Certification guidePT0-003

CompTIA PenTest+: the honest guide

Everything CompTIA publishes about PT0-003, in one place: what the exam asks, how the domains are weighted, and what it takes to be ready.

This guide page is built from the registry, not written yet.

Everything below comes from PenTest+’s published exam data, and every figure links to the vendor page it came from. The researched version, with study plans and the parts nobody publishes, is still being written. This page is not submitted to search engines until it is.

Practise PenTest+ questions in the meantime

What the exam actually asks you to do

Multiple choice, multiple response, and performance-based questions. The performance-based items drop you into a simulated console, network diagram, or configuration screen and score what you actually do.

  • Multiple choice
  • Multiple response
  • Performance-based

The highlighted formats are the ones you cannot answer from memory alone. CompTIA, PenTest+ exam details

Domain breakdown and official weightings

From the official CompTIA exam objectives. Attacks and Exploits is the heaviest domain at 35 percent, followed by Reconnaissance and Enumeration at 21 percent.

  • Engagement Management13%
  • Reconnaissance and Enumeration21%
  • Vulnerability Discovery and Analysis17%
  • Attacks and Exploits35%
  • Post-exploitation and Lateral Movement14%

Where to focus: Attacks and exploits is 35 percent, but engagement management and reporting are another 13. Candidates who only practice exploitation lose easy marks on scoping and documentation.

Official PenTest+ exam objectives ↗

What comes after passing

PenTest+ is valid for 3 years. 60 CEUs over the 3-year cycle, or pass the newest PenTest+ exam.

Costs across the full renewal cycle are on the PenTest+ cost page.

Frequently asked questions

What changed in PT0-003?

The blueprint was restructured around the shape of a real engagement: engagement management, reconnaissance and enumeration, vulnerability discovery, attacks and exploits, then post-exploitation and lateral movement. Attacks and exploits is the largest single domain at 35%.

Is PenTest+ enough to get a pentesting job?

On its own, rarely. It proves you know the methodology and the tooling vocabulary, which gets you read. What gets you hired is demonstrable practical work, so pair it with lab time you can talk about.

PenTest+ or eJPT first?

eJPT is a hands-on practical exam and cheaper. PenTest+ is broader, covers scoping and reporting properly, and is the one that shows up in HR filters. If you want skills, start with eJPT. If you want the credential a compliance-driven employer recognises, PenTest+.

How much of PenTest+ is tooling?

Enough that you need to recognise output from the common tools on sight, but the exam tests why you would reach for one, not memorised flags. Questions about scoping, rules of engagement, and reporting carry real weight.

Keep reading

Every guide and cost breakdown, by vendor

Practise PenTest+ for free while you decide

Original questions written from the published objectives, with the concept, the reasoning, and a note on every wrong option. No account needed to start.

Start free PenTest+ questions