CompTIA PenTest + PT0-003 (V3) Exam (New Version) Practice Test 5

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11371 | Total Attempts: 9,893,164
| Questions: 25 | Updated: Sep 23, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. While prioritizing targets, a tester notes that one server has no EDR agent, no logging forwarded to a SIEM, and no host-based firewall, making any successful compromise far less likely to be detected during the remainder of the engagement. Which prioritization factor does this observation relate to?

Explanation

The presence or absence of detection and defensive measures like EDR, SIEM logging, and host firewalls is the defensive capabilities factor, since a weakly defended target allows more stealthy testing. Running services concern what is actively listening, default configurations concern unchanged factory settings, vulnerable encryption concerns weak cryptography, and end-of-life software concerns unsupported systems.

Submit
Please wait...
About This Quiz
CompTIA PenTest + Pt0-003 (V3) Exam (New Version) Practice Test 5 - Quiz

This practice test focuses on the CompTIA PenTest + PT0-003 (V3) exam, assessing your knowledge of penetration testing methodologies, tools, and techniques. It evaluates critical skills such as vulnerability assessment, exploitation, and reporting. This resource is essential for anyone preparing for the certification, helping you identify strengths and areas fo... see moreimprovement in your understanding of penetration testing concepts. see less

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. At the conclusion of an engagement, before wiping any collected data or removing tools, the tester first securely archives screenshots, command output, and captured credentials in an encrypted format for inclusion as evidence in the final report. Which cleanup-related activity does this represent?

Explanation

Securely archiving evidence like screenshots, command output, and captured credentials before disposing of anything else is preserving artifacts, ensuring the report can be properly substantiated. Removing tools and reverting configuration changes address the client's systems, secure data destruction happens after artifacts are preserved, and spinning down infrastructure concerns the tester's own external systems.

Submit

3. A tester stages collected sensitive files inside an encrypted container file, then mounts that container as a virtual drive on the compromised host only when actively adding or retrieving data, keeping it unmounted and its contents inaccessible the rest of the time. Which technique is this?

Explanation

Staging data inside an encrypted container mounted as a virtual drive only when needed is virtual drive mounting. Alternate data streams hide data within NTFS file attributes, text storage sites paste data to public websites, cross-account resources move data between cloud accounts, and steganography hides data within another file's content such as an image.

Submit

4. Match each lateral movement tool to its primary function.

Explanation

Proxychains routes arbitrary tools through a proxy chain, sshuttle creates a transparent tunnel over SSH, CrackMapExec automates authentication and enumeration across many hosts at once, and Netcat is a flexible general-purpose networking utility, each serving a distinct role in lateral movement tooling.

Submit

5. Rather than installing any malware or creating a new account, a tester who has captured a legitimate employee's valid username and password simply uses those credentials to log back into the environment whenever needed throughout the engagement. Which persistence approach is this?

Explanation

Using a captured legitimate credential to regain access repeatedly, without installing additional software, is the persistence technique of obtaining valid account credentials. A backdoor and rootkit both involve installing something on the target system, and a scheduled task and registry key are other Windows-specific persistence mechanisms.

Submit

6. A tester wants a Python library collection providing low-level access to construct and manipulate network protocols like SMB and Kerberos for building custom attack and lateral movement tools. Which tool fits this description?

Explanation

Impacket is a Python library collection specifically providing low-level access to construct and manipulate protocols like SMB and Kerberos. Scapy is a more general packet crafting library not specific to these Windows protocols, PowerSploit and PowerView are PowerShell-based tools, and Caldera is a breach and attack simulation orchestration platform.

Submit

7. A tester sends unsolicited messages to nearby Bluetooth-enabled devices in a crowded conference area, without attempting to pair with or extract data from those devices, simply to demonstrate the devices' discoverability and lack of restrictions. Which attack is this?

Explanation

Bluejacking sends unsolicited messages to nearby Bluetooth devices without pairing or extracting data. NFC and RFID attacks target different short-range wireless technologies, Bluetooth spamming typically refers to overwhelming a device or channel with excessive traffic, and register manipulation is an OT attack technique unrelated to Bluetooth.

Submit

8. Rather than directly targeting a hardened corporate network, a tester compromises a third-party industry news website that employees of the target company are known to frequently visit, planting malicious code that only activates for visitors from the target company's IP range. Which attack is this?

Explanation

A watering hole attack compromises a site the target is known to frequent rather than attacking them directly. Phishing and spearphishing involve direct email-based deception, impersonation involves posing as a trusted person or entity directly, and credential harvesting collects login information through a fake portal.

Submit

9. A tester broadcasts high-power radio frequency noise on the same channel as a target's wireless network, degrading or completely disrupting legitimate wireless communication in the area as part of an availability-focused test. Which attack is this?

Explanation

Broadcasting radio frequency noise to degrade or disrupt wireless communication broadly is signal jamming. Deauthentication forcibly disconnects specific clients using crafted management frames, an evil twin attack sets up a rogue access point, a WPS PIN attack targets a specific authentication mechanism, and wardriving is a reconnaissance activity.

Submit

10. A tester demonstrates that two different input files can be crafted to produce the exact same hash value under an outdated hashing algorithm used by a client's file integrity verification system, undermining trust in that verification. Which attack is this?

Explanation

A collision attack finds two different inputs that produce the same hash output under a weak hashing algorithm, undermining systems relying on hash uniqueness. A brute-force attack systematically tries combinations to find a specific match, session hijacking steals an active session, directory traversal accesses files outside an intended directory, and arbitrary code execution runs attacker-controlled code.

Submit

11. A tester interacting with a locked-down public kiosk application finds a way to trigger a file open dialog box, which then gives access to the underlying operating system's file explorer and command execution, breaking out of the restricted kiosk interface. Which attack technique is this?

Explanation

Breaking out of a restricted kiosk application's locked-down interface to reach the underlying OS is specifically kiosk escape. A shell escape breaks out of a restricted command shell rather than a kiosk GUI application specifically, library injection loads malicious code into a running process, process hollowing replaces a suspended process's memory, and log tampering alters log records.

Submit

12. In one test, a tester manipulates login form input to alter an underlying directory service query's logic, attempting to bypass authentication. In a separate test, another tester forges a ticket-granting ticket to impersonate any user in the domain indefinitely. Which two attack categories are described, respectively?

Explanation

Manipulating login input to alter a directory service query's logic is LDAP injection, while forging a ticket-granting ticket to impersonate any domain user is a Kerberos attack. SAML and OIDC attacks target different federated identity protocols, and a dictionary attack tries candidate passwords rather than manipulating query syntax or forging tickets.

Submit

13. A tester finds a workstation with network interfaces connected to both the corporate office network and a separate, supposedly isolated lab network, and uses that workstation to route traffic between the two. Which network attack concept does this exploit?

Explanation

Exploiting a host connected to multiple network segments to route traffic between them, bridging networks that should be isolated, is multihomed host exploitation. VLAN hopping crosses trunking-based boundaries specifically, an on-path attack intercepts traffic between two parties, a relay attack forwards captured authentication material, and share enumeration lists accessible network shares.

Submit

14. A tester assessing an industrial control environment references a model that describes distinct hierarchical levels, from field devices and controllers up through enterprise business systems, to understand appropriate network segmentation boundaries. Which framework is this?

Explanation

The Purdue model describes hierarchical levels in industrial control environments, from field devices up through enterprise systems, used to understand segmentation boundaries. MITRE ATT&CK catalogs adversary techniques, OWASP Top 10 lists web application risks, CREST is a professional accreditation body, and OCTAVE is a broader organizational risk assessment methodology.

Submit

15. A tester manipulates the pins inside a physical door lock using specialized tools to open it without a key or the correct access credential, as part of testing a facility's physical security controls. Which technique is this?

Explanation

Lock picking manipulates a physical lock's internal mechanism to open it without the correct key or credential. Tailgating follows an authorized person through a door, badge cloning duplicates access card data, a USB drop leaves malicious media for someone to find, and a site survey observes and documents physical security controls.

Submit

16. A tester notices a vulnerability scan returned suspiciously few results for a large subnet and discovers the scanner's credentials had expired partway through, causing most hosts to be scanned without authentication. Fixing the credentials and rerunning the scan is an example of which activity?

Explanation

Diagnosing and fixing the underlying cause of a scan problem, such as expired credentials, is troubleshooting scan configurations. Public exploit selection concerns choosing an exploit for a confirmed finding, scan completeness assessment identifies the coverage gap itself, false positive review concerns individual finding accuracy, and scripting to validate results uses code to confirm specific findings.

Submit

17. A tester wants to scan a client's entire Git repository history, not just the current codebase, for accidentally committed API keys and passwords that may still exist in old commits even if removed from the current version. Which tool is designed for this?

Explanation

TruffleHog is specifically designed to scan Git repository history, including old commits, for accidentally committed secrets. Nikto scans web servers, Kube-hunter hunts for Kubernetes cluster weaknesses, Grype scans container images for vulnerabilities, and BloodHound maps Active Directory attack paths.

Submit

18. A tester wants to identify all third-party open-source libraries used within a client's application and flag any with publicly known vulnerabilities, without analyzing the client's own custom source code. Which scan type fits this need?

Explanation

Software composition analysis identifies third-party open-source components and flags known vulnerabilities among them, without analyzing custom code. SAST analyzes the organization's own source code, DAST tests a running application, IAST combines static and dynamic techniques during runtime, and a mobile scan targets mobile-specific concerns.

Submit

19. A tester uses advanced search engine operators to find publicly indexed documents on a target's domain that contain the word 'confidential,' without directly visiting or scanning the target's servers. Which OSINT technique is this?

Explanation

Using advanced search engine operators to find indexed content on a target's domain is search engine analysis or enumeration. Network sniffing captures live traffic, banner grabbing captures service information from direct connections, HTML scraping extracts content from pages already being visited, and certificate transparency logs reveal issued TLS certificates.

Submit

20. A tester wants to search a database of internet-wide scan results to find hosts running a specific, outdated TLS certificate configuration across an entire target organization's IP ranges. Which tool is well suited to this search?

Explanation

Censys.io indexes internet-wide scan results, including certificate data, making it well suited to finding hosts with a specific outdated TLS configuration. Aircrack-ng, InSSIDer, and WiGLE.net are wireless-focused tools, and Wireshark captures live packet traffic rather than searching pre-indexed scan data.

Submit

21. A tester's script checks each discovered open port and, only if the port is 443, proceeds to attempt an HTTPS-specific banner grab; otherwise it moves on to the next port. Complete the sentence: this branching decision-based logic is called a ______.

Explanation

A conditional executes a specific action only if a condition, such as the port being 443, evaluates as true, which is exactly the branching behavior described. This differs from a loop, which repeats an action across a collection regardless of a specific condition on each item.

Submit

22. A tester who has gained low-privileged access to a file server systematically checks which folders and files that account can read, write, or modify, to identify potential privilege escalation opportunities. Which enumeration technique is this?

Explanation

Systematically checking what access rights an account has to specific resources is permission enumeration. Share enumeration identifies which network shares exist, local user enumeration identifies accounts on a host, secrets enumeration searches for exposed credentials, and attack path mapping charts a broader route to a goal.

Submit

23. A tester searches public breach databases for any previously leaked credentials associated with a target company's employee email domain, to understand potential password reuse risk before active testing begins. Which OSINT category does this represent?

Explanation

Searching public breach databases for previously leaked credentials associated with a domain is the password dumps OSINT category. Cached pages refer to archived web content, certificate transparency logs reveal issued TLS certificates, job board analysis extracts clues from postings, and network sniffing captures live network traffic.

Submit

24. A tester finds that a client's API signing key has been in continuous use, unchanged, since the API was first deployed five years ago, meaning any historical compromise of that key would still be exploitable today. Which technical control would most directly address this finding?

Explanation

Key rotation periodically replaces cryptographic keys, limiting the window during which a compromised key remains exploitable. Network segmentation restricts network paths, system hardening reduces attack surface broadly, MFA strengthens user authentication, and role-based access control governs permission assignment.

Submit

25. A penetration test report includes a section noting that the assessment window did not include the organization's disaster recovery site, and that credentials for one critical application were never provided despite requests. Which report component does this section represent?

Explanation

Documenting what was not tested, such as an excluded site or credentials never received, is the test limitations and assumptions section. The executive summary is a high-level overview, methodology describes the general approach, the attack narrative walks through the specific attack path, and recommendations describe remediation steps.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
While prioritizing targets, a tester notes that one server has no EDR...
At the conclusion of an engagement, before wiping any collected data...
A tester stages collected sensitive files inside an encrypted...
Match each lateral movement tool to its primary function.
Rather than installing any malware or creating a new account, a tester...
A tester wants a Python library collection providing low-level access...
A tester sends unsolicited messages to nearby Bluetooth-enabled...
Rather than directly targeting a hardened corporate network, a tester...
A tester broadcasts high-power radio frequency noise on the same...
A tester demonstrates that two different input files can be crafted to...
A tester interacting with a locked-down public kiosk application finds...
In one test, a tester manipulates login form input to alter an...
A tester finds a workstation with network interfaces connected to both...
A tester assessing an industrial control environment references a...
A tester manipulates the pins inside a physical door lock using...
A tester notices a vulnerability scan returned suspiciously few...
A tester wants to scan a client's entire Git repository history, not...
A tester wants to identify all third-party open-source libraries used...
A tester uses advanced search engine operators to find publicly...
A tester wants to search a database of internet-wide scan results to...
A tester's script checks each discovered open port and, only if the...
A tester who has gained low-privileged access to a file server...
A tester searches public breach databases for any previously leaked...
A tester finds that a client's API signing key has been in continuous...
A penetration test report includes a section noting that the...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!