Prepare across all five PT0-003 domains using the official objectives and legitimate labs. This guide connects the syllabus to practical study tasks, explains the exam format and includes an original scope-reading exercise with a worked answer.
What the PT0-003 exam covers and how it runs
PenTest+ PT0-003 assesses penetration-testing work from planning and information gathering through analysis, testing, reporting and post-exploitation topics.
PT0-003 is exam version V3, launched December 17, 2024. It is offered in English, French, Japanese and Portuguese. The older PT0-002 retired June 17, 2025.
CompTIA recommends three to four years in a penetration-testing role, with Network+ and Security+ knowledge or equivalent preparation. These are recommendations, not mandatory prerequisite certifications.
The current page gives an estimated 2027 retirement for PT0-003, rather than a fixed announced day. Recheck the current exam code, language and dates before booking.
Sources: PenTest+ Certification V3 (New Version) | CompTIA — Exam details and skills sections; CompTIA PenTest+ PT0-003 Certification Exam: Exam Objectives Version 3.0 (publisher-hosted copy) — Test details, domain table, objectives 1.1–5.4
The five domains and their weights
Cover all five domains and use the weights alongside your own gaps when planning additional practice.
The CompTIA-authored objectives PDF linked here is a publisher-hosted copy; the current issuer page corroborates its exam specifications. Its listed examples are not exhaustive. Use the full objectives and supporting references for detailed coverage.
| Domain | Weight | What you practice (objectives) |
|---|---|---|
| Engagement Management | 13% | Scope and rules of engagement, legal and ethical compliance, collaboration, frameworks, and reporting (1.1–1.5) |
| Reconnaissance and Enumeration | 21% | Active and passive information gathering, enumeration, script modification, and tool selection (2.1–2.4) |
| Vulnerability Discovery and Analysis | 17% | Scan types, output analysis, validation of findings, and physical security concepts (3.1–3.3) |
| Attacks and Exploits | 35% | Network, authentication, host, web, cloud, wireless, and social engineering attacks, specialized systems, and scripted automation (4.1–4.10) |
| Post-exploitation and Lateral Movement | 14% | Persistence, lateral movement, staging and exfiltration, and cleanup (5.1–5.4) |
Sources: PenTest+ Certification V3 (New Version) | CompTIA — Exam details and skills sections; CompTIA PenTest+ PT0-003 Certification Exam: Exam Objectives Version 3.0 (publisher-hosted copy) — Test details, domain table, objectives 1.1–5.4
Prepare with the engagement requirements
Objective 1.1 covers scope, targets, authorizations, exclusions, testing windows and responsibilities. Practise reading those requirements together.
For a supplied practice scenario, identify the authorized targets, activities, timing and approval process. Compare each proposed action with those facts. A statement-of-work heading or a job title alone does not supply missing permission.
The exercise below states every rule needed to choose an answer. Its approval process and time window are fictional training premises, not universal CompTIA rules or legal advice.
Practice: authorization before technique
Choose the action that stays inside the signed scope and uses the required approval path for anything new.
The scenario below is fictional, built for practice; the decision it trains maps directly to objective 1.1's coverage of target selection, exclusions, testing windows, and authorization. Every premise you need is stated in the prompt.
Practice exercise
You hold a signed engagement for a fictional customer, Northwind Labs. The rules you signed authorize testing only two hosts, Lab-A and Lab-B, during a 10:00–12:00 window, and they prohibit any action that could disrupt service availability. The rules also state that any additional target requires the owner's written approval before testing. At 11:00, your inventory notes mention a third host, External-C, that appears to belong to the same customer. No written approval for External-C exists, and the scenario contains no emergency. What should you do? A) Run a light probe against External-C, since the customer's own inventory references it. B) Continue approved, non-disruptive work on Lab-A and Lab-B, and request the owner's written authorization before touching External-C. C) Test all three hosts after 12:00, when fewer staff are working.
Show answer
B
B stays within the authorized hosts, non-disruptive activity and 10:00-12:00 window, while following the stated approval process for a new host. A adds an unapproved target; the inventory reference does not amend this exercise's target list. C adds that target and moves outside the time window. These conclusions follow from the explicit fictional rules, not from assumptions about corporate ownership or a universal contract rule.
Turn the objectives into practical study tasks
Use legitimate labs and supplied scenarios to practise the objective verbs, then explain the result.
These tasks are preparation advice. Choose lab instructions and technical references that match the tool and environment; a syllabus topic alone is not an operational procedure.
- Reconnaissance and Enumeration: compare the information-gathering methods and tool categories in objectives 2.1-2.4; identify what a supplied task authorizes before attempting it.
- Vulnerability Discovery and Analysis: interpret legitimate scan output, distinguish findings requiring validation and explain the limitations of the supplied evidence.
- Attacks and Exploits: review the network, authentication, host, web, cloud, wireless, social-engineering, specialized-system and scripting objectives; use authorized labs to practise their stated tasks.
- Post-exploitation and Lateral Movement: review the persistence, lateral-movement, staging and cleanup objectives and relate each to a provided engagement's permissions.
- Engagement Management: practise explaining a scope decision and writing a clear planning note, finding and limitation.
Reporting for two audiences
Objective 1.4 includes report components such as executive summary, methodology, findings, attack narrative, remediation, assumptions and limitations.
As a study task, explain the same supplied finding for a decision-maker and a technical reader. Keep observed evidence separate from assumptions, scope limits and recommended next work. Objective 1.5 covers choosing remediation for supplied findings.
For the original scope exercise, a planning note could read: "Planned testing is limited to Lab-A and Lab-B, 10:00-12:00, with no availability-disrupting actions. External-C appears in inventory but has no written approval. Request owner approval before adding it to the work." This describes the supplied scope; it does not claim a vulnerability was tested or confirmed.
Performance-based questions: what test day looks like
PT0-003 includes performance-based questions delivered as simulations; simulation items can be skipped and revisited, and partial credit may apply.
CompTIA lists PenTest+ among exams using simulation PBQs. These approximate tools or environments with restricted functionality, so not every command or feature will be available.
You can skip a simulation and return later, with work saved. Reset clears only that question. Do not apply the no-return rule for virtual PBQs on other exams to PenTest+ simulations.
Multiple solution paths may be recognized and partial credit may be offered. Item-level scoring is confidential. Use legitimate samples to learn the format, then review how your actions and result compare with the task.
Sources: Performance-Based Questions Overview | CompTIA IT Certifications — Simulations, virtual environments, and PBQ tips; Performance-Based Questions FAQs | CompTIA Blog — Reset, skip/return, multiple paths, partial credit
Retake rules and booking details to verify
After a first failed attempt there is no required wait before a second. Before a third or later attempt, wait at least 14 calendar days from your last attempt.
The policy requires payment for each attempt. Some CompTIA bundles include a retake under their own terms, so confirm what your voucher covers. After passing and achieving the certification, retaking the same code requires CompTIA's prior consent.
Confirm current regional pricing, taxes, delivery options, identification requirements and voucher terms with CompTIA before booking.
Sources: CompTIA Certification Retake Policy | CompTIA IT Certifications — Waiting periods and per-attempt payment; PenTest+ Certification V3 (New Version) | CompTIA — Exam details and skills sections
Your preparation checklist
Use practice results to locate gaps across the objectives and confirm your exam arrangements.
Work through concepts, legitimate applied tasks and explanations of why an answer fits. Domain weights do not determine a fixed study schedule or guarantee a result.
- Match your resources and booked exam to PT0-003.
- Cover all five domains and revisit objectives behind repeated errors.
- Explain the authorized targets, actions and timing in a supplied scope scenario.
- Interpret sample findings and write an evidence-based report with clear limitations.
- Practise simulations and learn the skip, return and reset controls.
- Confirm pricing, voucher coverage, language, ID and booking details.
Sources: PenTest+ Certification V3 (New Version) | CompTIA — Exam details and skills sections; Performance-Based Questions Overview | CompTIA IT Certifications — Simulations, virtual environments, and PBQ tips; Performance-Based Questions FAQs | CompTIA Blog — Reset, skip/return, multiple paths, partial credit; CompTIA Certification Retake Policy | CompTIA IT Certifications — Waiting periods and per-attempt payment; CompTIA PenTest+ PT0-003 Certification Exam: Exam Objectives Version 3.0 (publisher-hosted copy) — Test details, domain table, objectives 1.1–5.4
Sources
Fact check:
- PenTest+ Certification V3 (New Version) | CompTIA
- Performance-Based Questions Overview | CompTIA IT Certifications
- Performance-Based Questions FAQs | CompTIA Blog
- CompTIA Certification Retake Policy | CompTIA IT Certifications
- CompTIA PenTest+ PT0-003 Certification Exam: Exam Objectives Version 3.0 (publisher-hosted copy)
