CompTIA PenTest+ Practice Questions: Engagement Management

20 free, exam-style CompTIA PenTest+ (PT0-003) practice questions covering Engagement Management, each with the correct answer and an explanation. Start a timed exam below, or scroll on to read through the questions.

🧠

Mini Exam

25 Questions · 50 minutes

Start Quiz 🚀
🏆

Mock PenTest+ Exam

85 Questions · 165 minutes

Start Quiz 🚀
📅

Daily Quiz

10 Questions · 20 minutes

Start Quiz 🚀
🎯

Standard Practice

50 Questions · 100 minutes

Start Quiz 🚀

Engagement Management practice questions

Answers and explanations are shown. Take the timed exam above to test yourself first.

Q1. Before testing a client network, what document should define targets, timing, and permitted techniques?

  • A.Password reuse list
  • B.Rules of engagement✓ Correct
  • C.Marketing plan
  • D.Printer maintenance log
Explanation: Rules of engagement define authorization, scope, methods, timing, contacts, and constraints for a penetration test. Learn more.

Q2. Which finding should generally be reported with the highest priority?

  • A.Remote code execution on an Internet-facing production server✓ Correct
  • B.Expired lab screenshot
  • C.Cosmetic HTML typo
  • D.Informational banner on an internal printer
Explanation: Remote code execution on exposed critical systems usually has high likelihood and impact. Learn more.

Q3. Which evidence best supports a SQL injection finding?

  • A.A vague suspicion with no request details
  • B.A screenshot of the homepage only
  • C.A reproducible request and response showing database-controlled output✓ Correct
  • D.A list of unrelated open ports
Explanation: High-quality findings include reproducible steps, affected parameters, impact, and evidence. Learn more.

Q4. Why should a tester avoid destructive payloads unless explicitly authorized?

  • A.They are required for every test
  • B.They improve scan speed
  • C.They make reports shorter
  • D.They can disrupt client operations and violate scope✓ Correct
Explanation: Penetration testing must follow authorization and avoid unnecessary business disruption. Learn more.

Q5. What should an executive summary emphasize in a penetration test report?

  • A.Tester workstation wallpaper
  • B.Business risk, major findings, and remediation priorities✓ Correct
  • C.Every tool command in chronological order
  • D.Raw packet bytes only
Explanation: Executive summaries translate technical findings into risk and prioritized actions for decision-makers. Learn more.

Q6. Which report section should contain exact commands, requests, and timestamps for reproducibility?

  • A.Invoice
  • B.Technical details✓ Correct
  • C.Glossary only
  • D.Executive summary only
Explanation: Technical details provide reproducible evidence and steps for remediation teams. Learn more.

Q7. Which scan should be coordinated carefully because it may crash fragile services?

  • A.WHOIS lookup
  • B.Aggressive vulnerability scan✓ Correct
  • C.Passive DNS lookup
  • D.Search engine query
Explanation: Aggressive scanning can disrupt legacy or fragile services and should be approved and scheduled. Learn more.

Q8. Which evidence should a tester avoid collecting unless it is required and authorized?

  • A.Bulk production personal data✓ Correct
  • B.A version banner
  • C.A sanitized screenshot
  • D.A proof-of-concept request
Explanation: Collecting unnecessary sensitive data increases legal and operational risk and may violate scope. Learn more.

Q9. Which activity should occur immediately when a tester discovers a critical out-of-scope exposure?

  • A.Ignore it permanently
  • B.Exploit it fully without approval
  • C.Publish it publicly
  • D.Notify the designated contact according to the rules of engagement✓ Correct
Explanation: Out-of-scope critical issues should be handled through the agreed escalation process. Learn more.

Q10. Which remediation is best for command injection caused by shelling out with user input?

  • A.Disable logs
  • B.Hide the command field
  • C.Increase CPU cores
  • D.Use safe APIs and strict input handling instead of concatenated shell commands✓ Correct
Explanation: Fixing command injection usually requires removing unsafe shell concatenation and applying strict input validation or safe APIs. Learn more.

Q11. Which document grants a penetration tester legal permission to attack a client's systems?

  • A.Service level agreement
  • B.Acceptable use policy
  • C.Non-disclosure agreement
  • D.Authorization to test (get-out-of-jail) letter✓ Correct
Explanation: The authorization letter is the tester's written proof that the owner consented to the testing. An NDA governs confidentiality, not permission to attack. Learn more.

Q12. A client asks for testing of a system hosted by a third-party cloud provider. What must be confirmed first?

  • A.That the client has cyber insurance
  • B.That the tester has a static IP address
  • C.That the system uses TLS 1.3
  • D.That the provider permits testing of that service✓ Correct
Explanation: The client cannot authorize testing of infrastructure it does not own. Provider testing policies must be checked, and some services are never in scope. Learn more.

Q13. During testing you discover evidence of an active, ongoing compromise by a third party. What should you do?

  • A.Stop and immediately notify the client's designated contact✓ Correct
  • B.Continue testing and include it in the final report
  • C.Remove the attacker's access yourself
  • D.Ignore it because it is outside your scope
Explanation: Active compromise is a defined stop condition. It is escalated immediately through the agreed communication path rather than held for the report or acted on unilaterally. Learn more.

Q14. What is the PRIMARY purpose of defining a rules of engagement document?

  • A.To calculate the cost of the engagement
  • B.To transfer liability to the client
  • C.To list the CVEs that will be tested
  • D.To set testing windows, permitted techniques, and escalation contacts✓ Correct
Explanation: Rules of engagement define how testing is conducted: timing, allowed and forbidden techniques, target lists, and who to contact when something goes wrong. Learn more.

Q15. Which scoping detail most directly limits the risk of testing affecting production users?

  • A.An agreed testing window during low-traffic hours✓ Correct
  • B.A larger IP range
  • C.A longer engagement duration
  • D.A higher tester day rate
Explanation: Scheduling intrusive testing outside peak hours limits the business impact if a target becomes unstable. Learn more.

Q16. A client provides credentials and network diagrams before testing begins. What type of assessment is this?

  • A.Red team
  • B.Black box
  • C.White box✓ Correct
  • D.Physical
Explanation: White box (or crystal box) testing supplies internal knowledge up front, which trades realism for depth and coverage. Learn more.

Q17. Why is a defined communication escalation path important during an engagement?

  • A.So the tester can bill for extra hours
  • B.So scan results can be published faster
  • C.So the client can watch the tester's screen
  • D.So critical findings and incidents reach the right person quickly✓ Correct
Explanation: Critical findings, accidental outages, and stop conditions all need a known contact and a known response time; otherwise serious issues sit unactioned. Learn more.

Q18. Which item belongs in the report's remediation section rather than the executive summary?

  • A.Business impact framing
  • B.Overall risk posture
  • C.High-level recommendations
  • D.Specific configuration changes and patch versions✓ Correct
Explanation: The executive summary is written for non-technical decision makers. Concrete technical fixes belong with the detailed findings. Learn more.

Q19. A tester finds a critical, actively exploitable vulnerability mid-engagement. What is the appropriate action?

  • A.Exploit it fully before telling anyone
  • B.Report it to the client immediately rather than waiting for the final report✓ Correct
  • C.Post it to a vulnerability disclosure list
  • D.Note it and continue to the end of the engagement
Explanation: Critical findings are communicated as they are discovered so the client can begin remediation, not held for weeks until delivery. Learn more.

Q20. What distinguishes a red team engagement from a standard penetration test?

  • A.It only uses automated scanners
  • B.It never involves social engineering
  • C.It is always shorter in duration
  • D.It tests detection and response, often without the defenders' knowledge✓ Correct
Explanation: Red teaming is objective-driven and measures how well the blue team detects and responds, rather than aiming for broad vulnerability coverage. Learn more.

More CompTIA PenTest+ practice topics

Keep studying CompTIA PenTest+

Full CompTIA PenTest+ practice exam · CompTIA PenTest+ study guide · All CompTIA practice questions

Last updated