CompTIA PenTest+ Practice Test

CompTIA PenTest+ Practice Test

1 / 10

A penetration test must comply with PCI DSS requirements. Which scoping consideration is critical?

2 / 10

You’re reviewing a Bash script used in a pen test. Which command identifies a potential command injection flaw?

3 / 10

A client requests a report tailored for non-technical executives. Which section should you prioritize?

4 / 10

You’re tasked with exploiting a web app via cross-site scripting (XSS). Which payload tests for reflected XSS?

5 / 10

A scan reveals an open port 445 on a Windows host. Which command confirms if SMB is exploitable?

6 / 10

You need to analyze a Python script for potential vulnerabilities. Which tool identifies insecure coding practices?

7 / 10

After a penetration test, you identify a critical vulnerability. Which report section should detail steps to fix it?

8 / 10

A web server is vulnerable to SQL injection. Which payload tests for this without modifying data?

9 / 10

You’re conducting passive reconnaissance on a target. Which tool retrieves historical DNS records without alerting the target?

10 / 10

A client requires a penetration test but prohibits testing during business hours. Which document should you update to reflect this constraint?

Your score is

The average score is 0%

0%