CompTIA PenTest+ (PT0-003): The
Complete 120-Question Practice Exam
with Answer Rationales
DOMAIN 1: ENGAGEMENT MANAGEMENT (13%)
Q1. Which document should be signed before a penetration test to ensure
the client's sensitive information remains confidential?
A) Rules of Engagement (RoE)
B) Non-Disclosure Agreement (NDA)
C) Statement of Work (SOW)
D) Service Level Agreement (SLA)
Answer: B
Rationale: An NDA is a legal document that ensures any sensitive
information accessed by the penetration tester during the engagement
remains confidential. RoE defines the testing boundaries and acceptable
methods, while the SOW outlines the specific tasks and deliverables. The
SLA pertains to service performance and uptime.
Q2. Select the stakeholders that are typically involved in a pentest
engagement. (Choose two)
,A) Users
B) Executive management
C) Pentesters
D) Human Resources
Answer: B, C
Rationale: During a pentest there are many stakeholders that might be
interested in the findings and success of the engagement. Typically, this
group is made up of executive management, contracting or legal
department, security personnel, IT department, and pentesters.
Q3. What is the first task you should complete when asked to perform a
penetration test?
A) Research the organization's product offerings
B) Determine the budget available for the test
C) Identify the scope of the test
D) Gain authorization to perform the test
Answer: C
Rationale: The first step in the penetration testing process is to work with
the client to clearly define the scope of the test. The scope determines what
penetration testers will do and how their time will be spent.
Q4. A consultant has been hired to perform a simulated attack for an
organization by mimicking a real-world adversary. The target is the
,organization's proprietary design documents. What type of assessment is
being conducted?
A) Objective-based assessment
B) Goal-based assessment
C) Compliance-based assessment
D) Red team assessment
Answer: D
Rationale: Red team assessments are typically more targeted than normal
penetration tests. The red team acts like an attacker, targeting sensitive
data or systems with the goal of acquiring access.
Q5. An organization is defining the scope of a pentest and would like to
see vulnerabilities from both outside and inside the network. They will share
some information but want to see how much a vendor can discover on their
own. Which methodology is best?
A) White box testing
B) Gray box testing
C) Black box testing
D) Red team testing
Answer: B
Rationale: A gray box test may provide some information about the
environment to the penetration testers without giving full access,
credentials, or configuration details.
, Q6. A consultant has been hired to perform a penetration test for an
organization in the healthcare industry targeting a public-facing self-service
website with patient health records. The tester has been given full
knowledge of the organization's underlying network. What type of test is
being conducted?
A) Goal-based assessment
B) Black box assessment
C) Objective-based assessment
D) White box assessment
Answer: D
Rationale: A white box test is performed with full knowledge of the
underlying technology, configuration, and settings of the target
organization's network.
Q7. In which type of penetration test does the tester have a limited amount
of information about the target environment but is not granted full access?
A) Gray box assessment
B) Black box assessment
C) Compliance-based assessment
D) White box assessment
Answer: A
Rationale: A gray box test may provide some information about the
environment to the penetration testers without giving full access,
credentials, or configuration details.
Complete 120-Question Practice Exam
with Answer Rationales
DOMAIN 1: ENGAGEMENT MANAGEMENT (13%)
Q1. Which document should be signed before a penetration test to ensure
the client's sensitive information remains confidential?
A) Rules of Engagement (RoE)
B) Non-Disclosure Agreement (NDA)
C) Statement of Work (SOW)
D) Service Level Agreement (SLA)
Answer: B
Rationale: An NDA is a legal document that ensures any sensitive
information accessed by the penetration tester during the engagement
remains confidential. RoE defines the testing boundaries and acceptable
methods, while the SOW outlines the specific tasks and deliverables. The
SLA pertains to service performance and uptime.
Q2. Select the stakeholders that are typically involved in a pentest
engagement. (Choose two)
,A) Users
B) Executive management
C) Pentesters
D) Human Resources
Answer: B, C
Rationale: During a pentest there are many stakeholders that might be
interested in the findings and success of the engagement. Typically, this
group is made up of executive management, contracting or legal
department, security personnel, IT department, and pentesters.
Q3. What is the first task you should complete when asked to perform a
penetration test?
A) Research the organization's product offerings
B) Determine the budget available for the test
C) Identify the scope of the test
D) Gain authorization to perform the test
Answer: C
Rationale: The first step in the penetration testing process is to work with
the client to clearly define the scope of the test. The scope determines what
penetration testers will do and how their time will be spent.
Q4. A consultant has been hired to perform a simulated attack for an
organization by mimicking a real-world adversary. The target is the
,organization's proprietary design documents. What type of assessment is
being conducted?
A) Objective-based assessment
B) Goal-based assessment
C) Compliance-based assessment
D) Red team assessment
Answer: D
Rationale: Red team assessments are typically more targeted than normal
penetration tests. The red team acts like an attacker, targeting sensitive
data or systems with the goal of acquiring access.
Q5. An organization is defining the scope of a pentest and would like to
see vulnerabilities from both outside and inside the network. They will share
some information but want to see how much a vendor can discover on their
own. Which methodology is best?
A) White box testing
B) Gray box testing
C) Black box testing
D) Red team testing
Answer: B
Rationale: A gray box test may provide some information about the
environment to the penetration testers without giving full access,
credentials, or configuration details.
, Q6. A consultant has been hired to perform a penetration test for an
organization in the healthcare industry targeting a public-facing self-service
website with patient health records. The tester has been given full
knowledge of the organization's underlying network. What type of test is
being conducted?
A) Goal-based assessment
B) Black box assessment
C) Objective-based assessment
D) White box assessment
Answer: D
Rationale: A white box test is performed with full knowledge of the
underlying technology, configuration, and settings of the target
organization's network.
Q7. In which type of penetration test does the tester have a limited amount
of information about the target environment but is not granted full access?
A) Gray box assessment
B) Black box assessment
C) Compliance-based assessment
D) White box assessment
Answer: A
Rationale: A gray box test may provide some information about the
environment to the penetration testers without giving full access,
credentials, or configuration details.