Free practice + study guide

CompTIA PenTest+ (PT0-003)

  • 22 free practice questions, every one explained · no signup
  • Timed mock exam (22 questions, 165 minutes) — free
  • Study guide: free to read online
Practice free 22 questions · explanations · no signup
01

Test what you know · free, all of it

Four ways to practise.

The same 22 questions, dealt four ways. Pick the one that fits the time you have.

02

Learn what the questions test

Practice · free
22
questions, each explained — finds what you don't know yet
Learn · free
5
chapters, free to read online

The five chapters, free online

every chapter free online
  1. 1Engagement Management13% of the examRead free →
  2. 2Reconnaissance and Enumeration21%Read free →
  3. 3Vulnerability Discovery and Analysis17%Read free →
  4. 4Attacks and Exploits35% — the largest sectionRead free →
  5. 5Post-exploitation and Lateral Movement14%Read free →
03

Before you sit

Know the exam you're walking into.

04

See the questions first

Two from the bank, answered.

Real items, with the answer marked and the reason written out — the same format as all 22.

Attacks and Exploits

An application concatenates untrusted user input directly into a database query, allowing an attacker to alter the query's logic. Which vulnerability class is this?

  1. ADenial of service
  2. BCross-site scripting
  3. CSQL injectionCorrect
  4. DPhysical tailgating

Why: SQL injection occurs when untrusted input is placed into a database query without proper parameterization, letting an attacker change the query's logic. The defense is to use parameterized queries and input validation. Cross-site scripting targets the browser, not the database.

Reconnaissance and Enumeration

A tester gathers information about a target organization from public sources such as social media, job postings, and DNS records without sending any packets to the target's systems. Which activity is this?

  1. APrivilege escalation
  2. BActive scanning
  3. CExploitation
  4. DPassive reconnaissance (OSINT)Correct

Why: Passive reconnaissance, including open-source intelligence (OSINT), collects information from publicly available sources without directly interacting with the target's systems, making it stealthy. Active scanning sends traffic to the target and is therefore detectable, unlike passive collection.

Read all 22 questions with answers →

06

The exam itself

CompTIA PenTest+ (PT0-003), by the numbers.

Time165 minutes
SectionsEngagement Management · Reconnaissance and Enumeration · Vulnerability Discovery and Analysis · Attacks and Exploits · Post-exploitation and Lateral Movement
Passing score750/900
Our bank22 questions · updated August 2026Written from CompTIA
LanguagesEnglish
SourceCompTIA
09

Questions

Asked before starting.

Is the practice really free, or does it stop after a few questions?

All 22 questions, the timed mock and the report are free with no sign-up. A free account only adds saving your progress.

Is your mock the same as the real CompTIA PenTest+ (PT0-003)?

No. Ours is 22 questions in 165 minutes; the real exam is 165 minutes long. Use the mock for stamina and section timing, not as a score predictor.

What score do I need?

750/900 — as published by CompTIA. Confirm the current rule with them before your exam date.

Practice questions are AI-assisted study material written from CompTIA and reviewed by PrepPass — for practice only, not official exam questions. Bank updated August 2026. PrepPass is an independent study resource and is not affiliated with, endorsed by, or approved by CompTIA. Always confirm current exam details with CompTIA.
Report