CertGrid
Security Study Guide

CompTIA PenTest+ (PT0-003) Study Guide

CompTIA PenTest+ (PT0-003) validates hands-on penetration testing and vulnerability management skills across the full engagement lifecycle. Its five official domains are Engagement Management (scoping, governance, communication, and reporting), Reconnaissance and Enumeration, Vulnerability Discovery and Analysis, Attacks and Exploits, and Post-exploitation and Lateral Movement. It targets intermediate cybersecurity professionals (3-4 years of hands-on experience) such as penetration testers, red-team members, and vulnerability analysts. The 165-minute exam has up to 90 multiple-choice and performance-based questions, with a passing score of 750 on a scale of 100-900.

Objective-mapped study guide, aligned to current exam objectives · Reviewed Aug 2026 · Independent practice platform.

Real exam: Max 90 qs · 165 min

Domain 1: Engagement Management

Key concepts you must know · 127 practice questions

Domain 2: Reconnaissance and Enumeration

Key concepts you must know · 202 practice questions

Domain 3: Vulnerability Discovery and Analysis

Key concepts you must know · 164 practice questions

Domain 4: Attacks and Exploits

Key concepts you must know · 336 practice questions

Domain 5: Post-exploitation and Lateral Movement

Key concepts you must know · 135 practice questions

CompTIA PenTest+ (PT0-003) exam tips

Study guide FAQ

What is the difference between PenTest+ PT0-002 and the current PT0-003 exam?

PT0-003 is the current version (PT0-002 retired) and reorganizes the objectives into five domains - Engagement Management, Reconnaissance and Enumeration, Vulnerability Discovery and Analysis, Attacks and Exploits, and Post-exploitation and Lateral Movement. It increases emphasis on hands-on attack execution, modern environments (cloud, containers, APIs, and AI/ML systems), and scripting/automation. Always study against PT0-003 objectives.

How is the exam scored and what do I need to pass?

PenTest+ uses a scaled score from 100 to 900, and you need 750 to pass. The 165-minute exam includes up to 90 questions mixing multiple-choice and performance-based (hands-on simulation) items. Performance-based questions are weighted heavily, so practice building commands and analyzing tool output.

Do I need to memorize exact tool syntax and commands?

Yes. Performance-based questions can require you to construct or interpret real commands - Nmap scans, Hashcat cracking, Metasploit/msfvenom payloads, Impacket (psexec.py/wmiexec.py) for Pass-the-Hash, and dig for zone transfers. Know the common flags, default ports, and which tool solves which problem.

How much experience should I have before taking PenTest+?

CompTIA recommends 3-4 years of hands-on information security or penetration testing experience and a Network+/Security+ level of foundational knowledge. It is an intermediate certification, so prior comfort with networking, the command line, and basic scripting (Bash, Python, PowerShell) is expected.

Related Security resources

What CertGrid is (and is not)

CertGrid is an independent IT certification practice platform for Azure, AWS, Google, Cisco, Security, Linux, Kubernetes, Terraform, and other certification tracks. It provides objective-mapped practice questions, readiness scoring, weak-domain drills, and explanations to help learners understand what to study next.

Independent & original. CertGrid is an independent practice platform and is not affiliated with or endorsed by Security. Questions are original practice items designed to mirror certification concepts and exam style. CertGrid does not provide official exam questions or braindumps.