Certification guide
PT0-003CompTIA PenTest+: the honest guide
PenTest+ is the offensive exam in CompTIA's stack. It sits above Security+ and alongside CySA+, and the difference between the two siblings is the whole reason to pick one: CySA+ is the defensive seat, reading alerts and deciding what matters, while PenTest+ puts you on the other side of the same network with a scope document and a deadline.
The current version is PT0-003. It is a maximum of 90 questions in 165 minutes, and the pass mark is 750 on a scale of 100 to 900. CompTIA publishes the count as a maximum rather than a fixed number, so plan your pacing around the clock rather than around a question total. Alongside multiple choice and multiple response you get performance-based questions, which drop you into a simulated console, network diagram or configuration screen and score what you actually do.
Those performance-based items are the reason this exam cannot be read for. A candidate who has never run an enumeration sweep, never read the output, and never decided what to do with it can memorise every definition in the objectives and still lose the marks that carry the most weight. Lab time is the study method, and everything else supports it.
The blueprint follows the shape of a real engagement. Attacks and exploits is the largest domain at 35 percent, reconnaissance and enumeration is 21, vulnerability discovery and analysis is 17, post-exploitation and lateral movement is 14, and engagement management is 13. That last one is the domain candidates write off, and it is the cheapest 13 percent on the paper.
Who PenTest+ is for
A good fit if
- You hold Security+ and want to move toward offensive work rather than the analyst seat.
- You already do vulnerability assessment or internal testing informally and need a credential that says so.
- You work in a compliance-driven environment where the certification has to appear on a list before the skills get read.
- You are on a security team that runs its own testing and you need the scoping, rules of engagement and reporting side properly covered, not just the tooling.
- You want a broad offensive credential that covers the whole engagement, from the statement of work to the report, rather than only the exploitation phase.
Probably not, if
- You do not have security fundamentals yet. PenTest+ assumes networking fluency and the control vocabulary Security+ teaches, and it does not stop to explain either. Take Security+ first, even if the offensive work is the part you actually want. CompTIA itself recommends Network+ and Security+ knowledge plus three to four years in a penetration testing role before this exam.
- You want the credential that offensive security hiring managers weight most heavily. That is usually a fully practical exam where you compromise real machines and write the report, because it demonstrates the work rather than describing it. eJPT is the cheaper hands-on starting point and a practical exam is the stronger hiring signal in that specific market. PenTest+ is broader and covers scoping and reporting properly, which those exams often do not.
- You want defensive work: detection, triage, incident response. That is CySA+. It is the same level in the same stack pointed the other way, and taking the offensive exam because it sounds more interesting is a poor reason to spend a voucher.
- You are looking for a first certification. This is an intermediate exam that assumes both fundamentals and hands-on comfort. Skipping to it tends to raise a question in an interview rather than answer one.
Is PenTest+ worth it?
For someone already in a security role moving toward offensive work, yes. PenTest+ is the credential that gets past the filter, and the studying itself is useful in a way that not every certification manages: the objectives push you through a full engagement rather than a tool list, so you come out understanding why a finding gets written up the way it does, not just how to produce it.
For someone who wants to be a penetration tester and has no security background, the honest answer is not yet. On its own PenTest+ rarely produces a testing job. It proves you know the methodology and the tooling vocabulary, which is what gets your CV read. What gets you hired is demonstrable practical work you can talk through in an interview. Pair the certification with lab machines you have actually compromised and can describe, or the credential sits on a page and does nothing.
For someone choosing between PenTest+ and a fully practical offensive exam, it depends on which door you are trying to open. A practical exam is the stronger technical signal to an offensive security team. PenTest+ is the one that appears in HR filters, government and contractor requirements, and compliance-driven job specs, and it covers scoping and reporting in a way hands-on exams generally skip. Plenty of working testers end up holding both, and the order usually depends on which of those two problems is blocking them right now.
For someone already testing professionally with years behind them, it is worth having rather than worth studying for. You will pass it without learning much, it ticks a contract or promotion box, and the study time is better spent elsewhere unless something specific is forcing it.
What the exam actually asks you to do
Multiple choice, multiple response, and performance-based questions. The performance-based items drop you into a simulated console, network diagram, or configuration screen and score what you actually do.
Item formats
- Multiple choice
- Multiple response
- Performance-based
The highlighted formats are the ones you cannot answer from memory alone. CompTIA, PenTest+ exam details ↗
Domain breakdown and official weightings
From the official CompTIA exam objectives. Attacks and Exploits is the heaviest domain at 35 percent, followed by Reconnaissance and Enumeration at 21 percent.
- Engagement Management13%
- Reconnaissance and Enumeration21%
- Vulnerability Discovery and Analysis17%
- Attacks and Exploits35%
- Post-exploitation and Lateral Movement14%
Where to focus: Attacks and exploits is 35 percent, but engagement management and reporting are another 13. Candidates who only practice exploitation lose easy marks on scoping and documentation.
Study plans by experience level
Holding Security+, already comfortable in a lab
8 to 10 weeksat 8 to 10 hours
- 1Week 1: read the PT0-003 objectives end to end and mark every line you could describe but not perform. That marked list is your syllabus. The unmarked lines are what Security+ already gave you.
- 2Weeks 2 to 3: reconnaissance and enumeration at 21 percent. Work against live targets from the first session. Run the sweeps, read the raw output, and practise deciding what the output tells you to do next rather than reciting what each tool is for.
- 3Weeks 4 to 6: attacks and exploits at 35 percent, the largest domain and the one that needs the most machine time. Cover network, web application, wireless, cloud and social engineering vectors rather than going deep on one you enjoy. The exam samples across all of them.
- 4Week 7: post-exploitation and lateral movement at 14 percent. Persistence, privilege escalation, pivoting, and cleanup. Practise this on a two or three machine lab, because reading about pivoting teaches almost nothing.
- 5Week 8: engagement management at 13 percent. Scope, rules of engagement, authorisation, communication triggers, and the report. It is the least interesting week and the highest marks per hour on this exam.
- 6Weeks 9 to 10: performance-based practice against the clock, then full timed mocks. Book the exam when your mock scores sit consistently above the pass line and you are finishing with time to spare.
Security fundamentals in place, new to offensive tooling
12 to 16 weeksat 6 to 8 hours
- 1Weeks 1 to 2: build the lab before you study anything. A hypervisor, a Kali or Parrot virtual machine, and two or three vulnerable targets. Everything after this is easier if you can break something on demand.
- 2Weeks 3 to 5: reconnaissance and enumeration. Passive collection, then active scanning, then service enumeration. Get to the point where you can look at a scan result and say what you would try next without a reference sheet.
- 3Weeks 6 to 8: vulnerability discovery and analysis at 17 percent. This is not running a scanner. It is reading what the scanner returned, deciding which finding is real, and ranking what matters given the asset and the exposure.
- 4Weeks 9 to 12: attacks and exploits. Work one vector class per week and compromise something in each. Network services, web applications, credential attacks, wireless, cloud and social engineering all appear in the objectives.
- 5Weeks 13 to 14: post-exploitation, lateral movement, and then engagement management. Write a short report on one of the machines you compromised, including scope and findings, because writing one teaches the reporting objectives faster than reading about them.
- 6Weeks 15 to 16: performance-based practice twice a week, then timed full mocks. The format should be unremarkable before exam day, not new.
Working as a tester, need the credential
3 to 4 weeksat 5 to 6 hours
- 1Read the objectives and mark only what your day job does not cover. For most working testers that is CompTIA's specific vocabulary for things you do by habit, plus whichever vector class your shop never touches.
- 2Take a full timed mock at the end of week one. It will name the gap between doing the work and answering CompTIA's questions about it faster than any amount of reading.
- 3Study the marked items and nothing else. Re-reading tools you use every week feels productive and moves your score very little.
- 4Spend the last week on the performance-based format and on engagement management. The exam marks CompTIA's terminology for scoping and reporting, not your firm's methodology, and that is where experienced testers lose marks they did not expect to lose.
Common mistakes
- Practising exploitation and skipping the paperwork
- Attacks and exploits is 35 percent, so it gets all the attention. Engagement management is another 13 percent, and it is scope, authorisation, rules of engagement, communication triggers and the report. Candidates who only practise the fun part lose easy marks on the part that takes no lab time to learn.
- Meeting the performance-based questions for the first time in the exam
- They drop you into a simulated console or configuration screen and score what you do, they take longer than a multiple choice item, and they are a different skill. Leaving them until the final week means learning the interaction with the clock running. Practise the format from the first month.
- Memorising tool flags instead of tool purpose
- The exam expects you to recognise output from the common tools on sight and to know why you would reach for one over another. It does not reward a memorised flag list. If you can read a scan result and say what it means and what comes next, you are testing the right skill.
- Studying PT0-002 material for a PT0-003 exam
- PT0-003 is the current version and PT0-002 is the previous one. The blueprint was restructured around the shape of a real engagement, and older material is organised differently and misses content. Check the exam code on anything you buy or download before you spend a week inside it.
- Reading about the attack instead of running it
- This is the exam where passive study fails most reliably. Watching a video of a privilege escalation and performing one produce very different recall under a clock. If a study week ends with no terminal open, that week did less than it felt like it did.
- Booking the exam to create pressure
- Paying $425 in advance to motivate yourself works until the date arrives and your lab hours are still short. Vouchers expire around twelve months from purchase, which is long enough for most plans and short enough to waste. Book when your mocks say you are ready.
- Ignoring the score report after a failure
- CompTIA breaks a failed result down by domain, and the domains point at very different fixes. A weak attacks and exploits line means lab hours. A weak engagement management line means a weekend of reading. Rebooking without reading the report is how a gap costs you a second $425.
What comes after passing
PenTest+ is valid for three years. Renewal is 60 continuing education units across the cycle plus CompTIA's continuing education fee, or re-sitting the current version of the exam at full price. If you take any higher security certification during the cycle, that alone can cover the CEU requirement, so the renewal ends up costing nothing beyond the fee.
The credential opens the door; the lab work walks through it. Keep compromising machines and keep writing them up, because the interview for an offensive role is a conversation about things you have actually done. A short, honest write-up of a box you rooted is worth more in that conversation than the certificate, and holding both is what makes the certificate mean something.
The next steps split by direction. A fully practical offensive exam is the natural follow-on if you want the technical signal that hands-on hiring managers weight most heavily. CySA+ is worth adding if your role sits on both sides and you want the defensive vocabulary to match. A senior technical or security architecture credential fits if you are heading toward designing the controls rather than breaking them.
If you are near government or contractor work, check the current DoD 8140 tables for the specific work role you are targeting rather than assuming the mapping. CompTIA and the DoD both revise them, and the answer changes by role.
Costs across the full renewal cycle are on the PenTest+ cost page.
Frequently asked questions
Is PenTest+ worth it?
For someone already in security moving toward offensive work, yes. It gets past HR and compliance filters that hands-on exams do not, and it covers scoping and reporting properly. For someone with no security background hoping it produces a testing job on its own, it rarely does.
What is on the PT0-003 exam?
Five domains: attacks and exploits at 35 percent, reconnaissance and enumeration at 21, vulnerability discovery and analysis at 17, post-exploitation and lateral movement at 14, and engagement management at 13. The blueprint follows the shape of a real engagement from scoping to reporting.
How long does PenTest+ take to study for?
Eight to ten weeks at 8 to 10 hours a week if you hold Security+ and are already comfortable in a lab. Twelve to sixteen weeks if offensive tooling is new to you. Three to four weeks if you already test professionally and mainly need CompTIA's vocabulary for it.
Do I need Security+ before PenTest+?
It is not enforced, but PenTest+ assumes the networking fluency and control vocabulary Security+ teaches. CompTIA recommends Network+ and Security+ knowledge along with three to four years in a penetration testing role. If security fundamentals are missing, start there.
What score do I need to pass PenTest+?
750 on a scale of 100 to 900, across a maximum of 90 questions in 165 minutes. The exam mixes multiple choice, multiple response and performance-based items, and the performance-based ones carry more weight, so raw question count and scaled score do not map cleanly onto each other.
Is PenTest+ or CySA+ the right one to take?
They are the same level pointed in opposite directions. CySA+ is the defensive exam: read the alert, triage it, respond. PenTest+ is the offensive one: scope the engagement, find the way in, document it. Pick the seat you want to sit in rather than the one that sounds more interesting.
Does PenTest+ have performance-based questions?
Yes. Alongside multiple choice and multiple response, PT0-003 includes performance-based items that put you in a simulated console, network diagram or configuration screen and score what you do. They are why reading alone does not prepare you for this exam.
How much of PenTest+ is about tools?
Enough that you need to recognise output from the common tools on sight, but the exam tests why you would reach for one rather than a memorised flag list. Scoping, rules of engagement and reporting carry real weight alongside the tooling.
Keep reading
- PenTest+ practice questions
Free sample questions with the full explanation on every answer.
- Free PenTest+ practice test
Ten real questions, playable now. No account, no card.
- PenTest+ passing score
The exact cut score, what kind of number it is, and the retake terms.
- How hard is PenTest+?
An honest difficulty read from the format, the clock and the weights.
- What PenTest+ costs
The voucher price, the retake, and what renewal costs across the cycle.
Compared with
Side by side on cost, difficulty, and which one to take first.
Practise PenTest+ for free while you decide
Original questions written from the published objectives, with the concept, the reasoning, and a note on every wrong option. No account needed to start.
Start free PenTest+ questions