100+ Free PJPT Practice Questions
Prepare for the Practical Junior Penetration Tester exam with instant access — no signup required.
Loading practice questions...
Explore More TCM Security Practical Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: PJPT Exam
$249
Exam Cost
TCM Security
48 + 48 hrs
Pentest + Report Time
TCM Security
1 free
Retake Included
TCM Security
DC compromise
Pass Requirement
TCM Security
12 months
Course Access Included
TCM Security
No proctor
Exam Monitoring
TCM Security
The PJPT from TCM Security is an affordable, practical junior penetration testing certification priced at $249 (including a free retake and 12 months of course access). Candidates have 48 hours to conduct an internal Active Directory pentest and 48 hours to write a professional report. The exam requires compromising the Domain Controller using real AD attack techniques. This practice exam tests theoretical knowledge; the actual PJPT requires live exploitation in a virtual lab environment.
Sample PJPT Practice Questions
Try these sample questions to test your PJPT exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1Which protocol does LLMNR use when a DNS query fails to resolve a hostname on a local network?
2Which tool is the standard choice for performing LLMNR/NBT-NS poisoning to capture NTLMv2 hashes?
3What type of hash does Responder capture during LLMNR poisoning attacks?
4What is the primary prerequisite for a successful SMB relay attack?
5When performing an SMB relay attack, which Responder configuration change is required before relaying?
6Which Impacket tool is used to relay captured NTLM authentication to another host during an SMB relay attack?
7What is Kerberoasting and what does it exploit?
8Which Impacket script is used to perform Kerberoasting by requesting TGS tickets for all service accounts?
9What Hashcat mode is used to crack Kerberoasted TGS ticket hashes?
10What is Pass-the-Hash (PTH) and which authentication protocol does it exploit?
About the PJPT Exam
The PJPT (Practical Junior Penetration Tester) is TCM Security's entry-level hands-on penetration testing certification. Unlike multiple-choice exams, the PJPT requires candidates to perform a real internal Active Directory penetration test over 48 hours, then write a professional report. This practice test covers the knowledge needed: networking fundamentals, AD architecture, LLMNR/NBT-NS poisoning, SMB relay, Kerberoasting, Pass-the-Hash, lateral movement, and Domain Controller compromise.
Assessment
Performance-based assessment
Time Limit
48 hours (pentest) + 48 hours (report)
Passing Score
DC compromise + professional report
Exam Fee
$249 (TCM Security)
PJPT Exam Content Outline
Active Directory Attacks
LLMNR/NBT-NS poisoning with Responder, SMB relay with ntlmrelayx.py, Kerberoasting, AS-REP Roasting, Pass-the-Hash, token impersonation, and Domain Controller compromise
Active Directory Enumeration
AD architecture, Domain Controller identification, BloodHound/SharpHound, PowerView, LDAP queries, domain user/group enumeration, and attack path mapping
Networking Fundamentals
TCP/IP, OSI model, subnetting, DNS/DHCP, SMB/LDAP/Kerberos ports, Nmap scanning, reverse shells, and internal network reconnaissance
Linux & Windows CLI
Essential Linux commands (id, ps, find SUID, sudo -l, ip addr), Windows commands (net user, netstat, tasklist, systeminfo), and privilege escalation enumeration
Post-Exploitation
Mimikatz credential dumping, secretsdump.py, lateral movement with psexec.py/wmiexec.py, file transfer techniques, and pivoting
Report Writing
Executive summary, technical findings with severity ratings, evidence screenshots, and remediation recommendations for a professional penetration test report
How to Pass the PJPT Exam
What You Need to Know
- Passing score: DC compromise + professional report
- Assessment: Performance-based assessment
- Time limit: 48 hours (pentest) + 48 hours (report)
- Exam fee: $249
Keys to Passing
- Work through all 100 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
PJPT Study Tips from Top Performers
Frequently Asked Questions
What is the PJPT exam format?
The PJPT gives you 48 hours to perform an internal Active Directory penetration test in a virtual lab environment, followed by 48 additional hours to write and submit a professional penetration test report. The exam is unproctored and all tools are permitted, including AI-assisted tools. You must compromise the Domain Controller and document your findings professionally to pass.
How much does the PJPT cost?
The PJPT costs $249 USD and includes 12 months of access to TCM Security's Practical Ethical Hacking course plus one free retake if needed. This makes it one of the most affordable practical penetration testing certifications available, significantly cheaper than OSCP ($1,499+) or eJPT alternatives.
What do I need to know to pass the PJPT?
The PJPT focuses on internal Active Directory penetration testing. You need to understand LLMNR/NBT-NS poisoning with Responder, SMB relay attacks with ntlmrelayx.py, Kerberoasting with GetUserSPNs.py, Pass-the-Hash with CrackMapExec, AD enumeration with BloodHound and PowerView, lateral movement techniques, and professional report writing. TCM's Practical Ethical Hacking course covers all required topics.
How hard is the PJPT exam?
The PJPT is designed as an entry-level practical exam — it is considered significantly more accessible than OSCP or PNPT. With completion of the Practical Ethical Hacking course and hands-on lab practice (building your own AD home lab is strongly recommended), most candidates pass within their first or second attempt. The exam includes a free retake if you don't pass the first time.
Does the PJPT require Active Directory experience?
The PJPT exam revolves entirely around an internal Active Directory environment. You must successfully compromise the Domain Controller, which requires practical knowledge of AD attack techniques including LLMNR poisoning, SMB relay, Pass-the-Hash, and Kerberoasting. Setting up and attacking your own AD home lab during preparation is highly recommended by successful candidates.
Is this practice exam like the real PJPT?
No — this is a theoretical multiple-choice practice exam. The real PJPT is a hands-on practical exam where you must actually exploit a real virtual Active Directory environment. This practice exam helps you learn the concepts, tools, commands, and techniques needed. To pass the actual PJPT, you must practice hands-on exploitation, ideally by building your own AD home lab and working through TCM's Practical Ethical Hacking course.