Certified Penetration Testing Engineer Exam Prep
Free practice questions

Free C)PTE Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

The C)PTE exam has 100 questions and runs 2 hours.

These 10 free C)PTE questions are organized by exam domain, so you can see how each part of the Certified Penetration Testing Engineer blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Penetration Testing Methodologies

Question 1

A production order-processing service begins restarting during permitted testing, and legitimate orders fail. The timing correlates with the tester's requests. The rules of engagement require an immediate pause for suspected test-induced disruption and reserve recovery changes to the service owner. The operator still has an active session. What takes priority now?

Show answer & explanation

Correct answer: D - Stop test traffic, notify the designated contact, and preserve the activity timeline.

Domain 2: Advanced Recon & Attack Surface Mapping

Question 2

A system maintainer disputes a remote-code-execution CVE flagged solely from an SSH service's upstream version banner. Authenticated inspection confirms that the running executable is the unmodified vendor package. The vendor advisory identifies that exact package release as containing the CVE fix through backporting. No independent evidence contradicts the inspection. What disposition is justified for this scanner result?

Show answer & explanation

Correct answer: B - Withdraw this CVE finding, retaining the verified package details and the vendor advisory.

Domain 3: Exploitation Techniques (Local & Remote)

Question 3

An approved exploit validation produces no reverse session. The evidence for this attempt is: Host telemetry: the web worker launches the agreed test process as its service account. Filesystem: the process writes this attempt's unique execution marker. Firewall: the outbound connection to the approved listener is denied. What conclusion separates execution from session establishment?

Show answer & explanation

Correct answer: A - Code execution succeeded as the service account, but the callback was blocked.

Domain 4: Post-Exploitation & Lateral Movement

Question 4

An internal HTTPS server is reachable through an approved application proxy using a browser configured for that proxy. The proxy supports TCP connections but no UDP or raw IP packets. A scanner on the tester's laptop uses ICMP discovery and raw SYN probes and reports that the server is down. Before accepting that conclusion, the tester should:

Show answer & explanation

Correct answer: C - Use a proxy-aware TCP connection test without ICMP discovery.

Domain 5: Cloud & Active Directory Exploitation

Question 5

An Active Directory delegation review finds that an ordinary service account has effective DS-Replication-Get-Changes and DS-Replication-Get-Changes-All rights on the domain naming context. It belongs to no administrative group and cannot log on interactively to a domain controller. The account can reach the domain controller's replication service. What exposure should the tester flag without retrieving real password material?

Show answer & explanation

Correct answer: D - The account can use DCSync to request replicated password material without administrative group membership or interactive logon.

Domain 6: Evasion & Payload Crafting

Question 6

During an isolated, authorized evasion exercise, file screening blocks a harmless test artifact before execution. An encoded variant with the same test behavior and a different hash passes that screening and writes its execution marker. EDR then raises the expected process-lineage alert, which is correlated to the test. No safety limit is crossed. The evidence supports which result?

Show answer & explanation

Correct answer: B - File screening allowed the variant; behavioral detection still identified its execution.

Domain 7: Web, API & Mobile Attacks

Question 7

A billing API uses signed access tokens and opaque invoice UUIDs. Two approved test customers have the same role, and each may read only their own invoices. With customer A's unchanged token, a tester requests customer B's invoice UUID and receives B's invoice details. The application log still identifies the caller as A. Which authorization boundary has failed?

Show answer & explanation

Correct answer: C - Object-level authorization: A has read an invoice outside A's permitted ownership.

Question 8

Code review of an invoice-search endpoint shows that customer values are correctly bound as SQL parameters. The ORDER BY column, however, is copied from the request's sort field and concatenated into the query. The feature only needs to sort by created_at or total. Which revision removes this injection path while preserving both supported sort choices?

Show answer & explanation

Correct answer: A - Map each supported sort value to a fixed server-side column identifier.

Domain 9: Purple Team Collaboration

Question 9

Before a detection rule enters production, a purple team runs 40 valid adversary-emulation tests and 160 representative benign tests. The rule alerts on 36 adversary tests and 24 benign tests. Each test counts once, and all required telemetry is present. The release gates are recall of at least 85% and precision of at least 75%. Select the decision supported by these results.

Show answer & explanation

Correct answer: B - Do not promote: recall is 90%, but precision is only 60%.

Domain 10: Reporting & Business Risk Analysis

Question 10

A vulnerability register records a CVSS v4.0 Base score of 8.2, an EPSS probability of 0.12, and an EPSS percentile of 0.96, all dated to the assessment. An executive asks whether this means the organization has a 96% chance of being breached. Which interpretation belongs in the report?

Show answer & explanation

Correct answer: D - High severity; an estimated 12% probability of observed exploitation in the wild over the next 30 days.

The rest of the C)PTE blueprint

The C)PTE exam also covers these domains. Drill them in the full free practice test:

That's 10 of 1,030

The full bank has 1,020 more C)PTE questions with explanations.

Continue in the free practice test →

View plans