Exampractice
IT & Networking

CompTIA PenTest+ Study Plan

A week-by-week PenTest+ PT0-003 study schedule pairing theory with hands-on lab work, from baseline audit to final timed simulation.

Liam Anderson · 6 min read
Ten-week calendar illustrating stages of PenTest+ study from reconnaissance to reporting to exam day

Picture the exam you are preparing for: PT0-003 gives you up to 90 questions and 165 minutes, mixes multiple-choice with performance-based questions (PBQs), and demands 750 on a 100–900 scale to pass. A schedule built purely on reading will not get you there, because PenTest+ questions are written the way engagements run — scoping decisions, tool output to interpret, findings to communicate. So this plan interleaves theory and lab work every single week, structured around the arc of a real penetration test, and ends with timed simulation rather than last-minute reading.

The plan below assumes roughly ten weeks at a steady part-time pace. It covers how to study, not whether PenTest+ is the right certification or how it compares with other offensive-security credentials — for the exam's full context, cost and format details, see the CompTIA PenTest+ certification guide.

Before week 1: run an honest baseline

CompTIA enforces no prerequisites for PenTest+, but it recommends three to four years in a penetration-testing role plus Network+ and Security+ level knowledge — or the equivalent. That recommendation is really a description of the exam's assumed vocabulary: networking, operating systems and core security concepts are used, not taught.

So before committing to the schedule, do three things:

  1. Download the official PT0-003 exam objectives from comptia.org (free) and skim every line, marking what is familiar, rusty or foreign. The objectives are the contract for the exam; this plan tells you when to study things, but the objectives tell you what.
  2. Audit your foundations. If TCP/IP behaviour, common ports, Linux command-line basics or core security concepts feel shaky, budget extra weeks up front or consider certifying those first — the Security+ certification guide covers the usual prior step.
  3. Choose one primary PT0-003-aligned study resource and stick with it. Materials written for PT0-002 or earlier are for a retired exam (PT0-002 retired in June 2025) — check the code before buying.

A note on timing honesty: CompTIA publishes no official study-hours figure, and your baseline audit is the only trustworthy predictor. A working security analyst might compress this plan to six weeks; someone whose pentesting exposure is entirely theoretical should stretch it rather than skim it.

The week-by-week schedule

Each week pairs a theory block with a lab block. For labs, a modest home setup is enough: virtual machines on your own hardware, with deliberately vulnerable practice targets — and only ever systems you own or are explicitly authorised to test. That legal-and-authorised habit is not just ethics; scoping and authorisation are themselves examined material.

Weeks 1–2: engagement planning and scoping

Start where every engagement starts. Study how penetration tests are scoped and governed: rules of engagement, authorisation, legal and compliance boundaries, and the frameworks that structure an assessment. This material is heavily conceptual, which makes it tempting to skip — resist that, because it is also the material you cannot reason your way to from technical instinct alone.

Lab thread: build your environment. Install your virtualisation platform, set up an attack machine and two or three practice targets, and snapshot everything so you can reset cleanly. Document the build as if a client had commissioned it — you are rehearsing the professional habit the exam's reporting content rewards.

Weeks 3–4: reconnaissance and vulnerability scanning

Move to information gathering: passive and active reconnaissance, enumeration, and vulnerability scanning. The skill the exam actually tests is interpretation — given scanner or enumeration output, what does it tell you, what is noise, and what would you investigate next?

Lab thread: run discovery and vulnerability scans against your practice targets. For every finding your scanner reports, write one sentence on what it means and whether you would pursue it. By the end of week 4 you should be reading raw tool output comfortably, because PBQs will not give you a friendly dashboard.

Weeks 5–7: attacks and exploitation

The longest block, matching the deepest content area: exploiting the weaknesses you have found across networks, applications, wireless, cloud and hosts, plus what follows initial access. Three weeks of theory-plus-practice here beats six weeks of theory.

Lab thread: work through your vulnerable targets end to end — from a scan finding to demonstrated access — and keep contemporaneous notes of every step and command. If a technique in your study materials cannot be reproduced in your lab, at minimum walk through the tool's documentation and output format so it is recognisable under exam conditions.

Week 8: post-engagement work — analysis and reporting

Reporting is where PenTest+ differs most from how self-taught attackers study. Cover findings analysis, remediation recommendations, and how results are communicated to technical and non-technical audiences.

Lab thread: write an actual report on your weeks 5–7 lab work: findings, evidence, severity reasoning, recommended fixes. It will feel slow. It is also the fastest way to make the reporting objectives stick, and it converts your lab notes into revision material for week 10.

Week 9: tools and scripting consolidation

Sweep back across the toolbox as its own topic: which tool fits which phase, and how to read the output of each. Add basic script analysis — you should be able to look at a short script and say what it does, even if you would struggle to write it from a blank page.

Lab thread: self-quiz from your own terminal history. Re-run key tools from the previous weeks and, before each, predict what the output will contain.

Week 10: full simulation and gap-closure

No new material. Run at least two full-length, timed practice sessions under exam conditions — 165 minutes, no notes — and treat the results as a diagnosis, not a verdict: every wrong answer gets traced back to an objective, and the days between sessions go to restudying those specific areas rather than re-reading everything. Avoid re-taking the same question set until you have merely memorised it; recognition is not readiness. ExamPractice's CompTIA practice questions include free samples for spot-checks, with fuller sets and a timed simulation mode for the full-length runs.

Book the exam — delivered through Pearson VUE, at a test centre or online — for the end of this week or shortly after. As of June 2026 the US retail price listed by CompTIA's authorised resellers is $439 (it varies by country; confirm current pricing on comptia.org), and CompTIA's retake policy allows an immediate second attempt but requires 14 days and a fresh voucher from the third attempt on. That price is a good argument for letting week 10's results, not the calendar alone, make the booking decision.

Common mistakes that derail PenTest+ preparation

  • All theory, no terminal. The exam's scenario questions and PBQs assume you have seen real tool output. Reading about a scanner is not the same memory as squinting at its results.
  • All terminal, no scoping or reporting. Technically-minded candidates routinely under-study planning, legal boundaries and communication — content a lab cannot teach by accident. Weeks 1–2 and 8 exist precisely for this.
  • Studying for the wrong exam code. PT0-003 has been the only live version since PT0-002 retired in June 2025; second-hand study materials often lag.
  • Memorising practice answers. Scaled scoring (750 on 100–900, with up to 90 questions of which some may be unscored seed items) rewards broad objective coverage. Memorised answers collapse the first time a question is phrased differently.
  • Ignoring the foundations audit. If week 3 feels impossible, the problem is usually missing Network+/Security+ level grounding, not the plan's pacing.

Your first move this week

Do not start with a textbook chapter. Start with the twenty minutes that shape everything else: download the PT0-003 objectives from comptia.org, run the baseline audit from the top of this plan, and set up the lab environment — because every subsequent week assumes it exists. A study plan only becomes real when week 1's lab block has somewhere to run.

Once you pass, PenTest+ stays valid for three years and renews through CompTIA's Continuing Education programme, with a higher-level CompTIA exam among the renewal routes — worth knowing when you plan what comes after.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like