Cybersecurity

CompTIA PenTest+ (PT0-003)

intermediate

CompTIA PenTest+

By The Exam Atlas Editorial Team · Verified 2026-08-05

Free PT0-003 practice questions 45 questions with full answer explanations. No sign-up. Start practice →

Overview

CompTIA PenTest+ (PT0-003) is a mid-level penetration-testing certification built around the whole engagement, not just the exploitation phase. Its five domains follow a real test end to end: engagement management (scoping, rules of engagement, reporting), reconnaissance and enumeration, vulnerability discovery and analysis, attacks and exploits, and post-exploitation and lateral movement. CompTIA weights attacks and exploits heaviest at 35%.

The exam mixes multiple-choice questions with performance-based questions, so it checks both that you know the methodology and that you can read tool output and pick the right next step. That places it between the knowledge-based CEH and the fully hands-on OSCP: more structured and far cheaper than either, but not a substitute for OSCP's practical proof.

The current version is PT0-003 (marketed as V3), which launched on 17 December 2024. The previous version, PT0-002, retired on 17 June 2025, so PT0-003 is the only version you can now sit - and a large amount of study material still on sale targets the retired version.

✓ Who it is for

  • Working testers who need a recognised, vendor-neutral credential for HR screens and contracts
  • Security or vulnerability analysts moving from defensive work into offensive testing
  • People whose job includes scoping, managing or reviewing penetration tests, not only running them
  • Candidates who want a structured, affordable step before attempting OSCP

✕ Who it is not for

  • Complete beginners - CompTIA recommends 3-4 years in a penetration tester role plus Network+/Security+ level knowledge.
  • Anyone who has to prove hands-on exploitation to a red-team hiring manager - OSCP's practical exam still carries more weight there.
  • Analysts committed to the defensive path - CySA+ maps far more closely to SOC and detection work.
  • Anyone who will not budget for renewal - PenTest+ needs 60 CEUs plus a US$150 CE fee every three years, and CertMaster CE does not cover it.

Exam structure

Engagement management13% - pre-engagement activities, scoping, rules of engagement, legal and compliance considerations, collaboration, and reporting and communication.
Reconnaissance and enumeration21% - passive and active information gathering, enumerating hosts, services, users, domains and cloud assets, and preparing a target picture.
Vulnerability discovery and analysis17% - scanning, interpreting scanner output, validating findings, prioritising by real risk, and analysing code and configuration weaknesses.
Attacks and exploits35% - the largest domain: network, host, web application, API, wireless, cloud, IoT and social-engineering attack concepts, and choosing the right technique for a target.
Post-exploitation and lateral movement14% - persistence and privilege concepts, moving through an environment, staging and exfiltration concepts, and cleaning up artefacts at the end of an engagement.
DeliveryUp to 90 questions in 165 minutes, mixing multiple choice with performance-based questions. Pass at 750 on a scale of 100-900.

How the exam is weighted

  • Engagement Management 13%
  • Reconnaissance and Enumeration 21%
  • Vulnerability Discovery and Analysis 17%
  • Attacks and Exploits 35%
  • Post-exploitation and Lateral Movement 14%
Approximate official domain weighting - confirm the current split in the official exam objectives. Verified 2026-08-05.

What each domain covers

Engagement Management
Pre-engagement activities and scoping · Rules of engagement and authorisation · Legal, regulatory and compliance considerations · Collaboration and communication during a test · Reporting, findings and remediation guidance
Reconnaissance and Enumeration
Passive information gathering and OSINT · Active reconnaissance concepts · Host, service and share enumeration · Domain, user and cloud asset discovery · Scripting and automation for reconnaissance
Vulnerability Discovery and Analysis
Vulnerability scanning types and configuration · Interpreting and validating scanner output · False positives and false negatives · Prioritising findings by real-world risk · Code, configuration and application analysis
Attacks and Exploits
Network and host attack concepts · Web application and API attack categories · Wireless and physical attack concepts · Cloud, container and IoT attack surfaces · Social engineering in an authorised test · Matching an attack technique to a target
Post-exploitation and Lateral Movement
Establishing and maintaining access concepts · Privilege escalation concepts · Lateral movement and pivoting concepts · Data staging and exfiltration concepts · Detection avoidance and defensive evasion concepts · Cleanup, artefact removal and restoring state

Realistic study time

  • Already testing or doing security work 60-90 hours, commonly 6-10 weeks part-time (unofficial estimate)
  • Security+ level knowledge, no testing experience 100-150 hours, commonly 3-4 months part-time, with lab time (unofficial estimate)

Bars show relative effort, not a guarantee. Your time depends on background and study method.

Turn this into a week-by-week schedule with the Study Plan Generator.

What it really costs

Exam voucher US$439
Voucher with one retake included US$579 CompTIA's Retake Assurance bundle; cheaper than paying twice if you are unsure
Retake on a plain voucher Full fee again there is no free retake
Optional CertMaster study products US$149-709 each Study, Practice, Labs, Learn and Perform are all optional; larger bundles cost more
Renewal US$150 CE fee per 3-year cycle plus 60 CEUs, or renew fee-free by passing a higher or newer qualifying exam

Fees change and vary by region. Confirm the current amount on the official site before you register.

Want your full out-of-pocket figure? Try the Cost Calculator.

Salary & career value

Indicative ranges for orientation only - not surveyed data, and not financial or career advice. Sources and date below.

Pass rate: Not published. CompTIA does not release official pass rates for any of its exams, so quoted percentages are third-party estimates, not verified data. The published standard is the passing score: 750 on a scale of 100 to 900.

Jobs that often ask for it:

  • Penetration tester
  • Vulnerability tester / vulnerability analyst
  • Security consultant running authorised assessments
  • Application or cloud security tester
  • Security analyst moving into offensive testing

Is it worth it?

It is worth it if the process side of testing is part of your job, or if you need a credential a non-technical HR filter will recognise. PenTest+ is the only mainstream pentest certification that weights scoping, rules of engagement, legal considerations and reporting as a full domain, and those are exactly the parts junior testers get wrong on real engagements. Its performance-based questions also push you past pure recall, and at US$439 it costs a fraction of OSCP or CEH. Be honest about what it does not do. It is a proctored exam with a mix of question types, not a 24-hour practical, so it does not prove to a red-team hiring manager that you can compromise a live network - OSCP still does that better, and job postings for hands-on roles say so. Against CEH the comparison is closer: both are largely assessment-style, but PenTest+ is cheaper, has no training-or-experience eligibility gate, and covers the engagement lifecycle in more depth, while CEH has broader brand recognition with recruiters and appears on more compliance baselines. A sensible reading: take PenTest+ if you want the methodology, the vendor-neutral badge and a stepping stone; take OSCP if you need to prove you can actually break in; take CEH mainly when a job posting or contract names it.

Not sure this is the right exam for you? Compare your options with the Exam Finder.

Our specialty · side by side

Compare PT0-003 with other exams

Independent, like-for-like comparisons to help you choose the right one.

What to do next

If you want proof of hands-on exploitation, OSCP is the usual next step and PenTest+ makes decent preparation for its methodology. If your work is drifting back toward defence, CySA+ covers detection and response, and CISSP is the long-term move into security leadership.

On exam day

Book through your CompTIA account, which hands off to Pearson VUE for a test centre seat or an OnVUE remotely proctored session. You get up to 90 questions in 165 minutes, mixing multiple choice with performance-based questions, and need 750 on a scale of 100-900. The performance-based questions usually appear first and consume the most time, so flag and return rather than stalling on one. If you test online, run the system check in advance and clear your desk and room, since the proctor will require it.

Keeping your certification

Valid 3 years under CompTIA's Continuing Education program. Renewal needs 60 CEUs across the three-year cycle plus a US$150 CE fee for that period. Single-activity alternatives include passing the newest PenTest+ version, earning a higher CompTIA certification, or earning a qualifying non-CompTIA industry certification (CompTIA lists bodies such as ISC2, ISACA, OffSec and EC-Council). CertMaster CE, the single-course renewal route, is not available for PenTest+ - CompTIA offers it only for A+, Network+ and Security+. Holding PenTest+ also renews lower CompTIA certifications such as A+, Network+ and Security+.

FAQ

Is CompTIA PenTest+ worth it compared with OSCP?
They prove different things. PenTest+ is a proctored exam covering the full engagement lifecycle, including scoping, legal considerations and reporting, and costs US$439. OSCP is a long hands-on practical against live machines and is the credential hiring managers use as evidence you can actually exploit systems. If you need proof of hands-on skill, OSCP wins; if you need methodology, a vendor-neutral badge and a far lower price, PenTest+ is the better buy - and many people do PenTest+ first.
PenTest+ or CEH - which should I take?
PenTest+ is cheaper, has no eligibility gate, and treats engagement management and reporting as a full domain. CEH is more widely recognised by recruiters and appears on more compliance and government baselines, but adds a training-or-experience requirement and a higher total cost. Choose CEH when a specific job posting or contract names it; otherwise PenTest+ generally gives more testing methodology per dollar.
Which exam version is current, PT0-002 or PT0-003?
PT0-003. It launched on 17 December 2024 and PT0-002 retired on 17 June 2025, so PT0-003 is the only version you can sit. Check the code on any book or course before you buy, because a lot of PT0-002 material is still on sale and the domain structure changed between versions.
How much does CompTIA PenTest+ cost in total?
The voucher is US$439 at standard retail. A voucher bundled with one retake is US$579, and there is no free retake on a plain voucher - a fail means buying another. Study products are optional: CompTIA's own CertMaster range runs from about US$149 to US$709 per product, and plenty of candidates prepare with the free objectives plus their own lab.
How long is PenTest+ valid and how do I renew it?
Three years, under CompTIA's Continuing Education program. Renewal needs 60 CEUs across the cycle plus a US$150 CE fee for the three-year period. You can also renew by passing the newest PenTest+ version, earning a higher CompTIA certification, or earning a qualifying industry certification from bodies such as ISC2, ISACA, OffSec or EC-Council. Note that CertMaster CE, the single-course renewal route, is not offered for PenTest+.
Do I need experience before taking PenTest+?
Not formally - there are no enforced prerequisites. CompTIA recommends 3-4 years in a penetration tester job role plus Network+ and Security+ level knowledge. In practice, people pass with less, but with no networking or security foundation the attacks and exploits domain, at 35% of the exam, becomes very hard to reason about.
What is the PenTest+ pass rate?
CompTIA does not publish pass rates for any of its exams, so any percentage you see quoted is a third-party estimate rather than verified data. The published standard is the passing score: 750 on a scale of 100 to 900.
What languages is PenTest+ available in?
CompTIA lists English, French, Japanese and Portuguese for PT0-003. Some CompTIA study products are also localised, but the language list for the exam itself is the one to check on the official certification page before you book.

Related exams

Free study resources

Sources