CompTIA PenTest+ (PT0-002) Advanced
Practice Examination: Comprehensive 150-
Question Multiple-Choice Assessment Covering
Planning, Scoping, Reconnaissance,
Vulnerability Scanning, Exploitation
Techniques, Post-Exploitation, Reporting, and
Tools Analysis for Cybersecurity Professionals
a well detailed one written and
graded A+ upgraded
Domain 1: Planning and Scoping (Questions 1–21)
Question 1
A penetration tester is hired to conduct an assessment with no prior knowledge of the internal
network. The client provides only the company name and public IP range. Which type of
engagement is this?
A. White box
B. Gray box
C. Black box
D. Crystal box
-” detailed answer 100 % correct :-”C
, 2
Rationale: A black-box test simulates an external attacker with zero prior knowledge of the
target environment. The tester receives only publicly available information and must discover
everything through reconnaissance. White-box testing provides full knowledge, and gray-box
testing provides partial knowledge.
Question 2
Which document explicitly defines the rules of engagement (ROE), including scope, timeline,
goals, and testing boundaries for a penetration test?
A. Non-Disclosure Agreement (NDA)
B. Statement of Work (SOW)
C. Service Level Agreement (SLA)
D. Master Services Agreement (MSA)
-” detailed answer 100 % correct :-”B
Rationale: The SOW defines the ROE, including scope, timeline, goals, and testing
boundaries. An NDA protects confidentiality, an SLA defines service performance metrics, and
an MSA is a framework for future agreements.
Question 3
A compliance-based penetration test is primarily concerned with:
A. Obtaining personally identifiable information (PII) from the protected network
B. Bypassing protection on edge devices
C. Determining the efficacy of a specific set of security standards
D. Obtaining specific information from the protected network
-” detailed answer 100 % correct :-”C
Rationale: Compliance-based testing ensures that an organization meets specific regulatory or
security standards (e.g., PCI DSS, HIPAA). It focuses on verifying control effectiveness rather than
simply obtaining data.
Question 4
A penetration tester wants to ensure that the test does not disrupt business operations. Which
of the following would be the best approach?
, 3
A. Perform the test only during business hours
B. Ask the client to shut down critical systems
C. Schedule the test during a maintenance window with clear rollback procedures
D. Use only passive reconnaissance techniques
-” detailed answer 100 % correct :-”C
Rationale: Scheduling during a maintenance window with explicit rollback procedures
minimizes the risk of business disruption. Active testing can still be performed, but with
controlled conditions and established contingency plans.
Question 5
A client requests a penetration test that simulates an attack from a malicious insider with
standard user credentials. Which testing methodology should the tester employ?
A. Black-box testing
B. Gray-box testing with standard user privileges
C. White-box testing with administrative privileges
D. Red-team engagement
-” detailed answer 100 % correct :-”B
Rationale: Gray-box testing provides the tester with partial knowledge or limited access, such as
standard user credentials. This simulates an insider threat scenario where the attacker has some
internal access but not full administrative control.
Question 6
Which of the following is the PRIMARY purpose of a penetration testing rules of engagement
(ROE) document?
A. To establish billing rates and payment terms
B. To define legal boundaries, permitted techniques, and emergency stop conditions
C. To list all vulnerabilities discovered during testing
D. To provide technical specifications for remediation
-” detailed answer 100 % correct :-”B
Rationale: The ROE document defines the legal boundaries, permitted testing techniques, scope
limitations, and emergency stop (call-out) conditions that protect both the tester and the client
during the engagement.
, 4
Question 7
A penetration tester is engaged for a test where the client provides network diagrams, source
code, and administrative credentials. This is an example of:
A. Black-box testing
B. Gray-box testing
C. White-box testing
D. Double-blind testing
-” detailed answer 100 % correct :-”C
Rationale: White-box testing (also known as crystal-box or clear-box testing) provides the tester
with full knowledge of the target environment, including network diagrams, source code, and
administrative credentials.
Question 8
What is the primary difference between a vulnerability assessment and a penetration test?
A. Vulnerability assessments are always automated; penetration tests are always manual
B. Vulnerability assessments identify potential weaknesses; penetration tests exploit
weaknesses to demonstrate impact
C. Vulnerability assessments require source code access; penetration tests do not
D. There is no meaningful difference between the two
-” detailed answer 100 % correct :-”B
Rationale: Vulnerability assessments identify and report potential weaknesses, while
penetration tests actively exploit those weaknesses to demonstrate real-world impact and
validate the severity of findings.
Question 9
A penetration tester discovers a critical vulnerability during the assessment that could allow
immediate unauthorized access to sensitive data. The ROE does not specifically address this
scenario. What should the tester do FIRST?
A. Exploit the vulnerability to demonstrate maximum impact
B. Immediately notify the client point of contact