Certified Penetration Testing Professional Free Sample Questions

20 free sample questions250 in the full practice test

Try simulator

CPENT Sample Questions

  1. Question 1

    A penetration tester is engaged to perform a black-box assessment of a corporate network. The tester decides to follow the Penetration Testing Execution Standard (PTES) to ensure a structured approach. During the Intelligence Gathering phase, the tester is attempting to map the organization's business relationships and employee hierarchy without touching the target's infrastructure. Which phase of the PTES does this activity strictly fall under, and which tool is MOST appropriate for visualizing these relationships?

    Answer and explanation

    Correct answer: B

    The Intelligence Gathering phase in PTES involves collecting as much information as possible about the target. Maltego is a premier tool for open-source intelligence (OSINT) and forensics that excels at visualizing relationships (links) between people, companies, domains, and internet infrastructure. BloodHound is for Active Directory trust mapping (internal), and Threat Modeling comes after intelligence gathering.

  2. Question 2

    During a strategic planning meeting for a new penetration test, the client requests that the assessment team specifically focus on simulating the tactics, techniques, and procedures (TTPs) of a specific Advanced Persistent Threat (APT) group known to target their industry. Which framework should the lead penetration tester reference to accurately design this emulation plan?

    Answer and explanation

    Correct answer: C

    The MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework is the industry standard for describing the actions an adversary might take during an intrusion. It provides detailed information on APT groups and their specific TTPs, making it the correct choice for adversary emulation.

  3. Question 3

    A penetration tester has discovered a critical vulnerability in a production database server that allows for remote code execution. The Rules of Engagement (RoE) explicitly state that no exploitation causing potential denial of service or data corruption is permitted on production systems. The tester believes they can exploit this to gain domain admin access. What is the correct course of action?

    Answer and explanation

    Correct answer: B

    The Rules of Engagement are a binding agreement. If the RoE prohibits risky exploitation on production systems, the tester must adhere to it strictly. The correct action is to document the finding (proof of vulnerability) without executing the dangerous payload, and report it.

  4. Question 4

    You are preparing the scoping document for a penetration test of a financial institution. The client requires that the test be conducted from the perspective of a malicious insider with standard user access. This type of test is BEST described as:

    Answer and explanation

    Correct answer: B

    Grey Box testing simulates an attacker with some knowledge or access to the system, such as a compromised employee account or an insider. This aligns with the client's request for a 'malicious insider with standard user access'. Black box implies no prior knowledge; White box implies full knowledge/admin access.

  5. Question 5

    While conducting OSINT on a target organization, you wish to identify all subdomains associated with 'example.com' that might be hosting development or staging environments. You decide to use a tool that queries multiple search engines (Google, Bing, etc.) and Shodan without actively scanning the target's network. Which tool is MOST suitable for this passive reconnaissance task?

    Answer and explanation

    Correct answer: B

    TheHarvester is a tool specifically designed for gathering emails, subdomains, hosts, employee names, open ports, and banners from different public sources like search engines, PGP key servers, and SHODAN. It is a passive reconnaissance tool (unless active options are enabled), fitting the requirement perfectly.

  6. Question 6

    A penetration tester wants to use Google Dorks to find publicly exposed PDF documents on a target website 'target-site.com' that might contain 'confidential' in the text. Which syntax is correct?

    Answer and explanation

    Correct answer: A

    The correct Google Dork syntax uses site: to restrict results to the specific domain, filetype: to specify the file extension (pdf), and quotes around confidential to search for that specific string within the files.

  7. Question 7

    You are performing a DNS analysis and suspect that the target's nameserver is misconfigured to allow Zone Transfers. You are using the dig command on a Linux system. Which command syntax would you use to attempt a full zone transfer for the domain example.com from the nameserver ns1.example.com?

    Answer and explanation

    Correct answer: A

    The AXFR query type is used to request a full zone transfer. The syntax dig @ -t AXFR directs the request specifically to the authoritative nameserver. If successful, this reveals all DNS records in the zone.

  8. Question 8

    A security consultant is using Shodan to identify industrial control systems exposed to the internet. They want to search for devices running the Modbus protocol on the standard port. Which search query should they use?

    Answer and explanation

    Correct answer: A

    Modbus typically runs on TCP port 502. The Shodan search query port:502 filters for this port, and adding modbus helps refine the results to devices identifying with that protocol banner.

  9. Question 9

    During a social engineering engagement, you plan to use the Social-Engineer Toolkit (SET) to harvest credentials. You want to clone the target's corporate login page and host it on your attacking machine, then email a link to the employees. Which attack vector in SET should you select?

    Answer and explanation

    Correct answer: A

    This is the correct path in the SET menu. Website Attack Vectors allows web-based attacks; Credential Harvester focuses on collecting usernames/passwords; Site Cloner automatically copies the target URL's HTML to the attacker's server.

  10. Question 10

    A penetration tester is drafting a phishing email targeting C-level executives. The email is crafted to look like a subpoena from a federal court, urging immediate action. This specific type of social engineering attack is known as:

    Answer and explanation

    Correct answer: A

    Whaling is a specific form of spear-phishing that targets high-profile individuals ('big fish') like CEOs, CFOs, or other C-level executives. The content is usually tailored to legal, executive, or financial matters.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 250 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon