PenTest+ Beta exam available

Tess Sluijter

Well-known member
Apr 1, 2020
377
1
539
the Netherlands
www.kilala.nl
Copy/pasting from my private blog:

A little under three years have passed since I last took the CompTIA Pentest+ exam. Like last time, I took the beta-version of the exam. Just like last time, I decided to go into the exam completely blank, only taking a glance at the official objectives beforehand.

The OnVue at-home testing experience offered by PearsonVue, like always, was decent. The tooling works well enough, the proctor was communicative, waiting times weren't too bad. The software feels kind of intrusive, as to what it wants to do on your laptop, but at least it didn't want me to install anything, nor does it require admin-level rights.

As to the exam itself, my experiences mirror what I felt back in 2018:
  • It feels like there's an over-reliance on NMap and its flags. The objectives state that 30% of your score comes from Attacks & Exploits, with a further 16% coming from Tools and Code Analysis. In my test, it felt like NMap-related questions made up 10-15% of the total question base. That doesn't sit right with me, but of course my impressions could be wrong.
  • A very small amount of questions were not good, from a test-taker perspective. Some were overly wordy, with long run-on sentences. Others either had zero correct answers (due to syntax mistakes), or made little sense logically.
  • The PBQs (performance based questions) were similar to last time, with the one I disliked the most making a re-appearance. It's one where you have to both categorize and remediate 7-10 vulnerabilities, where in some cases all responses are sub-optimal.
I feel that the PT1-002 exam needs some polishing and a few corrections, but overall the level of difficulty and the type of questions asked do in fact do a fairly good job at testing someone with 2-3 years of pentesting experience.

I'm curious whether I've passed! As was said: I went in without preparation and there's definitely a number of objective areas where I don't have experience.
 

Tess Sluijter

Well-known member
Apr 1, 2020
377
1
539
the Netherlands
www.kilala.nl
A forum-acquaintance elsewhere reminded me that, what to me feels like an over-reliance on NMap questions, is simply a symptom of the beta-exam. Of course the question pool isn't finished yet, so they're weeding out those questions that are sub-optimal.

@Stephen Schneiter : is there a way to pass word to the Pentest+ exam team that one question had very bad mistakes in the command syntax? All four responses were incorrect, because in the Linux commands the pipe symbol "|" had been replaced by a comma ",".
 

Rob F

Well-known member
Nov 7, 2019
24
24
Michigan
I seem to have had a similar experience. I did keep track of NMAP related questions and I had 12 out of 110. I also had a quite a few questions with regards to different scripting languages. I also had a question where 3 of the answers were correct but they only wanted one. I feel like, if they had a "NOT" in the question then it would have been ok. The run on sentences are in there :) . There were only 3 PBQ in my exam and ,yes, I had the one where you have to provide 20 answers !

The exam did seem to stick to the objectives document so that was good.

When I passed the PT0-001 exam I actually thought I had failed. After this exam I feel that I passed but will probably fail !
 

Rob F

Well-known member
Nov 7, 2019
24
24
Michigan
I forgot to mention that one of the PBQs did not seem to function correctly. It had 2 parts and part 1 was fine but when you clicked to see part 2, the answers for part 2 were there but no additional information was given. I had seen this PBQ in the PT0-001 exam and was expecting to see the additional information. So they either changed the question or mine did not work correctly. So...just an FYI for anybody that will be taking the beta.