dc dotCreds
CompTIA PenTest+ PT0-003 Practice Test

PenTest+ PT0-003 Practice Test

Start today’s free 10-question PenTest+ PT0-003 set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 10, 2026, 9:39 PM CDT

Go Pro - One Time Unlock

Unlock the full PT0-003 bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 PenTest+ PT0-003 questions

Use this PenTest+ PT0-003 practice test to review CompTIA PenTest+ PT0-003. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Evaluate AS-REP roasting exposure 4. Attacks and Exploits (35%)

As a security analyst, you are investigating an AS-REP roasting attack on your network. You notice that the attacker is exploiting accounts without Kerberos preauthentication to retrieve material for offline attacks. To mitigate this risk, what should be your next step?

Concept tested:
Question 2 of 10
Objective Analyze Active Directory movement paths 5. Post-exploitation and Lateral Movement (14%)

As a security analyst, you are investigating an Active Directory environment where multiple hosts have been compromised. You notice that a local administrator credential is reused across several hosts and there's evidence of lateral movement through group rights and remote services. However, the attack path does not clearly identify each prerequisite step for access. What should you do to improve the analysis?

Concept tested:
Question 3 of 10
Objective Analyze network-service weaknesses 3. Vulnerability Discovery and Analysis (17%)

You are conducting a network security assessment for a company that uses an open administrative service on its internal network. The service communicates using a legacy cleartext protocol, and you discover it can be reached from the internet due to misconfigured firewall rules. What is the best course of action to mitigate this risk?

Concept tested:
Question 4 of 10
Objective Apply scope inclusions and exclusions 1. Engagement Management (13%)

An in-scope office server exposes a share used by an expressly excluded satellite network. Testing the share could cross into the excluded environment, although the dependency was not documented initially. What should the tester do?

Concept tested:
Question 5 of 10
Objective Enumerate cloud assets and exposed services 2. Reconnaissance and Enumeration (21%)

As a security analyst, you are tasked with identifying exposed services in the cloud environment of a client company. During enumeration, you discover that a publicly named storage bucket has an access error when attempting to read its contents. Additionally, you find tenant identifiers that suggest potential unauthorized access attempts but do not confirm actual breaches. Given these findings and knowing that authorization boundaries between providers and customers are critical, what should be your next step?

Concept tested:
Question 6 of 10
Objective Document post-exploitation actions for reporting 5. Post-exploitation and Lateral Movement (14%)

During a penetration test, you have successfully exploited several systems and documented the actions taken. However, your report lacks clear timelines of events and does not include unsuccessful attempts that affected detection or operations. Additionally, some sensitive information is visible in the logs. What should be done to improve the post-exploitation documentation?

Concept tested:
Question 7 of 10
Objective Analyze identity and access weaknesses 3. Vulnerability Discovery and Analysis (17%)

As a penetration tester, you've identified that an employee's account has been inactive for over six months but still holds administrative privileges. The system uses strong authentication methods and does not show any signs of recent unauthorized access attempts. What should be your next step to address this identity and access management weakness?

Concept tested:
Question 8 of 10
Objective Use the communication and escalation plan 1. Engagement Management (13%)

During a penetration test, an unexpected critical vulnerability is discovered that could potentially compromise user data. The engagement plan includes regular reporting cadence but no immediate escalation path for such findings. What should the tester do?

Concept tested:
Question 9 of 10
Objective Exploit a vulnerable network service safely 4. Attacks and Exploits (35%)

A public exploit claims to affect the service, but the banner is ambiguous and the exploit may destabilize production. What should the tester do before adapting or running it?

Concept tested:
Question 10 of 10
Objective Use public records for organizational OSINT 2. Reconnaissance and Enumeration (21%)

While performing OSINT, you find public records indicating that a company's legal name has changed recently. The new business entity is suspected to be the target of your penetration test. What should you do next?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
PT0-003 Pro $4.99 one-time

Unlock all 200 PenTest+ PT0-003 questions, explanations, review tools, and exam-style practice.

50 Exam Practice Test $1.99 one-time

A 50-question PT0-003 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full PT0-003 bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily PT0-003 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily PenTest+ PT0-003 set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 As a security analyst, you are investigating an AS-REP roasting attack on your network. You notice that the attacker is exploiting accounts without Kerberos preauthentication to retrieve material for offline attacks. To mitigate this risk, what should be your next step?

Answer choices

  1. A. Implement stronger password policies across the board.
  2. B. Enable Kerberos preauthentication for all affected accounts.
  3. C. Disable all service tickets for high-risk services.
  4. D. Increase network monitoring and alerting thresholds.

Correct answer

Enable Kerberos preauthentication for all affected accounts.

AS-REP roasting exploits accounts lacking Kerberos preauthentication, allowing attackers to retrieve material for offline attacks. Enabling Kerberos preauthentication prevents this by requiring authentication before material is released.

Wrong-answer review

  • A. Implement stronger password policies across the board.: Accounts without Kerberos preauthentication are vulnerable to AS-REP roasting, making this the most direct mitigation strategy.
  • C. Disable all service tickets for high-risk services.: Disabling service tickets is a broader action that doesn't specifically address the AS-REP roasting vulnerability.
  • D. Increase network monitoring and alerting thresholds.: Increased monitoring won't prevent the attack; it only provides visibility after exploitation has occurred.

Extra learning features

Interview question

Q: Describe the immediate steps to mitigate an AS-REP roasting attack, and explain why those steps are prioritized over broader security improvements. Strong answer: Enable Kerberos preauthentication for all affected accounts. Accounts without Kerberos preauthentication are vulnerable to AS-REP roasting, making this the most direct mitigation strategy.

  • Accounts without Kerberos preauthentication are vulnerable to AS-REP roasting
  • AS-REP roasting applies to accounts configured without Kerberos preauthentication
  • Enabling preauthentication prevents the retrieval of material

Caution: This question is about the immediate response to the attack, not a general security improvement.

Why this matters

AS-REP roasting exploits accounts lacking Kerberos preauthentication, allowing attackers to retrieve material for offline attacks. Enabling Kerberos preauthentication prevents this by requiring authentication before material is released. This prevents the immediate compromise of sensitive data and reduces the attack surface.

Objective/domain: 4. Attacks and Exploits (35%)

Source: MITRE ATT&CK Enterprise Matrix

Question 2 As a security analyst, you are investigating an Active Directory environment where multiple hosts have been compromised. You notice that a local administrator credential is reused across several hosts and there's evidence of lateral movement through group rights and remote services. However, the attack path does not clearly identify each prerequisite step for access. What should you do to improve the analysis?

Answer choices

  1. A. Assume transitive access based on domain membership alone.
  2. B. Ignore unsuccessful attempts since they did not result in a breach.
  3. C. Document each specific prerequisite step required for lateral movement.
  4. D. Focus solely on identifying systems and identities involved.

Correct answer

Document each specific prerequisite step required for lateral movement.

Objective/domain: 5. Post-exploitation and Lateral Movement (14%)

Source: MITRE ATT&CK Enterprise Matrix

Question 3 You are conducting a network security assessment for a company that uses an open administrative service on its internal network. The service communicates using a legacy cleartext protocol, and you discover it can be reached from the internet due to misconfigured firewall rules. What is the best course of action to mitigate this risk?

Answer choices

  1. A. Treat the service as internal because public exposure was unintended
  2. B. Block public traffic without checking whether other controls apply
  3. C. Verify encryption or access restrictions before assuming exposure is controlled
  4. D. Replace the protocol before confirming current exposure and controls

Correct answer

Verify encryption or access restrictions before assuming exposure is controlled

Objective/domain: 3. Vulnerability Discovery and Analysis (17%)

Source: Technical Guide to Information Security Testing and Assessment, SP 800-115

Question 4 An in-scope office server exposes a share used by an expressly excluded satellite network. Testing the share could cross into the excluded environment, although the dependency was not documented initially. What should the tester do?

Answer choices

  1. A. Test the share because it is attached to an in-scope server
  2. B. Continue because the satellite network was not listed in the rules
  3. C. Document dependency, avoid the exclusion, and request scope approval
  4. D. Stop the entire engagement because the dependency was undocumented

Correct answer

Document dependency, avoid the exclusion, and request scope approval

Objective/domain: 1. Engagement Management (13%)

Source: CompTIA PenTest+ PT0-003 Exam Objectives, Version 3.0

Question 5 As a security analyst, you are tasked with identifying exposed services in the cloud environment of a client company. During enumeration, you discover that a publicly named storage bucket has an access error when attempting to read its contents. Additionally, you find tenant identifiers that suggest potential unauthorized access attempts but do not confirm actual breaches. Given these findings and knowing that authorization boundaries between providers and customers are critical, what should be your next step?

Answer choices

  1. A. Ignore the access errors as they indicate no public readability issues.
  2. B. Immediately report all tenant identifiers as evidence of security breaches.
  3. C. Review client IAM policies for authorization boundaries
  4. D. Disable all publicly named resources to prevent further unauthorized access.

Correct answer

Review client IAM policies for authorization boundaries

Objective/domain: 2. Reconnaissance and Enumeration (21%)

Source: Cloud Computing Forensic Reference Architecture, SP 800-201

Question 6 During a penetration test, you have successfully exploited several systems and documented the actions taken. However, your report lacks clear timelines of events and does not include unsuccessful attempts that affected detection or operations. Additionally, some sensitive information is visible in the logs. What should be done to improve the post-exploitation documentation?

Answer choices

  1. A. Remove all timestamps from the timeline for confidentiality.
  2. B. Focus only on successful actions and ignore system artifacts.
  3. C. Exclude unsuccessful attempts as they are not relevant to the breach.
  4. D. Include a detailed timeline with redacted secrets but retaining evidence value.

Correct answer

Include a detailed timeline with redacted secrets but retaining evidence value.

Objective/domain: 5. Post-exploitation and Lateral Movement (14%)

Source: Technical Guide to Information Security Testing and Assessment, SP 800-115

Question 7 As a penetration tester, you've identified that an employee's account has been inactive for over six months but still holds administrative privileges. The system uses strong authentication methods and does not show any signs of recent unauthorized access attempts. What should be your next step to address this identity and access management weakness?

Answer choices

  1. A. Reset the password immediately.
  2. B. Reduce the user's privilege level to a minimum necessary role.
  3. C. Conduct additional testing to confirm if the account is compromised.
  4. D. Implement lifecycle controls for dormant accounts.

Correct answer

Implement lifecycle controls for dormant accounts.

Objective/domain: 3. Vulnerability Discovery and Analysis (17%)

Source: Digital Identity Guidelines: Authentication and Authenticator Management, SP 800-63B

Question 8 During a penetration test, an unexpected critical vulnerability is discovered that could potentially compromise user data. The engagement plan includes regular reporting cadence but no immediate escalation path for such findings. What should the tester do?

Answer choices

  1. A. Contact the client's designated emergency contact immediately.
  2. B. Wait until the next scheduled report to inform the client.
  3. C. Document the finding and proceed with planned testing activities.
  4. D. Pause all testing activities until a new engagement plan is agreed upon.

Correct answer

Contact the client's designated emergency contact immediately.

Objective/domain: 1. Engagement Management (13%)

Source: Technical Guide to Information Security Testing and Assessment, SP 800-115

Question 9 A public exploit claims to affect the service, but the banner is ambiguous and the exploit may destabilize production. What should the tester do before adapting or running it?

Answer choices

  1. A. Run the original exploit against production to resolve the version uncertainty.
  2. B. Abandon the finding because an unverified banner is never useful evidence.
  3. C. Validate prerequisites, then reproduce the exploit in a controlled environment
  4. D. Report confirmed code execution because the public exploit exists.

Correct answer

Validate prerequisites, then reproduce the exploit in a controlled environment

Objective/domain: 4. Attacks and Exploits (35%)

Source: Technical Guide to Information Security Testing and Assessment, SP 800-115

Question 10 While performing OSINT, you find public records indicating that a company's legal name has changed recently. The new business entity is suspected to be the target of your penetration test. What should you do next?

Answer choices

  1. A. Verify if the change in legal name affects the scope and current assets of the engagement.
  2. B. Immediately proceed with testing based on the updated legal information.
  3. C. Ignore the legal name change as it does not impact the technical aspects of the test.
  4. D. Report the discrepancy to your supervisor for further instructions.

Correct answer

Verify if the change in legal name affects the scope and current assets of the engagement.

Objective/domain: 2. Reconnaissance and Enumeration (21%)

Source: CompTIA PenTest+ PT0-003 Exam Objectives, Version 3.0

Where to go after the daily web set

How are PenTest+ PT0-003 questions generated?

dotCreds builds PenTest+ PT0-003 practice questions from public exam objectives and CompTIA exam objectives and source-backed references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start PenTest+ PT0-003 practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.