PT0-003 Skills measured as of Launched 17 Dec 2024
Security August 22, 2026 6 min read

CompTIA PenTest+ PT0-003 Exam Guide 2026

PT0-003 did not just refresh the content — it renamed and re-cut every domain. Study material written for PT0-002 will send you looking for topics that no longer exist under those headings.

CompTIA PenTest+ PT0-003 exam guide

PenTest+ PT0-003 launched on 17 December 2024, replacing PT0-002 which retired on 17 June 2025. It certifies hands-on penetration testing across the full engagement lifecycle.

The domains were re-cut, not just refreshed

This matters more than a normal version bump, and it is the single most common source of confusion in third-party study material.

PT0-002 (retired) domainsPT0-003 domains
Planning and ScopingEngagement Management
Information Gathering and Vulnerability ScanningReconnaissance and Enumeration + Vulnerability Discovery and Analysis (split in two)
Attacks and ExploitsAttacks and Exploits (kept, and grown)
Reporting and Communicationfolded into Engagement Management
Tools and Code Analysisdistributed across the technical domains
Post-Exploitation and Lateral Movement (new as its own domain)
Check your study material

A surprising number of sites still publish the PT0-002 domain list under a PT0-003 heading. If the material you are using mentions “Planning and Scoping”, “Tools and Code Analysis”, or a 30% Attacks and Exploits weighting, it is describing the retired exam.

Exam format

Exam codePT0-003
Questionsmax 90
Duration165 min
Passing score750 / 900
Domains5
Launched17 Dec 2024

Multiple-choice plus performance-based questions, in English, French, Japanese and Portuguese. CompTIA recommends three to four years in a penetration tester role plus Network+ and Security+ knowledge. Estimated retirement is around 2027, roughly three years after launch.

The five domains and their weights

Attacks and Exploits35%
Reconnaissance and Enumeration21%
Vulnerability Discovery and Analysis17%
Post-Exploitation and Lateral Movement14%
Engagement Management13%

Read that shape carefully: the three purely offensive domains — recon, attacks, post-exploitation — are 70% of the exam. PenTest+ has moved decisively toward the technical work and away from process.

Why Attacks and Exploits dominates

At 35%, this single domain is more than a third of your score and larger than the next two combined. If you are triaging study time, it deserves proportionate attention — roughly one session in three.

The new Post-Exploitation and Lateral Movement domain is the other signal. Under PT0-002 this content was scattered; making it a named 14% domain says CompTIA expects you to be assessed on what happens after initial access — persistence, privilege escalation, moving through a network, and cleaning up.

Do not write off Engagement Management

At 13% it is the smallest domain, and because it absorbed the old Reporting and Communication content it is also the most learnable. Scoping, rules of engagement, communication during an engagement and reporting are stable, non-technical marks. Skipping them to spend more time on exploits is a false economy.

What the performance-based questions involve

PenTest+ PBQs are the reason the certification carries more practical weight than a purely multiple-choice exam. Typical shapes:

  • Analyse output. You are shown scanner results, a packet capture or command output and asked what it means or what to run next.
  • Complete or correct a command or script. Not writing from scratch, but knowing what a flag does and which tool fits the goal.
  • Sequence an attack path. Given a foothold and a target, order the steps — which is really testing methodology.
  • Choose the finding’s severity or the right remediation from evidence.

None of this rewards memorised tool syntax as much as it rewards having actually run the tools. A home lab — deliberately vulnerable targets on a virtual network — is the single highest-return preparation activity for this exam.

What PenTest+ is worth

Two honest points about its career value.

It opens doors it does not walk you through. PenTest+ satisfies HR filters and certain government and defence baseline requirements, which gets your application read. It does not by itself demonstrate the exploitation ability that a serious offensive role interviews for — for that, employers look at OSCP, a portfolio, or a technical assessment.

Its best fit is the transition. The candidate PenTest+ serves best is a SOC analyst, sysadmin or CySA+ holder moving toward offensive work. It formalises methodology you have partly absorbed, proves it externally, and gives you a structured syllabus to close gaps against — particularly around scoping, engagement management and reporting, which self-taught testers often skip.

PenTest+ versus CEH and OSCP

PenTest+ PT0-003CEHOSCP
FormatMCQ + performance-basedMostly MCQ (practical available separately)24-hour hands-on lab
ProvesStructured methodology + practical judgementBroad tool and concept awarenessDemonstrated exploitation skill
EffortModerateModerateHigh
Best forAnalysts moving into offensive work; DoD 8570-style requirementsScreening filters and HR keyword matchesSerious offensive roles

PenTest+ occupies a useful middle position: more practical than CEH thanks to its performance-based questions, far less punishing than OSCP. Our CEH v13 guide covers the comparison from the other side.

How to prepare

Weeks 1–2
Recon and enumeration (21%). Passive and active discovery, service and host enumeration, and the tooling. Build a repeatable methodology rather than memorising flags.
Weeks 3–5
Attacks and exploits (35%). The biggest block by far — give it the most time. Work across network, application, wireless, cloud and social engineering vectors in a lab, not on paper.
Week 6
Vulnerability discovery and analysis (17%). Scanning, validating, and the analysis that separates a finding from a false positive.
Week 7
Post-exploitation and lateral movement (14%). Persistence, escalation, pivoting, and cleanup.
Week 8
Engagement management and rehearsal (13%). Scoping, rules of engagement, reporting. Then timed practice with PBQs.

The study-time calculator will fit this to your available hours.

Frequently Asked Questions

What are the PenTest+ PT0-003 domains?

Engagement Management (13%), Reconnaissance and Enumeration (21%), Vulnerability Discovery and Analysis (17%), Attacks and Exploits (35%), and Post-Exploitation and Lateral Movement (14%).

How long is the PT0-003 exam?

165 minutes for a maximum of 90 questions, mixing multiple-choice and performance-based questions. The passing score is 750 on a 100-900 scale.

Is PT0-002 still valid?

The PT0-002 exam retired on 17 June 2025. Certifications earned on it remain valid for their normal three-year cycle, but new candidates sit PT0-003.

What experience does PenTest+ assume?

CompTIA recommends three to four years in a penetration tester job role, with Network+ and Security+ or equivalent knowledge.

Practise PenTest+ Before You Book

500–1,000+ practice questions with worked explanations, written against the current exam objectives.

PenTest+ Practice Test
ExamCert

ExamCert Team

Certified IT professionals tracking the cloud, AI, and security certification landscape. Every exam brief is rebuilt against the official skills-measured document on the date shown above.

Practice Before You Book

500–1,000+ practice questions per exam with detailed explanations, across Azure, AWS, GCP, security, and AI certifications.