Courseiva
Free · No account needed · No credit card

CompTIA PenTest+ (PT0-003) Practice Test

777 questions with instant explanations, domain breakdown, and wrong-answer analysis. Built for the real exam.

Instant feedback after each answer
Full explanations included
Domain score breakdown
Real exam: 165 min
Pass mark: 750/1000

Sample questions with explanations

This is exactly what you see during practice — question, options, and a full explanation after you answer.

During a penetration test, the tester discovers a critical vulnerability that could lead to a data breach. The tester needs to communicate this to the client's management, who are non-technical. What is the BEST way to communicate this finding?

AInclude the finding only in the final report
High-level summary with business impact and recommended timeline for fixCorrect
CEmail with subject 'URGENT' and no further details
DDetailed technical exploit steps

Option B is correct because communicating a critical vulnerability to non-technical management requires translating the technical finding into business terms, so a high-level summary that states the business impact (e.g., potential data breach, regulatory exposure, financial loss…Read full explanation

A penetration tester wants to identify all publicly accessible Amazon S3 buckets that belong to a specific organization. Which technique is most effective for passive reconnaissance?

Use Google dorks to search for bucket names and URLs.Correct
BSend DNS queries for common bucket name prefixes.
CUse nmap to scan all AWS IP ranges for open ports.
DPerform a DNS zone transfer on the target organization's domain.

Google dorks (e.g., site:s3.amazonaws.com "companyname") allow a penetration tester to passively discover publicly accessible S3 bucket names and URLs indexed by search engines without sending any traffic to the target organization. This technique leverages existing search engine…Read full explanation

A penetration tester is writing a Bash script to automate enumeration of a Linux system after gaining a shell. The script needs to extract user information from the /etc/passwd file. Which command would be most efficient for listing only the usernames?

cat /etc/passwd | cut -d: -f1Correct
Bcat /etc/passwd | awk '{print $1}'
Ccat /etc/passwd | head
Dgrep 'user' /etc/passwd

The `cut` command with `-d: -f1` splits each line of /etc/passwd on the colon delimiter and extracts the first field, which is the username. This is the most efficient and purpose-built approach for parsing colon-delimited files in Linux, avoiding unnecessary overhead from other …Read full explanation

Untimed Practice

Answer at your own pace. Explanation and domain tag shown immediately after each answer.

Timed Practice

Countdown timer starts immediately. Results and domain scores shown at the end — just like the real exam.

Why practice here?

Full explanations on every question

Not just the right answer — you get exactly why each wrong option is wrong, so you learn the concept, not the answer.

Domain score breakdown

After each session see your score by exam domain so you know exactly where to focus study time.

100% free, forever

No subscription, no trial, no email wall. Start a session in under 10 seconds.

Exam-style questions

Scenario-based, precise wording, realistic distractors — written to match what you actually see on exam day.

← All PT0-003 questionsPT0-003 exam guideStudy guidePractice by domain