Skip to content
Getting Digital
CompTIA certificationsCompTIA · exam PT0-003

CompTIA PenTest+

PenTest+ covers the penetration testing engagement end to end: scoping and legal agreements, reconnaissance, exploitation, post-exploitation, and the report that is the actual deliverable.

Two and three quarter hours, 750 needed, mixing simulated tasks with written questions.

Exam facts

Exam code
PT0-003
Level
Professional
Field
Cybersecurity
Duration
165 minutes
Questions
maximum of 90 (multiple choice and performance-based items)
Passing score
750 on a scale of 100 to 900
Languages
English, French, Japanese, Portuguese
Price
439 USD (read 8 September 2026)
Validity
3 years, renewable
Exam delivery
Pearson VUE (test centre or online proctored)

Prerequisites: No formal prerequisites. CompTIA recommends three to four years of penetration-testing experience plus Network+ and Security+ or equivalent knowledge.

Renewal: Continuing Education: 60 CEUs within three years, or pass the current PenTest+ exam

Source: exam page at CompTIA · Price: CompTIA list price since the June 2026 price round (partner price list, read 2026-09-08); CompTIA shows your local price in its purchase widget

How to prepare

  1. 1. A practice test in the exam format

    MeasureUp sells a practice test for PT0-003 with questions in the exam format, an explanation for every answer and a timed mode; the price shows in your currency on the shop page. Affiliate link.

    Practice test for PT0-003 at MeasureUp (opens in a new tab)
  2. Book the exam

    Delivered by Pearson VUE (test centre or online proctored). Schedule with CompTIA (opens in a new tab)

Affiliate disclosure: the practice-test link above is affiliate links — buying through them may earn us a commission at no extra cost to you. The vendor's learning path and booking links carry no commission.

The tension nobody selling it mentions

Penetration testing is judged on whether you got in and could explain how. PenTest+ is a written exam, up to 90 questions in 165 minutes with a pass mark of 750 on a scale of 100 to 900, and no written exam can measure the first half of that. Working testers say so, often bluntly. Employers outside specialist consultancies use it as a filter anyway, and defensive and audit roles value the structured knowledge it certifies. Both positions are right about different jobs, and the useful question is which job you are applying for.

Five domains, and the biggest is not the one that matters most

  • Attacks and exploits is the largest domain by a wide margin, and it is the one self-taught candidates arrive knowing.
  • Reconnaissance and enumeration and vulnerability discovery and analysis together are a similar size, and they are examined as method rather than as tool trivia.
  • Engagement management is the smallest domain and the one that decides careers: scope, authorisation, rules of engagement, and the report.
  • Post-exploitation and lateral movement rounds out the paper and is where the performance-based items tend to sit.
CandidateComes in strong onLoses marks on
Self-taught on practical labsAttacks, enumerationScope, authorisation, reporting
Working testerEverything technicalProcess, as the exam frames it
Defender or auditorReporting, governanceExploitation detail
Fresh from Security+VocabularyDepth everywhere; sit Network+ first

Where this paper is genuinely good

The unglamorous half. Scoping, rules of engagement, written authorisation, handling findings responsibly and writing a report the client can act on carry real weight here, and they are the parts self-taught candidates skip entirely. A tester who cannot scope an engagement or write a usable finding is unemployable regardless of technical skill, and this syllabus takes that seriously. The current exam, PT0-003, replaced a previous version that retired on 17 June 2025, and the languages are English, French, Japanese and Portuguese.

CompTIA recommends three or four years as a penetration tester with Network+ and Security+ or equivalent knowledge, which describes a working professional rather than a beginner. Read that as a statement about who passes comfortably, not about who may sit it. The certificate lasts three years; 60 continuing-education credits or a fresh pass keep it current, and holding it refreshes Security+ and the rungs beneath, which is the sensible way to keep the lower rungs current if you intend to keep this one.

A written exam for a discipline judged on practical work

Working testers are frequently dismissive of this certificate, and the objection is coherent: offensive security is judged on whether you got in and could explain how, which a written paper cannot measure. Hiring managers outside specialist consultancies do use it as a filter, and defensive and audit roles value the structured knowledge. Both positions are right about different jobs, and the useful question is which job you are applying for.

What a question looks like

Written by us in the exam's style. It is not a real question from any question bank, and we do not publish those.

During an authorised test you discover credentials that also grant access to a system belonging to a different company, outside the scope of your engagement. The finding is significant. What is the correct next action?

Every technically-minded answer is wrong and one of them is very tempting. The exam is testing whether you understand that authorisation is the boundary of the work and that a discovery outside it becomes a disclosure question rather than an access opportunity. Candidates who prepared on practical labs rather than on engagement conduct reliably misjudge this class of question.

What it costs to get and to keep

ItemAmountNote
Exam fee439 USDpartner price list after CompTIA's June 2026 price round; prices appear only inside the vendor's purchase widget, by country (read 8 September 2026)
Renewal every three yearsnot published60 continuing-education credits, or passing the current PenTest+ exam again. Holding it renews Security+ and the certificates beneath (read 12 September 2026)

How much preparation, from where you are

You already test professionally
The technical domains will be straightforward and the exam will still surprise you on process. Read the scoping, legal and reporting objectives properly; they carry more weight than practitioners expect.
You work in defence and want to understand attacks
A strong reason to sit it, and arguably a better one than becoming a tester. Understanding how an engagement is structured makes you considerably better at reading the report when one lands on your desk.
You are self-taught on practical labs
Your technical half is probably ahead of the syllabus and your professional half is missing entirely. Authorisation, scope and client communication are the sections to study, and they are the ones that make the difference in employment.

What passing this does not prove

  • Whether you can actually compromise anything, which is what the work consists of.
  • Creativity under constraint, which separates competent testers from good ones.
  • Whether your report would be understood by the person who has to act on it.
  • Tool fluency, deliberately, which is why practitioners discount it and employers do not.

Against the alternatives

312-50Certified Ethical Hacker (CEH)
Similar in shape and similarly contested, with wider recruiter and public-sector recognition. Neither is respected by practitioners in the way a practical, reported engagement is.
CS0-004CompTIA CySA+
The defensive counterpart at the same tier, with far more seats behind it. If you are choosing on employability rather than interest, that is the honest recommendation.
SY0-701CompTIA Security+
The entry certificate beneath, assumed by this one. Passing this renews it automatically.

PT0-003 — quick answers

Does it open the door to testing work?

By itself, rarely. Specialist consultancies hire on demonstrated practical work, and a written certificate does not substitute for that. It does get CVs past generalist filters, and it is genuinely useful for defensive, audit and consulting roles where understanding an engagement matters more than running one.

How does it compare with a practical exam?

A practical exam that puts you on live machines and requires a written report measures the thing employers care about, and takes a much harder day to pass. This certificate measures structured knowledge of the discipline, including the professional conduct a lab never teaches. They answer different questions about a candidate.

Why does scoping matter so much on the exam?

Because it matters that much in the work. Authorisation is the only thing separating a penetration test from an offence, and testers who are casual about scope end conversations with lawyers. Self-taught candidates skip this material and it is the part employers most need them to have.

Is 165 minutes enough?

For most candidates, comfortably, provided the performance-based items are budgeted for. They can each absorb several minutes, so take the multiple-choice questions first, flag doubts, and return to the simulations with the remaining time rather than meeting them cold at the start.

Do I need Security+ before this?

Not formally. CompTIA recommends it along with Network+ and several years of testing, and the recommendation is about comfort rather than eligibility. Candidates arriving from practical labs without the networking layer find the enumeration and lateral-movement questions harder than they expect, for reasons that have nothing to do with exploitation.

What comes next

Concepts this exam draws on

Glossary entries with the reason each one matters for PT0-003.

  • SSL/TLS

    Attacks on transport security and certificate misuse are exploitation topics.

  • Web Server

    Web application and server attacks carry the largest exam weight.

  • Penetration Testing

    The exam is this concept in written form: engagement management, reconnaissance, exploitation, reporting.

  • Vulnerability Management

    Vulnerability discovery and analysis is a domain of its own.

  • Phishing

    Social engineering attacks are examined within attacks and exploits.

  • Encryption

    Weak cryptography and its exploitation appear in the attacks domain.

A vendor certificate — not a degree and not an accredited qualification. Facts are from the vendor's exam page on the date shown; prices are list prices that vary by country and tax.

Last reviewed 12 September 2026 · Getting Digital