Exampractice
IT & Networking

CompTIA PenTest+ Certification Guide

What the CompTIA PenTest+ exam covers, what it costs, who it suits and how to prepare — a complete guide to the current PT0-003 version.

Liam Anderson · 10 min read
Split illustration showing a penetration testing terminal session next to a written findings report, representing the CompTIA PenTest+ exam's scope.

CompTIA PenTest+ is an intermediate-level certification for professionals who want to prove they can plan, scope and execute a penetration test — and, just as importantly, report on it. The current exam version is PT0-003, launched on 17 December 2024. It costs $439 (US retail, as listed by CompTIA's authorized resellers in June 2026), runs up to 90 questions in 165 minutes, and has no enforced prerequisites, although CompTIA recommends three to four years of hands-on experience in a penetration testing role.

This guide covers everything you need to know about the exam itself: the version situation, format, cost, content, candidate fit, preparation approach and renewal. If your real question is how PenTest+ stacks up against CEH or OSCP, that comparison deserves its own treatment (potential future page) — here the focus stays on the CompTIA exam.

What is the CompTIA PenTest+ certification?

CompTIA PenTest+ validates offensive-security skills: the ability to identify weaknesses in networks, systems and applications by attacking them the way a real adversary would, under an authorised, scoped engagement. It sits in CompTIA's cybersecurity track alongside CompTIA CySA+ — the two are often described as opposite sides of the same coin, with CySA+ testing defensive analysis and PenTest+ testing offensive technique. If the analyst path interests you more, the CompTIA CySA+ certification guide covers that exam in full.

CompTIA is the certification body; Pearson VUE delivers the exam, either at a test centre or online via OnVUE proctoring. Passing grants the vendor-neutral "CompTIA PenTest+" credential — the exam code (PT0-003) never appears in the certification name, which matters when you are choosing study materials but not on your CV.

Unlike some hands-on offensive certifications, PenTest+ is a proctored, timed exam rather than a days-long practical assault on a lab network. It uses multiple-choice and performance-based questions (PBQs) — interactive items that simulate tasks such as interpreting tool output or completing a configuration — so it tests applied judgement, not just recall, while remaining a single exam sitting.

PT0-003 or PT0-002: which version is current?

PT0-003 is the only live version. It launched on 17 December 2024, and PT0-002 retired on 17 June 2025. If you are searching for "PT0-002 objectives" in 2026, stop: any voucher you buy now books you into PT0-003, and study materials built for PT0-002 will not map cleanly to the current objectives. CompTIA estimates PT0-003 will remain live until around 2027, and no successor has been announced as of August 2026.

Two practical consequences follow from the version change:

  1. Check every resource's exam code before you pay for it. Books, video courses and question banks written for PT0-002 are still widely sold. Some content overlaps, but you would be studying to a retired blueprint.
  2. Your certification is unaffected by version churn. Anyone who passed PT0-002 before retirement holds the same "CompTIA PenTest+" credential, valid for three years from their pass date, exactly as a PT0-003 passer does.

PenTest+ exam format, cost and logistics

Here are the verified facts for PT0-003 as of August 2026:

DetailPT0-003
QuestionsMaximum of 90 (multiple-choice and performance-based)
Time165 minutes
Passing score750 on a 100–900 scale
Cost$439 US retail (June 2026 reseller listing; varies by country)
PrerequisitesNone enforced
Recommended experience3–4 years in a penetration tester role; Network+ and Security+ knowledge or equivalent
DeliveryPearson VUE test centre or OnVUE online proctoring
Validity3 years, renewable through CompTIA's Continuing Education (CE) programme

A few of these numbers reward a closer look.

The question count is a maximum, not a promise

"Maximum of 90 questions" means exactly that — many candidates see fewer, because CompTIA seeds unscored trial questions in varying numbers. Do not let a shorter-than-expected exam rattle you mid-sitting.

The passing score is scaled, not a percentage

750 out of 900 is not "83%". CompTIA scales raw performance onto the 100–900 range, and PBQs typically carry more weight than single multiple-choice items. The practical implication: partial credit and question weighting mean you cannot compute your result in your head, so answer everything — there is no penalty for guessing.

How much does PenTest+ really cost?

The $439 US retail figure comes from CompTIA's authorized resellers' June 2026 price lists, following a price rise that took effect around 1 June 2026. Prices vary by country and are typically lower through authorized voucher resellers, so confirm the current fee for your region on comptia.org before budgeting. Factor in retakes too: CompTIA's retake policy allows an immediate second attempt but imposes a 14-day wait before a third, and every attempt needs a full-price voucher unless you bought a retake bundle up front.

Time pressure is milder than you might fear

At 165 minutes for at most 90 questions, PenTest+ gives you noticeably more time per question than CompTIA's 90-minute core exams. The catch is that PBQs consume time disproportionately. A sensible pacing strategy is to flag any PBQ that is not yielding within a few minutes, clear the multiple-choice items, then return.

What does the PT0-003 exam cover?

CompTIA publishes the full PT0-003 objectives as a free download on comptia.org, and that document should be the spine of your preparation — every scored question traces back to it. Rather than reproduce the blueprint here (it runs to granular sub-objectives and changes with each version), it is more useful to describe what the exam expects of you in practice:

  • Engagement discipline, not just exploitation. PenTest+ is known for testing the parts of penetration testing that hobbyist hacking skips: scoping, rules of engagement, legal authorisation and professionalism. Expect scenario questions where the "correct" technical action is wrong because it exceeds the agreed scope.
  • The full engagement lifecycle. Reconnaissance and vulnerability identification, attacks against networks, wireless, applications and cloud targets, post-exploitation activity, and the reporting and remediation-communication phase at the end.
  • Tool literacy. You will be shown output from common offensive tooling and asked to interpret it or choose the next step. You do not need to be a developer, but you should be able to read scripts well enough to say what they do.
  • Vulnerability assessment as a component skill. Scanning, prioritising and validating findings sit inside the penetration testing workflow here — if pure vulnerability management with no exploitation is your day job, CySA+ may match your role more closely.

Work through the official objectives line by line and honestly grade yourself on each sub-objective: could you do this, explain this, or neither? That gap list becomes your study plan.

Who should take PenTest+? Requirements and candidate fit

There are no formal requirements — no mandated prior certification, no application, no experience verification. Anyone can book it. But the recommended profile is specific: three to four years in a penetration testing role, with knowledge equivalent to CompTIA Network+ and CompTIA Security+.

In practice, PenTest+ candidates usually arrive from one of three directions:

The SOC analyst pivoting to offence. A defender with two or three years of alert triage wants to move into red-team or pentest work. This is arguably the exam's sweet-spot audience: the security fundamentals are in place, and preparation fills the offensive-technique gap. If you hold Security+ and have been debating whether CySA+ or PenTest+ comes next, the honest answer is that they lead to different chairs in the same room — analysis versus attack — and the Security+ vs CySA+ comparison can help you locate yourself before committing.

The junior pentester formalising the role. You are already doing scoped assessments under supervision and need a credential for client-facing credibility or an HR filter. PT0-003 will feel like structured revision of your job.

The ambitious early-career candidate reaching upward. Nothing stops someone a year out of a helpdesk role from booking PenTest+, but the recommended-experience line exists for a reason. If terms like scoped engagement, privilege escalation and lateral movement are new vocabulary rather than daily practice, building through Security+ first is the faster route in the long run — the Security+ preparation guide shows what that groundwork involves.

If you are earlier still on the ladder and unsure where to begin, start with which CompTIA certification to take first rather than jumping into an intermediate offensive exam.

Where PenTest+ sits among penetration testing certifications

This guide deliberately avoids a deep CEH-versus-OSCP debate, but one placement note helps set expectations. PenTest+ occupies the accessible middle of the offensive-certification market: more affordable and more exam-shaped than multi-day practical certifications, broader and more engagement-focused than entry-level ethical hacking primers. Vendor-neutral alternatives at a similar or higher altitude include the GIAC track — for instance the GIAC GPEN penetration tester exam or the more specialised GIAC GWAPT web application penetration tester exam — which typically cost substantially more. Many candidates use PenTest+ as the structured, affordable proof-point on the way to a hands-on practical certification later.

How to prepare for the PenTest+ exam: a working sequence

CompTIA publishes no official study-hours figure, and any site that promises "X hours guarantees a pass" is guessing. What you can control is the order of work. A sequence that suits most candidates:

  1. Download the PT0-003 objectives from comptia.org and self-grade every sub-objective. This produces your personal gap map on day one.
  2. Close knowledge gaps with one primary resource. Pick a single up-to-date PT0-003 course or book and finish it. Resource-hopping is the most common way candidates burn months without progress.
  3. Build a small practice lab. Reading about exploitation does not stick; running tools against deliberately vulnerable targets does. Even a modest virtual lab lets you generate and interpret the kind of tool output the PBQs present.
  4. Drill the engagement framework separately. Scoping, authorisation, communication and reporting questions are pure study-and-recall for anyone without client-facing experience — make notes and review them repeatedly, because these items are easy marks to win or lose.
  5. Benchmark with practice questions, then target weak domains. Once you have covered the objectives, timed practice questions tell you which areas need another pass. ExamPractice offers free sample CompTIA PenTest+ practice questions, with fuller question sets and a timed simulation mode for subscribers. Treat every practice run as diagnosis: analyse which objective each miss maps to, restudy that area, and only then re-test. Memorising answers defeats the purpose — the live exam will paraphrase, and understanding is what transfers.
  6. Book when your benchmarks stabilise. When timed runs are consistently comfortable across all areas — not just on your favourite topics — schedule the exam rather than drifting into indefinite revision.

Common mistakes PenTest+ candidates make

  • Studying to the retired PT0-002 blueprint. The most avoidable error in 2026. Verify "PT0-003" on every resource.
  • Skipping the "boring" process content. Technically strong candidates lose disproportionate marks on scoping, legal and reporting questions because they only practised attacks.
  • Treating PBQs like trivia. Performance-based items reward hands-on familiarity. If you have never run the common tool categories yourself, screenshots in a course will not carry you.
  • Ignoring the scaled-scoring reality. Candidates who "felt like they got 80%" can still land under 750. Practise to a comfortable margin, not to the bare line.
  • Booking a retake immediately after a narrow fail without a diagnosis. The second attempt has no waiting period, but each attempt costs a full voucher — spend a week mapping your score report against the objectives first.

How long does PenTest+ last, and how do you renew?

CompTIA PenTest+ is valid for three years from your pass date. Renewal runs through CompTIA's Continuing Education programme: you can upload continuing-education units (CEUs) from qualifying training and work activities, complete a CertMaster CE course where offered, pass the latest exam version, or earn a higher-level CompTIA certification — renewing a higher certification automatically renews the ones beneath it, and you pay CE fees only for your highest cert. When renewing via CEU upload, PenTest+ sits in CompTIA's $150-per-three-year-cycle fee tier (per cycle, not per year). Check the exact CEU count required on CompTIA's renewal pages, as it differs by certification.

Frequently asked questions

Can I take the PenTest+ exam online from home?

Yes. CompTIA delivers PenTest+ through Pearson VUE, and you can sit it at a test centre or from home via OnVUE online proctoring, subject to the usual room-scan and identification requirements.

Do I need Security+ before PenTest+?

No certification is enforced as a prerequisite. CompTIA recommends knowledge equivalent to Network+ and Security+ plus three to four years of penetration testing experience — a description of readiness, not a rule.

What happens if I fail?

You can retake immediately on a second attempt; from the third attempt onward a 14-calendar-day wait applies. Each attempt requires a new full-price voucher unless you purchased a retake bundle.

Does PenTest+ involve a live hacking practical?

No. It is a proctored exam of up to 90 questions in 165 minutes. The performance-based questions simulate hands-on tasks, but there is no open-ended lab compromise as found in some practical certifications.

Is PenTest+ your next move?

Take PenTest+ if you are a security practitioner heading into offensive work and want a structured, affordable, vendor-neutral credential that tests the whole engagement — scoping through reporting — not just exploitation. Give it a pass for now if you are still building security fundamentals (start at Security+), or if your target employers specifically demand a practical lab-based certification, in which case PenTest+ is best used as a stepping stone rather than the destination. Either way, the free PT0-003 objectives from comptia.org and an honest self-assessment against them will tell you more about your readiness than any generic advice can.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like