CompTIA PenTest + PT0-003 (V3) Exam (New Version) Practice Test 1

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11371 | Total Attempts: 9,893,164
| Questions: 25 | Updated: Sep 23, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. Two vulnerabilities have similar CVSS base scores, but one has a high score under a different scoring system indicating a much higher probability of exploitation in the near term. Complete the sentence: the scoring system that specifically estimates the probability a vulnerability will be exploited in the near term is called the ______.

Explanation

EPSS specifically estimates the probability that a vulnerability will be exploited in the near term, a dimension CVSS's severity score does not capture on its own. When CVSS scores are similar, the higher EPSS score indicates the more realistically threatening and thus higher-priority target.

Submit
Please wait...
About This Quiz
CompTIA PenTest + Pt0-003 (V3) Exam (New Version) Practice Test 1 - Quiz

This practice test focuses on the CompTIA PenTest + PT0-003 (V3) certification, assessing skills in penetration testing methodologies, tools, and techniques. It is designed for individuals preparing for the certification exam, helping them understand key concepts such as vulnerability assessment, exploitation, and reporting. Engaging with this material enhances your readiness... see morefor real-world security challenges and demonstrates your expertise in the field. see less

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. At the conclusion of an engagement, a tester needs to ensure that any client data collected during testing, such as captured credentials or scan output, is irrecoverably wiped rather than simply deleted. Complete the sentence: this cleanup activity is called ______.

Explanation

Secure data destruction ensures sensitive data collected during testing is irrecoverably wiped rather than just deleted, which could otherwise leave residual client data exposed. This is distinct from removing persistence mechanisms or tools from client systems, which addresses artifacts left on the target rather than data the tester collected.

Submit

3. A tester needs to exfiltrate a small amount of sensitive data from a highly restricted network that blocks all outbound traffic except DNS queries. Which exfiltration technique fits this constraint?

Explanation

A DNS covert channel encodes data within DNS queries and responses, allowing exfiltration even when only DNS traffic is permitted outbound. Cloud storage and email require broader outbound access this network blocks, alternate data streams hide data within a file system rather than exfiltrating it, and virtual drive mounting is a local technique rather than a network exfiltration method.

Submit

4. A tester compromises a host that has network access to an otherwise unreachable internal segment, and configures that host to route the tester's traffic through it to reach systems on that internal segment. Which lateral movement technique is this?

Explanation

Pivoting uses a compromised host as a relay point to route traffic into network segments otherwise unreachable from the tester's original position. Credential dumping extracts stored credentials, service discovery identifies available services, string searches look for sensitive strings in files or memory, and WMI is a Windows management protocol rather than the routing technique itself.

Submit

5. After gaining initial access, a tester establishes an ongoing, encrypted channel between the compromised host and their own infrastructure, allowing them to issue commands and receive results throughout the remainder of the engagement. Which persistence mechanism does this describe?

Explanation

A C2 framework establishes the ongoing communication channel used to issue commands and retrieve results throughout an engagement. A scheduled task or registry key modification are specific persistence techniques rather than the communication channel itself, a rootkit hides malicious software's presence, and a browser extension is one specific persistence vector rather than the broader C2 concept.

Submit

6. A tester interacts with a client's AI-powered customer service chatbot and crafts an input specifically designed to override the chatbot's underlying system instructions, causing it to reveal internal configuration details it should never disclose. Which attack against a specialized system does this represent?

Explanation

Prompt injection crafts input specifically designed to override an AI system's underlying instructions, causing unintended behavior such as disclosing internal details. Model manipulation alters the model itself, jailbreak/rooting applies to mobile devices, permission abuse misuses granted app permissions, and register manipulation is an OT attack technique unrelated to AI chatbots.

Submit

7. A tester crafts a highly personalized email targeting a specific finance department employee by name, referencing a real ongoing project, to trick them into clicking a malicious link. Which social engineering attack type is this, as distinct from a mass phishing campaign?

Explanation

Spearphishing targets a specific individual with personalized, contextually relevant content, unlike a generic mass phishing campaign. Vishing and smishing use voice calls and text messages, whaling specifically targets high-profile executives, and a watering hole attack compromises a website the target frequents rather than sending a direct email.

Submit

8. A tester sets up a rogue wireless access point broadcasting the same SSID as a target organization's legitimate network, hoping employees' devices will automatically connect to it instead. Which wireless attack is this?

Explanation

An evil twin attack sets up a rogue access point mimicking a legitimate network's SSID to trick devices into connecting to it instead. Wardriving is scanning for wireless networks while driving, signal jamming disrupts wireless communication broadly, deauthentication forcibly disconnects clients, and a WPS PIN attack targets the WPS PIN mechanism specifically.

Submit

9. A tester exploits an SSRF vulnerability in a cloud-hosted application to query the instance's internal metadata service and retrieve temporary IAM credentials assigned to that instance. Which category of attack does this represent?

Explanation

Querying a cloud instance's metadata service to retrieve credentials is specifically a metadata service attack, a well-known technique often chained from SSRF. Container escape breaks out of a container, a supply chain attack compromises a trusted upstream component, trust relationship abuse exploits cross-account trust, and a workload runtime attack targets a running workload's execution rather than its metadata endpoint.

Submit

10. A tester finds that a web application's 'fetch URL preview' feature can be manipulated to make the server itself send a request to an internal-only administrative endpoint that is not directly reachable from the internet. Which attack does this describe?

Explanation

SSRF tricks the server itself into making requests on the attacker's behalf, often reaching internal resources not otherwise accessible, exactly as described. CSRF tricks a victim's browser into making unwanted requests, directory traversal accesses files outside an intended directory, insecure direct object reference exposes internal references, and session hijacking steals an active session.

Submit

11. A tester creates a legitimate-looking process in a suspended state, then replaces its memory contents with malicious code before resuming execution, so the malicious code runs under the guise of a trusted process name. Which technique is this?

Explanation

Process hollowing creates a legitimate process in a suspended state, replaces its memory with malicious code, and resumes it so the code runs under a trusted process's identity. Library injection loads a malicious library into a running process, a shell escape breaks out of a restricted shell, log tampering alters logs, and unquoted service path injection exploits unquoted paths in service configurations.

Submit

12. A tester extracts an NTLM hash from a compromised host and uses it directly to authenticate without cracking it. In a related test, another tester captures a Kerberos service ticket and replays it to access a resource without ever touching the account's password or hash. Which two attacks are described, respectively?

Explanation

Using a captured NTLM hash directly for authentication is pass-the-hash, while replaying a captured Kerberos ticket is pass-the-ticket. Pass-the-token involves reusing a captured token from a different protocol context, and dictionary and brute-force attacks attempt to recover a plaintext password rather than replaying captured material.

Submit

13. A tester on a network segment configured with 802.1Q trunking crafts packets with a forged VLAN tag to gain access to a separate VLAN that should be isolated from their current segment. Which network attack does this describe?

Explanation

VLAN hopping uses techniques like forged VLAN tags on trunking protocols to access a VLAN that should be isolated from the attacker's segment. An on-path attack intercepts traffic between two parties, a relay attack forwards captured authentication material, multihomed host exploitation abuses a dual-connected host, and share enumeration lists accessible network shares.

Submit

14. A client's statement of work specifies that the engagement covers only their public-facing REST API and explicitly excludes their mobile application and internal network. During testing, the tester notices the API's authentication also protects a mobile-only endpoint and considers testing it since access was technically available. What should the tester do?

Explanation

Rules of engagement and the statement of work define the authorized boundaries of a test, and testing anything outside that scope exposes the tester to legal and contractual risk even if technically reachable. The correct response is to stay within the defined scope and formally request a scope change if the client wants the endpoint included, rather than unilaterally expanding testing or hiding the activity.

Submit

15. During a physical security assessment, a tester follows closely behind an employee through a badge-secured door without presenting their own credentials, relying on the employee holding the door open. Which physical security technique is this?

Explanation

Tailgating involves following an authorized person through a secured entry point without presenting one's own credentials. Badge cloning duplicates a card's data, lock picking manipulates a physical lock, a USB drop leaves malicious media for someone to find, and a site survey observes and documents physical controls rather than bypassing them directly.

Submit

16. A vulnerability scan flags Server A as vulnerable but manual testing shows it is not; separately, the scan misses a real vulnerability on Server B because it was in a maintenance window during the scan. Which two concepts do these represent, respectively?

Explanation

A finding that manual verification disproves is a false positive, while a real vulnerability missed because the scan didn't reach the host during its window is a false negative. A true positive would be a correctly confirmed vulnerability, scan completeness concerns overall coverage, and troubleshooting scan configurations concerns diagnosing scanner setup issues rather than describing either individual finding here.

Submit

17. A tester wants a dedicated, general-purpose vulnerability scanner to identify known CVEs and misconfigurations across a range of hosts on an internal network, rather than a tool focused specifically on web server issues. Which tool fits this need?

Explanation

Nessus is a general-purpose vulnerability scanner designed to identify known CVEs and misconfigurations across a broad range of hosts. Nikto focuses specifically on web server vulnerabilities, TruffleHog searches for secrets in code repositories, BloodHound maps Active Directory attack paths, and PowerSploit is a post-exploitation PowerShell framework.

Submit

18. A tester runs a vulnerability scan against a Windows server using valid domain credentials, allowing the scanner to check locally installed software and patch levels in addition to network-exposed services. Which scan type is being performed?

Explanation

An authenticated scan uses valid credentials to log into the target and inspect locally installed software and patch levels, far beyond what is visible from the network alone. An unauthenticated scan only sees externally exposed services, a stealth scan avoids completing TCP handshakes, a container scan targets containerized workloads, and a wireless scan targets Wi-Fi networks.

Submit

19. A tester wants to discover subdomains that a target organization has issued TLS certificates for, even subdomains not otherwise publicly linked or indexed. Which OSINT technique is best suited to this goal?

Explanation

Certificate transparency logs are public records of issued TLS certificates, revealing subdomains an organization has secured even if not otherwise linked or indexed. Banner grabbing reveals service information, cached pages show archived content, password dumps reveal leaked credentials, and job board analysis reveals technology clues, none of which reveal certificate-issued subdomains directly.

Submit

20. Match each reconnaissance tool to its primary purpose.

Explanation

Shodan indexes internet-connected devices and services, Maltego maps relationships between OSINT data points visually, theHarvester harvests email addresses and subdomains from public sources, and WHOIS looks up domain registration and ownership records, each serving a distinct reconnaissance purpose.

Submit

21. A tester writes a Python script that repeatedly checks a list of 500 subdomains against a resolver until each has been tested, executing the same DNS lookup logic for every entry. Which logic construct is being used to repeat this action for each subdomain?

Explanation

A loop repeats a block of code for each item in a collection, exactly what is needed to test every subdomain with the same logic. A conditional makes a decision, a Boolean operator evaluates true/false logic, a string operator manipulates text, and an arithmetic operator performs calculations, none of which alone drive repetition across a list.

Submit

22. A tester runs a tool against a web server that systematically requests common file and folder names to discover hidden or unlinked content such as admin panels or backup files. Which enumeration technique is this?

Explanation

Directory enumeration systematically requests common paths to discover hidden or unlinked web content like admin panels or backups. DNS enumeration targets domain records, share enumeration targets network shares, permission enumeration targets access rights, and wireless enumeration targets Wi-Fi networks.

Submit

23. A tester wants to passively discover subdomains and mail server records associated with a target organization's domain without sending any traffic directly to the target's infrastructure. Which technique fits this goal?

Explanation

DNS lookups against public DNS infrastructure are a passive OSINT technique revealing subdomains and mail records without direct interaction with the target. Active scanning, banner grabbing, and directory enumeration all involve direct interaction with target systems, and wireless enumeration is unrelated to domain reconnaissance.

Submit

24. A tester wants to follow a methodology that defines a complete, phase-by-phase penetration testing process from pre-engagement through reporting, rather than a metrics-focused security testing methodology. Which framework fits this need?

Explanation

PTES defines a complete phase-by-phase penetration testing process from pre-engagement through reporting. OSSTMM focuses on measurable security testing metrics, OWASP Top 10 lists common web application risks, the Purdue model describes industrial network architecture, and DREAD is a risk-rating framework rather than a full testing methodology.

Submit

25. Mid-engagement, a penetration tester discovers a live, actively exploited backdoor left by a real attacker, not a finding related to the test itself. Which collaboration and communication concept should the tester immediately invoke?

Explanation

An escalation path defines how to immediately notify appropriate stakeholders when something urgent outside normal reporting cadence is discovered, such as an active real-world compromise. Goal reprioritization adjusts testing objectives, client acceptance concerns sign-off on results, peer review is quality checking, and business impact analysis assesses broader impact rather than providing an immediate notification mechanism.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
Two vulnerabilities have similar CVSS base scores, but one has a high...
At the conclusion of an engagement, a tester needs to ensure that any...
A tester needs to exfiltrate a small amount of sensitive data from a...
A tester compromises a host that has network access to an otherwise...
After gaining initial access, a tester establishes an ongoing,...
A tester interacts with a client's AI-powered customer service chatbot...
A tester crafts a highly personalized email targeting a specific...
A tester sets up a rogue wireless access point broadcasting the same...
A tester exploits an SSRF vulnerability in a cloud-hosted application...
A tester finds that a web application's 'fetch URL preview' feature...
A tester creates a legitimate-looking process in a suspended state,...
A tester extracts an NTLM hash from a compromised host and uses it...
A tester on a network segment configured with 802.1Q trunking crafts...
A client's statement of work specifies that the engagement covers...
During a physical security assessment, a tester follows closely behind...
A vulnerability scan flags Server A as vulnerable but manual testing...
A tester wants a dedicated, general-purpose vulnerability scanner to...
A tester runs a vulnerability scan against a Windows server using...
A tester wants to discover subdomains that a target organization has...
Match each reconnaissance tool to its primary purpose.
A tester writes a Python script that repeatedly checks a list of 500...
A tester runs a tool against a web server that systematically requests...
A tester wants to passively discover subdomains and mail server...
A tester wants to follow a methodology that defines a complete,...
Mid-engagement, a penetration tester discovers a live, actively...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!