CompTIA PenTest+ (PT0-003)
Complete Practice Exam: Questions
with In-Depth Rationales Covering All
5 Domains
## DOMAIN 1: ENGAGEMENT MANAGEMENT (13%)
**Q1. A penetration tester is hired to conduct a test with no prior
knowledge of the internal network. The client only provides the
company name and public IP range. Which type of engagement is
this?**
A) White box
B) Gray box
C) Black box
D) Crystal box
,**Answer: C**
*Rationale:* A black box test simulates an external attacker with zero
prior knowledge of the target environment. The tester receives only
publicly available information such as the company name or public IP
range. White box provides full internal access with credentials and
architecture details. Gray box provides partial information such as
network diagrams but no credentials .
---
**Q2. What is the primary purpose of a "Rules of Engagement" (ROE)
document?**
A) To list the employee salaries
B) To define the boundaries, limitations, and scope of the penetration
test, including prohibited actions, testing windows, and emergency
contacts
C) To report test findings to the board
D) To request additional budget
**Answer: B**
*Rationale:* The Rules of Engagement is a critical legal document that
defines the scope, boundaries, and limitations of the penetration test.
,It includes testing windows, allowed/forbidden techniques (e.g., DoS
attacks, phishing), emergency contacts, and authorization signatures.
Signing the ROE protects both the tester and the client .
---
**Q3. Select the stakeholders that are typically involved in a pentest
engagement. (Choose two.)**
A) Users
B) Executive management
C) Pentesters
D) Human Resources
**Answer: B, C**
*Rationale:* During a pentest, there are many stakeholders interested
in the findings and success of the engagement. This group typically
includes executive management, contracting or legal departments,
security personnel, IT departments, and pentesters .
---
, **Q4. During the scoping and planning phase of a penetration test,
which two limitations most significantly define the boundaries,
duration, and depth of the engagement?**
A) Organizational budget
B) Target selection
C) Technical constraints
D) FISMA
**Answer: A, C**
*Rationale:* Organizational budget and technical constraints are the
two primary limitations that define the boundaries, duration, and depth
of a penetration test engagement during the scoping and planning
phase .
---
**Q5. An organization is defining the scope of a pentest and would like
to see vulnerabilities from both outside and inside the network. They
are willing to share some information with the vendor but want to see
how much information the vendor can discover on their own. Which
type of methodology would be best suited?**
A) White box testing
Complete Practice Exam: Questions
with In-Depth Rationales Covering All
5 Domains
## DOMAIN 1: ENGAGEMENT MANAGEMENT (13%)
**Q1. A penetration tester is hired to conduct a test with no prior
knowledge of the internal network. The client only provides the
company name and public IP range. Which type of engagement is
this?**
A) White box
B) Gray box
C) Black box
D) Crystal box
,**Answer: C**
*Rationale:* A black box test simulates an external attacker with zero
prior knowledge of the target environment. The tester receives only
publicly available information such as the company name or public IP
range. White box provides full internal access with credentials and
architecture details. Gray box provides partial information such as
network diagrams but no credentials .
---
**Q2. What is the primary purpose of a "Rules of Engagement" (ROE)
document?**
A) To list the employee salaries
B) To define the boundaries, limitations, and scope of the penetration
test, including prohibited actions, testing windows, and emergency
contacts
C) To report test findings to the board
D) To request additional budget
**Answer: B**
*Rationale:* The Rules of Engagement is a critical legal document that
defines the scope, boundaries, and limitations of the penetration test.
,It includes testing windows, allowed/forbidden techniques (e.g., DoS
attacks, phishing), emergency contacts, and authorization signatures.
Signing the ROE protects both the tester and the client .
---
**Q3. Select the stakeholders that are typically involved in a pentest
engagement. (Choose two.)**
A) Users
B) Executive management
C) Pentesters
D) Human Resources
**Answer: B, C**
*Rationale:* During a pentest, there are many stakeholders interested
in the findings and success of the engagement. This group typically
includes executive management, contracting or legal departments,
security personnel, IT departments, and pentesters .
---
, **Q4. During the scoping and planning phase of a penetration test,
which two limitations most significantly define the boundaries,
duration, and depth of the engagement?**
A) Organizational budget
B) Target selection
C) Technical constraints
D) FISMA
**Answer: A, C**
*Rationale:* Organizational budget and technical constraints are the
two primary limitations that define the boundaries, duration, and depth
of a penetration test engagement during the scoping and planning
phase .
---
**Q5. An organization is defining the scope of a pentest and would like
to see vulnerabilities from both outside and inside the network. They
are willing to share some information with the vendor but want to see
how much information the vendor can discover on their own. Which
type of methodology would be best suited?**
A) White box testing