← All certifications

CompTIA · PT0-003 · 2024 objectives

CompTIA PenTest+

216
questions
9
practice tests
1
free test
750 / 900
to pass the real exam

Try 5 questions

Real questions from the PenTest+ bank, one per domain. No account, no card needed! Just choose an answer and see the why.

1 / 5OBJ 1.1

Before any testing begins, which document legally authorizes the engagement and protects the tester by proving the client consented to the activities?

Practice tests

Timed and scored like the real thing. Answers stay on the server until you submit, then every question is explained in review.

Exam objectives

What PT0-003 covers, and how much of the exam each domain accounts for. Percentages are the share of scored questions in the 2024 objectives.

1.0Engagement Management

13%
  • 1.1Summarize pre-engagement activities (Scope definition, Shared responsibility model, Legal and ethical considerations).
  • 1.2Explain collaboration and communication activities (Peer review, Stakeholder alignment, Root cause analysis, Escalation path, Secure distribution, Articulation of risk, severity, and impact).
  • 1.3Compare and contrast testing frameworks and methodologies (Penetration Testing Execution Standard (PTES), MITRE ATT&CK, Purdue model, Threat modeling frameworks).
  • 1.4Explain the components of a penetration test report (Format alignment, Documentation specifications, Risk scoring, Definitions, Report components, Test limitations and assumptions).
  • 1.5Given a scenario, analyze the findings and recommend the appropriate remediation within a report (Technical controls, Administrative controls, Operational controls, Physical controls).

2.0Reconnaissance and Enumeration

21%
  • 2.1Given a scenario, apply information gathering techniques (Active and passive reconnaissance, Open-source intelligence (OSINT), Network reconnaissance, Protocol scanning, Certificate transparency logs, Information disclosure).
  • 2.2Given a scenario, apply enumeration techniques (Operating system (OS) fingerprinting, Service discovery, Protocol enumeration, DNS enumeration, Directory enumeration, Host discovery).
  • 2.3Given a scenario, modify scripts for reconnaissance and enumeration (Information gathering, Data manipulation, Scripting languages, Logic constructs, Use of libraries, functions, and classes).
  • 2.4Given a scenario, use the appropriate tools for reconnaissance and enumeration (Wayback Machine, Maltego, Recon-ng, Shodan, SpiderFoot, WHOIS).

3.0Vulnerability Discovery and Analysis

17%
  • 3.1Given a scenario, conduct vulnerability discovery using various techniques (Container scans, Application scans, Network scans, Host-based scans, Authenticated vs unauthenticated scans, Secrets scanning).
  • 3.2Given a scenario, analyze output from reconnaissance, scanning, and enumeration phases (False positives, False negatives, True positives, Scan completeness, Troubleshooting scan configurations).
  • 3.3Explain physical security concepts (Tailgating, Site surveys, Universal Serial Bus (USB) drops, Badge cloning, Lock picking).

4.0Attacks and Exploits

35%
  • 4.1Given a scenario, analyze output to prioritize and prepare attacks (High-value asset identification, Descriptors and metrics, End-of-life software/systems, Default configurations, Running services, Vulnerable encryption methods).
  • 4.2Given a scenario, perform network attacks using the appropriate tools (Default credentials, On-path attack, Certificate services, Misconfigured services exploitation, Virtual local area network (VLAN) hopping, Multihomed hosts).
  • 4.3Given a scenario, perform authentication attacks using the appropriate tools (Multifactor authentication (MFA) fatigue, Pass-the-hash attacks, Pass-the-ticket attacks, Pass-the-token attacks, Kerberos attacks, Dictionary attacks).
  • 4.4Given a scenario, perform host-based attacks using the appropriate tools (Privilege escalation, Credential dumping, Circumventing security tools, Misconfigured endpoints, Payload obfuscation, User-controlled access bypass).
  • 4.5Given a scenario, perform web application attacks using the appropriate tools (Brute-force attack, Collision attack, Directory traversal, Server-side request forgery (SSRF), Cross-site request forgery (CSRF), Deserialization attack).
  • 4.6Given a scenario, perform cloud-based attacks using the appropriate tools (Metadata service attacks, Third-party integrations, Resource misconfiguration, Logging information exposure, Image and artifact tampering, Supply chain attacks).
  • 4.7Given a scenario, perform wireless attacks using the appropriate tools (Wardriving, Evil twin attack, Signal jamming, Protocol fuzzing, Packet crafting, Deauthentication).
  • 4.8Given a scenario, perform social engineering attacks using the appropriate tools (Phishing, Vishing, Whaling, Spearphishing, Smishing, Dumpster diving).
  • 4.9Explain common attacks against specialized systems (Mobile attacks, AI attacks, OT, Near-field communication (NFC), Bluejacking, Radio-frequency identification (RFID)).
  • 4.10Given a scenario, use scripting to automate attacks (PowerShell, Bash, Python, Breach and attack simulation (BAS)).

5.0Post-exploitation and Lateral Movement

14%
  • 5.1Given a scenario, perform tasks to establish and maintain persistence (Scheduled tasks/cron jobs, Service creation, Reverse shell, Bind shell, Add new accounts, Obtain valid account credentials).
  • 5.2Given a scenario, perform tasks to move laterally throughout the environment (Pivoting, Relay creation, Enumeration, Service discovery, Window Management Instrumentation (WMI), Window Remote Management (WinRM)).
  • 5.3Summarize concepts related to staging and exfiltration (File encryption and compression, Covert channel, Email, Cross-account resources, Cloud storage, Alternate data streams).
  • 5.4Explain cleanup and restoration activities (Remove persistence mechanisms, Revert configuration changes, Remove tester-created credentials, Remove tools, Spin down infrastructure, Preserve artifacts).

Summarized from CompTIA PenTest+’s published exam objectives. Always check the vendor’s current objectives before your exam.