About the Exam

CompTIA PenTest+ PT0-003 is a penetration-testing certification exam. CompTIA recommends 3–4 years in a penetration tester job role for candidates taking it. The exam covers engagement management, reconnaissance and enumeration, vulnerability discovery and analysis, attacks and exploits, and post-exploitation and lateral movement. Passing demonstrates the ability to plan and scope a penetration test, perform authorized attacks with appropriate tools and techniques, analyze results, and produce a written report with practical recommendations.

Exam Topics

  • Engagement Management13%
  • Reconnaissance and Enumeration21%
  • Vulnerability Discovery and Analysis17%
  • Attacks and Exploits35%
  • Post-exploitation and Lateral Movement11%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated June 21, 2026 at 3:20 AM

Topic filter
Retired questions
Question sort
Questions per page

QuestionQ1

Attacks and Exploits

A penetration tester tries to access a domain-joined Windows file server that requires authentication. Which of the following would most likely help gain access?

Explanation

An NTLM relay attack can relay captured Windows authentication to an SMB file server and establish access in the relayed user’s security context when the target configuration permits it. Microsoft identifies SMB relay as a class of attack against SMB services using NTLM authentication.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Attacks and Exploits

A penetration tester has found sensitive files on a system. Assuming that exfiltrating the files is within the test scope, which option is most likely to evade DLP systems?

Explanation

Encoding data and exfiltrating it through DNS tunneling can evade many DLP controls because DNS is often permitted and receives less content inspection than common file-transfer, cloud-storage, or email channels. The encoding also reduces direct matching against sensitive-data patterns.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Reconnaissance and Enumeration

A penetration tester is performing a wireless security assessment for a client that has 2.4GHz and 5GHz access points. The tester inserts a wireless USB dongle into the laptop to begin capturing WPA2 handshakes. Which of the following should the tester do next?

Explanation

A wireless adapter must operate in monitor mode to passively capture the raw 802.11 frames needed to obtain a WPA2 handshake. The Aircrack-ng suite’s airmon-ng utility enables monitor mode on a wireless interface.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Reconnaissance and Enumeration

During a security audit, a penetration tester needs to run a process that gathers information about a target network’s domain structure and associated IP addresses. Which of the following tools should the tester use?

Explanation

Dnsenum is a DNS-enumeration tool that discovers DNS records, subdomains, name servers, and associated IP addresses for a target domain.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Attacks and Exploits

Which of the following is the LOLBin most likely to be used to carry out exfiltration in a Microsoft Windows environment?

Explanation

BITSAdmin can create upload jobs that transfer a local file to a server, making it suitable for data exfiltration. Microsoft documents the /UPLOAD job type for bitsadmin /transfer.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home