Skip to exam content
← All Exams

CompTIA PT0-003 Practice Test

Penetration Tester

Scoping · Recon · Attacks · Reporting · Tools · 120 scenario questions

120
Questions
180
Minutes
70%
Techclick Practice Target

⚠️ Exam Rules

  • Once started, the timer cannot be paused
  • You can navigate freely — use Previous or the Navigator panel to revisit any question
  • Tab-switching triggers warnings (3 strikes = auto-submit)
  • Right-click and copy disabled during exam
  • If you fail, retry — questions and options reshuffle

PT0-003 practice test: what's covered

Questions in this Techclick bank120
Timer180 min
Techclick practice target70%
Official exam codePT0-003

Free PT0-003 sample questions

  1. A client signs your firm to test their environment but the kickoff email never references written authorization. Before scanning begins, which document most directly protects the tester from prosecution under computer-misuse law?

    • A. A signed authorization-to-test letter naming the in-scope assets, dates, and an authorizing signatory
    • B. The marketing proposal that originally described the engagement deliverables and pricing
    • C. An internal project schedule listing the testers assigned to each phase of work
    • D. A list of the scanning and exploitation tools the team intends to run during the test
    Show answer

    Correct: A. The authorization letter (the 'get-out-of-jail' letter) grants explicit permission and is the legal basis for testing, because without it any access is unauthorized. A proposal, schedule, or tool list does not grant legal authority and so none of those protect the tester.

  2. A scoping call defines an engagement where the tester receives only the company name and a public IP range, with no credentials, network diagrams, or source code. This engagement model is best described as:

    • A. Black-box testing that simulates an external attacker with no prior internal knowledge
    • B. White-box testing where full architecture and source are provided up front
    • C. Gray-box testing where the tester is issued a standard user account
    • D. A compliance audit that only reviews documentation and configuration baselines
    Show answer

    Correct: A. Black-box means no prior knowledge, mirroring an outside attacker, because only public information is supplied. White-box would include source and diagrams, gray-box would include partial access such as a user account, and a documentation-only audit is not active penetration testing.

  3. Mid-engagement you find a critical, exploitable flaw on a host that is clearly outside the agreed CIDR range listed in the rules of engagement. What is the most appropriate next action?

    • A. Pause testing of that host and notify the client to obtain written scope expansion before proceeding
    • B. Exploit the host immediately since the finding is critical and time-sensitive
    • C. Quietly add the host to your report without informing the client during the test
    • D. Delete the host from your notes and continue with the originally scoped targets
    Show answer

    Correct: A. Testers must stay within scope; the correct path is to report the discovery and let the client authorize expansion in writing, because exploiting an out-of-scope system is unauthorized. Exploiting anyway is illegal, and ignoring or hiding the finding violates professional and contractual duties.

  4. A retailer processing card data asks how often PCI DSS obligates them to run penetration tests on the cardholder data environment. The accurate answer aligned to PCI DSS requirement 11.4 is:

    • A. At least annually and after any significant infrastructure or application change
    • B. Only once during the initial environment certification and never again
    • C. Every single day as part of continuous automated vulnerability scanning
    • D. Whenever an auditor happens to request it, with no fixed cadence required
    Show answer

    Correct: A. PCI DSS 11.4 mandates internal and external penetration testing at least annually and after significant changes, because controls can drift as the environment evolves. A one-time test, daily testing, or ad-hoc-only testing all fail to meet the stated cadence.

  5. While drafting rules of engagement for an upcoming assessment, the team wants to capture the items that constrain how and when testing happens. Which elements belong in the rules of engagement? (Choose THREE)

    • A. Permitted testing windows and any blackout periods to avoid business disruption
    • B. Emergency contacts and an escalation path for critical or destructive findings
    • C. The explicit in-scope and out-of-scope IP ranges, domains, and applications
    • D. The tester's personal résumé and professional certification numbers
    • E. The retail pricing of competing penetration-testing vendors in the region
    Show answer

    Correct: A and B and C. Testing windows, escalation contacts, and scope boundaries are core rules-of-engagement content because they govern when, how, and where testing may occur. A tester résumé belongs to qualifications paperwork, not the RoE, and competitor pricing is irrelevant to engagement constraints.

Last updated:

PT0-003 practice test FAQ

Is this PT0-003 practice test free?

Yes. You can start, finish and score it for free, and download the Techclick practice certificate.

How many questions are in the Techclick PT0-003 practice test?

This bank has 120 original scenario-based questions with a 180-minute timer and a 70% Techclick practice target.

What is the official exam code and format?

The official exam code is PT0-003 (CompTIA).

Are these real PT0-003 exam questions or dumps?

No. They are original practice questions written by Techclick. This is not the vendor's official exam and not leaked dumps.

Do I get a certificate?

Score 70% or higher to get a Techclick practice certificate and LinkedIn badge. It is not an official CompTIA certification.

What should I take after PT0-003?

Related practice tests: CompTIA A+ 220-1101 / 220-1102, CompTIA CAS-005, CompTIA CLO-002, CompTIA CV0-004, CySA+ CS0-003, CompTIA A+ DA0-001 (linked below).

Techclick Infosec
TECHCLICK INFOSEC
CYBERSECURITY · PRACTICE ASSESSMENT
🥷
PRACTICE ASSESSMENT
COMPTIA PENTEST+ PT0-003
Penetration Tester
AWARDED TO
{NAME}
SCORE
0%
DATE
--
TC-NGFW-XXX
Verified at exam.techclick.in · Techclick Infosec Pvt Ltd · +91 92772 29456