Reinforce PT0-003 concepts with active-recall study cards covering all 5 blueprint domains. Each card shows the question on the front and the correct answer with a full explanation on the back.
Flashcards work through active recall — the process of retrieving information from memory rather than passively re-reading it. Research consistently shows that active recall produces stronger, longer-lasting memory than re-reading study guides. For PT0-003 preparation, this means flashcards are one of the highest-return study tools available.
Attempt recall first
Read the PT0-003 question on each card, pause, and attempt to formulate the answer in your own words before revealing. This retrieval attempt — even if wrong — dramatically strengthens memory compared to immediately reading the answer.
Review wrong cards again
When you get a card wrong, note it and add it back to your review pile. Spaced repetition — seeing difficult cards more frequently — is the mechanism that makes flashcard study far more efficient than linear reading.
Study by domain
Group your PT0-003 flashcard sessions by domain for the first 3–4 weeks. Master one domain before moving to the next. In the final week, shuffle all cards together to test cross-domain recall — which is what the real PT0-003 exam requires.
Short sessions beat marathon reviews
20–30 flashcard cards per session, done daily, produces better retention than a single 200-card marathon session. Five short daily sessions per week over 4 weeks gives you over 400 total card reviews — enough to reliably pass PT0-003.
Sample cards from the PT0-003 flashcard bank. Read the question, think of the answer, then read the explanation below.
A penetration tester is hired to assess the security of a company's internal network. The tester is given full network diagrams, credentials, and source code. Which type of penetration test is being performed?
White box
White box testing provides the tester with full knowledge of the target environment, including credentials and documentation.
During a pre-engagement meeting, the client states that no testing is allowed on the wireless network or on any cloud-based services hosted by third parties. Which part of the engagement documentation would specify these restrictions?
Rules of engagement (RoE)
The rules of engagement (RoE) define the scope, including what is allowed and not allowed, such as restrictions on wireless and cloud services.
A penetration tester is conducting an internal network assessment and wants to capture NTLMv2 hashes from Windows hosts without sending any authentication traffic. Which tool and attack technique should the tester use?
Responder with LLMNR/NBT-NS/mDNS poisoning
Responder poisons LLMNR/NBT-NS/mDNS to trick hosts into sending NTLM hashes to the attacker, capturing them without the attacker needing to authenticate.
During a web application test, the tester discovers a parameter that reflects user input in the response without sanitization. Which type of vulnerability is most likely present?
Reflected XSS
Reflected XSS occurs when user input is immediately reflected in the response without proper encoding or sanitization.
A tester wants to exploit a Windows service running with SYSTEM privileges that has an unquoted service path containing spaces. Which technique should be used to escalate privileges?
Unquoted service path exploitation
An unquoted service path allows placing an executable with the same name as a folder in the path, which Windows will execute with SYSTEM privileges.
A penetration tester is performing a password attack on a Windows domain and has captured NTLM hashes. Which tool can be used to perform a pass-the-hash attack to gain remote code execution on a target system?
pth-winexe
pth-winexe is a tool specifically designed for pass-the-hash attacks to execute commands on remote Windows systems.
During a web application test, the tester uses sqlmap and identifies a time-based blind SQL injection. Which technique is sqlmap using to extract data?
Time-based blind SQL injection
Time-based blind SQL injection uses conditional delays to infer the truth of queries based on response time.
A penetration tester needs to escalate privileges on a Linux system and finds that the current user can run a specific command with sudo without a password. Which tool should the tester consult to find known exploitation techniques for that command?
GTFOBins
GTFOBins is a curated list of Unix binaries that can be used to bypass local security restrictions.
A penetration tester has gained access to a Windows domain controller and wants to extract Kerberos tickets from memory to perform a pass-the-ticket attack. Which tool and command should the tester use to list and export all Kerberos tickets from the current session?
mimikatz # sekurlsa::tickets /export
To perform pass-the-ticket, the tester needs to extract Kerberos tickets from memory. Mimikatz's sekurlsa::tickets module lists all tickets in the current session and can export them with /export. The exported .kirbi files can then be injected using kerberos::ptt. Other commands like kerberos::golden forge new tickets, lsadump::dcsync retrieves the KRBTGT hash, and sekurlsa::logonpasswords extracts passwords but not tickets.
A penetration tester wants to exploit a vulnerable service on a target using a known module. Which framework provides a large database of exploit modules, payloads, and post-exploitation tools?
Metasploit Framework
The Metasploit Framework (option D) is the correct answer because it is specifically designed as a penetration testing platform that includes a vast, regularly updated database of exploit modules, payloads, and post-exploitation tools. This framework allows a tester to select a known module for a vulnerable service, configure a payload, and execute the exploit against a target, making it the standard tool for this purpose.
After gaining initial access to a Windows domain controller, a tester wants to extract password hashes from the SAM database and domain account hashes. Which Impacket tool is designed for this purpose?
secretsdump.py
D is correct because secretsdump.py is the Impacket tool specifically designed to extract password hashes from the SAM database and domain account hashes (NTDS.dit) on a Windows domain controller. It can perform remote dump operations using techniques like DRSUAPI replication or volume shadow copy, making it the standard choice for credential harvesting in penetration testing.
A penetration tester has captured a WPA2 handshake. Which tool from the Aircrack-ng suite is used to crack the pre-shared key?
aircrack-ng
Aircrack-ng (option D) is the tool in the Aircrack-ng suite specifically designed to crack WPA2 pre-shared keys (PSK) by performing an offline dictionary or brute-force attack against the captured four-way handshake. It uses the handshake data (specifically the EAPOL frames) to derive the Pairwise Master Key (PMK) and verify it against candidate passphrases, making it the correct choice for this task.
During a penetration test, you need to gather information about a target's email addresses and employee names without directly interacting with the target's systems. Which tool is most appropriate for this passive reconnaissance task?
theHarvester
theHarvester is an OSINT tool designed to gather emails, subdomains, IPs, and employee names from public sources like search engines and social media. Maltego is more for relationship mapping, Shodan for internet-facing devices, and Censys for certificate and network data.
You are performing a vulnerability scan on a web application and notice that the scanner reports a high-severity SQL injection vulnerability. However, manual testing confirms that the input is properly sanitized. Which term best describes this situation?
False positive
A false positive occurs when a scanner incorrectly identifies a vulnerability that does not exist. This is common in automated vulnerability scanning and requires manual verification.
Which Nmap scan type sends SYN packets to determine open ports without completing the TCP three-way handshake?
-sS
The SYN scan (-sS) sends a SYN packet and if a SYN/ACK is received, the port is considered open; it does not complete the handshake, making it stealthier than a full connect scan.
The PT0-003 flashcard bank covers all 5 official blueprint domains published by CompTIA. Cards are distributed proportionally, so domains with higher exam weight have more cards.
Domain Coverage
Engagement Management
Attacks and Exploits
Post-exploitation and Lateral Movement
Vulnerability Discovery and Analysis
Reconnaissance and Enumeration
Both flashcards and practice questions are evidence-based study tools. The difference is in what they train:
Flashcards — concept retention
Best for memorising definitions, acronyms, protocol behaviours, command syntax, and conceptual distinctions. Use flashcards to build the foundational vocabulary that PT0-003 questions assume you know.
Best in: weeks 1–3
Practice tests — application
Best for applying concepts to realistic scenarios, eliminating distractors, and building exam stamina.PT0-003 questions test scenario reasoning — not just recall — so practice tests are essential.
Best in: weeks 3–6
The most effective PT0-003 study plan combines both: use flashcards for the first 2–3 weeks to build conceptual foundations, then shift to practice tests and mock exams in the final 2–3 weeks to apply and benchmark that knowledge. Most candidates who pass on their first attempt use both tools.
Yes. Courseiva provides free PT0-003 flashcards across all official exam domains. Every card includes the correct answer and a full explanation of why it is right and why the distractors are wrong. The platform also includes topic-based practice, mock exams, and readiness tracking — no account required.
Courseiva has 777+ original PT0-003 flashcards across all 5 exam blueprint domains. New cards are added regularly as the question bank grows. All cards are checked against the official CompTIA exam objectives, with editorial oversight from an experienced network and security engineer.
Courseiva flashcards are purpose-built for IT certification exams. Unlike generic flashcard platforms where content quality varies, every Courseiva card is mapped to the official PT0-003 exam blueprint, written by engineers who hold the certification, and includes a full explanation of the correct answer and why the distractors are wrong. This explanation quality is what separates genuine learning from rote memorisation.
Courseiva is a web platform — an internet connection is required. For offline study, we recommend creating free Courseiva account, using the platform in your browser, and using your device's offline capabilities if your browser supports offline web apps.
Save your results, see which domains need more work, and get spaced repetition recommendations — all free.
Sign Up FreeFree forever · Every certification included