CompTIA PenTest+ (PT0-003) Practice Test

107 preguntas disponibles

Gana confianza para CompTIA PenTest+ (PT0-003). Practica los conceptos, comprende las respuestas y refuerza tus conocimientos pregunta a pregunta.

Probar una pregunta
Prueba 5 preguntas gratis
No necesitas cuenta. Una cuenta gratuita incluye 20 preguntas de este examen.
Examen de certificación
85 Preguntas del examen
2 horas 45 minutos Límite de Tiempo
Tu práctica
107 Preguntas de práctica
1 hora 47 minutos Tiempo de Práctica
Prueba 5 preguntas gratis
No necesitas cuenta. Una cuenta gratuita incluye 20 preguntas de este examen.
El listón a superar 750/900 Puntuación mínima publicada para obtener esta certificación.
Explora los temas del examen Objetivos oficiales de CompTIA
CompTIA107 preguntas de práctica
Temario verificadoVerificado con CompTIA official objectivesMetadatos verificados 2026-06-07Cómo verificamos

Descripción y detalles del examen

The CompTIA PenTest+ PT0-003 certification validates the intermediate-level skills required to plan, scope, and manage vulnerability assessments and penetration testing engagements. This performance-based certification focuses on the hands-on ability to conduct penetration testing across hybrid environments, including cloud, on-premises, and operational technology (OT) systems. Earning the PenTest+ demonstrates to employers that you possess the offensive security skills needed to identify, exploit, report, and manage vulnerabilities in enterprise systems. It bridges the gap between foundational security knowledge and advanced, specialized penetration testing roles, covering the entire attack lifecycle from reconnaissance and enumeration through post-exploitation and reporting. As a globally recognized, vendor-neutral credential, it is a key benchmark for roles such as Penetration Tester, Vulnerability Assessment Analyst, and Security Consultant, ensuring professionals can adapt methodologies to diverse and evolving threat landscapes.

Preguntas de Muestra

Elige una respuesta y consulta la explicación para ver cómo funciona la práctica.

Attacks and exploits

A penetration tester is working on a PT0-003 assessment for a logistics firm. The current objective involves SQL injection, and the SOC must be notified before any potentially noisy activity. Which action or interpretation is BEST for the tester to use?

Vulnerability discovery and analysis

A penetration tester is working on a PT0-003 assessment for a logistics firm. The current objective involves IDOR analysis, and the SOC must be notified before any potentially noisy activity. Which action or interpretation is BEST for the tester to use?

Vulnerability discovery and analysis

A penetration tester is working on a PT0-003 assessment for a logistics firm. The current objective involves DAST finding, and the SOC must be notified before any potentially noisy activity. Which action or interpretation is BEST for the tester to use?

Attacks and exploits

A penetration tester is working on a PT0-003 assessment for a regional bank. The current objective involves container escape, and the rules of engagement allow validation but prohibit service disruption. Which action or interpretation is BEST for the tester to use?

Engagement management

A penetration tester is working on a PT0-003 assessment for a SaaS provider. The current objective involves testing window breach, and the SOC must be notified before any potentially noisy activity. Which action or interpretation is BEST for the tester to use?

Oportunidades profesionales y salario

Salario medio: $129,180mercado de EE. UU.– Information Security Analysts

Fuente: BLS Occupational Employment and Wage Statistics, May 2025 -- Information Security Analysts (SOC 15-1212), US national. Occupation median, not a certification salary. (2025)

Information Security Analysts

Los rangos son cifras del mercado de EE. UU. salvo que se muestre un rango local.

Qué temas cubre este examen

Usa las ponderaciones publicadas de los dominios para planificar tu estudio. Los resultados de práctica no predicen tu puntuación en el examen de certificación.

01Attacks and exploits

35%

Temas

  • Network attacks
  • Authentication attacks
  • Host-based attacks
  • Web application attacks
  • Cloud-based attacks
  • AI attacks

Objetivos de aprendizaje

  • Network attacks: performing VLAN hopping, on-path attacks, and service exploitation
  • Authentication attacks: executing brute-force attacks, pass-the-hash, and credential stuffing
  • Host-based attacks: conducting privilege escalation, process injection, and credential dumping
  • Web application attacks: performing SQL injection, cross-site scripting (XSS), and directory traversal
  • Cloud-based attacks: exploiting container escapes, metadata service attacks, and identity and access management (IAM) misconfiguration
  • AI attacks: explaining prompt injection and model manipulation against artificial intelligence systems

02Reconnaissance and enumeration

21%

Temas

  • Active and passive reconnaissance
  • Enumeration techniques
  • Reconnaissance tools
  • Script modification

Objetivos de aprendizaje

  • Active and passive reconnaissance: gathering information using open-source intelligence (OSINT), network sniffing, and protocol scanning
  • Enumeration techniques: performing DNS enumeration, service discovery, and directory enumeration
  • Reconnaissance tools: using tools like Nmap, Wireshark, and Shodan for information gathering
  • Script modification: customizing Python, PowerShell, and Bash scripts for reconnaissance and enumeration

03Vulnerability discovery and analysis

17%

Temas

  • Vulnerability scans
  • Result analysis
  • Discovery tools

Objetivos de aprendizaje

  • Vulnerability scans: conducting authenticated, unauthenticated, static application security testing (SAST) and dynamic application security testing (DAST)
  • Result analysis: validating findings, troubleshooting configurations, and identifying false positives
  • Discovery tools: using tools like Nessus, Nikto, and OpenVAS for vulnerability discovery

04Post-exploitation and lateral movement

14%

Temas

  • Post-exploitation activities
  • Documentation

Objetivos de aprendizaje

  • Post-exploitation activities: establishing persistence, performing lateral movement, and cleaning up artifacts
  • Documentation: creating attack narratives and providing remediation recommendations

05Engagement management

13%

Temas

  • Planning and scoping
  • Legal and ethical compliance
  • Collaboration and communication
  • Penetration test reports

Objetivos de aprendizaje

  • Planning and scoping: defining rules of engagement, testing windows, and target selection
  • Legal and ethical compliance: ensuring authorization letters, mandatory reporting, and adherence to regulations
  • Collaboration and communication: aligning with stakeholders through peer reviews, escalation paths, and risk articulation
  • Penetration test reports: creating reports with executive summaries, findings, and remediation recommendations

Detalles del Examen PT0-003 | $404 USD | 2 horas 45 minutos

Código del Examen PT0-003
Proveedor CompTIA
Costo del Examen $404 USD
Puntaje Mínimo 750/900
Límite de Tiempo 2 horas 45 minutos
Preguntas del examen 85
Tipos de PreguntasAún no disponible en este idioma
Política de Repetición No waiting period required before first retake. After the second failed attempt, candidates must wait 14 calendar days before any subsequent attempt. No limit on total attempts.
Formato del Examen Linear
Supervisión en Línea Disponible
Disponible En
EnglishJapanesePortugueseSimplified Chinese

Preguntas Frecuentes

¿Cuáles son los requisitos previos para presentar el examen CompTIA PenTest+ PT0-003?

¿En qué se diferencia PenTest+ de otras certificaciones de pruebas de penetración como el OSCP?

¿Para qué roles laborales está diseñada la certificación PenTest+?

¿Cuál es el formato del examen y cuánto dura?

¿Con qué frecuencia se actualiza el examen PenTest+ y qué hay de nuevo en la versión PT0-003?