PT0-003

CompTIA PenTest+ practice questions

Original questions written from the published exam objectives, never recalled exam content, with an explanation that teaches the concept behind every answer. Why that matters.

Exam code
PT0-003
Cost
$425 USD
Questions
Maximum of 90
Duration
165 minutes
Passing score
750 (scale 100-900)
Format
Multiple choice and performance-based

The PT0-003 exam costs $425. Fail it and the retake is another $425. Practicing until you are ready is the cheapest part of this. Full cost breakdown.

Exam domains and official weightings

From the official CompTIA exam objectives. Put your study time where the weight is.

5domains
  • Engagement Management13%
  • Reconnaissance and Enumeration21%
  • Vulnerability Discovery and Analysis17%
  • Attacks and Exploits35%
  • Post-exploitation and Lateral Movement14%
  • Engagement Management13%
  • Reconnaissance and Enumeration21%
  • Vulnerability Discovery and Analysis17%
  • Attacks and Exploits35%
  • Post-exploitation and Lateral Movement14%

Where to focus: Attacks and exploits is 35 percent, but engagement management and reporting are another 13. Candidates who only practice exploitation lose easy marks on scoping and documentation.

Try 5 free sample questions

No account needed. Every question includes our three-tier explanation: the concept, why the answer follows, and why each wrong option is wrong.

Sample question 1 of 5

Engagement ManagementModerate

Mid-engagement you find that a host inside the agreed IP range is hosted by a third-party provider not named in the rules of engagement. What do you do?

Sample question 2 of 5

Reconnaissance and EnumerationEasy

During the passive phase of an external assessment, which activity stays passive?

Sample question 3 of 5

Attacks and ExploitsHard

An application fetches a URL supplied by the user to generate a link preview. You submit http://169.254.169.254/latest/meta-data/ and the response contains instance metadata. Which vulnerability is this, and what is the most effective fix?

Sample question 4 of 5

Post-exploitation and Lateral MovementModerate

You recover a local administrator NTLM hash from one workstation and authenticate to eleven other workstations with it without ever cracking it. Which weakness made that possible?

Sample question 5 of 5

Vulnerability Discovery and AnalysisModerate

Your scanner reports a critical remote code execution flaw on a production database server. The client has asked for proof before they will schedule downtime. What is the appropriate next step?

Full PenTest+ question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

What the exam actually asks you to do

Multiple choice, multiple response, and performance-based questions. The performance-based items drop you into a simulated console, network diagram, or configuration screen and score what you actually do.

  • Multiple choice
  • Multiple response
  • Performance-based

The highlighted formats are the ones you cannot answer from memory alone. CompTIA, PenTest+ exam details

An honest study plan

  1. 1. Read the official objectives first

    Download the official objectives from CompTIA and skim every line. The exam can only test what’s listed there, it’s the contract.

  2. 2. Weight your study toward Attacks and Exploits and Reconnaissance and Enumeration

    Together the top two domains are 56% of the exam. Practice them until your accuracy is consistently above 80%.

  3. 3. Drill weak domains, then take a mock exam

    Use Domain Drill on your weakest areas, then a full timed mock at real length (Maximum of 90 questions, 165 minutes). Book the real exam when you’re consistently passing mocks, not before.

Official free resources

Study from the source. These are CompTIA’s own materials:

Official PenTest+ exam page & objectives ↗

Where PenTest+ fits

Related certifications

Frequently asked questions

What changed in PT0-003?

The blueprint was restructured around the shape of a real engagement: engagement management, reconnaissance and enumeration, vulnerability discovery, attacks and exploits, then post-exploitation and lateral movement. Attacks and exploits is the largest single domain at 35%.

Is PenTest+ enough to get a pentesting job?

On its own, rarely. It proves you know the methodology and the tooling vocabulary, which gets you read. What gets you hired is demonstrable practical work, so pair it with lab time you can talk about.

PenTest+ or eJPT first?

eJPT is a hands-on practical exam and cheaper. PenTest+ is broader, covers scoping and reporting properly, and is the one that shows up in HR filters. If you want skills, start with eJPT. If you want the credential a compliance-driven employer recognises, PenTest+.

How much of PenTest+ is tooling?

Enough that you need to recognise output from the common tools on sight, but the exam tests why you would reach for one, not memorised flags. Questions about scoping, rules of engagement, and reporting carry real weight.

Ready to practice for PT0-003?

Play the free samples now. The full question bank is in progress, and you can join the waitlist on any sample question.

Start practicing free
PenTest+ pass coming soon

Payment is not switched on yet. Everything free stays free either way, and explanations are never behind a payment.

$29 buys the PenTest+ bank for good, including everything added to it later. Right now that is 5 sample questions, so buy it to back the work rather than for what is there today. Or go Pro for every certification.