Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CompTIA logo

CompTIAPenTest+

Domain 1Objective 1

Planning and Scoping PT0-003 Practice Questions (Page 3)

Part of the Engagement management domain, which accounts for 13% of the PT0-003 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~8–14 in this domain), expect 2–4 from this objective — we provide 18 practice questions to prepare you well beyond it. (estimate)

18questions here
4free pages
3concepts
13%of the exam

Questions 11–15

  1. 11application · medium

    A penetration tester is planning an engagement for a retail company that runs a major online sale every month. The company wants to test its e-commerce platform but cannot afford any downtime during the sale. Which testing window is most appropriate?

    Select an answer first
  2. 12application · medium

    A penetration tester is planning an engagement for a utility company. The company wants to test its SCADA systems but cannot afford any disruption to the power grid. Which testing window is most appropriate?

    Select an answer first
  3. 13expert · hard

    A penetration tester is contracted to test a financial institution's internal network. The rules of engagement state that testing is allowed only between 10 PM and 2 AM on weekdays. During the test, the tester discovers a critical vulnerability in a legacy application that is only accessible during business hours. The client's IT team is available only during business hours. What should the tester do?

    Select an answer first
  4. 14expert · hard

    A penetration tester is engaged to test a financial institution's trading platform. The rules of engagement specify that testing is allowed only between 1 AM and 5 AM on Saturdays. The tester discovers that a critical vulnerability in the trading engine can only be tested during market hours when the system is under load. The client's security team is available only during market hours. What should the tester do?

    Select an answer first
  5. 15application · medium

    A penetration tester is scoping an engagement for a regional bank. The bank's compliance team insists that all customer-facing web applications be tested, but the production database servers must not be touched under any circumstances. The tester needs to validate a SQL injection finding in a web application that connects to a production database. Which action is most appropriate?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “PT0-003” is a trademark of its owner, used for identification only.