CompTIA A+ Certification Guide for Beginners
·10 min read
What CompTIA A+ covers, how the 220-1201 and 220-1202 exams work, and a step-by-step plan to earn the certification as a complete beginner.
Continue readingA week-by-week PenTest+ PT0-003 study schedule pairing theory with hands-on lab work, from baseline audit to final timed simulation.

Picture the exam you are preparing for: PT0-003 gives you up to 90 questions and 165 minutes, mixes multiple-choice with performance-based questions (PBQs), and demands 750 on a 100–900 scale to pass. A schedule built purely on reading will not get you there, because PenTest+ questions are written the way engagements run — scoping decisions, tool output to interpret, findings to communicate. So this plan interleaves theory and lab work every single week, structured around the arc of a real penetration test, and ends with timed simulation rather than last-minute reading.
The plan below assumes roughly ten weeks at a steady part-time pace. It covers how to study, not whether PenTest+ is the right certification or how it compares with other offensive-security credentials — for the exam's full context, cost and format details, see the CompTIA PenTest+ certification guide.
CompTIA enforces no prerequisites for PenTest+, but it recommends three to four years in a penetration-testing role plus Network+ and Security+ level knowledge — or the equivalent. That recommendation is really a description of the exam's assumed vocabulary: networking, operating systems and core security concepts are used, not taught.
So before committing to the schedule, do three things:
A note on timing honesty: CompTIA publishes no official study-hours figure, and your baseline audit is the only trustworthy predictor. A working security analyst might compress this plan to six weeks; someone whose pentesting exposure is entirely theoretical should stretch it rather than skim it.
Each week pairs a theory block with a lab block. For labs, a modest home setup is enough: virtual machines on your own hardware, with deliberately vulnerable practice targets — and only ever systems you own or are explicitly authorised to test. That legal-and-authorised habit is not just ethics; scoping and authorisation are themselves examined material.
Start where every engagement starts. Study how penetration tests are scoped and governed: rules of engagement, authorisation, legal and compliance boundaries, and the frameworks that structure an assessment. This material is heavily conceptual, which makes it tempting to skip — resist that, because it is also the material you cannot reason your way to from technical instinct alone.
Lab thread: build your environment. Install your virtualisation platform, set up an attack machine and two or three practice targets, and snapshot everything so you can reset cleanly. Document the build as if a client had commissioned it — you are rehearsing the professional habit the exam's reporting content rewards.
Move to information gathering: passive and active reconnaissance, enumeration, and vulnerability scanning. The skill the exam actually tests is interpretation — given scanner or enumeration output, what does it tell you, what is noise, and what would you investigate next?
Lab thread: run discovery and vulnerability scans against your practice targets. For every finding your scanner reports, write one sentence on what it means and whether you would pursue it. By the end of week 4 you should be reading raw tool output comfortably, because PBQs will not give you a friendly dashboard.
The longest block, matching the deepest content area: exploiting the weaknesses you have found across networks, applications, wireless, cloud and hosts, plus what follows initial access. Three weeks of theory-plus-practice here beats six weeks of theory.
Lab thread: work through your vulnerable targets end to end — from a scan finding to demonstrated access — and keep contemporaneous notes of every step and command. If a technique in your study materials cannot be reproduced in your lab, at minimum walk through the tool's documentation and output format so it is recognisable under exam conditions.
Reporting is where PenTest+ differs most from how self-taught attackers study. Cover findings analysis, remediation recommendations, and how results are communicated to technical and non-technical audiences.
Lab thread: write an actual report on your weeks 5–7 lab work: findings, evidence, severity reasoning, recommended fixes. It will feel slow. It is also the fastest way to make the reporting objectives stick, and it converts your lab notes into revision material for week 10.
Sweep back across the toolbox as its own topic: which tool fits which phase, and how to read the output of each. Add basic script analysis — you should be able to look at a short script and say what it does, even if you would struggle to write it from a blank page.
Lab thread: self-quiz from your own terminal history. Re-run key tools from the previous weeks and, before each, predict what the output will contain.
No new material. Run at least two full-length, timed practice sessions under exam conditions — 165 minutes, no notes — and treat the results as a diagnosis, not a verdict: every wrong answer gets traced back to an objective, and the days between sessions go to restudying those specific areas rather than re-reading everything. Avoid re-taking the same question set until you have merely memorised it; recognition is not readiness. ExamPractice's CompTIA practice questions include free samples for spot-checks, with fuller sets and a timed simulation mode for the full-length runs.
Book the exam — delivered through Pearson VUE, at a test centre or online — for the end of this week or shortly after. As of June 2026 the US retail price listed by CompTIA's authorised resellers is $439 (it varies by country; confirm current pricing on comptia.org), and CompTIA's retake policy allows an immediate second attempt but requires 14 days and a fresh voucher from the third attempt on. That price is a good argument for letting week 10's results, not the calendar alone, make the booking decision.
Do not start with a textbook chapter. Start with the twenty minutes that shape everything else: download the PT0-003 objectives from comptia.org, run the baseline audit from the top of this plan, and set up the lab environment — because every subsequent week assumes it exists. A study plan only becomes real when week 1's lab block has somewhere to run.
Once you pass, PenTest+ stays valid for three years and renews through CompTIA's Continuing Education programme, with a higher-level CompTIA exam among the renewal routes — worth knowing when you plan what comes after.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·10 min read
What CompTIA A+ covers, how the 220-1201 and 220-1202 exams work, and a step-by-step plan to earn the certification as a complete beginner.
Continue reading·10 min read
What CompTIA Network+ covers, how the N10-009 exam works, who should take it and a practical preparation plan — everything in one guide.
Continue reading·9 min read
What CompTIA Security+ is, the SY0-701 exam format and cost, who the certification suits, and a practical five-step route to earning and keeping it.
Continue reading