CompTIA PenTest+ practice exams
Original questions written from the published objectives and cited to official documentation, never recalled exam content. How we verify, why not dumps.
- Exam code
- PT0-003
- Cost
- $425USD
- Questions
- Maximum of 90
- Duration
- 165minutes
- Passing score
- 750(scale 100-900)
- Level
- Mid level
- Valid for
- 3years
- Study guide
- How to prepare
- Sources
- 125official pages
- Practice all PBQs
- 12tasks
- Format
- Multiple choice and performance-based
PenTest+ practice exams
2 full-length forms, 90 questions each, apportioned to the published domain weightings.
After a successful USB-drop test, the client asks for the most direct control against that vector. Which recommendation fits?
The answer
Limit USB and removable media use
Checked against
attack.mitre.org, checked August 2026Limit the use of USB devices and removable media within a network.
What the exam tests
Exam domains and official weightings
The percentage is the exam weighting; the bar is how many verified questions we hold there, so a short bar is where our bank is thin.
- Engagement Management13%29 verified
- Reconnaissance and Enumeration21%45 verified
- Vulnerability Discovery and Analysis17%37 verified
- Attacks and Exploits35%71 verified
- Post-exploitation and Lateral Movement14%31 verified
Where to focus: Attacks and exploits is 35 percent, but engagement management and reporting are another 13. Candidates who only practice exploitation lose easy marks on scoping and documentation.
What the exam actually asks you to do
Multiple choice, multiple response, and performance-based questions. The performance-based items drop you into a simulated console, network diagram, or configuration screen and score what you actually do.
Item formats
- Multiple choice
- Multiple response
- Performance-based
The highlighted formats are the ones you cannot answer from memory alone. CompTIA, PenTest+ exam details ↗
The part of PenTest+ you cannot memorize
Performance-based questions are where memorized dumps fail, because you cannot memorize your way through configuring or analyzing something. A dump can tell you which letter was marked correct. It cannot read the output on the screen in front of you and tell you what it means.
We built 12 of them for PenTest+, across 4 interaction types. They score with partial credit, and every one ends with a walkthrough of the reasoning rather than just an answer key.
- Sorting
- Drop controls, data states, or hardening tasks into the category each one belongs to.
- Sequencing
- Put incident response phases, forensic collection, or a remediation cycle in the order the work actually happens.
- Log and output analysis
- Read a real log excerpt, firewall rule set, or command output, then answer what it tells you.
- Matching
- Assign the right technology to each requirement, with a pool bigger than the number of slots so guessing does not pay.
Between sittings
The same bank the numbered forms are assembled from.
Quick Practice
Open now
All 213 verified questions, untimed, with the explanation after each answer.
Domain Drill
Open now
Every domain on its own, for the area a score report says is weakest.
Review Missed
Fills as you go
Re-asks the questions you got wrong. Nothing to review until you miss something.
Where PenTest+ fits
CompTIA security track
The classic vendor-neutral ladder into security. Prerequisites are recommendations, not gates, until CISSP, which needs real experience.
CompTIA’s free resources
Study from the source. Everything below is published by the vendor, free to read, and is what our own questions are written from:
Official PenTest+ exam page & objectives ↗Keep reading
- Free PenTest+ practice test
Ten real questions, playable now. No account, no card.
- PenTest+ passing score
The exact cut score, what kind of number it is, and the retake terms.
- How hard is PenTest+?
An honest difficulty read from the format, the clock and the weights.
- What PenTest+ costs
The voucher price, the retake, and what renewal costs across the cycle.
- PenTest+ guide
Who it is for, study plans by experience level, and whether it is worth it.
Compared with
Side by side on cost, difficulty, and which one to take first.
Frequently asked questions
What changed in PT0-003?
The blueprint was restructured around the shape of a real engagement: engagement management, reconnaissance and enumeration, vulnerability discovery, attacks and exploits, then post-exploitation and lateral movement. Attacks and exploits is the largest single domain at 35%.
Is PenTest+ enough to get a pentesting job?
On its own, rarely. It proves you know the methodology and the tooling vocabulary, which gets you read. What gets you hired is demonstrable practical work, so pair it with lab time you can talk about.
PenTest+ or eJPT first?
eJPT is a hands-on practical exam and cheaper. PenTest+ is broader, covers scoping and reporting properly, and is the one that shows up in HR filters. If you want skills, start with eJPT. If you want the credential a compliance-driven employer recognises, PenTest+.
How much of PenTest+ is tooling?
Enough that you need to recognise output from the common tools on sight, but the exam tests why you would reach for one, not memorised flags. Questions about scoping, rules of engagement, and reporting carry real weight.