Prepare for the CompTIA PenTest+ (PenTest+) certification by CompTIA with free exam-style practice questions on CyberCertPrep. The PenTest+ exam has 85 questions, a time limit of PenTest+ hours 45 minutes, and a passing score of 75%.
Choose from Practice mode, Exam Simulation, Weak Areas review, and Daily Challenge. Track your progress with detailed analytics and study with flashcards.
CompTIA PenTest+ (PenTest+) Exam Domain
Focus your study on this domain with targeted practice questions. This domain accounts for 30% of your PenTest+ exam score.
The Attacks & Exploits domain is one of 5 exam domains on the CompTIA PenTest+ (PenTest+) certification exam by CompTIA. At 30% of the total exam, this is one of the most heavily weighted domains — mastering it is critical for passing.
The PenTest+ exam consists of 85 questions with a time limit of 2 hours 45 minutes and a passing score of 75%. That means approximately 26 questions on your exam will come from the Attacks & Exploits domain.
Multi-Factor Authentication (MFA)
A security mechanism that requires two or more independent credentials to verify a user's identity, combining factors fr...
IPS (Intrusion Prevention System)
A network security tool that monitors network traffic flows to detect and actively prevent identified threats in real ti...
AES (Advanced Encryption Standard)
A symmetric block cipher algorithm adopted by the U.S. government as the standard for encrypting electronic data, replac...
Malware
Malicious software designed to damage, disrupt, or gain unauthorized access to computer systems, encompassing a broad ca...
Ransomware
A type of malware that encrypts a victim's files or locks system access and demands a ransom payment (typically in crypt...
Phishing
A social engineering attack that uses fraudulent emails, text messages (smishing), or phone calls (vishing) to trick use...
SQL Injection
A code injection technique that exploits vulnerabilities in a web application's database layer by inserting malicious SQ...
Cross-Site Scripting (XSS)
A web security vulnerability that allows attackers to inject malicious client-side scripts (usually JavaScript) into web...
These certifications also cover topics related to Attacks & Exploits:
Computer & Network Hacker Exploits — 25% of exam
Web Application Attacks — 15% of exam
Password Attacks — 15% of exam
Network Attacks & Crypto — 25% of exam
Client-Side Attacks — 20% of exam
Server-Side Attacks (SSRF, SQLi, RCE) — 25% of exam