PenTest+ Practice Exams
PT0-003The intermediate, hands-on penetration testing and vulnerability assessment certification. Validates the skills to plan and scope engagements, gather information and scan for vulnerabilities, exploit and pivot through systems and applications, use core pentesting tools, and report findings — the offensive (red-team) counterpart to CySA+.
Start preparing today
5 flashcard sets · 5 learning tests · 2 timed exams · 90-question bank
Overview
What this certification is and how the exam works.
CompTIA PenTest+ (PT0-003) is the intermediate-level certification for penetration testers and vulnerability assessment professionals. The exam covers five domains: General/Pre-Engagement (13% — governance, legal considerations, scoping, and rules of engagement), Information Gathering and Vulnerability Scanning (21% — reconnaissance techniques, scanning tools, and vulnerability analysis/prioritization), Attacks and Exploits (30% — exploiting network, application, wireless, cloud, and physical/social attack vectors, plus post-exploitation and lateral movement), Reporting and Communication (16% — writing findings, risk ratings, remediation guidance, and stakeholder communication), and Tools and Code Analysis (20% — using and scripting with core pentesting tools, and analyzing exploit/attack code). The exam has a maximum of 85 performance-based and multiple-choice questions in 165 minutes, with a passing score of 750 on a 100–900 scale. CompTIA recommends Network+, Security+, and 3–4 years of hands-on information security experience.
Why should I take the exam?
What this credential does for your career.
- 1The natural red-team step after Security+ — focused on hands-on offensive security and vulnerability assessment
- 2Heavily performance-based: scoping, scanning, exploitation, and reporting, not just multiple choice
- 3Vendor-neutral and widely recognized alongside OSCP as an entry point into professional penetration testing
- 4Maps directly to in-demand roles: penetration tester, vulnerability analyst, and red-team associate
Skills measured
What you need to know to pass this exam.
- ✓Plan and scope a penetration test: rules of engagement, legal considerations, and compliance requirements
- ✓Perform reconnaissance and information gathering using OSINT and active/passive techniques
- ✓Run and interpret vulnerability scans, prioritizing findings by risk and exploitability
- ✓Exploit network, wireless, and physical/social attack vectors to gain initial access
- ✓Exploit web application vulnerabilities: injection, authentication bypass, and business-logic flaws
- ✓Exploit cloud, container, and specialized system (ICS/IoT/mobile) weaknesses
- ✓Perform post-exploitation: privilege escalation, lateral movement, persistence, and pivoting
- ✓Use core pentesting tools (Nmap, Metasploit, Burp Suite, and others) and read/modify basic exploit scripts
- ✓Analyze and adapt scripts in Bash, Python, and PowerShell to support engagement tasks
- ✓Write clear penetration test reports: findings, risk ratings, remediation recommendations, and executive summaries
- ✓Communicate findings effectively to both technical and non-technical stakeholders
Prerequisites
Credentials required before you can earn this certification.
About our PT0-003 practice exams
Our PenTest+ PT0-003 question bank holds 90 exam-style questions with a written explanation on every answer, mapped to the five exam domains published for PT0-003, covering General/Pre-Engagement, Information Gathering and Vulnerability Scanning, Attacks and Exploits, Reporting and Communication and Tools and Code Analysis.
Alongside the bank there are two full-length timed exams at the real 165-minute limit and 83% pass mark, plus five topic-based learning tests for working a single domain at a time. Randomised mock exams are dealt on demand from the full 90-question pool, so you never run out of fresh papers.
- Questions
- 90
- Exam domains
- 5
- Timed exams
- 2
- Pass mark
- 83%
How our practice content is created
Practice questions are independently developed using the official CompTIA PT0-003 exam guide and CompTIA documentation. Each question is checked for alignment with the current exam objectives and reviewed for technical accuracy before publication.
The PT0-003 bank cites 1 distinct CompTIA documentation page, and every question links the source it was written against — so you can check any answer at first hand.
Official PT0-003 exam guideCompTIA is a trademark of its respective owner. This is an independent study resource and is not affiliated with, endorsed by, or authorised by CompTIA.
Related certifications
Credentials that pair well with this exam or come next on the path.
Official resources
Provider documentation and study material for this exam.
Previous exam versions
Old or retired versions of this certification exam.
| Exam name | Code | Retired |
|---|---|---|
| PenTest+ | PT0-002 | 2024 |
5 flashcard sets · 5 learning tests · 2 timed exams · 90-question bank