Cheat Sheet · Cybersecurity

CompTIA PenTest+ (PT0-003) Cheat Sheet

intermediate

A free CompTIA PenTest+ (PT0-003) cheat sheet: domain weights, engagement documents, the testing phases, attack categories and must-know acronyms for final revision.

By The Exam Atlas Editorial Team · Verified 2026-08-05

A quick-revision summary for CompTIA PenTest+ (PT0-003). Use it in the final days before the exam to check recall. It is a study aid only - you cannot bring notes into the proctored exam, and everything here describes concepts, not operational steps.

The five domains and weights

#DomainWeight
1Engagement management13%
2Reconnaissance and enumeration21%
3Vulnerability discovery and analysis17%
4Attacks and exploits35%
5Post-exploitation and lateral movement14%

Attacks and exploits is the biggest single domain, but domains 1, 2 and 5 together are 48%. Do not neglect the process content.

Format at a glance

ItemDetail
QuestionsUp to 90
TypesMultiple choice plus performance-based questions (PBQs)
Time165 minutes
Passing score750 on a scale of 100-900
LanguagesEnglish, French, Japanese, Portuguese
DeliveryPearson VUE test centre or OnVUE online

Engagement documents to know

DocumentPurpose
Rules of engagement (RoE)What may be tested, when, from where, and what is off-limits
Statement of work (SOW)Deliverables, timeline and commercial terms
Master service agreement (MSA)The standing legal relationship
Non-disclosure agreement (NDA)Protects what the tester learns
Attestation of findingsShort signed statement of scope and dates, often for auditors

Pattern: nothing you do is legitimate outside written authorisation, and third-party assets may need the provider’s approval too.

The testing phases (methodology)

PhaseWhat it produces
Engagement managementScope, authorisation, communication plan, report
ReconnaissancePassive and active information about the target
EnumerationServices, versions, shares, users, domains, cloud assets
Vulnerability analysisValidated, prioritised findings
Attacks and exploitsProof a finding is real, with least necessary impact
Post-exploitationEscalation, movement and pivoting concepts, then cleanup

Attack categories by surface (concepts)

SurfaceExample categories
NetworkOn-path positioning, name/address resolution abuse, replay of authentication
HostCredential attacks, over-permissive configuration, unpatched components
Web applicationInjection, XSS, broken access control, SSRF, insecure deserialisation
APIBroken object-level authorisation, excessive data exposure, missing rate limiting
Wireless / physicalRogue and evil-twin access points, tailgating, unattended workstations
Cloud / container / IoTOver-permissive identity, exposed storage, vulnerable images, default credentials

Must-know acronyms

AcronymMeaning
RoE / SOW / MSA / NDARules of Engagement / Statement of Work / Master Service Agreement / Non-Disclosure Agreement
OSINTOpen-Source Intelligence
PBQPerformance-Based Question
CVE / CVSSVulnerability identifier / Common Vulnerability Scoring System (0-10)
XSSCross-Site Scripting
SSRFServer-Side Request Forgery
BOLABroken Object Level Authorisation
OnVUEPearson VUE online proctored delivery
CE / CEUContinuing Education / Continuing Education Unit

FAQ

Can I take a cheat sheet into the PenTest+ exam?
No. PenTest+ is a proctored exam and no notes are allowed. Use this as a final-revision summary in the days before your exam, not during it.

Sources