CompTIA

CompTIA PenTest+ (PT0-003)
exam objectives

CompTIA PenTest+ certification exam PT0-003 V3. Purpose-built for offensive security: planning, scoping, and executing authorized penetration test engagements across network, web, cloud, wireless, and specialized systems.

Questions
90
Duration
90 min
Passing score
750
Domains
5

370 practice questions available for PT0-003 on CertPilot AI, mapped to the domains below.

PT0-003 exam domains and weightings

The PT0-003 exam is split into 5 domains. The percentage next to each is the share of the exam it accounts for — study time is best spent proportionally.

1.0Engagement Management

13%

48 practice questions in this domain

  • 1.1Summarize pre-engagement activities (scope definition, rules of engagement, agreement types, target selection, assessment types, shared responsibility model, legal and ethical considerations)
  • 1.2Explain collaboration and communication activities (peer review, stakeholder alignment, escalation path, articulation of risk, business impact analysis, client acceptance)
  • 1.3Compare and contrast testing frameworks and methodologies (OSSTMM, CREST, PTES, MITRE ATT&CK, OWASP Top 10, OWASP MASVS, Purdue model, DREAD, STRIDE, OCTAVE)
  • 1.4Explain the components of a penetration test report (format alignment, report components, test limitations and assumptions, reporting considerations)
  • 1.5Given a scenario, analyze the findings and recommend the appropriate remediation within a report (technical, administrative, operational, and physical controls)

2.0Reconnaissance and Enumeration

21%

77 practice questions in this domain

  • 2.1Given a scenario, apply information gathering techniques (active/passive reconnaissance, OSINT, protocol scanning, certificate transparency logs, banner grabbing, HTML scraping)
  • 2.2Given a scenario, apply enumeration techniques (OS fingerprinting, service/protocol/DNS/directory enumeration, secrets enumeration, attack path mapping, WAF enumeration, manual enumeration)
  • 2.3Given a scenario, modify scripts for reconnaissance and enumeration (Bash, Python, PowerShell; logic constructs; libraries/functions/classes)
  • 2.4Given a scenario, use the appropriate tools for reconnaissance and enumeration (Nmap, Shodan, Maltego, Recon-ng, WHOIS, nslookup/dig, Amass, theHarvester, Wireshark/tcpdump, Aircrack-ng, etc.)

3.0Vulnerability Discovery and Analysis

17%

63 practice questions in this domain

  • 3.1Given a scenario, conduct vulnerability discovery using various techniques (container/application/network/host-based/wireless scans, ICS vulnerability assessment, tools like Nikto, OpenVAS, Nessus, BloodHound)
  • 3.2Given a scenario, analyze output from reconnaissance, scanning, and enumeration phases (false positives/negatives, scan completeness, public exploit selection, scripting to validate results)
  • 3.3Explain physical security concepts (tailgating, site surveys, USB drops, badge cloning, lock picking)

4.0Attacks and Exploits

35%

130 practice questions in this domain

  • 4.1Given a scenario, analyze output to prioritize and prepare attacks (target prioritization incl. CVSS/CVE/CWE/EPSS, capability selection, exploit customization, documentation)
  • 4.10Given a scenario, use scripting to automate attacks (PowerShell/PowerSploit/PowerView, Bash, Python/Impacket/Scapy, breach-and-attack-simulation frameworks)
  • 4.2Given a scenario, perform network attacks using the appropriate tools (default credentials, on-path, VLAN hopping, relay attacks; Metasploit, Netcat, Nmap, Impacket, CrackMapExec, Responder, Hydra)
  • 4.3Given a scenario, perform authentication attacks using the appropriate tools (MFA fatigue, pass-the-hash/ticket/token, Kerberos attacks, LDAP injection, password spraying; hashcat, John the Ripper, Hydra, Medusa)
  • 4.4Given a scenario, perform host-based attacks using the appropriate tools (privilege escalation, credential dumping, process injection; Mimikatz, Rubeus, Certify, Seatbelt, PsExec, Evil-WinRM, LOLBins)
  • 4.5Given a scenario, perform web application attacks using the appropriate tools (SSRF, CSRF, deserialization, SQLi, XSS, IDOR, JWT manipulation; Burp Suite, ZAP, sqlmap, Gobuster, WPScan)
  • 4.6Given a scenario, perform cloud-based attacks using the appropriate tools (metadata service attacks, IAM misconfigurations, container escape, supply chain attacks; Pacu, Docker Bench, Prowler, ScoutSuite)
  • 4.7Given a scenario, perform wireless attacks using the appropriate tools (wardriving, evil twin, deauthentication, WPS PIN attack; Aircrack-ng, WiFi-Pumpkin, Kismet)
  • 4.8Given a scenario, perform social engineering attacks using the appropriate tools (phishing, vishing, whaling, pretexting; SET, Gophish, Evilginx, BeEF)
  • 4.9Explain common attacks against specialized systems (mobile, AI, OT, NFC, Bluejacking, RFID; Scapy, MobSF, Frida, Drozer)

5.0Post-exploitation and Lateral Movement

14%

52 practice questions in this domain

  • 5.1Given a scenario, perform tasks to establish and maintain persistence (scheduled tasks, service creation, reverse/bind shells, C2 frameworks, backdoors, rootkits)
  • 5.2Given a scenario, perform tasks to move laterally throughout the environment (pivoting, relay creation, service discovery, WMI/WinRM, LOLBins, CrackMapExec, Impacket, PsExec, Mimikatz)
  • 5.3Summarize concepts related to staging and exfiltration (file encryption/compression, covert channels, cloud storage, alternate data streams)
  • 5.4Explain cleanup and restoration activities (remove persistence mechanisms, revert configuration changes, secure data destruction)

How to prepare for CompTIA PenTest+

Most candidates fail PT0-003 not because they didn't know the material, but because they couldn't tell which material they were weakest on. Reading the objectives end to end treats every domain as equally important — the exam doesn't. On PT0-003, Attacks and Exploits alone is 35% of your score.

CertPilot AI works the other way around. It tracks your accuracy per domain, weights each domain by its real exam share, and pulls most of each practice session from wherever you're currently weakest. The result is a single readiness score — at 90% you're in the range where candidates typically pass, so you book the exam on evidence instead of a hunch.

Every question comes with an AI explanation of why the right answer is right and why each distractor is wrong. The Exam Decoder goes further and breaks down how to read a question — the qualifiers, the scenario framing, and the trap options — which is the skill that separates a 740 from a 750.

CompTIA PenTest+ (PT0-003) FAQ

How many questions are on the CompTIA PenTest+ (PT0-003) exam?

The PT0-003 exam has up to 90 questions and you get 90 minutes to complete it.

What score do you need to pass CompTIA PenTest+?

CompTIA PenTest+ requires a scaled score of 750. Scaled scoring means the raw number of correct answers is adjusted for the difficulty of the specific question set you were served, so there is no fixed percentage that guarantees a pass.

What domains does the PT0-003 exam cover?

CompTIA PenTest+ is divided into 5 domains: Engagement Management (13%), Reconnaissance and Enumeration (21%), Vulnerability Discovery and Analysis (17%), Attacks and Exploits (35%), Post-exploitation and Lateral Movement (14%). The heaviest weighted domain is Attacks and Exploits at 35% of the exam.

How do I know when I'm ready to book the PT0-003 exam?

CertPilot AI calculates a readiness score by weighting your accuracy in each domain by that domain's share of the real exam, then scaling it by how many questions you've actually answered — so a domain you've barely touched can't inflate the number. At 90% you're in the range where candidates typically pass.

How much does the PT0-003 exam cost?

The CompTIA PenTest+ exam voucher typically costs around $404 USD. Pricing varies by region and vendors periodically adjust it, so confirm on the official vendor site before booking.

Free to start

Start practising PT0-003 questions

Adaptive sessions weighted to the domains above, AI explanations on every question, and a readiness score that tells you when to book.

Start free

Other CompTIA certifications