CertSafari

    Free Practice Questions for CompTIA PenTest+ Certification

    🔄 Last checked for updates September 5th, 2026

    Study with 353 exam-style practice questions designed to help you prepare for the CompTIA PenTest+.

    Exam experiencesNew

    Pass and fail outcomes from candidates who prepared here — advice, scores, and prep time.

    View exam experiences

    Start Practicing

    All Domains

    Practice with randomly mixed questions from all topics

    Question MixAll Topics
    FormatRandom Order

    Domain Mode

    Practice questions from a specific topic area

    Quiz History

    Exam Details

    Key information about CompTIA PenTest+

    Official study guide

    View

    Question formats CertSafari offers
    • Multiple choice
    • Ordering
    • Matching
    • Fill in the blank

    Exam Topics & Skills Assessed

    Skills measured (from the official study guide)

    Domain 1: Engagement management

    Subdomain 1.1: Planning and scoping

    Defining rules of engagement, testing windows, and target selection.

    Subdomain 1.2: Legal and ethical compliance

    Ensuring authorization letters, mandatory reporting, and adherence to regulations.

    Subdomain 1.3: Collaboration and communication

    Aligning with stakeholders through peer reviews, escalation paths, and risk articulation.

    Subdomain 1.4: Penetration test reports

    Creating reports with executive summaries, findings, and remediation recommendations.

    Domain 2: Reconnaissance and enumeration

    Subdomain 2.1: Active and passive reconnaissance

    Gathering information using open-source intelligence (OSINT), network sniffing, and protocol scanning.

    Subdomain 2.2: Enumeration techniques

    Performing DNS enumeration, service discovery, and directory enumeration.

    Subdomain 2.3: Reconnaissance tools

    Using tools like Nmap, Wireshark, and Shodan for information gathering.

    Subdomain 2.4: Script modification

    Customizing Python, PowerShell, and Bash scripts for reconnaissance and enumeration.

    Domain 3: Vulnerability discovery and analysis

    Subdomain 3.1: Vulnerability scans

    Conducting authenticated, unauthenticated, static application security testing (SAST) and dynamic application security testing (DAST).

    Subdomain 3.2: Result analysis

    Validating findings, troubleshooting configurations, and identifying false positives.

    Subdomain 3.3: Discovery tools

    Using tools like Nessus, Nikto, and OpenVAS for vulnerability discovery.

    Domain 4: Attacks and exploits

    Subdomain 4.1: Network attacks

    Performing VLAN hopping, on-path attacks, and service exploitation.

    Subdomain 4.2: Authentication attacks

    Executing brute-force attacks, pass-the-hash, and credential stuffing.

    Subdomain 4.3: Host-based attacks

    Conducting privilege escalation, process injection, and credential dumping.

    Subdomain 4.4: Web application attacks

    Performing SQL injection, cross-site scripting (XSS), and directory traversal.

    Subdomain 4.5: Cloud-based attacks

    Exploiting container escapes, metadata service attacks, and identity and access management (IAM) misconfiguration.

    Subdomain 4.6: AI attacks

    Explaining prompt injection and model manipulation against artificial intelligence systems.

    Domain 5: Post-exploitation and lateral movement

    Subdomain 5.1: Post-exploitation activities

    Establishing persistence, performing lateral movement, and cleaning up artifacts.

    Subdomain 5.2: Documentation

    Creating attack narratives and providing remediation recommendations.

    Techniques & products

    rules of engagement
    testing windows
    target selection
    authorization letters
    mandatory reporting
    regulations
    peer reviews
    escalation paths
    risk articulation
    executive summaries
    findings
    remediation recommendations
    open-source intelligence (OSINT)
    network sniffing
    protocol scanning
    DNS enumeration
    service discovery
    directory enumeration
    Nmap
    Wireshark
    Shodan
    Python scripts
    PowerShell scripts
    Bash scripts
    authenticated scans
    unauthenticated scans
    static application security testing (SAST)
    dynamic application security testing (DAST)
    validating findings
    troubleshooting configurations
    false positives
    Nessus
    Nikto
    OpenVAS
    VLAN hopping
    on-path attacks
    service exploitation
    brute-force attacks
    pass-the-hash
    credential stuffing
    privilege escalation
    process injection
    credential dumping
    SQL injection
    cross-site scripting (XSS)
    directory traversal
    container escapes
    metadata service attacks
    identity and access management (IAM) misconfiguration
    prompt injection
    model manipulation
    establishing persistence
    lateral movement
    cleaning up artifacts
    attack narratives

    CertSafari is not affiliated with, endorsed by, or officially connected to CompTIA, Inc.. Full disclaimer