Syllabus · Cybersecurity

CompTIA PenTest+ (PT0-003) Exam Objectives Explained

intermediate

All five CompTIA PenTest+ (PT0-003) domains explained in plain English with official weights, plus format, timing and what to focus on. Source-checked.

By The Exam Atlas Editorial Team · Verified 2026-08-05

CompTIA PenTest+ (PT0-003) has five domains: Engagement management (13%), Reconnaissance and enumeration (21%), Vulnerability discovery and analysis (17%), Attacks and exploits (35%), and Post-exploitation and lateral movement (14%), tested through up to 90 multiple-choice and performance-based questions in 165 minutes.

The weights below are CompTIA’s official PT0-003 figures. This page explains in plain English what each domain covers so you can plan your study; the official objectives PDF on CompTIA’s certification page is the authoritative document and should be your final checklist.

The five domains at a glance

#DomainWeight
1Engagement management13%
2Reconnaissance and enumeration21%
3Vulnerability discovery and analysis17%
4Attacks and exploits35%
5Post-exploitation and lateral movement14%
Total100%

A planning note most candidates miss: attacks and exploits is the biggest single domain, but domains 1, 2 and 5 together are 48% of the exam. PenTest+ is a methodology certification, and the process content is where prepared candidates gain their margin.

Domain 1 - Engagement management (13%)

Everything around the testing, from first conversation to signed-off report.

  • Pre-engagement and scoping: defining targets, permitted techniques, testing windows, and what is explicitly out of scope.
  • Governing documents: rules of engagement, statement of work, master service agreement, non-disclosure agreement.
  • Authorisation: written permission from someone empowered to give it, plus third-party approval where assets are hosted or managed by another provider.
  • Legal, regulatory and compliance considerations: privacy law, regulated data such as payment card and health information, and cross-border constraints.
  • Testing models: known-environment, partially known and unknown-environment testing, and the threat model being simulated.
  • Collaboration and communication: de-confliction with the defensive team, escalation contacts, stop conditions, and what triggers immediate notification.
  • Reporting: executive summary, methodology, findings with evidence and risk ratings, remediation guidance, attestation of findings, and retesting.

Domain 2 - Reconnaissance and enumeration (21%)

Turning a target definition into a precise map of the attack surface.

  • Passive reconnaissance: public records, certificate transparency data, document metadata, job adverts, code repositories and other open-source intelligence.
  • Active reconnaissance: probing that sends traffic to the target, which is detectable and legitimate only inside the agreed scope and window.
  • Host and service enumeration: identifying live systems, listening services and software versions.
  • Resource enumeration: shares, files, users, groups, directory and domain structure.
  • Application and API enumeration: site content, endpoints, methods and undocumented interfaces.
  • Cloud and wireless discovery: storage, functions and identity configuration; wireless networks and their authentication.
  • Scripting and automation: recognising what a reconnaissance script or automated workflow is doing and what its output means.

Domain 3 - Vulnerability discovery and analysis (17%)

Finding candidate weaknesses and judging which ones are real and which matter.

  • Scan types and configuration: credentialed versus non-credentialed, agent-based versus network-based, intensity and safety settings.
  • Specialist scanning: web application, API, container and image, cloud configuration and wireless assessment.
  • Validation: confirming findings manually, and distinguishing false positives from false negatives.
  • Analysis without a scanner: configuration review against a baseline, static and dynamic application analysis, dependency and supply-chain review, and business-logic flaws.
  • Prioritisation: using CVE identifiers and CVSS severity as inputs, then ranking by exposure, asset value, data sensitivity, practical exploitability and compensating controls.

Domain 4 - Attacks and exploits (35%)

The largest domain, organised by attack surface. The exam asks which category of technique fits a described target, what it would achieve, how it is detected and how it is prevented.

  • Network attack concepts: abuse of name and address resolution, on-path positions, relay and replay of authentication material, legacy and plaintext protocol exposure.
  • Host attack concepts: credential attacks, over-permissive service and task configuration, unpatched components, misuse of legitimate administrative tooling.
  • Web application attacks: injection, cross-site scripting, broken authentication and session handling, broken access control, server-side request forgery, insecure deserialisation, file upload weaknesses and security misconfiguration.
  • API attacks: missing object-level authorisation, excessive data exposure, absent rate limiting, forgotten or undocumented endpoints.
  • Wireless and physical: rogue and evil-twin access points, weak encryption standards, enterprise authentication attacks; tailgating, unattended workstations and visitor-control failures.
  • Social engineering: phishing and its variants, pretexting and impersonation, and the written authorisation that must precede any of it.
  • Cloud, container and IoT: over-permissive identity policies, exposed storage and metadata, vulnerable base images, secrets in images, over-privileged containers, default and hardcoded device credentials, and unpatchable firmware.
  • Technique selection: choosing the approach that answers the client’s question within scope, proves the finding with the least impact, and produces defensible evidence.

Domain 5 - Post-exploitation and lateral movement (14%)

What a professional does after gaining a foothold, including the part amateurs skip.

  • Establishing and maintaining access: persistence concepts, and why every mechanism must be agreed and recorded.
  • Privilege escalation: vertical versus horizontal, and the usual conceptual routes.
  • Lateral movement and pivoting: reusing trust relationships to reach further systems, and routing through a compromised host to reach an otherwise unreachable segment.
  • Data handling: staging and exfiltration concepts, minimum-necessary extraction, encrypted storage and destruction at engagement close.
  • Detection avoidance: why some activity blends into normal administration, and why the client benefits from knowing whether anyone noticed.
  • Cleanup: removing accounts, tools, files, tasks and configuration changes, restoring the original state, and documenting everything removed.

Format and passing standard

ItemDetail
QuestionsUp to 90
Question typesMultiple choice plus performance-based questions
Time165 minutes
Passing score750 on a scale of 100-900
LanguagesEnglish, French, Japanese, Portuguese
DeliveryPearson VUE test centre or OnVUE online proctoring

CompTIA does not publish pass rates for its exams, so the passing score above is the only official standard to plan against.

FAQ

How many domains are in CompTIA PenTest+ PT0-003?
Five: Engagement management (13%), Reconnaissance and enumeration (21%), Vulnerability discovery and analysis (17%), Attacks and exploits (35%), and Post-exploitation and lateral movement (14%). Attacks and exploits is the largest single domain, but the three process-focused domains together make up 48% of the exam.
Where do I get the official PT0-003 exam objectives?
From the Resources section of CompTIA's PenTest+ certification page, where the objectives PDF is a free download. This page is a plain-English summary to help you plan; the official document is authoritative and should be your final checklist.
Did the domains change between PT0-002 and PT0-003?
Yes. PT0-003 launched on 17 December 2024 with a reorganised set of five domains, and PT0-002 retired on 17 June 2025. Study material written for PT0-002 does not map cleanly onto the current structure, so check the exam code before you buy anything.

Sources