CompTIA PenTest+ PT0-003 Exam Guide 2026
PT0-003 did not just refresh the content — it renamed and re-cut every domain. Study material written for PT0-002 will send you looking for topics that no longer exist under those headings.

On this page
PenTest+ PT0-003 launched on 17 December 2024, replacing PT0-002 which retired on 17 June 2025. It certifies hands-on penetration testing across the full engagement lifecycle.
The domains were re-cut, not just refreshed
This matters more than a normal version bump, and it is the single most common source of confusion in third-party study material.
| PT0-002 (retired) domains | PT0-003 domains |
|---|---|
| Planning and Scoping | Engagement Management |
| Information Gathering and Vulnerability Scanning | Reconnaissance and Enumeration + Vulnerability Discovery and Analysis (split in two) |
| Attacks and Exploits | Attacks and Exploits (kept, and grown) |
| Reporting and Communication | folded into Engagement Management |
| Tools and Code Analysis | distributed across the technical domains |
| — | Post-Exploitation and Lateral Movement (new as its own domain) |
A surprising number of sites still publish the PT0-002 domain list under a PT0-003 heading. If the material you are using mentions “Planning and Scoping”, “Tools and Code Analysis”, or a 30% Attacks and Exploits weighting, it is describing the retired exam.
Exam format
Multiple-choice plus performance-based questions, in English, French, Japanese and Portuguese. CompTIA recommends three to four years in a penetration tester role plus Network+ and Security+ knowledge. Estimated retirement is around 2027, roughly three years after launch.
The five domains and their weights
Read that shape carefully: the three purely offensive domains — recon, attacks, post-exploitation — are 70% of the exam. PenTest+ has moved decisively toward the technical work and away from process.
Why Attacks and Exploits dominates
At 35%, this single domain is more than a third of your score and larger than the next two combined. If you are triaging study time, it deserves proportionate attention — roughly one session in three.
The new Post-Exploitation and Lateral Movement domain is the other signal. Under PT0-002 this content was scattered; making it a named 14% domain says CompTIA expects you to be assessed on what happens after initial access — persistence, privilege escalation, moving through a network, and cleaning up.
At 13% it is the smallest domain, and because it absorbed the old Reporting and Communication content it is also the most learnable. Scoping, rules of engagement, communication during an engagement and reporting are stable, non-technical marks. Skipping them to spend more time on exploits is a false economy.
What the performance-based questions involve
PenTest+ PBQs are the reason the certification carries more practical weight than a purely multiple-choice exam. Typical shapes:
- Analyse output. You are shown scanner results, a packet capture or command output and asked what it means or what to run next.
- Complete or correct a command or script. Not writing from scratch, but knowing what a flag does and which tool fits the goal.
- Sequence an attack path. Given a foothold and a target, order the steps — which is really testing methodology.
- Choose the finding’s severity or the right remediation from evidence.
None of this rewards memorised tool syntax as much as it rewards having actually run the tools. A home lab — deliberately vulnerable targets on a virtual network — is the single highest-return preparation activity for this exam.
What PenTest+ is worth
Two honest points about its career value.
It opens doors it does not walk you through. PenTest+ satisfies HR filters and certain government and defence baseline requirements, which gets your application read. It does not by itself demonstrate the exploitation ability that a serious offensive role interviews for — for that, employers look at OSCP, a portfolio, or a technical assessment.
Its best fit is the transition. The candidate PenTest+ serves best is a SOC analyst, sysadmin or CySA+ holder moving toward offensive work. It formalises methodology you have partly absorbed, proves it externally, and gives you a structured syllabus to close gaps against — particularly around scoping, engagement management and reporting, which self-taught testers often skip.
PenTest+ versus CEH and OSCP
| PenTest+ PT0-003 | CEH | OSCP | |
|---|---|---|---|
| Format | MCQ + performance-based | Mostly MCQ (practical available separately) | 24-hour hands-on lab |
| Proves | Structured methodology + practical judgement | Broad tool and concept awareness | Demonstrated exploitation skill |
| Effort | Moderate | Moderate | High |
| Best for | Analysts moving into offensive work; DoD 8570-style requirements | Screening filters and HR keyword matches | Serious offensive roles |
PenTest+ occupies a useful middle position: more practical than CEH thanks to its performance-based questions, far less punishing than OSCP. Our CEH v13 guide covers the comparison from the other side.
How to prepare
The study-time calculator will fit this to your available hours.
The tooling you are expected to know
PT0-003 dissolved the old standalone “Tools and Code Analysis” domain and distributed tooling across the technical domains. That is a meaningful change: tools are no longer examined as a topic in their own right, they are examined in the context of the phase you would use them in.
Questions rarely have one technically-possible answer. Several tools could do the job; one is appropriate given the constraints in the scenario — the scope, the noise tolerance, the access you already have, or the rules of engagement. Read for the constraint before choosing.
The practical implication for preparation is that reading a tool list will not help you much. Build a lab, run each phase end to end against a deliberately vulnerable target, and pay attention to why you reached for one tool over another. That reasoning is what the exam samples.
Frequently Asked Questions
What are the PenTest+ PT0-003 domains?
Engagement Management (13%), Reconnaissance and Enumeration (21%), Vulnerability Discovery and Analysis (17%), Attacks and Exploits (35%), and Post-Exploitation and Lateral Movement (14%).
How long is the PT0-003 exam?
165 minutes for a maximum of 90 questions, mixing multiple-choice and performance-based questions. The passing score is 750 on a 100-900 scale.
Is PT0-002 still valid?
The PT0-002 exam retired on 17 June 2025. Certifications earned on it remain valid for their normal three-year cycle, but new candidates sit PT0-003.
What experience does PenTest+ assume?
CompTIA recommends three to four years in a penetration tester job role, with Network+ and Security+ or equivalent knowledge.
Practise PenTest+ Before You Book
500–1,000+ practice questions with worked explanations, written against the current exam objectives.
PenTest+ Practice TestPractice Before You Book
500–1,000+ practice questions per exam with detailed explanations, across Azure, AWS, GCP, security, and AI certifications.
