CompTIA PenTest+ PT0-003 Exam Guide 2026
PT0-003 did not just refresh the content — it renamed and re-cut every domain. Study material written for PT0-002 will send you looking for topics that no longer exist under those headings.

On this page
PenTest+ PT0-003 launched on 17 December 2024, replacing PT0-002 which retired on 17 June 2025. It certifies hands-on penetration testing across the full engagement lifecycle.
The domains were re-cut, not just refreshed
This matters more than a normal version bump, and it is the single most common source of confusion in third-party study material.
| PT0-002 (retired) domains | PT0-003 domains |
|---|---|
| Planning and Scoping | Engagement Management |
| Information Gathering and Vulnerability Scanning | Reconnaissance and Enumeration + Vulnerability Discovery and Analysis (split in two) |
| Attacks and Exploits | Attacks and Exploits (kept, and grown) |
| Reporting and Communication | folded into Engagement Management |
| Tools and Code Analysis | distributed across the technical domains |
| — | Post-Exploitation and Lateral Movement (new as its own domain) |
A surprising number of sites still publish the PT0-002 domain list under a PT0-003 heading. If the material you are using mentions “Planning and Scoping”, “Tools and Code Analysis”, or a 30% Attacks and Exploits weighting, it is describing the retired exam.
Exam format
Multiple-choice plus performance-based questions, in English, French, Japanese and Portuguese. CompTIA recommends three to four years in a penetration tester role plus Network+ and Security+ knowledge. Estimated retirement is around 2027, roughly three years after launch.
The five domains and their weights
Read that shape carefully: the three purely offensive domains — recon, attacks, post-exploitation — are 70% of the exam. PenTest+ has moved decisively toward the technical work and away from process.
Why Attacks and Exploits dominates
At 35%, this single domain is more than a third of your score and larger than the next two combined. If you are triaging study time, it deserves proportionate attention — roughly one session in three.
The new Post-Exploitation and Lateral Movement domain is the other signal. Under PT0-002 this content was scattered; making it a named 14% domain says CompTIA expects you to be assessed on what happens after initial access — persistence, privilege escalation, moving through a network, and cleaning up.
At 13% it is the smallest domain, and because it absorbed the old Reporting and Communication content it is also the most learnable. Scoping, rules of engagement, communication during an engagement and reporting are stable, non-technical marks. Skipping them to spend more time on exploits is a false economy.
What the performance-based questions involve
PenTest+ PBQs are the reason the certification carries more practical weight than a purely multiple-choice exam. Typical shapes:
- Analyse output. You are shown scanner results, a packet capture or command output and asked what it means or what to run next.
- Complete or correct a command or script. Not writing from scratch, but knowing what a flag does and which tool fits the goal.
- Sequence an attack path. Given a foothold and a target, order the steps — which is really testing methodology.
- Choose the finding’s severity or the right remediation from evidence.
None of this rewards memorised tool syntax as much as it rewards having actually run the tools. A home lab — deliberately vulnerable targets on a virtual network — is the single highest-return preparation activity for this exam.
What PenTest+ is worth
Two honest points about its career value.
It opens doors it does not walk you through. PenTest+ satisfies HR filters and certain government and defence baseline requirements, which gets your application read. It does not by itself demonstrate the exploitation ability that a serious offensive role interviews for — for that, employers look at OSCP, a portfolio, or a technical assessment.
Its best fit is the transition. The candidate PenTest+ serves best is a SOC analyst, sysadmin or CySA+ holder moving toward offensive work. It formalises methodology you have partly absorbed, proves it externally, and gives you a structured syllabus to close gaps against — particularly around scoping, engagement management and reporting, which self-taught testers often skip.
PenTest+ versus CEH and OSCP
| PenTest+ PT0-003 | CEH | OSCP | |
|---|---|---|---|
| Format | MCQ + performance-based | Mostly MCQ (practical available separately) | 24-hour hands-on lab |
| Proves | Structured methodology + practical judgement | Broad tool and concept awareness | Demonstrated exploitation skill |
| Effort | Moderate | Moderate | High |
| Best for | Analysts moving into offensive work; DoD 8570-style requirements | Screening filters and HR keyword matches | Serious offensive roles |
PenTest+ occupies a useful middle position: more practical than CEH thanks to its performance-based questions, far less punishing than OSCP. Our CEH v13 guide covers the comparison from the other side.
How to prepare
The study-time calculator will fit this to your available hours.
Frequently Asked Questions
What are the PenTest+ PT0-003 domains?
Engagement Management (13%), Reconnaissance and Enumeration (21%), Vulnerability Discovery and Analysis (17%), Attacks and Exploits (35%), and Post-Exploitation and Lateral Movement (14%).
How long is the PT0-003 exam?
165 minutes for a maximum of 90 questions, mixing multiple-choice and performance-based questions. The passing score is 750 on a 100-900 scale.
Is PT0-002 still valid?
The PT0-002 exam retired on 17 June 2025. Certifications earned on it remain valid for their normal three-year cycle, but new candidates sit PT0-003.
What experience does PenTest+ assume?
CompTIA recommends three to four years in a penetration tester job role, with Network+ and Security+ or equivalent knowledge.
Practise PenTest+ Before You Book
500–1,000+ practice questions with worked explanations, written against the current exam objectives.
PenTest+ Practice TestPractice Before You Book
500–1,000+ practice questions per exam with detailed explanations, across Azure, AWS, GCP, security, and AI certifications.
