A purchase at PassSureExam is the start of a service relationship rather than the end of a transaction: after your PT0-002 order arrives, the team stays reachable around the clock for any CompTIA PenTest+ Certification question that comes up.
CompTIA PT0-002 Exam Overview:
| Certification Vendor: | CompTIA |
|---|---|
| Exam Name: | CompTIA PenTest+ Certification Exam (PT0-002) |
| Exam Number: | PT0-002 |
| Related Certifications: | CompTIA CySA+ CompTIA Security+ CompTIA Network+ |
| Passing Score: | 750 (on a scale of 100–900) |
| Available Languages: | English |
| Real Exam Qty: | Up to 85 |
| Exam Duration: | 165 minutes |
| Exam Format: | Performance-based questions (PBQs), Multiple-choice questions |
| Certificate Validity Period: | Retired (PT0-002 was replaced by newer PenTest+ exam version) |
| Exam Price: | USD $392 |
| Recommended Training: | CompTIA CertMaster Learn + Labs (PenTest+) CompTIA Official PenTest+ Study Resources |
| Exam Registration: | CompTIA Official Registration Pearson VUE CompTIA Exams |
| Sample Questions: | ![]() |
| Exam Way: | Available via Pearson VUE testing centers or online proctored exam |
| Pre Condition: | No mandatory prerequisites; recommended: 3–4 years of hands-on information security or penetration testing experience and familiarity with CompTIA Security+ level knowledge |
| Official Syllabus URL: | https://www.comptia.org/certifications/pentest |
CompTIA PT0-002 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Tools and Code Analysis | 18% | - Penetration testing tools usage - Basic scripting and code analysis |
| Information Gathering and Vulnerability Scanning | 22% | - Vulnerability scanning techniques and tools - Passive and active reconnaissance |
| Attacks and Exploits | 30% | - Exploitation techniques and post-exploitation - Wireless and social engineering attacks - Network and application attacks |
| Reporting and Communication | 16% | - Risk analysis and remediation reporting - Communication with stakeholders |
| Planning and Scoping | 14% | - Define scope and rules of engagement - Compliance and legal requirements |
PT0-002 Exam Facts and the Service Behind Them
- Planning and Scoping (14%)
- Tools and Code Analysis (18%)
- Attacks and Exploits (30%)
CompTIA PenTest+ Certification Sample Questions:
A penetration tester was able to compromise a server and escalate privileges. Which of the following should the tester perform AFTER concluding the activities on the specified target? (Choose two.)
- A. Reboot the target server.
- B. Disable the running services.
- C. Delete any created credentials.
- D. Remove the logs from the server.
- E. Restore the server backup.
- F. Remove any tools or scripts that were installed.
Correct Answer: C,F 🗳️
A security company has been contracted to perform a scoped insider-threat assessment to try to gain access to the human resources server that houses PII and salary data. The penetration testers have been given an internal network starting position.
Which of the following actions, if performed, would be ethical within the scope of the assessment?
- A. Leveraging a vulnerability on the internal CA to issue fraudulent client certificates
- B. Intercepting outbound TLS traffic
- C. Gaining access to hosts by injecting malware into the enterprise-wide update server
- D. Establishing and maintaining persistence on the domain controller
- E. Exploiting a configuration weakness in the SQL database
Correct Answer: B 🗳️
A penetration tester was contracted to test a proprietary application for buffer overflow vulnerabilities. Which of the following tools would be BEST suited for this task?
- A. Netcat
- B. SearchSpliot
- C. Burp Suite
- D. GDB
Correct Answer: D 🗳️
Explanation: Only visible for PassSureExam members. You can sign-up / login (it's free).
A Chief Information Security Officer wants a penetration tester to evaluate whether a recently installed firewall is protecting a subnetwork on which many decades- old legacy systems are connected. The penetration tester decides to run an OS discovery and a full port scan to identify all the systems and any potential vulnerability. Which of the following should the penetration tester consider BEFORE running a scan?
- A. The timing of the scan
- B. The bandwidth limitations
- C. The type of scan
- D. The inventory of assets and versions
Correct Answer: D 🗳️
During a vulnerability management process that lasted several months, a security analyst found the number of vulnerabilities in a production web application consistently grew. Which of the following should the analyst do to best remediate this situation?
- A. Implement a peer review process during the coding phase.
- B. Perform penetration testing regularly.
- C. Implement security scanning during the pipeline for the CI/CD flow.
- D. Perform a security evaluation based on the OWASP Top 10.
Correct Answer: C 🗳️



