Free PT0-002: CompTIA PenTest Certification Exam Questions and Answers
CompTIA PenTest Certification Exam is exam PT0-002, part of the CompTIA certification programme. CompTIA exam codes carry a family prefix and a version number — SY0- for Security+, N10- for Network+, CS0- for CySA+, 220- for A+ — and most Plus-series exams allow 90 minutes for up to 90 questions, mixing multiple choice with performance-based items in a simulated environment.
Candidates comparing PT0-002 exam dumps, ExamTopics and other PT0-002 practice tests use this page for the answers and explanations behind each question. Download the free PT0-002 PDF, then sit the timed PT0-002 exam simulation before booking with CompTIA.
Last updated: October 3, 2026
- Exam code
- PT0-002
- Provider
- CompTIA
- Questions in our bank
- 1000+
- Free to read
- First 10, with answers
- Official page
- Official Exam website
- Our test mode duration & pass mark
- 130 mins · 70%
Recommended: Switch to Test Mode to start a practice test that simulates the real exam experience.
Question #1
A penetration tester will be performing a vulnerability scan as part of the penetration test on a client's website. The tester plans to run several Nmap scripts that probe for vulnerabilities while avoiding detection. Which of the following Nmap options will the penetration tester MOST likely utilize?
Correct answer: B
Explanation
The --script "http*vuln*" option runs Nmap NSE scripts that probe for web vulnerabilities. Detection is minimized with slow timing, but only this option actually invokes the vulnerability scripts the tester needs.
Continue with PT0-002: CompTIA PenTest Certification Exam
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in PT0-002: CompTIA PenTest Certification Exam, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #2
Which of the following is the most secure method for sending the penetration test report to the client?
Correct answer: D
Explanation
This is the most secure method for sending the penetration test report to the client because it ensures that only the client can decrypt and read the report using their private key. Encrypting the report with the client’s public key prevents anyone else from accessing the report, even if they intercept or compromise the email. The other methods are not as secure because they rely on weaker or no encryption, or they expose the report to third-party services that may not be trustworthy or compliant.
Continue with PT0-002: CompTIA PenTest Certification Exam
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in PT0-002: CompTIA PenTest Certification Exam, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #3
A penetration tester is trying to restrict searches on Google to a specific domain. Which of the following commands should the penetration tester consider?
Correct answer: C
Explanation
The site: command can be used to restrict searches on Google to a specific domain. For example, site:company.com will return only results from the company.com domain. This can help the penetration tester to find information or pages related to the target domain.
Continue with PT0-002: CompTIA PenTest Certification Exam
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in PT0-002: CompTIA PenTest Certification Exam, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #4
A penetration tester is reviewing the following DNS reconnaissance results for comptia.org from dig: comptia.org. 3569 IN MX comptia.org- mail.protection.outlook.com. comptia.org. 3569 IN A 3.219.13.186. comptia.org. 3569 IN NS ns1.comptia.org. comptia.org. 3569 IN SOA haven. administrator.comptia.org. comptia.org. 3569 IN MX new.mx0.comptia.org. comptia.org. 3569 IN MX new.mx1.comptia.org. Which of the following potential issues can the penetration tester identify based on this output?
Correct answer: A
Explanation
The A record and the third-party mail protection entries point outside comptia.org's owned netblocks, so at least one record lies outside the agreed scope.
Continue with PT0-002: CompTIA PenTest Certification Exam
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in PT0-002: CompTIA PenTest Certification Exam, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #5
A penetration tester was contracted to test a proprietary application for buffer overflow vulnerabilities. Which of the following tools would be BEST suited for this task?
Correct answer: A
Explanation
GDB is a debugging tool that can be used to analyze and manipulate the memory of a running process, which is useful for finding and exploiting buffer overflow vulnerabilities. Burp Suite is a web application testing tool that does not directly test for buffer overflows. SearchSpliot is a database of known exploits that does not test for new vulnerabilities. Netcat is a network utility that can be used to send and receive data, but not to test for buffer overflows.
Continue with PT0-002: CompTIA PenTest Certification Exam
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in PT0-002: CompTIA PenTest Certification Exam, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #6
A penetration tester is evaluating a company's network perimeter. The tester has received limited information about defensive controls or countermeasures, and limited internal knowledge of the testing exists. Which of the following should be the FIRST step to plan the reconnaissance activities?
Correct answer: C
Explanation
Passive DNS lookups with dig reveal the externally reachable hosts first, giving the tester targets to work from without touching client systems or alerting defensive controls.
Continue with PT0-002: CompTIA PenTest Certification Exam
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in PT0-002: CompTIA PenTest Certification Exam, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #7
During the reconnaissance phase, a penetration tester obtains the following output: Reply from 192.168.1.23: bytes=32 time<54ms TTL=128 Reply from 192.168.1.23: bytes=32 time<53ms TTL=128 Reply from 192.168.1.23: bytes=32 time<60ms TTL=128 Reply from 192.168.1.23: bytes=32 time<51ms TTL=128 Which of the following operating systems is MOST likely installed on the host?
Correct answer: C
Explanation
The output shows the result of a ping command, which sends packets to a host and receives replies. The ping command can be used to determine if a host is alive and reachable on the network. One of the information that the ping command displays is the Time to Live (TTL) value, which indicates how many hops a packet can travel before it is discarded. The TTL value can also be used to guess the operating system of the host, as different operating systems have different default TTL values. In this case, the TTL value is 128, which is the default value for Windows operating systems. Linux and macOS have a default TTL value of 64, while NetBSD has a default TTL value of 255.
Continue with PT0-002: CompTIA PenTest Certification Exam
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in PT0-002: CompTIA PenTest Certification Exam, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #8
A penetration tester opened a reverse shell on a Linux web server and successfully escalated privileges to root. During the engagement, the tester noticed that another user logged in frequently as root to perform work tasks. To avoid disrupting this user’s work, which of the following is the BEST option for the penetration tester to maintain root-level persistence on this server during the test?
Correct answer: C
Explanation
The best option for the penetration tester to maintain root-level persistence on this server during the test is to add a new user with ID 0 to the /etc/passwd file. This will allow the penetration tester to use the same user account as the other user, but with root privileges, meaning that it won’t disrupt the other user’s work. This can be done by adding a new line with the username and the numerical user ID 0 to the /etc/passwd file. For example, if the username for the other user is “johndoe”, the line to add would be “johndoe:x:0:0:John Doe:/root:/bin/bash”. After the user is added, the penetration tester can use the “su” command to switch to the new user and gain root privileges.
Continue with PT0-002: CompTIA PenTest Certification Exam
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in PT0-002: CompTIA PenTest Certification Exam, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #9
Which of the following documents is agreed upon by all parties associated with the penetration-testing engagement and defines the scope, contacts, costs, duration, and deliverables?
Correct answer: A
Explanation
The document that is agreed upon by all parties associated with the penetration-testing engagement and defines the scope, contacts, costs, duration, and deliverables is the SOW (Statement of Work). The SOW is a formal document that describes the objectives, expectations, and responsibilities of the penetration- testing project2. The SOW should be clear, concise, and comprehensive to avoid any ambiguity or misunderstanding.
Continue with PT0-002: CompTIA PenTest Certification Exam
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in PT0-002: CompTIA PenTest Certification Exam, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Question #10
Which of the following expressions in Python increase a variable val by one (Choose two.)
Select 2 answers.
Correct answer: C, F
Explanation
In Python, there are two ways to increase a variable by one: using the assignment operator (=) with an arithmetic expression, or using the augmented assignment operator (+=). The expressions val=(val+1) and val+=1 both achieve this goal. The expressions val++ and ++val are not valid in Python, as there is no increment operator. The expressions +val and val=val++ do not change the value of val2. https://pythonguides.com/increment-and-decrement-operators-in-python/
Continue with PT0-002: CompTIA PenTest Certification Exam
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in PT0-002: CompTIA PenTest Certification Exam, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
Discussion
Explain your reasoning, not just the letterOther CompTIA certifications
- SK0-004: CompTIA Server (opens in a new tab)
- SY0-701: CompTIA Security 2023 (opens in a new tab)
- N10-008: CompTIA Network (opens in a new tab)
- CS0-002: CompTIA CySA Certification Exam (CS0-002) (opens in a new tab)
- SY0-601: CompTIA Security 2021 (opens in a new tab)
- N10-009: CompTIA Network+ Exam (opens in a new tab)
- N10-007: CompTIA Network 2018 (opens in a new tab)
- CS0-003: CompTIA CySA (CS0-003) (opens in a new tab)
- 220-1102: CompTIA A Certification Exam: Core 2 (opens in a new tab)
- SK0-005: CompTIA Server Certification Exam (opens in a new tab)
- 220-1101: CompTIA A Certification Exam: Core 1 (opens in a new tab)
- XK0-005: CompTIA Linux (opens in a new tab)
Reviews
Write a review★★★★★
Exam Practice is worth every penny. The mock exams are realistic, and the feedback helped me focus on key areas.
Amit SharmaVerified buyer
★★★★★
I highly recommend Exam Practice. The feedback after each test helped me improve significantly, and I passed my exams easily.
Oscar NyströmVerified buyer
★★★★★
This platform is a lifesaver. The practice questions and explanations are so detailed. It’s the best study tool I’ve ever used.
Hannah SmithVerified buyer
FAQ
Learn More: https://www.comptia.org/certifications
- Q1: Is the CompTIA PenTest+ PT0-002 exam retired?
- A: Yes. CompTIA retired PT0-002 on June 17, 2025. Its replacement, PenTest+ V3 (exam code PT0-003), launched on December 17, 2024 and is the only version available as of October 2026.
- Q2: How many questions were on the PT0-002 exam and how long did it take?
- A: The real PT0-002 exam had a maximum of 85 questions and a 165-minute time limit. The current PT0-003 exam has a maximum of 90 questions in the same 165 minutes.
- Q3: What types of questions were on PT0-002?
- A: The exam combined multiple-choice questions with performance-based questions that required you to carry out tasks in a simulated environment. PT0-003 uses the same two formats.
- Q4: What was the passing score for PT0-002?
- A: The passing score was 750 on a scale of 100 to 900. PT0-003 keeps the same passing score.
- Q5: What experience did CompTIA recommend for PT0-002?
- A: CompTIA's exam objectives recommended three to four years of hands-on experience performing penetration tests, vulnerability assessments and code analysis. For PT0-003 the guidance is three to four years in a penetration tester role plus Network+ and Security+ or equivalent knowledge.
- Q6: What domains did the PT0-002 exam cover?
- A: PT0-002 had five domains: Planning and Scoping (14%), Information Gathering and Vulnerability Scanning (22%), Attacks and Exploits (30%), Reporting and Communication (18%) and Tools and Code Analysis (16%). PT0-003 reorganised these into Engagement Management (13%), Reconnaissance and Enumeration (21%), Vulnerability Discovery and Analysis (17%), Attacks and Exploits (35%) and Post-exploitation and Lateral Movement (14%).
- Q7: What languages is the current PenTest+ exam offered in?
- A: As of October 2026 PT0-003 is available in English, French, Japanese and Portuguese. CompTIA estimates PT0-003 will itself retire around 2027, roughly three years after launch.
- Q8: How long is a PenTest+ certification valid?
- A: PenTest+ is valid for three years from the date earned and is renewed through CompTIA's Continuing Education program. As of October 2026 the CE fee for PenTest+ is USD 150 for the three-year cycle.
- Q9: What is the PT0-002: CompTIA PenTest Certification Exam exam?
- A: PT0-002: CompTIA PenTest Certification Exam is a CompTIA certification exam. Judging by the questions in our bank, it concentrates on tester, penetration, comptia.org, ifscope and penetration-testing.
- Q10: What topics does the PT0-002: CompTIA PenTest Certification Exam exam cover?
- A: Questions in our PT0-002: CompTIA PenTest Certification Exam bank cluster around tester, penetration, comptia.org, ifscope, penetration-testing, ethernet, commands and reconnaissance. Working through the full set is the quickest way to find which of these you are weakest on.
- Q11: How should I prepare for PT0-002: CompTIA PenTest Certification Exam?
- A: Work through the PT0-002: CompTIA PenTest Certification Exam practice questions here, checking your answer on each one, then sit the practice test to rehearse the exam under timed conditions before the real thing.
- Q12: Are these real PT0-002: CompTIA PenTest Certification Exam exam questions?
- A: They are drawn from officially released past questions and from community members who have sat PT0-002: CompTIA PenTest Certification Exam. Answers are verified and updated weekly.
- Q13: Where do I register for the PT0-002: CompTIA PenTest Certification Exam exam?
- A: Register through CompTIA directly at https://www.comptia.org/certifications. Exampractice is not affiliated with CompTIA and does not administer the exam.
- Q14: Is there a free PT0-002: CompTIA PenTest Certification Exam sample?
- A: Yes. Every PT0-002: CompTIA PenTest Certification Exam page shows a free sample of real questions. Upgrading opens the full bank and the practice test.
- Q15: What are CompTIA Certification Exams?
- A: CompTIA Certification Exams validate your expertise in various IT disciplines, including networking, security, cloud computing, and IT support. These certifications demonstrate your proficiency in applying best practices and industry standards to manage and troubleshoot IT environments.
- Q16: Why should I pursue CompTIA Certification?
- A: CompTIA Certification enhances your professional credibility, showcasing your skills and knowledge in essential IT areas. This can lead to better job opportunities, higher salaries, and career advancement in IT support, networking, cybersecurity, and cloud computing fields.
- Q17: What are the benefits of CompTIA Certification?
- A: Benefits include recognition as a certified IT professional, improved job performance, access to exclusive resources, continuing education opportunities, and staying current with the latest IT industry trends and best practices.
- Q18: Who should take CompTIA Certification Exams?
- A: IT professionals, network administrators, cybersecurity experts, cloud engineers, and anyone involved in managing and supporting IT infrastructure should consider these certifications to validate their expertise and advance their careers.
- Q19: What types of CompTIA Certification Exams are available?
- A: CompTIA offers various certification paths, including:
- Q20: How do I prepare for CompTIA Certification Exams?
- A: Preparation can include official CompTIA training courses, study guides, practice exams, online tutorials, and hands-on experience in relevant IT disciplines.
- Q21: Where can I take CompTIA Certification Exams?
- A: CompTIA Certification Exams can be taken at authorized Pearson VUE testing centers worldwide or online, providing flexibility to fit your schedule and location.
- Q22: How do CompTIA Certifications impact my career?
- A: CompTIA Certifications significantly boost your career by demonstrating your expertise to employers, making you a more competitive candidate for advanced roles and promotions in IT support, networking, cybersecurity, and cloud computing.
- Q23: Are there any prerequisites for CompTIA Certification Exams?
- A: Some exams may have prerequisites, such as foundational knowledge or prior certifications. Check the specific requirements for each certification path on the CompTIA website.
- Q24: How often do I need to recertify for CompTIA Certifications?
- A: CompTIA Certifications typically require recertification every three years to ensure that certified professionals stay updated with the latest IT technologies and industry practices.



