Free Practice Questions for CompTIA PenTest+ Certification
Study with 353 exam-style practice questions designed to help you prepare for the CompTIA PenTest+.
Exam experiencesNew
Pass and fail outcomes from candidates who prepared here — advice, scores, and prep time.
Start Practicing
All Domains
Practice with randomly mixed questions from all topics
Domain Mode
Practice questions from a specific topic area
Quiz History
Exam Details
Key information about CompTIA PenTest+
- Multiple choice
- Ordering
- Matching
- Fill in the blank
Exam Topics & Skills Assessed
Skills measured (from the official study guide)
Domain 1: Engagement management
Subdomain 1.1: Planning and scoping
Defining rules of engagement, testing windows, and target selection.
Subdomain 1.2: Legal and ethical compliance
Ensuring authorization letters, mandatory reporting, and adherence to regulations.
Subdomain 1.3: Collaboration and communication
Aligning with stakeholders through peer reviews, escalation paths, and risk articulation.
Subdomain 1.4: Penetration test reports
Creating reports with executive summaries, findings, and remediation recommendations.
Domain 2: Reconnaissance and enumeration
Subdomain 2.1: Active and passive reconnaissance
Gathering information using open-source intelligence (OSINT), network sniffing, and protocol scanning.
Subdomain 2.2: Enumeration techniques
Performing DNS enumeration, service discovery, and directory enumeration.
Subdomain 2.3: Reconnaissance tools
Using tools like Nmap, Wireshark, and Shodan for information gathering.
Subdomain 2.4: Script modification
Customizing Python, PowerShell, and Bash scripts for reconnaissance and enumeration.
Domain 3: Vulnerability discovery and analysis
Subdomain 3.1: Vulnerability scans
Conducting authenticated, unauthenticated, static application security testing (SAST) and dynamic application security testing (DAST).
Subdomain 3.2: Result analysis
Validating findings, troubleshooting configurations, and identifying false positives.
Subdomain 3.3: Discovery tools
Using tools like Nessus, Nikto, and OpenVAS for vulnerability discovery.
Domain 4: Attacks and exploits
Subdomain 4.1: Network attacks
Performing VLAN hopping, on-path attacks, and service exploitation.
Subdomain 4.2: Authentication attacks
Executing brute-force attacks, pass-the-hash, and credential stuffing.
Subdomain 4.3: Host-based attacks
Conducting privilege escalation, process injection, and credential dumping.
Subdomain 4.4: Web application attacks
Performing SQL injection, cross-site scripting (XSS), and directory traversal.
Subdomain 4.5: Cloud-based attacks
Exploiting container escapes, metadata service attacks, and identity and access management (IAM) misconfiguration.
Subdomain 4.6: AI attacks
Explaining prompt injection and model manipulation against artificial intelligence systems.
Domain 5: Post-exploitation and lateral movement
Subdomain 5.1: Post-exploitation activities
Establishing persistence, performing lateral movement, and cleaning up artifacts.
Subdomain 5.2: Documentation
Creating attack narratives and providing remediation recommendations.
Techniques & products