CompTIA PenTest+ (PT0-003) has five domains: Engagement management (13%), Reconnaissance and enumeration (21%), Vulnerability discovery and analysis (17%), Attacks and exploits (35%), and Post-exploitation and lateral movement (14%), tested through up to 90 multiple-choice and performance-based questions in 165 minutes.
The weights below are CompTIA’s official PT0-003 figures. This page explains in plain English what each domain covers so you can plan your study; the official objectives PDF on CompTIA’s certification page is the authoritative document and should be your final checklist.
The five domains at a glance
| # | Domain | Weight |
|---|---|---|
| 1 | Engagement management | 13% |
| 2 | Reconnaissance and enumeration | 21% |
| 3 | Vulnerability discovery and analysis | 17% |
| 4 | Attacks and exploits | 35% |
| 5 | Post-exploitation and lateral movement | 14% |
| Total | 100% |
A planning note most candidates miss: attacks and exploits is the biggest single domain, but domains 1, 2 and 5 together are 48% of the exam. PenTest+ is a methodology certification, and the process content is where prepared candidates gain their margin.
Domain 1 - Engagement management (13%)
Everything around the testing, from first conversation to signed-off report.
- Pre-engagement and scoping: defining targets, permitted techniques, testing windows, and what is explicitly out of scope.
- Governing documents: rules of engagement, statement of work, master service agreement, non-disclosure agreement.
- Authorisation: written permission from someone empowered to give it, plus third-party approval where assets are hosted or managed by another provider.
- Legal, regulatory and compliance considerations: privacy law, regulated data such as payment card and health information, and cross-border constraints.
- Testing models: known-environment, partially known and unknown-environment testing, and the threat model being simulated.
- Collaboration and communication: de-confliction with the defensive team, escalation contacts, stop conditions, and what triggers immediate notification.
- Reporting: executive summary, methodology, findings with evidence and risk ratings, remediation guidance, attestation of findings, and retesting.
Domain 2 - Reconnaissance and enumeration (21%)
Turning a target definition into a precise map of the attack surface.
- Passive reconnaissance: public records, certificate transparency data, document metadata, job adverts, code repositories and other open-source intelligence.
- Active reconnaissance: probing that sends traffic to the target, which is detectable and legitimate only inside the agreed scope and window.
- Host and service enumeration: identifying live systems, listening services and software versions.
- Resource enumeration: shares, files, users, groups, directory and domain structure.
- Application and API enumeration: site content, endpoints, methods and undocumented interfaces.
- Cloud and wireless discovery: storage, functions and identity configuration; wireless networks and their authentication.
- Scripting and automation: recognising what a reconnaissance script or automated workflow is doing and what its output means.
Domain 3 - Vulnerability discovery and analysis (17%)
Finding candidate weaknesses and judging which ones are real and which matter.
- Scan types and configuration: credentialed versus non-credentialed, agent-based versus network-based, intensity and safety settings.
- Specialist scanning: web application, API, container and image, cloud configuration and wireless assessment.
- Validation: confirming findings manually, and distinguishing false positives from false negatives.
- Analysis without a scanner: configuration review against a baseline, static and dynamic application analysis, dependency and supply-chain review, and business-logic flaws.
- Prioritisation: using CVE identifiers and CVSS severity as inputs, then ranking by exposure, asset value, data sensitivity, practical exploitability and compensating controls.
Domain 4 - Attacks and exploits (35%)
The largest domain, organised by attack surface. The exam asks which category of technique fits a described target, what it would achieve, how it is detected and how it is prevented.
- Network attack concepts: abuse of name and address resolution, on-path positions, relay and replay of authentication material, legacy and plaintext protocol exposure.
- Host attack concepts: credential attacks, over-permissive service and task configuration, unpatched components, misuse of legitimate administrative tooling.
- Web application attacks: injection, cross-site scripting, broken authentication and session handling, broken access control, server-side request forgery, insecure deserialisation, file upload weaknesses and security misconfiguration.
- API attacks: missing object-level authorisation, excessive data exposure, absent rate limiting, forgotten or undocumented endpoints.
- Wireless and physical: rogue and evil-twin access points, weak encryption standards, enterprise authentication attacks; tailgating, unattended workstations and visitor-control failures.
- Social engineering: phishing and its variants, pretexting and impersonation, and the written authorisation that must precede any of it.
- Cloud, container and IoT: over-permissive identity policies, exposed storage and metadata, vulnerable base images, secrets in images, over-privileged containers, default and hardcoded device credentials, and unpatchable firmware.
- Technique selection: choosing the approach that answers the client’s question within scope, proves the finding with the least impact, and produces defensible evidence.
Domain 5 - Post-exploitation and lateral movement (14%)
What a professional does after gaining a foothold, including the part amateurs skip.
- Establishing and maintaining access: persistence concepts, and why every mechanism must be agreed and recorded.
- Privilege escalation: vertical versus horizontal, and the usual conceptual routes.
- Lateral movement and pivoting: reusing trust relationships to reach further systems, and routing through a compromised host to reach an otherwise unreachable segment.
- Data handling: staging and exfiltration concepts, minimum-necessary extraction, encrypted storage and destruction at engagement close.
- Detection avoidance: why some activity blends into normal administration, and why the client benefits from knowing whether anyone noticed.
- Cleanup: removing accounts, tools, files, tasks and configuration changes, restoring the original state, and documenting everything removed.
Format and passing standard
| Item | Detail |
|---|---|
| Questions | Up to 90 |
| Question types | Multiple choice plus performance-based questions |
| Time | 165 minutes |
| Passing score | 750 on a scale of 100-900 |
| Languages | English, French, Japanese, Portuguese |
| Delivery | Pearson VUE test centre or OnVUE online proctoring |
CompTIA does not publish pass rates for its exams, so the passing score above is the only official standard to plan against.