ExamDumpster

Free CPENT sample questions

Real questions from the Certified Penetration Testing Professional practice bank, with the correct answer and an explanation for each one. No junk, no filler.

Try them in the simulator Same questions, with study, timed and flashcard modes.

Showing 10 of 20 free sample questions.

Question 1Choose one

A penetration tester is engaged to perform a black-box assessment of a corporate network. The tester decides to follow the Penetration Testing Execution Standard (PTES) to ensure a structured approach. During the Intelligence Gathering phase, the tester is attempting to map the organization's business relationships and employee hierarchy without touching the target's infrastructure. Which phase of the PTES does this activity strictly fall under, and which tool is MOST appropriate for visualizing these relationships?

Question 2Choose one

During a strategic planning meeting for a new penetration test, the client requests that the assessment team specifically focus on simulating the tactics, techniques, and procedures (TTPs) of a specific Advanced Persistent Threat (APT) group known to target their industry. Which framework should the lead penetration tester reference to accurately design this emulation plan?

Question 3Choose one

A penetration tester has discovered a critical vulnerability in a production database server that allows for remote code execution. The Rules of Engagement (RoE) explicitly state that no exploitation causing potential denial of service or data corruption is permitted on production systems. The tester believes they can exploit this to gain domain admin access. What is the correct course of action?

Question 4Choose one

You are preparing the scoping document for a penetration test of a financial institution. The client requires that the test be conducted from the perspective of a malicious insider with standard user access. This type of test is BEST described as:

Question 5Choose one

While conducting OSINT on a target organization, you wish to identify all subdomains associated with 'example.com' that might be hosting development or staging environments. You decide to use a tool that queries multiple search engines (Google, Bing, etc.) and Shodan without actively scanning the target's network. Which tool is MOST suitable for this passive reconnaissance task?

Question 6Choose one

A penetration tester wants to use Google Dorks to find publicly exposed PDF documents on a target website 'target-site.com' that might contain 'confidential' in the text. Which syntax is correct?

Question 7Choose one

You are performing a DNS analysis and suspect that the target's nameserver is misconfigured to allow Zone Transfers. You are using the `dig` command on a Linux system. Which command syntax would you use to attempt a full zone transfer for the domain `example.com` from the nameserver `ns1.example.com`?

Question 8Choose one

A security consultant is using Shodan to identify industrial control systems exposed to the internet. They want to search for devices running the Modbus protocol on the standard port. Which search query should they use?

Question 9Choose one

During a social engineering engagement, you plan to use the Social-Engineer Toolkit (SET) to harvest credentials. You want to clone the target's corporate login page and host it on your attacking machine, then email a link to the employees. Which attack vector in SET should you select?

Question 10Choose one

A penetration tester is drafting a phishing email targeting C-level executives. The email is crafted to look like a subpoena from a federal court, urging immediate action. This specific type of social engineering attack is known as:

10 more free samples are waiting

Create a free account to unlock the whole CPENT sample bank, or get full access to all 250 practice questions in the simulator.

Create account