Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 61 pages
Exam (elaborations)

CompTIA PenTest+ (PT0-002) Advanced Practice Examination v2.0 a well detailed one 2025 / 2026 written and graded A+ upgraded Comprehensive 150-Question Multiple-Choice Assessment Covering Planning and Scoping, Information Gathering and Vulner

Document preview thumbnail
Preview 4 out of 61 pages

CompTIA PenTest+ (PT0-002) Advanced Practice Examination v2.0 a well detailed one 2025 / 2026 written and graded A+ upgraded Comprehensive 150-Question Multiple-Choice Assessment Covering Planning and Scoping, Information Gathering and Vulnerability Scanning, Attacks and Exploits, Reporting and Communication, and Tools and Code Analysis for Cybersecurity Professionals

Content preview

1




CompTIA PenTest+ (PT0-002) Advanced
Practice Examination v2.0 a well detailed
one written and graded A+
upgraded Comprehensive 150-Question
Multiple-Choice Assessment Covering
Planning and Scoping, Information
Gathering and Vulnerability Scanning,
Attacks and Exploits, Reporting and
Communication, and Tools and Code
Analysis for Cybersecurity Professionals

, 2




Domain 1: Planning and Scoping (Questions 1–21)

Question 1
A client requests a penetration test that specifically excludes social engineering and physical
security testing. Which document should explicitly state these restrictions?

A. Non-Disclosure Agreement (NDA)
B. Rules of Engagement (ROE)
C. Vulnerability scan report
D. Service Level Agreement (SLA)

-” detailed answer 100 % correct :-”B

Rationale: The ROE document defines the boundaries of the engagement, including what
techniques are permitted and what is explicitly excluded. Social engineering and physical testing
restrictions should be clearly documented in the ROE to prevent misunderstandings and legal
issues.



Question 2
A penetration tester is hired to perform an assessment where the client provides network
diagrams, but no credentials or source code. This is best described as:

A. Black-box testing
B. Gray-box testing
C. White-box testing
D. Double-blind testing

-” detailed answer 100 % correct :-”B

Rationale: Gray-box testing provides the tester with partial knowledge of the target
environment, such as network diagrams, but not full access or credentials. This simulates an
attacker with some internal knowledge.



Question 3
Which of the following is the MOST critical element to obtain before beginning any penetration
testing activity?

, 3



A. A list of all employee usernames
B. Written authorization from the client
C. The client's firewall configuration
D. A copy of the client's disaster recovery plan

-” detailed answer 100 % correct :-”B

Rationale: Written authorization is legally required before conducting any penetration testing
activities. Without it, the tester could face legal consequences under computer fraud laws. This
authorization should be documented in the ROE or SOW.



Question 4
A penetration tester discovers a critical vulnerability during an engagement that allows access to
sensitive customer data. The ROE states that data exfiltration is not permitted. What should the
tester do?

A. Exfiltrate a small sample of data to demonstrate impact
B. Document the vulnerability and demonstrate access without exfiltrating data
C. Ignore the vulnerability and continue testing
D. Immediately delete all evidence of the vulnerability

-” detailed answer 100 % correct :-”B

Rationale: The tester must respect the ROE boundaries. If data exfiltration is prohibited, the
tester should demonstrate the vulnerability's impact by showing proof of access without
actually extracting data, maintaining ethical and legal compliance.



Question 5
A compliance-driven penetration test is required for an organization that processes credit card
payments. Which regulatory standard is MOST likely driving this requirement?

A. HIPAA
B. PCI DSS
C. GDPR
D. SOX

-” detailed answer 100 % correct :-”B

, 4



Rationale: PCI DSS (Payment Card Industry Data Security Standard) requires regular penetration
testing for organizations that process, store, or transmit credit card data. This is a compliance-
driven requirement.



Question 6
What is the PRIMARY purpose of a post-engagement cleanup activity?

A. To identify new vulnerabilities
B. To remove all artifacts, backdoors, and tools left on client systems
C. To create a final report
D. To bill the client for additional services

-” detailed answer 100 % correct :-”B

Rationale: Post-engagement cleanup ensures that all testing artifacts, backdoors, and tools are
removed from client systems, returning the environment to its pre-test state and preventing
unauthorized access after the engagement ends.



Question 7
A client asks the penetration tester to sign a Non-Disclosure Agreement (NDA). What is the
primary purpose of this document?

A. To define the scope of the penetration test
B. To protect the client's confidential information from being disclosed
C. To establish the payment terms for the engagement
D. To list the tester's qualifications

-” detailed answer 100 % correct :-”B

Rationale: An NDA legally binds the tester to maintain the confidentiality of any sensitive
information learned during the engagement, protecting the client's proprietary and business
information.



Question 8
Which of the following scenarios would MOST likely require a "call-out" or emergency stop
condition in the ROE?

Document information

Uploaded on
July 25, 2026
Number of pages
61
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$27.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
wise254
5.0
(571)
Sold
61
Followers
5
Items
2970
Last sold
3 days ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions