If you're weighing whether to sit CompTIA PenTest+, this guide is the place to start. It pulls together the current exam facts, walks through what each domain expects of you, and points you toward focused resources for the parts that trip most candidates up. Think of it as the map; the linked articles are the detailed routes.
PenTest+ sits in the intermediate tier of CompTIA's cybersecurity pathway. It's the offensive, hands-on counterpart to a defense-focused credential like CySA+, and it's usually taken after you already have foundational knowledge from Network+ and Security+ (or the equivalent experience). What makes it stand out is that it doesn't just quiz you on definitions — it asks you to do things.
What PenTest+ actually validates
The certification is built to confirm that you can run a penetration test end to end and communicate what you found. In practice that means you can:
- Plan and scope an engagement within legal and compliance boundaries.
- Gather information and enumerate targets across on-prem, cloud, web, wireless, API, and hybrid environments.
- Discover and analyze vulnerabilities, then separate real findings from false positives.
- Execute attacks and exploits appropriate to the target, adapting tools as needed.
- Move laterally and operate post-exploitation without breaking scope.
- Write a clear, professional report and brief stakeholders on remediation.
That last point matters more than newcomers expect. A pen tester who can't explain a finding to a non-technical decision-maker only did half the job, and the exam reflects that.
The current exam at a glance
The version in the field now is PT0-003, marketed as V3. It launched on December 17, 2024 and replaced PT0-002, which retired on June 17, 2025. This refresh added coverage for AI-driven attacks, expanded cloud and API exploitation, and more modern post-exploitation technique.
| Item | Detail |
|---|---|
| Exam code | PT0-003 (V3) |
| Number of questions | Up to 90 |
| Question types | Multiple-choice and performance-based (PBQs) |
| Length | 165 minutes (2 hours 45 minutes) |
| Passing score | 750 on a 100–900 scale |
| Recommended experience | Network+, Security+, or equivalent knowledge, plus 3–4 years of hands-on security work |
| Validity | 3 years, renewable via continuing education |
For a fuller breakdown of pacing, PBQ mechanics, and how the scaled score works, see our companion piece on the PenTest+ PT0-003 exam format.
The five domains and their weights
PT0-003 is organized into five domains. The percentages tell you where to spend your study hours — Attacks and Exploits alone is more than a third of the exam.
- Engagement Management — 13%. Scoping, rules of engagement, agreements (NDA, MSA, SoW, ToS), and the legal/ethical framing of a test.
- Reconnaissance and Enumeration — 21%. Active and passive information gathering, OSINT, scanning, and enumeration across many asset types.
- Vulnerability Discovery and Analysis — 17%. Running scans, validating results, and telling true positives from noise.
- Attacks and Exploits — 35%. The heaviest domain: injection attacks, web and application flaws, network and wireless attacks, cloud, and more.
- Post-exploitation and Lateral Movement — 14%. Persistence, pivoting, privilege escalation, and cleanup — all within scope.
Each of these deserves its own study session. We break them all down objective by objective in the PenTest+ domains guide.
Do you need prerequisites?
No exam prerequisite is enforced — you can register and sit PenTest+ without holding another certification. That said, CompTIA recommends you come in with Network+ and Security+ level knowledge and a few years of hands-on experience. If you jump in cold, the performance-based questions will feel much harder, because they assume you've actually used the tools rather than just read about them.
If you're still deciding where PenTest+ fits against other offensive certs, our comparison of PenTest+ vs CEH, OSCP, and GPEN lays out the trade-offs.
How to prepare
A realistic plan blends three ingredients: structured learning to cover the objectives, hands-on labs to build muscle memory, and practice questions to expose weak spots before exam day. Reading alone won't carry you through the PBQs.
- Work the objectives methodically — a week-by-week structure keeps you honest. See our 8-week PenTest+ study plan.
- Build hands-on reps in a lab. The PBQ and hands-on prep guide covers the tools and environments worth practicing.
- Choose your study materials deliberately. Our study resources overview explains how CertMaster Learn, Labs, Practice, and Perform differ so you don't over- or under-buy.
Is it worth it?
PenTest+ maps to real job roles — penetration tester, security consultant, vulnerability analyst, and related titles — and it's recognized within workforce frameworks that some employers and public-sector roles reference. Whether it's the right investment depends on your career direction. We dig into roles, expectations, and what hiring managers actually look for in is PenTest+ worth it.
Keeping the certification current
PenTest+ is valid for three years. You renew through CompTIA's continuing education program — earning continuing education units, passing a higher-level CompTIA exam, or passing the newest version of the exam — rather than letting it lapse. Passing PenTest+ also renews eligible lower-level CompTIA certifications you hold, which is a nice side benefit if you already carry Security+.
Getting started
When you're ready to prepare, the official self-paced course is a solid backbone for covering every objective in order.
Start with the official course: CompTIA PenTest+ CertMaster Learn (PT0-003 / V3). When you're closer to test day and need to book the exam, you can grab an exam voucher here. As an Authorized CompTIA Partner, we carry official materials only.
A note on voucher eligibility: Voucher eligibility depends on your exam testing location, per CompTIA policy. Testing in an emerging-market region? We don't sell those here — contact us.
FAQ
What's the difference between PT0-003 and V3? They're the same thing. PT0-003 is the official exam code; "V3" is the common shorthand for this third version of PenTest+.
Is PT0-002 still available? No. PT0-002 retired on June 17, 2025. PT0-003 is the only current version.
How many questions is the exam, and how long do I get? Up to 90 questions in 165 minutes, mixing multiple-choice with performance-based questions.
What score do I need to pass? 750 on a scaled range of 100 to 900. It isn't a straight percentage — harder questions carry more weight.
Do I have to take Security+ first? It isn't required to register, but CompTIA recommends Security+ and Network+ level knowledge plus a few years of hands-on experience before attempting PenTest+.
How long is the certification valid? Three years, after which you renew through continuing education units or a qualifying higher-level certification.
0 comments