100+ Free PT1 Practice Questions
Prepare for the TryHackMe Junior Penetration Tester (PT1) exam with instant access — no signup required.
Loading practice questions...
Explore More TryHackMe Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: PT1 Exam
48 hours
Exam Duration
TryHackMe
750 pts
Passing Score
TryHackMe
$297
Exam Cost
TryHackMe
3 domains
Engagements (Web/Network/AD)
TryHackMe
1 retake
Free Retake Included
TryHackMe
3 months
Premium Subscription Included
TryHackMe
The TryHackMe PT1 is a 48-hour practical penetration testing exam with three engagements: web (OWASP Top 10), network (SMB/RDP/FTP/SNMP), and Active Directory. You need 750 points to pass plus a professional report. The exam costs $297 including one free retake and a 3-month Premium subscription. Recommended prep: complete the Jr Penetration Tester learning path (~80 hours) on TryHackMe before attempting.
Sample PT1 Practice Questions
Try these sample questions to test your PT1 exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1Which Nmap flag is used to perform a SYN stealth scan (half-open scan) against a target?
2Which Nmap flag enables version detection for discovered services?
3What Nmap Scripting Engine (NSE) script category is best used to check for known vulnerabilities on open ports?
4During SMB enumeration, which tool is commonly used on Linux to gather shares, users, and OS information from a Windows SMB host?
5Which default TCP port does the SMB protocol use on Windows systems?
6What does the Nmap script 'smb-enum-shares' reveal about a target Windows system?
7An FTP server responds to an anonymous login attempt with '230 Login successful'. What does this indicate from a penetration testing perspective?
8Which SNMP version sends community strings and data in cleartext, making it vulnerable to network sniffing?
9What tool can enumerate SNMP OIDs and retrieve system information using the default 'public' community string?
10When performing RDP reconnaissance, which Nmap script checks whether the target's Remote Desktop Protocol service is vulnerable to the BlueKeep exploit (CVE-2019-0708)?
About the PT1 Exam
The TryHackMe PT1 (Junior Penetration Tester) is a practical 48-hour certification exam covering web application security, network enumeration and exploitation, and Active Directory attacks. Candidates connect via OpenVPN, tackle three separate engagements, earn flag-based points, and submit a professional penetration test report. This practice test covers the knowledge needed for the Jr Penetration Tester learning path and PT1 exam.
Assessment
Performance-based assessment
Time Limit
48 hours
Passing Score
750 points
Exam Fee
$297 (TryHackMe)
PT1 Exam Content Outline
Reconnaissance and Network Enumeration
Nmap scanning (SYN, UDP, version detection, NSE scripts), passive OSINT (WHOIS, Shodan, Censys, certificate transparency), SMB/FTP/RDP/SNMP enumeration with enum4linux, snmpwalk, and Nmap scripts
Web Application Security (OWASP Top 10)
SQL injection (union, blind, time-based), XSS (stored, reflected, DOM), IDOR, SSRF (regular and blind), command injection, file upload bypass, directory brute-forcing with Gobuster, and Burp Suite (Proxy, Repeater, Intruder)
Active Directory Enumeration and Attacks
BloodHound/SharpHound, PowerView, Kerbrute username enumeration, AS-REP Roasting, Kerberoasting, Pass-the-Hash, LLMNR/NBT-NS poisoning with Responder, DCSync with secretsdump.py, and lateral movement with CrackMapExec
Exploitation and Post-Exploitation
Metasploit Framework (msfvenom, multi/handler, meterpreter), EternalBlue (MS17-010), privilege escalation (Linux SUID/sudo/cron, Windows unquoted service paths, SeImpersonatePrivilege), and pivoting with Ligolo-ng or SSH tunneling
Methodology and Report Writing
Penetration testing phases (recon→scan→exploit→post-exploit→report), scoping and rules of engagement, CVSS scoring, executive summary vs technical findings, proof file documentation
How to Pass the PT1 Exam
What You Need to Know
- Passing score: 750 points
- Assessment: Performance-based assessment
- Time limit: 48 hours
- Exam fee: $297
Keys to Passing
- Work through all 100 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
PT1 Study Tips from Top Performers
Frequently Asked Questions
What is the TryHackMe PT1 exam format?
PT1 is a 48-hour practical exam. Candidates receive an OpenVPN file and access to a pentest simulator with three separate engagements: web application security, network penetration testing, and Active Directory exploitation. Points are earned by capturing flags on compromised systems. You need 750 points to pass. After the exam, you submit a professional penetration test report, which is graded by an AI system.
What tools are needed for the PT1 exam?
TryHackMe allows any tools of your choice. Key tools include: Nmap (port scanning), Burp Suite (web testing), Gobuster/Nikto (web enumeration), Metasploit Framework (exploitation), Hydra (brute-forcing), enum4linux/CrackMapExec (SMB/AD), BloodHound/SharpHound + PowerView (AD enumeration), Impacket suite (GetUserSPNs.py, secretsdump.py), Responder (LLMNR poisoning), and Ligolo-ng (pivoting). Kali Linux is the recommended OS.
How does the PT1 exam compare to eJPT and PJPT?
PT1 ($297) is comparable in difficulty to INE Security's eJPT and TCM Security's PJPT. All three are entry-level practical certifications. PT1 covers all three domains (web/network/AD) in a single exam, while PJPT focuses specifically on Active Directory. eJPT includes MCQ components alongside labs. PT1 is attractive because it bundles 3 months of TryHackMe Premium and a free retake with the purchase.
What learning path should I complete before PT1?
TryHackMe recommends completing the Jr Penetration Tester learning path (approximately 80 hours), which covers: pentesting methodology, Nmap, Burp Suite, OWASP Top 10 web vulnerabilities, Metasploit, network services exploitation (SMB, FTP, SNMP, RDP, Telnet), Active Directory enumeration and attacks, and Linux/Windows privilege escalation. Practice rooms like Attacktive Directory, OWASP Juice Shop, and Blue are especially valuable.
How difficult is the PT1 exam?
PT1 is designed for junior-level pentesters. Community reviews indicate the Active Directory engagement is the most straightforward, while the web application engagement is the most technically challenging. Candidates who have completed the full Jr Penetration Tester path and practiced on Active Directory rooms (Attacktive Directory, AD Basics) generally report being well-prepared. Budget your 48 hours wisely across all three engagements.
Is this practice test the same as the PT1 exam?
No — this is a theoretical multiple-choice knowledge-prep test. The real PT1 exam requires actually exploiting live systems and capturing flags in a virtual environment. This practice test helps you learn and verify the concepts, tools, commands, and techniques covered in the Jr Penetration Tester learning path. To pass PT1, you must practice hands-on exploitation in TryHackMe's interactive labs.