PT0-003

CompTIA PenTest+ practice exams

Original questions written from the published objectives and cited to official documentation, never recalled exam content. How we verify, why not dumps.

Exam code
PT0-003
Cost
$425USD
Questions
Maximum of 90
Duration
165minutes
Passing score
750(scale 100-900)
Level
Mid level
Valid for
3years
Study guide
How to prepare
Sources
125official pages
Practice all PBQs
12tasks
Format
Multiple choice and performance-based

PenTest+ practice exams

2 full-length forms, 90 questions each, apportioned to the published domain weightings.

PT0-003CompTIA PenTest+

After a successful USB-drop test, the client asks for the most direct control against that vector. Which recommendation fits?

The answer

Limit USB and removable media use

Checked against

Limit the use of USB devices and removable media within a network.

attack.mitre.org, checked August 2026
Answer five like it, free

What the exam tests

Exam domains and official weightings

The percentage is the exam weighting; the bar is how many verified questions we hold there, so a short bar is where our bank is thin.

5domains
  • Engagement Management13%
    29 verified
  • Reconnaissance and Enumeration21%
    45 verified
  • Vulnerability Discovery and Analysis17%
    37 verified
  • Attacks and Exploits35%
    71 verified
  • Post-exploitation and Lateral Movement14%
    31 verified

Where to focus: Attacks and exploits is 35 percent, but engagement management and reporting are another 13. Candidates who only practice exploitation lose easy marks on scoping and documentation.

What the exam actually asks you to do

Multiple choice, multiple response, and performance-based questions. The performance-based items drop you into a simulated console, network diagram, or configuration screen and score what you actually do.

Item formats

  • Multiple choice
  • Multiple response
  • Performance-based

The highlighted formats are the ones you cannot answer from memory alone. CompTIA, PenTest+ exam details

The part of PenTest+ you cannot memorize

Performance-based questions are where memorized dumps fail, because you cannot memorize your way through configuring or analyzing something. A dump can tell you which letter was marked correct. It cannot read the output on the screen in front of you and tell you what it means.

We built 12 of them for PenTest+, across 4 interaction types. They score with partial credit, and every one ends with a walkthrough of the reasoning rather than just an answer key.

Sorting
Drop controls, data states, or hardening tasks into the category each one belongs to.
Sequencing
Put incident response phases, forensic collection, or a remediation cycle in the order the work actually happens.
Log and output analysis
Read a real log excerpt, firewall rule set, or command output, then answer what it tells you.
Matching
Assign the right technology to each requirement, with a pool bigger than the number of slots so guessing does not pay.

Between sittings

The same bank the numbered forms are assembled from.

  • Quick Practice

    Open now

    All 213 verified questions, untimed, with the explanation after each answer.

  • Domain Drill

    Open now

    Every domain on its own, for the area a score report says is weakest.

  • Review Missed

    Fills as you go

    Re-asks the questions you got wrong. Nothing to review until you miss something.

Open PenTest+ practice

Where PenTest+ fits

CompTIA’s free resources

Study from the source. Everything below is published by the vendor, free to read, and is what our own questions are written from:

Official PenTest+ exam page & objectives ↗

Keep reading

Cheat sheets

Printable reference tables, free.

Compared with

Side by side on cost, difficulty, and which one to take first.

Every guide and cost breakdown, by vendor

Frequently asked questions

What changed in PT0-003?

The blueprint was restructured around the shape of a real engagement: engagement management, reconnaissance and enumeration, vulnerability discovery, attacks and exploits, then post-exploitation and lateral movement. Attacks and exploits is the largest single domain at 35%.

Is PenTest+ enough to get a pentesting job?

On its own, rarely. It proves you know the methodology and the tooling vocabulary, which gets you read. What gets you hired is demonstrable practical work, so pair it with lab time you can talk about.

PenTest+ or eJPT first?

eJPT is a hands-on practical exam and cheaper. PenTest+ is broader, covers scoping and reporting properly, and is the one that shows up in HR filters. If you want skills, start with eJPT. If you want the credential a compliance-driven employer recognises, PenTest+.

How much of PenTest+ is tooling?

Enough that you need to recognise output from the common tools on sight, but the exam tests why you would reach for one, not memorised flags. Questions about scoping, rules of engagement, and reporting carry real weight.