PenTest+ PT0-003 performance-based questions (PBQs) test whether you can do a task, not whether you recognise a definition: read scan output and pick the next step, match a tool to a goal, spot what breaks the rules of engagement. The way to prepare is to do those tasks in a lab until reading output feels routine, then practise under time pressure.
Below: what CompTIA says about the exam format, how PBQs typically feel, six original practice scenarios mapped to the PT0-003 domains (with worked answers), and a weekly routine. None of the scenarios reproduce real exam content. They’re written by our team to exercise the same skills.
What are PBQs on the PenTest+ PT0-003 exam?
CompTIA’s PenTest+ page states that PT0-003 has a maximum of 90 questions, “including multiple-choice and performance-based questions”, a 165-minute time limit, and a passing score of 750 on a 100–900 scale. CompTIA doesn’t publish how many PBQs you’ll get, and the number can vary, so don’t rely on anyone who quotes a fixed figure.
In practice, a PBQ is a small interactive task. Formats you should be ready for include:
- Drag and drop: match tools, commands or techniques to goals.
- Ordering: put steps of an engagement or an attack chain in the right sequence.
- Output analysis: read a scan, log or command result and choose a conclusion or next action.
- Configuration or selection: pick the right command options, or select the hosts that are in scope.
PBQs take longer than a multiple-choice question, and CompTIA doesn’t publish how they’re weighted. That shapes your exam strategy, covered further down.
The PT0-003 domains your practice must cover
From CompTIA’s exam page, PT0-003 is weighted as follows:
| Domain | Weight | What PBQ-style tasks look like |
|---|---|---|
| 1. Engagement management | 13% | Reading scope and rules of engagement, choosing frameworks, structuring findings |
| 2. Reconnaissance and enumeration | 21% | Interpreting Nmap and enumeration output, OSINT choices |
| 3. Vulnerability discovery and analysis | 17% | Triaging scanner output, spotting false positives |
| 4. Attacks and exploits | 35% | Choosing an attack for a given weakness, reading payloads |
| 5. Post-exploitation and lateral movement | 14% | Privilege escalation paths, persistence, moving between hosts |
Attacks and exploits is over a third of the exam, but notice that domains 1 and 2 together are another third. Many candidates over-practise exploitation and under-practise scope and recon. The full objectives breakdown is in our PT0-003 study guide.
Six original practice scenarios (with answers)
Work through each one before reading the answer. Time yourself: aim for under eight minutes each.
Scenario 1: scope and rules of engagement (Domain 1)
You’re testing fictional Acme Fintech. The statement of work says:
In scope: 10.20.30.0/24 and
portal.acme-fintech.test. Out of scope: 10.20.30.50 (production database). Testing window: 22:00–05:00 WAT, Monday to Friday. No denial-of-service. Social engineering of staff is not authorised.
Which of these actions are permitted?
A. Running an Nmap service scan against 10.20.30.0/24 at 23:30 on Tuesday, excluding 10.20.30.50
B. Brute-forcing SSH on 10.20.30.50 at 01:00 on Wednesday
C. Phoning the helpdesk to request a password reset for a staff member
D. Testing portal.acme-fintech.test for SQL injection at 14:00 on Thursday
E. Running a slow vulnerability scan of 10.20.30.12 at 03:00 on Sunday
Answer: Only A. B targets an excluded host. C is social engineering. D is outside the time window. E is outside the testing days. In Nmap, the exclusion is one flag:
nmap -sV 10.20.30.0/24 --exclude 10.20.30.50
Lesson: scope questions are easy marks if you read every constraint (hosts, times, days, techniques) and hard if you skim.
Scenario 2: reading Nmap output (Domain 2)
You run this against a lab host:
nmap -sV -sC -p- 10.20.30.21
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.9p1 Ubuntu 3ubuntu0.10
80/tcp open http Apache httpd 2.4.52 ((Ubuntu))
|_http-title: Acme Staff Wiki
139/tcp open netbios-ssn Samba smbd 4.6.2
445/tcp open netbios-ssn Samba smbd 4.6.2
| smb2-security-mode:
| 3:1:1:
|_ Message signing enabled but not required
3306/tcp open mysql MySQL 8.0.36-0ubuntu0.22.04.1
Which is the best next enumeration step, and why?
A. nmap -sU --top-ports 100 10.20.30.21
B. smbclient -L //10.20.30.21 -N
C. hydra -l root -P rockyou.txt ssh://10.20.30.21
D. nmap -sn 10.20.30.0/24
Answer: B. SMB is exposed and anonymous share listing is cheap, quiet and often revealing. A is reasonable later but slower. C is noisy brute-forcing before basic enumeration, and many rules of engagement restrict it. D is host discovery, which you’ve already done. The note that SMB signing is “enabled but not required” is also worth recording for relay attacks later. Our Nmap commands cheat sheet covers each flag used here.
Scenario 3: triaging scanner output (Domain 3)
A vulnerability scan of 10.20.30.21 reports:
| Finding | Scanner evidence |
|---|---|
| Apache HTTP Server path traversal (a CVE affecting 2.4.49 only) | Banner: Apache/2.4.52 (Ubuntu) |
| SMB signing not required | Message signing enabled but not required |
| MySQL reachable from the network | Port 3306 open |
| TLS certificate expired | Port 80, no TLS |
Which findings are likely false positives?
Answer: The first and fourth. The CVE affects a different Apache version than the banner shows (and Ubuntu backports fixes, so version banners need care in both directions). The TLS finding is on a port serving plain HTTP, so there is no certificate to expire. The other two are confirmed by direct evidence. Lesson: PBQs reward checking evidence against the claim, which is exactly what you’ll do on real engagements. CVSS scores, maintained by FIRST, tell you severity, not whether a finding is real.
Scenario 4: matching attack to weakness (Domain 4)
Match each lab observation to the most suitable attack technique.
| Observation | Technique |
|---|---|
| 1. A login form returns different errors for “unknown user” and “wrong password” | a. Kerberoasting |
| 2. An Active Directory service account has an SPN and a weak password policy | b. Username enumeration, then password spraying |
3. A URL parameter ?file=report.pdf loads files from the server |
c. Server-side request forgery |
| 4. A “fetch preview” feature retrieves any URL the user supplies | d. Local file inclusion / path traversal |
Answer: 1–b, 2–a, 3–d, 4–c. For item 3, a lab test would look like this (our lab only):
curl -s “http://10.20.30.21/view.php?file=../../../../etc/passwd” | head -3
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
Only test systems you own or have written permission to test.
Scenario 5: privilege escalation (Domain 5)
You have a shell as www-data on a Linux lab host. You run:
sudo -l
Matching Defaults entries for www-data on wiki01:
env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin
User www-data may run the following commands on wiki01:
(root) NOPASSWD: /usr/bin/find
What does this give you, and what’s the command?
Answer: find can execute commands with -exec, so passwordless sudo on find is a root shell:
sudo /usr/bin/find . -maxdepth 0 -exec /bin/bash -p \;
root@wiki01:/var/www/html# id
uid=0(root) gid=0(root) groups=0(root)
The reporting point matters as much as the trick: the finding is “excessive sudo rights for the web service account”, and the fix is removing that sudoers entry.
Scenario 6: putting the engagement in order (Domains 1 and 5)
Order these steps for a standard engagement:
- Clean up test accounts and tools left on hosts
- Agree scope, rules of engagement and emergency contacts
- Enumerate services and identify vulnerabilities
- Write the report with findings, evidence and remediation
- Exploit and escalate privileges within scope
- Passive and active reconnaissance
Answer: 2, 6, 3, 5, 1, 4. Candidates often put cleanup after the report. Cleanup belongs before you finalise reporting, and the report should state what was cleaned up. NIST’s SP 800-115 describes a comparable planning, discovery, attack and reporting flow if you want an authoritative reference.
How to practise PBQs properly
Scenarios on paper are a warm-up. The skill comes from producing output yourself and reading it.
Build a two-machine lab. A Kali VM plus a deliberately vulnerable target on a host-only network (for example 192.168.56.0/24). Then every scenario above becomes something you can run, not just read.
Do “output-first” drills. Run a command, save the output, come back a day later and write down three conclusions and one next step without rerunning it. That’s the core PBQ skill.
nmap -sV -sC -oN wiki01-$(date +%F).txt 192.168.56.110
Use the objectives as a checklist. Download the PT0-003 objectives from CompTIA and, next to each sub-objective, write the lab exercise where you last practised it. Blank lines show you where you’d struggle in a PBQ.
Practise writing findings. Domain 1 includes reporting. For every lab finding, write a two-line description, the evidence and the fix.
Use only legitimate practice material. Official CompTIA material and reputable practice tests written by authors (not “real exam questions”) are fine. Dumps are not, and using them breaches CompTIA’s candidate agreement; our article on why exam dumps can cost you your certification explains the risk.
Exam-day strategy for PBQs
- Read the whole task first. Some PBQs have tabs or scrollable panes; make sure you’ve seen everything before answering.
- Flag and return if stuck. If a PBQ is eating your time, give it a reasonable answer, flag it and move on. Exam interfaces generally let you mark items for review, but confirm how yours behaves in the tutorial at the start.
- Budget your time. With 165 minutes for up to 90 items, keep an eye on the clock after the first few questions rather than at the end.
- Partial credit may exist, so don’t leave blanks. CompTIA doesn’t publish how PBQs are scored, so the safe assumption is that a reasoned answer beats an empty one.