CompTIA · COMPTIA-PENTEST · Advanced
CompTIA PenTest+ — Practice Questions and Mock Exam
Practice real COMPTIA-PENTEST questions, never dumps. Alex explains every answer, and your readiness score tells you when you're ready to pass.
Checked against CompTIA · July 2026Current exam version
Overview
About the exam
CompTIA PenTest+ (PT0-003) validates the skills required to plan, scope, and perform penetration tests, analyze findings, and effectively communicate results to stakeholders. It covers the full penetration testing lifecycle including reconnaissance, enumeration, vulnerability discovery, exploitation, post-exploitation, and lateral movement across traditional, cloud, hybrid, web application, API, and IoT environments.
The PT0-003 version launched December 17, 2024, adding coverage for AI-based attacks, expanded cloud and API exploitation, modern post-exploitation techniques, and updated tooling. It is the only certification focused specifically on penetration testing with a hands-on, performance-based approach.
PenTest+ is considered intermediate-level, positioned above Security+ and complementary to CySA+ (which focuses on defensive security). It is recommended for professionals with 3-4 years of hands-on penetration testing experience.
Exam Domains
What's on the exam
The exam consists of a maximum of 90 questions to be completed in 165 minutes. Questions include both multiple-choice and performance-based (simulation) items. Performance-based questions require candidates to solve problems in simulated environments, such as executing commands, analyzing tool output, or configuring exploits.
SourceCompTIA exam page
Format
What to expect
Multiple-choice questions include both single-answer and multiple-response formats. Some questions may present scenarios requiring analysis of network diagrams, log outputs, or tool results. Drag-and-drop questions test the ability to sequence attack phases or match techniques to scenarios.
The passing score is 750 on a scale of 100-900. Questions are weighted differently, with performance-based questions typically carrying more weight than standard multiple-choice items.
Watch out
Where candidates struggle
Common pitfalls for PenTest+ candidates include:
1. Neglecting engagement management: Many candidates focus heavily on technical exploitation while underestimating the importance of scoping, rules of engagement, legal considerations, and compliance requirements. Domain 1 (Engagement Management) and reporting are frequently underestimated.
2. Tool familiarity without understanding: Knowing tool names (Nmap, Burp Suite, Metasploit) without understanding what the output means or when to use each tool. The exam tests applied knowledge, not just recognition.
3. Skipping the methodology: Jumping straight to exploitation without proper reconnaissance and enumeration. The exam follows a structured penetration testing methodology and expects candidates to understand why each phase matters.
4. Confusing vulnerability scanning with penetration testing: Understanding the difference between automated vulnerability assessment and manual penetration testing is critical.
5. Weak reporting skills: The exam tests your ability to communicate findings, write executive summaries, and recommend remediation. Technical skills alone are insufficient.
6. Overlooking cloud and API testing: PT0-003 expanded coverage of cloud environments, API testing, and modern attack surfaces. Candidates who only prepare for traditional network pentesting will struggle.
- 01Engagement Scoping — Underestimating rules of engagement, legal requirements, and proper scoping documentation
- 02Tool Output Analysis — Knowing tool names but not understanding how to interpret their output or when to use them
- 03Methodology Shortcuts — Jumping to exploitation without proper reconnaissance and enumeration phases
- 04Vuln Scan vs Pentest — Confusing automated vulnerability scanning with manual penetration testing
- 05Reporting Skills — Weak executive summaries, missing remediation recommendations, poor finding communication
- 06Cloud and API Testing — Only preparing for traditional network pentesting and neglecting cloud, API, and IoT attack surfaces
- 07Post-exploitation — Not understanding lateral movement, persistence, and data exfiltration techniques
Details
Exam logistics
CompTIA PenTest+ PT0-003 is delivered through Pearson VUE testing centers worldwide or via online proctoring from home or office. The exam is available in English, French, Japanese, and Portuguese.
The exam voucher costs approximately $404 USD (pricing may vary by region). Candidates must pay the full exam fee for each attempt. CompTIA does not offer free retests or discounts on retakes.
No formal prerequisites are required, but CompTIA recommends Network+ and Security+ certifications or equivalent knowledge, plus 3-4 years of hands-on penetration testing experience.
The certification is valid for three years from the date earned. Renewal requires earning 60 Continuing Education Units (CEUs) within the three-year cycle, plus paying the annual CE fee. CEUs can be earned through training courses, industry conferences, teaching, publishing, and other approved activities. Alternatively, passing a higher-level CompTIA certification automatically renews PenTest+.
SourceCompTIA exam page
Before you book the exam
Would you pass COMPTIA-PENTEST today?
Take the free readiness check. Answer real COMPTIA-PENTEST questions and get your readiness score across every domain.
Take the free readiness check20 questions · freeReach 80% readiness by exam day. Pass, or your money back.