100+ Free PNPT Practice Questions
Prepare for the TCM Security Practical Network Penetration Tester exam with instant access — no signup required.
Loading practice questions...
Explore More TCM Security Practical Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: PNPT Exam
$499
Exam Cost (includes retake + training)
TCM Security
5 days
Pentest Engagement Window
TCM Security
2 days
Report Submission Window
TCM Security
15 min
Live Debrief Duration
TCM Security
Zero flags
No CTF Elements — Real Pentest
TCM Security
1 free
Retake Included
TCM Security
The PNPT from TCM Security is a practical penetration testing certification covering 5 domains: OSINT/External Recon (20%), External Exploitation (20%), Active Directory Attacks (35%), AV Evasion/Lateral Movement (15%), and Report Writing (10%). The exam gives 5 full days for the pentest plus 2 days to write a professional report, followed by a mandatory live 15-minute verbal debrief with TCM Security assessors. All tools are permitted — including Metasploit and AI tools. Cost is $499 with one free retake. Primary prep: Practical Ethical Hacking (PEH) course by Heath Adams (TheCyberMentor). This practice exam covers the conceptual knowledge; actual PNPT requires hands-on exploitation.
Sample PNPT Practice Questions
Try these sample questions to test your PNPT exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1Which tool is most commonly used in the PNPT exam to perform LLMNR/NBT-NS poisoning to capture NTLMv2 hashes?
2LLMNR (Link-Local Multicast Name Resolution) operates on which UDP port?
3After capturing an NTLMv2 hash with Responder, which tool and hashcat mode combination would you use to crack it offline?
4Which condition MUST be met on the target network for an SMB relay attack to succeed instead of simply capturing and cracking hashes?
5Which Impacket tool is used to execute the SMB relay attack by relaying captured NTLMv2 hashes to other hosts in the network?
6What does Pass-the-Hash (PtH) allow an attacker to do without knowing the plaintext password?
7Which mimikatz command is used to dump credentials (NTLM hashes and cleartext passwords) from LSASS memory on a compromised Windows host?
8Kerberoasting targets service accounts that have which attribute set in Active Directory?
9Which tool from the Impacket suite is used to perform Kerberoasting from a Linux machine without needing an interactive session?
10What hashcat mode is used to crack Kerberoasting TGS-REP hashes?
About the PNPT Exam
The PNPT (Practical Network Penetration Tester) is TCM Security's flagship certification validating real-world network penetration testing skills. Unlike multiple-choice exams, the PNPT requires conducting a full external and internal network penetration test over 5 days, writing a professional report, and delivering a live 15-minute debrief to senior assessors. This practice test covers the theoretical knowledge: LLMNR poisoning, SMB relay, Kerberoasting, AS-REP Roasting, Golden/Silver tickets, Pass-the-Hash, AV evasion, and professional reporting.
Assessment
Performance-based assessment
Time Limit
5 days pentest + 2 days report + 15-min live debrief
Passing Score
Pass/Fail (Domain Controller compromised + professional report + debrief)
Exam Fee
$499 (includes one free retake and 12 months TCM Academy access) (TCM Security)
PNPT Exam Content Outline
Active Directory Attacks
LLMNR/NBT-NS poisoning with Responder, SMB relay with ntlmrelayx.py, Pass-the-Hash with crackmapexec/evil-winrm, Kerberoasting (GetUserSPNs.py), AS-REP Roasting (GetNPUsers.py), Golden Ticket, Silver Ticket, DCSync via secretsdump.py, BloodHound/PowerView enumeration, and token impersonation
External Network Enumeration & Exploitation
Nmap scanning, SMB/SNMP/web enumeration, EternalBlue (MS17-010), web vulnerabilities (LFI, SQLi, WordPress), default credential attacks, password spraying with kerbrute, and initial shell access techniques
OSINT & External Reconnaissance
theHarvester, Hunter.io, crt.sh certificate transparency, Shodan, LinkedIn scraping, Google dorking, haveibeenpwned breach data, subdomain enumeration, and technology profiling
AV/EDR Evasion & Lateral Movement
Living-off-the-land binaries (LOLBins), msfvenom payload generation, staged vs stageless payloads, Chisel/proxychains pivoting, certutil download, WDigest manipulation, and stealthy lateral movement
Report Writing & Professional Debrief
Professional penetration test report structure (Executive Summary, Technical Findings, CVSS severity, remediation recommendations), rules of engagement, attack chain documentation, and verbal debrief presentation
How to Pass the PNPT Exam
What You Need to Know
- Passing score: Pass/Fail (Domain Controller compromised + professional report + debrief)
- Assessment: Performance-based assessment
- Time limit: 5 days pentest + 2 days report + 15-min live debrief
- Exam fee: $499 (includes one free retake and 12 months TCM Academy access)
Keys to Passing
- Work through all 100 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
PNPT Study Tips from Top Performers
Frequently Asked Questions
What is the PNPT exam format?
The PNPT gives candidates 5 full days to perform an external and internal network penetration test against a simulated organization. There are zero flags to capture and zero multiple-choice questions. After completing the engagement, candidates have 2 additional days to write a professional penetration test report. Finally, candidates schedule a live 15-minute verbal debrief with senior TCM Security assessors to present their findings. All tools are permitted including Metasploit, custom scripts, and AI-assisted tools (which must be disclosed in the report).
What Active Directory attacks are covered in the PNPT?
The PNPT covers the full internal Active Directory attack chain: LLMNR/NBT-NS poisoning with Responder to capture NTLMv2 hashes, SMB relay attacks with ntlmrelayx.py, Pass-the-Hash with crackmapexec and evil-winrm, Kerberoasting (GetUserSPNs.py / hashcat -m 13100), AS-REP Roasting (GetNPUsers.py / hashcat -m 18200), Golden Ticket and Silver Ticket attacks using mimikatz, DCSync with secretsdump.py, token impersonation, and BloodHound/PowerView enumeration for attack path discovery.
How does the PNPT compare to OSCP?
The PNPT ($499) is more affordable than OSCP ($1,699+) and focuses heavily on Active Directory attacks and OSINT, while OSCP emphasizes standalone machine exploitation, buffer overflows (legacy), and restricts tool use (one Metasploit use per exam). PNPT allows all tools including Metasploit. OSCP is more widely recognized by enterprise employers, while PNPT is gaining strong reputation in the penetration testing community as a practical, realistic assessment. Many candidates use PNPT as an intermediate step before OSCP.
What courses should I take to prepare for the PNPT?
TCM Security's Practical Ethical Hacking (PEH) by Heath Adams (TheCyberMentor) is the primary recommended preparation — it covers the complete external and internal pentest methodology end-to-end. TCM's OSINT Fundamentals course covers the external reconnaissance phase. The $499 PNPT package includes 12 months of TCM Academy access covering 45+ hours of training. Supplemental practice on TryHackMe and Hack The Box Active Directory rooms is highly beneficial.
What tools are required for the PNPT exam?
Key tools include: Responder and ntlmrelayx.py for LLMNR/SMB relay attacks; Impacket suite (secretsdump.py, GetUserSPNs.py, GetNPUsers.py, psexec.py, wmiexec.py) for AD attacks; mimikatz for credential dumping and ticket attacks; BloodHound/bloodhound-python and PowerView for AD enumeration; crackmapexec and evil-winrm for lateral movement; Chisel/proxychains for pivoting; nmap for scanning; and standard offensive Linux tools. Kali Linux is the recommended operating system.
Is this practice exam like the real PNPT?
No — this is a theoretical multiple-choice knowledge exam. The real PNPT is a 5-day hands-on practical penetration test where you must actually exploit a simulated network and write a professional report. Use this practice exam to test your understanding of PNPT concepts, tools, and attack techniques. To pass the actual PNPT, you must practice hands-on exploitation in lab environments like TCM Academy, TryHackMe, and Hack The Box.