Popular
COMPTIA · PT0-003

CompTIA PenTest+ PT0-003 Exam Practice Questions

344 questionsInstant PDF downloadUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 344 questions in this pack

Question 1

A penetration tester wants to send a specific network packet with custom flags and sequence numbers to a vulnerable target.

Which of the following should the tester use?

  1. tcprelay
  2. Bluecrack
  3. Scapy
  4. tcpdump
Show answer and explanation

Correct answer: C. Scapy

Scapy is a powerful Python library that allows penetration testers to craft, send, and manipulate network packets with custom flags, sequence numbers, and other fields. It provides programmatic control over packet construction at the protocol level, making it ideal for sending specially crafted packets to vulnerable targets.

Why the other options are wrong

  • A. tcprelay is a tool for relaying TCP connections, not for crafting custom packets.
  • B. Bluecrack is a Bluetooth cracking tool, not relevant for crafting IP-level network packets.
  • D. tcpdump is a packet capture and analysis tool, not for creating and sending custom packets.

Question 2

Which of the following explains the reason a tester would opt to use DREAD over PTES during the planning phase of a penetration test?

  1. The tester is conducting a web application test.
  2. The tester is assessing a mobile application.
  3. The tester is evaluating a thick client application.
  4. The tester is creating a threat model.
Show answer and explanation

Correct answer: D. The tester is creating a threat model.

DREAD is a threat modeling methodology used to identify and prioritize threats based on Damage, Reproducibility, Exploitability, Affected users, and Discoverability. PTES is a comprehensive penetration testing execution standard. DREAD is specifically chosen during the planning phase when the goal is to create a threat model and understand potential risks before conducting the actual test.

Why the other options are wrong

  • A. Web application testing does not specifically require DREAD over PTES.
  • B. Mobile application assessment would use similar methodologies but doesn't distinguish DREAD as the primary reason.
  • C. Thick client application testing doesn't specifically mandate DREAD over PTES.

Question 3

A penetration tester is performing a security review of a web application.

Which of the following should the tester leverage to identify the presence of vulnerable open-source libraries?

  1. VM
  2. IAST
  3. DAST
  4. SCA
Show answer and explanation

Correct answer: D. SCA

Software Composition Analysis (SCA) is specifically designed to identify vulnerable open- source libraries and dependencies within applications. It scans source code and binaries to locate third-party components and checks them against known vulnerability databases to detect security issues in dependencies.

Why the other options are wrong

  • A. VM (Virtual Machine) is an execution environment, not a tool for identifying vulnerable libraries.
  • B. IAST (Interactive Application Security Testing) analyzes running applications but is not specialized for open-source library detection.
  • C. DAST (Dynamic Application Security Testing) tests running applications but is not optimized for dependency vulnerability identification.

See all 10 free questions Get the full pack, US$39

344 practice questions for CompTIA PenTest+ (PT0-003), MCQs and PBQs, with full explanations.

Every multiple choice and performance-based question comes with the correct answer, a clear explanation, and a note on why each other option is wrong. Mapped to the current PT0-003 objectives.

  • 344 questions, MCQs and PBQs, mapped to the PT0-003 objectives
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A PenTest+ voucher is US$439. This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 344 questions

What makes the PenTest+ hard

Fail it and CompTIA charges the full US$439 again. The PBQs are the main reason people do: you read tool output, interpret code and make testing decisions against the clock, across 165 minutes. Knowing Nmap and Metasploit well does not guarantee you will read CompTIA’s scenarios the way the exam expects.

PT0-003 is also recent. It launched on 17 December 2024 and replaced PT0-002, which retired on 17 June 2025. The new version added AI-based attacks, more cloud and API exploitation, and newer post-exploitation techniques, so study material written before the launch can miss what is on the exam today.

Weighting is lopsided: attacks and exploits alone is 35%, and reconnaissance and enumeration adds another 21%. More than half the exam sits in those two domains, and this pack covers both in depth.

About the exam

PenTest+ is CompTIA’s intermediate penetration testing certification. It validates planning, scoping and running engagements across networks, cloud, web applications, IoT and hybrid environments, through the full lifecycle from planning and reconnaissance to exploitation, post-exploitation and reporting. The current version is V3, exam code PT0-003, launched 17 December 2024. It is DoD 8140 approved. CompTIA recommends 3 to 4 years in a penetration testing role, plus Network+ and Security+ or equivalent knowledge.

Exam domains

  • Engagement management: 13%
  • Reconnaissance and enumeration: 21%
  • Vulnerability discovery and analysis: 17%
  • Attacks and exploits: 35%
  • Post-exploitation and lateral movement: 14%

Up to 90 questions including PBQs, 165 minutes, pass mark 750 out of 900, US$439 per voucher, offered in English, French, Japanese and Portuguese, at a Pearson VUE centre or online, valid for three years.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the CompTIA PenTest+ PT0-003 pack?

344 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Straight away. The full PDF and a questions-only copy are emailed to you the moment your payment goes through, and the same links are on your order page.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.