CompTIA PenTest + PT0-003 (V3) Exam (New Version) Practice Test 2

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11371 | Total Attempts: 9,893,164
| Questions: 25 | Updated: Sep 23, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. Before launching an exploit against a critical production database server, a tester creates a low-level diagram showing exactly which systems will be touched and in what order, to ensure the team understands the full scope of planned actions. Which capability selection activity does this represent?

Explanation

Creating a low-level diagram of planned actions is a documentation activity specifically aimed at mapping the attack path before execution. Tool selection concerns choosing a tool, exploit customization concerns modifying an exploit, dependency analysis concerns what a plan relies on, and labeling sensitive systems flags high-risk targets rather than diagramming the sequence.

Submit
Please wait...
About This Quiz
CompTIA PenTest + Pt0-003 (V3) Exam (New Version) Practice Test 2 - Quiz

This practice assessment focuses on the CompTIA PenTest + PT0-003 exam, evaluating essential skills in penetration testing and vulnerability assessment. It covers key concepts such as network security, risk management, and ethical hacking techniques. This resource is crucial for learners aiming to validate their expertise in cybersecurity and prepare effectively... see morefor the certification. see less

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. During testing, a tester temporarily disabled a host-based firewall rule to facilitate lateral movement testing. At the conclusion of the engagement, what must the tester do regarding this change?

Explanation

Reverting configuration changes made during testing, such as re-enabling a temporarily disabled firewall rule, ensures the client's environment returns to its pre-engagement security posture. Leaving it disabled or only documenting it would leave the client weaker than before, and converting it into a recommendation confuses a testing artifact with an actual remediation suggestion.

Submit

3. A tester hides a small payload within an NTFS file system feature that allows extra data to be attached to a file without changing its visible size or content in standard directory listings. Which technique is this?

Explanation

Alternate data streams are an NTFS feature allowing additional data to be attached to a file without appearing in its visible size or standard directory listing. Steganography hides data within another file's content, virtual drive mounting creates a mountable encrypted container, cloud storage staging uses external cloud services, and a covert DNS channel encodes data within DNS traffic.

Submit

4. A tester enumerates a network and finds several hosts listening on port 445, indicating a specific file and printer sharing protocol commonly targeted for lateral movement. Which protocol is this?

Explanation

Port 445 is associated with SMB, used for Windows file and printer sharing and a common target for lateral movement techniques like share enumeration and credential relay. RDP uses port 3389, SSH uses port 22, LDAP is used for directory services, and RPC is a broader remote procedure call protocol.

Submit

5. A tester configures a compromised host to initiate an outbound connection back to the tester's listening system, bypassing inbound firewall restrictions that would otherwise block a directly initiated connection. Which persistence technique is this?

Explanation

A reverse shell has the compromised host initiate the outbound connection, which typically bypasses inbound firewall restrictions since outbound connections are often less restricted. A bind shell instead listens for an inbound connection, which blocking rules would prevent, and a rootkit, scheduled task, and registry key are different persistence or concealment mechanisms.

Submit

6. A tester wants a PowerShell module specifically designed to enumerate Active Directory objects, trust relationships, and group memberships to help identify privilege escalation paths. Which tool fits this need?

Explanation

PowerView is a PowerShell module specifically designed for enumerating AD objects, trusts, and group memberships to find privilege escalation paths. PowerSploit is a broader post-exploitation framework PowerView is often bundled within, PowerUpSQL focuses on SQL Server enumeration, and Impacket is a Python library collection rather than a PowerShell AD enumeration module.

Submit

7. A tester calls the IT help desk pretending to be a locked-out employee, using researched personal details to convince the help desk staff to reset the employee's password over the phone. Which social engineering attack type is this?

Explanation

Vishing is voice-based social engineering, such as this phone call to the help desk. Phishing and smishing use email and text messages, a watering hole attack compromises a website the target frequents, and dumpster diving involves physically searching discarded materials.

Submit

8. A tester wants to force employees' devices to disconnect from the legitimate corporate wireless network and then automatically connect to a rogue access point broadcasting the same SSID that the tester controls. Which two techniques would the tester combine to achieve this?

Explanation

Setting up a rogue access point with the same SSID is the evil twin attack, while forcibly disconnecting devices with deauthentication frames pushes them toward reconnecting to the rogue one. Signal jamming broadly disrupts communication rather than steering devices to a specific rogue AP, a WPS PIN attack targets a different mechanism, and wardriving is a reconnaissance activity.

Submit

9. A tester discovers a cloud storage bucket configured with public read access, containing customer backup files that should have been restricted to internal use only. Which category of cloud attack does this finding fall under?

Explanation

A publicly accessible storage bucket containing data that should be restricted is a resource misconfiguration, specifically an exposed storage bucket. A metadata service attack targets an instance's credential endpoint, container escape breaks out of isolation, trust relationship abuse exploits cross-account trust, and a workload runtime attack targets a running workload's execution.

Submit

10. A tester finds that a web application accepts serialized objects from client input and reconstructs them server-side without validation, allowing the tester to craft a malicious serialized object that executes arbitrary code when the server deserializes it. Which attack is this?

Explanation

A deserialization attack crafts a malicious serialized object that triggers unintended code execution when the server reconstructs it without proper validation. Cross-site scripting injects malicious scripts, directory traversal accesses files outside an intended directory, SQL injection manipulates database queries, and session hijacking steals an active session token.

Submit

11. A tester needs to extract plaintext passwords, hashes, and Kerberos tickets from a compromised Windows host's memory. Complete the sentence: the tool most commonly used for this specific credential dumping task is ______.

Explanation

Mimikatz is purpose-built to extract plaintext passwords, hashes, and Kerberos tickets directly from Windows memory, making it the standard tool for this task. Other post-exploitation tools like Rubeus or Seatbelt focus on more specific Kerberos abuse or host reconnaissance rather than this broad credential extraction capability.

Submit

12. In one test, a tester extracts an NTLM hash from a compromised host and uses it directly to authenticate to another system without cracking it. In a separate test, a different tester captures a valid Kerberos service ticket and replays it to access a resource without touching the account's password or hash at all. Which two attacks are described, respectively?

Explanation

Using a captured NTLM hash directly for authentication is pass-the-hash, while replaying a captured Kerberos ticket is pass-the-ticket. Pass-the-token involves reusing a captured token from a different protocol context, and password spraying and credential stuffing both involve attempting passwords rather than replaying captured hashes or tickets.

Submit

13. A tester runs a tool on an internal network segment that listens for and responds to broadcast name resolution requests such as LLMNR and NBT-NS, tricking hosts into sending their authentication hashes to the tester's machine. Which tool is this?

Explanation

Responder specifically poisons LLMNR and NBT-NS broadcast name resolution requests to capture authentication hashes. Netcat is a general networking utility, msfvenom generates payloads, Impacket is a protocol manipulation library collection, and CrackMapExec is used for lateral movement rather than name resolution poisoning.

Submit

14. A penetration test report includes a section that walks through, in narrative form, exactly how the tester moved from initial access on a web server to full domain administrator rights, including the specific commands and pivots used. Which report component is this?

Explanation

The attack narrative tells the story of how the tester progressed step by step, including specific commands and pivots. The executive summary is a high-level overview, detailed findings list vulnerabilities discretely, recommendations describe remediation steps, and methodology describes the general approach rather than the specific narrative of this test.

Submit

15. Before conducting an on-site physical security assessment, a tester walks the perimeter and interior of a facility, documenting camera placement, entry points, and badge reader locations without attempting to bypass anything yet. Which physical security activity is this?

Explanation

A site survey observes and documents physical security controls as a reconnaissance step before attempting any bypass. Tailgating, badge cloning, lock picking, and USB drops are all active bypass or delivery techniques rather than this observational documentation step.

Submit

16. A vulnerability scan does not flag a critical unpatched service on a server because that server was offline for maintenance during the scheduled scan window, even though the vulnerability genuinely exists. Which concept does this illustrate?

Explanation

A false negative occurs when a real vulnerability exists but the scan fails to detect it, exactly as described with the offline server. A true positive would be a correctly detected real vulnerability, a false positive an incorrectly flagged non-issue, public exploit selection concerns choosing an exploit for a confirmed finding, and troubleshooting scan configurations concerns diagnosing scanner setup rather than describing this missed detection.

Submit

17. A tester wants to visually map Active Directory trust relationships and permission chains to identify the shortest path from a low-privileged compromised account to domain administrator. Which tool is purpose-built for this?

Explanation

BloodHound is purpose-built to map Active Directory relationships and permission chains, visually identifying attack paths to privileged accounts. Nikto scans web servers, TruffleHog searches for secrets, OpenVAS is a general vulnerability scanner, and Trivy scans containers and images.

Submit

18. A tester runs a network scan designed to avoid completing the full TCP three-way handshake with target hosts, aiming to reduce the likelihood of triggering IDS alerts or appearing in connection logs. Complete the sentence: this technique is known as a ______ scan.

Explanation

A stealth scan, such as a TCP SYN scan, avoids completing the full three-way handshake to reduce its detection footprint in logs and IDS alerts. This distinguishes it from a full connect scan, which completes the handshake and is more easily logged by the target.

Submit

19. A tester wants to identify the true origin IP address of a web server that sits behind a web application firewall, since attacking the WAF's IP directly would be filtered. Which enumeration goal does this represent?

Explanation

WAF enumeration specifically aims to uncover the origin server's real IP, often through historical DNS records or misconfigured subdomains, bypassing the WAF entirely. DNS enumeration is broader domain record discovery, directory enumeration finds hidden web paths, and share and permission enumeration find shares and access rights rather than unmasking an origin server.

Submit

20. A tester captures traffic on a segment of the network used by building automation controllers and observes cleartext Modbus and BACnet traffic between devices. Which reconnaissance technique produced this observation?

Explanation

Network sniffing passively captures live network traffic, including IoT and OT protocol traffic like Modbus and BACnet. Banner grabbing captures service banners from direct connections, certificate transparency review examines TLS certificates, search engine enumeration uses public indexes, and HTML scraping extracts content from web pages.

Submit

21. Match each recon tool below to its primary purpose.

Explanation

Amass focuses on in-depth subdomain and attack surface mapping, Recon-ng is a modular OSINT framework similar in concept to Metasploit, SpiderFoot automates aggregation across dozens of sources into one report, and Censys.io indexes internet-wide scan data, each serving a distinct reconnaissance role.

Submit

22. A tester writes a conditional in a reconnaissance script that only flags a host as a target if it responds on port 443 AND has a certificate issued within the last 30 days. Which logic construct is the 'AND' keyword an example of?

Explanation

A Boolean operator such as AND combines or evaluates true/false conditions, exactly as this AND combines two conditions that both must be true. A loop repeats code, a string operator manipulates text, an arithmetic operator performs calculations, and a class defines a reusable object structure rather than combining conditions.

Submit

23. During enumeration of a target's public code repositories, a tester discovers a committed configuration file containing an AWS access key and secret key that were never removed from the commit history. Which enumeration category does this discovery fall under?

Explanation

Discovering cloud access keys, passwords, API keys, or session tokens exposed in code is specifically secrets enumeration. Permission enumeration identifies access rights, share enumeration identifies accessible network shares, local user enumeration identifies host accounts, and attack path mapping charts routes to a goal rather than finding exposed credentials.

Submit

24. Before beginning any active testing against a client's infrastructure, a tester ensures they are carrying a signed document explicitly granting permission to conduct the agreed-upon testing activities, in case law enforcement or a third party questions the activity mid-engagement. Which document is this?

Explanation

An authorization letter explicitly grants permission for the testing activities and is carried during testing to prove legitimacy if questioned. An NDA protects confidential information, an MSA and SoW define broader business and project terms, and terms of service define usage rules for a product rather than authorizing this test.

Submit

25. A tester's report notes that once initial access was gained on a single workstation, lateral movement to the finance server, the domain controller, and the backup server was trivial because all systems shared the same flat network with no internal restrictions. Which technical control would most directly address this finding?

Explanation

Network segmentation divides a flat network into isolated zones, limiting how easily the tester moved laterally to sensitive systems. MFA strengthens authentication, patch management addresses software vulnerabilities, and key rotation and certificate management address cryptographic material rather than network architecture.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
Before launching an exploit against a critical production database...
During testing, a tester temporarily disabled a host-based firewall...
A tester hides a small payload within an NTFS file system feature that...
A tester enumerates a network and finds several hosts listening on...
A tester configures a compromised host to initiate an outbound...
A tester wants a PowerShell module specifically designed to enumerate...
A tester calls the IT help desk pretending to be a locked-out...
A tester wants to force employees' devices to disconnect from the...
A tester discovers a cloud storage bucket configured with public read...
A tester finds that a web application accepts serialized objects from...
A tester needs to extract plaintext passwords, hashes, and Kerberos...
In one test, a tester extracts an NTLM hash from a compromised host...
A tester runs a tool on an internal network segment that listens for...
A penetration test report includes a section that walks through, in...
Before conducting an on-site physical security assessment, a tester...
A vulnerability scan does not flag a critical unpatched service on a...
A tester wants to visually map Active Directory trust relationships...
A tester runs a network scan designed to avoid completing the full TCP...
A tester wants to identify the true origin IP address of a web server...
A tester captures traffic on a segment of the network used by building...
Match each recon tool below to its primary purpose.
A tester writes a conditional in a reconnaissance script that only...
During enumeration of a target's public code repositories, a tester...
Before beginning any active testing against a client's infrastructure,...
A tester's report notes that once initial access was gained on a...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!