CompTIA PenTest+
PenTest+ covers the penetration testing engagement end to end: scoping and legal agreements, reconnaissance, exploitation, post-exploitation, and the report that is the actual deliverable.
Two and three quarter hours, 750 needed, mixing simulated tasks with written questions.
Exam facts
- Exam code
- PT0-003
- Level
- Professional
- Field
- Cybersecurity
- Duration
- 165 minutes
- Questions
- maximum of 90 (multiple choice and performance-based items)
- Passing score
- 750 on a scale of 100 to 900
- Languages
- English, French, Japanese, Portuguese
- Price
- 439 USD (read 8 September 2026)
- Validity
- 3 years, renewable
- Exam delivery
- Pearson VUE (test centre or online proctored)
Prerequisites: No formal prerequisites. CompTIA recommends three to four years of penetration-testing experience plus Network+ and Security+ or equivalent knowledge.
Renewal: Continuing Education: 60 CEUs within three years, or pass the current PenTest+ exam
Source: exam page at CompTIA · Price: CompTIA list price since the June 2026 price round (partner price list, read 2026-09-08); CompTIA shows your local price in its purchase widget
How to prepare
1. A practice test in the exam format
MeasureUp sells a practice test for PT0-003 with questions in the exam format, an explanation for every answer and a timed mode; the price shows in your currency on the shop page. Affiliate link.
Practice test for PT0-003 at MeasureUp (opens in a new tab)Book the exam
Delivered by Pearson VUE (test centre or online proctored). Schedule with CompTIA (opens in a new tab)
Affiliate disclosure: the practice-test link above is affiliate links — buying through them may earn us a commission at no extra cost to you. The vendor's learning path and booking links carry no commission.
The tension nobody selling it mentions
Penetration testing is judged on whether you got in and could explain how. PenTest+ is a written exam, up to 90 questions in 165 minutes with a pass mark of 750 on a scale of 100 to 900, and no written exam can measure the first half of that. Working testers say so, often bluntly. Employers outside specialist consultancies use it as a filter anyway, and defensive and audit roles value the structured knowledge it certifies. Both positions are right about different jobs, and the useful question is which job you are applying for.
Five domains, and the biggest is not the one that matters most
- Attacks and exploits is the largest domain by a wide margin, and it is the one self-taught candidates arrive knowing.
- Reconnaissance and enumeration and vulnerability discovery and analysis together are a similar size, and they are examined as method rather than as tool trivia.
- Engagement management is the smallest domain and the one that decides careers: scope, authorisation, rules of engagement, and the report.
- Post-exploitation and lateral movement rounds out the paper and is where the performance-based items tend to sit.
| Candidate | Comes in strong on | Loses marks on |
|---|---|---|
| Self-taught on practical labs | Attacks, enumeration | Scope, authorisation, reporting |
| Working tester | Everything technical | Process, as the exam frames it |
| Defender or auditor | Reporting, governance | Exploitation detail |
| Fresh from Security+ | Vocabulary | Depth everywhere; sit Network+ first |
Where this paper is genuinely good
The unglamorous half. Scoping, rules of engagement, written authorisation, handling findings responsibly and writing a report the client can act on carry real weight here, and they are the parts self-taught candidates skip entirely. A tester who cannot scope an engagement or write a usable finding is unemployable regardless of technical skill, and this syllabus takes that seriously. The current exam, PT0-003, replaced a previous version that retired on 17 June 2025, and the languages are English, French, Japanese and Portuguese.
CompTIA recommends three or four years as a penetration tester with Network+ and Security+ or equivalent knowledge, which describes a working professional rather than a beginner. Read that as a statement about who passes comfortably, not about who may sit it. The certificate lasts three years; 60 continuing-education credits or a fresh pass keep it current, and holding it refreshes Security+ and the rungs beneath, which is the sensible way to keep the lower rungs current if you intend to keep this one.
A written exam for a discipline judged on practical work
Working testers are frequently dismissive of this certificate, and the objection is coherent: offensive security is judged on whether you got in and could explain how, which a written paper cannot measure. Hiring managers outside specialist consultancies do use it as a filter, and defensive and audit roles value the structured knowledge. Both positions are right about different jobs, and the useful question is which job you are applying for.
What a question looks like
Written by us in the exam's style. It is not a real question from any question bank, and we do not publish those.
During an authorised test you discover credentials that also grant access to a system belonging to a different company, outside the scope of your engagement. The finding is significant. What is the correct next action?
Every technically-minded answer is wrong and one of them is very tempting. The exam is testing whether you understand that authorisation is the boundary of the work and that a discovery outside it becomes a disclosure question rather than an access opportunity. Candidates who prepared on practical labs rather than on engagement conduct reliably misjudge this class of question.
What it costs to get and to keep
| Item | Amount | Note |
|---|---|---|
| Exam fee | 439 USD | partner price list after CompTIA's June 2026 price round; prices appear only inside the vendor's purchase widget, by country (read 8 September 2026) |
| Renewal every three years | not published | 60 continuing-education credits, or passing the current PenTest+ exam again. Holding it renews Security+ and the certificates beneath (read 12 September 2026) |
How much preparation, from where you are
- You already test professionally
- The technical domains will be straightforward and the exam will still surprise you on process. Read the scoping, legal and reporting objectives properly; they carry more weight than practitioners expect.
- You work in defence and want to understand attacks
- A strong reason to sit it, and arguably a better one than becoming a tester. Understanding how an engagement is structured makes you considerably better at reading the report when one lands on your desk.
- You are self-taught on practical labs
- Your technical half is probably ahead of the syllabus and your professional half is missing entirely. Authorisation, scope and client communication are the sections to study, and they are the ones that make the difference in employment.
What passing this does not prove
- Whether you can actually compromise anything, which is what the work consists of.
- Creativity under constraint, which separates competent testers from good ones.
- Whether your report would be understood by the person who has to act on it.
- Tool fluency, deliberately, which is why practitioners discount it and employers do not.
Against the alternatives
- 312-50 — Certified Ethical Hacker (CEH)
- Similar in shape and similarly contested, with wider recruiter and public-sector recognition. Neither is respected by practitioners in the way a practical, reported engagement is.
- CS0-004 — CompTIA CySA+
- The defensive counterpart at the same tier, with far more seats behind it. If you are choosing on employability rather than interest, that is the honest recommendation.
- SY0-701 — CompTIA Security+
- The entry certificate beneath, assumed by this one. Passing this renews it automatically.
PT0-003 — quick answers
Does it open the door to testing work?
By itself, rarely. Specialist consultancies hire on demonstrated practical work, and a written certificate does not substitute for that. It does get CVs past generalist filters, and it is genuinely useful for defensive, audit and consulting roles where understanding an engagement matters more than running one.
How does it compare with a practical exam?
A practical exam that puts you on live machines and requires a written report measures the thing employers care about, and takes a much harder day to pass. This certificate measures structured knowledge of the discipline, including the professional conduct a lab never teaches. They answer different questions about a candidate.
Why does scoping matter so much on the exam?
Because it matters that much in the work. Authorisation is the only thing separating a penetration test from an offence, and testers who are casual about scope end conversations with lawyers. Self-taught candidates skip this material and it is the part employers most need them to have.
Is 165 minutes enough?
For most candidates, comfortably, provided the performance-based items are budgeted for. They can each absorb several minutes, so take the multiple-choice questions first, flag doubts, and return to the simulations with the remaining time rather than meeting them cold at the start.
Do I need Security+ before this?
Not formally. CompTIA recommends it along with Network+ and several years of testing, and the recommendation is about comfort rather than eligibility. Candidates arriving from practical labs without the networking layer find the enumeration and lateral-movement questions harder than they expect, for reasons that have nothing to do with exploitation.
What comes next
Concepts this exam draws on
Glossary entries with the reason each one matters for PT0-003.
- SSL/TLS
Attacks on transport security and certificate misuse are exploitation topics.
- Web Server
Web application and server attacks carry the largest exam weight.
- Penetration Testing
The exam is this concept in written form: engagement management, reconnaissance, exploitation, reporting.
- Vulnerability Management
Vulnerability discovery and analysis is a domain of its own.
- Phishing
Social engineering attacks are examined within attacks and exploits.
- Encryption
Weak cryptography and its exploitation appear in the attacks domain.
Last reviewed 12 September 2026 · Getting Digital
