PENTEST+ Study Guide 2026
Everything you need to pass the PENTEST+ exam in one place: the exam format, every topic to study, real practice questions with explanations, flashcards, and full-length practice tests. Free, no sign-up needed.
📋 PENTEST+ Exam Format at a Glance
📚 PENTEST+ Topics to Study (36)
✍️ Sample PENTEST+ Questions & Answers
1. Which set of DNS records is critical for organizations to configure to defend against email spoofing used in phishing?
SPF validates sending IP addresses, DKIM adds cryptographic signatures to emails, and DMARC enforces policy — together they significantly reduce domain spoofing in phishing.
2. An attacker sends an email appearing to come from an executive asking an employee to wire funds immediately. Which social engineering technique is this?
Business Email Compromise (BEC) involves impersonating executives or vendors to trick employees into transferring money or sensitive data.
3. What is the primary purpose of defining the target audience in a penetration test report?
Understanding the target audience allows the report to be written at an appropriate technical level, making findings actionable for executives or technical staff.
4. What is 'shoulder surfing' as a physical security attack?
Shoulder surfing involves physically positioning close enough to observe a target's screen, keyboard input, or documents to capture sensitive information without any technical tools.
5. Which document formally authorizes a penetration tester to perform testing activities and provides legal protection?
A get-out-of-jail-free letter (authorization letter) from the client explicitly grants permission to test and provides legal protection if the tester is questioned by law enforcement.
6. What does token impersonation allow an attacker to do in a Windows post-exploitation scenario?
Token impersonation steals authentication tokens from other logged-in users to assume their privileges without needing their plaintext password.