CompTIA PenTest + PT0-003 (V3) Exam (New Version) Practice Test 3

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11371 | Total Attempts: 9,893,164
| Questions: 25 | Updated: Sep 23, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. During target prioritization, a tester notices one server is running an operating system version that the vendor stopped supporting and patching over two years ago. Which prioritization factor does this observation most directly relate to?

Explanation

A system running an unsupported, unpatched OS version is an end-of-life software or system, a high-priority target since it will never receive further fixes. Default configurations concern unchanged factory settings, running services concern what is listening, vulnerable encryption concerns weak cryptography, and defensive capabilities concern detection posture.

Submit
Please wait...
About This Quiz
CompTIA PenTest + Pt0-003 (V3) Exam (New Version) Practice Test 3 - Quiz

This quiz assesses your knowledge and skills related to the CompTIA PenTest + PT0-003 certification. It covers essential topics such as vulnerability assessment, exploitation techniques, and reporting. Engaging with this material is vital for anyone preparing for the certification or seeking to enhance their penetration testing expertise.

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. At the conclusion of an engagement, a tester ensures that any exploitation frameworks, scripts, and binaries they uploaded to client systems during testing are fully deleted from those systems. Which cleanup activity does this represent?

Explanation

Deleting exploitation frameworks, scripts, and binaries uploaded to client systems is specifically the removal of tools. Preserving artifacts keeps evidence rather than deleting it, secure data destruction concerns data the tester collected, spinning down infrastructure concerns the tester's own external systems, and reverting configuration changes addresses altered settings.

Submit

3. A tester uploads collected sensitive files to a personal account on a mainstream cloud storage service, blending the exfiltration traffic in with the large volume of legitimate cloud storage traffic the organization already generates. Which exfiltration technique is this?

Explanation

Uploading data to a personal cloud storage account, blending in with legitimate traffic, is cloud storage exfiltration. Alternate data streams hide data within a file system, virtual drive mounting creates a local encrypted container, text storage sites paste data to public services, and a DNS covert channel encodes data within DNS traffic.

Submit

4. A tester uses a native Windows remote management protocol, built on top of HTTP or HTTPS, to execute commands and PowerShell sessions on remote systems without needing to install additional software. Which protocol is this?

Explanation

WinRM is a native Windows remote management protocol built on HTTP/HTTPS that allows remote command and PowerShell session execution. RDP provides graphical remote desktop access, SMB is used for file and printer sharing, LDAP is used for directory service queries, and RPC is a broader remote procedure call mechanism.

Submit

5. A tester configures a Linux server to automatically re-establish the tester's backdoor connection every hour, even if the original connection is terminated or the server reboots, by adding an entry that runs on a fixed schedule. Which persistence mechanism is this?

Explanation

A cron job schedules a command to run automatically at fixed intervals on Linux, ensuring the backdoor re-establishes hourly even after a reboot. A registry key is a Windows-specific persistence location, a rootkit hides malicious software, a browser extension is a different vector, and a bind shell describes a listening connection method rather than a scheduling mechanism.

Submit

6. A tester wants to run automated, repeatable adversary emulation exercises against a network to validate detection and response capabilities over time, using a platform that orchestrates a library of attack techniques rather than scripting each one manually. Which tool fits this need?

Explanation

Caldera is a breach and attack simulation platform that orchestrates automated, repeatable adversary emulation exercises from a library of techniques. Impacket is a protocol manipulation library collection, Scapy is a packet crafting library, PowerSploit is a PowerShell post-exploitation framework, and PowerUpSQL focuses on SQL Server enumeration.

Submit

7. A tester removes manufacturer and carrier restrictions from an iOS device as part of a mobile application security assessment, gaining root-level access to the device's file system to inspect how the application stores sensitive data locally. Which technique is this?

Explanation

Jailbreaking (iOS) or rooting (Android) removes manufacturer and carrier restrictions to gain root-level file system access. Permission abuse misuses granted application permissions, information disclosure describes unintentional exposure of sensitive data, and prompt injection and model manipulation are AI-specific attack techniques unrelated to mobile devices.

Submit

8. One wireless attack exploits a flawed PIN validation design to dramatically reduce the effective brute-force search space for gaining network access. A separate wireless attack instead sends deliberately malformed frames to a wireless driver or firmware to discover crashes or unexpected behavior. Which two attacks are described, respectively?

Explanation

Exploiting the flawed WPS PIN validation design is the WPS PIN attack, while sending malformed frames to find crashes is protocol fuzzing. An evil twin attack sets up a rogue access point, signal jamming disrupts communication broadly, and wardriving is a reconnaissance activity rather than either of these two techniques.

Submit

9. A tester discovers that a client's CI/CD pipeline pulls a base container image from a public registry that was recently found to contain a maliciously modified library, which then gets built into every deployment. Which category of cloud attack does this represent?

Explanation

A supply chain attack compromises a trusted upstream component, such as a base container image, that propagates into downstream deployments. Container escape breaks out of a container's isolation, trust relationship abuse exploits cross-account permissions, a workload runtime attack targets a running workload's execution, and a metadata service attack targets an instance's credential endpoint.

Submit

10. A tester intercepts a web application's authentication token and discovers it can modify the token's payload, including changing their user role from 'user' to 'admin,' because the application fails to properly verify the token's signature. Which attack is this?

Explanation

JWT manipulation exploits a token whose signature is not properly verified, allowing an attacker to alter claims like a user role. Session hijacking steals an existing valid session, API abuse covers broader misuse of API functionality, insecure direct object reference exposes internal references through parameters, and CSRF tricks a victim's browser into unwanted requests.

Submit

11. A tester finds a Windows service configured with an unquoted file path containing spaces, such as C:\Program Files\My App\service.exe, and places a malicious executable named C:\Program.exe so that Windows executes it instead of the intended service binary. Which technique is this?

Explanation

Unquoted service path injection exploits how Windows parses unquoted paths containing spaces, potentially executing an attacker-placed file instead. Library injection loads a malicious library into a running process, process hollowing replaces a suspended process's memory, a shell escape breaks out of a restricted shell, and log tampering alters log records.

Submit

12. In one test, a tester tries a single common password against every account in the directory before moving to the next password, to avoid lockouts. In a separate test, another tester uses a list of username/password pairs leaked from an unrelated previous breach, betting that some employees reused those exact credentials. Which two attacks are described, respectively?

Explanation

Trying one password across many accounts to avoid lockouts is password spraying, while using previously breached username/password pairs is credential stuffing. A dictionary attack tries many passwords against one account, a mask attack uses a defined pattern, and a brute-force attack systematically tries all combinations rather than relying on breached data.

Submit

13. A tester finds a network printer still configured with its factory-set administrative username and password, never changed since deployment, and uses these to gain administrative access. Which attack type is this?

Explanation

Using factory-set, never-changed credentials to gain access is specifically the default credentials attack type. An on-path attack intercepts traffic, a relay attack forwards captured authentication material, packet crafting builds custom packets, and multihomed host exploitation abuses a dual-connected host.

Submit

14. Midway through an engagement, the tester's initial findings suggest the original testing scope significantly underestimates the complexity of the client's environment. Before continuing, the tester meets with the client's project sponsor to confirm priorities still match expectations and adjust the plan if needed. Which collaboration concept does this meeting represent?

Explanation

Stakeholder alignment ensures testing priorities and expectations remain synchronized between tester and client as new information emerges. Peer review is a quality check among testers, root cause analysis investigates why an issue occurred, business impact analysis assesses organizational consequences, and client acceptance is formal sign-off on final results.

Submit

15. As part of a physical and social engineering assessment, a tester leaves several USB drives labeled 'Confidential Payroll Data' in the parking lot and break room of a target company, hoping an employee will plug one into a corporate machine. Which technique is this?

Explanation

A USB drop leaves malicious removable media where a target is likely to find and use it. Tailgating follows someone through a secured door, a site survey observes physical security controls, badge cloning duplicates access card data, and lock picking manipulates a physical lock mechanism.

Submit

16. A vulnerability scan flags a server as running an outdated version of OpenSSL with a known critical vulnerability, and manual verification confirms the exact vulnerable version is indeed installed and exploitable. Which concept does this finding represent?

Explanation

A finding that manual verification confirms as accurate is a true positive. A false positive would be an incorrectly flagged non-issue, a false negative a missed real vulnerability, scan completeness concerns coverage, and public exploit selection concerns choosing an exploit for this confirmed finding.

Submit

17. A tester wants a tool specifically designed to hunt for security weaknesses in a Kubernetes cluster's configuration, such as exposed dashboards or overly permissive service accounts. Which tool fits this need?

Explanation

Kube-hunter is specifically designed to hunt for security weaknesses in Kubernetes cluster configurations, such as exposed dashboards. Grype scans container images for known vulnerabilities, TruffleHog searches for exposed secrets, Nikto scans web servers, and OpenVAS is a general-purpose vulnerability scanner.

Submit

18. A tester wants to assess the security of individual containers within a Kubernetes cluster, including auxiliary containers that run alongside the main application container to provide supporting functionality like logging. Which scan type specifically targets these auxiliary containers?

Explanation

A sidecar scan specifically targets the auxiliary containers running alongside a main application container. A host-based scan targets a full OS host, a wireless scan targets Wi-Fi networks, a secrets scan searches for exposed credentials, and SAST analyzes source code.

Submit

19. A tester's script calculates the number of remaining subdomains to test by subtracting the count already processed from the total count discovered. Which type of operator performs this calculation?

Explanation

An arithmetic operator performs mathematical calculations such as subtraction. A Boolean operator evaluates true/false logic, a string operator manipulates text, a loop repeats code, and a conditional makes decisions rather than performing a calculation.

Submit

20. A tester uses a tool to systematically identify which email addresses at a target domain are valid and actively in use, without yet attempting to access any of them. Which enumeration technique is this?

Explanation

Email account enumeration specifically identifies which email addresses at a domain are valid and active. Local user enumeration identifies accounts on a host, share enumeration identifies accessible network shares, wireless enumeration identifies Wi-Fi networks, and permission enumeration identifies access rights.

Submit

21. While researching a target company, a tester finds a publicly accessible internal wiki page, unintentionally left without access controls, that lists internal server hostnames and IP address ranges. Which OSINT category does this finding fall under?

Explanation

Sensitive internal information unintentionally exposed to the public is classified as information disclosure. Cached pages refer to archived web content, password dumps refer to leaked credential databases, job board analysis extracts clues from postings, and search engine enumeration uses search engines to systematically find indexed content.

Submit

22. A tester wants a modular framework, similar in concept to Metasploit but focused specifically on web-based open-source reconnaissance, with plugins for different data sources like social media and breach databases. Which tool fits this description?

Explanation

Recon-ng is a modular OSINT reconnaissance framework, conceptually similar to Metasploit, with plugins covering different data sources. Wireshark captures packet traffic, Nmap performs network scanning, and Aircrack-ng and InSSIDer are wireless-focused tools.

Submit

23. A tester's script needs to check whether a captured banner string contains the word 'Apache' before proceeding with a version-specific check. Complete the sentence: an operator that performs operations on text values, such as checking whether one string contains another, is called a ______ operator.

Explanation

A string operator performs operations on text values, such as checking whether one string contains a substring like 'Apache.' An arithmetic operator performs calculations, a Boolean operator evaluates true/false logic, and a loop repeats code, none of which directly perform text pattern matching.

Submit

24. A penetration testing firm uses an AI tool to help draft portions of a client report, but has a policy requiring a human reviewer to verify every AI-generated finding against actual test evidence before the report is finalized. Which reporting consideration does this policy address?

Explanation

Requiring human verification of AI-generated content against actual evidence is a quality control measure addressing the AI reporting consideration. Legal and ethical considerations concern broader compliance and conduct obligations, format alignment concerns matching an agreed template, and risk scoring concerns how findings are numerically rated.

Submit

25. Match each risk or threat modeling framework to its correct description.

Explanation

DREAD produces a numeric score across five risk categories, STRIDE categorizes threats into six named types, OCTAVE is a broader organizational risk assessment methodology focused on critical assets, and MITRE ATT&CK catalogs real-world adversary techniques mapped to known threat groups.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
During target prioritization, a tester notices one server is running...
At the conclusion of an engagement, a tester ensures that any...
A tester uploads collected sensitive files to a personal account on a...
A tester uses a native Windows remote management protocol, built on...
A tester configures a Linux server to automatically re-establish the...
A tester wants to run automated, repeatable adversary emulation...
A tester removes manufacturer and carrier restrictions from an iOS...
One wireless attack exploits a flawed PIN validation design to...
A tester discovers that a client's CI/CD pipeline pulls a base...
A tester intercepts a web application's authentication token and...
A tester finds a Windows service configured with an unquoted file path...
In one test, a tester tries a single common password against every...
A tester finds a network printer still configured with its factory-set...
Midway through an engagement, the tester's initial findings suggest...
As part of a physical and social engineering assessment, a tester...
A vulnerability scan flags a server as running an outdated version of...
A tester wants a tool specifically designed to hunt for security...
A tester wants to assess the security of individual containers within...
A tester's script calculates the number of remaining subdomains to...
A tester uses a tool to systematically identify which email addresses...
While researching a target company, a tester finds a publicly...
A tester wants a modular framework, similar in concept to Metasploit...
A tester's script needs to check whether a captured banner string...
A penetration testing firm uses an AI tool to help draft portions of a...
Match each risk or threat modeling framework to its correct...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!