as the evidence appears valid.
  2. B. Discard all improperly collected evidence and start over from scratch.
  3. C. Document collection time, source, collector, and context
  4. D. Transfer responsibility to another team member without addressing the documentation issues.

Correct answer

Document collection time, source, collector, and context

Objective/domain: 1. Engagement Management (13%)

Source: Technical Guide to Information Security Testing and Assessment, SP 800-115

Question 8 During a penetration test, you need to gather information about a target system without triggering alarms. Which method should you use?

Answer choices

  1. A. Perform an active scan using Nmap.
  2. B. Contact the client's IT department for access details.
  3. C. Use passive reconnaissance techniques like sniffing network traffic.
  4. D. Request permission from the client to perform active scans.

Correct answer

Use passive reconnaissance techniques like sniffing network traffic.

Objective/domain: 2. Reconnaissance and Enumeration (21%)

Source: Technical Guide to Information Security Testing and Assessment, SP 800-115

Question 9 While reviewing source code for a web application, you find that input is sanitized before reaching a SQL query, but the sanitizer uses a different interpreter or context from the one executing that query. What should the reviewer conclude?

Answer choices

  1. A. Trace the value to the SQL sink and validate it in execution context
  2. B. Replace the sanitizer without tracing the query path or confirming how the application interprets the value.
  3. C. Conclude that the sanitizer is effective because it runs before the query is built.
  4. D. Add logging and treat the logged input as evidence that the query is protected.

Correct answer

Trace the value to the SQL sink and validate it in execution context

Objective/domain: 3. Vulnerability Discovery and Analysis (17%)

Source: Secure Software Development Framework, SP 800-218

Question 10 While testing a network service, you find that it uses default credentials. You are unsure if these credentials have been changed since deployment or if they represent an unauthenticated state of the service. What should be your next step?

Answer choices

  1. A. Test for authentication without attempting further access.
  2. B. Immediately report the use of default credentials.
  3. C. Attempt to authenticate using known default credentials.
  4. D. Cease testing and inform management of potential risks.

Correct answer

Test for authentication without attempting further access.

Objective/domain: 4. Attacks and Exploits (35%)

Source: Digital Identity Guidelines: Authentication and Authenticator Management, SP 800-63B

Where to go after the daily web set

How are PenTest+ PT0-003 questions generated?

dotCreds builds PenTest+ PT0-003 practice questions from public exam objectives and CompTIA exam objectives and source-backed references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start PenTest+ PT0-003 practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.