CompTIA · PenTest+ · PT0-002 (retired) → PT0-003 (current) · Practice Exam

CompTIA PenTest+ (PT0-002) Practice Exam

PenTest+ validates hands-on penetration-testing and vulnerability-assessment skills across the full engagement — scoping, reconnaissance, exploitation, and reporting. Note: PT0-002 has retired; the current exam is PT0-003. This practice covers the penetration-testing fundamentals shared by both versions, in Learn mode and timed Exam mode.

Start 24-hour free trial →
500+
Practice questions
5
Objective domains
2
Study modes
24h
Free trial
PT0-002 has retired — the current exam is PenTest+ PT0-003. CompTIA retired the PT0-002 version of PenTest+ on June 17, 2025; it can no longer be scheduled. The current, bookable version is PenTest+ PT0-003 (launched December 17, 2024), which adds AI-based attacks and expanded cloud and API exploitation and reorganises the domains. If you already hold PenTest+, your certification stays valid for three years from your test date. If you are studying now, prepare for PT0-003. See the current CompTIA PenTest+ (PT0-003) page →

PenTest+ PT0-002 at a glance (retired version)

Vendor
CompTIA
Exam code
PT0-002 (retired)
Certification
CompTIA PenTest+
Level
Intermediate (offensive security / penetration testing)
Status
Retired June 17, 2025; superseded by PT0-003
Format
Maximum of 85 questions; multiple-choice and performance-based
Duration
165 minutes
Passing score
750 on a scale of 100–900
Delivery
Pearson VUE test center or online proctored (while it was active)
Recommended experience
3–4 years of hands-on penetration-testing, vulnerability-assessment, and code-analysis experience; Network+ and Security+ or equivalent
Current version
PT0-003 — max 90 questions, 165 minutes, passing 750 (100–900)

Source: CompTIA — PenTest+ (current PT0-003 page, with prior-version retirement dates). PT0-002 facts reflect its final published objectives; verify the current exam with CompTIA before scheduling.

About CompTIA PenTest+ (PT0-002 → PT0-003)

PenTest+ is CompTIA’s intermediate, hands-on penetration-testing certification — the offensive-security counterpart to the defensively-oriented CySA+. It validates that you can run a full engagement end to end: plan and scope it legally, gather intelligence and scan for weaknesses, exploit what you find across networks, web apps, cloud, wireless and hosts, and then write up the findings so a client can act on them. It sits above Security+ and is aimed at practitioners with roughly three to four years of experience.

Version status matters here. The PT0-002 version this page is named for retired on June 17, 2025 and can no longer be booked. The current exam is PT0-003, which launched December 17, 2024 and adds coverage of AI-assisted attacks, expanded cloud and API exploitation, and modern post-exploitation, while reorganising the five domains. If you are starting fresh, study for PT0-003; if you already passed PenTest+ on PT0-002, your certification remains valid for three years from your test date.

The penetration-testing fundamentals themselves are stable across both versions — scoping and rules of engagement, OSINT and active reconnaissance, common exploit classes, privilege escalation, evidence handling and reporting — so the practice below is built on that shared core and remains directly useful for PT0-003. For the concepts behind every domain, start with our enterprise security practices guide.

PenTest+ PT0-002 domains and weights (retired version)

The retired PT0-002 exam split across five domains summing to 100%. Attacks and Exploits was by far the heaviest at 30%. (The current PT0-003 reorganises these — see the deep dive below for the mapping.)

Attacks and Exploits

Network, wireless, application-based, cloud, and host attacks; social engineering; post-exploitation techniques such as lateral movement, privilege escalation, and persistence.

30%Heaviest domain
Information Gathering and Vulnerability Scanning

Passive and active reconnaissance (OSINT, enumeration), vulnerability scanning with tools like Nmap and scanners, and analysing the results to prioritise targets.

22%
Reporting and Communication

Writing findings and recommendations, communicating with stakeholders, remediation guidance, and the professional and delivery aspects of closing an engagement.

18%
Tools and Code Analysis

Understanding common pentest tools and their use, plus reading and analysing scripts and code snippets (Bash, Python, Ruby, PowerShell) used during testing.

16%
Planning and Scoping

Governance, risk and compliance; legal concepts and permission to attack; rules of engagement; defining and documenting the scope of a test.

14%

Source: CompTIA — PenTest+. PT0-002 weights reflect its final (retired) objectives and total 100%. For the current PT0-003 domain split, see the deep dive.

Who PenTest+ is for

PenTest+ targets working offensive-security practitioners rather than beginners — CompTIA recommends three to four years of hands-on experience, with Security+ level knowledge assumed:

  • Penetration testers and red-team members validating a vendor-neutral, DoD-recognised credential covering the full engagement lifecycle.
  • Vulnerability and security analysts moving from defensive work into offensive testing and wanting proof of hands-on exploitation skills.
  • Security consultants whose clients or contracts require a recognised penetration-testing certification.
  • Government and defence staff pursuing roles mapped to DoD 8140 work roles, where PenTest+ is an approved baseline.

If you are earlier in the security path, Security+ is the foundation below PenTest+, and CySA+ is the defensive analyst counterpart. For where offensive-security work leads — roles, responsibilities and salary ranges — see the cybersecurity specialist career track in our Career Hub.

What this PenTest+ practice exam delivers

Learn mode

Correct answer, the reasoning, why each distractor fails, and a link to the concept — immediately after each question. Best for the attacks-and-exploits and reconnaissance material, where the right move depends on the phase of the engagement.

Exam mode

A timed simulation on the PenTest+ format — multiple-choice plus performance-based items across all five domains. Builds pacing and stamina for the 165-minute exam, current PT0-003 included.

Source-linked explanations

Every answer links to the concept it tests on CompTIA’s PenTest+ objectives or a PowerKram deep-dive, so you can verify and read further rather than memorise.

Score by domain

Results break down across the objective areas, so practice tells you whether the next session goes on scoping, reconnaissance, exploitation, tooling, or reporting.

Sample PenTest+ practice questions

Ten free questions on penetration-testing fundamentals that carry across PT0-002 and the current PT0-003, each with a full explanation and a link to the concept it tests. The complete bank comes with the 24-hour trial.

Question 1 · Planning and Scoping

Before any testing begins, which document defines the boundaries, permitted targets, and constraints of the engagement, protecting the tester legally?

  1. The rules of engagement (and signed scope/authorization)
  2. The final penetration-test report
  3. The vulnerability scan output
  4. The exploit payload
Show answer & explanation

Correct: A — the rules of engagement and signed scope/authorization. Scope, permitted targets, timing, and constraints are agreed and signed before testing starts; this written authorization (“permission to attack”) is what makes the work legal and defines its limits.

Why not the others: the report (B) comes at the end of the engagement; scan output (C) is a result produced during testing, not the authorizing document; an exploit payload (D) is a tool used in testing, not a scoping artifact.

Source: CompTIA PenTest+ — planning and scoping →
Question 2 · Information Gathering and Vulnerability Scanning

A tester wants to learn about a target using only publicly available information, without sending any packets to the target’s systems. Which activity is this?

  1. An authenticated vulnerability scan
  2. Passive reconnaissance (OSINT)
  3. A brute-force attack
  4. Privilege escalation
Show answer & explanation

Correct: B — passive reconnaissance (OSINT). Gathering open-source intelligence — public records, DNS data, social media, leaked credentials — without touching the target’s systems is passive reconnaissance, the stealthiest first information-gathering step.

Why not the others: an authenticated scan (A) actively probes the target; a brute-force attack (C) is an active exploit attempt; privilege escalation (D) happens post-exploitation, after access is gained.

Source: CompTIA PenTest+ — information gathering → Further reading: PowerKram — enterprise security practices →
Question 3 · Information Gathering and Vulnerability Scanning

During active reconnaissance, which tool is most commonly used to discover live hosts, open ports, and running services on a network?

  1. Wireshark
  2. Metasploit
  3. Nmap
  4. John the Ripper
Show answer & explanation

Correct: C — Nmap. Nmap is the standard port-and-service scanner for host discovery, open-port enumeration, and service/version detection — the core active-reconnaissance tool in the PenTest+ toolset.

Why not the others: Wireshark (A) captures and analyses packets but does not scan for hosts/ports; Metasploit (B) is an exploitation framework; John the Ripper (D) is a password cracker. None is the primary discovery scanner.

Source: CompTIA PenTest+ — scanning tools →
Question 4 · Attacks and Exploits

A web form passes user input directly into a backend database query without sanitisation, letting an attacker read arbitrary tables. Which attack is this?

  1. Cross-site scripting (XSS)
  2. Denial of service
  3. ARP spoofing
  4. SQL injection
Show answer & explanation

Correct: D — SQL injection. Passing unsanitised input into a database query lets an attacker alter the query to read or modify data — the defining mechanism of SQL injection, a core application-attack objective.

Why not the others: XSS (A) injects script into pages viewed by other users, not into database queries; denial of service (B) disrupts availability; ARP spoofing (C) is a network-layer man-in-the-middle technique. None describes database-query manipulation.

Source: CompTIA PenTest+ — application attacks → Further reading: PowerKram — enterprise security practices →
Question 5 · Attacks and Exploits

After gaining a low-privilege shell on a Linux host, a tester exploits a misconfigured SUID binary to gain root. What is this step called?

  1. Privilege escalation
  2. Passive reconnaissance
  3. Scoping
  4. Report writing
Show answer & explanation

Correct: A — privilege escalation. Moving from a low-privilege foothold to higher (here, root) rights by abusing a misconfiguration — such as a SUID binary — is vertical privilege escalation, a key post-exploitation activity.

Why not the others: passive reconnaissance (B) is pre-attack intelligence gathering; scoping (C) happens before testing begins; report writing (D) is the closing phase. None describes elevating rights on a compromised host.

Source: CompTIA PenTest+ — post-exploitation →
Question 6 · Attacks and Exploits

A tester sends targeted emails impersonating IT support to trick employees into revealing credentials. Which attack category is this?

  1. SQL injection
  2. Social engineering (phishing)
  3. Buffer overflow
  4. Port scanning
Show answer & explanation

Correct: B — social engineering (phishing). Manipulating people into divulging credentials or taking unsafe actions — here via a targeted phishing email — is social engineering, an explicit part of the attacks-and-exploits domain.

Why not the others: SQL injection (A) targets databases, not people; a buffer overflow (C) exploits memory handling in software; port scanning (D) is reconnaissance. Only phishing exploits human behaviour.

Source: CompTIA PenTest+ — social engineering → Further reading: PowerKram — enterprise security practices →
Question 7 · Tools and Code Analysis

A tester needs an exploitation framework that bundles exploits, payloads, and post-exploitation modules to deliver and manage a compromise. Which tool fits?

  1. Nmap
  2. Burp Suite
  3. Metasploit Framework
  4. tcpdump
Show answer & explanation

Correct: C — Metasploit Framework. Metasploit bundles exploits, payloads, encoders, and post-exploitation modules into one framework for delivering and managing a compromise — the canonical exploitation toolkit in the tools domain.

Why not the others: Nmap (A) is a scanner; Burp Suite (B) is a web-application proxy for testing web apps, not a general exploitation framework; tcpdump (D) is a packet capture tool. None is a full exploitation framework.

Source: CompTIA PenTest+ — tools → Further reading: PowerKram — how IT certifications fit together →
Question 8 · Attacks and Exploits

After compromising one host, a tester uses harvested credentials to access other systems across the network. What is this movement called?

  1. Scoping
  2. Vulnerability scanning
  3. Report delivery
  4. Lateral movement
Show answer & explanation

Correct: D — lateral movement. Using access or credentials from one compromised host to reach additional systems — for example via pass-the-hash — is lateral movement, a post-exploitation technique for expanding a foothold.

Why not the others: scoping (A) is the pre-engagement planning step; vulnerability scanning (B) is reconnaissance; report delivery (C) is the closing phase. Only lateral movement describes spreading across the network after initial compromise.

Source: CompTIA PenTest+ — lateral movement →
Question 9 · Reporting and Communication

When documenting evidence collected during a penetration test, which practice preserves its integrity and admissibility?

  1. Deleting logs after the test
  2. Maintaining a documented chain of custody
  3. Sharing findings publicly
  4. Skipping timestamps to save time
Show answer & explanation

Correct: B — maintaining a documented chain of custody. Recording who handled each piece of evidence, when, and how preserves its integrity and admissibility — a reporting-and-communication requirement that also protects the tester and client.

Why not the others: deleting logs (A) destroys evidence; sharing findings publicly (C) breaches confidentiality; skipping timestamps (D) undermines the very integrity chain of custody exists to protect.

Source: CompTIA PenTest+ — reporting and communication → Further reading: PowerKram — cybersecurity specialist career track →
Question 10 · Reporting and Communication

A penetration-test report lists several findings. Which approach best helps the client fix the most important issues first?

  1. List findings in the order they were discovered
  2. Include only the technical exploit code
  3. Prioritise findings by risk (severity and business impact) with remediation guidance
  4. Omit remediation steps to keep the report short
Show answer & explanation

Correct: C — prioritise by risk with remediation guidance. Ranking findings by severity and business impact, each with clear remediation advice, is what lets a client fix the highest-risk issues first — the core purpose of the reporting domain.

Why not the others: discovery order (A) ignores severity; exploit code only (B) is not actionable for most stakeholders; omitting remediation (D) strips the report of its practical value.

Source: CompTIA PenTest+ — risk-based reporting →

Keep going: study guides and career paths

PenTest+ is a hands-on, offensive-security credential, so the supporting material is practical. Two PowerKram resources back this exam directly.

Deep dive: the PT0-002 to PT0-003 transition, format, and where PenTest+ sits

The PT0-002 to PT0-003 transition

CompTIA retired PT0-002 on June 17, 2025, six months after PT0-003 launched on December 17, 2024. PT0-003 is now the only bookable version. The refresh added coverage of AI-based attacks, expanded cloud and API exploitation, and modernised post-exploitation, and it reorganised the domains — but the core role and passing bar are unchanged, and a PenTest+ earned on PT0-002 remains valid for three years from the test date. If you are studying now, use PT0-003-aligned material. Read the security practices guide →

PT0-002 vs PT0-003 domains

PT0-002 used five domains: Planning and Scoping (14%), Information Gathering and Vulnerability Scanning (22%), Attacks and Exploits (30%), Reporting and Communication (18%), and Tools and Code Analysis (16%). PT0-003 also uses five, re-cut as Engagement Management (13%), Reconnaissance and Enumeration (21%), Vulnerability Discovery and Analysis (17%), Attacks and Exploits (35%), and Post-exploitation and Lateral Movement (14%). The through-line is clear: exploitation is the heaviest area in both, and PT0-003 splits reconnaissance and vulnerability work into their own domains and promotes post-exploitation to a named domain. See how IT certifications fit together →

Format and scoring

PT0-002 delivered a maximum of 85 questions in 165 minutes; PT0-003 raises the maximum to 90 questions in the same 165-minute window. Both mix multiple-choice with performance-based questions that put you in a simulated environment to complete real tasks, and both are scored on the 100–900 scale with a passing score of 750. Because the performance-based items reward hands-on fluency, a home lab (Kali plus deliberately vulnerable targets) is the single most useful preparation investment. Read the security practices guide →

Where PenTest+ sits

PenTest+ is an intermediate, vendor-neutral penetration-testing credential. It sits above Security+ and complements the defensive CySA+; it is a practical step below expert practical certifications like OSCP, and it is recognised under DoD 8140 for relevant U.S. government and defence work roles. It is most valuable paired with demonstrable hands-on experience rather than as a standalone theory credential. See the cybersecurity specialist career track →

PenTest+ (PT0-002 / PT0-003) exam FAQ

Is PT0-002 still available, or has it retired?
PT0-002 retired on June 17, 2025 and can no longer be scheduled. The current, bookable version of CompTIA PenTest+ is PT0-003, launched December 17, 2024. If you already passed PenTest+ on PT0-002, your certification remains valid for three years from your test date.
What changed between PT0-002 and PT0-003?
PT0-003 adds coverage of AI-based attacks, expanded cloud and API exploitation, and modernised post-exploitation, and reorganises the five domains (Engagement Management, Reconnaissance and Enumeration, Vulnerability Discovery and Analysis, Attacks and Exploits, and Post-exploitation and Lateral Movement). The role, format style, and 750 passing score are unchanged; the question maximum rises from 85 to 90.
What were the PT0-002 domains and weights?
The retired PT0-002 had five domains: Attacks and Exploits (30%, heaviest), Information Gathering and Vulnerability Scanning (22%), Reporting and Communication (18%), Tools and Code Analysis (16%), and Planning and Scoping (14%). They summed to 100%.
What is the PenTest+ passing score and format?
Both versions are scored 750 on a 100–900 scale, over 165 minutes, mixing multiple-choice and performance-based questions. PT0-002 had a maximum of 85 questions; PT0-003 has a maximum of 90.
How does PenTest+ compare to Security+ and CySA+?
Security+ is the foundational security credential; CySA+ is the intermediate defensive (blue-team) analyst certification; PenTest+ is the intermediate offensive (red-team) penetration-testing certification. PenTest+ assumes Security+ level knowledge plus three to four years of hands-on experience, and it is recognised under DoD 8140 for relevant roles.

Start your free 24-hour PenTest+ practice trial

Full access to the question bank, both study modes, source-linked explanations and score-by-domain. No credit card required. (Prepare for the current PT0-003 exam.)

Start free trial →