CompTIA · Free Practice Questions · Last reviewed May 2026
26real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
13% of exam · 6 sample questions below
A penetration tester is hired to assess the security of a company's internal network. The tester is given full network diagrams, credentials, and source code. Which type of penetration test is being performed?
White box
White box testing grants the tester complete knowledge of the target environment, including source code, architecture diagrams, credentials, and internal documentation. This enables deep static analysis and code-path-specific vulnerability discovery, such as identifying logic flaws or hardcoded secrets that would be invisible to a black-box approach. The elevated access reduces reconnaissance effort and speeds up the assessment, but requires the tester to prioritize findings against a vast attack surface and validate beyond mere code scanning.
Black box
Grey box
Red team
During a pre-engagement meeting, the client states that no testing is allowed on the wireless network or on any cloud-based services hosted by third parties. Which part of the engagement documentation would specify these restrictions?
Get-out-of-jail letter
Rules of engagement (RoE)
The rules of engagement (RoE) is the official document that codifies all permissible actions, boundaries, and constraints for a penetration test, including explicit 'no testing' restrictions on designated assets or services. It also specifies emergency procedures, legal boundaries, and points of contact, ensuring both client and tester agree on the exact operational parameters. In a pre-engagement meeting, the client's stated restrictions would be formally recorded in the RoE, making it the correct document that defines what is off-limits.
Statement of work (SOW)
Non-disclosure agreement (NDA)
A penetration testing company is contracted to perform a social engineering engagement. The client requests that only employees in the finance department be targeted. Which scoping consideration is most relevant?
Personnel scope
Personnel scope defines the specific subset of employees, departments, or roles that a social engineering campaign may legitimately target. For example, it may list all non-executive staff as in-scope but exclude executive leadership or a particular division for internal political reasons. This is the correct scoping element because the question asks where the target population is recorded, and that is precisely what the personnel scope does.
Rules of engagement
Production vs. staging environments
Third-party services
A penetration tester discovers evidence of ongoing criminal activity, such as a data breach by an internal employee, during a white box penetration test. The client's legal team has not provided specific instructions on handling such discoveries. According to best practices and legal considerations, what should the tester do first?
Notify law enforcement directly
Continue testing and document the evidence for later reporting
Stop testing and contact the client's emergency contact
Halting all testing and invoking the client's pre-arranged emergency contact path is the only action that both preserves the integrity of forensic evidence and keeps the engagement within its legal scope. The emergency contact is typically the client's incident-response lead or executive with authority to decide whether to involve law enforcement, issue containment orders, or terminate the test. This step ensures that the tester remains a controlled, auditable resource rather than acting unilaterally on potentially sensitive criminal matters.
Ignore the activity and proceed as planned
Which penetration testing standard provides a structured methodology for conducting penetration tests, including pre-engagement, reconnaissance, and reporting phases?
NIST SP 800-115
OWASP Testing Guide
PTES
PTES, the Penetration Testing Execution Standard, offers a comprehensive, structured methodology that explicitly defines seven phases: pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting. It standardizes both technical execution and communication, including rules of engagement, data handling, and report templates. This makes it a complete, industry-recognized standard for penetration testing, clearly surpassing the narrower guides.
OSSTMM
A company wants to simulate a real-world attack scenario where the penetration tester has no prior knowledge of the environment and must act as an external threat actor. However, the tester is allowed to use social engineering to gain initial access. Which type of engagement is most appropriate?
Red team exercise
A red team exercise is a full-scope, objective-based simulation that mimics a real adversary's tactics, techniques, and procedures (TTPs), including social engineering, physical access, email phishing, and exploitation. Unlike a single-vector assessment, it is designed to test the organization's overall security posture — people, processes, and technology — by stealthily moving toward a defined goal, such as data exfiltration or domain compromise. Social engineering is a core component because it validates whether employee awareness and security policies can resist real-world manipulation.
Network penetration test
Wireless penetration test
Web application penetration test
Want more Engagement Management practice?
Practice this domain35% of exam · 6 sample questions below
A penetration tester is conducting an internal network assessment and wants to capture NTLMv2 hashes from Windows hosts without sending any authentication traffic. Which tool and attack technique should the tester use?
Responder with LLMNR/NBT-NS/mDNS poisoning
Responder is the correct tool because it actively listens for LLMNR, NBT-NS, and mDNS name-resolution queries broadcast by Windows hosts when DNS lookups fail. By replying with a spoofed response that claims to be the requested host, Responder forces the victim to initiate an SMB authentication handshake to the attacker, sending an NTLMv2 hash in the process. This hash can then be cracked offline with hashcat or relayed with ntlmrelayx, and the attack works without any prior credentials or access to the target system.
Metasploit's hashdump module
Hashcat with a wordlist attack
Bettercap with ARP spoofing
During a web application test, the tester discovers a parameter that reflects user input in the response without sanitization. Which type of vulnerability is most likely present?
DOM-based XSS
Stored XSS
SQL injection
Reflected XSS
Reflected XSS is correct because the tester's parameter value is immediately included in the server's HTTP response without proper output encoding, creating a non-persistent vulnerability. An attacker can craft a malicious URL that, when clicked, causes the victim's browser to execute the injected script in the context of the application's origin. The immediate echo back in the response exactly matches the definition of reflected XSS, distinguishing it from stored XSS, which involves server-side persistence, and DOM-based XSS, which never involves the server response.
A tester wants to exploit a Windows service running with SYSTEM privileges that has an unquoted service path containing spaces. Which technique should be used to escalate privileges?
AlwaysInstallElevated
Token impersonation
Unquoted service path exploitation
An unquoted service path occurs when the ImagePath registry value for a service contains spaces but is not enclosed in quotes. When Windows starts the service, it attempts to locate the executable by splitting the path at each space and trying the resulting filenames, moving from left to right. If an attacker has write access to a directory earlier in that sequence, they can drop a malicious executable (e.g., C:\Program.exe or C:\Program Files\Vendor.exe) that Windows will execute with the service's SYSTEM privileges. This is the correct exploitation method because it directly abuses the service's own path configuration to achieve code execution as SYSTEM.
DLL hijacking
A penetration tester is performing a password attack on a Windows domain and has captured NTLM hashes. Which tool can be used to perform a pass-the-hash attack to gain remote code execution on a target system?
Hashcat
Responder
pth-winexe
pth-winexe is part of the pass-the-hash toolkit that implements the Windows SMB client and authentication stack, allowing you to authenticate to a remote Windows host using only the NTLM hash as the credential. It substitutes the password in the NTLM/SPNEGO exchange with the hash, establishes an authenticated session, and executes a specified command without ever knowing the plaintext password. This directly demonstrates pass-the-hash: the hash itself serves as the proof of knowledge to impersonate the user.
John the Ripper
During a web application test, the tester uses sqlmap and identifies a time-based blind SQL injection. Which technique is sqlmap using to extract data?
Error-based SQL injection
Boolean-based blind SQL injection
UNION-based SQL injection
Time-based blind SQL injection
Time-based blind SQL injection is the correct answer because the tester can extract data by injecting conditional expressions that invoke database delay functions, such as `IF(condition, SLEEP(5), 0)` in MySQL or `WAITFOR DELAY '0:0:5'` in MSSQL, and then measuring the application's response time. Sqlmap automatically generates these payloads and uses a statistical threshold to distinguish between true and false conditions based on elapsed time, making it effective when no error messages or content changes are visible. This aligns perfectly with the scenario where the tester used sqlmap and observed time-based behavior.
A penetration tester needs to escalate privileges on a Linux system and finds that the current user can run a specific command with sudo without a password. Which tool should the tester consult to find known exploitation techniques for that command?
Exploit-DB
HackTricks
Metasploit
GTFOBins
GTFOBins is the authoritative, community-maintained list of Unix binaries that can be abused to bypass local security restrictions, with a dedicated 'sudo' section. It provides exact commands—such as `sudo find . -exec /bin/sh \;`—for each binary that can be used to escalate privileges when that binary is listed in the sudoers file. Cross-referencing the output of `sudo -l` against GTFOBins is the standard technique for detecting sudo misconfigurations during a Linux privilege escalation assessment.
Want more Attacks and Exploits practice?
Practice this domain14% of exam · 2 sample questions below
A penetration tester has gained access to a Windows domain controller and wants to extract Kerberos tickets from memory to perform a pass-the-ticket attack. Which tool and command should the tester use to list and export all Kerberos tickets from the current session?
mimikatz # sekurlsa::tickets /export
The sekurlsa::tickets command in Mimikatz lists all Kerberos tickets in memory for the current session, and the /export option exports them to .kirbi files. These files can then be used with kerberos::ptt to inject the tickets into a new session, enabling pass-the-ticket. This is the standard method for extracting and reusing Kerberos tickets during post-exploitation.
mimikatz # lsadump::dcsync /user:krbtgt
mimikatz # sekurlsa::logonpasswords
mimikatz # kerberos::golden /user:Administrator /domain:example.com /sid:S-1-5-21-... /krbtgt:... /ticket:golden.kirbi
A penetration tester has compromised a Windows host and wants to perform lateral movement using WMI. The tester has obtained local administrator credentials for the target host but wants to avoid writing files to disk. Which two methods can be used to execute commands remotely via WMI without creating files on the target? (Choose two.)
Using wmic /node:target process call create "cmd.exe /c ..."
The wmic command-line tool can execute processes on a remote host via WMI. When using process call create, it creates a new process on the target, which runs the specified command. This does not require writing a file to disk on the target, as the command is executed directly. However, it may create temporary files depending on the command, but the WMI mechanism itself does not write a payload to disk. This is a common fileless lateral movement technique.
Using winrs -r:target cmd.exe
Using schtasks /create /s target /tn ... /tr ... /sc once /st ...
Using Invoke-WmiMethod -Class Win32_Process -Name Create -ComputerName target -ArgumentList "cmd.exe /c ..."
The Invoke-WmiMethod PowerShell cmdlet calls the Win32_Process Create method on a remote computer. This executes the specified command without writing any files to the target's disk. The command runs in the context of the WMI provider, and the output can be captured if needed. This is a fileless method for remote command execution via WMI, often used in penetration testing to avoid leaving artifacts on disk.
Using psexec.exe \\target -accepteula cmd.exe
Want more Post-exploitation and Lateral Movement practice?
Practice this domain17% of exam · 6 sample questions below
A penetration tester wants to exploit a vulnerable service on a target using a known module. Which framework provides a large database of exploit modules, payloads, and post-exploitation tools?
Burp Suite
Wireshark
Nmap
Metasploit Framework
The Metasploit Framework is the correct choice because it is a dedicated exploitation framework with a large, continuously updated database of exploit modules, payloads, encoders, and post-exploitation tools. It allows a penetration tester to pair a specific exploit (e.g., a buffer overflow in a network service) with a compatible payload (e.g., Meterpreter reverse shell), then launch the attack and maintain interactive access to the compromised host. This workflow directly matches the task of exploiting a vulnerable service, encompassing both the delivery and the post-exploitation phases that standalone tools like Wireshark or Nmap lack.
After gaining initial access to a Windows domain controller, a tester wants to extract password hashes from the SAM database and domain account hashes. Which Impacket tool is designed for this purpose?
psexec.py
GetUserSPNs.py
wmiexec.py
secretsdump.py
secretsdump.py is an Impacket tool that copies the SAM, SYSTEM, and SECURITY hives from a local Windows machine, or remotely retrieves NTDS.dit and registry data using Volume Shadow Copy or the DRSUAPI (DCSync) protocol. On a domain controller, it can extract all domain password hashes, including NTDS.dit database and cached credentials, without requiring additional tools on the target. Its ability to perform DCSync and remote registry reads makes it the standard for credential harvesting after gaining admin access to Active Directory.
A penetration tester has captured a WPA2 handshake. Which tool from the Aircrack-ng suite is used to crack the pre-shared key?
airmon-ng
airodump-ng
aireplay-ng
aircrack-ng
Aircrack-ng performs the actual offline cryptanalysis of the captured four-way handshake, deriving the WPA2 pre-shared key by testing candidate passphrases against the MIC. Other suite tools only capture, inject or deauthenticate; aircrack-ng is the cracking component the scenario requires.
During a code review of a PHP web application, you encounter the following code: $result = mysql_query("SELECT * FROM users WHERE username='" . $_GET['user'] . "'");. Which vulnerability does this represent?
Cross-site scripting (XSS)
Path traversal
Command injection
SQL injection
SQL injection is confirmed when user input is embedded directly into an SQL query without sanitization or parameterization, allowing the attacker to modify the query's logic. For example, input like ' OR '1'='1 can bypass authentication, and UNION SELECT statements can extract data from other tables. This occurs because the database engine interprets the attacker's input as part of the SQL syntax, not just as data. Proper defense involves prepared statements with bound parameters or stored procedures, which separate data from SQL code.
A tester needs to brute-force SSH credentials on a target. Which tool is most appropriate for this task?
Aircrack-ng
Hashcat
Hydra
Hydra is the correct choice because it is a network logon cracker that supports the SSH protocol among hundreds of others. It can supply username/password pairs from wordlists, perform parallel connection attempts, and handle SSH's banner and authentication exchange, making it ideal for online brute-force testing against a live target.
John the Ripper
In a Python script for a penetration test, you need to craft a custom TCP packet with specific flags. Which library is best suited for low-level packet manipulation?
requests
scapy
Scapy is purpose-built for packet crafting and manipulation. It provides a declarative, layer-by-layer API where you can compose packets like `IP(src='10.0.0.1')/TCP(dport=80, flags='S')`, then send them with functions such as `send()`, `sendp()`, or `sr()`. Scapy also handles checksum calculation, fragmentation, retransmissions, and dissection of responses, making it the de facto standard for network exploration, fuzzing, and custom TCP flag testing in penetration tests.
socket
impacket
Want more Vulnerability Discovery and Analysis practice?
Practice this domain21% of exam · 6 sample questions below
During a penetration test, you need to gather information about a target's email addresses and employee names without directly interacting with the target's systems. Which tool is most appropriate for this passive reconnaissance task?
Shodan
Censys
Maltego
theHarvester
theHarvester is the correct answer because it is a dedicated OSINT tool engineered to passively gather emails, subdomains, hostnames, and employee names from public sources. It queries search engines like Bing and Google, PGP key servers, and other open data repositories, making it ideal for the early reconnaissance phase of a penetration test. Its specific focus on email harvesting and subdomain enumeration aligns precisely with the task of gathering information about an organization's digital footprint, unlike general-purpose scanners or link-analysis platforms.
You are performing a vulnerability scan on a web application and notice that the scanner reports a high-severity SQL injection vulnerability. However, manual testing confirms that the input is properly sanitized. Which term best describes this situation?
False negative
True positive
Inconclusive
False positive
A false positive is an incorrect alert in which the scanner reports a vulnerability that does not actually exist in the web application, such as flagging a sanitized input parameter as SQL injectable. This often occurs due to heuristic detection misfires, outdated signature databases, or responses that imitate vulnerability patterns without the underlying weakness. It consumes security team time and resources on investigating and remediating non-existent issues, highlighting why every automated finding should be validated before being acted upon.
Which Nmap scan type sends SYN packets to determine open ports without completing the TCP three-way handshake?
-sU
-sS
The -sS option, Nmap's default SYN scan, transmits a raw TCP packet with only the SYN flag set to each port; an open port replies with a SYN/ACK, a closed port with an RST, and a filtered port drops the packet or returns an ICMP unreachable. Because Nmap aborts the handshake immediately upon receiving SYN/ACK, it determines TCP port state without ever completing a full connection, making it fast and relatively unobtrusive.
-sT
-sN
You are conducting a penetration test and need to identify subdomains of a target domain using a passive approach that does not generate traffic to the target's servers. Which technique should you use?
Certificate transparency logs
Certificate transparency logs are a passive discovery resource because they are publicly available, append-only ledgers maintained by independent log operators, and querying them does not involve sending any packets to the target organization's own servers or infrastructure. Services like crt.sh or Censys provide APIs that return certificates issued for a domain, often revealing subdomains, wildcard entries, and even expired certificates that were previously in use. This method leaves no trace on the target's DNS logs, web servers, or intrusion detection systems, making it a classic OSINT/ passive-recon technique. For a penetration tester, it provides a high-yield, low-risk baseline for expanding the attack surface before active testing begins.
DNS cache snooping
Subdomain bruteforce with gobuster
DNS zone transfer
During a penetration test, you want to discover API endpoints and hidden parameters in a web application. Which tool combination is most effective for this task?
Wappalyzer and curl
WhatWeb and theHarvester
Gobuster and Nikto
Arjun and ffuf
Arjun discovers hidden API parameters and endpoints through its extensive wordlists and passive/active scanning, while ffuf fuzzes directories, parameters and virtual hosts at high speed. Together they satisfy the stem's need to uncover endpoints and hidden parameters in a web application.
Which tool is specifically designed for scanning WordPress websites to detect vulnerabilities, such as outdated plugins, themes, and weak passwords?
OpenVAS
Nikto
WPScan
WPScan is a dedicated WordPress vulnerability scanner that enumerates installed plugins, themes and users, then checks them against known vulnerability databases and tests for weak credentials. Generic web scanners lack this WordPress-specific enumeration and detection logic.
Nessus
Want more Reconnaissance and Enumeration practice?
Practice this domainThe PT0-003 exam has 85 questions and must be completed in 165 minutes. The passing score is 750/1000.
Multiple-choice and performance-based questions covering IT security, networking, and operations. Some questions are performance-based (PBQs), asking you to complete tasks in a simulated environment.
The exam covers 5 domains: Engagement Management, Attacks and Exploits, Post-exploitation and Lateral Movement, Vulnerability Discovery and Analysis, Reconnaissance and Enumeration. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official CompTIA PT0-003 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.