Study Plan · Cybersecurity

CompTIA PenTest+ (PT0-003): A 12-Week Study Plan

intermediate

A free, realistic 12-week study plan for CompTIA PenTest+ (PT0-003): weekly goals, lab tasks and checkpoints across all five domains, with performance-based practice.

By The Exam Atlas Editorial Team · Verified 2026-08-05

This is a realistic twelve-week plan assuming around 8 hours of study per week. Adjust the pace to your background: people already testing or working in security can compress it toward eight weeks, while those coming straight from Security+ with no testing experience should stretch toward sixteen. The golden rule is to pair every week of reading with hands-on work in an isolated lab you own, because the performance-based questions reward interpreting real output.

Week 1 - Set up and the shape of the exam

Download the official PT0-003 objectives. Set up an isolated home lab using a purpose-built vulnerable practice range and a hypervisor. Learn the five domains, their weights, the up-to-90-question format and the 750/900 passing standard. Checkpoint: you can recite the five domains and their weights from memory.

Week 2 - Engagement management: scoping and documents

Study pre-engagement and scoping, rules of engagement, statement of work, master service agreement and non-disclosure agreement, and how they relate. Checkpoint: you can draft a rules-of-engagement outline and say what is out of scope.

Cover authorisation and third-party approval, regulated-data constraints, de-confliction and stop conditions, and the structure of a professional report. Checkpoint: you can name every section of a report and what belongs in each.

Week 4 - Reconnaissance: passive versus active

Learn passive reconnaissance and OSINT sources, active reconnaissance concepts, and why the split matters legally and for detection. Checkpoint: you can classify a given activity as passive or active and justify it.

Week 5 - Enumeration and attack surface

Study host, service, share, user, domain, application, API, wireless and cloud enumeration, and how output builds an attack-surface picture. Checkpoint: you can say what each enumeration category yields and how it changes your next step.

Week 6 - Vulnerability discovery

Cover scan types (credentialed versus non-credentialed, agent versus network), specialist scanning, and reading scanner output. Checkpoint: you can choose the right scan type for a stated goal and explain why.

Week 7 - Vulnerability analysis and prioritisation

Learn validation, false positives versus false negatives, and prioritising by exposure and business impact rather than CVSS alone. Checkpoint: you can validate a finding and rank a short list by real risk.

Week 8 - Attacks and exploits: network and host concepts

Study network and host attack categories at a conceptual level: what each achieves, how it is detected, and how it is prevented. Checkpoint: you can match a network or host attack category to a described target.

Week 9 - Attacks and exploits: web, API and cloud

Cover web application and API attack categories, and cloud, container and IoT attack surfaces, focusing on what each category is for. Checkpoint: you can match a web, API or cloud attack category to a described weakness.

Week 10 - Attacks and exploits: wireless, physical and social

Learn wireless and physical attack concepts and social engineering, including the written authorisation any of it requires. Checkpoint: you can explain why social engineering needs explicit authorisation and how it is scoped.

Week 11 - Post-exploitation and lateral movement

Cover persistence, privilege escalation, lateral movement and pivoting, data staging and exfiltration concepts, detection avoidance and cleanup. Checkpoint: you can explain vertical versus horizontal escalation and what cleanup must remove.

Week 12 - Review and timed practice

Take full-length, timed mixed reviews. Drill performance-based question tasks deliberately. Revisit your weakest domain and confirm exam-day logistics. Checkpoint: you consistently score above the pass standard on fresh, timed, mixed-domain sets.

A note on practice

Practise interpreting output and applying judgement, not memorising answers. Avoid any site offering “real exam questions” - they violate exam policy and copyright and can get your certification revoked. Everything you practise must stay inside a lab you own or have written permission to test, and the official objectives are your checklist throughout.

FAQ

How many weeks do I need to study for PenTest+?
There is no official figure. People already doing security or testing work often need 8 to 10 weeks; those with Security+ level knowledge but no testing experience usually need 12 to 16 weeks. This plan uses twelve weeks at around 8 hours per week and can be compressed or stretched.
What if I fall behind the plan?
Protect two things: the process domains (engagement management, reconnaissance and post-exploitation together are 48% of the exam) and the performance-based question practice. Understanding how a test is scoped, sequenced and reported well beats skimming every attack category.

Sources