1|Page
COMPTIA PENTEST+ (PT0-003) EXAM &
PRACTICE TEST BANK COMPLETE 400
REAL EXAM QUESTIONS WITH
VERIFIED ANSWERS AND RATIONALES
EXAM OVERVIEW
CompTIA PenTest+ (PT0-003) validates intermediate-level skills in penetration testing,
vulnerability management, and post-exploitation techniques. This certification focuses
on hands-on, practical skills for security professionals.
Feature Specification
Exam Code PT0-003
Total Questions Maximum 90 (multiple-choice and performance-based)
Time Limit 165 minutes
Passing Score 750 (scale 100-900)
Launch Date December 17, 2024
Experience Required 3-4 years in penetration testing, Network+, Security+
EXAM DOMAINS AND WEIGHTING
Domain Weight Questions
1.0 Engagement Management 13% ~52 questions
,2|Page
Domain Weight Questions
2.0 Reconnaissance & Enumeration 21% ~84 questions
3.0 Vulnerability Discovery & Analysis 17% ~68 questions
4.0 Attacks & Exploits 35% ~140 questions
5.0 Post-Exploitation & Lateral Movement 14% ~56 questions
TOTAL 100% 400 questions
SECTION 1: ENGAGEMENT MANAGEMENT (Questions 1-52)
Question 1
A penetration tester is in the planning phase of an engagement. Which document
should be signed by both parties before testing begins to define the scope and rules
of the engagement?
A) Master Service Agreement (MSA)
B) Rules of Engagement (RoE)
C) Non-Disclosure Agreement (NDA)
D) Statement of Work (SOW)
Answer: B) Rules of Engagement (RoE)
Rationale: The Rules of Engagement (RoE) document is critical in the planning
phase of a penetration test. It specifies the scope, testing boundaries, allowed
techniques, and any systems that are off-limits. Both parties must agree to this
document before any testing begins to ensure legal and ethical compliance. The RoE
serves as the binding contract that defines what the penetration tester is authorized
to do.
Why the other options are wrong:
,3|Page
A) MSA is a general services agreement that sets terms for ongoing business
relationships
C) NDA protects confidential information but does not define testing scope or rules
D) SOW typically defines project deliverables and timeline, not technical testing
rules
Question 2
During post-engagement activities, you discover that you left a test user account
active on a client system. What should you do?
A) Report the oversight in the final documentation
B) Do nothing; the client will find it during their review
C) Immediately remove the account and document the removal
D) Change the account password and leave it for future testing
Answer: C) Immediately remove the account and document the removal
Rationale: Post-engagement cleanup requires removing all artifacts of the testing
process, including test accounts, tools, and backdoors. Leaving any artifacts creates
a security risk for the client. Documentation of the removal ensures transparency
and shows due diligence. This is a critical professional responsibility.
Why the other options are wrong:
A) Reporting without removing leaves a security risk
B) Leaving the account for the client to find is irresponsible
D) Leaving or changing the account password violates ethical testing practices
Question 3
Which of the following is NOT typically included in the executive summary of a
penetration test report?
A) A high-level overview of the testing objectives
B) A summary of key findings and risk levels
C) Detailed step-by-step exploitation procedures
D) An overall security posture assessment
, 4|Page
Answer: C) Detailed step-by-step exploitation procedures
Rationale: The executive summary is written for management and non-technical
stakeholders. It should provide a high-level overview without technical jargon.
Detailed exploitation procedures belong in the technical appendices of the report,
not the executive summary. The PT0-003 exam emphasizes the importance of
tailoring content to the audience.
Why the other options are wrong:
A) Objectives are a standard part of the executive summary
B) Key findings and risk levels are essential for executive understanding
D) Security posture assessment provides valuable context for decision-makers
Question 4
A client asks you to perform a penetration test without signing a formal agreement.
What should you do?
A) Proceed with the test as requested
B) Refuse to test until proper authorization documents are signed
C) Test the systems but not document the findings
D) Conduct a basic vulnerability scan only
Answer: B) Refuse to test until proper authorization documents are signed
Rationale: Penetration testing requires explicit, documented authorization to avoid
legal issues. Without a signed agreement, the tester has no legal protection and
could be accused of unauthorized access. Professional ethics and legal requirements
mandate proper authorization before any testing activities begin.
Why the other options are wrong:
A) Proceeding without authorization is illegal and unethical
C) Testing without documentation does not address the legal issue
D) Even basic scanning requires proper authorization
COMPTIA PENTEST+ (PT0-003) EXAM &
PRACTICE TEST BANK COMPLETE 400
REAL EXAM QUESTIONS WITH
VERIFIED ANSWERS AND RATIONALES
EXAM OVERVIEW
CompTIA PenTest+ (PT0-003) validates intermediate-level skills in penetration testing,
vulnerability management, and post-exploitation techniques. This certification focuses
on hands-on, practical skills for security professionals.
Feature Specification
Exam Code PT0-003
Total Questions Maximum 90 (multiple-choice and performance-based)
Time Limit 165 minutes
Passing Score 750 (scale 100-900)
Launch Date December 17, 2024
Experience Required 3-4 years in penetration testing, Network+, Security+
EXAM DOMAINS AND WEIGHTING
Domain Weight Questions
1.0 Engagement Management 13% ~52 questions
,2|Page
Domain Weight Questions
2.0 Reconnaissance & Enumeration 21% ~84 questions
3.0 Vulnerability Discovery & Analysis 17% ~68 questions
4.0 Attacks & Exploits 35% ~140 questions
5.0 Post-Exploitation & Lateral Movement 14% ~56 questions
TOTAL 100% 400 questions
SECTION 1: ENGAGEMENT MANAGEMENT (Questions 1-52)
Question 1
A penetration tester is in the planning phase of an engagement. Which document
should be signed by both parties before testing begins to define the scope and rules
of the engagement?
A) Master Service Agreement (MSA)
B) Rules of Engagement (RoE)
C) Non-Disclosure Agreement (NDA)
D) Statement of Work (SOW)
Answer: B) Rules of Engagement (RoE)
Rationale: The Rules of Engagement (RoE) document is critical in the planning
phase of a penetration test. It specifies the scope, testing boundaries, allowed
techniques, and any systems that are off-limits. Both parties must agree to this
document before any testing begins to ensure legal and ethical compliance. The RoE
serves as the binding contract that defines what the penetration tester is authorized
to do.
Why the other options are wrong:
,3|Page
A) MSA is a general services agreement that sets terms for ongoing business
relationships
C) NDA protects confidential information but does not define testing scope or rules
D) SOW typically defines project deliverables and timeline, not technical testing
rules
Question 2
During post-engagement activities, you discover that you left a test user account
active on a client system. What should you do?
A) Report the oversight in the final documentation
B) Do nothing; the client will find it during their review
C) Immediately remove the account and document the removal
D) Change the account password and leave it for future testing
Answer: C) Immediately remove the account and document the removal
Rationale: Post-engagement cleanup requires removing all artifacts of the testing
process, including test accounts, tools, and backdoors. Leaving any artifacts creates
a security risk for the client. Documentation of the removal ensures transparency
and shows due diligence. This is a critical professional responsibility.
Why the other options are wrong:
A) Reporting without removing leaves a security risk
B) Leaving the account for the client to find is irresponsible
D) Leaving or changing the account password violates ethical testing practices
Question 3
Which of the following is NOT typically included in the executive summary of a
penetration test report?
A) A high-level overview of the testing objectives
B) A summary of key findings and risk levels
C) Detailed step-by-step exploitation procedures
D) An overall security posture assessment
, 4|Page
Answer: C) Detailed step-by-step exploitation procedures
Rationale: The executive summary is written for management and non-technical
stakeholders. It should provide a high-level overview without technical jargon.
Detailed exploitation procedures belong in the technical appendices of the report,
not the executive summary. The PT0-003 exam emphasizes the importance of
tailoring content to the audience.
Why the other options are wrong:
A) Objectives are a standard part of the executive summary
B) Key findings and risk levels are essential for executive understanding
D) Security posture assessment provides valuable context for decision-makers
Question 4
A client asks you to perform a penetration test without signing a formal agreement.
What should you do?
A) Proceed with the test as requested
B) Refuse to test until proper authorization documents are signed
C) Test the systems but not document the findings
D) Conduct a basic vulnerability scan only
Answer: B) Refuse to test until proper authorization documents are signed
Rationale: Penetration testing requires explicit, documented authorization to avoid
legal issues. Without a signed agreement, the tester has no legal protection and
could be accused of unauthorized access. Professional ethics and legal requirements
mandate proper authorization before any testing activities begin.
Why the other options are wrong:
A) Proceeding without authorization is illegal and unethical
C) Testing without documentation does not address the legal issue
D) Even basic scanning requires proper authorization