EnglishDeutschFrançaisEspañolPortuguês

CompTIA · COMPTIA-PENTEST · Advanced

CompTIA PenTest+ — Practice Questions and Mock Exam

Practice real COMPTIA-PENTEST questions, never dumps. Alex explains every answer, and your readiness score tells you when you're ready to pass.

85Questions
165minTime Limit
750/ 900Pass Score

Checked against CompTIA · July 2026Current exam version

About the exam

CompTIA PenTest+ (PT0-003) validates the skills required to plan, scope, and perform penetration tests, analyze findings, and effectively communicate results to stakeholders. It covers the full penetration testing lifecycle including reconnaissance, enumeration, vulnerability discovery, exploitation, post-exploitation, and lateral movement across traditional, cloud, hybrid, web application, API, and IoT environments.

The PT0-003 version launched December 17, 2024, adding coverage for AI-based attacks, expanded cloud and API exploitation, modern post-exploitation techniques, and updated tooling. It is the only certification focused specifically on penetration testing with a hands-on, performance-based approach.

PenTest+ is considered intermediate-level, positioned above Security+ and complementary to CySA+ (which focuses on defensive security). It is recommended for professionals with 3-4 years of hands-on penetration testing experience.

What's on the exam

The exam consists of a maximum of 90 questions to be completed in 165 minutes. Questions include both multiple-choice and performance-based (simulation) items. Performance-based questions require candidates to solve problems in simulated environments, such as executing commands, analyzing tool output, or configuring exploits.

Engagement Management13%
Reconnaissance and Enumeration21%
Vulnerability Discovery and Analysis17%
Attacks and Exploits35%
Post-exploitation and Lateral Movement14%

SourceCompTIA exam page

What to expect

Multiple-choice questions include both single-answer and multiple-response formats. Some questions may present scenarios requiring analysis of network diagrams, log outputs, or tool results. Drag-and-drop questions test the ability to sequence attack phases or match techniques to scenarios.

The passing score is 750 on a scale of 100-900. Questions are weighted differently, with performance-based questions typically carrying more weight than standard multiple-choice items.

Multiple Choice60%
Command Line20%
Drag & Drop10%
Multiple Response10%

Try it now

Practice real COMPTIA-PENTEST questions

Five sample questions from our CompTIA PenTest+ bank. Answer one — Alex, your AI tutor, explains the why. Real prep, never dumps.

Where candidates struggle

Common pitfalls for PenTest+ candidates include:

1. Neglecting engagement management: Many candidates focus heavily on technical exploitation while underestimating the importance of scoping, rules of engagement, legal considerations, and compliance requirements. Domain 1 (Engagement Management) and reporting are frequently underestimated.

2. Tool familiarity without understanding: Knowing tool names (Nmap, Burp Suite, Metasploit) without understanding what the output means or when to use each tool. The exam tests applied knowledge, not just recognition.

3. Skipping the methodology: Jumping straight to exploitation without proper reconnaissance and enumeration. The exam follows a structured penetration testing methodology and expects candidates to understand why each phase matters.

4. Confusing vulnerability scanning with penetration testing: Understanding the difference between automated vulnerability assessment and manual penetration testing is critical.

5. Weak reporting skills: The exam tests your ability to communicate findings, write executive summaries, and recommend remediation. Technical skills alone are insufficient.

6. Overlooking cloud and API testing: PT0-003 expanded coverage of cloud environments, API testing, and modern attack surfaces. Candidates who only prepare for traditional network pentesting will struggle.

  1. 01
    Engagement Scoping — Underestimating rules of engagement, legal requirements, and proper scoping documentation
  2. 02
    Tool Output Analysis — Knowing tool names but not understanding how to interpret their output or when to use them
  3. 03
    Methodology Shortcuts — Jumping to exploitation without proper reconnaissance and enumeration phases
  4. 04
    Vuln Scan vs Pentest — Confusing automated vulnerability scanning with manual penetration testing
  5. 05
    Reporting Skills — Weak executive summaries, missing remediation recommendations, poor finding communication
  6. 06
    Cloud and API Testing — Only preparing for traditional network pentesting and neglecting cloud, API, and IoT attack surfaces
  7. 07
    Post-exploitation — Not understanding lateral movement, persistence, and data exfiltration techniques

Exam logistics

CompTIA PenTest+ PT0-003 is delivered through Pearson VUE testing centers worldwide or via online proctoring from home or office. The exam is available in English, French, Japanese, and Portuguese.

The exam voucher costs approximately $404 USD (pricing may vary by region). Candidates must pay the full exam fee for each attempt. CompTIA does not offer free retests or discounts on retakes.

No formal prerequisites are required, but CompTIA recommends Network+ and Security+ certifications or equivalent knowledge, plus 3-4 years of hands-on penetration testing experience.

The certification is valid for three years from the date earned. Renewal requires earning 60 Continuing Education Units (CEUs) within the three-year cycle, plus paying the annual CE fee. CEUs can be earned through training courses, industry conferences, teaching, publishing, and other approved activities. Alternatively, passing a higher-level CompTIA certification automatically renews PenTest+.

Exam fee$425 USD
DeliveryPearson VUE (testing center or online proctored)
Retake policyNo wait after first failure. 14-day wait required after second and subsequent failures. Full exam fee required each attempt.
Validity3 years
CE credits60
Career outcomesPenetration tester, security consultant, vulnerability analyst, red team operator, application security tester, security engineer
Renewal60 CEUs within 3-year cycle plus annual CE fee, or pass a higher-level CompTIA certification
Study time~120 hours
Official guideView on vendor site

SourceCompTIA exam page

Before you book the exam

Would you pass COMPTIA-PENTEST today?

Take the free readiness check. Answer real COMPTIA-PENTEST questions and get your readiness score across every domain.

Take the free readiness check20 questions · free

Reach 80% readiness by exam day. Pass, or your money back.

Ready to commit? Own COMPTIA-PENTEST for $29.99 →